AML / CTF / AUSTRAC
Customer risk does not stop at onboarding.
Since 1 July 2026, businesses providing newly covered designated services may need to enrol with AUSTRAC and operate an AML/CTF program. The system question is how people identify, assess, escalate and record a concern without losing control of sensitive information.
A working example / Finance & AML
A risk change needs a controlled path.
An illustrative design question based on this kind of work. This is not a client project, delivered product or claim that every organisation follows this process.
Restricted risk review
Checks before a decision
- 01New signal
Information changes the customer's risk picture.
- 02Existing checks
Prior due diligence is available to the reviewer.
- 03Access
Only authorised people see the review.
- 04Owner
A reviewer records the next action and why.
What should an authorised reviewer do with the new signal?
Record the human decision and follow-up without exposing restricted work.
Discovery notes
What has to be checked in the real operation.
The example above frames a design question. These conditions need to be checked with the organisation and its advisers before scope or software behaviour is decided.
- 01
AUSTRAC reporting entities must maintain an AML/CTF program, conduct ongoing customer due diligence, and report suspicious matters within 3 business days (or 24 hours where terrorism financing is suspected), with tamper-evident records.
- 02
Customer due diligence and ongoing monitoring create records that should show what was checked, by whom, and when further review was required.
- 03
Suspicious matter work needs restricted access and a clear escalation path. Disclosing report information is a tipping-off offence where it would or could reasonably be expected to prejudice an investigation.
- 04
A useful system makes exceptions, human decisions and follow-up visible without assuming software can make the compliance judgement.
Control the review without exposing it.
Examples to investigate, not off-the-shelf products or a claim that an integration is available.
AML/CTF program systems
Risk assessment frameworks, customer due diligence workflows, and ongoing monitoring, built around the AUSTRAC reporting obligations.
SMR workflow platforms
Encrypted Suspicious Matter Report preparation, statutory deadline tracking, and structured submission records.
KYC/CDD verification systems
Multi-level identity verification, beneficial ownership mapping, and risk-scored customer profiles.
Reviewable action history
Timestamped, tamper-evident records with ownership and export paths that can be assessed during discovery.
Published obligations to check
Rules and timeframes for Finance & AML work.
| Ref | Obligation | Figure |
|---|---|---|
| 2.1 | Ref 2.1: Suspicious Matter Report, general | 3 business days |
| 2.2 | Ref 2.2: Suspicious Matter Report, terrorism financing | 24 hours |
| 2.3 | Ref 2.3: Customer due diligence records, retention | 7 years |
| 2.4 | Ref 2.4: Accountants, lawyers and others regulated since | 1 July 2026 |
Bring us the sticking point.
Tell us how this work runs in your organisation. We can assess whether a software project makes sense, with the real rules and existing tools in view.
Send an enquiryRelated capabilities