Skip to main content

Resources › Guide

AML/CTF Compliance Guide
for Australian reporting entities

Australia’s AML/CTF rules apply when a business provides a designated service with a geographical link to Australia. The expanded regime has been in force since 1 July 2026. This guide outlines the questions to check before designing a system around it.

Reviewed 4 October 2026 against the AUSTRAC sources linked below. General information only; confirm which obligations apply to your designated services with AUSTRAC and qualified Australian advisers.

On this page
1

Who is a reporting entity?

The question is which designated service a business provides, and whether that service has a geographical link to Australia. The business’s profession or industry label alone does not decide whether it must enrol.

Examples of sectors with designated services include:

  • Banks, credit unions, and authorised deposit-taking institutions
  • Insurance companies and brokers providing life insurance or annuity products
  • Superannuation fund trustees
  • Finance companies providing consumer credit
  • Currency exchange services and remittance dealers
  • Virtual asset service providers
  • Bullion dealers
  • Casinos and gambling providers (in certain circumstances)
  • Loan brokers and finance intermediaries

Check the exact service against AUSTRAC’s designated-services guidance. A business providing a designated service with the required Australian link must enrol; remittance and virtual asset providers also have registration requirements.

2

The four pillars of AML/CTF compliance

These four areas are a useful way to plan a workflow. The duties that apply depend on the designated service, the business and any transitional arrangements.

Pillar 1

Customer Due Diligence (CDD)

Apply initial and ongoing customer due diligence under a risk-based program. The information collected and verified depends on the customer and the assessed risk.

Pillar 2

Transaction Monitoring

Monitor customers and activity for changes in risk and signs of suspicious behaviour. The appropriate process depends on the services and risks involved; a real-time software feed is not universally required.

Pillar 3

Regulatory Reporting

SMRs are due within 24 hours for terrorism-financing suspicions and generally within 3 business days for other suspicions; a legal-professional-privilege exception may affect the latter deadline. A designated service involving $10,000 or more in physical currency can trigger a TTR. Other reports depend on the service.

Pillar 4

AML/CTF Program

Document a risk assessment and AML/CTF policies, obtain the required senior-manager approval, review them when required, and arrange independent evaluation. Evaluation frequency must suit the business and be at least once every 3 years, subject to first-evaluation transitional deadlines.

The program should describe how the organisation performs its obligations in practice. AUSTRAC’s guidance distinguishes the organisation’s own reviews from an independent evaluation of the program.

3

Tranche 2: July 2026 reforms

Expanded regime in force since 1 July 2026

The reforms expanded designated services to work done in legal, accounting, real estate and precious-goods businesses, among others.

Services to check include:

  • Certain legal and conveyancing services
  • Certain accounting, trust and company services
  • Certain real-estate services
  • Certain dealings in precious metals, stones and products

If you provide a designated service, check your enrolment and program duties now. AUSTRAC says newly regulated businesses providing a designated service from 1 July 2026 had until 29 July 2026 to apply to enrol. A business starting later must apply within 28 days after it starts providing a designated service. Transitional arrangements can affect when some existing entities must complete their first independent evaluation and move to the new CDD framework.

4

Record retention depends on the record

Many AML/CTF records must be retained for at least 7 years, but the clock does not always start when the record is made. For example, AUSTRAC says:

  • CDD records are kept for 7 years after an ongoing business relationship ends, or after an occasional transaction is completed
  • Transaction records are generally kept for 7 years after the transaction is completed
  • Program records are kept until 7 years after they are no longer relevant to demonstrating compliance

Map each record type to its statutory retention trigger before setting deletion rules. Records must remain accessible, accurate and secure for the applicable period.

5

What happens when obligations are missed

AUSTRAC can take enforcement action for breaches of AML/CTF obligations. The consequence depends on the provision, the conduct and the circumstances. A system should therefore show who is responsible for a task, when it was completed and what evidence supports it. Obtain legal advice for penalty exposure in a particular situation.

6

How software supports AML/CTF compliance

Software can help people keep decisions, deadlines and evidence connected. The reporting entity remains responsible for its program and reports. Useful functions to assess for a particular workflow include:

  • CDD steps with role assignment and a record of human decisions
  • Retention rules matched to the type of record and its statutory trigger
  • Restricted SMR escalation and deadline tracking, including the 24-hour terrorism-financing window
  • TTR preparation where a designated service involves at least $10,000 in physical currency
  • Exportable records of program changes, reviews and training

Sources checked on 4 October 2026

Designing an AML/CTF workflow?

We can discuss how software might support responsibilities, reviews and records in your operation. Your qualified advisers should confirm the obligations before they become system requirements.