Australia runs its anti-money-laundering regime through AUSTRAC under the AML/CTF Act 2006. A business that provides a designated service is a reporting entity. That status triggers a sequence: enrolment with AUSTRAC, an AML/CTF Program with a Part A (risk management) and a Part B (customer identification), ongoing customer due diligence and transaction monitoring, and the reports lodged when they fall due. The reports are suspicious matter reports, threshold transaction reports, and international funds transfer instructions. The Tranche 2 expansion brought additional sectors into the regime on 1 July 2026, so businesses previously outside it fall to be reassessed.
Australia's anti-money-laundering and counter-terrorism-financing regime is administered by AUSTRAC under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. The obligations attach to a business by reference to the designated services it provides rather than to the sector it identifies with, and they begin on the day it starts providing such a service.
This guide covers the Australian regime in the order a practitioner works through it: who is covered, what they enrol for, what goes in the program, how customer due diligence and monitoring work, which reports fall due, who runs the program, and what the independent review tests. The Australian facts here stay distinct from the United States BSA framework. The regulator is AUSTRAC, the suspicious-activity report is a suspicious matter report, and the law is the AML/CTF Act 2006. Where a specific scope or threshold is still moving, the controlling detail sits with AUSTRAC.
Who regulates this, and where the obligations come from
The regulator is AUSTRAC, the Australian Transaction Reports and Analysis Centre. It is both the supervisor that examines compliance and the financial intelligence unit that receives and analyzes reports. The governing law is the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, supported by the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth) (F2025L01026), which replaced the AML/CTF Rules Instrument 2007 (No. 1) with effect from 31 March 2026. Together they set out who is covered, what a compliant program looks like, and what has to be reported.
For a compliance professional moving from a United States program, the mapping holds only as far as the differences are kept in view. AUSTRAC plays the financial-intelligence-unit role that FinCEN plays in the United States, but the statute, the defined services, the report types, and the thresholds are Australian and stand on their own.
Who is a reporting entity
A reporting entity is any business that provides one or more designated services listed in the AML/CTF Act 2006. The designated service carries the whole regime. The Act enumerates the services that bring a business inside it, and providing any one of them to a customer makes the provider a reporting entity with obligations attached.
Designated services run across financial and non-financial activity. The list includes the services below. For the controlling detail of any item, check AUSTRAC guidance.
| Service area | Examples of designated services |
|---|---|
| Banking and accounts | Opening and maintaining accounts, taking deposits, and allowing transactions on accounts. |
| Lending and finance | Making loans and providing finance in the course of carrying on a business. |
| Remittance | Providing a remittance (money transfer) service, including as an independent remittance dealer or a network affiliate. |
| Currency exchange | Exchanging one currency for another, whether physical or electronic. |
| Digital currency exchange | Exchanging digital currency for money, or money for digital currency. |
| Gambling | Providing certain gambling services, including by casinos and other gambling operators. |
| Bullion | Buying or selling bullion in the course of carrying on a business. |
Timing is the element a new business most often overlooks. There is no opting in and no notice to wait for: a business becomes a reporting entity the moment it starts providing a designated service, and the obligations attach from that point. Where it is unclear whether a product is a designated service, the question is resolved against the Act and AUSTRAC guidance before launch.
Enrolment and registration with AUSTRAC
Once a business provides a designated service, it has to enrol with AUSTRAC and appear on the Reporting Entities Roll. Enrolment tells AUSTRAC who the entity is, what designated services it provides, and how to reach the people accountable for its program. Some activities carry an additional registration step on top of enrolment. Remittance service providers and digital currency exchange providers, for example, need to be registered with AUSTRAC to operate, not only enrolled.
Enrolment and registration function as the entry gate. Operating a service that requires registration without being registered is a serious failure, and a supervisor checks for it early. The current enrolment and registration requirements for a given set of services are confirmed with AUSTRAC before go-live.
The AML/CTF Program: Part A and Part B
Every reporting entity has to build and maintain an AML/CTF Program. The program holds the whole obligation set together, and it comes in two parts that do different jobs.
