Plain English

The independent evaluation requirement, explained

What the reformed AML/CTF Act actually requires, who can perform an evaluation, and when yours is due.

Where it comes from


The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (as reformed) — section 26F(4)(f) — and section 5-10 of the AML/CTF Rules 2025: your AML/CTF policies must provide for periodic independent evaluations of your program. This sits alongside, not instead of, your own internal reviews.

What it must cover


  1. How your ML/TF risk assessment was undertaken or reviewed;
  2. Whether your AML/CTF policies are properly designed against the Act and Rules;
  3. Whether you've actually identified, managed and mitigated your risk — and complied with your own policies.

When


At least once every three years, at a frequency suited to your size and complexity. Many programs written for the 2026 reforms commit to a first evaluation within 12 months — check what yours says. No need to panic; completing it closes the open item.

Who can do it


AUSTRAC sets no mandatory qualification. The evaluator must be independent, must not have built or run your program, must not be your compliance officer, and must know the obligations and your sector.

In a small practice, nobody internal is distant enough — an external evaluator is the clean answer.

What it costs elsewhere


External AML/CTF consultants and law firms typically charge $150–$330+ per hour; big-firm reviews often run to many thousands. For a small, low-risk firm, a right-sized fixed fee is the sensible path.

Want your window and scope confirmed?

Bring your program document to a 20-minute call — I'll tell you when your evaluation is due and what it should cover.

Book a call