FAQ

What must be included in Part A vs Part B of an AML/CTF program?

AUSTRAC no longer requires reporting entities, including AFS licensees, to structure AML/CTF programs into Part A and Part B. AUSTRAC now expects a single, documented, risk-based AML/CTF program that includes an ML/TF risk assessment and integrated policies, procedures, systems and controls covering customer due diligence, monitoring, reporting, governance, and training.

Expanded Answer
AUSTRAC’s updated AML/CTF framework removes the prescriptive requirement to separate programs into Part A (governance and controls) and Part B (customer identification procedures). Instead, AUSTRAC expects a unified AML/CTF program that clearly documents how the reporting entity identifies, mitigates, and manages money laundering and terrorism financing risks across its operations.

In practice, the elements previously associated with Parts A and B still exist but must be integrated. This includes a documented ML/TF risk assessment, governance structures (including a senior manager and AML/CTF compliance officer), customer due diligence processes, transaction monitoring, suspicious matter reporting, employee due diligence, and ongoing training. The focus is on whether these elements are coherent, risk-based, and operational within the business.

Regulatory scrutiny increases where legacy “Part A / Part B” documents are retained but not aligned to current AUSTRAC expectations or actual business practices. AUSTRAC assesses whether the program is tailored, current, and embedded in workflows. Programs that are fragmented, template-based, or not implemented in practice are treated as higher risk, as highlighted in AML/CTF for financial planners and what’s changing in 2026 under the AML/CTF reforms.

Why it matters
Relying on outdated Part A and Part B structures can lead to gaps, duplication, or misalignment with AUSTRAC expectations. Regulators assess effectiveness, not format, and poorly integrated programs increase the risk of enforcement, particularly where controls are not clearly linked to identified risks.

Practical guidance

  • Replace legacy Part A and Part B documents with a single, integrated AML/CTF program aligned to current AUSTRAC expectations
  • Map each control (CDD, monitoring, reporting, training) directly to identified ML/TF risks in the risk assessment
  • Test whether the program operates in practice by reviewing onboarding, advice, and transaction workflows against documented procedures

Further reading
AML/CTF for financial planners
What’s changing in 2026 under the AML/CTF reforms

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?