
Here’s a question worth sitting with honestly: if your nominated AML/CTF Compliance Officer resigned tomorrow, or was suddenly unavailable for an extended period, would your program keep functioning, or would it quietly stall while everyone waited to work out what happens next? For a role this central to your entire program, “we’ll figure it out when it happens” is a genuinely risky plan, and it’s one a surprising number of agencies are running on without realising it.
Here’s what actually needs to survive a change in who holds this role, and how to plan for it properly.
Why this role is a single point of failure by default
In a small agency, the Compliance Officer is often one specific person, frequently the principal themselves. That’s entirely appropriate for the size of the business, and we’ve covered why proportionate governance makes sense for smaller agencies elsewhere in this series. But it also means, unless you’ve deliberately planned otherwise, your entire program’s day to day accountability rests on one individual continuing to be present, engaged, and available.
That’s fine right up until it isn’t. People resign, get sick, take extended leave, or simply move on to other opportunities, all for entirely ordinary reasons that have nothing to do with your business or your program. The question isn’t whether this will eventually happen, over time it almost certainly will in some form, it’s whether your agency has thought about it before it does.
What actually needs to transfer
Succession isn’t just handing someone a new title. Several distinct things need to move together for the transition to actually work.
The formal nomination itself. Your Compliance Officer is someone AUSTRAC has been told about as part of your agency’s enrolment, and when that person changes, AUSTRAC needs to be kept informed of who currently holds the role. This isn’t optional paperwork, it’s making sure the regulator’s own records match reality.
Genuine knowledge of the program’s current state. Not just where the documents live, but an actual understanding of what’s been updated recently, what’s scheduled (an independent review that’s coming up, a risk assessment update that’s overdue), and any issues that were being actively managed at the point of handover.
Access to records and systems. If the outgoing Compliance Officer was the only person with meaningful access to your record keeping system, your training records, or your document version history, that access needs to transfer cleanly, not get tangled up in deactivated accounts and forgotten passwords.
The relationships staff actually rely on. Remember the escalation principle from earlier in this series, a junior agent needs to know exactly who to call if something seems off. If that person changes without staff being told clearly, you’ve quietly broken your own escalation path, even if the paperwork says otherwise.
Building a genuine backup, not just a plan for later
The strongest protection against this risk isn’t a lengthy succession document, it’s identifying at least one other person in your agency who has enough visibility into the program to step in immediately if needed, even if they’re not formally the Compliance Officer day to day. This person doesn’t need full expertise on day one, they need enough continuity, knowing where things are, understanding roughly what’s currently in progress, having genuine access to records, so that nothing goes dark the moment the primary person is unavailable.
This is exactly why the centralised, business owned record keeping we’ve covered separately matters so much here. Succession planning isn’t really a separate task from good record keeping, it’s largely the natural consequence of doing record keeping properly in the first place. If your system already survives staff turnover at the records level, a genuine handover at the Compliance Officer level becomes far more achievable.
A worked comparison
One agency’s sole Compliance Officer, also the principal’s second in charge, resigns with two weeks’ notice to take a role elsewhere. Records were kept largely in her own email and a personal cloud account. Training logs existed, but only she knew exactly how they were organised. When she leaves, the agency spends the better part of a month reconstructing where things stand, effectively running without functioning oversight during that gap.
A second agency faces an identical departure, but records had always lived in a shared, business owned system, and a second staff member had genuine visibility into the program’s current state, not as a formality, but through actual periodic involvement. The handover takes days, not weeks, and the program keeps functioning through the transition rather than stalling.
Neither agency did anything wrong in hiring or in day to day operations. Only one of them had actually planned for the ordinary reality that people leave jobs.
For genuinely small agencies and sole traders
If you’re a sole trader or an agency of two or three people, formal succession planning can feel like it’s designed for a much larger business. The proportionate version for a small agency is simpler: at minimum, think through what happens if you’re unavailable due to illness or leave, not just resignation. Does anyone else know where your records are kept, or who to contact at AUSTRAC if something urgent comes up while you’re away? Even a brief, written note covering this is worth having, precisely because the risk doesn’t disappear just because your business is small, it just looks different in scale.
Where Lead Comply fits into this
The Lead Comply AML Portal’s role based permissions structurally support genuine succession, since access to records and workflows isn’t tied to any single person’s personal login, it belongs to your agency’s business account. That means when a Compliance Officer changes, whether planned or sudden, the underlying system doesn’t need to be rebuilt from scratch by whoever steps in next.
If you’re not sure whether your current setup would genuinely survive a change in who holds this role, that’s exactly the kind of question our free 30 minute Compliance Gap Audit is built to answer honestly, before you’re forced to find out the hard way.
Create your free account and book No Obligation Compliance Gap Audit→ Lead Comply AML Portal