Blog > AML/CTF Training Obligations

AML/CTF Training Obligations

AML/CTF Training Obligations 2026 | eCompliance Central
Financial Crime & AML

AML/CTF Training Obligations Under Tranche 2 in 2026

Since 1 July 2026, tens of thousands of Australian firms have carried AML/CTF training obligations for the first time. Moreover, AUSTRAC now expects evidence that your people can recognise and escalate financial crime risk. This guide sets out what the duty requires, who it covers, and how to prove it.

Last updated on August 18, 2026

Tranche 2 Has Commenced and Training Is Now Live

What changed on 1 July 2026

The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 extended Australia’s AML/CTF regime to a new cohort of businesses. Lawyers, accountants, conveyancers, real estate agents, trust and company service providers, and dealers in precious metals and stones all became reporting entities. AUSTRAC has estimated that roughly 80,000 businesses now fall within scope.

Consequently, enrolment opened on 31 March 2026 and closed for most newly captured firms on 29 July 2026. However, enrolment was only the administrative gateway. Substantive duties — risk assessment, customer due diligence, reporting, record keeping and staff training — all commenced on 1 July regardless of whether a firm had enrolled.

Why training is the duty most firms underestimate

Many Tranche 2 firms spent the first half of 2026 writing their AML/CTF programme. Training, by contrast, often got deferred to a single induction email or a slide pack circulated among partners. Notably, that approach leaves the widest gap between what a programme says and what staff actually do.

Your programme is a document. In practice, your people are the control. When a receptionist accepts a third-party cash payment, or a sales agent waves through an unverified buyer, the written programme has already failed.

Who this article is for

Principals, practice managers, AML/CTF compliance officers and learning leads inside newly regulated Australian firms will find the most value here. Furthermore, established reporting entities can use it to benchmark existing programmes against the expanded regime.

Seven weeks into the new rules, the practical question has shifted. Rather than asking whether you are captured, you now need to demonstrate that your controls work.

Executive Summary

  • What this blog covers: What AML/CTF training obligations require under the AML/CTF Act 2006, who must be trained, and how to evidence competence to AUSTRAC.
  • Who it’s for: Principals, AML/CTF compliance officers, practice managers and learning leads inside newly regulated Tranche 2 firms across Australia.
  • Key regulatory context: The Amendment Act 2024 brought roughly 80,000 businesses into the regime from 1 July 2026, with AUSTRAC as the responsible regulator.
  • The central risk: Generic training that staff complete but never apply, leaving sector-specific red flags unrecognised and suspicious matters unreported.
  • Primary action required: Build role-specific training on your own risk assessment and designated services, then keep dated records of who completed what.
Compliance team completing AML/CTF training obligations session in an Australian workplace

What AML/CTF Training Obligations Actually Require

The short answer

Your AML/CTF programme must include an ongoing training programme for staff, and you must actually run it. Specifically, people who provide or support designated services need to understand your obligations, the risks your firm carries, and the procedures they follow. Training is not a one-off induction task; instead, it repeats as risks, roles and rules change.

What a compliant training programme covers

AUSTRAC does not publish a fixed syllabus. Nevertheless, published guidance and enforcement history point to a consistent set of components that any credible programme addresses.

At minimum, your training should cover the following:

  • Your firm’s designated services, and where money laundering risk enters each one
  • Customer due diligence steps, including identity verification and beneficial ownership
  • Politically exposed person, sanctions and adverse media screening triggers
  • Red flags specific to your sector, drawn directly from your own risk assessment
  • Internal escalation routes, plus the tipping-off prohibition and why it exists
  • Record-keeping duties, including the seven-year retention requirement

Who must be trained

Coverage extends well beyond your compliance officer. Anyone who onboards clients, handles funds, prepares transaction documents or supervises those tasks needs training proportionate to their exposure.

Directors and senior managers sit in scope too. Ultimately, AUSTRAC assesses whether governance understood the risk, not merely whether a mandatory module was assigned.

Why AML/CTF Training Fails in Australian Firms

The generic module problem

Off-the-shelf modules describe the Act competently enough. However, they cannot describe your clients, your settlement process, or the commercial pressure your agents face at the end of a quarter.

