AML Audit Readiness: AUSTRAC Tranche 2 Records
An AML audit is not passed by having a policy document alone. The organisation needs to demonstrate how its programme operates, how risks are assessed, how decisions are made and how required records are maintained.
AUSTRAC Tranche 2 brings new sectors into Australia’s AML/CTF regime and reinforces the importance of governance, customer due diligence, reporting and record keeping. For organisations preparing for review, customer interaction records may form part of the evidence supporting those activities.
This does not mean every phone call, meeting, message or screen interaction must be recorded. It means organisations should understand which interactions support an AML/CTF obligation or control and ensure those records are accurate, complete, appropriately retained and retrievable.
What an AML audit is likely to test
The exact scope will depend on the organisation, its services and its risk profile. However, an independent evaluation, internal audit or regulatory review may examine whether the AML/CTF programme is risk-based, current, implemented and operating effectively.
Reviewers may look for evidence that the organisation:
- has identified and assessed its money laundering, terrorism financing and proliferation financing risks;
- has appropriate customer due diligence and enhanced due diligence processes;
- can explain decisions about customer risk, monitoring and escalation;
- has trained relevant employees and assigned clear accountability;
- meets reporting obligations and retains supporting records;
- reviews and improves the programme when risks, products or services change.
AUSTRAC’s guidance on changes to AML/CTF obligations provides the official context for current reporting entities and the reform transition.
Why interaction records may matter
Many AML/CTF decisions begin with or are clarified through an interaction. A customer may explain the purpose of a transaction, provide additional identity information, respond to a due-diligence query or challenge an account restriction. An employee may escalate concerns, obtain approval or document why a particular action was taken.
Where that interaction supports a control or decision, the organisation may need more than a brief case note. It may need a reliable record that can be connected to the correct customer, transaction, risk assessment or report.
The difference between a record and defensible evidence
A record exists when information has been captured. Defensible evidence is a record whose integrity, context and handling can be demonstrated. For an AML audit, that distinction can be important.
A defensible interaction record should be:
- complete enough to support the relevant decision or control;
- linked to the correct customer, case or transaction;
- retained under an approved policy;
- protected from unauthorised alteration or deletion;
- accessible only to authorised users;
- retrievable without excessive delay;
- supported by an audit trail of access and administrative activity.
Five interaction-record tests before an AML audit
1. Coverage
Identify the channels through which compliance-significant interactions occur. These may include contact-centre calls, Microsoft Teams, video meetings, messaging, email, web chat or case-management notes. Coverage should follow the organisation’s obligations and risk assessment, not a blanket assumption that every channel must be recorded.
2. Context
Test whether a reviewer can connect the interaction to the relevant customer, transaction, risk rating, alert or escalation. A file without context may be difficult to use as evidence.
3. Integrity
Confirm that records are protected from unauthorised change and that the organisation can demonstrate how they were captured, stored and handled.
4. Retention
Check that applicable retention rules are defined and enforced across all relevant systems. AUSTRAC guidance states that many AML/CTF records must be retained for seven years, but the precise requirement depends on the record and obligation.
5. Retrieval
Run a sample request across current and archived systems. The organisation should be able to locate the correct record, supporting information and audit history without depending on informal knowledge or extensive manual assembly.
Common reasons audit evidence breaks down
- Interaction records are distributed across several communication platforms.
- Case notes refer to evidence that cannot be located.
- Retention settings differ between systems or business units.
- Legacy records become inaccessible after a platform migration.
- Exports lose metadata or audit history.
- Access is poorly controlled or cannot be reconstructed.
- The organisation cannot distinguish compliance-significant interactions from general communications.
These weaknesses are often symptoms of fragmented governance rather than a complete absence of records. The organisation may have captured the interaction but still struggle to prove that the record is complete, trustworthy and linked to the relevant AML/CTF process.
Build a repeatable evidence process
Audit readiness improves when record retrieval is treated as an operational capability rather than a one-off exercise. A repeatable process should define:
- which interaction records are in scope and why;
- where those records are captured and stored;
- how they are connected to customer and case information;
- which retention and access policies apply;
- who is authorised to retrieve or export them;
- how the organisation records the retrieval and disclosure;
- how issues discovered during testing are remediated.
This creates a clearer line between the AML/CTF programme, day-to-day operations and the evidence available to demonstrate compliance.
How Liquid Voice supports audit-ready interaction records
Liquid Voice provides a governed approach to capturing and retaining communications across voice and digital channels. Its compliance solution supports controlled access, policy-led retention, search and retrieval across complex and changing technology environments.
Explore the Liquid Voice Compliance Solution to see how interaction records can be governed across their lifecycle.
Read the Compliance Readiness Guide
The Compliance Readiness Guide provides a broader framework for assessing capture, governance, retention, retrieval and auditability. Use it alongside your organisation’s AML/CTF programme, legal advice and audit plan to identify practical evidence gaps before scrutiny begins.