Trackers
Trackers

AML & KYC in Australia: 2026 Update

Australia';s anti-money laundering and know-your-customer framework is one of the most actively evolving compliance environments in the Asia-Pacific region. The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act) sets the primary legal foundation, and recent legislative reforms have substantially expanded its reach. Businesses operating in Australia - whether financial institutions, fintech platforms, legal practices or real estate agencies - now face a broader and more demanding set of obligations than at any point in the framework';s history. This guide explains the current rules, the key regulatory bodies, the scope of recent changes, and the practical steps entities must take to remain compliant.

What AML & KYC in Australia requires: the legal foundation

The AML/CTF Act is the cornerstone of Australia';s financial crime prevention regime. It imposes obligations on "reporting entities" - businesses that provide designated services listed in the Act. These services span deposit-taking, lending, currency exchange, remittance, securities dealing, bullion dealing and certain digital asset services.

The Act requires reporting entities to:

  • Enrol with the Australian Transaction Reports and Analysis Centre (AUSTRAC), the primary regulator.
  • Adopt and maintain an AML/CTF programme that covers customer due diligence (CDD), transaction monitoring and staff training.
  • Submit threshold transaction reports (TTRs) for cash transactions at or above AUD 10,000.
  • File suspicious matter reports (SMRs) whenever a transaction or customer raises a reasonable suspicion of financial crime.
  • Conduct ongoing customer due diligence and enhanced due diligence (EDD) for higher-risk relationships.

The Financial Transaction Reports Act 1988 (FTR Act) continues to apply to certain cash dealers not yet captured under the AML/CTF Act, though its relevance is diminishing as the reform programme progresses.

Australia is a member of the Financial Action Task Force (FATF), the global standard-setter for AML/CTF policy. FATF';s mutual evaluation process has historically identified gaps in Australia';s framework - particularly the exclusion of lawyers, accountants and real estate agents from the AML/CTF Act - and those findings have directly driven the current reform agenda.

The tranche 2 reforms: who is now covered and when

The most consequential recent development is the passage of the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act, which extends the AML/CTF Act to a new category of "tranche 2" entities. This reform brings Australia into alignment with FATF recommendations and addresses longstanding criticism that designated non-financial businesses and professions (DNFBPs) operated outside the regime.

Tranche 2 entities now captured by the expanded framework include:

  • Lawyers, conveyancers and notaries when conducting certain transactions.
  • Accountants and tax agents providing specified financial services.
  • Real estate agents and property developers involved in buying and selling real property.
  • Dealers in precious metals and stones above defined thresholds.
  • Trust and company service providers.

The reforms introduce a phased implementation timeline. Affected businesses are required to enrol with AUSTRAC and begin building compliant AML/CTF programmes within defined transition periods. Entities that have never previously engaged with AUSTRAC face the steepest learning curve, as they must simultaneously understand the enrolment process, design a risk-based programme, train staff and implement CDD procedures.

A common mistake among newly captured entities is treating AML/CTF compliance as a one-time documentation exercise. In practice, the Act requires a living programme that is regularly reviewed and updated to reflect changes in the business';s risk profile, customer base and the regulatory environment.

KYC requirements: customer due diligence in practice

Know-your-customer obligations under the AML/CTF Act are structured around a risk-based approach. The intensity of CDD applied to any given customer must reflect the assessed risk that the customer or the service poses for money laundering or terrorism financing.

Standard CDD applies to most customers and requires a reporting entity to:

  • Collect and verify the customer';s full name, date of birth and residential address for individuals.
  • For companies, verify the legal name, registered address, Australian Company Number (ACN) or equivalent, and the identity of beneficial owners holding 25% or more of ownership or control.
  • Confirm the nature and purpose of the business relationship.

Enhanced due diligence is mandatory for higher-risk customers. This category typically includes politically exposed persons (PEPs), customers from high-risk jurisdictions identified by FATF, and complex or opaque ownership structures. EDD requires deeper scrutiny of the source of funds, source of wealth and the rationale for the transaction or relationship.

Simplified due diligence is available in limited circumstances where the risk is demonstrably low - for example, certain government bodies or listed companies subject to their own disclosure regimes.

A non-obvious requirement is the obligation to conduct ongoing CDD throughout the life of a customer relationship, not merely at onboarding. If a customer';s risk profile changes - for instance, if they begin transacting in higher volumes or with counterparties in higher-risk jurisdictions - the reporting entity must update its CDD and, where appropriate, escalate to EDD.

Many foreign-owned businesses operating in Australia underestimate the beneficial ownership verification requirement. Australian regulators expect entities to look through corporate layers to identify natural persons who ultimately own or control a customer, which can be operationally demanding for customers with complex international structures.

AUSTRAC';s supervisory approach and enforcement powers

AUSTRAC is the Australian Government agency responsible for both financial intelligence and AML/CTF regulation. It operates a dual mandate: collecting and analysing financial intelligence to support law enforcement, and supervising reporting entities for compliance with the AML/CTF Act.

AUSTRAC';s supervisory toolkit is broad. It can conduct compliance assessments, issue formal warnings, accept enforceable undertakings, impose civil penalties and refer matters to the Director of Public Prosecutions for criminal prosecution. Civil penalties for serious or systemic non-compliance can reach into the hundreds of millions of dollars - a point made vivid by enforcement actions against major financial institutions in recent years.

In practice, AUSTRAC';s supervisory focus has shifted toward thematic reviews of specific sectors and risk-based targeting of entities whose reporting patterns suggest programme weaknesses. Entities that file few or no SMRs relative to their transaction volumes, or that show gaps between their documented programme and their actual practices, attract heightened scrutiny.

