All industries

Five of the ten AML/CTF steps live in your systems. Here is how to check them

efex·14 August 2026·About 4 minutes
Five of the ten AML/CTF steps live in your systems. Here is how to check them

There are ten steps to AML/CTF readiness, and they split five and five. The first five belong to you and your advisers: working out whether the reforms apply to your firm, enrolling with AUSTRAC, appointing a compliance officer, completing a risk assessment, and writing the program that sets out how you will meet your obligations. The final five sit in the systems underneath, and they are the ones that decide whether the first five hold up when somebody asks you to show your work.

Most firms are further along on those last five than they expect. Very few could prove it. That gap is the thing worth knowing about, because the question is never whether you are doing the right thing. It is whether you can show it, at short notice, when requested.

To show you where you stand, we have built a free checklist. There are just thirteen questions, it takes about three minutes, and every question is tied to a specific obligation under either the Privacy Act or the AML/CTF Act. What comes back is a short written report you can put straight in front of your adviser or your compliance officer.

What the checklist covers

  • The strength of your cyber security. Who can still get into your systems, how identity documents reach you, what happens when someone clicks the wrong link, and whether a password on its own is enough.
  • Whether a suspicious matter report stays with the people who must see it. Where that paperwork is stored, who can open it, and whether that limit is set in the software or depends on each person remembering the rule.
  • Your ability to retain and retrieve records for seven years. Whether you could find every copy of one client’s ID, what you keep after verifying, everywhere a copy could be sitting right now, and what actually removes a scan once you no longer need it.
  • Your readiness for a cyber or data breach. Whether you could say who opened a client’s file and when, and what happens in the first hour after a breach comes to light.
  • Whether your people know what to do with highly sensitive data. What the person who opens the general inbox does with a passport photo.

The thirteen things the checklist reviews

Each of the thirteen is one thing that is either set up in your systems or is not, and each is on the list because it is the difference between believing something is handled and being able to show it. Twelve sit inside one of the five steps above. The thirteenth asks whether all five get looked at again once they are in place, because most of what fails here fails quietly, months after somebody set it up correctly.

Your report names the obligation behind each one, so you can hand the page over rather than explain it.

  • 01 Know where data lives
  • 02 Collect only what is needed
  • 03 Store records securely
  • 04 Limit access to sensitive information
  • 05 Encrypt sensitive data
  • 06 Defend against cyber threats
  • 07 Log and monitor activity
  • 08 Retain and recover records
  • 09 Protect suspicious-matter information
  • 10 Be ready for incidents
  • 11 Secure your systems
  • 12 Build staff cyber awareness
  • 13 Review systems regularly

What one answer turns into

Take the first one, know where data lives. The question is whether you could find every copy of a client's ID if they rang today and asked. The answer we hear most often is most of them, but I would have to go looking, which reads as partly in place. Your report then gives you this:

Search your mailbox for the word licence, filter to attachments, and count what comes back.

An honest answer, what it means, and one thing you can do in the next ten minutes without us, a budget or a meeting. Thirteen of those. That search is worth running.

What you get back

An overview of the controls already in place, and a written findings report: your three highest priorities in order of impact, the obligation behind each one so you can hand the page to your adviser, and something you can do right now.

It takes just three minutes

Every question is multiple choice. Nothing is looked up, nothing is uploaded, no client file is opened. You can answer the whole thing sitting where you are right now.

Where you stand

At the end of it you have a written record of where your firm stands on the five steps that sit in your systems, the obligation behind each gap, and a short list of what to do about them.

Start the checklist here.

Back to News and Resources

Thirteen questions. About three minutes. No client files.

Or talk it through first. Thirty minutes, no obligation, with somebody who does this work every day.

These articles explain what the regulators have published and what it commonly means in practice. General information only, not legal or compliance advice.