For registered Clubs, an AML/CTF independent review should never be treated as simply another compliance exercise to complete and file away.
The real value comes from what the Club does with the findings.
An AML/CTF independent review provides the Board, senior management, and the AML/CTF Compliance Officer with an opportunity to understand whether the Club’s AML/CTF Program is working in practice, where weaknesses exist, and what needs to change.
Under the reformed AML/CTF framework, this governance responsibility has become even clearer.
AUSTRAC expects the written independent evaluation report to be provided to the reporting entity’s governing body and relevant senior managers as soon as reasonably practicable after its preparation. The purpose is straightforward: decision-makers need to be aware of deficiencies so that adverse findings and ongoing non-compliance can be addressed.
For a registered Club, the governing body will generally be the Board of Directors.
What Happens After an AML/CTF Independent Review?
Once an AML/CTF independent review has been completed, Clubs should not simply file the report and move on.
The findings should be reviewed, assessed according to risk, assigned to responsible people, given appropriate completion dates, and monitored through to completion.
The Board and relevant senior management should have appropriate visibility of significant findings, while the Compliance Officer and management should establish a clear corrective action process.
Corrective actions should then be verified to confirm that the original issue has actually been addressed.
In practical terms, the process should move from:
Independent Review → Findings → Board Oversight → Corrective Action → Implementation → Verification → Closure
This turns an independent review from a report into an ongoing improvement process.
Don’t Just Receive the AML/CTF Review Report — Review It
There is an important difference between receiving an independent review report and properly considering it.
A report sitting in the Compliance Officer’s files provides little protection if significant findings are not escalated, understood, and addressed.
Once the AML/CTF independent review has been completed, I recommend that the Compliance Officer and senior management work through every finding and determine:
- What was identified?
- Is it a legislative non-compliance, control weakness, improvement opportunity, or observation?
- What risk does it create for the Club?
- Does it require changes to the AML/CTF risk assessment?
- Does it require changes to policies or procedures?
- Does it require changes to CIRT or another compliance system?
- Does it require additional staff or supervisor training?
- Who is responsible for fixing it?
- When will it be completed?
- How will the Club confirm that the action has actually worked?
This approach ensures that the AML/CTF independent review becomes a practical improvement process rather than simply a compliance document.
Why the Board Needs to Know About AML/CTF Independent Review Findings
One of the most important parts of the process is ensuring the Board is properly informed.
AUSTRAC’s current guidance states that AML/CTF policies must require the independent reviewer to prepare a written report, which must be provided to the governing body and any senior manager responsible for approving the AML/CTF Program.
This is consistent with the broader governance obligations placed on the governing body. AUSTRAC explains that the governing body must take reasonable steps to ensure the organisation appropriately identifies, assesses, mitigates, and manages its ML/TF risks and complies with its AML/CTF obligations.
For Clubs, this means AML/CTF compliance cannot simply be delegated to the Compliance Officer.
The Compliance Officer may coordinate the program, but the Board needs appropriate visibility of significant compliance issues and the findings arising from an AML/CTF independent review.
What AML/CTF Findings Should Go to the Board?
Rather than simply placing a 30-page independent review in the Board papers and asking Directors to read it, I recommend providing both the full report and a concise management summary.
More importantly, the Board should understand the recommendations and what management proposes to do about them.
The summary could identify:
| Finding | Risk/Priority | Proposed Action | Responsible Person | Due Date | Status |
| Transaction monitoring procedures require improvement | High | Review procedures and monitoring rules | Compliance Officer | 30 days | Open |
| Supervisor AML/CTF knowledge inconsistent | Medium | Conduct supervisor training | Operations Manager | 60 days | Open |
| CDD records incomplete in sample reviewed | High | Review process and conduct staff refresher training | Compliance Officer | 30 days | Open |
| AML/CTF risk assessment requires updating | High | Review and update risk assessment | Compliance Officer/CEO | 30 days | Open |
This gives Directors something practical they can understand and monitor.
The Board should be able to see not only what was identified, but also what is being done, who is responsible, when it will be completed, and whether the action has been effective.
The Board Should Formally Consider the Independent Review
As a governance practice, Clubs should consider having the independent review formally tabled and recorded in the Board minutes.
The minutes should demonstrate that the Board has:
- received the independent review report
- considered the findings
- acknowledged any significant deficiencies or areas requiring improvement
- reviewed management’s proposed corrective actions
- agreed on appropriate responsibilities and timeframes for addressing the findings
The important point is not simply the wording of a Board resolution. It is creating evidence that the Board has genuinely exercised oversight.
AUSTRAC specifically identifies records of discussions about independent evaluation findings with senior managers and the governing body as records that may demonstrate compliance. It also identifies records showing how adverse findings have been addressed, how progress will be tracked, who is responsible, and reasons for any decision not to address a finding.
Every AML/CTF Finding Should Have an Action and Timeframe
One of the biggest mistakes after an AML/CTF independent review is agreeing that something needs to be fixed without deciding when.
“Management will review the procedure” is not an effective corrective action.
A better response is:
Action: Compliance Officer to review and update the transaction monitoring procedure, provide updated procedures for approval, and brief relevant gaming and duty management staff.
Responsible: AML/CTF Compliance Officer
Due: 30 September 2026
Verification: Updated procedure approved, training completed, and implementation checked through transaction monitoring sampling.
That creates accountability.
Not every recommendation needs the same timeframe.
A Club could adopt a simple approach such as:
Critical or Significant Compliance Issue — Immediate Action
Where there may be an existing legislative breach, significant ML/TF exposure, or a serious failure of a key control, the Club should consider implementing interim controls and undertaking urgent remediation.
