AML/CTF PROGRAM
Part A – Risk-Based Systems and Controls
Part B – Employee Due Diligence and Training
CJ Financial Pty Ltd
ABN: 33 618 593 776 | AUSTRAC Account Number (AAN): pending — to be inserted upon AUSTRAC enrolment
Version 1.0 | Approved by: The Partners (Lara O'Byrne and Merlina Viernes) | Date: to be dated upon signing
Next scheduled review: 12 months from the date of signing
How to use this document
Drafting note: This Program has been completed for CJ Financial Pty Ltd, tailored to a small accounting partnership whose only designated service is forming and administering companies and trusts for clients. It is not a substitute for legal advice, and it is not AUSTRAC-approved — no program is "pre-approved"; AUSTRAC assesses adequacy if and when it reviews you. The remaining highlighted items are dates and the AUSTRAC Account Number, which only exist once the Program is signed and the Firm is enrolled with AUSTRAC. Have a lawyer or AML/CTF specialist review this before relying on it, particularly the risk assessment and CDD thresholds, since getting these wrong carries civil penalty exposure.
This Program has two parts, consistent with AUSTRAC's requirements for reporting entities:
- Part A – governance, risk assessment, and the systems and controls the firm uses to identify, mitigate and manage money laundering and terrorism financing (ML/TF) risk.
- Part B – employee due diligence and the training program that ensures staff understand and can meet their AML/CTF obligations.
PART A
Risk-Based Systems and Controls
A1. Purpose and application
This Program sets out how CJ Financial Pty Ltd ("the Firm") identifies, assesses, mitigates and manages the risk that its services could be used to facilitate money laundering or the financing of terrorism (ML/TF), in accordance with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (the AML/CTF Act) and associated Rules.
This Program applies to all partners, employees and contractors of the Firm who are involved in providing designated services, and to all clients who receive those services.
A2. Designated services provided by the Firm
The Firm has assessed the services it provides against the designated services tables in the AML/CTF Act. The Firm has identified that it provides the following designated service(s):
- Company and trust formation and administration — including incorporating companies, establishing trusts and other legal structures for clients, and providing registered office, nominee director/secretary or trustee services where applicable.
Drafting note: Confirm precisely which of the sub-limbs apply (e.g. forming companies, acting as registered agent, providing a registered office, acting as nominee director/secretary or trustee, or arranging for another person to act in those roles). If the firm's role is limited to formation only and it never acts as a continuing office holder, say so explicitly here — the scope drives everything downstream in this Program.
The Firm has determined it does NOT currently provide other designated services (such as managing client money/assets held on trust, or facilitating property or business sale transactions). This position must be reassessed whenever the Firm's service offering changes (see A11).
A3. Governance and accountability
| Role | Person / Responsibility |
| Governing body | The Partners of CJ Financial Pty Ltd (Lara O'Byrne and Merlina Viernes), collectively responsible for approving this Program, overseeing its effectiveness, and ensuring adequate resourcing. |
| AML/CTF Compliance Officer | Lara O'Byrne, Managing Director & Partner, appointed to align with Program approval date. Notified to AUSTRAC within 14 days of AUSTRAC enrolment. Responsible for day-to-day oversight of this Program, CDD decisions escalated to them, suspicious matter assessment, liaison with AUSTRAC, and reporting to the Partners at least annually. |
| Senior manager (if distinct from Compliance Officer) | N/A — role held by the Compliance Officer in this small partnership |
| All staff | Must complete AML/CTF training (Part B) and apply this Program to every client receiving a designated service. |
The Compliance Officer has the authority and practical access needed to perform this role effectively, including direct access to client files, the ability to decline or pause an engagement on AML/CTF grounds, and a standing item to report to the Partners.
A4. ML/TF risk assessment
The Firm has assessed its ML/TF risk across the standard risk categories. This assessment determines the level of due diligence applied to each client (see A5–A6) and must be reviewed at least annually or when a material change occurs.
A4.1 Customer risk
- Higher risk indicators: clients who are politically exposed persons (PEPs) or close associates; clients using complex or opaque ownership structures without an evident commercial rationale; clients requesting structures across multiple jurisdictions with no clear connection to the client's business; new clients referred with little background information; cash-intensive client businesses; reluctance to provide beneficial ownership information.
- Lower risk indicators: long-standing clients well known to the Firm; Australian resident individuals and companies with transparent, simple ownership; publicly listed entities and their subsidiaries; government bodies.
A4.2 Service / channel risk
- Company and trust formation is inherently a higher-risk designated service because it can be used to obscure beneficial ownership. The Firm treats all instructions to form a company, trust or other structure as at least standard risk, escalating to enhanced due diligence where any higher-risk indicator in A4.1 or A4.3 is present.
- Non-face-to-face onboarding (fully remote engagements) is treated as a risk-elevating factor requiring stronger identity verification.
A4.3 Jurisdiction risk
- Higher risk: clients, beneficial owners, or underlying assets connected to jurisdictions identified by FATF as having strategic AML/CTF deficiencies, or subject to Australian sanctions regimes.
- The Firm screens relevant jurisdictions against the current FATF lists and DFAT Consolidated List at onboarding and periodically thereafter (see A7).
A4.4 Overall risk rating
Based on the above, the Firm assesses its overall inherent ML/TF risk as Medium, reflecting that company/trust formation is a recognised higher-risk designated service, moderated by a client base that is predominantly long-standing, Australian-resident, and low-complexity.
A5. Customer due diligence (CDD)
Before providing a designated service, the Firm must complete initial CDD, comprising:
- Client identification and verification — for individuals: full name, date of birth, and residential address, verified against a reliable and independent document, data or electronic source (e.g. current passport or driver's licence).
