Understanding the Australian AML/CTF Regime
The Australian Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) regime exists to detect, deter and disrupt money laundering, terrorism financing and proliferation financing. A person or business that provides a designated service with the required Australian connection may be a reporting entity and must comply with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act) and the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025.
Primary guidance: AUSTRAC obligations and guidance. Regime and reform context: Attorney-General’s Department.
What is AUSTRAC’s role?
The Australian Transaction Reports and Analysis Centre (AUSTRAC) is the regulatory body responsible for overseeing the AML/CTF regime. AUSTRAC functions as both a regulator and a financial intelligence unit (FIU). As a regulator, it ensures businesses comply with their obligations. As an FIU, it collects and analyses financial reports to assist law enforcement agencies.
Who must comply?
Coverage turns on the designated service being provided, not simply a business label. Existing regulated sectors were joined by newly regulated tranche-two services from 1 July 2026. The expanded regime includes certain services typically provided by:
- Established regulated sectors: banks and other financial service providers, remittance providers, gambling businesses, bullion dealers and virtual asset service providers.
- Legal and conveyancing services: lawyers, conveyancers and other legal professionals when they provide designated higher-risk services.
- Accounting and professional services: accountants and trust and company service providers when their work falls within a designated service.
- Real estate services: real estate agents, buyer’s agents and property developers when providing designated services covered by the Act.
- Precious metals and stones: dealers in precious metals, precious stones and relevant products when providing covered services.
Changes for existing reporting entities generally commenced on 31 March 2026. Enrolment opened for newly regulated sectors on that date, and AML/CTF obligations for tranche-two entities commenced on 1 July 2026. Because coverage depends on the service and statutory definitions, this summary does not determine whether a particular business is a reporting entity.
What are the core obligations for reporting entities?
If your business falls under the AML/CTF Act, you must operationalise a range of controls to identify and mitigate financial crime risk. The core obligations include:
- Enrolment and Registration: You must enrol with AUSTRAC. Some sectors, such as remitters and digital currency exchanges, must also register before commencing operations.
- Risk Assessment: You must identify and assess the ML/TF risks specific to your business, considering your customer base, services, delivery channels and jurisdictions.
- AML/CTF Program: You must develop, document and implement a comprehensive program detailing how your business manages ML/TF risk.
- Customer Due Diligence (CDD): You must verify the identity of your customers before providing a designated service and conduct ongoing monitoring throughout the relationship.
- Reporting: You are legally required to report suspicious matters (SMRs), threshold transactions (TTRs) of $10,000 or more in physical currency, and international funds transfer instructions (IFTIs).
- Record Keeping: Customer identification records and transaction details must generally be retained for a minimum of seven years.
What happens if a reporting entity does not comply?
AUSTRAC takes a robust approach to enforcement. Failures in operationalising your AML/CTF obligations can result in severe consequences, including significant civil penalties, enforceable undertakings, infringement notices, and reputational damage. Compliance is not merely a documentation exercise; it is an active, ongoing operational requirement.