Appointing an AML/CTF Compliance Officer (AMLCO): 2026 Guide

Every Australian Tranche 2 business must appoint an AML/CTF Compliance Officer before 1 July 2026. Here is who can hold the role, what they are responsible for, and how to document the appointment.
From 1 July 2026, every Australian business captured by the Tranche 2 reforms to the AML/CTF Act 2006 must appoint an AML/CTF Compliance Officer — the AMLCO. Now that Tranche 2 has commenced, naming the right person and documenting their authority is one of the first decisions a reporting entity has to get right, because almost every other obligation in your AML/CTF Programme flows through this role. This guide explains who can be an AMLCO, what the role is accountable for, whether it can be outsourced, and how to record the appointment so it withstands AUSTRAC scrutiny.
What Is an AML/CTF Compliance Officer?
The AML/CTF Compliance Officer (commonly the AMLCO, and sometimes called the MLRO — Money Laundering Reporting Officer — in other jurisdictions) is the designated individual responsible for overseeing a reporting entity's compliance with its AML/CTF obligations. The appointment is a mandatory element of Part A of your AML/CTF Programme: the programme must name the officer, describe their responsibilities, and set out their reporting line to senior management. The AMLCO is the person AUSTRAC, your staff, and your senior management look to as the central point of accountability for money laundering and terrorism financing risk.
Appointing an AMLCO is not a formality you can satisfy by adding a name to a template. The role carries real responsibility for the day-to-day operation of the programme, and the person who holds it must have the seniority, knowledge, and access to discharge it.
Is Appointing an AMLCO Mandatory?
Yes. Designating an AML/CTF Compliance Officer is a core requirement of having a compliant AML/CTF Programme, and a programme is mandatory for every entity that provides a designated service from 1 July 2026. There is no business-size exemption: a sole practitioner accounting firm, a two-partner conveyancing practice, and a national real estate franchise all have the same obligation to name an AMLCO. What scales with size is not whether you appoint one, but how the role is resourced — a large entity may have a dedicated compliance team reporting to the AMLCO, while a small firm may have a principal who holds the role alongside other duties.
Who Can Be the AMLCO?
The AMLCO must be a fit and proper person engaged at management level within the reporting entity, with enough seniority and authority to make and enforce compliance decisions. In practice this means the person should:
- Hold sufficient seniority — the role should sit at management level, with the authority to escalate issues, halt onboarding of a high-risk client, and require remediation when procedures are not followed
- Have direct access to senior management and the board — the AMLCO must be able to report compliance matters to the people who approved the programme, without those reports being filtered or suppressed
- Be fit and proper — of good repute, with no history that would undermine their integrity in a compliance role
- Understand the business and its ML/TF risks — the officer should know the entity's designated services, client base, and risk profile well enough to apply the programme intelligently rather than mechanically
- Have the time and resources to do the job — appointing a nominal AMLCO who has no capacity to monitor the programme is a common and serious failure
In a small firm, the AMLCO is frequently the principal, managing partner, or a senior director. In a larger organisation, it is often a dedicated compliance manager or the head of risk. The key test is not job title but whether the person genuinely has the authority and standing to make compliance decisions stick.
Can the AMLCO Role Be Outsourced?
This is one of the most common questions for smaller Tranche 2 businesses, and the answer requires care. The reporting entity cannot outsource its legal accountability for compliance — the obligation to have a functioning AML/CTF Programme, and to lodge reports with AUSTRAC, always remains with the entity itself. The named AMLCO is generally expected to be a person within the business who can exercise genuine authority over its operations.
What you can do is engage external consultants and technology to support the AMLCO — to help draft the programme, run training, provide screening tools, conduct the independent review, and advise on complex matters. An external adviser can carry much of the workload; what they cannot do is become a substitute for an accountable officer inside the business. A firm that simply names its external consultant as AMLCO and assumes the obligation has been discharged is exposed if that arrangement does not give the consultant real authority and visibility over the firm's day-to-day client work. If you are considering an external arrangement, document precisely who holds the accountable role internally and how the external support feeds into it.
What Is the AMLCO Responsible For?
The AMLCO's remit covers the practical operation of the AML/CTF Programme. Typical responsibilities include:
- Overseeing the AML/CTF Programme — ensuring Part A and Part B are implemented, kept current, and actually followed in practice
- Customer due diligence oversight — supervising how clients are identified, verified, and risk-rated, and approving enhanced due diligence for high-risk relationships
- Suspicious matter decisions — receiving internal escalations, deciding whether a reasonable suspicion exists, and ensuring suspicious matter reports are lodged with AUSTRAC within the required timeframe while managing the tipping-off prohibition
- Other AUSTRAC reporting — overseeing threshold transaction reports and any other reports the entity must lodge
- Ongoing monitoring — ensuring active client relationships are reviewed, and that PEP and sanctions re-screening occurs at the intervals the programme specifies
- Training — making sure all relevant staff receive AML/CTF training appropriate to their roles, and that training records are kept
- Reporting to senior management — providing regular updates on the programme's operation, emerging risks, and any compliance failures
- Supporting the independent review — facilitating the regular independent review of the programme and ensuring findings are acted upon
AMLCO, Senior Management, and the Board — Who Does What?
