Building 7 min read

Case study: a 119-page AML/CTF program in three days

How we built a seven-document AML/CTF compliance pack for a small accounting practice in three days, working from 31 confirmed assumptions.

In the week the 1 July 2026 deadline landed, a small accounting practice came to us. A handful of staff, a mix of individual tax, company and trust work, SMSF establishments, and some corporate secretarial services. They had known the AML/CTF reforms were coming but had not had room to act on them; tax season does not leave much space for compliance projects.

Three days later they had a finalised, seven-document compliance pack: 119 pages covering risk assessment, policy, process document, customer due diligence forms, implementation checklist, assumptions register, and a compliance traceability matrix mapping every AUSTRAC obligation to where their documents address it. Every assumption confirmed by the directors. Ready for implementation.

This post is the record of that engagement: what the law now requires, how the pack was built, and what the client’s side of the work looked like. It is a case study, not a service page.

Who is actually caught by the new AML/CTF rules?

Since 1 July 2026, accountants who provide certain services have been reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act. Not all accountants, and not all services. The trigger is providing one of the professional services listed in table 6 of the Act, and AUSTRAC’s guidance on professional designated services spells them out: assisting in the creation or restructuring of companies and trusts, selling shelf companies, assisting with equity or debt financing, acting (or arranging for someone to act) in roles within a company or trust, and providing a registered office or principal place of business address. SMSF establishment can be caught too, because it involves setting up the underlying trust. Real estate agents and settlement agents came into scope on the same date under their own designated services list.

The obligations are not theoretical. A reporting entity needs a written AML/CTF program covering risk assessment, a compliance policy, documented procedures for customer due diligence, ongoing monitoring, and suspicious matter reporting. It needs an appointed AML/CTF compliance officer. Records must be kept for seven years. And the whole program faces an independent evaluation, on a staggered timetable set by the transitional rules: for the earliest cohort of newly regulated businesses, by 30 June 2029.

Most small practices we had spoken to before the deadline fell into one of three camps: they had not heard of it, they had heard of it and assumed it was a tick-box exercise, or they had looked at the AUSTRAC guidance and did not know where to start. This practice was in a fourth camp, probably the most common of all: aware of the obligation, out of runway. None of those positions got more comfortable when the deadline arrived. The honest task at that point is closing the gap quickly, not pretending the date was met.

How was the program built in three days?

By inverting the usual process: instead of starting with questions for the client, we started with assumptions about the client. The conventional sequence for compliance work is interview, questionnaire, wait for answers, draft, send for review, revise, repeat. For a small practice, that sequence takes weeks, and most of the elapsed time is waiting. We ran it the other way around.

Step 1: we researched the practice. We reviewed the firm’s website, ASIC registrations, service offerings, and public profile, and from that built a detailed set of assumptions about its structure, designated services, client base, risk profile, and operational model. For this practice, that came to 31 assumptions, covering everything from which table 6 services they provide to which screening software they use. Everything came from public sources; no client files or client identities were involved at any point. (For how we think about what does and does not get sent to an AI tool, see What happens to your data when you press ‘Send’.)

Step 2: we built the full program. Using those assumptions as the foundation, we constructed all seven documents: risk assessment, policy, processes, forms, implementation plan, compliance matrix, and the assumptions register itself. This is where AI carried the load. Drafting seven cross-referencing documents against a fixed set of obligations is exactly the work a well-directed language model does in hours and a human team does in weeks. The architecture (which documents exist, what the assumptions register feeds, what the traceability matrix has to prove) and the page-by-page review were ours. That division of labour is the whole method.

Step 3: the directors reviewed the assumptions. The firm received the complete pack with the assumptions register at the front. Their job was to read each assumption and mark it confirmed, amended, or removed, telling us what was different where something was wrong. The directors worked through the register over a couple of hours and workshopped it between themselves. Their total time commitment across the engagement was two to four hours.

Step 4: we updated and finalised. The amendments flowed through all seven documents, the pack was re-verified for internal consistency, and the finalised version went back the same day.

The inversion matters more than the speed. Instead of the client answering abstract compliance questions (“What is your risk appetite for customer due diligence?”), they reviewed concrete statements about their own practice (“The practice uses Annature for identity verification, sanctions screening and PEP screening”). That is a different conversation: faster, more accurate, and far less dependent on the client learning AML/CTF jargon first.

