Skip to main content
All industries

AML / CTF / AUSTRAC

Customer risk does not stop at onboarding.

Since 1 July 2026, businesses providing newly covered designated services may need to enrol with AUSTRAC and operate an AML/CTF program. The system question is how people identify, assess, escalate and record a concern without losing control of sensitive information.

A working example / Finance & AML

A risk change needs a controlled path.

An illustrative design question based on this kind of work. This is not a client project, delivered product or claim that every organisation follows this process.

Illustrative decision gate

Restricted risk review

Example ref / RISK-018

Checks before a decision

  1. 01
    New signal

    Information changes the customer's risk picture.

  2. 02
    Existing checks

    Prior due diligence is available to the reviewer.

  3. 03
    Access

    Only authorised people see the review.

  4. 04
    Owner

    A reviewer records the next action and why.

Decision to make

What should an authorised reviewer do with the new signal?

Record to keep

Record the human decision and follow-up without exposing restricted work.

Discovery notes

What has to be checked in the real operation.

The example above frames a design question. These conditions need to be checked with the organisation and its advisers before scope or software behaviour is decided.

  • 01

    AUSTRAC reporting entities must maintain an AML/CTF program, conduct ongoing customer due diligence, and report suspicious matters within 3 business days (or 24 hours where terrorism financing is suspected), with tamper-evident records.

  • 02

    Customer due diligence and ongoing monitoring create records that should show what was checked, by whom, and when further review was required.

  • 03

    Suspicious matter work needs restricted access and a clear escalation path. Disclosing report information is a tipping-off offence where it would or could reasonably be expected to prejudice an investigation.

  • 04

    A useful system makes exceptions, human decisions and follow-up visible without assuming software can make the compliance judgement.

Control the review without exposing it.

Examples to investigate, not off-the-shelf products or a claim that an integration is available.

AML/CTF program systems

Risk assessment frameworks, customer due diligence workflows, and ongoing monitoring, built around the AUSTRAC reporting obligations.

SMR workflow platforms

Encrypted Suspicious Matter Report preparation, statutory deadline tracking, and structured submission records.

KYC/CDD verification systems

Multi-level identity verification, beneficial ownership mapping, and risk-scored customer profiles.

Reviewable action history

Timestamped, tamper-evident records with ownership and export paths that can be assessed during discovery.

Published obligations to check

Rules and timeframes for Finance & AML work.

AUSTRAC

AML/CTF Act 2006

Checked against austrac.gov.au on 23/09/2026.

RefObligationFigure
Ref 2.1: Suspicious Matter Report, general3 business days
Ref 2.2: Suspicious Matter Report, terrorism financing24 hours
Ref 2.3: Customer due diligence records, retention7 years
Ref 2.4: Accountants, lawyers and others regulated since1 July 2026

Bring us the sticking point.

Tell us how this work runs in your organisation. We can assess whether a software project makes sense, with the real rules and existing tools in view.

Send an enquiry