← Back

10 Critical Questions to Ask Your AML Provider After 1 July 2026

Published: 1 September 2026 | Topic: Provider Evaluation | Read time: 8 minutes

You have purchased AML compliance software or engaged a provider. The question now is: have you actually bought compliance, or just a workflow tool?

Here are 10 critical questions every principal should ask their AML provider to assess whether your framework is genuinely defensible. Print this list. Email it to your provider. See how they answer.

1. Who is our named Compliance Officer and what are their qualifications?

Why this matters: AUSTRAC requires a named, qualified Compliance Officer. A login is not a person.

What you want to hear: A specific name, their AML/CTF qualifications or experience, their professional background, and what training they've completed.

Red flag: "Your staff member," "a position," "your login," or vague answers about team involvement. If they cannot name a person, you do not have a CO.

2. If our CO is unavailable (illness, leave, emergency), how is coverage arranged?

Why this matters: AUSTRAC will ask this. If your CO is the only person with authority to make SMR/escalation decisions and they disappear, you cannot operate.

What you want to hear: A named backup, their qualifications, and how handover occurs.

Red flag: "We have not thought about this," "it has not come up," or "the backup is less qualified."

3. How much time does our CO spend on our account weekly/monthly?

Why this matters: If your CO spends 1 hour per month on your account and you process 500+ transactions monthly, they are not adequately resourced.

What you want to hear: A specific commitment (e.g., "minimum 4 hours per week" or "dedicated to your account").

Red flag: Vagaries like "as needed" or "proportional to size." This often means "minimal."

4. Can you show me records of CO involvement in our escalations this quarter?

Why this matters: This is the evidence AUSTRAC will ask for. Do you have documented records that a real person reviewed flagged customers and made decisions?

What you want to hear: Specific examples with dates, decision notes, and CO sign-off.

Red flag: "We don't track that," "it's all in the system," or no examples provided.

5. If we have an international company owner, how does your provider handle beneficial owner identification?

Why this matters: Automated systems cannot verify offshore ownership. The question reveals whether your provider has a judgment-making process or just automated flagging.

What you want to hear: "Our Compliance Officer investigates using available sources and documents findings and gaps," not "our system checks a database."

Red flag: "We only use API verification" or "if the system cannot verify, we decline the customer." (The first is incomplete; the second is operationally problematic.)

6. How are Suspicious Matter Reports (SMR) actually decided, and who has authority to lodge them?

Why this matters: SMRs are critical compliance decisions. If your software auto-generates them without CO review, you may be filing frivolous reports or, conversely, missing required ones.

What you want to hear: "Our Compliance Officer evaluates escalations against your risk profile and decides SMR necessity. They have exclusive authority to lodge SMRs."

Red flag: "The system generates SMR recommendations," or "anyone can lodge an SMR."

7. What happens if your company ceases operations or we terminate the contract?

Why this matters: You need a clear handover plan and your 7-year records. If they disappear, you're in trouble.

What you want to hear: "We provide a complete record export, transition support, and documentation of all decisions to date."

Red flag: "That's not part of our agreement," or vague promises of cooperation.

8. Are you involved in our independent evaluation preparation, and what will that cost?

Why this matters: Your provider should help you prepare for independent evaluation (AUSTRAC can require one every 10 years, sooner if risk is elevated).

What you want to hear: "Yes, included in our service" or "yes, for an additional fee." Not surprised or vague.

Red flag: "That is your responsibility," or "we have not handled that."

9. If an AUSTRAC audit happens, will you support us and provide your records?

Why this matters: In an audit, AUSTRAC may request records directly from your provider. You need certainty they will cooperate and be transparent.

What you want to hear: "Yes, we have protocols for audit support and will provide AUSTRAC with records of our involvement."

Red flag: Hesitation, concerns about "confidentiality," or "you will need to request records from us."

10. If there is a regulatory enforcement action related to AML compliance, what is your liability and what insurance do you carry?

Why this matters: If something goes wrong, where does liability lie? A professional provider should have professional indemnity insurance.

What you want to hear: Clarity on liability allocation (usually: provider liable for provider failures, you liable for business decisions), and confirmation of adequate insurance.

Red flag: "Not our problem," or "you assume all liability." (This means they take none.)

Red Flags Summary

If your provider cannot clearly answer these questions, or answers suggest:

...you likely have a software platform, not compliance governance. This is fixable, but you need to know it now.

Want a Second Opinion?

If your current provider's answers concern you, AMLHQ can review your arrangements and discuss whether hybrid (keep software + add AMLHQ CO oversight) or full transition makes sense.

Email admin@amlhq.com.au — no obligation