AML/CTF Compliance in Australia: A Plain-English Guide

What is AML/CTF compliance?

Anti-money laundering and counter-terrorism financing (AML/CTF) compliance refers to the systems, policies and processes a business must have in place to detect, prevent and report financial crime.

In Australia, these obligations are set out in the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (the AML/CTF Act) and administered by AUSTRAC, the Australian Transaction Reports and Analysis Centre.

Businesses that provide certain financial, property or professional services, known as designated services, are required by law to comply. Until now, that captured mainly banks, financial services firms and gambling operators. From 1 July 2026, it extends to a much broader group of businesses under what is commonly called the Tranche 2 reforms.

hero tranche
A couple discussing who AML Compliance applies to

Who does AML/CTF compliance apply to?

Any business that provides a designated service under the AML/CTF Act is a reporting entity. Reporting entities must enrol with AUSTRAC and meet ongoing compliance obligations.

 From 1 July 2026, the following professions are captured for the first time under Tranche 2:

If your business provides any of these services, you are likely a reporting entity. Visibl can help you confirm which of your services are designated and what obligations apply.

What does AML/CTF compliance actually require?

Compliance is not a single action. It is an ongoing program that covers several interconnected obligations.

check icon
AUSTRAC enrolmentReporting entities must enrol with AUSTRAC. Enrolment opened on 31 March 2026 for newly captured Tranche 2 businesses. If you have not yet enrolled, you must do so within 28 days of commencing a designated service from July 2026.
check icon
A written AML/CTF policyEvery reporting entity must develop and maintain a written AML/CTF program tailored to their specific business. A generic template is not sufficient. The program must address your particular services, your client base, your delivery channels and the risks those create. It must be reviewed and updated regularly, not filed away.
check icon
An ML/TF risk assessmentYour program must be built on a documented Money Laundering and Terrorism Financing (ML/TF) risk assessment. This requires you to actively consider and record the risks your business faces and the controls you have in place to mitigate them. The risk assessment is a living document that must be updated when your business changes.
check icon
Customer due diligence (CDD)Before providing a designated service, you must verify the identity and risk-rate your clients. This is commonly referred to as Know Your Customer (KYC) for individuals and Know Your Business (KYB) for companies, trusts and other entities. For higher-risk clients, enhanced due diligence (EDD) is required, which may include verifying the source of funds or wealth.
check icon
Ongoing monitoringInitial verification is not enough. You must monitor ongoing client relationships and transactions for activity inconsistent with what you know about the client. The frequency and depth of monitoring should be proportionate to the client's risk level.
check icon
Reporting to AUSTRACReporting entities must lodge Suspicious Matter Reports (SMRs) when they form a suspicion that a client or transaction may be connected to financial crime. Threshold Transaction Reports (TTRs) are required for cash transactions of $10,000 or more. An annual AML/CTF compliance report must also be submitted to AUSTRAC each year.
check icon
Staff trainingYour staff must be trained to understand your AML/CTF obligations and to identify suspicious activity. Training must be role-appropriate and kept up to date as your program evolves.
check icon
RecordkeepingRecords of your compliance activities, including verification documents, risk assessments, training completion and reporting, must be kept for a minimum of seven years.
check icon
A designated AML/CTF compliance officerEvery reporting entity must appoint a compliance officer responsible for the day-to-day management of the AML/CTF program. Changes to the compliance officer must be notified to AUSTRAC.

AUSTRAC has broad enforcement powers.

This includes the ability to conduct compliance assessments, issue enforceable undertakings and apply for civil penalties through the courts. Civil penalties under the AML/CTF Act can reach up to 100,000 penalty units per contravention for a body corporate. Responsible individuals can also face personal liability.

Beyond financial penalties, AUSTRAC can make enforcement actions public. Reputational consequences for a firm found to have inadequate compliance are significant, particularly in sectors such as legal and property where client trust is foundational.

What are the consequences of non-compliance?

Businesses assessing how to tackle AML Compliance

Why many businesses struggle with AML/CTF compliance

For most Tranche 2 businesses, AML/CTF compliance is entirely new territory. The most common challenges are:

  • Not knowing where to start with building a compliant program
  • Using generic policy templates that do not reflect how the business actually operates
  • Completing KYC verification without an adequate framework sitting behind it
  • Failing to document decisions, particularly around higher-risk clients
  • Underestimating the ongoing nature of the obligations, including monitoring, training and regular program reviews
  • Dealing with staff who are unclear on their responsibilities or what a red flag looks like

The federal government estimates the annual cost of an AML compliance program at over $23,000.

Many businesses attempt to manage obligations through spreadsheets and manual processes, which can create both inefficiency and compliance risk.

A major regulatory shift for your business is coming.

What makes AML/CTF compliance defensible?

AUSTRAC does not expect perfection from day one. What it expects is evidence of genuine effort: a program that reflects your actual business, decisions that are documented and reasoned, and a system that improves over time.

Defensibility means being able to demonstrate, if AUSTRAC ever reviews your records, that:

  • Your program was built on a proper risk assessment of your specific business
  • Your client verifications were completed and the results recorded
  • Decisions about higher-risk clients were considered, documented and approved
  • Your staff were trained and that training was tracked
  • Your program has been reviewed and updated as your business or the regulatory environment changed

A policy document sitting in a drawer does not meet this standard. The program must be implemented and operational.

Preparing for AML/CTF compliance

For businesses captured under Tranche 2, preparation should begin well before obligations commence. A practical approach is to identify which services are designated, complete a risk assessment, develop your AML/CTF program, train staff and establish systems for customer due diligence, monitoring and recordkeeping.

Businesses that prepare early are typically better positioned to implement compliance in a structured and sustainable way, rather than reacting under time pressure once obligations commence.

How Visibl helps businesses meet their AML/CTF compliance obligations

Visibl combines AML/CTF compliance software with certified AML specialists. The platform is designed to help Australian businesses implement, manage and demonstrate compliance through one central system.

The platform takes you through a proprietary risk questionnaire, developed against AUSTRAC’s guidance, that automatically generates a tailored AML/CTF policy and ML/TF risk assessment for your business. Every answer is recorded and every approval is timestamped, producing an audit trail AUSTRAC can review.

From there, Visibl gives you the tools to manage the day-to-day work: client verification, risk monitoring, training tracking, review reminders and compliance reporting, all in one place, with specialist support available when you need it.

For businesses managing Tranche 2 obligations for the first time, Visibl estimates the platform reduces the time spent on AML compliance from the equivalent of a full working week to around two to three hours per week.

See how the platform works and supports your specific industry; real estate, conveyancing, legal or accounting.

Make sure your business meets it's AML/CTF compliance obligations