Specialist Compliance Solutions for AML/CTF Tranche 2, ISO 9001 & ISO 42001.

  0437 801 021    1/457-459 Elizabeth Street, Surry Hills, NSW 2010

AML/CTF Program Part A: What It Is and What It Must Contain

AML/CTF Program Part A: What It Is and What It Must Contain

Every Australian real estate agency that provides designated services must have an AML/CTF Program in place before 1 July 2026. The program has two parts. Part A covers governance. Part B covers Customer Due Diligence. This guide explains Part A in full — what it is, what it must contain, and what makes it defensible during an AUSTRAC examination.

The AML/CTF Program is the core compliance document of every reporting entity under the AML/CTF Act 2006. It is the document that brings together the agency’s ML/TF risk assessment, its governance procedures, its staff training obligations, its reporting processes, and its management oversight framework into a single coherent system.

Part A is the governance part of that system. It establishes how the agency manages its AML/CTF obligations at an organisational level. It does not deal with how individual clients are identified and verified. That is Part B. Part A addresses the structures, policies, and procedures that govern how the agency operates as a whole within the AML/CTF framework.

AUSTRAC has published detailed guidance on AML/CTF program requirements at austrac.gov.au. The legislative requirements are set out in the AML/CTF Act 2006 and the AML/CTF Rules, both available at legislation.gov.au. This article translates those requirements into plain English for real estate agency principals and compliance officers.

⚠️  PROGRAM MUST BE IN PLACE BEFORE 1 JULY 2026
A real estate agency cannot lawfully provide designated services as a reporting entity without an AML/CTF Program that meets the requirements of the AML/CTF Act. Enrolling with AUSTRAC satisfies Obligation 1. Having a compliant AML/CTF Program satisfies Obligations 2 and 3. These are separate requirements. An agency that is enrolled but has no program, or has a generic downloaded template that does not reflect its actual operations, is in breach from 1 July 2026.

Part A and Part B: Understanding the Two-Part Structure

The AML/CTF Act requires every reporting entity to adopt and maintain an AML/CTF Program with two distinct components. Understanding the division between them prevents the common mistake of conflating governance with customer identification procedures.

Part A — GovernancePart B — Customer Identification
What it coversHow the agency manages its AML/CTF obligations at an organisational levelHow the agency identifies and verifies clients before providing designated services
AudienceLeadership, senior management, and all staff across the agencyStaff who conduct client onboarding and Customer Due Diligence
Driven byThe ML/TF Risk Assessment and the agency’s governance frameworkThe ML/TF Risk Assessment and the customer types the agency serves
Key componentsGovernance, risk assessment link, employee obligations, training, reporting, monitoring, reviewCDD procedures, beneficial owner identification, EDD, PEP screening, sanctions screening, ongoing monitoring
AUSTRAC focusIs there a functioning governance framework with appropriate oversight and accountability?Are clients properly identified and verified before designated services are provided?
🎓  FROM LEAD COMPLY’S COMPLIANCE EXPERIENCE
The most common structural error Lead Comply observes in downloaded AML/CTF program templates is that Part A and Part B are either combined into a single undifferentiated document, or Part Ais present only in skeleton form with headings but no substantive content.
In a regulated industry environment, Part A is the document that senior management signs, is accountable for, and reviews annually. It is the governance architecture of the entire AML/CTF framework. An AUSTRAC examiner reviewing a real estate agency’s program will look at Part A to assess whether the agency’s leadership has genuinely adopted and oversees the compliance framework, or whether compliance exists only on paper. A Part A that runs to two pages and contains only generic headings does not demonstrate genuine adoption by management. A defensible Part A reflects the agency’s actual governance structure, its specific ML/TF risk profile, and the real procedures its leadership uses to oversee the AML/CTF framework.

The Seven Required Components of AML/CTF Program Part A

The AML/CTF Rules specify the matters that must be addressed in Part A of a reporting entity’s program. For real estate agencies, seven components are required. Each must be addressed with substantive content that reflects the agency’s actual operations, not generic language that could apply to any business.

