AML after implementation: how do you know your programme is actually working?

For newly regulated Australian law firms, the months leading up to 1 July were understandably dominated by implementation. There were policies to write, staff to train, systems to configure, responsibilities to assign and new client due diligence processes to bed in. Getting ready was a major piece of work.
Now comes the more important question: is your AML programme actually working in practice?
A programme can look comprehensive on paper and still struggle when it meets the reality of a busy legal practice. Clients do not always arrive with simple ownership structures. Source of funds explanations are not always neat. Matters become urgent. Documents conflict. Staff make judgement calls. Clients push back when they are asked for more information. These are the situations that reveal whether AML has genuinely become part of the way a firm operates, or whether it still sits slightly apart from day-to-day legal work.
The first few months after implementation are therefore a valuable opportunity to look for gaps while they are still relatively easy to correct.
Start with the files, not just the policy
One of the most useful ways to assess how well your AML framework is operating is to review a sample of actual client matters. The question is not simply whether a form has been completed. Look at whether the information collected supports the risk rating, whether identification and verification steps match the client profile, whether purpose and nature have been properly understood and whether any higher-risk indicators were recognised and escalated.
A file review can quickly show where procedures are working well and where staff may be interpreting them differently.
It is also worth looking at consistency. Two lawyers dealing with similar clients should not routinely reach completely different outcomes without a clear reason. Some professional judgement will always be involved, but the programme should give people enough structure to make defensible and repeatable decisions.
Check whether the training has landed
Completing training is not the same as understanding how to apply it. This becomes particularly obvious once people start encountering real matters.
Staff may know the definition of enhanced due diligence but still be unsure when to apply it. They may understand source of funds in theory but struggle to decide when an explanation is sufficient. They may know there is an escalation process but hesitate to use it because they are concerned about delaying a matter or upsetting a client.
These are not unusual problems. They are exactly why post-implementation review matters.
Speak to the people using the process. Ask what is causing friction, which questions clients are pushing back on and where staff are making the most judgement calls. Those conversations can identify issues that will never appear in a policy review alone.
Look for workarounds
Every new process creates some operational friction, and people are naturally good at finding ways around friction. That is useful when it improves efficiency, but potentially risky when the workaround bypasses an important control.
Perhaps documents are being saved outside the intended system. Maybe matters are progressing while information is still outstanding. Perhaps risk ratings are being copied from similar files rather than considered independently. Or maybe teams have developed their own informal rules about what is and is not acceptable.
None of these necessarily indicate poor intent. They often indicate that a process needs refining.
The goal is not to catch people out. It is to find the points where the designed process and the actual process have drifted apart.
Treat your first review as an opportunity to improve
A post-implementation review should give the firm a practical list of what is working, what needs strengthening and what should happen next. It can also help the AML Compliance Officer understand where additional training, clearer guidance or system changes would make the biggest difference.
Importantly, reviewing your programme early also helps establish good habits for the future. AML compliance is not a one-off implementation exercise. Firms will need to monitor, test and improve their controls over time.
AML Sorted’s post-implementation audit is designed to help firms do exactly that. We review your policies, speak with key staff and examine client due diligence on live or completed matters to assess how the programme is being applied in practice. You receive a written report setting out our findings and practical recommendations.
Because the most useful AML programme is not the one that looks perfect in a folder. It is the one your people can use confidently when a real client, a real transaction and a real judgement call land on their desk.
Need practical help making AML work in your firm? Speak to AML Sorted. Reach out to us at hello@amlsorted.com and let's have a chat.
%20(2).png)


