Hello Bigboy

Bigboy Wealth Pty Ltd is a small AFSL with nine staff and ~650 active clients. It operates a fairly typical advice and dealing model with retail clients, some SMSFs, and some corporate trustee structures. It uses a wrap/platform provider for administration and custody, and it recently bought a low-cost eKYC + sanctions/PEP screening tool as part of its “post-reform uplift”.

This is an illustrative learning exercise using an established licensee and AML/CTF for relevance, novelty and schadenfreude. At the request of the current staff, names have been changed. Out of respect for the former employees, the rest has been told exactly as it occurred. If you’re currently grappling with AML changes, learn from their example. 


As a market-leader with an exceptional compliance culture, Bigboy

  • has a newly updated AML/CTF Program (template-based but polished).
  • has a post-reform risk assessment with heatmaps and residual risk ratings.
  • has training records showing near-complete attendance.
  • can explain its processes confidently.

Bigboy have recently done the conference circuit explaining how to turn AML obligations into a source of competitive advantage. They’re experts and are promoted as such.

Let’s depart from industry practice and presume that self-praise is no recommendation.

Now, let’s play regulator and run Bigboy’s first post-reform AML/CTF review.

Bigboy, like most licensees, might assume this review is a “document check”, but it isn’t (and never is). 

Instead, our review will test whether Bigboy can prove control effectiveness, not whether it can describe intent. And Bigboy will probably fail because its compliance framework is nothing more than a set of documents concealing an inconsistent operational reality.

From a regulatory perspective, these types of failures are often obvious because:

  • Evidence is missing or non-standard.
  • Controls don’t operate consistently.
  • Governance is passive.
  • Outsourcing is treated as risk transfer.
  • Monitoring is assumed rather than demonstrated.

Bigboy is exactly the profile regulators worry about post-reform: small entities with high confidence and low control maturity.


The Regulator’s Mindset

If you adopt the regulator’s mindset, you’re not trying to catch Bigboy out because of malice, KPIs or to chase social-media rizz. You’re doing something more pragmatic and more serious:

You are trying to determine whether Bigboy is a reliable gatekeeper in a regime that depends on gatekeepers.

You might assume three things upfront:

  1. The written framework will look better than reality.
  2. If there are gaps, they will be systemic, not isolated.
  3. If the entity cannot evidence performance, it cannot be trusted to self-correct.

These assumptions, or presumptions, are critical because you’ll approach Bigboy’s framework like an engineer approaches a safety system: you’ll stress test it to see how it actually operates. You’ll trust, but verify, or, if you’re one of those people, simply verify. 


How would a regulator test Bigboy’s framework?

Test 1: Traceability. Did Bigboy connect the dots?

What the regulator is really testing:

Despite constant exposure, Regulators (and compliance experts) are allergic to compliance that isn’t connected. The key test isn’t whether Bigboy has relevant policies and procedures, but whether Bigboy can link:

Risk Assessment → Control Design → Control Operation → Evidence → Governance oversight

This is the structural backbone of all post-reform compliance frameworks.

Testing Bigboy

So, if you want to verify effectiveness, what should you do?

We can’t know for sure what you’d do, but we suspect that once you slip into this mindset, your curiosity and bias for facts and evidence might prompt you to ask for:

  • The AML/CTF risk assessment (and an explanation of how it was developed)
  • The risk rating methodology (customer risk scoring)
  • The EDD trigger logic
  • Periodic review schedule logic
  • Monitoring approach (reports, thresholds, escalation)
  • Assurance/testing plan and results

What you would probably look for

Remember, you’re not looking for updated policy documents; you’re looking for alignment. So you’d probably investigate whether:

  • the risk drivers in the risk assessment appear in customer risk ratings
  • “high-risk” customers actually treated differently?
  • review cadences have been implemented or merely described
  • monitoring tailored to identified typologies

What you’d probably find (failure signal)

Unfortunately, Bigboy couldn’t demonstrate alignment; the risk assessment only existed as a narrative artifact and the operational controls were generic and inconsistent.

In all likelihood, this is enough to conclude that a risk-based approach isn’t operating. That’s more than embarrassing; it’s a primary failure.


Test 2: Population testing and working at scale. Did Bigboy build proof points?

