The 10 steps to AML/CTF readiness, and the 5 we can help with
·24 August 2026·About 3 minutes
There are ten steps to being ready. Five are decisions for your business and your advisers. The other five are about the technology those decisions run on: the email, file storage, practice software and backups that actually hold your clients' identity documents. This page has both, and names who to call for the five that are not ours.
The five related to your systems
Strengthen your cyber security
The systems holding client identity and due diligence data are configured to keep people out, and watched for the times someone gets in.
In place looks like: multi-factor authentication on every account, no shared logins, and somebody watching for the alerts around the clock rather than only in office hours.
Apply tipping-off controls
Information about a suspicious matter is restricted to the people authorised to see it, and the restriction is held by the system.
In place looks like: a defined list of people who can open it, logged access, and nothing sitting in a shared inbox.
Secure your records for 7 years
Records of verification have to survive seven years and still be findable, readable and unaltered.
In place looks like: one place they live, encrypted, with retention that runs on its own rather than on someone remembering.
Be ready for a cyber or data breach
If client data is exposed, the assessment and any notification to the OAIC must happen within thirty days. The work is deciding who does what before the day arrives.
In place looks like: a written incident response plan with names in it, and records complete enough to tell you what was actually reached.
Train your people
The people who handle identity documents know what to do with them, and know that a suspicious matter is never mentioned to the client it concerns.
In place looks like: training on phishing, identity documents, tipping off and breach escalation, with a record of who completed it and when, repeated rather than done once.
The five that are not ours
efex does not do these five. Here is where firms usually go for them.
| Step | Where firms usually go |
|---|---|
| 01 Confirm if you are captured | AUSTRAC's designated services list, and your own legal adviser |
| 02 Enrol with AUSTRAC | AUSTRAC directly |
| 03 Appoint an AML/CTF Compliance Officer | An internal senior appointment. Your professional body may have guidance on who qualifies |
| 04 Complete a risk assessment | An AML/CTF consultant or your legal adviser |
| 05 Build your AML/CTF program | An AML/CTF consultant, your legal adviser, or your professional body's template |
We built a free readiness checklist so you can work out where your firm stands today. Twelve of the thirteen questions sit inside steps 06 to 10. The thirteenth asks whether all five get looked at again once they are set up.
We do the technology half, your adviser does the rest.
Check where you stand: thirteen questions and just three minutes start the checklist.
Thirteen questions. About three minutes. No client files.
Or talk it through first. Thirty minutes, no obligation, with somebody who does this work every day.
These articles explain what the regulators have published and what it commonly means in practice. General information only, not legal or compliance advice.
