New AML/CTF rules: what changed for programs
The new AML/CTF rules changed the program, not the letterhead. Part A and Part B are no longer the shape you write.
Quick answer
The new AML/CTF rules replaced the Part A and Part B habit with one program: an ML/TF risk assessment, and the policies that manage it. A senior manager approves it before designated services start. FreeAML does not write that program. The firm suite is A$0 and verification is client-pays.
A search for “new aml ctf rules” usually wants the delta, not the table of contents. The delta that changes a Tuesday is the program. AUSTRAC’s current shape is on your AML/CTF program overview. The instrument is the AML/CTF Rules 2025, Part 5 of which is the program machinery. Checked on 2 October 2026. This is general information, not legal advice. This page does not reproduce the overview or the Rules. Which document is the live instrument is AML/CTF rules 2025 and what firms use in 2026. Who is in the regime is /tranche-2.
What moved in the program
Practices that lived with the old rules still talk about Part A and Part B. AUSTRAC’s current overview is a single program. Write to that shape. The writing list on this site is what tranche 2 firms put in an AML/CTF program.
The program change in plain language. It is not the statutory text. Read the overview before you treat a row as complete.
| Old habit | What the program is now | What you still do |
|---|---|---|
| A Part A risk document and a separate Part B customer manual | One AML/CTF program: the risk assessment plus the policies | Keep them findable. Do not file two unlabeled folders and call it current |
| Money laundering and terrorism financing, said as if that were the whole assessment | An assessment of money laundering, terrorism financing, and proliferation financing risk. AUSTRAC calls these ML/TF risks | Assess the services you actually provide |
| A template saved the year it was downloaded | Documented before you provide a designated service, and approved by a senior manager | The approval is the firm’s. A kit is the starting point |
| Set and forget until an audit | Review when circumstances change, and run periodic independent evaluations | Diary the review. Record what you changed |
What the policies have to be able to do
Part 5 of the Rules is where the policy topics sit. In short, a program’s policies have to be capable of customer due diligence, targeted financial sanctions, personnel due diligence, training, reporting, the assessment of a potential suspicious matter, and the prevention of tipping off, plus the governance lines AUSTRAC describes. Read the overview for the wording. This article does not copy the rule text.
- Customer due diligence. The policies say when initial, delayed, and enhanced checks run. The requirement itself is customer due diligence requirements.
- Training. The policies have to provide initial and ongoing training for people whose work touches the obligations. A principal who is also the officer is the AML course for that dual role.
- Reporting and tipping off. The program names who decides a suspicious matter and what staff must not say to the client. The lodgement decision stays with the firm.
- Independent evaluation. AUSTRAC expects a periodic independent look at the program, not a self-grade on the day you wrote it. Confirm the interval on their page. This article does not restate it.
The officer line inside the new program
The new rules still require an AML/CTF compliance officer, and they still expect that officer to report to the governing body. AUSTRAC’s compliance officer page says that report is not required where the officer and the governing body are the same person, which is the usual micro-firm case. You do not invent a memo to yourself. You still keep the records. That role is the sole trader compliance officer.
The check is not the program change
Rewriting the program does not verify a customer. When the approved policies say a designated matter needs an identity or entity check, that is a separate step. On FreeAML the firm suite is A$0. The firm emails the client. Verification is client-pays. On the public list a personal KYC check is A$20 and a company or trust KYB check is A$40. Confirm the live amounts on FreeAML pricing. The path is /aml-check.
FreeAML does not approve the program, does not run the independent evaluation, and does not replace austrac.gov.au. If the file is out of scope, do not send a check to look as if the new rules have been “done”. The service test is Table 6 designated services.
📚 Related Resources
Free KYC Check →
Verify customer identity in 60 seconds. Government ID + AML screening.
Free AML Program →
Board-ready AML/CTF Program template. All 10 AUSTRAC sections included.
Risk Assessment Generator →
AI-powered ML/TF risk assessment. 20-page compliant report in 5 minutes.
Free AML Training →
Online courses for staff. CPD-certified certificates included.
AUSTRAC Reporting Tools →
File SMRs, TTRs, IFTIs directly to AUSTRAC. Pre-filled forms.
Frequently Asked Questions
The program is written. Send the check.
The firm suite is A$0. The client pays the identity or entity step by email, where the program requires it.
Start an AML checkQuestions: team@freeaml.com.au