All industries

The 10 steps to AML/CTF readiness, and the 5 we can help with

efex·24 August 2026·About 3 minutes
The 10 steps to AML/CTF readiness, and the 5 we can help with

There are ten steps to being ready. Five are decisions for your business and your advisers. The other five are about the technology those decisions run on: the email, file storage, practice software and backups that actually hold your clients' identity documents. This page has both, and names who to call for the five that are not ours.

The five related to your systems

06

Strengthen your cyber security

The systems holding client identity and due diligence data are configured to keep people out, and watched for the times someone gets in.

In place looks like: multi-factor authentication on every account, no shared logins, and somebody watching for the alerts around the clock rather than only in office hours.

07

Apply tipping-off controls

Information about a suspicious matter is restricted to the people authorised to see it, and the restriction is held by the system.

In place looks like: a defined list of people who can open it, logged access, and nothing sitting in a shared inbox.

08

Secure your records for 7 years

Records of verification have to survive seven years and still be findable, readable and unaltered.

In place looks like: one place they live, encrypted, with retention that runs on its own rather than on someone remembering.

09

Be ready for a cyber or data breach

If client data is exposed, the assessment and any notification to the OAIC must happen within thirty days. The work is deciding who does what before the day arrives.

In place looks like: a written incident response plan with names in it, and records complete enough to tell you what was actually reached.

10

Train your people

The people who handle identity documents know what to do with them, and know that a suspicious matter is never mentioned to the client it concerns.

In place looks like: training on phishing, identity documents, tipping off and breach escalation, with a record of who completed it and when, repeated rather than done once.

The five that are not ours

efex does not do these five. Here is where firms usually go for them.

StepWhere firms usually go
01 Confirm if you are capturedAUSTRAC's designated services list, and your own legal adviser
02 Enrol with AUSTRACAUSTRAC directly
03 Appoint an AML/CTF Compliance OfficerAn internal senior appointment. Your professional body may have guidance on who qualifies
04 Complete a risk assessmentAn AML/CTF consultant or your legal adviser
05 Build your AML/CTF programAn AML/CTF consultant, your legal adviser, or your professional body's template

We built a free readiness checklist so you can work out where your firm stands today. Twelve of the thirteen questions sit inside steps 06 to 10. The thirteenth asks whether all five get looked at again once they are set up.

We do the technology half, your adviser does the rest.

Check where you stand: thirteen questions and just three minutes start the checklist.

Back to News and Resources

Thirteen questions. About three minutes. No client files.

Or talk it through first. Thirty minutes, no obligation, with somebody who does this work every day.

These articles explain what the regulators have published and what it commonly means in practice. General information only, not legal or compliance advice.