Australia';s anti-money laundering and know-your-customer framework is one of the most actively evolving compliance environments in the Asia-Pacific region. The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act) sets the primary legal foundation, and recent legislative reforms have substantially expanded its reach. Businesses operating in Australia - whether financial institutions, fintech platforms, legal practices or real estate agencies - now face a broader and more demanding set of obligations than at any point in the framework';s history. This guide explains the current rules, the key regulatory bodies, the scope of recent changes, and the practical steps entities must take to remain compliant.
The AML/CTF Act is the cornerstone of Australia';s financial crime prevention regime. It imposes obligations on "reporting entities" - businesses that provide designated services listed in the Act. These services span deposit-taking, lending, currency exchange, remittance, securities dealing, bullion dealing and certain digital asset services.
The Act requires reporting entities to:
The Financial Transaction Reports Act 1988 (FTR Act) continues to apply to certain cash dealers not yet captured under the AML/CTF Act, though its relevance is diminishing as the reform programme progresses.
Australia is a member of the Financial Action Task Force (FATF), the global standard-setter for AML/CTF policy. FATF';s mutual evaluation process has historically identified gaps in Australia';s framework - particularly the exclusion of lawyers, accountants and real estate agents from the AML/CTF Act - and those findings have directly driven the current reform agenda.
The most consequential recent development is the passage of the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act, which extends the AML/CTF Act to a new category of "tranche 2" entities. This reform brings Australia into alignment with FATF recommendations and addresses longstanding criticism that designated non-financial businesses and professions (DNFBPs) operated outside the regime.
Tranche 2 entities now captured by the expanded framework include:
The reforms introduce a phased implementation timeline. Affected businesses are required to enrol with AUSTRAC and begin building compliant AML/CTF programmes within defined transition periods. Entities that have never previously engaged with AUSTRAC face the steepest learning curve, as they must simultaneously understand the enrolment process, design a risk-based programme, train staff and implement CDD procedures.
A common mistake among newly captured entities is treating AML/CTF compliance as a one-time documentation exercise. In practice, the Act requires a living programme that is regularly reviewed and updated to reflect changes in the business';s risk profile, customer base and the regulatory environment.
Know-your-customer obligations under the AML/CTF Act are structured around a risk-based approach. The intensity of CDD applied to any given customer must reflect the assessed risk that the customer or the service poses for money laundering or terrorism financing.
Standard CDD applies to most customers and requires a reporting entity to:
Enhanced due diligence is mandatory for higher-risk customers. This category typically includes politically exposed persons (PEPs), customers from high-risk jurisdictions identified by FATF, and complex or opaque ownership structures. EDD requires deeper scrutiny of the source of funds, source of wealth and the rationale for the transaction or relationship.
Simplified due diligence is available in limited circumstances where the risk is demonstrably low - for example, certain government bodies or listed companies subject to their own disclosure regimes.
A non-obvious requirement is the obligation to conduct ongoing CDD throughout the life of a customer relationship, not merely at onboarding. If a customer';s risk profile changes - for instance, if they begin transacting in higher volumes or with counterparties in higher-risk jurisdictions - the reporting entity must update its CDD and, where appropriate, escalate to EDD.
Many foreign-owned businesses operating in Australia underestimate the beneficial ownership verification requirement. Australian regulators expect entities to look through corporate layers to identify natural persons who ultimately own or control a customer, which can be operationally demanding for customers with complex international structures.
AUSTRAC is the Australian Government agency responsible for both financial intelligence and AML/CTF regulation. It operates a dual mandate: collecting and analysing financial intelligence to support law enforcement, and supervising reporting entities for compliance with the AML/CTF Act.
AUSTRAC';s supervisory toolkit is broad. It can conduct compliance assessments, issue formal warnings, accept enforceable undertakings, impose civil penalties and refer matters to the Director of Public Prosecutions for criminal prosecution. Civil penalties for serious or systemic non-compliance can reach into the hundreds of millions of dollars - a point made vivid by enforcement actions against major financial institutions in recent years.
In practice, AUSTRAC';s supervisory focus has shifted toward thematic reviews of specific sectors and risk-based targeting of entities whose reporting patterns suggest programme weaknesses. Entities that file few or no SMRs relative to their transaction volumes, or that show gaps between their documented programme and their actual practices, attract heightened scrutiny.
Reporting entities should be aware that AUSTRAC shares financial intelligence with domestic law enforcement agencies including the Australian Federal Police, the Australian Criminal Intelligence Commission and state police forces, as well as with international counterparts under mutual assistance arrangements. This means that a compliance failure is not merely a regulatory matter - it can have direct law enforcement consequences.
