Australia’s AML/CTF reforms have reshaped the compliance landscape for small and medium businesses. Since 31 March 2026, existing reporting entities operate under a reformed Anti-Money Laundering and Counter-Terrorism Financing Act. From 1 July 2026, approximately 90,000 new Tranche 2 entities joined the regulatory fold. One obligation stands out as both misunderstood and underestimated: the independent AML audit in Australia. Although many businesses still refer to it as an “independent AML audit,” AUSTRAC now uses the term “independent evaluation” under the reformed AML/CTF framework.
For many SMEs, the prospect of an independent evaluation raises immediate questions. Who can conduct it? How often is it required? What does it actually cover? This guide answers those questions in practical terms. It walks you through what AUSTRAC expects, what the reformed rules changed and how smaller businesses can approach the evaluation without overspending or underdelivering.
| Compliance area | Key requirement | Why it matters |
|---|---|---|
| Independent evaluation | Must assess the entire AML/CTF program | Replaces the old Part A-only review under pre-reform rules |
| Frequency | Determined by risk profile; maximum interval under the Rules is three years | SMEs must formally document the rationale for their chosen review cycle |
| Evaluator independence | Reviewer must not have developed or maintained the program | Internal staff can qualify if they meet this independence standard |
| Scope under reformed rules | Covers risk assessment, CDD, screening, monitoring, reporting, training and record-keeping | Evaluation now extends to proliferation financing risks |
| Tranche 2 deadlines | First evaluation due between 30 June 2029 and 31 December 2030 (staggered) | Deadline depends on the last two digits of your AUSTRAC account number |
What is an independent AML audit and why does AUSTRAC require one?
An independent AML audit is a structured, independent assessment of your AML/CTF program. AUSTRAC uses the term “independent evaluation” under the reformed Anti-Money Laundering and Counter-Terrorism Financing Rules 2025. The purpose is straightforward: to verify that your program identifies money laundering and terrorism financing risks accurately and that your controls work in practice.
This evaluation goes beyond an internal compliance check. Your compliance officer or team can review procedures as part of daily operations. That is expected and encouraged. However, the independent evaluation must be conducted by someone who had no role in building, implementing or maintaining the program. The evaluator can be an internal auditor (provided they meet the independence test) or an external specialist such as an AML consultant, lawyer or accountant.
AUSTRAC does not prescribe specific qualifications for the evaluator. The regulator does expect the person to have competence in AML/CTF obligations relevant to your business. An evaluator should possess sufficient AML/CTF expertise relevant to the entity’s business and obligations.
Before 31 March 2026, the independent review applied only to Part A of an entity’s AML/CTF program. The reformed rules removed the Part A and Part B structure entirely. As a result, the independent evaluation now covers the full program. For SMEs that previously treated the Part B customer identification component as outside the review scope, this is a meaningful shift that expands the evaluation’s reach.
What changed under the 2026 reforms
| Area | Before 31 March 2026 | After 31 March 2026 |
|---|---|---|
| Scope of review | Part A of AML/CTF program only | Entire AML/CTF program |
| Terminology | Independent review | Independent evaluation |
| Risk coverage | ML/TF risks | ML/TF and proliferation financing risks |
| Program structure | Mandatory Part A and Part B | Flexible, outcomes-focused structure |
| Compliance officer | Recommended | Mandatory “fit and proper” appointment |
Who needs an independent AML audit in Australia?
In short, reporting entities required to maintain an AML/CTF program are generally required to undertake an independent evaluation. A sole-trader faces the same core obligation as a major regulated entity, although transitional provisions and risk-based timing apply. A sole-trader remittance provider faces the same legal obligation as a major bank, although the scope and depth of the evaluation will differ based on risk profile.
For example, existing reporting entities include banks, credit unions, remittance service providers, digital currency exchanges, gambling operators, insurance companies, securities dealers and bullion dealers. These entities have been subject to AUSTRAC oversight for years and should already have a history of independent reviews.
Tranche 2: newly regulated businesses from July 2026
The bigger story in 2026 is Tranche 2. From 1 July 2026, AML/CTF obligations extend to designated non-financial businesses and professions (DNFBPs). This includes lawyers (for specific transaction types), accountants and tax agents, real estate professionals, dealers in precious metals and stones and trust and company service providers.
AUSTRAC has acknowledged that many of these businesses are small practices with limited compliance infrastructure. The regulator has published starter programs to help new entrants meet their obligations. Despite this support, the obligation to eventually undergo an independent evaluation generally applies to all Tranche 2 reporting entities required to maintain an AML/CTF program.
Australia’s ongoing FATF mutual evaluation adds further urgency. FATF has historically criticised Australia for not regulating these gatekeeper professions. As a result, AUSTRAC will face pressure to demonstrate that the new regime is producing real outcomes, not just paperwork.
