Existing Reporting Entities – Guidance

Reforms to Australia’s AML/CTF regime have been passed and will for the most part commence in 2026. For existing reporting entities, the reforms and the new AML/CTF Rules  introduce changes to various AML/CTF obligations and requirements which are contained in the original AML/CTF Act 2006. While many of these changes do not start until 31 March 2026, existing reporting entities should become familiar with these changes so that they are on track to implement them. This will help ensure reporting entities continue to stay compliant with the AML/CTF regime in its next iteration.

Key AML/CTF Reforms applicable to existing reporting entities

Understanding AML/CTF - Reforms - Existing Reporting Entities

AML/CTF Programs

Under the reforms, an AML/CTF Program no longer needs to be separated into Part A and Part B. A reporting entity can choose how it wants to structure their AML/CTF Program, so long as the AML/CTF Program documents the reporting entity’s:

  • assessment of money laundering, terrorism financing and proliferation financing (“ML/TF/PF“) risks specific to its business (ML/TF risk assessment);
  • procedures and measures appropriate to manage and mitigate the ML/TF/PF risks specific to its business; and
  • procedures and measures to ensure it complies with its obligations and requirements under the AML/CTF Act.

 

A failure to comply with the procedures and requirements as outlined in a reporting entity’s own AML/CTF Program will be a breach attracting civil penalties. This means reporting entities need to not only have an AML/CTF Program, but also implement what they say they will do in their AML/CTF Program.

Customer due diligence ("CDD") procedures

The reforms give a reporting entity more flexibility when conducting CDD procedures.

When?What?How?Outcome
Initial CDD

(at the onboarding stage)
  • Establish the identity of the customer in the first instance - the AML/CTF Rules prescribe the minimum KYC information that must be collected for most customer types;

  • Identify the ML/TF risk of the customer;

  • Collect further KYC information based on the ML/TF risk of the customer; and

  • Verify the KYC information collected.


The reporting entity must determine the CDD procedures to apply based on their risk assessment. Simplified CDD can be applied in certain circumstances, when the ML/TF risk of the customer is low.

Enhanced CDD must be applied where:

  • ML/TF risk of the customer is high; or

  • suspicion arises in relation to the customer and the reporting entity wants to continue to provide services; or
  • customer / agent / beneficial owner is:


    • a foreign PEP; or

    • physically located or incorporated in a high-risk jurisdiction; or

    • a body corporate or legal arrangement that was formed in a high risk jurisdiction; or

    • the customer requests unusually complex or large transactions or an unusual pattern of transactions which have no apparent economic or legal purpose.



The reporting entity must be satisfied about factors such as:

  • the identity of the customer / agent / beneficial owner;

  • whether the customer is a politically exposed person or subject to sanctions; and

  • the nature or purpose of the transaction


Ongoing CDD

(on an ongoing basis)
  • Monitor the customer's transactions / behaviour for anything unusual or suspicious;

  • Review and update the ML/TF risk assessment of the customer; and

  • Review, update or reverify the customer's KYC information based on the ML/TF risk of the customer.

The reporting entity must appropriately identify, assess, manage and mitigate the ML/TF risks associated with providing designated services to the customer.

The terms “simplified CDD” and “enhanced CDD” are not specifically defined in the legislation, although some enhanced CDD procedures are mandated for certain customer types. A reporting entity will have the flexibility to decide what constitutes simplified and enhanced CDD procedures, so long as enhanced CDD involves more rigorous checks and monitoring on the customer when compared to simplified CDD.

From 'Designated Business Group' to 'Reporting Group'

The reforms replace the existing “Designated Business Group” regime with the “Reporting Group” concept. If a reporting entity is part of a reporting group, the AML/CTF governance structure is set out as follows:

Business GroupEither:
  • A business group, where one member controls the others, and one member is a reporting entity; or

  • A group of 2 or more persons who have elected to form a group as permitted by the AML/CTF Rules.

Elective Reporting GroupA group of 2 or more persons who have elected to form a group as permitted by the AML/CTF Rules.

Lead EntityThe method for determining the lead entity of a reporting group is to be defined in the AML/CTF Rules. The lead entity will likely be the entity which controls all other members of a Business Group who provide a designated service OR the other members have agreed that it does not control any other members of the Elective Reporting Group. It must have a connection to Australia, and the capability and authority to develop and maintain the AML/CTF Policies required by other Members of the Reporting Group.

