FAQ

I’m a small licensee — what type of AML/CTF Program do I need?

It depends on how you provide your services.


Scenario A: You provide the designated service yourself

Examples include:

  • You issue or operate a financial product
  • You provide custodial or depository services
  • You run MDAs directly
  • You lend, fund, or deal directly with customer assets

In these cases, you must maintain a full AML/CTF Program (Parts A & B), which includes:

  • Part A risk assessment and governance
  • Oversight and compliance frameworks
  • Training of staff
  • Independent review
  • Part B customer due diligence and verification

Scenario B: You only perform the item 54 “arranging” service (agent/distributor model)

If you arrange for customers to receive a designated service from a product issuer, and you are not providing any designated service directly, you may be eligible for Special AML/CTF Program (Part B-only)

This is appropriate when:

  • The principal provider maintains the full Part A program, and
  • Your role is limited to conducting customer identification and following their AML/CTF procedures.

This significantly reduces the compliance burden for small AFSLs.


Scenario C: You don’t provide any designated service

This includes:

  • Advice-only businesses
  • Intermediaries that do not issue or operate products
  • Administrative/support services without product provision

In these cases, you do not need any AML/CTF Program, but the product issuers you work with may still require you to follow their AML/CTF procedures contractually.

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?