Part A: the general part
Part A is where the business identifies, manages, and mitigates the money-laundering and terrorism-financing risk it faces. It is risk-led by design, the same discipline a strong program follows anywhere: the entity understands its customers, products, channels, and geographies, rates the risk, and builds controls that match it. A complete Part A covers the elements below.
| Part A element | What it does |
|---|---|
| Risk assessment | Identifies and assesses the ML/TF risk across the business: customer types, the designated services provided, delivery channels, and the jurisdictions involved. |
| Governance and oversight | Sets the board-and-senior-management approval and oversight of the program, and names the accountable compliance officer. |
| Ongoing customer due diligence | Keeps customer information current and applies enhanced measures to higher-risk customers and relationships. |
| Transaction monitoring | Monitors customer transactions to identify activity that is unusual, complex, or inconsistent with what is known about the customer. |
| Employee due diligence and training | Screens staff in relevant roles and trains them to recognize and act on ML/TF risk. |
| Independent review | Provides for regular review of Part A by a party independent of the people who run the program. |
Part B: customer identification
Part B sets out the applicable customer identification procedures, the know-your-customer steps the business follows before it provides a designated service. It specifies how the entity collects and verifies customer identity, how it handles individuals, companies, trusts, and other entity types, and how it identifies the beneficial owners behind a customer where that applies. The general rule is that the customer is identified and verified before the designated service is provided. The rules set out the limited circumstances where verification can follow.
The two parts work together. Part B produces a verified customer at the start of the relationship, and Part A keeps that knowledge current while it watches the activity that follows.
Customer due diligence
Customer due diligence is the work of establishing who the customer is and what activity is expected from that customer. In the Australian regime it spans both parts of the program. The initial identification sits in Part B; the ongoing scrutiny sits in Part A.
- Initial customer due diligence. The entity collects and verifies the customer's identity before providing the designated service, using the procedures set out in Part B. For non-individual customers, this extends to understanding the structure and identifying the beneficial owners.
- Enhanced customer due diligence. Deeper scrutiny applies where the risk is higher: politically exposed persons, higher-risk countries, complex or unusual structures, and situations where a suspicion has formed. Enhanced measures can include gathering more information about the customer and the source of their funds, and seeking senior approval to continue the relationship.
- Simplified measures. Where the risk is demonstrably low and the rules allow it, lighter measures may apply. Low risk is a conclusion documented from the assessment rather than a starting assumption.
Due diligence is risk-based, which means the rating has to carry consequences. A program that rates every customer the same way cannot separate ordinary business activity from activity that warrants scrutiny. The rating sets the depth of identification, the closeness of monitoring, and the speed of escalation.
Ongoing customer due diligence and transaction monitoring
Identifying a customer once is only the start. Part A requires ongoing customer due diligence, which keeps customer information current and reassesses risk as the relationship changes, and a transaction monitoring program that watches activity over time.
Effective monitoring rests on establishing what normal activity looks like for a given customer and surfacing the activity that departs from it. Monitoring that compares a customer's behavior against a baseline for comparable customers is more discriminating than a single fixed number, which flags the large customer constantly and the small one never. The output is a manageable set of meaningful alerts that a person reviews and dispositions, with the genuinely suspicious cases moving toward a report. Alert volume that exceeds review capacity allows genuine activity to pass unexamined.
The reports: SMR, TTR, and IFTI
Reporting is the point where the program reaches AUSTRAC. Three core report types answer different triggers, and they are distinct from the United States equivalents: in Australia the suspicious-activity report is a suspicious matter report submitted to AUSTRAC, not a SAR submitted to FinCEN.
| Report | What triggers it | What it captures |
|---|---|---|
| SMR Suspicious matter report | The reporting entity forms a relevant suspicion about a customer or a transaction, including suspected money laundering, terrorism financing, or other serious offences. | The matter and the grounds for suspicion, reported to AUSTRAC within the timeframes set by the Act and rules. |
| TTR Threshold transaction report | A transaction involving physical currency or e-currency at or above the reporting threshold set in the regime. | The threshold transaction and its details. The current threshold and what counts toward it are confirmed against AUSTRAC guidance. |
| IFTI International funds transfer instruction | An instruction to transfer money or property into or out of Australia. | The cross-border instruction and the parties to it, reported to AUSTRAC. |
Alongside these transaction-driven reports, reporting entities lodge a periodic compliance report to AUSTRAC describing their compliance with their obligations. Timeframes and thresholds for each report are set in the Act and the AML/CTF Rules 2025, and the operating detail is confirmed against AUSTRAC guidance rather than assumed.
