Skip to content

How much evidence is enough when it comes to AML/CTF?

Published September 21, 2026

When you're completing Customer Due Diligence (CDD) or Enhanced Customer Due Diligence (ECDD), one of the hardest questions to answer can be surprisingly simple: How much evidence is enough?  One bank statement? Three months of payslips? A contract of sale? Tax returns? A statutory declaration? Unfortunately, there isn't a magic number or a set checklist.

Under Australia's AML/CTF framework, businesses are expected to take a risk-based approach. AUSTRAC's guidance talks a lot about establishing required matters on reasonable grounds and applying measures that are appropriate and proportionate to the customer's money laundering and terrorism financing (ML/TF) risk.  If these seemingly vague phrases frustrate you, you’re not alone, but there is a good reason why the AML/CTF evidence requirements are not prescribed - there are simply far too many unique circumstances to easily contain them all within a prescribed framework.

What this means for you is that you shouldn’t be aiming to build the biggest possible folder of evidence.  Instead, consider what evidence you can collect that will explain the information your client provides you.  You should be able to understand what it tells you and be able to explain why you were reasonably satisfied with the outcome.

When might you need additional evidence?

There are circumstances where particular information must be collected or verified as part of your CDD obligations (be that initial or enhanced CDD). Your AML/CTF Program should set out how your business will meet those requirements.  But there will also be situations where something about a customer or transaction warrants further investigation.

Perhaps a conveyancing client is purchasing a property without finance and you need to better understand where the funds have come from.  Or a lawyer may be instructed to establish an unexpectedly complex corporate structure.  If you’re an accountant, you may discover information about a beneficial owner that doesn't align with what the client initially provided. Or perhaps a precious metals dealer may notice a customer's transactions have suddenly become much larger or more frequent.

Depending on the circumstances, additional evidence could include bank statements, corporate records, sale documentation, information about Source of Funds or Source of Wealth, or another reliable and independent source.  We talked more about what the concepts of Source of Funds and Source of Wealth are over on a recent blog.

The important point in all of this is that the evidence should have a purpose.  Please don’t make the mistake of collecting documents simply because the customer has received a particular risk rating. You're trying to answer a question or address an identified risk.

What does 'reasonable grounds' actually mean?

This is where professional judgement enters the equation.  AUSTRAC describes "reasonable grounds" as an objective standard. In simple terms, if another reasonable person in your position, with similar knowledge, experience or training, were to review the same information, would they understand how you reached your conclusion?

Imagine another appropriately trained person picked up the file tomorrow…

If the answer is yes, you may be reasonably satisfied.  If there are still unanswered questions, inconsistencies or information that still has some gaps, you may need to keep looking.

More risk may mean more evidence - the ‘risk-based approach’

A risk-based approach means the level of scrutiny you give a transaction or an explanation should reflect the risk you're dealing with.  AUSTRAC specifically notes that businesses will generally collect and verify more information in higher-risk situations than lower-risk ones. Enhanced CDD measures also need to be targeted to the particular risk and be proportionate to it.

Consider two property transactions:

In the first, a long-standing local client is selling their principal residence. Everything you know about the transaction is consistent with the customer's circumstances and nothing unusual arises.

In the second, the purchaser is using funds transferred from several overseas accounts and the explanation initially provided doesn't clearly explain their origin.

It doesn’t make reasonable sense to treat those customers the same.  The second scenario may warrant additional questions and evidence. The first likely doesn’t.  And this is why AUSTRAC requires you to take a risk-based approach.

Two businesses may reasonably reach different conclusions

There's another important nuance in all this and that is that two reporting entities involved with the same customer may not necessarily need exactly the same evidence.  A common example where this might occur is when we look at a real estate agent and conveyancer involved in the same property transaction.

The agent may have spent months interacting with the seller, attended the property, discussed their reasons for selling and observed their behaviour throughout the campaign.  The conveyancer may have access to different information about the transaction, ownership, settlement arrangements and movement of funds.

Both have AML/CTF obligations, but they are looking at that same customer through different lenses, and their business’ AML/CTF Programs and risk assessments likely also differ.  As a result, each business may reasonably decide that different enquiries or evidence are necessary to manage the risk it has identified.

The question isn't: "What did the other reporting entity collect?"

It's: "What does my business reasonably need to know?"

More evidence isn't automatically better

A few months into AML/CTF regulations and this is a conversation that’s come up regularly… That temptation to think, "If I'm unsure, I'll just collect everything."  But that isn't necessarily good compliance either.  It’s important to remember that your AML/CTF obligations sit alongside your other legal responsibilities, including privacy obligations.

Tranche 2 organisations are subject to the Australian Privacy Principles, and APP 3 requires personal information collected to be reasonably necessary for the organisation's functions or activities. The Office of the Australian Information Commissioner (OAIC) specifically encourages a data minimisation approach, limiting collection to the minimum amount necessary in the circumstances.  That makes the "just collect everything" approach problematic.

More information means more personal data to securely store, manage and eventually dispose of. It can also increase the consequences of a data breach.

Balance is important: Collect what you are required to collect, and only collect additional information where it's reasonably necessary to understand and manage the identified ML/TF risk.  But don't collect sensitive financial information simply because having more documents feels safer.

Ten documents with no context may tell you less than two with a good file note

If you finish reading this article with only one takeaway, make it this one: Evidence without context doesn't necessarily demonstrate good decision-making.  Imagine we’re three years down the road and you are completing your first AML audit.  The auditor opens a file from three years ago, which contains 15 bank statements, two contracts and an ASIC extract, and that’s it.  Why are they there? What was the concern? What was the person reviewing them trying to establish, and what conclusion did they reach?

It will be very difficult for anyone, including yourself to reverse-engineer your thought process from a pile of documents months or years later.

Now compare that with a file containing the same supporting evidence but this time, with a clear note explaining:

"Customer identified as higher risk due to purchase funds originating overseas. Customer advised funds represent proceeds from the sale of their previous residence. Sale documentation and bank statement reviewed confirming receipt of proceeds. Information is consistent with customer's explanation and no further discrepancies identified. Satisfied that identified risk has been appropriately addressed."

The second file tells a story, which can be understood by third parties, at any point in the future.

Importantly, AUSTRAC's record-keeping guidance requires CDD records to demonstrate not only what information was collected and how it was verified, but also the analysis, risk assessment and decision-making that explains why that level of CDD was applied.  When unusual activity is reviewed, AUSTRAC similarly expects businesses to document the steps taken, decisions made, how they responded and why. Your file note becomes part of the evidence.

Ask yourself three questions

When you're wondering whether you've collected enough, come back to three things:

  1. What am I trying to establish?  Be clear about the risk or question you're addressing.
  2. Does the evidence reasonably answer that question? Look at the quality and relevance of the information, not simply the quantity.
  3. Could someone else understand why I reached this decision?  Document your reasoning so another appropriately trained person could follow the same trail.

Sometimes one reliable piece of evidence will answer your question, whereas other times you'll need several.  That's professional judgement in action.

Evidence + context = stronger compliance

easyAML is designed to help businesses manage both sides of that equation.  The platform brings your customer risk assessment, CDD and ECDD processes, supporting evidence and decision-making together, so you're not simply accumulating documents.  There is one central source-of-truth for you to maintain the context explaining why they were requested and how you reached your conclusion.

Good AML compliance demonstrates not just that you identified the risk, but that you made reasonable enquiries, exercised professional judgement and can clearly explain why you were satisfied.

Get started with easyAML for free today. With no credit card required and no commitments, you’ve got nothing to lose (except for uncomplicated compliance).