The regulatory principle

Self-nominated awards might be reliable indicators of character and competence but you, like regulators, probably wouldn’t trust samples volunteered by Bigboy (or, to be fair, from any person or entity).

So you’d probably ask for population data.

Just between us, this is the moment most small AFSLs often fall apart; the reality is that most extrapolate from small samples and have never had to treat compliance as a population-level control system. They think in terms of exceptions instead of systems. 

What you would probably look for

You know that neither Licensees nor advisers would cherry-pick records to mitigate their regulatory risk, but you’d probably still request:

  • Full client list for the last 18 months (new + existing)
  • Customer risk ratings (including dates and change history)
  • Client types (individual, SMSF, company trustee)
  • Client onboarding channel (remote/in-person)
  • Screening outcomes (sanctions/PEP) with timestamps
  • Periodic review of due dates and completion records

What you’re testing

You’re biased towards evidence, so you’ll probably look for two things in Bigboy’s AML/CTF control framework:

  1. Completeness: do the controls apply to everyone it should?
  2. Repeatability: do these controls operate consistently, regardless of staff member?

What you’d probably find (failure signal)

Bigboy couldn’t produce clean extracts because “proof” (where it exists at all) is scattered between :

  • CRM tick boxes
  • email trails
  • shared drives
  • PDFs stored inconsistently (if at all)

Bigboy’s lauded tech stack created a fundamental problem for the Licensee because the architecture provided no reliable way for them to prove:

  • screening occurred
  • screening occurred before onboarding
  • periodic reviews happened
  • beneficial owners were identified/screened

In all likelihood, you’d quickly conclude that the control environment was not reliable. The reality is that a compliance framework that cannot evidence population coverage is not credible.


Test 3: File testing. Did Bigboy evidence the lifecycle?

This is where the review becomes forensic, and natural intelligence trumps artificial versions. 

To test the framework, you’d probably select files across risk tiers and structures:

  • low-risk retail clients
  • medium/high-risk clients
  • SMSFs
  • proprietary company trustees
  • clients with large contributions or withdrawals

You then run an end-to-end file test.

Files can vary between licenses and even within a single licensee. When you review those files, you’ll be looking for evidence of:

  • identity verification (not just “verified”)
  • screening results (sanctions/PEP) with timestamps
  • beneficial ownership/controlling persons (for entities)
  • purpose and intended nature of the relationship
  • source of funds/source of wealth (where relevant)
  • EDD triggers and approvals
  • ongoing due diligence actions (review, rescreening)
  • monitoring events and escalation (if any)

What you would probably look for

No reviewer is expecting perfection. No regulator is expecting perfection.

They’re simply pursuing evidence of control logic.

In particular, most file reviews have a modest goal of trying to identify or confirm:

  • a consistent file structure
  • timestamps
  • documented decisions
  • approvals
  • escalation when something doesn’t meet the standard. 

What you’d probably find (failure signal)

Bigboy’s files show “compliance theatre”:

  • “IDV complete” tick box, but there’s no evidence retained
  • screening reports missing or untimestamped
  • entity beneficial owners not identified or not screened
  • source of funds/wealth recorded as dropdowns with no corroboration
  • no EDD rationale even where risk factors exist

In this case, Bigboy couldn’t demonstrate that its CDD/EDD controls operate effectively, because they don’t. This wasn’t a trivial finding, but a failure that goes to the heart of its AML/CTF obligations.


Test 4: Monitoring. Does Bigboy actually detect risk, or just assume someone else does?

In practice, Bigboy relies heavily on the wrap/platform provider. A key management assumption is that “The platform handles transactions; therefore, monitoring is handled.”

It’s a convenient position, but, unfortunately for Bigboy, Regulators treat this as a known failure mode.

To test the effectiveness of any compliance framework, you’d focus on monitoring and supervision by asking questions like:

  • What monitoring is performed by Bigboy?
  • What monitoring is performed by the platform?
  • What does Bigboy receive?
  • How does Bigboy review it?
  • What thresholds apply?
  • What exceptions were identified?
  • What happened next?