What did the practice actually receive?

Seven documents, each with a specific job:

Compliance traceability matrix. Maps every AUSTRAC obligation to where the program addresses it. This is the document the independent evaluator will work from when the first evaluation falls due.

Assumptions register. The foundation layer: every factual assumption about the practice, confirmed by the directors. When the legislation changes or the practice evolves, this is what gets updated first; the downstream documents follow.

Business-wide risk assessment. Identifies money laundering, terrorism financing, and proliferation financing risks across five dimensions: customer, service, delivery channel, country, and new technology. Each risk carries existing controls and a residual risk score.

AML/CTF compliance policy. The governing document: roles, responsibilities, risk appetite, customer due diligence thresholds, reporting obligations, record retention, training requirements, and the independent evaluation schedule.

AML/CTF process document. The operational playbook: step-by-step procedures for onboarding, standard, simplified, and enhanced customer due diligence, sanctions and PEP screening, ongoing monitoring, suspicious matter reporting, and annual reviews.

Customer due diligence forms. Ready-to-use forms for individuals, companies, trusts, and SMSFs, supplementing (not replacing) the practice’s existing onboarding process.

Implementation checklist. A phased rollout plan: what to do immediately, what to do in the first 90 days, and what to schedule as ongoing compliance.

Every document cross-references the others. The policy says what the practice will do; the process says how; the forms capture the evidence; the checklist says when; and the matrix proves nothing was missed.

What was our role, and what was it not?

We did compliance program development: we built the documents, structured the risk assessment, mapped the obligations, and produced the operational procedures. The practice reviewed, confirmed, and adopted the program as its own.

This was not legal advice, and nothing in this post is. We do not interpret the law for specific client situations, we do not say whether a particular transaction triggers a suspicious matter report, and we do not make judgement calls about individual client risk ratings. Those decisions belong to the practice’s AML/CTF compliance officer; the documents give that officer the framework and the decision criteria to make them.

The source material is entirely public: the AML/CTF Act 2006 as amended in 2024, the AML/CTF Rules 2025, AUSTRAC’s published reform guidance and sector starter kits, national risk assessments, and FATF publications. AUSTRAC has been explicit that reporting entities are expected to build their own programs; the starter kits exist for exactly that reason. What we brought was structure, speed, and consistency, not a substitute for the practice’s own accountability for its obligations.

Does PAC sell this as a service?

No. This was a scoped, one-off engagement, and we have not turned it into a standing AML/CTF product. What carries forward is the architecture, because nothing about it is specific to AML/CTF.

An assumptions register at the foundation. A set of documents that flow from it. A traceability matrix on top that proves the documents cover the obligations. When the practice changes (a new service line, new staff, new software), you update the assumptions and flow the changes through; when the legislation changes, the same. That pattern is what we call the Compliance engine, and it fits any regulated practice that has to demonstrate its documents cover its obligations, whichever regulator sits behind them.

The reason this case study is worth writing up is not the AML/CTF content. It is the shape of the work: research first, assumptions before questions, AI for drafting horsepower, human judgement on architecture and review, and a client whose total time cost was an afternoon. The same research-first approach is how we analyse any business before recommending anything: see AI audit that starts with your business.

If you run a professional practice and want that kind of engineering pointed at your own regulated workflows, see how we work with professional services practices in Perth. Or start with a conversation.

Published 4 July 2026

Perth AI Consulting delivers AI opportunity analysis for small and medium businesses. Start with a conversation.

Prepared by Claude, directed and approved by PAC.

More from Thinking

Evaluation 11 min read

AI in property valuation: the evidence, the design rules, and what it could become

The best Australian evidence on vision AI in valuation measures a different task than the one vendors demo. The findings, and the design rules that follow.

Evaluation 7 min read

Eleven cells moved. Here is what they mean for your business.

Reading the September 2026 State of AI verdict table: what improved, what declined, and what to do differently this quarter.

Evaluation 7 min read

Competitor intelligence for small business: what AI can and cannot see

What AI-assisted competitor intelligence really is for a small business: the public sources worth watching, what they cannot tell you, and the legal line.