1ML/TF Risk Assessment — The Foundation of Part A  [Required by: AML/CTF Rules] Part A must be based on and reference the agency’s ML/TF Risk Assessment. The risk assessment identifies the money laundering and terrorism financing risks specific to the agency — the types of clients it serves, the services it provides, the channels through which it delivers them, and the geographic markets it operates in. Part A must explain how the program addresses each identified risk. A program that is not demonstrably connected to a completed risk assessment does not meet this requirement.
2Governance and Oversight Framework  [Required by: AML/CTF Act s.84]Part A must establish clear accountability for AML/CTF compliance within the agency. This includes identifying the AML/CTF compliance officer by role and name, specifying the reporting line to senior management, documenting the responsibilities of the principal officer, and setting out how AML/CTF compliance is overseen at board or principal level. The governance framework must show that leadership has genuinely adopted and is accountable for the program, not simply that a document exists.
3Employee Due Diligence  [Required by: AML/CTF Rules Part 9.4]Part A must include procedures for conducting background screening of employees who are involved in providing designated services or who have access to sensitive compliance information. Employee due diligence covers criminal history checks, identity verification, reference checks, and, for higher-risk roles, enhanced background screening. The procedures must specify which roles are subject to screening, what the screening involves, and how results are documented and acted upon.
4AML/CTF Staff Awareness and Training  [Required by: AML/CTF Rules Part 9.3]Part A must document the agency’s approach to staff training, including the content of training, who is required to complete it, the delivery method, how often training is refreshed, and how completion is recorded. The training program described in Part A must be appropriate to the roles involved and tailored to the agency’s designated services and risk profile. Generic AML/CTF awareness training that is not connected to the agency’s specific obligations does not satisfy this component.
5AUSTRAC Reporting Procedures  [Required by: AML/CTF Act Part 3]Part A must set out the agency’s procedures for meeting all AUSTRAC reporting obligations. For real estate agencies, this covers three categories: Suspicious Matter Reports (SMRs), including the suspicion threshold, reporting timeframes (24 hours for terrorism, three business days for other matters), and the tipping off prohibition; the obligation to lodge Threshold Transaction Reports if applicable; and the Annual Compliance Report submitted to AUSTRAC each year. The procedures must identify who is responsible for lodging each type of report and include an escalation path for uncertain cases.
6Ongoing Customer Due Diligence and Transaction Monitoring  [Required by: AML/CTF Rules Part 15] Part A must address how the agency monitors its clients and transactions on an ongoing basis. This is distinct from the initial CDD procedures in Part B. Ongoing monitoring under Part A covers the procedures for reviewing client relationships when circumstances change, the triggers for re-verifying client identity, the approach to monitoring transactions for unusual patterns, and the process for escalating concerns identified through ongoing monitoring. For most real estate agencies this component focuses on the review triggers rather than a sophisticated transaction monitoring system.
7Independent Review of the Program  [Required by: AML/CTF Rules Part 9.2] Part A must include a procedure for the periodic independent review of the AML/CTF program. The review must assess whether the program is operating effectively, whether it remains appropriate to the agency’s risk profile, and whether any changes to the business, the regulatory environment, or AUSTRAC guidance require the program to be updated. The review must be conducted by a person or function that is independent of the compliance function being reviewed. The results of each review must be documented and reported to senior management.
C L
Ask Dan — AML/CTF Program Part A Questions Not sure your Part A covers everything it needs to? Ask Dan directly.
AI may make mistakes. See our Privacy Policy. · info@leadcomply.com.au

How Often Must Part A Be Reviewed?

The AML/CTF Act requires reporting entities to review their program periodically to ensure it remains appropriate and effective. AUSTRAC expects the review to occur in three circumstances.

Review TriggerWhat the Review Must Address
At least annuallyWhether the program remains appropriate to the agency’s current risk profile, whether all required components are functioning as intended, and whether any regulatory changes require updates to the program
When the business changes materiallyWhen the agency adds new designated services, enters new markets, changes its client profile significantly, or restructures its governance, the program must be reviewed and updated to reflect those changes
When AUSTRAC issues new guidance or legislative changes take effectThe AML/CTF framework is actively evolving. When AUSTRAC publishes new guidance that affects real estate agencies, the program must be assessed against that guidance and updated where necessary
When an internal review, audit, or compliance incident identifies a gapA gap identified through internal review or an SMR near-miss is a trigger to review and update the relevant part of the program immediately, not at the next scheduled review
🎓  FROM LEAD COMPLY’S COMPLIANCE EXPERIENCE
The review requirement is the component of Part A that most agencies treat as an administrative formality. In a mature AML/CTF program environment, the annual review is a substantive exercise that involves testing whether the program reflects current operations, whether the risk assessment still accurately represents the agency’s risk profile, and whether the controls in place are actually working. Lead Comply consistently finds that programs reviewed for the first time after initial design have outdated content within twelve months. Agencies onboard new client types, add services, change staff, or encounter situations the original program did not anticipate. A program that is not reviewed promptly in response to those changes provides a false sense of compliance while actual practice diverges from the documented framework.

What Makes a Part A Defensible in an AUSTRAC Examination?

AUSTRAC examiners assess Part A against three questions: Is it based on an actual risk assessment? Does it reflect how the agency genuinely operates? Has leadership actually adopted and overseen it?

A Part A that is defensible in an examination has the following characteristics.