  • Content written for banks, then delivered to conveyancers and accountants
  • Scenarios set overseas, with no Australian designated services in sight
  • No connection between the module and the firm’s documented risk assessment
  • Assessment questions that reward recall rather than judgement

Completion gets treated as the outcome

Completion rates are easy to report and easy to game. Consequently, boards receive a green dashboard while frontline judgement stays entirely untested.

Compliance officers then discover the gap during an incident rather than during a review. By that point the record shows training was delivered, which makes the failure harder to explain, not easier.

This distance has a useful name borrowed from safety science: the gap between work-as-imagined and work-as-done.

Training stops once the programme is signed off

Money laundering typologies move quickly. Similarly, your own risk profile shifts as you take on new client types, new geographies or new services.

  • New designated services added without any matching training update
  • Lateral hires and contractors who never receive induction training
  • Red-flag guidance that ages quietly while typologies evolve
  • No refresher cycle scheduled after the initial rollout

Accordingly, an annual review of the training programme belongs inside your broader AML/CTF programme review, not beside it.

AML CTF programme records and reporting entity documentation on an Australian office desk

The Legal Framework Behind Your Training Duty

Where the obligation sits in Australian law

The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 requires reporting entities to maintain an AML/CTF programme, and staff training forms part of that programme. In addition, the Amendment Act 2024 received Royal Assent on 10 December 2024 and extended these duties to Tranche 2 sectors from 1 July 2026. AUSTRAC administers and enforces the regime.

Australian regulators apply a consistent logic to training across regimes. Under the Work Health and Safety Act 2011, for example, a PCBU must provide information, training and supervision, while officers exercise due diligence that Safe Work Australia describes as active and ongoing. Similarly, AUSTRAC expects reporting entities to show that training happened, that it suited the role, and that leadership oversaw it.

What regulator scrutiny looks like in practice

AUSTRAC has signalled a risk-based and educative posture during the early transition period. Nevertheless, the obligations themselves carry full legal force, and enforcement powers were never suspended.

  • Your written training programme, plus the date it was approved
  • Records showing who completed which training, and when
  • Role mapping that explains why each cohort received that content
  • Evidence that content reflects your documented risk assessment
  • Refresher and remediation records following any incident

Crucially, an examiner reads these records together. Gaps between them tell a clearer story than any single document does on its own.

Why documentation carries the weight

Contraventions of the AML/CTF Act can attract substantial civil penalties, and serious conduct carries criminal exposure. Rather than fixating on figures, treat the underlying principle as the point: undocumented compliance is indistinguishable from no compliance.

Good records also protect the firm. Where an individual acts outside procedure, dated training records demonstrate that the organisation set the standard, communicated it, and reinforced it.

Leadership, Governance and the AML/CTF Compliance Officer

What the compliance officer role demands

Every reporting entity must appoint an AML/CTF compliance officer at management level and notify AUSTRAC of that appointment. Most Tranche 2 firms had to complete the notification by 29 July 2026.

  • Own the training programme rather than merely approving it once
  • Map training content to designated services and roles each year
  • Report coverage, gaps and remediation to the board or principals
  • Escalate promptly where commercial pressure erodes due diligence

How to choose an AML/CTF training provider

Buying compliance training is a governance decision, not a procurement exercise. Therefore, ask providers the questions that reveal whether the content will actually change behaviour.

  • How long has the provider designed workplace training, and for which Australian sectors?
  • Will the module be built around our policies, our designated services and our red flags?
  • Does content update when Australian legislation or AUSTRAC guidance changes?
  • Is it SCORM-ready for our LMS, and do we own it without subscription lock-in?

Tone from the top operates as a control

Staff read what leaders tolerate. When a principal overrides a due diligence hold to protect a settlement, that single decision teaches more than any module ever will.

Conversely, visible support for escalation makes reporting feel normal. Leaders who complete the same training as their teams send that signal quickly and cheaply.

Completion Is Not Competence: The Gap That Creates Risk

Defining the gap

Work-as-imagined is the process described in your AML/CTF programme. Work-as-done is what a sales agent or paralegal actually does at 4.45pm on a Friday with an impatient client waiting.

