ISO 9001:2026 was published on 16 September. See what changed →


Your First Annual Program Review: A Checklist for Twelve Months In

Twelve months after you first built your AML/CTF program, it’s worth asking an honest question: is this still a system your agency actually runs on, or has it quietly become a document nobody’s opened since the week it was written. This is the real test of everything we’ve covered across this series, and it’s a test worth running deliberately, once a year, rather than waiting to find out the hard way.

Here’s a practical checklist for that review, and how to run it properly.

How this differs from an independent review

We’ve covered the independent review separately, and it’s worth being clear this annual check in isn’t the same thing. An independent review needs genuine objectivity, someone who wasn’t involved in building the program, examining it properly at intervals suited to your size and risk. This annual review is different: it’s an internal, honest gut check, done by you or your team, more frequent and lighter touch, a genuine look in the mirror rather than a formal evaluation. The two are complementary, not substitutes for each other. This one you can and should do yourself, every year, regardless of when your next independent review falls due.

The checklist

Governance. Is your nominated Compliance Officer still accurate, both in your documents and with AUSTRAC itself? Do they still hold genuine authority in the business, not just the title? If they were unavailable tomorrow, does anyone else know enough to step in?

Risk assessment. Does it still describe your agency as it actually operates today, or has your business changed in ways the document hasn’t caught up with, a new service line, a new office, a shift in the kinds of customers or transactions you’re handling? If anything’s changed and you haven’t updated it yet, that’s the first thing to schedule.

Policies, procedures, and work instructions. Are these still properly separated, with the day to day procedures usable by staff without wading through governance philosophy to find them? Do the work instructions still match the actual tools your team is using, or has your software changed without the instructions catching up?

Document control. Is your version log genuinely up to date, with every change recorded, dated, and approved? Are superseded versions properly archived rather than simply overwritten and lost?

Customer due diligence and training. Pull a small, honest sample of recent CDD files, not the tidiest ones, a genuine cross section. Do they actually reflect your documented procedure? Is training current and evidenced for every staff member currently on your team, including anyone who’s joined in the past year?

Record keeping. Could someone unfamiliar with your system retrieve a specific file from eighteen months ago in a few minutes, without needing to track down a particular staff member to ask where things are kept?

Independent review. Is one genuinely scheduled, with a date rather than a vague intention? If your last one already happened, were its findings actually acted on, or noted and quietly left as they were?

Annual Compliance Report. Are you on track for your reporting period, with evidence being gathered naturally as you go, or will you be scrambling to reconstruct a year’s worth of records under deadline pressure when the submission window opens?

Regulatory monitoring. Has anything from AUSTRAC changed in the past twelve months that your program hasn’t yet accounted for? A quick check against your own quarterly monitoring notes, if you’ve been keeping them, should answer this quickly.

How to actually run this review

This shouldn’t take days, and it shouldn’t be a formality either. A few hours, done honestly, genuinely beats a longer process done superficially. If more than one person in your agency has visibility into the program, involve them, a second perspective catches things a single, close viewpoint misses, particularly when that person has been living with the program all year and has stopped noticing its rough edges.

The same principle that makes an independent review valuable applies here: the whole point is honesty, not presentation. If you go into this review trying to make everything look tidy rather than actually checking whether it’s tidy, you’ve spent the time without getting the benefit. Look at what’s genuinely there, not what you’d like an examiner to see.

Document the review itself, even briefly. A short note covering what you checked, what you found, and what you’re doing about it becomes a real record, both for your own reference next year and as evidence that this kind of ongoing diligence is actually happening in your business, not just assumed.

What to actually do with what you find

Small, quick fixes should happen immediately, don’t let a five minute correction linger just because it surfaced during a formal review rather than in the normal course of business. Larger gaps need a genuine plan with a realistic timeline, not just a note added to a list that never gets revisited. And if you find something that should have triggered action months ago, a risk assessment update you’d been meaning to get to, a training gap for a new starter, treat finding it now as the moment to actually fix it, not another opportunity to defer it further.

What twelve months in actually tells you

This is really the conclusion the whole series has been building toward. An AML/CTF program is a management system, not a folder of documents, and the difference between those two things only becomes visible over time. A folder of documents looks identical on day one and month twelve, because nothing about it changes regardless of what’s happening in your business. A genuine management system looks different twelve months in, not because it’s fallen apart, but because it’s been used, tested, updated, and kept honest against what your agency actually does.

If your review this year turns up a program that’s aged well, current, evidenced, actually reflecting your business, that’s a genuine result worth recognising, not a formality to rush past. If it turns up real gaps, that’s not a failure either, it’s exactly what this process is for, catching drift while it’s still a straightforward fix rather than something an examiner finds first.

Where Lead Comply fits into this

If you’ve worked through this checklist honestly and you’re not confident about the answers, particularly around governance, risk assessment currency, or whether your documentation would genuinely hold up to scrutiny, that’s precisely what our free 30 minute Compliance Gap Audit is designed to assess properly, with an outside, genuinely independent perspective rather than your own read of your own work. And if the review reveals your program needs more than a light touch update, whether that’s a proper rebuild of your risk assessment or a Program Manual that’s simply fallen too far out of step with how your agency now operates, our Program Manual service is built to bring it back to something genuinely current, written specifically for your business as it actually is today, not as it was the day you first enrolled.

Create your free account and book No Obligation Compliance Gap Audit→ Lead Comply AML Portal



Leave a Reply

Your email address will not be published. Required fields are marked *