Evaluation 10 min read

AI in regulated professional work, Mid-2026

One structure links family law, valuation, and building inspections: a signed document others rely on. How each field's regulator answered the AI question.

Technical 9 min read

The business knowledge base: evidence, risks, and how to build one

What a business knowledge base actually is, what the evidence says it delivers, the security and privacy realities, and how we build one that holds up.

Evaluation 8 min read

What AI can see in your customer data (and what it cannot)

What AI can genuinely find in the customer records an SME already holds, what it cannot, and when a spreadsheet honestly beats a model.

Building 7 min read

What an AI quoting engine actually does

What an AI quoting engine takes in, what it drafts, what the evidence says about accuracy and speed, and why the final price stays with a human.

Adoption 6 min read

Australia's AI adoption gap is bigger than the 12% headline suggests

ABS says 12% of Australian businesses use AI. The real story is 35% of large businesses against 11% of small ones, and the barrier isn't the technology.

Building 7 min read

Why we let AI run the interviews (and why we never let it pretend to be human)

AI-conducted interviews compress weeks of stakeholder discovery into days, standardise what gets asked, and lower the guard that distorts honest answers.

Adoption 14 min read

How AI capability actually moves through a business

The decisive variable in SME AI adoption is the human absorption sequence, not the tooling. A working framework from observation across WA businesses.

Evaluation 7 min read

AHPRA advertising rules for psychologist websites

Recovery stories, 'specialist', 'clinical psychologist', and endorsement titles are where psychology sites breach the National Law. A practical read-through.

Adoption 4 min read

Customer service AI has finally grown up

Chatbots and AI receptionists earned their bad reputation. What changed, and how the mature version answers every call without replacing anyone.

Evaluation 6 min read

Who can use the titles 'Dr', 'Specialist', and 'Surgeon'?

AHPRA restricts 'specialist' and 'surgeon' to specific registrations, and 'Dr' has its own rule. What health practice websites can and cannot claim.

Adoption 5 min read

Your best people hate writing reports

The operators you promote are brilliant at the work and allergic to reporting. A scheduled AI call interviews them, drafts the briefing, they approve it.

Building 6 min read

Your website isn't just for humans anymore

How to build a chatbot that keeps itself up to date, can't leak client information, and won't answer beyond what you've published.

Evaluation 7 min read

Can you show Google reviews on your health practice website?

AHPRA bans clinical testimonials, even true ones, but service reviews are fine. What that means for the Google reviews widget on your practice site.

Evaluation 7 min read

What AHPRA's advertising rules mean for your website

Your practice website is advertising under the National Law. What AHPRA's rules prohibit, who is responsible, and how to check your own site.

Evaluation 8 min read

Is it safe to paste client data into ChatGPT?

Short answer: it depends on one setting, and most people have it wrong. What ChatGPT, Claude and Copilot do with your data, and what the Privacy Act expects.

Evaluation 4 min read

What a good AI audit actually delivers

The audit report named one recommendation specific enough to check, and what the Build that followed looked like: one real engagement, generalised.

Evaluation 7 min read

AI and video, Mid-2026: the models can watch now, not just listen

AI could always transcribe video. It can now read the frames as well, and every hour of footage a business owns becomes something it can question.

Building 11 min read

From evidence base to delivery: a production AI methodology

How we delivered 34 evidence-anchored AI briefings to a WA peer-advisory chapter: fact-checked literature review, multi-agent verification, one method.

Technical 9 min read

The six functions of a working AI system

A working AI system is six functions doing six jobs. When all six connect, hallucinations get caught, outputs hold steady, and models become swappable.

Technical 7 min read

Supervised autonomy: the middle path for AI architecture

Between drafts you approve and agents you hope about sits the middle path: an envelope of authorised routine work, supervised, audited, and yours to widen.

Evaluation 5 min read

The state of applied AI in Mid-2026

Our literature review of applied AI in mid-2026: ten capability categories, three fact-check passes, written for operational leaders.

Technical 9 min read

How to design a PHI redaction system for clinical AI

PHI redaction is part of a clinical AI tool's architecture, not a feature you add. What the literature says it should look like, and how we built it.

