Compliance11 min read

AUSTRAC Just Told Enrolled Firms What Comes Next. The Last Item Is the One With a Clock: Reviewing Your Program.

On 30 September 2026 AUSTRAC published a short piece for firms that have enrolled, and its last heading is the one most small firms have not planned for: your program is not a one-off task. Here are the events that force a review of your risk assessment and policies, how fast each one has to happen, who signs off, and the 14 day rule for writing it down.

2026-10-07· AML Mate Team
AUSTRAC Just Told Enrolled Firms What Comes Next. The Last Item Is the One With a Clock: Reviewing Your Program.

On 30 September 2026, the same day it announced its first infringement notices for businesses that never enrolled, AUSTRAC published a much quieter piece aimed at everyone else. It opens: "You've completed your enrolment. What's next?" and answers in the next line: "Enrolling with us is an important milestone, but it's only the beginning." (AUSTRAC, you've enrolled, what next? (opens in a new tab))

Most of the piece is a tour of things you have probably already done: build a program, understand your risks, read the guidance, look at the starter kits, train your staff. The last heading is different. It is called "Monitor and improve your program", and it starts with a sentence worth pinning above the desk of whoever wrote yours:

"Building your AML/CTF program isn't a one-off task."

That is friendly newsletter language for an obligation with rules attached. Fourteen weeks after 1 July, it is also the obligation most small firms have no plan for, because the program still feels new. This post is the plan.

What the Friendly Sentence Is Standing On

AUSTRAC's guidance on reviewing and updating your program sets a floor: you must review your risk assessment at least once every 3 years, and at a minimum you must review your entire risk assessment and all your AML/CTF policies at least once every 3 years. (AUSTRAC, review and update your AML/CTF program (opens in a new tab), updated 27 March 2026)

If that were the whole rule, you could set a reminder for 2029 and close this tab. It is not the whole rule. The same page lists events that force a review whenever they happen, and for a firm in its first year those matter far more than the three year backstop. We have said before that life after enrolment runs on triggers, not deadlines. Program review is the clearest example.

The Events That Force a Review

You must review your risk assessment if there is a significant change to any of these:

  • your designated services
  • how you deliver your designated services
  • your customer types
  • the countries you deal with
  • any new or emerging technologies related to your designated services or how you deliver them

You must also review it if AUSTRAC communicates information, to you or to your sector generally, that identifies or assesses risks associated with providing your designated services, or if an independent evaluation report has adverse findings about your risk assessment. (AUSTRAC, review and update your AML/CTF program (opens in a new tab))

"Significant" is doing real work in that list. AUSTRAC describes a significant change as a change to any of the factors in your risk assessment that could have a significant impact on your money laundering and terrorism financing risks. Its examples are ordinary business decisions:

  • offering a new designated service
  • expanding from in-person service to online
  • introducing a new technology to deliver a service
  • serving a new customer type, such as corporations when you previously only served individuals
  • providing a service that involves dealing with a new country

It also gives an example of what does not count: a website update that does not change the way you deliver your services. You are not expected to reopen the risk assessment every time something moves. You are expected to notice when the thing that moved is one of the inputs.

Each Trigger Has Its Own Timing

This is the part firms get backwards. The timing depends on who caused the change. (AUSTRAC, review and update your AML/CTF program (opens in a new tab))

What happenedWhen you reviewWhen you update
A significant change within your controlBefore the change occursBefore the change occurs
A significant change outside your controlAs soon as practicable after it occursAs soon as practicable after the review
AUSTRAC communicates risk information about your servicesAs soon as practicable after it communicatesAs soon as practicable after the review
Your governing body receives an independent evaluation report with adverse findingsAs soon as practicable after it receives the reportAs soon as practicable after the review

Read the first row twice. If you decide to start doing something new, the review comes first. AUSTRAC's own worked example is a business that plans to add online delivery to an in-person service: because the change is within its control, it must review and update the risk assessment before making the change. In that example the review turns up a new identity fraud risk, the compliance officer seeks a senior manager's approval for the updated assessment, and the policies are then reviewed to match.

For a small practice, that row covers more than it first appears to. The accountant who starts forming companies for clients. The conveyancer who moves to fully remote onboarding. The agency that takes its first overseas buyer. Each is a business decision made in a partners' meeting or over coffee, and each is a review trigger that fires before the first client, not after.

Changes outside your control include a change in the risk of a country you deal with, for example one affected by targeted financial sanctions. You cannot review those in advance, so the standard is "as soon as practicable".

Your Inbox Is a Trigger

The third row is the one almost nobody has a process for. When AUSTRAC communicates information that identifies or assesses risks tied to your designated services, you must review your risk assessment as soon as practicable. AUSTRAC says it will typically make you aware through its newsletters, adding "we expect you to subscribe for updates", or through direct communication with you. (AUSTRAC, review and update your AML/CTF program (opens in a new tab))

"As soon as practicable" is less alarming than it sounds. In AUSTRAC's example, it publishes a new financial crime guide for a sector and emails the affected businesses. The information is general rather than an imminent threat, so the compliance officer schedules the review for the following week, updates the risk assessment to reflect it, and records that they considered the communication.

