AML/CTF programs explained

‍ ‍

An anti-money laundering and counter-terrorism financing program, or AML/CTF program, explains how a reporting entity identifies, manages and reviews its financial crime risks.

A reporting entity must have an up-to-date AML/CTF program before it starts providing a designated service. The program must reflect the business as it operates in practice, not simply reproduce the legal requirements.

An effective AML/CTF program connects two things: the risks the business faces and the controls it uses to manage those risks.

What is an AML/CTF program?

Under Australia’s anti-money laundering and counter-terrorism financing laws, an AML/CTF program has two parts:

  • a money laundering and terrorism financing risk assessment, known as an ML/TF risk assessment; and

  • the reporting entity’s AML/CTF policies.

The ML/TF risk assessment identifies and assesses the money laundering, terrorism financing and proliferation financing risks that the reporting entity may reasonably face when providing designated services.

The AML/CTF policies describe the procedures, systems and controls used to manage those risks and comply with the law.

The risk assessment should come first because it provides the basis for the policies. The policies should respond to the risks identified in the assessment.

A generic set of policies may address the legal requirements in broad terms. It will not necessarily address the customers, services, technologies, delivery channels and countries that create risk for your business.

Who needs an AML/CTF program?

A business that provides one or more designated services is a reporting entity and must have an AML/CTF program.

Designated services are the activities covered by Australia’s AML/CTF regime. They include specified services provided by financial institutions, professional service providers and other regulated businesses.

A reporting entity must develop and document its AML/CTF program before it begins providing a designated service. It must then maintain, comply with and update the program.

What must an ML/TF risk assessment cover?

An ML/TF risk assessment must identify and assess the money laundering, terrorism financing and proliferation financing risks that a reporting entity may reasonably face when providing its designated services.

For services provided at or through a permanent establishment in Australia, the assessment must consider:

  • the types of designated services the business provides;

  • the types of customers it serves;

  • the channels through which it provides its services;

  • the countries connected with its services and transactions;

  • the effect of new or emerging technologies;

  • relevant risk information provided by the Australian Transaction Reports and Analysis Centre (AUSTRAC); and

  • any other matters required by the AML/CTF Rules.

These are mandatory considerations, but they are not a complete list. A reporting entity must also consider other features of its business that may create or affect its ML/TF risk.

The depth of the assessment must be appropriate to the nature, size and complexity of the business. There is no single template suitable for every reporting entity.

A national payment provider may need detailed analysis of products, transaction patterns, customer segments, distribution channels and jurisdictions. A small advisory firm may need a shorter assessment, but it must still show a defensible process and address the risks its services actually present.

Shorter does not mean generic.

How should an ML/TF risk assessment be documented?

The risk assessment should explain how the reporting entity identified its ML/TF risks, how it assessed them and why it reached its conclusions.

Supporting records should show:

  • the information and risk sources considered;

  • the business activities included in the assessment;

  • ·the method used to assess risk;

  • the risk factors identified;

  • the effect of existing controls;

  • any gaps or weaknesses found;

  • the person who approved the assessment; and

  • the date on which the assessment took effect.

The assessment should provide enough detail for the governing body, AUSTRAC, an independent evaluator or a new compliance officer to understand the process followed and the basis for its conclusions.

When must an ML/TF risk assessment be reviewed?

An ML/TF risk assessment is not a one-off document. A reporting entity must review it:

  • when there is a significant change to a matter considered in the assessment;

  • when AUSTRAC provides new risk information relevant to the entity’s designated services;

  • when an independent evaluation makes an adverse finding about the assessment; and

  • at least once every three years, even if there has been no apparent change.

The three-year review cycle is a minimum requirement. It is not a reason to defer a review when the business changes.

A new product, customer segment, delivery channel, country or technology may alter the entity’s ML/TF risk. Acquiring another business, changing an important service provider or redesigning customer onboarding may have the same effect.

Where a planned change is within the entity’s control, the risk assessment should be reviewed and any identified issues addressed before the change takes place. In other cases, the assessment should be updated as soon as practicable.

