Five AML Questions You Must Be Able To Answer

And my advice is to always answer the question
Better that than to ask it all your life

Taylor Swift, AML Expert

Under the expanded AML/CTF regime (Tranche 2), reporting entities like advice licensees must arrange periodic independent reviews of their AML risk management framework. It’s not compliance for compliance’s sake; the review objectively assesses whether the firm’s risk assessment, governance and operational controls are functioning effectively in practice.

In reality, when an independent reviewer assesses a financial advice business or licensee, the questions they ask are likely to be very practical. In the context of AML/CTF, they are trying to determine whether the AML framework actually operates in the business, not just whether documents exist. We expect that most reviews will end up circling around a small set of core governance questions.


First Question:

First, they will probably ask: “How does the business identify its AML/CTF risks?” You are expected to show that the risk assessment is specific to the firm’s business model. The reviewer will look for evidence that the assessment considers client types, services provided, delivery channels, jurisdictions, and client activity or product usage patterns. They will also check whether the scoring methodology is documented and whether the assessment is reviewed periodically.


Second Question:

Second, they should ask: “How do you ensure customer due diligence is consistently applied?” This is where they examine onboarding procedures. They normally want to see the process advisers follow when identifying clients, verifying identity, checking beneficial ownership, and screening PEPs or sanctions. Reviewers may test several client files to confirm the documented process is actually followed.


Third Question:

Third, we’d expect them to ask: “How would suspicious activity be identified and escalated in practice?” This question tests operational awareness. Suspicion does not arise only from transactions. It may also arise from client behaviour, advice activity, or unusual product use. Reviewers may ask advisers or operations staff directly what they would do if they suspected money laundering. The reviewer wants to see that staff know the internal escalation process and that the AML Compliance Officer can demonstrate how suspicious matter reports would be assessed and reported to AUSTRAC.


Fourth Question:

Fourth, we’d certainly ask: “How does senior management oversee AML risk?” Here, the reviewer is looking for evidence of governance rather than procedures. They should expect to see risk assessment results reviewed by management, periodic AML updates, and board reporting. The key issue is whether leadership has visibility of AML risk exposure and control effectiveness.


Fifth Question:

Fifth, they should conclude by asking: “How do you know your AML controls are working?” This question focuses on monitoring and testing. Reviewers will likely look for things like periodic reviews of the AML program, training records, control testing, or independent reviews. The aim is to determine whether the firm periodically evaluates whether its controls remain effective.


How Did You Do?

If a firm can answer those five questions clearly and show supporting evidence, most independent AML reviews proceed smoothly. Policies and risk assessments matter, but reviewers are mainly assessing whether the framework is understood, implemented, and overseen.

Preparing for an AML independent review?
Assured Support works with advice licensees to strengthen AML governance, review risk assessments, and ensure controls operate effectively in practice, before the reviewer arrives.

Learn how Assured Support can help your licensee prepare for AML/CTF obligations.

If you liked this article, you might also enjoy:


Frequently Asked Questions

What is an AML/CTF independent review?

An independent review is a periodic evaluation of a reporting entity’s AML/CTF program to determine whether it is appropriately designed and operating effectively. AUSTRAC expects these reviews to assess governance, risk assessments, customer due diligence processes, and reporting controls.

How often should AML programs be independently reviewed?

Australian AML/CTF rules require reporting entities to arrange independent reviews at intervals appropriate to the nature, size and risk profile of the business. Regulators typically expect reviews every two to three years, depending on risk exposure.

What evidence do reviewers typically request?

Reviewers often request the AML risk assessment, onboarding procedures, customer identification records, training records, suspicious matter reporting processes, and governance reporting to senior management.

How do advisers escalate suspicious activity?

If suspicious behaviour or transactions are identified, advisers usually escalate the issue internally to the AML Compliance Officer, who determines whether a Suspicious Matter Report must be lodged with AUSTRAC.

Do advice businesses always need their own AML program?

Not always. Many advisers operate under their AFSL’s AML program. However, when a licensee provides a designated service, the licensee must maintain and review a compliant AML/CTF program.

Keep exploring

Five AML Questions You Must Be Able To Answer

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?