What the evaluation must cover under the reformed rules
The AML/CTF Rules 2025 set out three core requirements for an independent evaluation. The evaluator must assess how you conducted or reviewed your ML/TF risk assessment against the requirements of the Act, regulations and Rules. They must evaluate the design of your AML/CTF policies. They must also test whether you have appropriately identified, assessed, mitigated and managed your money laundering, terrorism financing and proliferation financing risks in practice.
In other words, this translates into six areas that the evaluator will examine.
Risk assessment and governance. Does your ML/TF risk assessment reflect your current business model, customer base, products, delivery channels and geographic exposure? Have you appointed a fit and proper AML/CTF compliance officer and notified AUSTRAC within the transitional deadlines?
Customer due diligence. Are your identification and verification procedures meeting regulatory requirements? Are you applying simplified or enhanced due diligence where the risk profile demands it?
Transaction monitoring and reporting. Are your monitoring systems detecting suspicious activity effectively? Are suspicious matter reports (SMRs) and threshold transaction reports (TTRs) being submitted accurately and on time?
Record-keeping. Are you retaining all required documentation for at least seven years, including CDD records, transaction histories and staff training logs?
Staff training. Have you delivered role-appropriate AML/CTF training, documented completion and refreshed content as obligations evolve?
Proliferation financing. The 2026 reforms now require entities to assess and mitigate proliferation financing risks (the risk that funds or services may contribute to the spread of weapons of mass destruction) alongside ML/TF risks. As a result, this is a new area that many SMEs have not yet addressed in their programs.
Under Rule 5-15(2) of the AML/CTF Rules 2025, any updates or changes you make to your AML/CTF policies or procedures in response to adverse evaluation findings must be documented in writing within 14 days of making the change. Under Rule 5-10(2), the final independent evaluation report must be provided to both senior management and the governing body (for example, the board of directors).
How often should your business schedule an independent AML audit?
AUSTRAC does not set a fixed interval for all reporting entities. The frequency of your independent evaluation depends on the nature, size and complexity of your business and its ML/TF risk profile. The Rules set a maximum interval that effectively requires an evaluation at least every three years, but the actual frequency should be driven by risk.
Your AML/CTF policies must document the frequency you have chosen and the rationale behind that decision. Simply stating “every three years” without explanation is unlikely to satisfy AUSTRAC if the regulator reviews your program.
Consequently, higher-risk entities should schedule evaluations more frequently. A remittance provider operating in high-risk corridors or a digital currency exchange handling significant transaction volumes may need annual or two-yearly reviews. On the other hand, a small accounting firm providing limited designated services in a low-risk environment may reasonably justify a three-year cycle.
When to schedule outside the regular cycle
Certain events should trigger an evaluation regardless of where you sit in your standard cycle. These include material changes to your business model, significant expansion of products or services, entry into new geographic markets, changes in your customer risk profile and systemic issues identified through internal monitoring.
For newly regulated Tranche 2 entities, the transitional rules provide additional flexibility. The first independent evaluation is not required before three years from the 1 July 2026 start date. AUSTRAC has staggered the deadlines based on the last two digits of each entity’s AUSTRAC account number. Entities with both digits odd must complete their first evaluation by 30 June 2029. Those with the second-last digit odd and last digit even have until 31 December 2029. Entities with both digits even face a 30 June 2030 deadline, while those with the second-last digit even and last digit odd have until 31 December 2030.
This staggered approach prevents the entire Tranche 2 cohort from competing for evaluators at the same time.
Existing reporting entities that completed a Part A independent review under pre-reform rules have until the later of four years from their last review or 31 March 2027 to complete their first post-reform independent evaluation. Do not assume the Tranche 2 timeline applies to your business if you were already enrolled with AUSTRAC before 1 July 2026.
Common audit findings that catch small businesses off guard
AUSTRAC’s enforcement history reveals consistent patterns. The same deficiencies appear repeatedly in independent evaluations and compliance assessments. Smaller businesses are not immune to these findings.
Risk assessments and due diligence gaps
Outdated risk assessments are the most frequent issue. In many cases, SMEs completed a risk assessment when they first enrolled with AUSTRAC and have not revisited it since. A risk assessment written three or four years ago will not reflect your current products, customer mix or delivery channels. Under the reformed law, material changes should trigger a review and update of the risk assessment to ensure it remains current and effective.
