Black Shard

Independent evaluation of your AML/CTF program.

An independent evaluation of the ML/TF risk assessment, the design of the AML/CTF policies and compliance with them, reported in writing to the governing body.

Open a brief

AML/CTF Act evaluation requirement
Section 26F
Longest interval between evaluations
3 years
CyberCert public registry
SMB1001:2026 Gold

Black Shard conducts independent evaluations of AML/CTF programs for Australian reporting entities, from outside the entity's compliance function, with a written report to the governing body.

How the evaluation runs, and the practice behind it

Black Shard conducts those evaluations for Australian reporting entities. The evaluator sits outside the entity's compliance function, evaluates the ML/TF risk assessment and the design of the AML/CTF policies against the Act, the regulations and the AML/CTF Rules 2025, tests compliance on sampled records, and delivers a written report to the governing body and the senior manager who approves the program.

The evaluation applies the firm's compliance practice to the AML/CTF program: the same evaluation of control design and control operation that runs through its Essential Eight assessments, SMB1001 and ISO 27001 readiness work and Privacy Act uplift, with each finding tied to the evidence behind it and written for the people who have to act on it. Black Shard holds SMB1001:2026 Gold, issued by CyberCert, and its ISO 27001 readiness work is led by a certified ISO/IEC 27001:2022 Lead Auditor.

What the Act requires

Section 26F(4)(f) of the Act requires a reporting entity's AML/CTF policies to deal with the conduct of independent evaluations of its AML/CTF program, including the frequency of those evaluations, which must be appropriate to the nature, size and complexity of the business and at least once every three years.

  • Evaluation of the steps taken to undertake or review the ML/TF risk assessment, against the Act, regulations and Rules
  • Evaluation of the design of the AML/CTF policies against the same requirements
  • Testing and evaluation of the entity's compliance with its own AML/CTF policies
  • Testing whether the entity identifies, assesses, manages and mitigates the money laundering, terrorism financing and proliferation financing risks it faces
  • A written independent evaluation report containing findings on each of those matters
  • Delivery of the report to the governing body and to any senior manager responsible for approvals under section 26P
The reformed Act and the 2025 Rules

The requirement forms part of the reformed Act and the AML/CTF Rules 2025 that apply from 31 March 2026, and it replaces the independent review of Part A of the program under the previous Rules with an evaluation of the entire program.

Section 5-10 and AUSTRAC guidance

Section 5-10 of the Rules sets out what the policies must require of every evaluation, and section 5-10(3) requires the policies to deal with how the entity will respond to the report. AUSTRAC's guidance adds that the independent evaluation is conducted in addition to the entity's own reviews of the program, and that it expects the entity to document the rationale for the frequency it has chosen, including the factors of nature, size and complexity behind the decision.

The six requirements in full
  • Evaluation of the steps taken when undertaking or reviewing the ML/TF risk assessment, against the requirements of the Act, the regulations and the Rules
  • Evaluation of the design of the AML/CTF policies against the same requirements
  • Testing and evaluation of the entity's compliance with its own AML/CTF policies
  • Testing and evaluation of whether the entity is appropriately identifying, assessing, managing and mitigating the money laundering, terrorism financing and proliferation financing risks it may reasonably face in providing its designated services
  • A written independent evaluation report containing findings on each of those matters
  • Delivery of the report to the governing body and to any senior manager responsible for approvals under section 26P

What the evaluation covers

The evaluation covers three things: how the risk assessment was undertaken or reviewed, the design of the policies, and compliance tested on sampled records.

The risk assessment

The risk assessment is evaluated on how it was undertaken or reviewed. The evaluation reads the documents behind it, confirms that the reviews section 26D requires were carried out when a significant change occurred, when AUSTRAC communicated risk information, and in any event at least once every three years, and checks that the assessment was updated to address what those reviews found and approved by a senior manager under section 26P.

Policy design

The policies are evaluated on design: whether each matter the Act and the Rules require the policies to deal with is dealt with, including customer due diligence, targeted financial sanctions, the actions that need senior manager approval, the information provided to the governing body, personnel due diligence and training, the assessment of potential suspicious matters, the prevention of tipping off, and the conduct of the independent evaluation itself.

