Field Guide

Australia AML/CTF Compliance: A Practitioner's Guide

The short version

Australia runs its anti-money-laundering regime through AUSTRAC under the AML/CTF Act 2006. A business that provides a designated service is a reporting entity. That status triggers a sequence: enrolment with AUSTRAC, an AML/CTF Program with a Part A (risk management) and a Part B (customer identification), ongoing customer due diligence and transaction monitoring, and the reports lodged when they fall due. The reports are suspicious matter reports, threshold transaction reports, and international funds transfer instructions. The Tranche 2 expansion brought additional sectors into the regime on 1 July 2026, so businesses previously outside it fall to be reassessed.

Australia's anti-money-laundering and counter-terrorism-financing regime is administered by AUSTRAC under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. The obligations attach to a business by reference to the designated services it provides rather than to the sector it identifies with, and they begin on the day it starts providing such a service.

This guide covers the Australian regime in the order a practitioner works through it: who is covered, what they enrol for, what goes in the program, how customer due diligence and monitoring work, which reports fall due, who runs the program, and what the independent review tests. The Australian facts here stay distinct from the United States BSA framework. The regulator is AUSTRAC, the suspicious-activity report is a suspicious matter report, and the law is the AML/CTF Act 2006. Where a specific scope or threshold is still moving, the controlling detail sits with AUSTRAC.

Who regulates this, and where the obligations come from

The regulator is AUSTRAC, the Australian Transaction Reports and Analysis Centre. It is both the supervisor that examines compliance and the financial intelligence unit that receives and analyzes reports. The governing law is the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, supported by the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth) (F2025L01026), which replaced the AML/CTF Rules Instrument 2007 (No. 1) with effect from 31 March 2026. Together they set out who is covered, what a compliant program looks like, and what has to be reported.

For a compliance professional moving from a United States program, the mapping holds only as far as the differences are kept in view. AUSTRAC plays the financial-intelligence-unit role that FinCEN plays in the United States, but the statute, the defined services, the report types, and the thresholds are Australian and stand on their own.

Who is a reporting entity

A reporting entity is any business that provides one or more designated services listed in the AML/CTF Act 2006. The designated service carries the whole regime. The Act enumerates the services that bring a business inside it, and providing any one of them to a customer makes the provider a reporting entity with obligations attached.

Designated services run across financial and non-financial activity. The list includes the services below. For the controlling detail of any item, check AUSTRAC guidance.

Service areaExamples of designated services
Banking and accountsOpening and maintaining accounts, taking deposits, and allowing transactions on accounts.
Lending and financeMaking loans and providing finance in the course of carrying on a business.
RemittanceProviding a remittance (money transfer) service, including as an independent remittance dealer or a network affiliate.
Currency exchangeExchanging one currency for another, whether physical or electronic.
Digital currency exchangeExchanging digital currency for money, or money for digital currency.
GamblingProviding certain gambling services, including by casinos and other gambling operators.
BullionBuying or selling bullion in the course of carrying on a business.

Timing is the element a new business most often overlooks. There is no opting in and no notice to wait for: a business becomes a reporting entity the moment it starts providing a designated service, and the obligations attach from that point. Where it is unclear whether a product is a designated service, the question is resolved against the Act and AUSTRAC guidance before launch.

Enrolment and registration with AUSTRAC

Once a business provides a designated service, it has to enrol with AUSTRAC and appear on the Reporting Entities Roll. Enrolment tells AUSTRAC who the entity is, what designated services it provides, and how to reach the people accountable for its program. Some activities carry an additional registration step on top of enrolment. Remittance service providers and digital currency exchange providers, for example, need to be registered with AUSTRAC to operate, not only enrolled.

Enrolment and registration function as the entry gate. Operating a service that requires registration without being registered is a serious failure, and a supervisor checks for it early. The current enrolment and registration requirements for a given set of services are confirmed with AUSTRAC before go-live.

The AML/CTF Program: Part A and Part B

Every reporting entity has to build and maintain an AML/CTF Program. The program holds the whole obligation set together, and it comes in two parts that do different jobs.

Part A: the general part

Part A is where the business identifies, manages, and mitigates the money-laundering and terrorism-financing risk it faces. It is risk-led by design, the same discipline a strong program follows anywhere: the entity understands its customers, products, channels, and geographies, rates the risk, and builds controls that match it. A complete Part A covers the elements below.

