days leftTranche 2 is live — Compliance Kickstart: 20% off for 6 months. Ends 30 September 2026.
AMLify logoAMLify
Compliance Guides

Independent Review Obligations for TCSPs

6 August 20264 min readAMLify Team
Independent Review Obligations for TCSPs

What AUSTRAC's independent review requirement means for TCSPs, how often it's due, and what a compliant review checks for beneficial ownership.

An independent review is a periodic, arms-length check on whether a trust and company service provider's AML/CTF Programme is actually working in practice — not just documented on paper — and the AML/CTF Act 2006 requires every Tranche 2 reporting entity, including TCSPs, to complete one, typically every one to three years depending on its own risk assessment.

What does an independent review check for a TCSP?

An independent review tests whether the AML/CTF Programme is followed day to day, not merely whether it exists. For a TCSP, a reviewer typically examines: - Programme currency — whether the Part A and Part B documents still reflect the services actually provided, from company formation to acting as a nominee director - CDD and beneficial ownership file quality — a sample of client files checked for verification that traces through to the natural person, not just the instructing director or trustee - SMR and TTR timeliness — whether reportable matters were lodged within statutory timeframes - Training records — whether staff who handle formation and nominee arrangements completed AML/CTF training at the committed frequency

Who can conduct the review?

The reviewer must be independent of the compliance function being assessed — someone who didn't design or operate the programme under review. Most TCSPs engage an external AML/CTF consultant given typically smaller compliance teams; a larger provider may use an internal audit function, provided it sits outside the AMLCO's reporting line. AUSTRAC doesn't accredit reviewers, but a TCSP should be able to justify the reviewer's independence if asked.

How often is an independent review required?

The AML/CTF Act 2006 doesn't fix a single interval — frequency is set out in the TCSP's own AML/CTF Programme and calibrated to its ML/TF risk rating. Given the sector's elevated exposure to nominee arrangements and layered ownership structures, AUSTRAC's guidance points most TCSPs toward the shorter end of the one- to three-year cycle rather than the longer end.

What should a TCSP's review focus on beyond a standard programme check?

Beneficial ownership is the sector's defining risk, so a compliant review should specifically test whether ownership and control records were re-verified after known trigger events — a change of trustee, a share transfer, a new appointor — rather than only at onboarding. A reviewer should also sample nominee director and shareholder arrangements to confirm the rationale on file still holds, not just that a rationale was recorded once.

What happens after the review?

  1. Findings are documented in a written report identifying gaps between the programme as designed and as operated
  2. A remediation plan is agreed, with an owner and deadline for each finding
  3. The AMLCO reports outcomes to the board or responsible principal
  4. The programme is updated where a provision no longer fits how the TCSP actually operates
  5. An unactioned finding left open for years signals the TCSP knew about a weakness and chose not to fix it — AUSTRAC treats that as worse than the original gap.

Key Takeaways

  • Independent review tests whether the AML/CTF Programme is actually followed, not just whether it's written down
  • The reviewer must sit outside the compliance function that designed and runs the programme
  • Most TCSPs should plan for a review every one to three years, calibrated to risk and often at the shorter end given nominee and ownership complexity
  • Beneficial ownership re-verification after trigger events deserves specific attention in the review scope
  • AMLify for TCSPs tracks the review due date and stores findings alongside the programme itself

Frequently Asked Questions

Q: Is an independent review the same as an AUSTRAC audit?

No. An independent review is an obligation the TCSP arranges and pays for itself. An AUSTRAC audit is a regulatory action AUSTRAC initiates and controls. A well-run review reduces the risk of adverse findings if AUSTRAC does examine the TCSP.

Q: Does a sole-practitioner TCSP still need one?

Yes. The obligation applies to any reporting entity with an AML/CTF Programme, regardless of size. A sole practitioner can engage an external consultant for a proportionate, lower-cost review instead of building an internal audit function.

Q: Can the AMLCO conduct the review themselves?

No. The AMLCO operates the programme day to day, so reviewing their own work wouldn't meet the independence requirement. They can coordinate the process and respond to findings, but the assessment must come from outside that reporting line.

Q: What happens if a TCSP has never completed one?

There's no grace period — the obligation has been live for every Tranche 2 TCSP since 1 July 2026. Providers without a completed review should schedule one now, since it's one of the first things AUSTRAC checks in a supervision engagement.

This is general information only and not a substitute for legal advice.