Building 9 min read

How we built on-device de-identification so AI never sees real names

Most AI privacy is a policy. Ours is architecture: an NER model runs in the browser and strips names before anything leaves the device.

Technical 7 min read

Your agency's clients are about to ask why this costs so much

A solo consultant built in three weeks what your agency quoted twelve for. The client doesn't know why yet. The agencies that survive change what they sell.

Adoption 6 min read

What do you love doing? What do you hate doing?

Ask people what they love doing and what they hate doing, then show them AI is coming for the second list. Why the reframe works, and how it fails.

Technical 7 min read

Why I don't use n8n (and what I do instead)

n8n demos well. But a compelling demo and a reliable production system are different things, and the distance between them is where businesses get hurt.

Technical 10 min read

Your codebase was not built for AI. That's the actual problem.

Amazon's mandatory meeting about AI breaking production is an architecture story: codebases built for human maintainers only, now maintained by AI.

Adoption 4 min read

Your team has AI licences. You don't have an AI system.

Fifteen people, fifteen separate AI accounts, no shared context. The problem isn't the tool; it's the architecture around it. Here's the fix.

Building 7 min read

Your $2,000 day starts the night before: our system keeps you on the tools, not on the phone

Optimised routes overnight, automatic customer notifications, and promises the system keeps or corrects. A scheduling system that protects your daily rate.

Evaluation 4 min read

The fastest way for an executive to get across AI

AI moves faster than any executive can track. One focused conversation, one written report, and a decision you can act on: your time stays on the business.

Building 6 min read

Your IT department will take 18 months. You need this working by next quarter.

Senior leaders know what they need built; the gap is time. A prototype gets the tool working now and hands IT a validated blueprint for later.

Building 8 min read

We built an AI invoice verifier. Here's where it hits a wall.

We built an AI invoice verifier and watched a fake beat a real invoice. Why document analysis alone cannot stop fraud, and the five layers that can.

Building 5 min read

How to build an AI chatbot that doesn't lie to your customers

Woolworths scripted its AI to talk about its mother. The business fix is honesty; the technical fix is architecture that prevents fabrication by design.

Technical 9 min read

Why AI safety features are load-bearing architecture, not political decoration

The 'woke AI' label came from real failures, but they were engineering failures, not safety failures. The difference matters wherever errors have consequences.

Adoption 3 min read

Woolworths' AI told a customer it had a mother. That's a problem.

Woolworths' AI assistant Olive was scripted to talk about its mother and uncle. When callers realised, trust broke instantly. The fix is honesty.

Evaluation 5 min read

Google is no longer the only way your customers find you

Customers now find businesses through ChatGPT, Perplexity, and Gemini. The sites AI cites are structured differently to the sites Google ranks.

Evaluation 6 min read

The personal workflow analysis: what watching a real workday reveals about automation

People describe the work they value, not the work that eats their time. Recording a real workday reveals the automation opportunities interviews miss.

Evaluation 11 min read

An AI audit that starts with your business

How an operations-first AI audit works: what it looks for, how the evidence is collected, what the report contains, and what it tells you to skip.

Building 6 min read

What production AI teaches you that demos never will

The gap between a demo and a working system is where the useful lessons live. Architecture, framing, privacy, adoption: the patterns repeat every time.

Adoption 6 min read

The psychology of why your team won't use AI

You buy the tool, run the demo, and three months later nobody is using it. Five predictable psychological barriers, each with a strategy that works.

Technical 4 min read

Stop telling AI what NOT to do (and what to say instead)

Instructions built on prohibitions make AI cautious and generic. Describing what you want instead transforms the output, and the reason comes from psychology.

Building 5 min read

How we turned generic AI into a specialist: and what that means for your business

Mediocre AI output is rarely the model's fault. Three structural changes that turn the same model from generic to specialist-grade.

Evaluation 6 min read

Your business has 9 customer touchpoints. AI can fix the 6 you're dropping.

You pay to get customers to your door, then lose them to missed follow-up. AI can handle the six touchpoints most businesses drop.

Technical 6 min read

What happens to your data when you press 'Send' on an AI tool

Businesses send customer data to AI tools without knowing what happens during processing. The spectrum of AI privacy is wider than you think.