Generic Part A — Not DefensibleTailored Part A — Defensible
Risk assessment referenced but not integrated — the program does not explain how identified risks are addressedEach risk identified in the risk assessment is addressed by a specific control or procedure in Part A
Compliance officer role defined generically without naming the specific position in the agencyCompliance officer is identified by role title and the reporting line to the principal is explicit
Employee due diligence described as “background checks as appropriate”Employee due diligence specifies which roles require screening, what checks are conducted, and how results are documented
Training described as “annual AML/CTF awareness training”Training component specifies content, delivery method, frequency, who is covered, and how completion is recorded
AUSTRAC reporting section says “SMRs will be lodged as required”SMR procedure specifies the suspicion threshold, the internal escalation path, who is authorised to lodge, and the documentation requirement
Review section says “the program will be reviewed annually”Review section specifies who conducts the review, what the review covers, how results are reported to management, and when the last review was conducted

How Lead Comply Designs AML/CTF Program Part A

Lead Comply’s AML/CTF program design starts with Part A, not Part B. The governance framework must be established before the client identification procedures are built, because Part B must reflect the risk profile established in Part A.

For each real estate agency engagement, Lead Comply delivers a Part A that covers:

  • A direct, traceable link to the completed ML/TF Risk Assessment, with each identified risk addressed by a specific program control
  • A governance section that names the compliance officer, specifies the reporting line, and documents the principal’s accountability for the program
  • An employee due diligence procedure specifying which roles are screened, what checks are required, and how results are handled
  • A staff training section that specifies content, delivery method, who is covered, frequency, and how completion is recorded and retained
  • An AUSTRAC reporting procedure for SMRs, including the escalation path, the tipping off prohibition, and the documentation requirements
  • An ongoing monitoring procedure with clear triggers for client review and transaction escalation
  • An independent review procedure specifying the review scope, the review cycle, and how results are reported to management

Every Part A is written in plain English, reviewed with the principal before adoption, and formally adopted by the agency before 1 July 2026. The program is not a template. It is a document that reflects how the agency actually operates.

📋  WHAT GOES WRONG IN PRACTICE — WHAT LEAD COMPLY SEES
Three consistent failures appear in Part A documents when Lead Comply reviews agency programs:
1 — Part A is present as a heading structure only. The document contains the right section titles but no substantive content under each heading. A Part A with seven headings and two sentences per section does not meet the program requirements. AUSTRAC examiners assess the quality and substance of the program content, not just whether the required sections are present.
2 — The risk assessment and Part A are disconnected. The risk assessment concludes that the agency has a medium AML/CTF risk profile. Part A contains no reference to that finding and no explanation of how the program controls address the identified risks. Without that connection, Part A cannot demonstrate that it is based on the risk assessment as the AML/CTF Rules require.
3 — Part A has never been reviewed since it was created. The agency designed a program before 1 July 2026 and treated it as a permanent document. Staff have changed, client types have evolved, and AUSTRAC has issued new guidance — but the program still reflects the business as it was in June 2026. An unreviewed program is a program that no longer meets the requirements it was designed to satisfy.
✓  WHAT A COMPLIANT AML/CTF PROGRAM PART A LOOKS LIKE
Formally adopted by the agency before 1 July 2026 with principal sign-off. Based on a completed ML/TF Risk Assessment with traceable links between identified risks and controls. Governance section that names the compliance officer, specifies the reporting line, and documents principal accountability. Employee due diligence procedure that specifies which roles are screened and how. Staff training section covering content, delivery, frequency, scope, and documentation. SMR and AUSTRAC reporting procedure with escalation path and tipping off guidance. Ongoing monitoring triggers documented with clear escalation procedures. Independent review procedure with a defined review cycle and management reporting. Reviewed and updated at least annually and whenever the business changes materially
Frequently asked questions on AML/CTF Program Part A:

How long should Part A be?
— Length is not the measure. Content is. A defensible Part A for a small real estate agency typically runs 15 to 25 pages of substantive content. A two-page document with headings and one-sentence descriptions does not meet the standard.

Can we use a template for Part A?
— A template can provide structure. It cannot provide the content. The substantive content of Part A must reflect the agency’s actual risk profile, governance structure, and operational procedures.

Does every staff member need to read Part A?
— Part A must be accessible to all relevant staff. Not every staff member needs to read every section, but the training obligations, SMR escalation procedure, and applicable policies must be communicated to those they affect.

When does Part A need to be formally adopted?
— Before 1 July 2026 for agencies providing designated services from that date. Adoption requires formal sign-off from the principal or senior management — not just completion of the document.
Not sure your AML/CTF Program Part A is ready for 1 July 2026?

Book a free 30-minute Clarity Call with Lead Comply. In 30 minutes you will know whether your Part A addresses all seven required components, whether it is connected to your risk assessment, and whether it would hold up in an AUSTRAC examination.

📅 Request a Call


Leave a Reply

Your email address will not be published. Required fields are marked *