Part A elementWhat it does
Risk assessmentIdentifies and assesses the ML/TF risk across the business: customer types, the designated services provided, delivery channels, and the jurisdictions involved.
Governance and oversightSets the board-and-senior-management approval and oversight of the program, and names the accountable compliance officer.
Ongoing customer due diligenceKeeps customer information current and applies enhanced measures to higher-risk customers and relationships.
Transaction monitoringMonitors customer transactions to identify activity that is unusual, complex, or inconsistent with what is known about the customer.
Employee due diligence and trainingScreens staff in relevant roles and trains them to recognize and act on ML/TF risk.
Independent reviewProvides for regular review of Part A by a party independent of the people who run the program.

Part B: customer identification

Part B sets out the applicable customer identification procedures, the know-your-customer steps the business follows before it provides a designated service. It specifies how the entity collects and verifies customer identity, how it handles individuals, companies, trusts, and other entity types, and how it identifies the beneficial owners behind a customer where that applies. The general rule is that the customer is identified and verified before the designated service is provided. The rules set out the limited circumstances where verification can follow.

The two parts work together. Part B produces a verified customer at the start of the relationship, and Part A keeps that knowledge current while it watches the activity that follows.

Customer due diligence

Customer due diligence is the work of establishing who the customer is and what activity is expected from that customer. In the Australian regime it spans both parts of the program. The initial identification sits in Part B; the ongoing scrutiny sits in Part A.

Due diligence is risk-based, which means the rating has to carry consequences. A program that rates every customer the same way cannot separate ordinary business activity from activity that warrants scrutiny. The rating sets the depth of identification, the closeness of monitoring, and the speed of escalation.

Ongoing customer due diligence and transaction monitoring

Identifying a customer once is only the start. Part A requires ongoing customer due diligence, which keeps customer information current and reassesses risk as the relationship changes, and a transaction monitoring program that watches activity over time.

Effective monitoring rests on establishing what normal activity looks like for a given customer and surfacing the activity that departs from it. Monitoring that compares a customer's behavior against a baseline for comparable customers is more discriminating than a single fixed number, which flags the large customer constantly and the small one never. The output is a manageable set of meaningful alerts that a person reviews and dispositions, with the genuinely suspicious cases moving toward a report. Alert volume that exceeds review capacity allows genuine activity to pass unexamined.

The reports: SMR, TTR, and IFTI

Reporting is the point where the program reaches AUSTRAC. Three core report types answer different triggers, and they are distinct from the United States equivalents: in Australia the suspicious-activity report is a suspicious matter report submitted to AUSTRAC, not a SAR submitted to FinCEN.

ReportWhat triggers itWhat it captures
SMR
Suspicious matter report
The reporting entity forms a relevant suspicion about a customer or a transaction, including suspected money laundering, terrorism financing, or other serious offences.The matter and the grounds for suspicion, reported to AUSTRAC within the timeframes set by the Act and rules.
TTR
Threshold transaction report
A transaction involving physical currency or e-currency at or above the reporting threshold set in the regime.The threshold transaction and its details. The current threshold and what counts toward it are confirmed against AUSTRAC guidance.
IFTI
International funds transfer instruction
An instruction to transfer money or property into or out of Australia.The cross-border instruction and the parties to it, reported to AUSTRAC.

Alongside these transaction-driven reports, reporting entities lodge a periodic compliance report to AUSTRAC describing their compliance with their obligations. Timeframes and thresholds for each report are set in the Act and the AML/CTF Rules 2025, and the operating detail is confirmed against AUSTRAC guidance rather than assumed.

A suspicious matter report carries the same weight a suspicious activity report carries in the United States, and the same writing discipline applies. The grounds for suspicion have to be specific. A report that names the customer, the transactions, the dates, the amounts, and the reason the activity does not fit the customer's profile is actionable by AUSTRAC. A report that asserts suspicion without the underlying facts gives an investigator nothing to work with.

The AML/CTF compliance officer

A reporting entity has to designate an AML/CTF compliance officer at management level, accountable for the program. The same principle sits at the center of strong programs everywhere. One named senior person owns compliance, with the resources to do the job and the standing to be heard by the board and senior management.