Training that only teaches work-as-imagined leaves staff unprepared for the second situation. Meanwhile, criminals design their approach around exactly that pressure point.

Closing the gap requires scenario-based practice, not policy recitation.

What competence looks like on the floor

Competence is observable. Specifically, you should be able to walk into any client-facing team and hear the following without prompting.

  • A staff member can name three red flags specific to their own service line
  • They know exactly who to tell internally, and within what timeframe
  • Tipping-off is understood as a legal prohibition, not office etiquette
  • Under time pressure, the documented procedure still gets followed

Compliant on paper versus competent in practice

The difference between the two approaches shows up across five dimensions. Use the comparison below to audit where your current programme sits.

Dimension Tick-box approach Competence-based approach
Trigger Annual calendar reminder New service, new hire, new typology or incident
Content source Generic library module Your risk assessment and your procedures
Assessment Definition recall quiz Scenario decisions under realistic pressure
Evidence held Completion percentage Role mapping, dates, versions and remediation
Behaviour Staff defer to the deal Staff pause, verify and escalate

Notably, most newly regulated firms sit somewhere between the two columns. Honest self-assessment against this table gives your compliance officer a concrete remediation list.

The eCompliance Central AML/CTF Training Framework

Building training that survives regulator scrutiny follows a repeatable sequence. Furthermore, each step produces an artefact you can show an examiner, which means the work doubles as your evidence trail.

An 8-Step Framework for Control

Map Your Designated Services

Begin with a written list of every designated service your firm provides. Each one anchors a different risk profile and a different training need.

Translate Risk Into Scenarios

Convert your risk assessment into short, realistic situations staff will recognise instantly. Abstract risk categories rarely change behaviour.

Segment Roles and Cohorts

Group people by what they actually do: onboarding, funds handling, supervision, governance. Depth of content should follow exposure.

Build On Your Own Policies

Embed real forms, thresholds and escalation paths into the module itself. Generic content only ever teaches generic responses.

Assess Judgement, Not Recall

Test decisions inside scenarios rather than definitions in isolation. A pass should mean somebody can act correctly under pressure.

Evidence It Automatically

Capture completion, scores, dates and content version history in your LMS. Manual spreadsheets tend to fail under examination.

Refresh On A Fixed Cycle

Schedule refreshers alongside update triggers tied to legislative change or new services. Currency forms part of the obligation itself.

Report Coverage To Governance

Give principals a quarterly view of coverage, gaps and remediation progress. Oversight only exists once somebody documents it.

Making the framework operational

Sequence matters more than speed here. Firms that start at step four, buying a module before mapping services, consistently end up retrofitting content to a risk assessment it was never designed to match.

Instead, treat steps one to three as a half-day workshop with your compliance officer and service line leads. Everything downstream becomes faster, cheaper and considerably easier to defend.

What Weak AML/CTF Training Costs Australian Firms

The consequence chain

Failures rarely announce themselves as training failures. Rather, they surface as a missed suspicious matter report, an unverified beneficial owner, or a transaction nobody questioned.

The chain typically runs in this order:

  • Staff cannot recognise a red flag that sits outside the generic examples they were shown
  • Escalation never happens, so the suspicious matter goes unreported within the required timeframe
  • AUSTRAC identifies the pattern later, and the firm’s training records become the first exhibit

The reputational and commercial cost

Enforcement outcomes are public. Consequently, a compliance failure follows the firm into tender processes, professional indemnity renewals and client onboarding conversations for years afterwards.

Insurers and banking partners increasingly ask newly regulated firms to evidence their AML/CTF controls directly. Solid training records answer that question in minutes rather than weeks.

Compliance Intelligence: Key Insights

Tranche 2 obligations commenced on 1 July 2026, bringing roughly 80,000 Australian businesses into the AML/CTF regime for the first time.
Staff training is a component of the AML/CTF programme itself, not an optional supplement to it.
Enrolment closed for most newly captured firms on 29 July 2026, yet the underlying duties applied from 1 July regardless.
Generic modules built for banks leave conveyancers, agents and accountants without the red flags that appear in their own transactions.
Completion percentages measure attendance, while scenario assessment measures the judgement AUSTRAC actually cares about.
Regulators across Australian regimes, from AUSTRAC to Safe Work Australia, assess training the same way: was it delivered, was it suitable, was it evidenced.
Undocumented training offers no defence, because an examiner cannot distinguish it from training that never happened.

