AML/CTF Programme for Trust & Company Service Providers
Every Australian TCSP must have a written AML/CTF Programme before 1 July 2026. Here is what Part A and Part B must contain and how to get approved.
Every Australian trust and company service provider (TCSP) must adopt a written AML/CTF Programme before 1 July 2026. The programme is mandatory under Part 2 of the AML/CTF Act 2006 and is the centrepiece of what AUSTRAC will assess in any compliance review. Without an approved programme in place from the commencement date, your business is non-compliant from day one.
What is an AML/CTF Programme for a TCSP?
An AML/CTF Programme is the written framework a reporting entity uses to identify, assess, and manage its money laundering and terrorism financing (ML/TF) risks. Every TCSP that provides a designated service must adopt and maintain one before providing that service. The programme is not a one-time form — it is a living document that must reflect how your business actually operates, be approved by senior management, and be updated whenever your services, client base, or risk profile changes materially.
Which TCSP services require a written programme?
A programme is mandatory for any TCSP that offers one or more of the following Tranche 2 designated services: - Company and trust formation — incorporating companies, registering business names, establishing or administering trusts on behalf of clients - Nominee services — supplying nominee directors, shareholders, or beneficial owners for client entities - Registered office or company secretarial services — acting as a registered agent or providing ongoing company secretary functions - Managing client assets or funds — holding client money, directing asset transfers, or controlling financial accounts on a client's behalf If your TCSP provides any of these services — even occasionally — you are in scope for the full programme, customer due diligence, and reporting obligations.
What must Part A of the programme include?
Part A governs how your TCSP manages and oversees its compliance obligations. A compliant Part A must address: - AML/CTF Compliance Officer (AMLCO) — the named individual responsible for overseeing the programme, their responsibilities, and their direct reporting line to senior management - ML/TF risk assessment — a documented assessment of the risks your services, client base, delivery channels, and jurisdictions present, reviewed and updated whenever circumstances change materially - Senior management oversight — how the programme is approved and how compliance reports flow to the people accountable for the business - Employee due diligence — screening procedures for staff in key compliance roles, particularly those with access to client funds or beneficial ownership information - AML/CTF training — regular training for relevant staff with completion records retained - Independent review — a commitment to periodic review of the programme's design and operation (at least every two years) - Record-keeping — how and for how long CDD files, transaction records, and compliance decisions are retained (minimum seven years under the Act)
What must Part B of the programme include?
Part B governs how your TCSP performs customer due diligence (CDD). For TCSPs, Part B is especially demanding because company and trust formation services frequently involve multi-layered entity structures. A compliant Part B must address: - Client identification and verification — procedures for verifying the identity of individual clients and entity clients before providing a designated service - Beneficial ownership identification — procedures for tracing natural persons who ultimately own or control a client entity through any number of intermediate layers - PEP and sanctions screening — screening at onboarding and periodically against current politically exposed person, sanctions, and adverse media lists - Risk-based client categorisation — a methodology for assessing each client's ML/TF risk level and applying proportionate due diligence accordingly - Enhanced due diligence (EDD) — mandatory EDD for higher-risk clients, including foreign entities, clients with nominee arrangements, and relationships with no clear business rationale - Ongoing monitoring — reviewing active client relationships at a frequency proportionate to risk and updating records when material information changes - Suspicious matter reporting — the internal escalation process ensuring the AMLCO assesses potential SMRs and lodges with AUSTRAC within three business days
Why are TCSPs subject to heightened ML/TF scrutiny?
TCSPs are identified by both FATF and AUSTRAC as a high-risk sector because their core services can be exploited to create or maintain structures that obscure the true ownership of assets. Company and trust formation, nominee arrangements, and registered office services all appear in typologies associated with layered ownership schemes used to conceal proceeds of crime. Your programme must directly address these inherent risks rather than apply a generic template — the risk assessment must reflect the specific services you provide, and the Part B procedures must be calibrated to the exploitation scenarios your business can enable. A programme that accurately reflects your operations is far more defensible in an AUSTRAC review than one that treats all clients identically regardless of their structure or risk.
How do you get your programme approved before 1 July 2026?
Now that Tranche 2 has commenced, the practical path to a compliant programme has five steps: 1. Complete your ML/TF risk assessment — identify the designated services you provide, the client types you serve, your delivery channels, and the jurisdictions involved. This assessment informs the level of CDD required in Part B. 2. Draft Part A — set out governance arrangements, name your AMLCO, record their responsibilities and reporting line, and document training and review commitments. 3. Draft Part B — write the CDD procedures for each designated service, with particular care for beneficial ownership tracing and EDD triggers relevant to TCSP structures. 4. Obtain senior management approval — formally approve the programme at senior management level and record the date, approver's name, and their role. 5. Implement and train — distribute the programme to all relevant staff, confirm procedures are operational, and schedule the first AML/CTF training session before the deadline. AMLify's TCSP compliance module guides you through each step with a structured programme builder and produces a version-controlled document ready for senior management sign-off.
Key Takeaways
- A written AML/CTF Programme is mandatory for every TCSP providing a designated service from 1 July 2026
- Part A covers governance: AMLCO appointment, ML/TF risk assessment, senior management oversight, employee due diligence, training, independent review, and record-keeping
- Part B covers CDD: client identification and verification, beneficial ownership tracing, PEP and sanctions screening, risk-based categorisation, EDD for higher-risk clients, ongoing monitoring, and suspicious matter reporting
- TCSPs face elevated inherent ML/TF risk because their services are directly exploited to obscure beneficial ownership — your programme must reflect this specifically, not apply a generic template
- Five steps remain: risk assessment, Part A draft, Part B draft, senior management approval, and staff implementation before 1 July 2026
Frequently Asked Questions
Q: Does a small TCSP need the same programme as a large one?
The obligation applies to every TCSP providing a designated service, regardless of size. What differs between a sole-director TCSP and a large trust administration firm is the depth and resourcing of the programme, not whether one is required. A smaller operation can have a shorter, more proportionate programme, provided it still covers all required elements and is calibrated to the actual services and risk profile of the business. Simplicity is acceptable — omission is not.
Q: Can we adapt an existing template for our TCSP programme?
A template can be a useful starting point, but it must be substantially customised to your specific services, client types, and risk profile before senior management approves it. AUSTRAC's guidance makes clear that a generic document not tailored to the reporting entity's circumstances will not be treated as a compliant programme. AMLify's guided programme builder produces a customised output by working through structured questions about your TCSP's designated services and risk environment, rather than providing a fill-in-the-blanks form.
Q: How often must the AML/CTF Programme be updated?
The programme must be updated whenever there is a material change to your business — new designated services, changed client acceptance criteria, new delivery channels or jurisdictions, or gaps identified through the independent review. Annual review is good practice, and the independent review (required at least every two years) will typically identify whether updating is needed. AMLify tracks programme versions with timestamps and approval records so the review history is documented alongside the current programme text.
Q: What are the penalties for operating without a programme after 1 July 2026?
Operating a designated service without a compliant AML/CTF Programme is a contravention of the AML/CTF Act 2006. Civil penalties for corporate entities can reach $18.5 million per contravention. AUSTRAC has identified TCSPs as a supervision priority under Tranche 2, and enforcement outcomes are published publicly — meaning a penalty can affect client confidence and professional standing in addition to imposing a direct financial cost.
This is general information only and not a substitute for legal advice.