FAQ

What AML/CTF training is required and how should it be documented?

AUSTRAC expects reporting entities, including AFS licensees where applicable, to provide risk-based AML/CTF training to relevant staff and to maintain documented evidence of training content, attendance, timing, and competency to demonstrate that employees understand and can apply AML/CTF obligations.

Expanded Answer
AUSTRAC guidance requires AML/CTF programs to include an ongoing employee due diligence and training component. Training must be tailored to staff’s roles and responsibilities, reflecting the entity’s ML/TF/PF risk profile. This includes ensuring that employees understand key obligations such as customer due diligence, suspicious matter reporting, record-keeping, and escalation processes.

In practice, training should be structured by role. Advisers and client-facing staff require practical training on identifying red flags and applying controls, while compliance staff require deeper knowledge of reporting obligations and regulatory interaction. Training should occur at onboarding and regularly, with additional sessions triggered by regulatory changes, identified control weaknesses, or incidents.

Documentation is critical. AUSTRAC expects evidence that training has occurred and is effective. This includes training materials, attendance records, completion logs, assessment results where used, and records of refresher training. Licensees should also be able to demonstrate how they monitor and improve training outcomes over time. Weak or generic training is a common issue identified in AML reviews. For broader compliance capability expectations, see AML/CTF financial planners Australia and Influencing change: training and education.

Why it matters
Inadequate AML/CTF training increases the risk of missed suspicious activity, reporting failures, and systemic breaches. AUSTRAC assesses whether staff can operationalise obligations, making poorly evidenced or ineffective training a key enforcement risk.

Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call.

Practical guidance

  • Design role-specific AML/CTF training aligned to your risk assessment, covering practical scenarios and obligations relevant to each function.
  • Deliver training at onboarding and regularly thereafter, with additional updates following regulatory or business changes.
  • Maintain comprehensive training records, including materials, attendance, completion status, and evidence of understanding, such as assessments or attestations.

Further reading
Five AML questions you must be able to answer
Why AML programs fail adviser audits

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?