Regulation and standard

What AML/CTF training does AUSTRAC require?

Short answer

The Australian Transaction Reports and Analysis Centre (AUSTRAC) requires reporting entities' AML/CTF policies to provide initial training on engagement and ongoing training after that. Under the reformed Anti-Money Laundering and Counter-Terrorism Financing Act 2006 and the 2025 Rules, training must suit each person's function, money laundering and terrorism financing risks, and responsibilities, and must be readily understandable. The reforms applied to existing entities from March 31, 2026 and to newly regulated professions from July 1, 2026.

By the Knowledge Foundry editorial team. How we write and check these pages

Published
Updated
Reading time
9 min
Jurisdiction
Australia (Commonwealth)
Regulator
Australian Transaction Reports and Analysis Centre (AUSTRAC)

Key takeaways

  • Training is a mandatory element of AML/CTF policies under section 26F(4)(e) of the reformed Act, with detail in section 5-9 of the AML/CTF Rules 2025.
  • Existing reporting entities moved to the reformed obligations on March 31, 2026, unless a transitional rule deferred a specific obligation. Lawyers, accountants, real estate professionals, conveyancers, trust and company service providers and dealers in precious stones and metals are regulated from July 1, 2026.
  • Training must be tailored to the person's function, the ML/TF risks of that function, and their responsibilities, and delivered so the person can readily understand it.
  • AUSTRAC expects a training plan, a completion register, effectiveness monitoring and knowledge checks, and says its own e-learning cannot be relied on alone.
  • Personnel due diligence (skills, knowledge, expertise and integrity) sits beside training and must be done before engagement and on an ongoing basis.

What does the law require for AML/CTF training?

The reformed Act requires a reporting entity's AML/CTF policies to deal with providing training to the people it employs or engages, and the Rules set the minimum content of that obligation. AUSTRAC's AML/CTF training guidance ties the obligation to section 26F(4)(e) of the Act and section 5-9 of the Rules.

Section 5-9 of the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 contains two operative requirements. Subsection (2) says the policies "must deal with both initial training upon a person's employment or engagement and ongoing training during a person's employment or engagement". Subsection (3) requires that the training provided to a person is appropriate having regard to the particular function they perform, the particular risks of money laundering, financing of terrorism and proliferation financing relevant to that function, and their particular responsibilities under the AML/CTF policies, and that it "is readily understandable by the person".

AUSTRAC states the purpose plainly: training must make sure personnel understand the entity's obligations under the Act, Rules and regulations, and its ML/TF risks. The standard is therefore not a course completion target. It is whether each person can apply the entity's policies in their role, which is the difference described in completion tracking vs competency verification.

Currency

This page reflects the law and AUSTRAC guidance as at September 2026. AUSTRAC's training guidance was last updated on March 27, 2026. Check the primary sources before relying on any date or section number.

When did the AML/CTF reforms commence?

The reforms commenced in stages: March 31, 2026 for businesses already regulated, and July 1, 2026 for newly regulated professions. Parliament passed the AML/CTF Amendment Bill on November 29, 2024, and the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 amended the 2006 Act.

Key reform and transition dates relevant to training programs (source: AUSTRAC and the Transitional Rules 2026)
DateWhat happenedRelevance to training
March 31, 2025Revised tipping off offense commencedCustomer facing and investigations staff need current guidance on what may and may not be disclosed
March 31, 2026Reformed program and due diligence obligations started for existing reporting entities, unless deferred under the transitional rules; new ongoing customer due diligence obligations apply to all customersTraining content must reflect the new AML/CTF policies, ongoing CDD and the new governance roles
May 30, 2026Deadline for existing entities to notify AUSTRAC of their AML/CTF compliance officerThe compliance officer role needs deep, role specific training
July 1, 2026Newly regulated businesses must comply; existing entities using the ACIP transition must have transitional policies in placeTranche 2 businesses need initial training for every person performing AML/CTF functions
March 31, 2027 (earliest)First independent evaluation for existing entities is due by the later of this date or four years after their last independent reviewEvaluations test whether policies, including training, are designed and operating as required
March 31, 2029End of the transitional period for applying ACIP instead of the new initial CDD frameworkOnboarding staff may need training on two approaches until each customer class transitions

AUSTRAC's reform overview lists the newly regulated sectors as real estate professionals, dealers in precious stones, metals and products, lawyers, conveyancers, accountants, trust and company service providers, and businesses providing certain virtual asset services. The transitional rules guidance explains which obligations were deferred and for whom.