- For companies/trusts: verification of legal name, registration/ACN or ABN, registered office, and structure, using ASIC or equivalent records.
- Beneficial ownership identification — identifying and, on a risk basis, verifying any individual who ultimately owns or controls 25% or more of the client (or exercises control by other means), including for any new company or trust the Firm is forming.
- Purpose and intended nature of the engagement — recording why the client wants the structure formed and its intended use.
- Source of funds / source of wealth — at a level proportionate to risk; enhanced detail required for higher-risk clients (see A6).
- PEP and sanctions screening — screening the client and beneficial owners against the DFAT Consolidated List and a recognised PEP database before the engagement proceeds.
CDD must be completed before the designated service is provided, not after. Where CDD cannot be completed, the Firm must not proceed with the engagement and should consider whether a suspicious matter report is required (A8).
A6. Enhanced customer due diligence (ECDD)
ECDD applies automatically where a client or matter presents any higher-risk indicator identified in A4, including all PEP clients, high-risk jurisdiction connections, or complex/opaque structures. ECDD requires:
- Approval from the Compliance Officer before the engagement proceeds.
- Verified (not merely self-reported) source of funds and source of wealth.
- Verification of all beneficial owners, regardless of ownership percentage, where the structure is complex.
- More frequent ongoing review — at minimum annually, or on any trigger event.
- Senior management sign-off recorded on the client file.
Simplified due diligence may only be applied to categories expressly permitted under the AML/CTF Rules (e.g. certain listed public companies or government bodies) and must still include basic identity verification.
A7. Ongoing customer due diligence and monitoring
- Re-screen active clients and beneficial owners against sanctions and PEP lists at least annually, and immediately on a risk basis where a trigger event occurs, and whenever a name-match alert is raised elsewhere in the Firm.
- Keep client identification and beneficial ownership information current — trigger a review when a client instructs a change to a structure's ownership, directors, or control.
- Monitor for changes in client behaviour or instructions that are inconsistent with the known purpose of the structure (e.g. unexplained changes in beneficial ownership, requests to insert layers of offshore entities with no commercial rationale).
A8. Suspicious matter reporting
Any partner or staff member who forms a suspicion that a matter may relate to ML/TF, tax evasion, or other relevant offence must report it immediately and confidentially to the Compliance Officer, who is responsible for assessing whether a Suspicious Matter Report (SMR) must be lodged with AUSTRAC within the statutory timeframe (24 hours where the suspicion relates to terrorism financing; 3 business days otherwise).
Drafting note: Tipping-off is a criminal offence — staff must not inform the client (or anyone else) that a suspicion has been formed or a report made. Consider adding an internal escalation form as an appendix.
A9. Record keeping
- All CDD records, transaction records, risk assessments, and internal reports (including SMR assessments, whether or not a report was lodged) are retained for at least 7 years from the end of the client relationship, in accordance with the AML/CTF Act.
- Records are stored securely in the Firm's CJ Workflow practice management system, with client identification and supporting documents held in the Firm's secure client files, with access restricted to partners and staff members directly engaged in that client's designated service.
A10. Reliance and Designated Business Groups
Not applicable — the Firm conducts its own CDD in all cases and does not currently form part of a Designated Business Group.
A11. Program review and update
- This Program is reviewed by the Compliance Officer and approved by the Partners at least annually, and immediately following any material change to the Firm's services, client base, ownership, or the AML/CTF Rules.
- An independent review of the effectiveness of this Program (which may be conducted internally by someone independent of its day-to-day operation, or externally) is conducted at least every 3 years, with findings reported to the Partners.
PART B
Employee Due Diligence and Training
B1. Employee due diligence
Before a new partner, employee or contractor is given a role involving AML/CTF obligations (including access to client files for designated services), the Firm carries out proportionate background checks, including:
- Verification of identity and right to work.
- Verification of relevant professional qualifications and, where applicable, a police/National Police Check for roles with elevated AML/CTF responsibility (e.g. the Compliance Officer).
- A check of the individual's employment history for unexplained gaps or matters relevant to trust and integrity.
Due diligence outcomes are recorded on the individual's personnel file and reviewed if new information comes to light.
B2. AML/CTF training program
All partners, employees and relevant contractors receive AML/CTF training appropriate to their role, delivered as follows:
| When | Who | Content |
| Induction (before handling any designated service) |
All new partners, staff and relevant contractors |
This Program; how to identify a designated service; CDD/ECDD procedures; red flags; how to escalate a suspicion; tipping-off offence. |
| Annual refresher |
All staff covered above |
Program updates; case studies/typologies relevant to company and trust formation; recap of escalation procedure. |
| Role-specific |
Compliance Officer / partners |
SMR assessment and lodgement; ECDD approval; regulatory reporting obligations; AUSTRAC liaison. |
| Ad hoc |
All staff |
Triggered by a material change to this Program, a new typology alert from AUSTRAC, or an identified gap in staff understanding. |
B3. Training records
- The Firm maintains a record of who has completed each training session, the date, and the content covered, retained for at least 7 years.
- Completion of induction training is a precondition to independently handling a client matter involving a designated service.
B4. Competency and awareness
Training is designed to ensure staff can, at minimum: recognise when a matter involves a designated service; apply the correct level of CDD/ECDD; recognise red flags relevant to company and trust formation (e.g. layered ownership with no commercial rationale, reluctant beneficial ownership disclosure, unexplained urgency); and know exactly who to escalate a concern to and how, without alerting the client.
Approval
This AML/CTF Program (Parts A and B) was approved by the Partners of CJ Financial Pty Ltd and takes effect from the date signed below: to be dated upon signing.
Signed: _______________________ Signed: _______________________
Lara O'Byrne Merlina Viernes
Compliance Officer: _______________________ Date: _______________________