It is important not to confuse the AMLCO's role with the role of senior management. The AMLCO runs the programme day to day; senior management and the board remain ultimately responsible for approving it and providing oversight. Senior management must approve the AML/CTF Programme, ensure the AMLCO has the resources and authority to do the job, and receive and act on the AMLCO's reports. Appointing an AMLCO does not transfer the board's accountability — it creates a dedicated operational owner who reports up to it. A programme that names an AMLCO but shows no evidence of senior management oversight has only addressed half the governance obligation.
How to Document the AMLCO Appointment
The appointment must be recorded in writing and reflected in your AML/CTF Programme. A defensible appointment record typically includes:
- The named individual and their position within the entity
- A written statement of responsibilities — what the AMLCO is accountable for, drawn from the list above and tailored to your business
- The reporting line — to whom the AMLCO reports, and how often
- The authority granted — confirmation that the officer can escalate, require remediation, and access the information and systems they need
- The date of appointment and senior-management approval — a resolution, signed minute, or programme cover page showing who approved the appointment and when
- A record of the officer's suitability — evidence the person is fit and proper and adequately trained for the role
Keep this record with your programme version history so that, if AUSTRAC reviews your compliance, you can show not only who your AMLCO is today but when each appointment took effect and who authorised it. The AMLify programme builder captures the AMLCO appointment, responsibilities, and approval record as part of the guided Part A workflow, with version control built in.
Common AMLCO Mistakes to Avoid
- The nominal appointment — naming someone with no time, authority, or training to actually run the programme
- No reporting line — appointing an AMLCO who has no clear channel to senior management, so compliance issues never reach decision-makers
- Confusing support with accountability — assuming an external consultant or software vendor can be the AMLCO and relieve the business of its obligation
- No documented authority — failing to record that the AMLCO can halt onboarding, require remediation, or escalate, leaving the role toothless in practice
- Set and forget — appointing an AMLCO at launch and never reviewing whether the arrangement still works as the business grows or its risk profile changes
Key Takeaways
- Every Tranche 2 reporting entity must appoint an AMLCO as part of Part A of its AML/CTF Programme — there is no exemption for small firms or sole practitioners
- The AMLCO must be fit and proper, engaged at management level, and have genuine authority, seniority, and access to senior management
- The role cannot be outsourced in substance — external advisers and technology can support the AMLCO, but legal accountability stays with the entity and an accountable person inside the business
- The appointment must be documented — named individual, responsibilities, reporting line, authority, and dated senior-management approval, kept with the programme version history
- Get compliant now — naming and documenting your AMLCO is a prerequisite for almost every other obligation, so it should be among the first steps in your compliance build
Frequently Asked Questions
Q: Can the business owner or principal be the AMLCO?
Yes. In small businesses the principal, managing partner, or a senior director is very often the most appropriate AMLCO because they already have the seniority and authority the role requires. What matters is that the person genuinely has the time, knowledge, and access to discharge the responsibilities — not that the role is held by a particular title. A principal who appoints themselves AMLCO but delegates all compliance work without oversight has not met the obligation in substance.
Q: Does a sole practitioner need an AMLCO?
Yes. The obligation applies by reference to the designated services a business provides, not its size. A sole practitioner who provides a designated service must still designate an AML/CTF Compliance Officer — which, in a one-person practice, will be the practitioner themselves. The programme should still name the officer, set out their responsibilities, and record the appointment, even where the same person performs every role in the business.
Q: Can we use an external consultant as our AMLCO?
You can engage an external consultant to support your AML/CTF compliance — drafting the programme, delivering training, running screening, and conducting the independent review. However, the reporting entity cannot outsource its legal accountability, and the accountable officer is generally expected to be a person within the business with genuine authority over its operations. Treat external advisers as support for an internal AMLCO, not a replacement for one, and document clearly who holds the accountable role inside the firm.
Q: What qualifications does an AMLCO need?
The AML/CTF Act does not prescribe a specific qualification, but the AMLCO must be a fit and proper person with sufficient knowledge of the entity's business and its ML/TF risks to run the programme competently. In practice this means appropriate AML/CTF training, a working understanding of the entity's designated services and client base, and the seniority to act on compliance decisions. The depth of expertise expected scales with the size and complexity of the business.
Q: How does the AMLCO relate to the AML/CTF Programme and risk assessment?
The ML/TF risk assessment identifies the entity's exposure; the AML/CTF Programme sets out the policies and procedures that respond to it; and the AMLCO is the person accountable for making sure those procedures operate in practice. The three work together: the risk assessment informs the programme, the programme defines the AMLCO's responsibilities, and the AMLCO ensures the programme is implemented and kept current as the risk assessment changes.
This is general information only and not a substitute for legal advice.