What changed from the pre-reform training requirement?

The main change is a shift from a generic risk awareness program to training tailored to each person's function, risks and responsibilities. Under the pre-reform Rules, Part A of an AML/CTF program had to include an "AML/CTF risk awareness training program" giving employees appropriate training at appropriate intervals, having regard to the ML/TF risk the entity may reasonably face (Part 8.2 of the pre-reform Rules).

  • Scope of people: the obligation now covers persons employed or otherwise engaged, which AUSTRAC reads as anyone employed or engaged to perform AML/CTF functions, including contractors.
  • Tailoring: training must be appropriate to the person's particular function, risks and responsibilities, not only to the entity's overall risk.
  • Comprehension: training must be readily understandable by the person, which AUSTRAC links to comprehension and language skills.
  • Governance roles: the governing body, senior manager and AML/CTF compliance officer each have defined responsibilities, and AUSTRAC expects each to understand the obligations attached to their role.
  • Evaluation: independent evaluations of the whole program replace independent reviews of Part A, so training design and operation are in scope.

Who needs AML/CTF training, and how often?

Anyone who performs functions relevant to the entity's AML/CTF obligations needs initial training at the start of their engagement and ongoing training after that. AUSTRAC says the frequency and extent of ongoing training depend on the functions a person performs and the ML/TF risks involved, and that training should also be given before a person takes on new duties that expose them to other risks.

AUSTRAC gives example frequencies, which it describes as examples only: compliance officers and senior management every 6 to 12 months, customer facing personnel every 12 months, personnel in onboarding, transaction monitoring or enhanced CDD roles every 12 months, third party vendors at onboarding and when a contract is renewed or changed, and general awareness at onboarding for other staff. It also expects training to be updated as soon as practicable after changes to law, new risks, program changes, evaluation findings, significant breaches or new AUSTRAC guidance. The guide on mandatory training refresh cycles explains how to set and justify intervals.

How do AML/CTF obligations map to training and evidence?

The most defensible approach maps each role's AML/CTF obligations to a learning outcome and a specific piece of assessment evidence. The table below is an original, illustrative mapping built from the role examples in AUSTRAC's guidance. It is a starting point, not a template AUSTRAC has endorsed.

Illustrative mapping of AML/CTF roles to learning outcomes and evidence
Role or functionLearning outcomeAssessment evidence
Customer onboardingApplies the entity's identity verification, beneficial ownership, sanctions and PEP checks correctlyScenario assessment on sample customer files, supervisor sign off on first live cases
Any customer or transaction facing roleRecognizes indicators of suspicious activity and follows escalation procedures and timelinesRed flag identification quiz with a pass mark, audit of escalations raised
Cash handlingExplains threshold transactions and structuring, and who reports TTRs and whenKnowledge check plus observed handling of a threshold scenario
Enhanced CDD and investigationsTailors enhanced measures to customer risk and assesses source of funds and wealthCase review of completed enhanced CDD files against the policy
AML/CTF compliance officer, senior manager, governing bodyExplains the obligations of their governance role, the ML/TF risk assessment and the AML/CTF policiesBoard or committee minutes showing briefing content, attendance and questions raised
Record keepingKeeps accurate, complete records including decisions madeSample file review for completeness

AUSTRAC says entities must keep records reasonably necessary to demonstrate compliance with training obligations (it refers to section 116 of the Act). Its examples include who completed training, the topics and content version delivered, how understanding was assessed and the results, and each person's training history. The guide to preparing training records for an audit covers how to structure that register.

