For many businesses, one of the biggest AML/CTF compliance risks is not having an AML/CTF Program.
It is that the program exists, has been approved, staff have been trained – but over time, what is written in the program and what is actually happening in the business begin to drift apart.
That is where regular internal audits or compliance reviews can provide significant value.
AUSTRAC makes it clear that an AML/CTF Program is not simply a document that is prepared and put on the shelf. Reporting entities must comply with their program, follow their AML/CTF policies in daily operations, and monitor the effectiveness of those controls. (AUSTRAC)
This is why we have introduced a quarterly AML/CTF review structure within CIRT – to help clients progressively check implementation throughout the year rather than waiting until an independent evaluation identifies the problems.
The difference between having a program and implementing it
A business might have an excellent AML/CTF Program.
It might say that the business will:
- undertake Customer Due Diligence (CDD);
- identify and manage higher-risk customers;
- conduct Enhanced Customer Due Diligence (ECDD) when required;
- monitor transactions and customer behaviour;
- identify and investigate unusual activity;
- lodge Suspicious Matter Reports (SMRs) where required;
- conduct AML/CTF training;
- undertake personnel due diligence;
- maintain appropriate records; and
- report AML/CTF compliance information to senior management or the governing body.
But the important question is:
Can the business demonstrate that these things are actually happening?
AUSTRAC’s current guidance states that businesses must implement their AML/CTF policies and demonstrate how they are applied. (AUSTRAC)
That makes monitoring implementation just as important as writing the program in the first place.
Why conduct internal reviews throughout the year?
A quarterly internal review provides an opportunity to look at a manageable part of the AML/CTF Program and ask some simple questions:
Are we doing what our program says we will do?
Are our controls actually working?
Do we have evidence to demonstrate this?
Have there been changes to our customers, services, risks or business operations?
Are there gaps that need to be corrected?
This creates a continuous improvement process rather than a last-minute compliance exercise.
For example, an internal review might identify that staff completed their initial AML/CTF training but some new employees have not yet been trained. AUSTRAC specifically recognises internal compliance reviews and audits as tools that can help identify training and knowledge gaps. (AUSTRAC)
Another review might identify that CDD forms are being completed but customer risk ratings are not being consistently recorded.
A transaction-monitoring review might find that transactions are being identified but there is insufficient documentation explaining what was investigated and why an SMR was or was not considered necessary.
These are often relatively straightforward issues to fix when identified early.
Why quarterly reviews?
There is an important distinction here.
A quarterly internal review is not the same as the independent evaluation required under the AML/CTF framework.
AUSTRAC requires independent evaluations at a frequency appropriate to the nature, size and complexity of the business, with a minimum frequency of at least once every three years. (AUSTRAC)
Our quarterly approach is an additional management control designed to help businesses stay on top of their program between those independent evaluations.
In fact, AUSTRAC provides an example where, following adverse findings from an independent evaluation, a business decides to conduct an internal review three months later to check whether its updated policies and procedures are working effectively. (AUSTRAC)
For us, that reinforces a simple principle:
Don’t wait three years to find out whether your AML/CTF Program is working.
The CIRT quarterly review approach
This is why we have implemented a quarterly AML/CTF review structure within CIRT.
Rather than asking the Compliance Officer to undertake one enormous review at the end of the year, the process can be broken into manageable quarterly activities.
A quarterly review could examine areas such as customer identification and CDD, higher-risk customers and ECDD, transaction monitoring, SMRs and threshold transaction reporting, personnel training and due diligence, changes to ML/TF and proliferation-financing risks, record-keeping, AUSTRAC correspondence, corrective actions and management or board reporting.
Importantly, the review should not simply be a tick-and-flick exercise.
Where appropriate, the reviewer should sample actual records.
For example, if the program requires higher-risk customers to undergo ECDD, select several higher-risk customer files and check whether the required process actually occurred.
If the program requires particular transactions to be monitored, select a sample and check whether the monitoring occurred and whether there is evidence of the outcome.
This moves the review from:
“Do we have a procedure?”
to:
“Can we demonstrate that the procedure is working?”
Creating an AML/CTF compliance evidence trail
There is another important benefit.
Every quarterly review creates evidence.
Over the course of a year, the business develops a record demonstrating that it has been actively monitoring its AML/CTF Program, identifying gaps, allocating corrective actions and following them through.
This can also improve governance.
Rather than the AML/CTF Compliance Officer simply telling the governing body that “everything is okay”, they can report:
- We completed the quarterly AML/CTF review.
- We tested these areas.
- We identified these issues.
- These corrective actions have been allocated.
- These matters have now been closed.
That is a much stronger compliance conversation.
Internal reviews also help prepare for the independent evaluation
Regular internal reviews should ultimately make the independent evaluation less daunting.
The objective should never be to make sure an independent evaluator doesn’t find anything. A good evaluation may identify opportunities for improvement.
The objective is to avoid the evaluator finding basic implementation failures that the business could reasonably have identified itself months earlier.
AUSTRAC itself notes that identifying compliance and ML/TF risk-management issues early allows businesses to correct them sooner and reduce their exposure. (AUSTRAC)
Compliance is a process, not an annual event
AML/CTF compliance shouldn’t become something that receives attention once a year when the AUSTRAC compliance report is due, or once every few years when an independent evaluation approaches.
A better approach is:
Implement → Monitor → Review → Identify gaps → Correct → Report → Repeat.
That is the thinking behind the quarterly AML/CTF review structure we have implemented in CIRT.
It gives Compliance Officers a practical way to progressively test their AML/CTF Program, retain evidence of those reviews, identify actions and demonstrate that the organisation is actively monitoring whether its AML/CTF controls are working.
Most importantly, it helps answer one of the questions every reporting entity should be able to answer:
“We have an AML/CTF Program — but can we demonstrate that we are actually following it?”
For further guidance, see AUSTRAC – Your AML/CTF program overview and AUSTRAC – Review and update your AML/CTF program.
#CHDPartners #CIRT #RTO #WHS #WorkHealthAndSafety #Training #RiskManagement #SecurityAndSafetyCompliance #SME #SmallBusiness #MichaelHuggett #AUSTRAC #AMLCTFAnnualComplianceReports #AMLCTFCompliance #AMLCTF #AntiMoneyLaundering