All posts
employee-due-diligenceaml-programstaff-screeningtranche-2governance

Employee due diligence under AML/CTF: the obligation that covers your hires, not your clients

AML/CTF Tranche 2 is live, and your program must include a documented process for screening the staff who perform AML-relevant duties, not just the clients you verify. Here is what a proportionate process looks like for a small agency.

By AML Simple Team

Employee due diligence under AML/CTF: the obligation that covers your hires, not your clients

Ask most agency principals what their AML/CTF program covers and you get the same answer: verifying clients, screening for sanctions, keeping records on file. All correct. All client-facing.

There is a separate obligation sitting in the same program, pointed the other way. It applies to the person you just hired to run your front desk, or the agent you promoted into a role that touches compliance records. Employee due diligence is the part of your AML/CTF program that looks inward, and it is easy to build a program that is thorough on clients and silent on staff.

Start here: check whether your program actually covers this

The fastest way to find out where you stand is the AUSTRAC Readiness Check. It takes around 5 minutes and tells you exactly which parts of your program are documented and which are still open, employee due diligence included. AML Simple's AML/CTF program tools build a documented staff-screening section as part of the same program you use for client CDD, so the obligation lives in one place instead of a separate spreadsheet nobody remembers to update.

That is the fast path. The rest of this post is what the obligation actually requires, whether you use a tool to document it or write it up yourself.

Why this is a program obligation, not a background-check errand

The AML/CTF Act 2006 requires your program to address the risk that a staff member could be the point of failure in your compliance controls, not just the client. An agency's front-line and compliance-adjacent staff have access to identity documents, risk ratings, and the judgment calls that decide whether a transaction gets flagged. If that access is compromised, coerced, or simply careless, the client-facing controls around it don't matter much.

Employee due diligence is how your program documents that you have thought about that risk and done something proportionate about it. It is not a police-check line item you tick once at hiring and forget. Current guidance treats it as three connected pieces:

  1. Screening at hire, before someone starts performing AML-relevant duties, not after.
  2. Ongoing checks, at a frequency and depth that matches the role's risk, not a one-off event.
  3. A risk-based standard, more scrutiny for a compliance officer than for a receptionist with no system access, calibrated the same way the rest of your program is calibrated.

Who it actually applies to

Not every staff member needs the same level of scrutiny, and AUSTRAC does not prescribe one fixed checklist. The threshold is whether a role performs AML-relevant duties. In most small agencies that includes anyone who:

AML-relevant duties (screening applies)

Conducts customer identification or verification
Sets or reviews a client's risk rating
Handles source-of-funds documentation
Monitors transactions for suspicious activity
Has access to compliance records, screening results, or reporting systems
Holds the compliance officer role, including a principal who fills that role themselves

In a 3 to 5-person agency, that description often covers everyone above pure admin. In a larger agency it may be a defined subset. Either way, the first real step is writing down who does what, so the list of who needs screening isn't a guess.

What a proportionate process looks like for a small agency

A documented employee due diligence process does not need to look like a bank's. It needs to be written down, applied consistently, and calibrated to what each role can actually touch. AUSTRAC does not prescribe a specific list of checks, the approach is risk-based: what is appropriate depends on the role's access to compliance functions and the level of risk it carries. For most agencies captured by Tranche 2, a documented process means recording, per role, the four things below.

  1. 1

    What is checked before someone starts

    Common approaches include a police check or equivalent, and confirmation of prior employment or professional registration. The depth should track the role, more for a compliance officer than for a role with no access to compliance systems.

  2. 2

    What is checked on an ongoing basis

    A one-off check at hiring does not cover someone five years into the role. Ongoing checks, at a frequency you set and can justify, are part of what makes this a program obligation rather than an onboarding task.

  3. 3

    How results are recorded and retained

    Employee due diligence records are AML/CTF records. They need to be kept for at least 7 years, the same retention period as your other program records.

  4. 4

    What happens when a check raises a concern

    Your program should say who reviews a flagged result and what the escalation looks like. This is a governance question as much as a compliance one.

Source: AUSTRAC Real Estate Program Starter Kit structure · As of August 2026

The point is not the specific check you run. It is that you have a documented procedure, you applied it, and you kept the records.

The boundary this post will not cross

Screening a person is not the same as screening a document. Employee due diligence sits directly on top of privacy obligations and employment law, both well outside what an AML/CTF compliance tool, or this article, can resolve for you.

What checks you are legally permitted to run, how you handle a flagged result fairly, and what you can and cannot ask a candidate before an offer is made are questions for privacy and employment law, not AML/CTF guidance. If a specific check or a specific flagged result raises those questions for your agency, that is a conversation for an employment lawyer or HR professional, not something to resolve from a compliance checklist. AML Simple documents the AML/CTF side of this, the policy, the roles in scope, and the record. It does not tell you what you are allowed to ask a candidate.

Why it belongs next to your other program components

Employee due diligence is one of the components AUSTRAC's Program Starter Kit structure expects alongside customer due diligence, risk assessment, and governance. Reviewers treat a program that is detailed on clients and blank on staff as incomplete, the same way an independent review would flag it. A missing employee due diligence section is a documented gap regardless of whether anything has ever gone wrong with a hire.

Penalties for a body corporate under the Act run up to A$36.4 million per contravention, and up to A$7.28 million per contravention for an individual, following the penalty unit increase to A$364 from 1 July 2026. Those figures apply across the Act generally, and this post is not suggesting employee due diligence specifically invites a maximum penalty. The more useful frame is the one AUSTRAC reviewers actually use: does the program cover every required component, or does it stop at the client-facing half.

What the market is saying

At the REIV AML/CTF Summit in late April 2026, the Real Estate Employers' Federation (REEF) presented guidance on HR obligations in the AML era, including employment contracts, position descriptions, and appropriate considerations for staff taking on AML Supervisor responsibilities.

An employer body publishing formal guidance on AML employment obligations was an early signal that agencies were starting to ask the HR questions, not just the compliance questions. Employee due diligence sits at the intersection of both, and that intersection is exactly where the privacy and employment-law boundary above matters most.

What to do this week

If your agency has not mapped which roles are AML-relevant, that is the first move, before the screening question even comes up. From there:

  • Write down who at your agency touches client identity, risk ratings, or compliance records.
  • Decide what gets checked at hire and what gets checked on an ongoing basis for each role.
  • Record where the results live and how long they are kept.
  • Confirm who reviews a flagged result and what happens next.

Get employee due diligence into your program, not a separate spreadsheet

The AUSTRAC Readiness Check shows you exactly what's covered and what's still open, in around 5 minutes. AML Simple's program tools then let you document staff screening alongside client CDD in the same place.

Take the AUSTRAC Readiness Check

Sources: Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act 2006); AUSTRAC Real Estate Program Starter Kit and Tranche 2 guidance for real estate agents (austrac.gov.au/reforms/sector-specific-guidance/real-estate-guidance).

Related reading

We use cookies for advertising measurement. See our Privacy Policy.