Review triggers should be built into product approval, procurement, technology governance and change management processes. The process should not depend on the compliance team discovering a change after it has occurred.

What must AML/CTF policies cover?

AML/CTF policies are the policies, procedures, systems and controls used to manage ML/TF risks and comply with the AML/CTF regime.

The policies must be appropriate to the nature, size and complexity of the reporting entity’s business.

Depending on the entity and its designated services, its policies may need to address:

  • initial and ongoing customer due diligence;

  • enhanced customer due diligence;

  • customer risk ratings;

  • sanctions compliance;

  • higher-risk customers and activities;

  • senior management approvals;

  • suspicious matter review and reporting;

  • safeguards against tipping off;

  • the appointment of an AML/CTF compliance officer;

  • reporting to the governing body;

  • employee due diligence;

  • initial and ongoing employee training;

  • data quality and protection against unauthorised changes;

  • reviews and updates to the AML/CTF program; and

  • independent evaluation of the program.

Additional requirements apply to some reporting groups and to institutions involved in value transfers, merchant payments and virtual asset transfers.

What makes an AML/CTF policy effective?

An effective AML/CTF policy tells staff what they must do, when they must do it, who is responsible and how the action must be recorded.

A policy that says “apply enhanced customer due diligence to high-risk customers” may not provide enough practical direction. Staff also need to know:

  • what triggers enhanced customer due diligence;

  • what additional information must be obtained;

  • how that information must be checked;

  • who decides whether the customer can be accepted or retained;

  • when senior management approval is required; and

  • how the decision and reasons must be recorded.

Policies must reflect the systems and processes the business actually uses. If a control depends on information passing between customer-facing staff, operations and compliance, the policy should explain how that information is shared and who must act on it.

Must a reporting entity follow its own AML/CTF policies?

Yes. A reporting entity must comply with its AML/CTF policies. Failing to follow those policies can itself be a breach of the AML/CTF Act.

This creates a practical drafting risk. Policies should contain clear and effective controls, but they should not impose requirements the business cannot consistently meet.

For example, a policy may require every high-risk customer review to be completed within 24 hours. If staffing, systems and escalation arrangements cannot support that deadline, the policy may create repeated non-compliance.

Before approving a policy, test it against the business’s actual operations. Check that the people responsible for each control understand their role and have the authority, information and resources needed to perform it.

What is an independent evaluation of an AML/CTF program?

An independent evaluation tests the design and operation of a reporting entity’s AML/CTF program.

AML/CTF policies must provide for independent evaluations at least once every three years. Evaluations may need to occur more frequently where that is appropriate to the nature, size and complexity of the business.

An independent evaluation must examine:

  • how the reporting entity undertook or reviewed its ML/TF risk assessment;

  • whether the AML/CTF policies are properly designed;

  • whether the entity complies with its policies; and

  • whether the entity appropriately identifies, assesses, manages and mitigates its ML/TF risks.

The evaluator must prepare a written report for the governing body and relevant senior managers. The reporting entity must consider the findings and address any weaknesses identified.

Reviewing the policies against a list of legal requirements is not enough. The evaluator needs access to the records, systems and staff required to test what happens in practice.

That testing may include customer files, customer risk ratings, alerts, approvals, reports, training records and evidence that earlier findings have been addressed.

The evaluator must be independent and suitable for the work. Independence does not necessarily require an external evaluator, but the person must be able to form an objective view and have the knowledge and skills needed to assess the program.

Why conduct a post-implementation review?

A post-implementation review checks whether a new or substantially updated AML/CTF program is operating as intended.

Even a carefully designed program may encounter problems when staff begin using it. Policies may depend on information that is difficult to access. Responsibilities may be unclear. Systems may not capture the required records. A control that appeared workable during drafting may create delays, duplicate work or leave an unexpected gap.

