Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

AUSTRAC Sets Out Five Habits for Stronger AML Compliance

AUSTRAC Sets Out Five Habits for Stronger AML Compliance

By
Key Takeaways
  • Know What Applies: AUSTRAC said AML/CTF obligations depend on a business’s services, customers and specific risk exposure.
  • Keep Information Current: Businesses should update AUSTRAC Online when personnel, contact information or business locations change.
  • Reassess Changing Risks: Growth, new services and different customer groups can alter a business’s exposure to financial crime.
  • Make Reporting Useful: Businesses do not need to prove criminal activity before reporting suspicions, and information that appears minor can become valuable when combined with other intelligence.
  • Keep the Record Straight: Accurate and accessible records help businesses explain compliance decisions, respond to scrutiny and assess whether controls are working.
Deep Dive

AUSTRAC has reduced good anti-money laundering compliance to five pieces of advice, and none of them is particularly exotic. Know which obligations apply to the business. Keep the regulator informed when basic company details change. Revisit the risks as the business changes. Make sure reports contain information somebody can actually use. Keep records good enough to explain the decisions made along the way.

The Australian Transaction Reports and Analysis Centre published the guidance, arguing that effective AML/CTF programs are built on what it calls “simple habits done well.” Behind that fairly modest description is a practical warning. A compliance framework can exist on paper and still lose its grip on the business it is supposed to govern.

AUSTRAC said AML/CTF obligations vary according to the services a business provides, the customers it deals with and the risks it faces. A business serving individual customers will not necessarily confront the same customer risks as one dealing with complex trusts and corporate structures. This is important because knowing what applies determines where the compliance effort goes. AUSTRAC’s advice is not to accumulate controls indiscriminately, but to understand the requirements relevant to the business well enough that gaps do not develop around them.

Risk presents a similar problem because the answer can change. A company that once dealt only with customers in Australia may begin doing business overseas. A remittance provider may encounter transaction patterns that warrant closer attention. New services, new customers and growth can alter the ways criminals might seek to misuse an otherwise legitimate business.

AUSTRAC therefore wants businesses reviewing their risks regularly rather than assuming an assessment remains correct because it was correct when it was written. There is a more mundane obligation alongside that work. Businesses need to keep their AUSTRAC Online details current. The information in those accounts is how AUSTRAC contacts businesses about regulatory changes, reporting requirements, compliance updates and new guidance. Changes to personnel, contact details and business locations should be reflected there.

AUSTRAC uses the departure of an AML/CTF compliance officer to show how quickly a small omission can matter. If the officer leaves and the account is not updated, compliance notices and reminders may continue going to the wrong person. The business may then be slower to respond to a reporting requirement or a change in its obligations.

Nothing about the problem is technically difficult. Someone simply has to notice that the information is wrong and fix it.

The Information That Reaches AUSTRAC

Reporting carries a different weight because the information does not stop at the edge of the business. Reports submitted to AUSTRAC help the regulator and law enforcement develop a wider picture of criminal activity in Australia. They can contribute to intelligence gathering, investigations and enforcement action, while high-quality reporting can help identify threats and trends developing across industries.

A business is not being asked to establish that a crime took place. AUSTRAC instead tells reporting entities to recognize unusual activity, ask questions where necessary and report suspicions when required.

The regulator points to the kinds of circumstances that can deserve another look. A customer might give inconsistent accounts of where money came from. Instructions may change repeatedly. A complicated ownership structure may have no obvious business purpose. Someone may be reluctant to identify who ultimately controls a company.

Those circumstances do not, by themselves, mean criminal activity is occurring. AUSTRAC said they may justify further review and, where appropriate, a suspicious matter report. That qualification is important because the reporting system depends on fragments. A piece of information held by one company may reveal little on its own. Combined with information from other reporting entities, it can become useful intelligence. The company does not have the wider picture. AUSTRAC might.

For the business, that puts pressure on two things it can control. Staff need to recognize activity that deserves attention, and the process for handling it needs to be consistent enough that a suspicious transaction is not treated differently simply because a different employee happens to see it. Then there is the record left behind. AUSTRAC’s fifth recommendation is to maintain records that are organized, accessible, current and accurate. That includes documents supporting customer due diligence, risk assessments, reporting decisions and other AML/CTF work.

The immediate value is evidentiary. When an audit, review or request for information arrives, a business needs to be able to show how it managed a risk, met an obligation and reached a particular compliance decision. But the records also tell the business something about itself. AUSTRAC said they can help identify trends, test whether controls are effective and expose areas that need improvement.

Taken individually, none of AUSTRAC’s five recommendations asks much that should surprise an experienced compliance team. Together, they describe something harder to maintain than to design: a compliance program that remains connected to the business as the people, customers, services and risks around it change.

That is where AUSTRAC has placed the emphasis. Not on how elaborate the program looks, but on whether the information is current, the risks are understood, the reports are useful and the decisions can still be explained when somebody comes asking.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong