AUSTRAC expects reporting entities, including AFS licensees where applicable, to provide risk-based AML/CTF training to relevant staff and to maintain documented evidence of training content, attendance, timing, and competency to demonstrate that employees understand and can apply AML/CTF obligations.
Expanded Answer
AUSTRAC guidance requires AML/CTF programs to include an ongoing employee due diligence and training component. Training must be tailored to staff’s roles and responsibilities, reflecting the entity’s ML/TF/PF risk profile. This includes ensuring that employees understand key obligations such as customer due diligence, suspicious matter reporting, record-keeping, and escalation processes.
In practice, training should be structured by role. Advisers and client-facing staff require practical training on identifying red flags and applying controls, while compliance staff require deeper knowledge of reporting obligations and regulatory interaction. Training should occur at onboarding and regularly, with additional sessions triggered by regulatory changes, identified control weaknesses, or incidents.
Documentation is critical. AUSTRAC expects evidence that training has occurred and is effective. This includes training materials, attendance records, completion logs, assessment results where used, and records of refresher training. Licensees should also be able to demonstrate how they monitor and improve training outcomes over time. Weak or generic training is a common issue identified in AML reviews. For broader compliance capability expectations, see AML/CTF financial planners Australia and Influencing change: training and education.
Why it matters
Inadequate AML/CTF training increases the risk of missed suspicious activity, reporting failures, and systemic breaches. AUSTRAC assesses whether staff can operationalise obligations, making poorly evidenced or ineffective training a key enforcement risk.
Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call.
Practical guidance
- Design role-specific AML/CTF training aligned to your risk assessment, covering practical scenarios and obligations relevant to each function.
- Deliver training at onboarding and regularly thereafter, with additional updates following regulatory or business changes.
- Maintain comprehensive training records, including materials, attendance, completion status, and evidence of understanding, such as assessments or attestations.
Further reading
Five AML questions you must be able to answer
Why AML programs fail adviser audits