Compliance testing on sampled records

Compliance is tested on sampled records. Customer files are sampled against the customer due diligence policies: what was collected, what was verified, how the customer was risk rated and whether ongoing due diligence ran as written. Transactions are sampled against the monitoring and reporting policies. Personnel records are sampled against the due diligence and training policies. The report records what was tested, which files were sampled, and how the tests and the sampling were carried out, because that is what AUSTRAC says the report will typically include. For an entity operating in more than one jurisdiction, the sample includes a reasonable share of the Australian operations, as AUSTRAC expects.

What the evaluator needs

AUSTRAC expects the entity to give the evaluator access to the documents behind the risk assessment and the policies, the risk assessment and policies themselves, the relevant staff and senior managers, customer identification and transaction records, the results of the entity's own monitoring and reviews, and previous independent evaluation or review reports. The request list is agreed at scoping so the fieldwork runs against records that are already assembled.

Independence, and why an external evaluator

AUSTRAC describes independence as the evaluator's ability to conduct the evaluation without bias, influence or conflicts of interest, free from relationships and circumstances that could compromise objectivity and professional judgement.

What AUSTRAC expects of an evaluator

It expects the evaluator to have the authority to exercise independent judgement, to be empowered to conduct the evaluation as they see fit, to have no responsibility for implementing or maintaining the program, no involvement in developing the program, its systems and controls, or in assessing the ML/TF risks, and to be independent of the work areas evaluated. The AML/CTF compliance officer and members of the compliance team are named as people who do not qualify.

Internal or external

An internal evaluator is permitted where the entity has a function, such as internal audit, that meets those conditions. Where no such function exists, an evaluator from outside the business is how the conditions are met. Black Shard does not evaluate a program it developed or maintains, and confirms before quoting that it has had no role in the entity's risk assessment, policies, systems or controls.

Qualifications and experience

There are no mandatory qualifications for an evaluator. AUSTRAC expects knowledge of the AML/CTF obligations that apply to the business and experience of the sector and of the ML/TF risks businesses in it may reasonably face, and lists experience evaluating the effectiveness of systems, controls, policies and procedures and experience preparing reports that document findings among the matters an entity may consider. Black Shard's compliance practice is that work: evaluating whether a control is designed to a requirement and whether it operates as designed, across the Essential Eight, SMB1001, ISO 27001 and the Australian Privacy Principles. The firm also builds and operates compliance systems for regulated Australian businesses, including a fund-administration platform with a monthly-sealed compliance audit log. A statement of the evaluator's independence and experience is supplied with the engagement, because AUSTRAC expects the entity to keep a record of why it considers the evaluator suitable and how it selected them.

The written report and the response

The Rules require the evaluation to produce a written independent evaluation report containing findings on each of the matters evaluated, delivered to the governing body and to any senior manager responsible for approvals under section 26P.

The report as a board paper

AUSTRAC expects them to receive it as soon as reasonably practicable once it is prepared. Black Shard's report is written as a board paper: a summary of the evaluation process, the aspects of the business reviewed and the method used; findings on how the risk assessment was undertaken or reviewed and on the design of the policies; findings on compliance with the policies; and what was tested, the files sampled and how the tests and sampling were conducted. Each adverse finding names the provision of the Act, the Rules or the policy it concerns and the evidence behind it. The findings are presented to the governing body on request.

The entity's response

The response is the entity's. If the report contains adverse findings on the risk assessment, section 5-1 of the Rules requires a review as soon as practicable after the governing body receives the report, and section 26D requires the assessment to be updated to address what the review finds. If it contains adverse findings on the policies, section 5-4 requires the policies to be reviewed and, where required, updated. Any update to the risk assessment or the policies must be documented within 14 days after it is made, under section 5-15, and approved by a senior manager under section 26P. AUSTRAC states the entity need not agree with every adverse finding, and expects it to record how each finding was addressed, who is responsible, how progress is tracked, and the reasons for any finding it has not acted on.

Record keeping

Section 116 of the Act requires records reasonably necessary to demonstrate compliance with the program obligations, retained for seven years after they stop being relevant. For the evaluation that means the sampled files, the report, the record of the discussions with senior managers and the governing body, the record of why the evaluator was considered suitable, and the record of the response. The engagement closes with that set assembled.