What does AUSTRAC expect on effectiveness and outsourced training?

AUSTRAC expects entities to monitor whether training is completed, understood and applied, and it keeps the entity responsible for training even when delivery is outsourced. Suggested monitoring tools include post-training assessments, incident reviews that look for missed red flags or late suspicious matter reports, staff feedback, performance reviews, and compliance reporting to the governing body.

When monitoring reveals a gap, AUSTRAC expects targeted or remedial training, documentation of the action taken, reassessment, and escalation, which may include reassigning the person's AML/CTF functions. AUSTRAC's own e-learning modules can be used but "can't be relied on solely" because training must be tailored to the person. If an external provider is used, AUSTRAC expects due diligence on the provider, confirmation that content reflects the entity's own risks and policies, and alignment with the AML/CTF program. The guide on showing a regulator that training works sets out evidence types that meet this expectation.

How does personnel due diligence relate to training?

Personnel due diligence assesses whether a person has the skills, knowledge, expertise and integrity for their AML/CTF role, and training is the usual remedy when a capability gap is found. Section 5-8 of the Rules requires the policies to assess, both before and during a person's employment or engagement, their skills, knowledge and expertise relevant to their responsibilities, and their integrity.

AUSTRAC's personnel due diligence guidance suggests knowledge-based assessments, interviews and checks of prior qualifications, and says that where gaps are identified an entity might provide targeted training before the person starts the AML/CTF function or delay assigning responsibilities until training is complete. A competency assessment that serves both purposes avoids duplicate testing.

How does Knowledge Foundry approach this?

Knowledge Foundry models the AML/CTF obligations, roles and risks as a structured framework first, then links each role to the concepts and assessment points it must demonstrate. When the Rules or an entity's policies change, affected roles and assessments are identified from the framework rather than by rereading every course, and the evidence record shows which version each person was assessed against.

Frequently asked questions

Does every employee need AML/CTF training?

The Rules require training for persons employed or engaged by the reporting entity, and AUSTRAC focuses the obligation on people who perform AML/CTF functions. AUSTRAC's examples also include general awareness training at onboarding for personnel not in AML/CTF relevant roles, so most entities give everyone a baseline and add role specific modules.

Is annual AML/CTF training mandatory?

No fixed interval is set in the Rules. They require initial and ongoing training appropriate to the person's function and risks. AUSTRAC gives 6 to 12 months for compliance officers and senior management and 12 months for customer facing staff as examples only, and expects extra training when laws, risks or policies change.

Can we use AUSTRAC's free e-learning to meet the obligation?

AUSTRAC says its e-learning modules can be used as part of training but cannot be relied on solely, because training must be tailored to each person's AML/CTF functions, the risks relevant to those functions and their responsibilities under the entity's own policies.

What if we are a newly regulated accounting or legal practice?

Newly regulated businesses must comply from July 1, 2026. That includes having AML/CTF policies that provide initial and ongoing training and personnel due diligence. AUSTRAC publishes program starter kits for these sectors, which should be adapted to the practice's own risk assessment.

What training records should we keep?

AUSTRAC expects records reasonably necessary to demonstrate compliance, such as who completed training and their role, the topics and content version, delivery method, how understanding was assessed and the result, and each person's history of initial, refresher and role specific training.

Sources

  1. AML/CTF training, AUSTRAC
  2. Personnel due diligence (PDD), AUSTRAC
  3. About the reforms, AUSTRAC
  4. AML/CTF Transitional Rules 2026, AUSTRAC
  5. Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, Federal Register of Legislation
  6. Anti-Money Laundering and Counter-Terrorism Financing Rules 2025, Federal Register of Legislation
  7. Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026, Federal Register of Legislation
  8. Anti-Money Laundering and Counter-Terrorism Financing Rules Instrument 2007 (No. 1), compilation of 26 January 2024, Federal Register of Legislation

This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.

Ready to see it?

Bring a subject. Leave with a framework.

A 45-minute working session with our team on a real subject or program you own. You see the system operate on your material, and you keep the framework it produces.

We reply within one business day.