Key Takeaways

  • Map every designated service your firm provides before you buy or build any training content.
  • Segment your workforce by exposure, then match training depth to each role rather than issuing one module to everyone.
  • Build scenarios from your own risk assessment so staff practise decisions they will genuinely face.
  • Test judgement through realistic situations instead of definition-recall quizzes.
  • Document completion, dates, content versions and role mapping inside a single retrievable system.
  • Refresh content whenever legislation, AUSTRAC guidance, services or typologies change.
  • Report training coverage and gaps to your principals or board every quarter.

Frequently Asked Questions

Obligations and coverage

Do we need AML/CTF training if we only occasionally provide designated services?
Yes. The obligation attaches to the designated service, not to how frequently you provide it. Consequently, a firm that handles two property settlements a year still needs staff who can recognise and escalate risk in those two transactions. Frequency may reasonably influence the depth and cadence of your training, though it never removes the duty. Document that reasoning inside your risk assessment so the proportionality is visible to AUSTRAC.
Who has to complete AML/CTF training in a Tranche 2 business?
Anyone involved in providing or supporting a designated service falls within scope. In a real estate agency, that typically includes sales agents, property managers, trust account staff and reception. Additionally, principals and directors need training because governance oversight is itself assessed. Support staff who never touch customer onboarding may receive a shorter awareness module rather than the full programme.
How often should AML/CTF training be refreshed?
Most Australian firms run a full refresher annually, with shorter updates triggered by change. Specifically, a new designated service, a new client segment, an AUSTRAC guidance update or an internal incident should all trigger targeted training. New starters need induction training before they touch customer onboarding, not at the next scheduled cycle. Record the trigger alongside the training so the logic is auditable later.

Evidence, providers and common mistakes

What records does AUSTRAC expect us to keep for AML/CTF training?
Keep your written training programme, its approval date, and the version history of the content delivered. Alongside that, retain records of who completed which module and when, plus the role mapping that explains why each cohort received that content. Remediation records matter too, particularly where somebody failed an assessment or an incident prompted extra training. Broader AML/CTF record-keeping under the Act runs to seven years, so align your training retention to the same standard.
Is generic online AML training enough to meet our obligations?
Generic training can cover legislative background reasonably well. However, it cannot teach your staff the red flags that appear in your specific transactions, or the escalation path inside your own firm. Because your programme must reflect your documented risk assessment, training disconnected from that assessment creates a visible inconsistency for any examiner. Customised content built around your policies, services and workforce closes that gap directly.
What is the most common AML/CTF training mistake newly regulated firms make?
Treating the rollout as the finish line. Firms invest heavily in an initial module during commencement, then leave it untouched while services, staff and typologies all change around it. Furthermore, many never map training to roles, so senior people receive the same content as administrative staff and neither cohort is well served. Set the refresh cycle and governance reporting rhythm at rollout, and the programme stays current by design.

About the Author

This comprehensive article was actively developed by the expert content team at eCompliance Central, under the highly skilled direction of Dr. Denise Meyerson. Dr. Meyerson is the successful founder, a PhD-qualified educator, and a leading learning innovation specialist boasting over 35 years of deep, practical experience in learning and development, strict compliance, and vocational education. She has consulted extensively for leading global organisations and currently remains a highly recognised authority on behaviour-based compliance training within the complex Australian context. We firmly help ambitious organisations meet their strict compliance obligations through highly customised, deeply engaging, SCORM-ready training modules. We proudly build these robust tools precisely around your specific policies, your unique people, and your actual, daily operational realities. Note: We are professional educators, absolutely not legal advisors. For specific legal advice tailored precisely to your exact situation, please consult a fully qualified legal professional.

Turn Your AML/CTF Programme Into Trained Behaviour

Our AML/CTF and sector-specific modules are built around your designated services, your policies and your real red flags, then delivered SCORM-ready to your LMS with no subscription lock-in. Talk to us about a module your team will actually apply.

Explore Custom Compliance Solutions
0
    0
    Your Cart
    Your cart is emptyReturn to Shop