How to test whether your AML/CTF controls are actually operating
An AML/CTF program describes how an organisation intends to manage its money laundering and terrorism financing risks.
Testing asks a different question: is that actually happening?
The distinction between control design and control effectiveness is well established in audit and assurance, but it is particularly useful for businesses implementing AML/CTF requirements for the first time. A control can be well designed and still fail in operation.
Start with the important controls
Testing every requirement at once is rarely necessary. A better starting point is to identify the controls that matter most to the agency's exposure and regulatory obligations. Depending on the business, these might include customer identification and verification, customer risk assessment, enhanced due diligence, suspicious matter escalation, staff training and record keeping.
For each control, establish what should happen, who is responsible and what evidence should exist if the control has operated correctly. That gives you something concrete to test.
Look at actual cases
Policies tell you how a process was designed. Files tell you how it operates. Select a small sample of actual customer files or transactions and compare what happened against the requirements of the AML/CTF program.
For example:
Was the required customer information obtained?
Was identity verified in accordance with the agency's procedure?
Was the customer's risk assessed?
Where higher-risk characteristics were identified, were the additional procedures applied?
Is there a clear record of the checks completed?
Where something unusual occurred, is there evidence that it was considered or escalated appropriately?
The objective is not merely to find missing documents, it is to determine whether the control produced the result it was designed to achieve.
Talk to the people applying the controls
File testing should be accompanied by discussions with staff. A short conversation can reveal implementation problems that are difficult to identify from documents alone.
Staff may have developed workarounds because a procedure is impractical. Two employees may interpret the same requirement differently. Training may have covered an obligation without giving staff enough guidance to recognise it in a real customer interaction. These are useful findings because they explain why inconsistency occurs.
Test the evidence, not just the explanation
One of the most common assurance problems is relying on statements about what normally happens: ‘The agent always checks that’, ‘We would escalate something suspicious’, ‘The Compliance Officer reviews those’.
Those explanations may be completely genuine, but assurance requires evidence. A useful test is whether an independent person could examine the file, record or system and reach the same conclusion.
Where important controls leave no evidence, it becomes difficult for management to know whether they are operating consistently and difficult for the agency to demonstrate compliance later.
Look for patterns rather than isolated mistakes
A single incomplete file may be human error. The same omission across several files points towards a control problem. Testing should therefore look for patterns. Repeated problems may indicate unclear procedures, inadequate training, poorly allocated responsibilities, system limitations or a control that is simply too difficult to perform consistently.
The appropriate response depends on the cause. This is why control testing should go beyond identifying exceptions. Its value comes from understanding what those exceptions say about the underlying system.
Use the findings to improve the program
AML/CTF implementation should not be treated as a one-off exercise completed on 1 July 2026.
AUSTRAC's own guidance describes AML/CTF programs as arrangements that need to remain current as business circumstances and risks change. Reviews are expected to identify new risks, weaknesses and control failures and inform updates to the program.
Early control testing therefore serves two purposes: It provides assurance over whether the new arrangements are operating and it creates evidence that the business is actively identifying and improving weaknesses.
For a newly regulated sector, that is a useful discipline to establish from the beginning.
Argus Assurance provides AML/CTF Health Checks and control effectiveness testing for real estate agencies, with a focus on whether documented requirements are operating consistently and effectively in practice.
Need independent assurance over how your AML/CTF controls are operating?