If your business is navigating AUSTRAC enrolment or programme design for the first time, early specialist advice is valuable. We can help structure the setup correctly the first time. Contact us at info@vlolawfirm.com.
Every reporting entity must adopt and maintain an AML/CTF programme. The programme has two parts under the Act.
Part A covers the entity';s framework for managing money laundering and terrorism financing risk. It must include:
Part B governs the entity';s approach to identifying and verifying customers - in effect, the operational KYC procedures. It must be consistent with the risk assessment in Part A and must specify the CDD measures applied to different customer categories.
A common mistake is drafting a programme that reads well on paper but does not reflect how the business actually operates. AUSTRAC';s compliance assessments focus on whether the documented programme is genuinely implemented, not merely whether a document exists. Entities that cannot demonstrate staff training records, CDD file completeness or transaction monitoring alerts are vulnerable to enforcement action regardless of the quality of their written programme.
In practice, founders and compliance officers should consider the programme a dynamic document. It must be updated when the business launches new products, enters new markets, onboards new customer segments or when AUSTRAC issues updated guidance.
Scenario one: a fintech payment platform. A technology company operating a payment platform in Australia is a reporting entity under the AML/CTF Act because it provides a designated remittance or payment service. It must enrol with AUSTRAC, conduct CDD on all customers before providing the service, monitor transactions for suspicious patterns and file SMRs promptly when suspicion arises. If the platform operates internationally, it must also apply correspondent banking-style due diligence to any overseas financial institutions it partners with. Many fintech operators underestimate the volume of SMRs that active transaction monitoring generates, and the operational resources required to investigate and report within the required timeframes.
Scenario two: a law firm advising on property transactions. Under the tranche 2 reforms, a law firm that assists clients in buying or selling real property is now a reporting entity for those services. The firm must enrol with AUSTRAC, implement a Part A and Part B programme, conduct CDD on clients before providing the relevant service and file SMRs where warranted. A common mistake for legal practices is assuming that legal professional privilege resolves all tension between confidentiality obligations and AML/CTF reporting duties. The Act contains specific provisions addressing this tension, and firms must understand where the boundaries lie.
What are the consequences of failing to enrol with AUSTRAC as a reporting entity?
Operating as a reporting entity without enrolling with AUSTRAC is a breach of the AML/CTF Act and can attract significant civil penalties. AUSTRAC has the power to issue infringement notices, accept enforceable undertakings or pursue civil penalty proceedings in the Federal Court. Beyond financial penalties, a failure to enrol means the entity has no compliant AML/CTF programme in place, which compounds the regulatory exposure. Newly captured tranche 2 entities should prioritise enrolment as the first step, as all other obligations flow from it. AUSTRAC publishes guidance on the enrolment process, and specialist legal advice can help entities determine whether their specific services fall within the designated services list.
How long does it take to build a compliant AML/CTF programme, and what does it cost?
The timeline depends heavily on the complexity of the business. A straightforward single-service entity with a limited customer base can typically develop and document a compliant programme within two to three months if it engages specialist support promptly. Larger or more complex businesses - particularly those with diverse product lines, international customers or correspondent relationships - should allow six months or more. Professional fees for programme development vary with scope; smaller entities typically face costs in the low to mid thousands of dollars, while larger institutions may invest considerably more. Ongoing costs include compliance officer time, staff training, transaction monitoring technology and the triennial independent review.
Does the AML/CTF Act apply to businesses that only operate online or are incorporated overseas but serve Australian customers?
The AML/CTF Act applies to entities that provide designated services in Australia, regardless of where the entity is incorporated or whether it operates through physical premises. An overseas-incorporated company that provides payment, remittance or digital asset services to Australian customers through an online platform is likely to be a reporting entity and must enrol with AUSTRAC accordingly. The Act';s territorial reach has been a source of uncertainty for some cross-border operators, and AUSTRAC has issued guidance on the subject. Foreign businesses entering the Australian market should obtain a legal assessment of their obligations before commencing operations, as retroactive compliance is more costly and more disruptive than building the programme from the outset.
Australia';s AML and KYC framework is in a period of significant transition. The tranche 2 reforms have expanded the regime to cover professional services sectors that previously operated outside it, and AUSTRAC';s supervisory approach continues to mature. Businesses that invest in robust, genuinely implemented compliance programmes are best positioned to operate without regulatory disruption and to build the trust of customers, counterparties and regulators alike.
VLO Law Firms advises international clients on AML and KYC matters in Australia. We can assist with AUSTRAC enrolment, AML/CTF programme design and review, CDD framework development, and ongoing compliance support. To request a consultation, contact: info@vlolawfirm.com