If you are starting from zero with about 90 days until 1 July 2026, you can build a working AML/CTF program in that window. What decides whether you make it is not effort. It is order. Run the steps in the wrong sequence and you redo half of them.
The most common mistake I see is firms that start with the document. They find a thick policy template, fill it in, and feel ahead. Then the risk assessment comes last, or never, and the policies end up describing a business that is not theirs. Policies are meant to answer the risks you found. If you have not found them yet, you are guessing.
So the order is fixed. Confirm you are caught and enrol with AUSTRAC. Appoint someone with real authority to own it. Assess your ML/TF risk. Then, and only then, write the policies that respond to that risk. Train the people who will run it. Get senior sign-off. Go live. The plan below fits that into 90 days.
A principal handed me a 40-page policy document before we had said a word about risk. It looked impressive. It also described a low-risk retail business with walk-in customers paying small deposits. Their actual book was half trusts and company buyers, 2 of them overseas, with funds arriving from accounts nobody had looked at. The policies answered risks they did not really run and stayed silent on the ones they did. We put the document aside, did the risk assessment first, and rebuilt the policies from what it showed. The second version was shorter and it actually fit. Order is not a formality. A program written before the risk assessment is a guess with a cover page.
Figure 1. The 90-day sequence. Each step is an input to the next, so the order is not interchangeable.
The 90-day sequence
Days 1 to 15: confirm you are caught, enrol, appoint your compliance officer
Map your services against the designated services list first. If you do not provide a designated service, you are not caught. If you do, enrol. Enrolment opens 31 March 2026 and is free. Then appoint your compliance officer, and treat this as a real decision. AUSTRAC expects a senior person with genuine authority, fit and proper, at management level. Nominating a junior to hold the title creates its own risk. Put the appointment in writing. For the mechanics of getting onto AUSTRAC Online, see the step-by-step enrolment guide.
Days 16 to 45: run the ML/TF risk assessment
This is the foundation of the whole program, so it gets the most time. You are scoring money laundering and terrorism financing risk across 4 dimensions: your customers, the services you provide, how you deliver them, and the countries involved. A trust-heavy book, overseas buyers, or large cash-adjacent transactions push your risk up. The output is a documented assessment you can put in front of AUSTRAC, and more usefully, one that tells you where to spend your effort. Skip it and everything downstream is built on a guess.
Days 46 to 70: write the policies and build the workflows
Now you write the policies, because now you know what they have to address. This is the second half of the AML/CTF program the reformed Act requires. Alongside the policies you stand up the operational pieces: a customer due diligence workflow, record keeping, and a process for suspicious matter reporting. This is also where you decide whether the AUSTRAC starter kit fits your firm or you build a custom program. Tooling earns its place here, by carrying the CDD and the evidence trail a static template cannot run for you.
Days 71 to 85: train the people who will run it
A program nobody understands is not operational. Train by role. Your front desk and agents need to recognise red flags in a live conversation, not recite a policy at audit time. Principals need to know what gets escalated and when. Run personnel due diligence on anyone holding an AML/CTF role, and document that you did.
Days 86 to 90: approve, go live, set the cadence
Senior management signs the program off. For a real estate agency that is the licensee in charge or the owner. For a law practice it is a principal or managing partner. The program has to be operational by 1 July 2026, not merely drafted and filed. Before you move on, write your review cadence and the timing of your first independent evaluation into the policies, so the program keeps pace with the business after go-live.
Why the order is not negotiable
Each step is an input to the next. The compliance officer owns the risk assessment, so they have to exist first. The risk assessment defines the policies, so it comes before them. The policies define what training has to cover. Training is what makes the program operational rather than theoretical. Sign-off is where someone with authority takes ownership of the risk. Jump ahead and you are building on air, which is exactly how firms end up with an impressive document that does not match the business it is supposed to protect. This is also why enrolment is the start of the work, not the finish line.
The regulatory detail
The dates that bind you
Enrolment opens 31 March 2026 and obligations commence 1 July 2026. You must enrol within 28 days of first providing a designated service. Firms already providing one on 1 July 2026 enrol by 29 July 2026. Your Tranche 2 compliance officer notification to AUSTRAC is due by 29 July 2026. AUSTRAC’s stated expectation is that by 1 July 2026 you are enrolled and hold an AML/CTF program, whether you built it from an AUSTRAC starter program or your own. Note that Tranche 2 goes straight into the reformed framework. The 3-year transition period applies to existing Tranche 1 entities, not to you.
What the program has to contain
Under the reformed Act the program is a single risk-based document set with 2 parts: a documented ML/TF risk assessment and AML/CTF policies, overseen by your governing body, with a fit and proper compliance officer at management level. The provisions sit at sections 26B to 26L. The 90-day plan is just the order in which you build those 2 parts and stand them up.
What it costs to miss it
Late enrolment is itself a contravention. Not having an operational program is a contravention. Program and CDD contraventions carry civil penalties up to 100,000 penalty units for a body corporate and 20,000 for an individual. A penalty unit is $364 on and after 1 July 2026. At the current rate that is up to $33 million and $6.6 million. The 90 days of work is the cheap option.
Common questions
How long does it take to build an AML/CTF program?
For a small firm starting from nothing, roughly 90 days of focused work, which is why the run-up to 1 July 2026 matters. Most of that time goes into the risk assessment and the policies that follow it, not the paperwork of enrolment.
What comes first, enrolment or the program?
Enrolment comes first in time, but it does not fulfil your obligations. You enrol, then you build and operate the program. Treating enrolment as the finish line is the single most common error.
Can I just use the AUSTRAC starter kit?
Only if your firm fits the suitability profile and you customise it. The kit is a legitimate baseline for small, low-complexity firms, but you still run a risk assessment and approve the result. Firms with trusts, overseas buyers or multiple service lines usually need a custom program.
Who has to approve the program?
Your senior management or governing body. For a real estate agency that is the licensee in charge or owner. For a law practice it is a principal or managing partner. The approval is what makes the documents your program.
Do I need a compliance officer if I am a sole operator?
Yes. Someone has to hold the role and own day-to-day compliance, even in a 1-person practice. In a sole practice that is usually you, and you still formalise it.
Sources
AUSTRAC, Regulatory expectations and priorities 2025 to 2026
AUSTRAC, AML/CTF transitional rules update
AUSTRAC, Real estate program starter kit: Getting started
Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