A post-implementation review provides a second set of eyes. It can test whether:

  • the risk assessment reflects how the business actually provides its designated services;

  • staff understand the policies and can apply them;

  • responsibilities and escalation paths are clear;

  • systems collect and retain the information required by the program;

  • higher-risk customers receive the intended level of scrutiny;

  • approvals, decisions and exceptions are properly recorded;

  • training has prepared staff for their responsibilities; and

  • the controls operate consistently in practice.

A review may also identify controls that create substantial work without addressing a material risk. It may find manual hand-offs that are easily missed or customer risk ratings that do not match the risks identified in the risk assessment.

Finding these issues early allows the business to correct them before they become established practices.

Does a post-implementation review replace an independent evaluation?

No. A post-implementation review and an independent evaluation have different purposes.

A post-implementation review is usually a focused assessment conducted after a new program or major change has been put into operation. Its purpose is to confirm that the program has been properly implemented and operates as intended.

An independent evaluation is a formal requirement under the AML/CTF regime. It must assess both the design of the program and the reporting entity’s compliance with it.

A post-implementation review can help the entity prepare for an independent evaluation, but it does not replace one.

The person conducting the post-implementation review should have enough distance from the original project to question assumptions and identify gaps. A second perspective is particularly useful where the same team conducted the risk assessment, drafted the policies and managed implementation.

How should an AML/CTF program be maintained?

The ML/TF risk assessment and AML/CTF policies must be documented before the reporting entity provides a designated service. Updates to the program must also be documented promptly.

Good records should show:

  • what information the reporting entity considered;

  • how it assessed the identified risks;

  • why it selected particular controls;

  • who approved the assessment and policies;

  • what changed during each review; and

  • how findings and control gaps were addressed.

Version control is also important. The business should be able to identify which risk assessment and policies applied at a particular time, who approved them and when they took effect.

What should you do?

  • Map your designated services. Confirm which services are covered by the AML/CTF regime and identify the systems, teams and third parties involved in providing them.

  • Check that the risk assessment reflects the current business. Review the customers, services, technologies, delivery channels and countries involved today.

  • Connect each material risk to a control. A reader should be able to move from the risk assessment to the policies and see how each significant risk is managed.

  • Build AML/CTF checks into business change. Product approval, technology procurement, entry into new countries and changes to customer eligibility should trigger an AML/CTF assessment where relevant.

  • Test practice against policy. Review customer files, alerts, approvals, reports and training records to confirm that staff and systems follow the written program.

  • Assign clear ownership. Each material control should have an owner with the authority, information and resources needed to operate it.

  • Schedule a post-implementation review. Once there is evidence of how the controls operate, use a second set of eyes to check whether the written program matches day-to-day practice.

  • Plan the independent evaluation. Set an appropriate evaluation frequency and make sure the evaluator has the independence, skills and access needed to test the program properly.

  • Report clearly to the governing body. Reports should identify the main ML/TF risks, significant control gaps, overdue actions and emerging issues.

The bottom line

An AML/CTF program is a connected system. The reporting entity identifies its ML/TF risks, designs controls in response, follows those controls, tests whether they work and updates them when the business changes.

If the risk assessment does not drive the policies, or the policies do not match day-to-day operations, the program will not achieve its purpose.

Need help with AML/CTF?

Dwyer Harris assists reporting entities to develop, review, implement and update their AML/CTF programs.

We can help you:

  • identify the designated services your business provides;

  • prepare or review your ML/TF risk assessment;

  • draft AML/CTF policies that reflect your risks, systems and day-to-day operations;

  • review an existing program against current AML/CTF requirements;

  • conduct a post-implementation review to check whether the program is working as intended;

  • test selected controls and customer files;

  • identify and prioritise gaps between the written program and actual practice; and

  • update your program following a business change, regulatory development or review finding.

Our focus is on producing an AML/CTF program that meets the legal requirements, gives staff clear instructions and works within the practical constraints of your business.

Get in touch with Dwyer Harris if you need help drafting, reviewing, implementing or updating your AML/CTF program.

This article provides general information only and is not legal advice.

Previous
Previous

AML/CTF customer due diligence (CDD) explained

Next
Next

Unfair trading practices: a new focus of consumer protection law