Case study: a 119-page AML/CTF program in three days
How we built a seven-document AML/CTF compliance pack for a small accounting practice in three days, working from 31 confirmed assumptions.
In the week the 1 July 2026 deadline landed, a small accounting practice came to us. A handful of staff, a mix of individual tax, company and trust work, SMSF establishments, and some corporate secretarial services. They had known the AML/CTF reforms were coming but had not had room to act on them; tax season does not leave much space for compliance projects.
Three days later they had a finalised, seven-document compliance pack: 119 pages covering risk assessment, policy, process document, customer due diligence forms, implementation checklist, assumptions register, and a compliance traceability matrix mapping every AUSTRAC obligation to where their documents address it. Every assumption confirmed by the directors. Ready for implementation.
This post is the record of that engagement: what the law now requires, how the pack was built, and what the client’s side of the work looked like. It is a case study, not a service page.
Who is actually caught by the new AML/CTF rules?
Since 1 July 2026, accountants who provide certain services have been reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act. Not all accountants, and not all services. The trigger is providing one of the professional services listed in table 6 of the Act, and AUSTRAC’s guidance on professional designated services spells them out: assisting in the creation or restructuring of companies and trusts, selling shelf companies, assisting with equity or debt financing, acting (or arranging for someone to act) in roles within a company or trust, and providing a registered office or principal place of business address. SMSF establishment can be caught too, because it involves setting up the underlying trust. Real estate agents and settlement agents came into scope on the same date under their own designated services list.
The obligations are not theoretical. A reporting entity needs a written AML/CTF program covering risk assessment, a compliance policy, documented procedures for customer due diligence, ongoing monitoring, and suspicious matter reporting. It needs an appointed AML/CTF compliance officer. Records must be kept for seven years. And the whole program faces an independent evaluation, on a staggered timetable set by the transitional rules: for the earliest cohort of newly regulated businesses, by 30 June 2029.
Most small practices we had spoken to before the deadline fell into one of three camps: they had not heard of it, they had heard of it and assumed it was a tick-box exercise, or they had looked at the AUSTRAC guidance and did not know where to start. This practice was in a fourth camp, probably the most common of all: aware of the obligation, out of runway. None of those positions got more comfortable when the deadline arrived. The honest task at that point is closing the gap quickly, not pretending the date was met.
How was the program built in three days?
By inverting the usual process: instead of starting with questions for the client, we started with assumptions about the client. The conventional sequence for compliance work is interview, questionnaire, wait for answers, draft, send for review, revise, repeat. For a small practice, that sequence takes weeks, and most of the elapsed time is waiting. We ran it the other way around.
Step 1: we researched the practice. We reviewed the firm’s website, ASIC registrations, service offerings, and public profile, and from that built a detailed set of assumptions about its structure, designated services, client base, risk profile, and operational model. For this practice, that came to 31 assumptions, covering everything from which table 6 services they provide to which screening software they use. Everything came from public sources; no client files or client identities were involved at any point. (For how we think about what does and does not get sent to an AI tool, see What happens to your data when you press ‘Send’.)
Step 2: we built the full program. Using those assumptions as the foundation, we constructed all seven documents: risk assessment, policy, processes, forms, implementation plan, compliance matrix, and the assumptions register itself. This is where AI carried the load. Drafting seven cross-referencing documents against a fixed set of obligations is exactly the work a well-directed language model does in hours and a human team does in weeks. The architecture (which documents exist, what the assumptions register feeds, what the traceability matrix has to prove) and the page-by-page review were ours. That division of labour is the whole method.
Step 3: the directors reviewed the assumptions. The firm received the complete pack with the assumptions register at the front. Their job was to read each assumption and mark it confirmed, amended, or removed, telling us what was different where something was wrong. The directors worked through the register over a couple of hours and workshopped it between themselves. Their total time commitment across the engagement was two to four hours.
Step 4: we updated and finalised. The amendments flowed through all seven documents, the pack was re-verified for internal consistency, and the finalised version went back the same day.
The inversion matters more than the speed. Instead of the client answering abstract compliance questions (“What is your risk appetite for customer due diligence?”), they reviewed concrete statements about their own practice (“The practice uses Annature for identity verification, sanctions screening and PEP screening”). That is a different conversation: faster, more accurate, and far less dependent on the client learning AML/CTF jargon first.
What did the practice actually receive?
Seven documents, each with a specific job:
Compliance traceability matrix. Maps every AUSTRAC obligation to where the program addresses it. This is the document the independent evaluator will work from when the first evaluation falls due.
Assumptions register. The foundation layer: every factual assumption about the practice, confirmed by the directors. When the legislation changes or the practice evolves, this is what gets updated first; the downstream documents follow.
Business-wide risk assessment. Identifies money laundering, terrorism financing, and proliferation financing risks across five dimensions: customer, service, delivery channel, country, and new technology. Each risk carries existing controls and a residual risk score.
AML/CTF compliance policy. The governing document: roles, responsibilities, risk appetite, customer due diligence thresholds, reporting obligations, record retention, training requirements, and the independent evaluation schedule.
AML/CTF process document. The operational playbook: step-by-step procedures for onboarding, standard, simplified, and enhanced customer due diligence, sanctions and PEP screening, ongoing monitoring, suspicious matter reporting, and annual reviews.
Customer due diligence forms. Ready-to-use forms for individuals, companies, trusts, and SMSFs, supplementing (not replacing) the practice’s existing onboarding process.
Implementation checklist. A phased rollout plan: what to do immediately, what to do in the first 90 days, and what to schedule as ongoing compliance.
Every document cross-references the others. The policy says what the practice will do; the process says how; the forms capture the evidence; the checklist says when; and the matrix proves nothing was missed.
What was our role, and what was it not?
We did compliance program development: we built the documents, structured the risk assessment, mapped the obligations, and produced the operational procedures. The practice reviewed, confirmed, and adopted the program as its own.
This was not legal advice, and nothing in this post is. We do not interpret the law for specific client situations, we do not say whether a particular transaction triggers a suspicious matter report, and we do not make judgement calls about individual client risk ratings. Those decisions belong to the practice’s AML/CTF compliance officer; the documents give that officer the framework and the decision criteria to make them.
The source material is entirely public: the AML/CTF Act 2006 as amended in 2024, the AML/CTF Rules 2025, AUSTRAC’s published reform guidance and sector starter kits, national risk assessments, and FATF publications. AUSTRAC has been explicit that reporting entities are expected to build their own programs; the starter kits exist for exactly that reason. What we brought was structure, speed, and consistency, not a substitute for the practice’s own accountability for its obligations.
Does PAC sell this as a service?
No. This was a scoped, one-off engagement, and we have not turned it into a standing AML/CTF product. What carries forward is the architecture, because nothing about it is specific to AML/CTF.
An assumptions register at the foundation. A set of documents that flow from it. A traceability matrix on top that proves the documents cover the obligations. When the practice changes (a new service line, new staff, new software), you update the assumptions and flow the changes through; when the legislation changes, the same. That pattern is what we call the Compliance engine, and it fits any regulated practice that has to demonstrate its documents cover its obligations, whichever regulator sits behind them.
The reason this case study is worth writing up is not the AML/CTF content. It is the shape of the work: research first, assumptions before questions, AI for drafting horsepower, human judgement on architecture and review, and a client whose total time cost was an afternoon. The same research-first approach is how we analyse any business before recommending anything: see AI audit that starts with your business.
If you run a professional practice and want that kind of engineering pointed at your own regulated workflows, see how we work with professional services practices in Perth. Or start with a conversation.