Reporting entities should be aware that AUSTRAC shares financial intelligence with domestic law enforcement agencies including the Australian Federal Police, the Australian Criminal Intelligence Commission and state police forces, as well as with international counterparts under mutual assistance arrangements. This means that a compliance failure is not merely a regulatory matter - it can have direct law enforcement consequences.

If your business is navigating AUSTRAC enrolment or programme design for the first time, early specialist advice is valuable. We can help structure the setup correctly the first time. Contact us at info@vlolawfirm.com.

AML/CTF programme requirements: what a compliant programme looks like

Every reporting entity must adopt and maintain an AML/CTF programme. The programme has two parts under the Act.

Part A covers the entity';s framework for managing money laundering and terrorism financing risk. It must include:

  • A documented ML/TF risk assessment covering the entity';s customers, products, services, delivery channels and geographic exposure.
  • Policies and procedures for CDD, EDD, ongoing monitoring and transaction reporting.
  • A designated AML/CTF compliance officer with appropriate seniority and authority.
  • An employee due diligence programme covering recruitment and ongoing screening.
  • A training programme that ensures staff understand their obligations and can identify suspicious activity.
  • An independent review function that tests the programme';s effectiveness at least every three years.

Part B governs the entity';s approach to identifying and verifying customers - in effect, the operational KYC procedures. It must be consistent with the risk assessment in Part A and must specify the CDD measures applied to different customer categories.

A common mistake is drafting a programme that reads well on paper but does not reflect how the business actually operates. AUSTRAC';s compliance assessments focus on whether the documented programme is genuinely implemented, not merely whether a document exists. Entities that cannot demonstrate staff training records, CDD file completeness or transaction monitoring alerts are vulnerable to enforcement action regardless of the quality of their written programme.

In practice, founders and compliance officers should consider the programme a dynamic document. It must be updated when the business launches new products, enters new markets, onboards new customer segments or when AUSTRAC issues updated guidance.

Practical scenarios: how the rules apply to different businesses

Scenario one: a fintech payment platform. A technology company operating a payment platform in Australia is a reporting entity under the AML/CTF Act because it provides a designated remittance or payment service. It must enrol with AUSTRAC, conduct CDD on all customers before providing the service, monitor transactions for suspicious patterns and file SMRs promptly when suspicion arises. If the platform operates internationally, it must also apply correspondent banking-style due diligence to any overseas financial institutions it partners with. Many fintech operators underestimate the volume of SMRs that active transaction monitoring generates, and the operational resources required to investigate and report within the required timeframes.

Scenario two: a law firm advising on property transactions. Under the tranche 2 reforms, a law firm that assists clients in buying or selling real property is now a reporting entity for those services. The firm must enrol with AUSTRAC, implement a Part A and Part B programme, conduct CDD on clients before providing the relevant service and file SMRs where warranted. A common mistake for legal practices is assuming that legal professional privilege resolves all tension between confidentiality obligations and AML/CTF reporting duties. The Act contains specific provisions addressing this tension, and firms must understand where the boundaries lie.

Frequently asked questions

What are the consequences of failing to enrol with AUSTRAC as a reporting entity?

Operating as a reporting entity without enrolling with AUSTRAC is a breach of the AML/CTF Act and can attract significant civil penalties. AUSTRAC has the power to issue infringement notices, accept enforceable undertakings or pursue civil penalty proceedings in the Federal Court. Beyond financial penalties, a failure to enrol means the entity has no compliant AML/CTF programme in place, which compounds the regulatory exposure. Newly captured tranche 2 entities should prioritise enrolment as the first step, as all other obligations flow from it. AUSTRAC publishes guidance on the enrolment process, and specialist legal advice can help entities determine whether their specific services fall within the designated services list.

How long does it take to build a compliant AML/CTF programme, and what does it cost?

The timeline depends heavily on the complexity of the business. A straightforward single-service entity with a limited customer base can typically develop and document a compliant programme within two to three months if it engages specialist support promptly. Larger or more complex businesses - particularly those with diverse product lines, international customers or correspondent relationships - should allow six months or more. Professional fees for programme development vary with scope; smaller entities typically face costs in the low to mid thousands of dollars, while larger institutions may invest considerably more. Ongoing costs include compliance officer time, staff training, transaction monitoring technology and the triennial independent review.

Does the AML/CTF Act apply to businesses that only operate online or are incorporated overseas but serve Australian customers?

The AML/CTF Act applies to entities that provide designated services in Australia, regardless of where the entity is incorporated or whether it operates through physical premises. An overseas-incorporated company that provides payment, remittance or digital asset services to Australian customers through an online platform is likely to be a reporting entity and must enrol with AUSTRAC accordingly. The Act';s territorial reach has been a source of uncertainty for some cross-border operators, and AUSTRAC has issued guidance on the subject. Foreign businesses entering the Australian market should obtain a legal assessment of their obligations before commencing operations, as retroactive compliance is more costly and more disruptive than building the programme from the outset.

Conclusion

Australia';s AML and KYC framework is in a period of significant transition. The tranche 2 reforms have expanded the regime to cover professional services sectors that previously operated outside it, and AUSTRAC';s supervisory approach continues to mature. Businesses that invest in robust, genuinely implemented compliance programmes are best positioned to operate without regulatory disruption and to build the trust of customers, counterparties and regulators alike.

VLO Law Firms advises international clients on AML and KYC matters in Australia. We can assist with AUSTRAC enrolment, AML/CTF programme design and review, CDD framework development, and ongoing compliance support. To request a consultation, contact: info@vlolawfirm.com