A suspicious matter report carries the same weight a suspicious activity report carries in the United States, and the same writing discipline applies. The grounds for suspicion have to be specific. A report that names the customer, the transactions, the dates, the amounts, and the reason the activity does not fit the customer's profile is actionable by AUSTRAC. A report that asserts suspicion without the underlying facts gives an investigator nothing to work with.
The AML/CTF compliance officer
A reporting entity has to designate an AML/CTF compliance officer at management level, accountable for the program. The same principle sits at the center of strong programs everywhere. One named senior person owns compliance, with the resources to do the job and the standing to be heard by the board and senior management.
The role depends on genuine authority and allocated time. A compliance officer who also carries a large revenue-side job, or who reports through the function whose activity they are supposed to challenge, is poorly positioned to perform it. The designation is kept current, the authority is stated plainly, and cover is arranged for periods when the officer is unavailable.
Independent review
Part A has to be reviewed regularly by a party independent of the people who designed and run the program. The independent review tests whether Part A suits the business's risk, whether the business actually follows it, and whether it works. Independence is the operative condition, since a team assessing its own program cannot supply it. Internal audit can perform the review where that function is genuinely independent of compliance, or an external party can.
Findings go to senior management and the board, with management responses and a record of remediation. Findings that are not tracked to closure leave the review without effect.
The Tranche 2 expansion
For most of the regime's life, the AML/CTF obligations sat on financial and a defined set of other businesses. Tranche 2 is the expansion of the regime to additional sectors that were previously outside it, commonly described as certain professional and high-value-dealer services. The sectors associated with the expansion include the following.
- Legal practitioners providing relevant services.
- Accountants providing relevant services.
- Trust and company service providers.
- Real estate professionals involved in property transactions.
- Dealers in precious metals and stones and other high-value goods, as covered.
A business in one of these sectors starts where every reporting entity starts, with the question of whether it provides a designated service. Where it does, the sequence follows: enrolment with AUSTRAC, registration where required, an AML/CTF Program with its Part A and Part B, and the due diligence, monitoring, and reporting that sit under it. Tranche 2 followed a phased timeline: enrolment for the newly covered sectors opened on 31 March 2026, the new obligations commenced on 1 July 2026, and newly regulated entities were required to enrol with AUSTRAC by 29 July 2026. Both dates have now passed: a business in a newly covered sector that provides a designated service is a reporting entity with live obligations, and one that has not yet enrolled should do so without delay, since providing a designated service without enrolment is itself a contravention. Existing reporting entities were required to implement the new AML/CTF Rules by 31 March 2026. Confirm the exact scope and any sector-specific detail against current AUSTRAC guidance.
A readiness checklist
The items below are the ones a reporting entity confirms before treating its Australian program as complete.
- The entity has determined whether it provides a designated service, confirmed against the Act and AUSTRAC guidance.
- The entity is enrolled with AUSTRAC, and registered where its services require it.
- A documented AML/CTF Program exists with a Part A and a Part B.
- Part A includes a current risk assessment covering customers, services, channels, and jurisdictions.
- Part B sets out customer identification procedures, including beneficial ownership where it applies.
- Ongoing customer due diligence keeps customer information current and applies enhanced measures to higher-risk relationships.
- A transaction monitoring program surfaces unusual activity against a sensible baseline.
- SMRs, TTRs, and IFTIs are lodged when triggered, within the required timeframes, along with the periodic compliance report.
- An AML/CTF compliance officer at management level owns the program with real authority.
- Part A is subject to a regular independent review, with findings tracked to closure.
- Staff in relevant roles receive training appropriate to their part in the program.
The regime's demands are extensive and its structure is legible. A reporting entity identifies its customers, monitors their activity, lodges the reports the Act requires, and demonstrates that the program works through a review it does not control. A program documented on those four points is the one that holds up under AUSTRAC scrutiny.
For the plain-language definitions behind the terms in this guide, see the Australia AML/CTF glossary.