Timing under the transitional rules

The Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026, registered on 30 March 2026, stagger the first independent evaluation so that demand after 1 July 2026 is spread. Two provisions apply.

A newly regulated entity, and an entity that before 31 March 2026 provided only item 54 designated services, complies if the first evaluation is conducted before the date set by the last two digits of its AUSTRAC account number, the enrolment identifier issued when it enrolled.

  • Both digits odd: before 30 June 2029
  • Second-last odd, last even: before 31 December 2029
  • Both even: before 30 June 2030
  • Second-last even, last odd: before 31 December 2030
Entities with a prior Part A review, and evaluating early

An entity that was enrolled with AUSTRAC on 30 March 2026 and had at least one independent review of Part A of its program under the 2007 Rules on or before that date complies with its policy frequency if the first independent evaluation is conducted before the later of four years after its most recent independent review and 31 March 2027.

AUSTRAC's guidance notes that newly enrolled entities may wish to conduct the first evaluation earlier than the transitional deadline: issues in risk management and compliance get corrected early, and evaluators with appropriate skills may be more readily available. The frequency written into the policies applies after the first evaluation, at least once every three years.

Scope and how it is quoted

The evaluation runs as a fixed-scope engagement with a written scope and quote before it starts. Six things drive the quote.

  • Designated services and business lines in the program
  • The size of the customer base, and the sample that follows from it
  • Jurisdictions and permanent establishments
  • Lead entity of a reporting group, with the section 26F(5) and (6) matters
  • A first evaluation, or a repeat with a prior report to work from
  • Records that can be queried, or have to be assembled by hand
Delivery, item 54 services, and how to start

The evaluation is delivered Australia-wide, with fieldwork run remotely against the entity's systems and records and on site where records are held on paper.

Section 26T disapplies subsection 26F(4) for a reporting entity whose designated services are all item 54 arranging services, so an AFSL holder that only arranges for its clients to receive designated services carries no independent evaluation obligation. Send a brief to info@blackshard.com.au with the sector and designated services, the enrolment date, whether a prior independent review was carried out and when, and the deadline the transitional rules set for the business. The independence check runs first, and the scope, the sample and the timetable to the governing body's meeting follow.

Questions, answered

Does the evaluator need to be authorised or accredited by AUSTRAC?

No. AUSTRAC sets no mandatory qualifications for an evaluator, and expects independence and suitability to the nature, size and complexity of the business. Section 164 separately lets the AUSTRAC CEO authorise external auditors; that is a distinct function, and Black Shard holds no authorisation under section 164.

Can our AML/CTF compliance officer or compliance team conduct the evaluation?

No. AUSTRAC expects the evaluator to be independent of the work areas evaluated and names the compliance officer and members of the compliance team as people who do not qualify. An internal evaluator is acceptable where a function such as internal audit has the authority to exercise independent judgement and had no part in developing, implementing or maintaining the program.

How often must an independent evaluation be conducted?

At least once every three years, at a frequency the policies set and justify. The first evaluation follows the Transitional Rules 2026: for an entity with a prior independent review, the later of four years after it and 31 March 2027; for a newly regulated entity, a date set by its AUSTRAC account number.

What do we need to give the evaluator?

The documents behind the risk assessment and the policies, the current versions of both, access to the relevant staff and senior managers, customer identification and transaction records, your own monitoring and review results, and any previous evaluation or review report. The request list is settled at scoping.

What happens if the report contains adverse findings?

Adverse findings on the risk assessment require a review as soon as practicable and an update; adverse findings on the policies require a review and, where required, an update. Updates are documented within 14 days and approved by a senior manager. The entity records its reasons where it does not act on a finding.

Is the evaluation legal advice?

No. The evaluation tests the program against the requirements of the Act, the regulations and the Rules and reports findings with the evidence behind them. Where a finding turns on a question of legal interpretation, the report says so, and the entity's legal adviser makes that call from the record the report provides.

Tell us your sector, your enrolment date and when your last independent review was.

Brisbane head office.

Open a briefinfo@blackshard.com.au