You have spent months learning to check other people. Identify the customer, verify the beneficial owner, screen the name, rate the risk, keep the record.
There is a second obligation in the same part of the Act that points the other way, at the people inside your own office. It has had almost none of the attention, and it is not optional.
The obligation with your own name on it
You must conduct personnel due diligence to assess the people you employ or engage to perform AML/CTF roles.
(AUSTRAC, personnel due diligence, updated 13 April 2026, referring to Rules section 5-8(2) and Act section 26F(4)(d).)
AUSTRAC gives two reasons for it. The first is unremarkable: making sure only suitable people perform AML/CTF functions. The second is worth sitting with, because it is stated plainly and it is about you rather than your customers:
reducing the likelihood of internal fraud
The regime assumes that a business built to detect financial crime can also be used to commit it, by the people who run it. That is not an insult. It is the reason the obligation exists at all.
"Personnel" is wider than your payroll
The word does a lot of work here. It covers people you employ and also people you otherwise engage, and AUSTRAC lists the examples: contractors or consultants, volunteers or interns whether paid or unpaid, and people employed by service providers you use (AUSTRAC, identifying roles that require due diligence and training, updated 27 March 2026).
That last one catches more small practices than they expect. The offshore bookkeeping team, the contract paralegal, the virtual admin who opens the post and scans identity documents. If they touch a function relevant to your AML/CTF obligations, they are in scope.
As for who counts, the same page names four groups:
- people in AML/CTF governance roles, including your governing body, senior managers and your AML/CTF compliance officer
- anyone with responsibilities under your AML/CTF program
- anyone working in a role that could be exposed to ML/TF risk
- anyone else performing functions that support your obligations
Read the first bullet again. Your compliance officer is on the list. So is whoever approves the program. The person who runs your due diligence is themselves subject to due diligence, and if you are a sole practitioner wearing all three hats, you are assessing yourself and writing down that you did.
Two things to assess, and one of them is uncomfortable
You must assess the person's skills, knowledge and expertise relevant to their AML/CTF responsibilities, and separately their integrity.
The first is an ordinary hiring conversation with a compliance flavour. The second is not ordinary at all. It asks whether you would trust this person around a process specifically designed to notice crime, which is a question most firms have never put in writing about anyone.
Before, and then for as long as they stay
The timing is explicit: before you employ or engage the person, and on an ongoing basis during their employment or engagement.
So it is not an onboarding checkbox. Whatever you decide about a person on their first day has a shelf life, and your policies have to say what that shelf life is.
What AUSTRAC's own example firm actually does
AUSTRAC publishes a worked good-practice example built around a 25-person legal and financial services firm (AUSTRAC, examples of personnel due diligence and training in practice, updated 25 March 2026). Before employing or engaging anyone, that firm runs:
- reference checks
- a police check
- a check for government regulator or professional body disciplinary action
- verification of qualifications
- an assessment of AML/CTF knowledge during the interview
- self-disclosure of conflicts of interest or any other material information
For high-risk roles, meaning things like the roles that create or restructure bodies corporate and trusts, it runs a more comprehensive process again.
Look at that list honestly. Most established firms already do references and check qualifications. Two items are usually missing: the regulator and professional body disciplinary search, which takes minutes and which nobody thinks of, and the AML/CTF knowledge question in the interview, which costs nothing at all.
If you enrolled with AUSTRAC in July you may be further ahead than you think, because the enrolment form already asked you to gather police certificates for key personnel. That work is done. It is the writing down that usually is not.
The eight things your policies have to say
Your AML/CTF policies must ensure you conduct initial and ongoing personnel due diligence, and AUSTRAC expects them to set out how you:
- assess which roles need personnel due diligence
- make it appropriate to the risk associated with the role
- make it appropriate to the seniority of the role
- assess that an individual has the skills, knowledge and expertise for their AML/CTF functions
- conduct integrity checks, including background checks where appropriate
- schedule the frequency and triggers for periodic reassessment
- respond to adverse assessments
- document all assessments and decisions reasonably necessary to demonstrate compliance
Seven and eight are the two almost nobody has.
Everyone can picture ordering a police check. Very few firms have written down what happens when one comes back with something on it. Does the person still get the role? A different role? Who decides, and on what basis, and does that decision go anywhere a regulator could later read it? Deciding that in advance is the whole point, because deciding it in the moment, about someone you already like, is how it gets decided badly.
And eight is the one that turns all of this from a private judgement into evidence. Our piece on what AUSTRAC asks for in an examination covers what that file needs to look like.
Why this is harder in a four-person firm than a forty-person one
A 25-person firm can put a process between the partners and the decision. A four-person practice where everyone has known each other for fifteen years cannot, and the obligation lands as something close to an insult: run an integrity check on your business partner, then file the result.
The way through is to notice that the obligation attaches to the role, not to the person. You are not accusing anyone of anything. You are recording that the people doing your AML/CTF work are suitable to do it, which is precisely the statement you would want sitting in a file if something ever did go wrong and somebody asked how you chose them.
Doing it early, while nothing has happened, is also the only time it is a neutral act. Introducing personnel due diligence the week after something goes missing is a very different conversation.
The half of the obligation people did do
Personnel due diligence and training are the same clause of the Act, sections 26F(4)(d) and (e), covering the same people on the same timing. Same "before and ongoing", same requirement to tailor it to the person's role and risk.
Most firms have done the training half and not the due diligence half. That is not one obligation out of two. It is half of one, because AUSTRAC treats them as a pair: a well-trained person in a role they should never have been given is exactly the failure mode this is aimed at. Our guide to staff training requirements covers the other half, and what your compliance officer is actually responsible for covers the person most likely to be forgotten in both.
Where AML Mate fits, and where it does not
Part B of the program editor is where this policy gets written, with AUSTRAC's own guidance linked from the section so you are not drafting from memory. Training modules, completion records and certificates give you the evidence for the other half of the clause, and the registration tracker holds your key personnel with their police certificate dates from enrolment.
Being clear about the limit: we do not run background checks, police checks or disciplinary searches. Those you arrange yourself through the usual channels. What the platform holds is the policy, the training evidence, and the record of what you decided.
The short version
- The obligation covers anyone who performs an AML/CTF function, including contractors, interns, and staff of your service providers.
- Your compliance officer and your governing body are in scope. A sole practitioner assesses themselves and writes it down.
- Assess two things: skills and knowledge, and integrity.
- Before engagement, and on an ongoing basis afterwards, with triggers you set in advance.
- Write down what you will do about a bad result before you get one.
- If you did the training and not this, you did half of one clause.
Nobody is going to send you a reminder about this one. It has no date attached, no portal, and no form. It sits inside the program you have already written, waiting to be the question you cannot answer.
This article is general information, not legal advice. For advice specific to your circumstances, consult a qualified AML/CTF professional.