The role depends on genuine authority and allocated time. A compliance officer who also carries a large revenue-side job, or who reports through the function whose activity they are supposed to challenge, is poorly positioned to perform it. The designation is kept current, the authority is stated plainly, and cover is arranged for periods when the officer is unavailable.

Independent review

Part A has to be reviewed regularly by a party independent of the people who designed and run the program. The independent review tests whether Part A suits the business's risk, whether the business actually follows it, and whether it works. Independence is the operative condition, since a team assessing its own program cannot supply it. Internal audit can perform the review where that function is genuinely independent of compliance, or an external party can.

Findings go to senior management and the board, with management responses and a record of remediation. Findings that are not tracked to closure leave the review without effect.

The Tranche 2 expansion

For most of the regime's life, the AML/CTF obligations sat on financial and a defined set of other businesses. Tranche 2 is the expansion of the regime to additional sectors that were previously outside it, commonly described as certain professional and high-value-dealer services. The sectors associated with the expansion include the following.

A business in one of these sectors starts where every reporting entity starts, with the question of whether it provides a designated service. Where it does, the sequence follows: enrolment with AUSTRAC, registration where required, an AML/CTF Program with its Part A and Part B, and the due diligence, monitoring, and reporting that sit under it. Tranche 2 followed a phased timeline: enrolment for the newly covered sectors opened on 31 March 2026, the new obligations commenced on 1 July 2026, and newly regulated entities were required to enrol with AUSTRAC by 29 July 2026. Both dates have now passed: a business in a newly covered sector that provides a designated service is a reporting entity with live obligations, and one that has not yet enrolled should do so without delay, since providing a designated service without enrolment is itself a contravention. Existing reporting entities were required to implement the new AML/CTF Rules by 31 March 2026. Confirm the exact scope and any sector-specific detail against current AUSTRAC guidance.

A readiness checklist

The items below are the ones a reporting entity confirms before treating its Australian program as complete.

The regime's demands are extensive and its structure is legible. A reporting entity identifies its customers, monitors their activity, lodges the reports the Act requires, and demonstrates that the program works through a review it does not control. A program documented on those four points is the one that holds up under AUSTRAC scrutiny.

For the plain-language definitions behind the terms in this guide, see the Australia AML/CTF glossary.

Common questions

Who regulates AML/CTF compliance in Australia?
AUSTRAC, the Australian Transaction Reports and Analysis Centre, is the regulator and financial intelligence unit. It administers the AML/CTF Act 2006 and the associated rules, enrols and registers reporting entities, receives reports, and supervises compliance. AUSTRAC is the Australian counterpart to a financial intelligence unit such as FinCEN in the United States, though the two regimes differ in detail.
Who is a reporting entity under the AML/CTF Act 2006?
A reporting entity is any business that provides one or more designated services listed in the AML/CTF Act 2006. Designated services span banking, lending, remittance, currency exchange, gambling, bullion, and digital currency exchange, among others. Status follows the service, so a company becomes a reporting entity the moment it starts providing a designated service to a customer in Australia.
What is the difference between Part A and Part B of an AML/CTF Program?
Part A is the general part: it identifies, manages, and mitigates ML/TF risk and covers governance, the compliance officer, ongoing customer due diligence, transaction monitoring, training, and independent review. Part B sets out the customer identification procedures, the know-your-customer steps a business follows before it provides a designated service.
What reports does AUSTRAC require?
The core reports are suspicious matter reports (SMRs) when a relevant suspicion forms, threshold transaction reports (TTRs) for cash or physical-currency transactions at or above the reporting threshold, and international funds transfer instructions (IFTIs) for instructions to move money across the Australian border. Reporting entities also lodge a periodic compliance report. An SMR is the Australian counterpart to a suspicious activity report and is reported to AUSTRAC.
What is Tranche 2 of Australia's AML/CTF regime?
Tranche 2 is the expansion of the regime to additional sectors that were not covered when it began, commonly described as certain professional and high-value-dealer services such as lawyers, accountants, conveyancers, trust and company service providers, and real estate professionals. Obligations for the newly covered sectors commenced on 1 July 2026, with enrolment required by 29 July 2026. Businesses in these sectors determine whether they provide designated services, enrol with AUSTRAC, and stand up an AML/CTF Program. For current scope and detail, rely on AUSTRAC guidance.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.

Primary sources

The authoritative texts this guide is grounded in. Government sites may block automated access but resolve in a browser.