Similarly, weak customer due diligence documentation follows closely behind. AUSTRAC’s enforcement record shows how quickly compliance gaps attract regulatory attention. Castra Licensee received a $50,000 Federal Court penalty in May 2026 for failing to lodge annual compliance reports. Separately, AUSTRAC ordered an external audit of payment platform Airwallex in January 2026 over suspected AML/CTF compliance failures. CDD gaps remain a consistent theme across enforcement actions. The gaps tend to be practical rather than procedural: staff know the policy exists but do not follow it consistently across every customer interaction.
Training records and program updates
Incomplete training records are another recurring finding. Records that show training was assigned but never completed, or that lack evidence of comprehension, raise red flags for both evaluators and AUSTRAC. The reformed rules expect role-specific training rather than generic awareness sessions.
Failure to update the AML/CTF program itself is also common. The shift from the old Part A and Part B structure to the reformed, outcomes-focused model requires every existing reporting entity to review and revise its program documentation. Entities still operating from pre-2024 procedures carry a material compliance gap that an evaluator will flag immediately.
Finally, some small businesses treat the evaluation as a formality. They engage the cheapest available reviewer and expect a clean report without genuine testing. A deficient evaluation does not relieve a reporting entity of its statutory AML/CTF obligations and may prompt questions about both the entity’s governance and the evaluator’s competence.
How to prepare for an independent AML audit in Australia
Preparation determines whether the evaluation produces genuine insights or creates unnecessary stress. The following steps will help SMEs approach their independent evaluation with confidence.
First, start with your risk assessment. Confirm that it reflects your current business model, including any changes in products, customer types, delivery channels or geographic activity since the last review. If you have not updated it since the 2026 reforms took effect, do so before engaging an evaluator.
Review your AML/CTF program documentation. Confirm that your policies align with the AML/CTF Rules 2025 and that you have moved away from the old Part A and Part B structure. Your program should clearly address all six evaluation areas: risk assessment, governance, CDD, monitoring, reporting and record-keeping.
Verify appointments and documentation
Check your compliance officer appointment. Existing reporting entities were required to notify AUSTRAC of their AML/CTF compliance officer by 30 May 2026. Tranche 2 entities had until 29 July 2026. Confirm that this notification has been completed and that the appointed officer meets the “fit and proper” standard.
In addition, gather your CDD records and test a sample internally before the evaluator arrives. Look for gaps in customer identification, missing verification documents and cases where enhanced due diligence should have been applied but was not.
Verify that your staff training records are complete. Each employee should have documented evidence of training received, the date of completion and a record of comprehension. Update training content to reflect the reformed obligations.
Furthermore, pull together any findings from prior reviews and confirm that corrective actions have been completed. Unresolved findings from a previous evaluation will be among the first things a new evaluator check.
Choose your evaluator carefully. The cheapest option is rarely the best value. Look for someone with demonstrated AML/CTF expertise relevant to your sector. A credible evaluator produces a report that withstands regulatory scrutiny, not one that simply confirms what you want to hear.
Frequently Asked Questions (FAQ)
Is an independent AML audit mandatory for small businesses in Australia?
Yes. Reporting entities required to maintain an AML/CTF program must undergo an independent evaluation, regardless of size. AUSTRAC applies the proportionality principle, so the scope and depth will match the complexity and risk profile of your business.
Can our compliance officer conduct the independent evaluation?
In most cases, no. The evaluator must not have been involved in developing, implementing or maintaining the AML/CTF program. Your compliance officer typically manages the program, so they cannot also assess it independently. For most SMEs, an external AML/CTF consultant is the most practical choice.
How much does an independent AML audit cost for an SME?
Costs vary based on business size, number of designated services, transaction volumes and the current state of your program documentation. A straightforward evaluation for a small single-service entity will cost significantly less than one for a multi-service provider with complex operations.
Take the next step
The independent AML audit is one of the most practical tools available to Australian SMEs navigating the reformed AML/CTF landscape. Conducted properly, it identifies gaps before AUSTRAC does. It gives your board or senior management independent assurance that your program works in practice. It also signals to the regulator that your business takes its obligations seriously.
Whether you are an existing reporting entity adjusting to the reformed rules or a newly regulated Tranche 2 business building a program from scratch with professional AML compliance support, the evaluation is not something to defer until the deadline approaches. Early preparation reduces cost, improves the quality of findings and gives you time to fix gaps without regulatory pressure. Businesses that plan their first evaluation well ahead of the deadline typically spend less time and money fixing gaps after the fact.
Compliance7 provides independent AML audit and evaluation services for reporting entities across Australia, the UAE, India and other jurisdictions. Our CAMS-certified team has more than 12 years of experience helping businesses build defensible compliance programs. If you need guidance on your evaluation obligations or want to schedule an independent review, book a free consultation with our team.
This article is for informational purposes only and does not constitute legal or regulatory advice. For guidance specific to your business, consult a qualified compliance professional.