What you would probably look for

This isn’t Compliance101, but a reviewer or regulator would want to see a monitoring framework with:

  • defined typologies relevant to Bigboy
  • thresholds and triggers
  • a log of reviews
  • exception tracking
  • escalation decisioning
  • Suspicion Assessment Records

What you’d probably find (failure signal)

As a result of its conscious reliance on the platform provider, Bigboy has not independently created the records, processes and systems needed to generate and retain:

  • monthly platform reports
  • evidence of systematic review
  • sign-off trail
  • an exception log
  • a suspicion decision framework

Operating does not prove monitoring. Bigboy had an unmanaged detection gap that required deliberate effort to mitigate. 


Test 5: Governance and assurance. Can Bigboy detect and diagnose problems?

Whether you describe it as continuous improvement or sustainability, the decisive test of a compliance and control framework is its capacity adapt and evolve in response to reforms and identified issues.

Reviewers and regulators need to be satisfied that an entity can:

  • identify its own control weaknesses
  • measure effectiveness
  • remediate systematically
  • verify remediation

Where to look

  • Board/RM compliance reports
  • minutes evidencing challenge and decisions
  • action registers and closure evidence
  • QA sampling results (file reviews)
  • thematic reviews (e.g., beneficial ownership)
  • independent audit activity

What you would probably look for

You look for “active ownership”, not passive reporting:

  • Are issues surfaced early?
  • Are backlogs visible?
  • Are resourcing decisions made?
  • Is remediation verified?

What you’d probably find (failure signal)

  • Board/RM packs show KPIs like training completion
  • little evidence of challenge
  • no structured testing plan
  • no remediation verification

The reality is that Bigboy’s governance is not effective. The entity cannot be relied upon to correct itself.


The Bottom Line.

This is a failure (not a warning).

From the Licensee’s perspective, these are teething issues and administrative gaps, but from a regulator’s perspective, they indicate something deeper. In fact, someone less generous than you might conclude that Bigboy did not have an AML/CTF control system. It only had AML/CTF documentation.

That distinction matters.

If you limit your focus to their AML/CTF framework, your critical assessment is premised on three points:

  • If Bigboy can’t evidence controls, it can’t demonstrate compliance.
  • If it can’t demonstrate compliance, it may be enabling laundering risk without knowing it.
  • If it can’t self-detect weaknesses, supervisory intervention must be stronger.

This is why Bigboy’s failure is a matter of operational effectiveness and culture” failure—because the entity’s controls are not provably functioning.


The practical “regulator’s checklist” (what you’d look for)

If you want to assess Bigboy, or your own business, like a regulator might, look for these five indicators:

  1. Audit trail maturity
    Can the Business show timestamps, decision logs, approvals?
  2. Population coverage
    Can the Business prove controls apply to all relevant clients, not just samples?
  3. Risk differentiation
    Do high-risk clients actually receive higher scrutiny in practice?
  4. Exception handling
    When something is missing or fails, is it escalated, recorded, resolved?
  5. Assurance loop
    Does the Business test itself, track findings, remediate, and verify closure?

Bigboy failed because it couldn’t answer these questions with evidence. Don’t take the same approach and expect a different outcome. 

If this scenario felt uncomfortably familiar, you’re not alone, but inaction is no longer defensible. Assured Support works with licensees to identify control gaps, build population-level evidence, and restore regulator confidence. Contact the team to assess whether your AML/CTF framework is operating or merely described.

If you enjoyed this article, you might also like:


Frequently Asked Questions

Is a well-written AML/CTF Program enough to satisfy regulators?

No. Regulators assess whether controls operate effectively in practice. Policies without evidence of consistent execution are treated as non-functional.

Why is population testing critical in AML/CTF reviews?

Because regulators must be satisfied that controls apply to all relevant customers. Sampling alone cannot demonstrate systemic compliance.

Can an AFSL rely on its platform provider for AML monitoring?

No. While platforms may perform transaction monitoring, the AML/CTF Act places responsibility for oversight, review, and escalation on the reporting entity.

What does AUSTRAC expect from AML governance?

Evidence of active oversight: issue identification, remediation tracking, verification, and documented challenge at the Board or senior management level.

What is the difference between AML documentation and an AML control system?

Documentation describes intent. A control system produces timestamps, decisions, approvals, and audit trails that prove the intent is executed.

Keep exploring

Hello Bigboy

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?