High Priority — 30 Days
Issues affecting important AML/CTF controls, such as CDD, transaction monitoring, suspicious matter escalation, or regulatory reporting, should generally receive priority.
Medium Priority — 60 to 90 Days
Procedural improvements, training gaps, and control improvements may reasonably require additional implementation time.
Low Priority or Improvement Opportunity — 3 to 6 Months
Lower-risk administrative or continuous improvement matters may be incorporated into the Club’s broader compliance improvement program.
These are practical governance timeframes rather than statutory deadlines. Where legislation or AUSTRAC specifies a timeframe, that requirement takes priority.
Importantly, AUSTRAC states that where an independent evaluation identifies adverse findings regarding the ML/TF risk assessment, the review should occur as soon as practicable after the governing body receives the report, with required updates made as soon as practicable thereafter.
How Should Clubs Verify AML/CTF Corrective Actions?
Another important point is verification.
If an AML/CTF independent review identifies that staff are not completing CDD correctly, simply changing the procedure does not necessarily solve the problem.
The Club might need to:
- update the procedure
- communicate the change
- train affected employees
- monitor compliance
- sample CDD records
- confirm that the original problem has actually been addressed
AUSTRAC expects reporting entities to monitor changes made to their AML/CTF Program to ensure they have addressed adverse findings. If the issue persists, further review and updates may be required.
This is why I recommend including corrective actions in the Club’s continuous improvement register, or, if the Club is using CIRT, the Continuous Improvement, Corrective and Preventive Action Report (CICPAR), where evidence is required to close out a recommendation or action.
The goal should not simply be to demonstrate that a document was updated.
The goal should be to demonstrate that the underlying compliance issue was addressed.
Keep the Board Updated Until AML/CTF Actions Are Closed
Board involvement should not finish when the independent review is accepted.
Outstanding actions should be included in the Compliance Officer’s regular reporting to the Board.
A simple section could be added to the monthly or quarterly AML/CTF Compliance Report:
Independent Review Corrective Actions
- Total findings: 12
- Actions completed: 7
- Actions outstanding: 5
- High-priority actions outstanding: 2
- Actions overdue: 1
- Actions due before next meeting: 3
The Board can then ask a very simple question:
“Are we fixing what the independent reviewer identified?”
If an action becomes overdue, the Compliance Officer should explain why, identify the revised timeframe, and specify any interim controls being used to manage the risk.
This ongoing reporting also provides the Board with evidence that findings from an AML/CTF independent review are being actively managed rather than simply acknowledged.
How AML/CTF Independent Reviews Drive Continuous Improvement
An AML/CTF independent review should not be viewed negatively.
Finding weaknesses is part of the process’s purpose.
AUSTRAC describes independent evaluations as a mechanism for assessing the risk assessment, the design of AML/CTF policies, and whether the organisation is appropriately managing its ML/TF risks and complying with its policies.
The concern should therefore not necessarily be that an independent reviewer found issues.
The greater concern is when the Club knows about an issue and fails to address it.
A strong compliance culture looks more like this:
Independent Review → Findings → Board Oversight → Corrective Action → Implementation → Verification → Closure
That process demonstrates that the Club is not simply maintaining an AML/CTF Program on paper or online.
It demonstrates that the Board, management, and Compliance Officer are actively using assurance activities to identify weaknesses and continuously improve the effectiveness of the Club’s AML/CTF controls.
A Simple AML/CTF Independent Review Action Plan for Clubs
Following every AML/CTF independent review, Clubs should:
- Receive the written independent review report.
- Have the Compliance Officer and management review every finding.
- Develop a corrective action plan (CICPAR).
- Allocate a responsible person to every action.
- Set realistic completion dates based on risk and priority.
- Provide the full report and management response to the Board.
- Have the Board formally acknowledge and consider the report and action plan.
- Record the discussion and decisions in the Board minutes.
- Report outstanding actions back to the Board until completed.
- Verify that corrective actions have addressed the original findings.
The independent review is not the end of the process.
It is the point where good AML/CTF governance should become visible.
For a Club, the strongest position is being able to demonstrate not only that an AML/CTF independent review was conducted, but that the findings reached the Board, were understood, responsibilities and timeframes were established, corrective actions were implemented, and the Club checked that those actions were effective.
That is the difference between having a compliance report and using compliance to manage risk.
If your Club needs support reviewing its AML/CTF Program, addressing independent review findings, or developing a corrective action plan, contact CHD Partners to discuss your compliance requirements.
Final Thoughts
An AML/CTF independent review is not simply a compliance report to receive, acknowledge, and file away. It is an opportunity for a Club to identify weaknesses, strengthen its controls, and demonstrate that its AML/CTF Program is operating effectively.
The real value of an AML/CTF independent review comes from what happens after the report is received. Findings should be understood, prioritised, assigned to responsible people, given appropriate timeframes, and monitored until they are properly addressed.
Just as importantly, Clubs should verify that corrective actions have actually resolved the underlying issue rather than simply changing a policy or procedure.
A strong compliance culture is therefore not about having a perfect AML/CTF independent review. It is about being able to demonstrate that the Club identified issues, acted on them, and continuously improved its approach to managing ML/TF risk.
Ultimately, an AML/CTF independent review is not the end of the compliance process.
It is the starting point for meaningful action, stronger governance, and continuous improvement.
References
AUSTRAC – Step 5: Conduct an independent evaluation
AUSTRAC – Governing body – AML/CTF governance responsibilities