That last step is the habit to copy. Not every item in an AUSTRAC newsletter identifies a risk in your services, and deciding whether one does is a judgement. A two line note with a date, saying what you read and whether it changed anything, is what turns that judgement into evidence.

AUSTRAC's starter kit for accountants describes the same trigger and says what the communications include: national risk assessments, indicators of suspicious activity and direct communications from AUSTRAC. It also lists an internal incident or control failure as a review trigger in the kit's own program. (AUSTRAC, maintain and review your accounting program (opens in a new tab), updated 2 April 2026) If your program started life as a starter kit, that list is already in the document you adopted. It is worth checking you know where.

Two practical consequences. First, make sure the right person is actually receiving AUSTRAC's updates. In its top 5 tips for good compliance (opens in a new tab), also published on 30 September, AUSTRAC points out that if your compliance officer leaves and their contact details are not updated, important updates and reminders may go to the wrong person. Second, changed enrolment details have their own 14 day rule, which is a separate obligation from the one below.

Three Rules for the Paperwork

Reviewing is half of it. If the review finds an issue, such as a new or changed risk, you must update the risk assessment, and three rules follow. (AUSTRAC, review and update your AML/CTF program (opens in a new tab))

A senior manager must approve the update. You must also notify your governing body in writing as soon as practicable after making it. In a small firm those roles often sit with one or two people, and AUSTRAC has specific guidance on how sole traders and micro businesses (opens in a new tab) handle senior manager obligations. We unpacked who signs what in a small firm in August.

The policies follow the risk assessment. You must review and, if required, update your AML/CTF policies following a review of your risk assessment. AUSTRAC expects you to prioritise the policies dealing with the new or changed risks before the rest, and then to communicate and implement the updates across the business. For staff whose work changes, that is what ongoing training is for: AUSTRAC requires training that continues during a person's employment, not just at the start. (AUSTRAC, AML/CTF training (opens in a new tab), updated 27 March 2026)

You have 14 days to write it down. You must document updates to your risk assessment, and updates to your policies, in your AML/CTF program within 14 days after making the update. AUSTRAC spells out what that means: record the updates in writing, along with the dates the changes were made.

AUSTRAC notes that you may face civil penalties if you do not review and update your risk assessment as required. The more likely day to day cost is quieter. A program dated June 2026 that describes a business you no longer quite are is an easy thing for an examiner, or your independent evaluator, to notice.

Who Does the Review

Not a consultant, unless you want one. The person who conducts your review is not required to have specific qualifications. Your policies must make sure that the person or team has sufficient knowledge of your AML/CTF obligations and your risks, and AUSTRAC names the compliance officer as an example. (AUSTRAC, review and update your AML/CTF program (opens in a new tab))

The scope depends on what triggered it. A review may cover everything or focus on specific areas, so a new service does not mean rewriting the whole program. This is also separate from the independent evaluation, which has its own rules and its own schedule.

A Twenty Minute Version for This Week

AUSTRAC's other 30 September piece opens with the line "The most effective compliance programs are built on simple habits done well." Here is the habit, sized for a firm with no compliance department:

  1. Open your risk assessment and read the description of your business. Services, delivery channels, customer types, countries. Is each still true today?
  2. List what has changed since 1 July. A new service line, a new way of onboarding, a new kind of client, a new country. For each, decide whether it could significantly affect your risk and write the answer down either way.
  3. Check who receives AUSTRAC's emails, and that the firm is subscribed to its updates.
  4. Add one standing question to partner or team meetings: "Is anything we are about to start doing a change to our services, delivery, customers or countries?" That question is how you catch the first row of the table before the change, when the rule says the review is due.
  5. If you update anything, get the senior manager approval, tell the governing body in writing, and date the entry in the program within 14 days.

If nothing has changed, the note saying so, with a date, is still worth having. It shows the question was asked.

Where AML Mate Fits

AML Mate builds your AML/CTF Program in Parts A to F from templates for your industry, and keeps it editable, with export to PDF and Word, so a review ends in an updated document rather than a note stapled to an old one. The audit-ready export pack puts the program, client register, training records and audit log in one file for whoever asks to see how the program has been run. If you want a quick read on where you stand before you start, the free compliance check scores your readiness across the six core obligations, no signup needed.

AUSTRAC spent the first three months of this regime getting firms onto the Roll. Its message to the firms now on it is that the document they wrote in June is meant to keep moving. The rule underneath that message is simple enough to remember: when the business changes, the program changes first.


This article is general information, not legal advice. For advice specific to your circumstances, consult a qualified AML/CTF professional.

austracprogram-reviewrisk-assessmentaml-ctf-programtranche-2accountantslegalreal-estateconveyancersjewellers

Ready to build your AML/CTF program?

AML Mate generates your AML/CTF program in 15 minutes using AUSTRAC's official templates. Start a 14-day free trial, cancel anytime.

This article is based on AUSTRAC's publicly available guidance. It does not constitute legal or compliance advice. Consult a licensed compliance professional for complex situations.