Why AML Programs Fail Adviser Audits

(and why the 2026 reforms will make the gaps easier to see)

Most advice businesses (or their Licensee) currently need to have an AML/CTF program in place. The policies are written, procedures documented and staff trained. On the surface, the structure appears sound, yet in practice, audit findings continue to arise.

In many cases, the issue is not that the program is deficient. It is that the program is not consistently reflected in the client file. Over time, processes that were carefully designed become compressed, assumed or treated as administrative steps rather than as part of professional judgement:

As the reforms approach, the distinction between having a program or framework and applying it will become increasingly visible.

Below, we discuss the new reforms and issues we commonly find in advice files.


The 2026 Reforms: clearer rules, greater scrutiny

“They can’t read my… Poker Face…”

(AUSTRAC’s got me like nobody; or like Lady Gaga)

The 2026 reforms modernise the regime and simplify its structure, including moving away from the legacy Part A / Part B framework. We outlined these changes in our recent article What’s Changing in 2026 Under the AML/CTF Reforms?

A key change is the formation of “reporting groups”, which can either be a “business group” or “by election”:

  • Advice businesses that only arrange (rather than provide) designated services will therefore need to follow the product issuer’s KYC and onboarding processes,
  • Advice businesses that also offer broader services (e.g. assistance with SMSF documentation) may come under the new “designated services” classifications (AUSTRAC gives some guidance to help you assess this),
  • In the meantime, AUSTRAC has indicated it expects currently reporting entities to show sustained effort and progress against their implementation plans.

Where rules become clearer, inconsistent execution becomes easier to identify:

  • Customer due diligence, verification, risk assessment and record-keeping remain central obligations for the reporting group,
  • In an outcomes-focused environment, evidence becomes the primary measure of compliance.

Issue 1: Familiarity with clients

“Now you’re just somebody that I used to know”

Gotye, or an adviser who didn’t see behind the veil until too late.

Long-standing client relationships create confidence, but they can also reduce discipline. Client files for long-term clients are among the hardest to review for compliance – because there is so much information:

  • Advisers who have worked with a client for many years often rely on accumulated knowledge rather than documented assessment,
  • Changes in ownership, structure, business activity or geographic exposure may occur gradually and not trigger a formal reassessment.

Reviews frequently identify files where:

  • Original onboarding documentation is incomplete,
  • Beneficial ownership has evolved without updated records, or
  • New risk factors were absorbed into the relationship without analysis.

Familiarity is not a substitute for due diligence. In some respects, it increases the risk that assumptions go untested.


Issue 2: Prioritising implementation instead of process

AML processes are most vulnerable when advice moves quickly toward implementation.

When a strategy is agreed upon, and the client is ready to proceed, procedural steps can be deferred until “after the meeting” or “during file completion”. This often results in incomplete identification, unclear verification methods, or missing risk assessments: the issue is rarely intent, but sequencing.

AML obligations are designed to inform whether and how services should proceed. When processes occur retrospectively, they lose their preventative value and become administrative.


Issue 3: Over-reliance on others

Advice practices operate through teams. Administrative support, paraplanning and compliance functions all contribute to delivering services.

However, AML responsibilities involve professional judgement that cannot be fully delegated. Determining the appropriate level of due diligence requires an understanding of the client, the service and the surrounding circumstances.

Where responsibility is assumed to sit elsewhere – whether with support staff or centralised functions – documentation often becomes inconsistent. Clear ownership of the process is essential.

Navigating responsibility for AML/CTF will be even more important under the new rules, where the “lead entity” will do the actual reporting to AUSTRAC. The intent of this new framework is to increase efficiency and flexibility. However:

  • The reality will be that advisers can’t simply assume it’s all been taken care of by somebody else and still need to exercise and document professional judgement,
  • Advisers deal with multiple product providers, and having multiple systems is a risk in and of itself,
  • Maintaining rigorous and consistent AML/CTF systems, rather than an ad hoc approach depending on the designated service being arranged, is arguably the best approach.

Issue 4: Documentation quality

“We are all working from imperfect files, but some of us are at least checking the documentation.”

Oscar Wilde… or your Review Team

Many AML findings arise not from incorrect decisions, but from the absence of a clear record explaining those decisions.

A well-prepared file should allow an independent reviewer to understand:

  • What was considered,
  • What actions were taken,
  • Why those actions were sufficient.

Common gaps include incomplete verification records, unclear use of electronic identification methods and insufficient evidence supporting beneficial ownership assessments. For client groups (e.g. married couples), KYC may have been completed for both clients originally, but we still see files where the original KYC documentation was never verified for one member of the couple, or where it has now expired.

Documentation should reflect the adviser’s reasoning, not simply the completion of tasks.


Issue 5: Electronic verification and remote engagement

Remote advice delivery has increased reliance on electronic identification methods.

These methods are acceptable when properly implemented, but they require clear evidence of:

  • The verification method used,
  • The sources relied upon,
  • The outcome of the process,
  • Any follow-up actions taken.

Where anomalies arise, the file should demonstrate escalation and additional checks. Convenience should not reduce the depth of due diligence.


What a Strong File Demonstrates

Files that withstand review share a common feature: they demonstrate a clear link between risk assessment and action.

Typically, this includes:

  • A concise assessment of the client’s ML/TF risk profile,
  • A record of identification and verification steps,
  • Evidence of beneficial ownership analysis,
  • Documentation of screening activities,
  • A reasoned conclusion.

The objective is not exhaustive documentation, but a coherent narrative that explains the adviser’s decisions.


Embedding the Policy

“Between the policy and the file falls the shadow.”

T.S. Elliot: Limitations in AML/CTF Frameworks

Programs or frameworks are most effective when they are embedded in everyday practice rather than treated as compliance overlays:

  • The reforms will expand the regime and bring new services into scope, but the underlying expectation remains unchanged,
  • Advisers must actively assess and manage risk as part of delivering professional services.

For advice leaders, a useful test is whether a small sample of files would demonstrate consistent application of the program or framework without additional explanation:

  • Where gaps exist, they are usually addressed through better integration – templates, prompts, training and periodic internal reviews – rather than more documentation,
  • AML programs rarely fail dramatically. They usually fail quietly, in files that look complete at first glance — a bit like a poker face that no one thought to test.

Do your files comply?

As businesses prepare for the reforms, we recommend you reflect on whether your AML/CTF program or framework operates as intended at the file level.

Policies set expectations. Files demonstrate whether those expectations are met. Bridging that gap is often where the most meaningful improvements occur.

For help with your files, contact Assured Support.

If you enjoyed this article, you might also like:


Frequently Asked Questions

Does providing strategy-only advice trigger AML obligations?

Not necessarily. AML/CTF obligations generally apply when a designated service is provided. Strategy advice may fall within scope if it involves assisting with transactions or arrangements, but purely conceptual advice may not. The specific circumstances matter.

What is the difference between KYC and CDD?

Know Your Customer (KYC) focuses on identifying and verifying the client’s identity.
Customer Due Diligence (CDD) is broader and includes assessing the client’s risk profile, understanding beneficial ownership and determining the appropriate level of scrutiny.

How often should client due diligence be reviewed?

CDD should be revisited when there are material changes in the client’s circumstances, services provided or risk factors. Periodic reviews may also be appropriate for higher-risk relationships.

Are electronic identification methods sufficient?

They can be, provided they are reliable, appropriately applied and supported by clear records of the verification process and outcomes.

What is the most common reason AML frameworks fail reviews?

Inconsistent application at the file level. Most findings relate to gaps between documented procedures and what occurred in practice.

Keep exploring

Why AML Programs Fail Adviser Audits

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?