"
Compliance

Building your AML/CTF program: a guide to Part A and Part B

28 May 2026 8 min read
In short

AUSTRAC requires a written, two-part AML/CTF program. Part A assesses your ML/TF risk and sets controls; Part B defines how you identify and monitor customers. Treat it as a living framework — and make sure your day-to-day practice matches what it says.

Once you are a reporting entity, AUSTRAC requires a written, two-part AML/CTF program. Part A identifies and manages your money-laundering and terrorism-financing risk; Part B sets out how you know your customers. Here is how to structure both.

Why a two-part program?

The AML/CTF program is the backbone of your compliance — the document AUSTRAC expects to see if it ever asks how you manage risk, and what turns a set of obligations into a repeatable, defensible process. The regime splits it into two parts because they answer two different questions:

Part A

What is our risk?

Identify and manage the ML/TF risk your business faces, and the controls that respond to it.

Part B

How do we verify customers?

The customer identification, verification and due-diligence procedures you actually apply.

Part A: risk assessment & controls

Part A is where you assess the ML/TF risk your business faces and document the controls that manage it. A robust Part A considers risk across four factors:

  • Customer types — including higher-risk categories such as PEPs and complex ownership structures
  • Products and services — which designated services carry the most risk
  • Delivery channels — face-to-face versus remote onboarding
  • Jurisdictions — the countries your customers and transactions touch

From that assessment, Part A sets out your controls: governance and oversight, your risk-based approach to due diligence, employee due diligence and training, independent review, and the role of your compliance officer.

Part B: customer due diligence

Part B sets out the customer identification and verification procedures you apply before providing a designated service. At a minimum it covers:

  • Know Your Customer (KYC) — collecting and verifying identity for customers and beneficial owners
  • Ongoing due diligence — keeping information current and monitoring the relationship
  • Enhanced due diligence (EDD) — extra steps for higher-risk customers identified in Part A
  • Sanctions and PEP screening — checking customers against the relevant lists
A common mistake

Treating Part A and Part B as a one-off writing exercise. A good program is a living framework: your risk assessment should be reviewed as your business, customers and the regulatory environment change.

From document to operation

The hardest part is not writing the program — it is operating it consistently. Every customer onboarded, every screen run, every monitoring alert reviewed and every report filed needs to align with what your program says, and needs to be evidenced. That audit trail is exactly what demonstrates compliance if AUSTRAC asks.

This is where purpose-built software earns its place: it turns the policies in Part A and Part B into guided workflows, applies your risk-based rules automatically, and logs every decision so your written program and your actual practice never drift apart.

Key takeaways

  • AUSTRAC requires a written program in two parts: A (risk) and B (due diligence).
  • Part A weighs risk across customers, services, channels and jurisdictions.
  • Part B covers KYC, ongoing and enhanced due diligence, and screening.
  • Keep it a living framework — and make sure practice matches the document.

Turn your program into guided workflows

AMLyticsAI operationalises Part A and Part B — applying your risk rules automatically and logging every decision for audit.

Explore the platform
← Back to all articles