Australia's new Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) reforms have created a significant new responsibility for thousands of Australian businesses.
But there's a danger in how businesses respond.
They could do everything required on paper and still fail to build an effective compliance culture.
A policy is written.
A risk assessment is completed.
A client is identified.
A sanctions check is performed.
Staff complete their training.
The boxes are ticked.
But does the business actually understand the risks it faces?
That's the question that matters.
Effective AML compliance isn't about creating the largest possible collection of policies, forms and procedures.
It's about building a framework that helps people make better decisions.
For example, a risk assessment shouldn't simply sit in a folder because the business is required to have one.
It should help the business understand where its particular vulnerabilities lie.
Staff training shouldn't simply involve watching a presentation and recording attendance.
People need to understand what they should be looking for, when they should ask questions and what they should do when something doesn't make sense.
And documentation shouldn't exist simply because a regulator might ask to see it.
It should provide a clear record of how and why important decisions were made.
This is particularly important because AML compliance is risk-based.
There isn't a single process that will work equally well for every business.
A large property group, a suburban real estate agency, an accounting practice and a law firm may face very different risks.
Their compliance frameworks should reflect those differences.
The objective isn't to make every business operate like a financial crime investigation unit.
It's to ensure businesses understand their risks and have appropriate systems, controls and accountability in place to manage them.
Technology can help.
It can make identification, screening, record keeping and other compliance processes more efficient.
But technology alone doesn't create compliance.
Neither does a policy.
Neither does a risk assessment.
And neither does a completed checklist.
Compliance ultimately comes down to people understanding what is expected of them and having the processes, information and support they need to make sound decisions.
That's why the most effective AML programs are likely to be the ones that become part of normal business operations rather than something that sits alongside them.
The real test isn't whether a business can say:
"We've completed our AML requirements."
It's whether it can confidently say:
"We understand our risks, we know what we're doing about them, and we can demonstrate why."
That's the difference between having an AML program and actually having an effective one.

