Understanding the Australian AML/CTF Regime

Written by , Principal Consultant
Reviewed: 19 September 2026
Australian Regulatory Guidance
Educational notice: This information is educational and general in nature. It is not legal advice and does not determine whether your business is a reporting entity. Your obligations depend on your services, circumstances, ML/TF risk and the law in force. Check the current AUSTRAC guidance and legislation linked below, and obtain qualified advice where needed.

The Australian Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) regime exists to detect, deter and disrupt money laundering, terrorism financing and proliferation financing. A person or business that provides a designated service with the required Australian connection may be a reporting entity and must comply with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act) and the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025.

Primary guidance: AUSTRAC obligations and guidance. Regime and reform context: Attorney-General’s Department.

What is AUSTRAC’s role?

The Australian Transaction Reports and Analysis Centre (AUSTRAC) is the regulatory body responsible for overseeing the AML/CTF regime. AUSTRAC functions as both a regulator and a financial intelligence unit (FIU). As a regulator, it ensures businesses comply with their obligations. As an FIU, it collects and analyses financial reports to assist law enforcement agencies.

Who must comply?

Coverage turns on the designated service being provided, not simply a business label. Existing regulated sectors were joined by newly regulated tranche-two services from 1 July 2026. The expanded regime includes certain services typically provided by:

  • Established regulated sectors: banks and other financial service providers, remittance providers, gambling businesses, bullion dealers and virtual asset service providers.
  • Legal and conveyancing services: lawyers, conveyancers and other legal professionals when they provide designated higher-risk services.
  • Accounting and professional services: accountants and trust and company service providers when their work falls within a designated service.
  • Real estate services: real estate agents, buyer’s agents and property developers when providing designated services covered by the Act.
  • Precious metals and stones: dealers in precious metals, precious stones and relevant products when providing covered services.

Changes for existing reporting entities generally commenced on 31 March 2026. Enrolment opened for newly regulated sectors on that date, and AML/CTF obligations for tranche-two entities commenced on 1 July 2026. Because coverage depends on the service and statutory definitions, this summary does not determine whether a particular business is a reporting entity.

What are the core obligations for reporting entities?

If your business falls under the AML/CTF Act, you must operationalise a range of controls to identify and mitigate financial crime risk. The core obligations include:

  • Enrolment and Registration: You must enrol with AUSTRAC. Some sectors, such as remitters and digital currency exchanges, must also register before commencing operations.
  • Risk Assessment: You must identify and assess the ML/TF risks specific to your business, considering your customer base, services, delivery channels and jurisdictions.
  • AML/CTF Program: You must develop, document and implement a comprehensive program detailing how your business manages ML/TF risk.
  • Customer Due Diligence (CDD): You must verify the identity of your customers before providing a designated service and conduct ongoing monitoring throughout the relationship.
  • Reporting: You are legally required to report suspicious matters (SMRs), threshold transactions (TTRs) of $10,000 or more in physical currency, and international funds transfer instructions (IFTIs).
  • Record Keeping: Customer identification records and transaction details must generally be retained for a minimum of seven years.

What happens if a reporting entity does not comply?

AUSTRAC takes a robust approach to enforcement. Failures in operationalising your AML/CTF obligations can result in severe consequences, including significant civil penalties, enforceable undertakings, infringement notices, and reputational damage. Compliance is not merely a documentation exercise; it is an active, ongoing operational requirement.

AML Ops Consulting

Practical AML, CTF and KYC support for businesses ready to replace uncertainty with a way of working that holds up.

Explore

Start a conversation

Book a clarity call

Educational information only. Advice is shaped around your business, obligations and operating reality.

© 2026 AML Ops ConsultingClarity first. Controls that work.