When you enrolled with AUSTRAC, the form asked for the name of your AML/CTF compliance officer. One field, one name, done. It felt like nominating a contact person.
It was actually one third of a governance structure. The Act sets up three distinct roles: a governing body that oversees, a senior manager who approves, and a compliance officer who runs the day to day (AUSTRAC, governance for sole traders and micro businesses). In a firm of one to ten people these are hats, not hires, and most or all of them sit on the same head. AUSTRAC's guidance even says, in as many words, that a person acting in all three roles does not need to report to themselves.
What wearing all the hats does not do is merge the duties. Each role owes different things, a few of them cannot be delegated, and AUSTRAC expects your records to show that each one actually happened. Here is the practical version.
Who is who in a firm your size
The governing body is the person or group primarily responsible for the governance and executive decisions of the business. In a listed company that is the board. In your firm it is the business owner, or the partners collectively (AUSTRAC, governing body).
A senior manager is an individual who makes, or is involved in making, decisions affecting all or a substantial part of the business. AUSTRAC is explicit that this is about authority, not title: nobody needs to be a C-suite executive, and in a smaller business it is typically the owner, a director, or whoever manages broader risks and operations (AUSTRAC, senior manager).
The AML/CTF compliance officer must be employed or engaged at management level, a resident of Australia if you provide designated services through a permanent establishment here, and a fit and proper person. They do not need to be an AML expert, and management level refers to authority in the business: a person can qualify with zero direct reports (AUSTRAC, AML/CTF compliance officer). If you are only starting designated services now, you must appoint one within 28 days and notify AUSTRAC within 14 days of the appointment. The same page covers the other direction: if your compliance officer leaves or becomes ineligible, you appoint a replacement and tell AUSTRAC.
In a two partner practice the mapping usually looks like this: the partnership is the governing body, both partners are senior managers, and one partner is the compliance officer. A sole practitioner is all three at once. Both arrangements are fine. What changes is not whether the duties exist but who they flow between.
The signatures that cannot be delegated
The senior manager role is the odd one out. The governing body and compliance officer mostly oversee. The senior manager personally does. AUSTRAC's wording: a senior manager must fulfil these obligations personally, they can't delegate them (AUSTRAC, senior manager).
The list is short and worth pinning up:
- Your risk assessment, your AML/CTF policies, and every update to either. A program without a senior manager's approval on it is not finished, and a risk assessment nobody consciously decided on is not an assessment at all.
- Starting to act for certain PEPs. A customer you have established is a foreign PEP, or a high-risk customer who is a domestic or international organisation PEP, needs senior manager approval before the designated service starts. If an existing client or their beneficial owner becomes one mid-relationship, approval is needed before you continue. What to do when a screening match comes back is its own topic; the governance point is that the decision to proceed is a named person's signature, not a team consensus.
- Third party CDD arrangements. Any written agreement under which someone else collects and verifies CDD information for you needs senior manager approval before you enter it.
AUSTRAC suggests handling the program approvals through version control: approval date, approver, version number, next review date, recorded in the document itself. That one habit turns "did anyone sign this off" from an awkward question into a line you can point at.
The meeting you owe yourself once a year
The compliance officer must report to the governing body at least once every 12 months, covering three things: whether the business is complying with its AML/CTF policies, whether those policies are actually managing and mitigating the risks it faces, and whether it is complying with the Act and Rules. The report, or a record of it, must be in writing (AUSTRAC, AML/CTF compliance officer).
If your obligations went live on 1 July 2026, that clock is already running, and the cheapest time to book the meeting is now. At small firm scale this is not a board pack. It is a standing item at a partner meeting and a one page minute. AUSTRAC's program starter kits even ship a fill-in "Annual report to the governing body" form so you do not have to invent the format (AUSTRAC, accounting starter kit document library).
Two clarifications that save people from wrong turns. First, this internal report is not the annual compliance report you lodge with AUSTRAC. Same word, different documents, different audiences. Second, the "no reporting to yourself" relief is narrow: it applies when the business is an individual and the same person holds both the governing body and compliance officer roles (AUSTRAC, governance for sole traders and micro businesses). A two partner firm does not qualify. The partner wearing the compliance officer hat reports to the partners, minuted, once a year.
The governing body must also receive written notification of any update to the risk assessment as soon as practicable after it is made (AUSTRAC, governing body). In a small firm that can be as simple as an email to your co-owner with the new version attached. The point is that it exists in writing.
What oversight looks like at partner meeting scale
AUSTRAC publishes two lists for governing bodies: behaviours that look like appropriate oversight and behaviours that look like its absence (AUSTRAC, governing body). The good list is unglamorous: AML/CTF as a regular standing agenda item, minutes showing you engaged with it, questioning what is in the compliance officer's report, asking for the root cause when something was non-compliant, monitoring whether fixes actually landed. The bad list is the mirror image: reports nobody reads, no agenda item, no questions ever asked.
Notice what is not on either list: sophistication. AUSTRAC is not asking a three person conveyancing practice for a risk committee. It is asking whether the person in charge engaged with the thing or rubber stamped it. Twenty minutes on the agenda once a quarter, with one line of minutes, clears the bar that matters.
The records that prove each hat did its job
You must keep records showing how these roles have been met, and AUSTRAC spells out what it expects them to show (AUSTRAC, senior manager):
- Appointments: who holds each role, from when, and why they qualify. For a senior manager, which parts of their actual job let them make decisions affecting the business. For the compliance officer, how they meet the eligibility requirements and what you considered, with open-source searches, reference checks and police checks given as examples.
- Escalations: which customers went to a senior manager and why, who made the call, on what date, and the reason for the decision.
- Fit and proper: the considerations are exactly that, considerations, not a pass or fail quiz. Document what you weighed, including conflicts of interest, and expect to reassess periodically. The checks you run on the people holding these hats sit alongside personnel due diligence for everyone else in AML/CTF roles.
A thirty minute check for this week
- Write down the three role holders, even if the answer is your own name three times, with one sentence each on why they qualify.
- Open your risk assessment and policies. Do they carry a version number, an approver and an approval date? If not, the next senior manager job is signing what you already have.
- Put the annual report to the governing body in the calendar, dated before your obligations turn one year old.
- Create the escalations file, even if it is empty. When the first foreign PEP match arrives, the record of the decision needs somewhere to live.
- If anyone has joined or left since enrolment, check the compliance officer named in AUSTRAC Online is still the right person. If it is not, the appointment and notification clocks are already running.
If your program lives in AML Mate, the program editor stamps versions and approval dates as you go, and the audit export shows the oversight trail in one place. But nothing above requires software. It requires half an hour and the willingness to write down who decided what.
The reform did not just give your firm obligations. It gave three specific jobs to specific people, and in a small firm those people are mostly you. Running the program day to day is the routine; governance is the part that proves someone is steering. And when AUSTRAC ran its first proactive supervision campaigns under the reformed Act, reviewing governance was on the list before any breach was alleged. The steering gets checked.
This article is general information, not legal advice. For advice specific to your circumstances, consult a qualified AML/CTF professional.