Reporting Groups

Understanding AML/CTF Reforms - Part 1: Existing Reporting Entities

AML/CTF Compliance Officer

The reforms set out specific eligibility requirements for a person to be an AML/CTF Compliance Officer, including that they must:

  • have sufficient authority, independence and access to resources and information to ensure they can oversee and coordinate the reporting entity’s AML/CTF compliance on a day-to-day basis;
  • be an employee of the reporting entity or otherwise engaged at management level;
  • be a fit and proper person – some factors when considering fitness and propriety are competence, character, integrity, criminal history, records of misconduct, bankruptcy, and conflict of interest.

 

Further, if a reporting entity provides designated services through a permanent establishment in Australia, the AML/CTF Compliance Officer must be a resident of Australia.

Offence of "Tipping Off"

Previously, the tipping off provision was very broad such that a reporting entity could not share information about suspicious matters to anyone other than AUSTRAC, except in very limited circumstances.

The reforms have amended the offence such that it will be an offence only if the person discloses information about suspicious matters or in relation to AUSTRAC’s request for further information, to a person other than AUSTRAC, where the disclosure would or could reasonably be expected to prejudice an investigation of an offence.

Key Elements of the New "Tipping Off" Offence
Understanding AML/CTF Reforms - Part 1: Existing Reporting Entities

Note: the changes to the offence of “tipping off” came into effect on 31 March 2025. Further information is available here.

AUSTRAC's New Powers

The reforms give AUSTRAC a new ‘examination power’ which allows AUSTRAC to issue a notice to a person, requiring the person to produce documents or appear before an examiner to answer questions and produce documents. The examination must be relevant to compliance with the AML/CTF regime or a criminal offence that relates to the AML/CTF regime. A failure to comply with the notice, whether intentionally or recklessly, is an offence.

The reforms also amend AUSTRAC’s ‘information gathering’ power, to allow AUSTRAC to issue a notice to a person, requiring the person to provide certain information or documents, in circumstances that do not relate to suspicious matter, threshold transaction or international funds transfer instruction reports. This enables AUSTRAC to conduct investigations into a reporting entity’s regulatory compliance with the AML/CTF regime or to gather information to support its other functions like financial crime analysis and intelligence. A failure to comply with a notice of this type constitutes a breach attracting civil penalties.

Note: the changes to AUSTRAC’s powers came into effect in January 2025.

Virtual Asset Service Providers

Under the Reforms, the terms ‘virtual asset service provider’ and ‘virtual asset’ replace the previously used terms ‘digital currency exchange’ and ‘digital currency’. Currently, only the exchange of virtual assets for money (and vice versa) is a designated service under the AML/CTF Act. Virtual asset service providers who provide this designated service are required to enrol and register with AUSTRAC.

The Reforms have expanded the list of designated services that would apply to virtual asset service providers to include the following:

  • Exchanging a virtual asset for another virtual asset of the same or different kind – this includes mixing and tumbling activities.
  • Transferring virtual assets from payer to payee (the payer and payee can be the same person).
  • Providing a virtual asset safekeeping service (i.e. ability to hold/trade/transfer/spend the virtual asset per the user’s instructions) – this designated service captures those who administer digital wallets, but does not capture those who provide ancillary infrastructure to support the safekeeping services.
  • Participating in and providing financial services related to an issuer’s offer and/or sale of a virtual asset (e.g. initial coin offerings).
Extending the regime to Tranche-Two Entities 2025

Further Reading

This article only provides a high-level overview of some of the changes introduced under the reforms. Further detail can be found in the AML/CTF Amendment Act 2024, as well as the upcoming new AML/CTF Rules and AUSTRAC’s core guidance.

AUSTRAC's AML/CTF Reforms Hub
AML/CTF Amendment Act 2024
Explanatory Memorandum
Supplementary Explanatory Memorandum
Future Law Compilation of the AML/CTF Act
AML/CTF Rules 2025

If you have any questions about how these changes affect you, please contact us.

AML/CTF Reforms

Sophie Grace can provide you with an AML/CTF Program and can assist you to tailor it to your business’ needs. We have three different options available to suit your business and finance needs.

Template Documents

You can purchase template documents from our online shop. The template is an instant download and includes prompts to help you tailor the document yourself. We have template documents for:

  • Tranche 1 Reporting Entities;
  • Item 54 Providers; and
  • Tranche 2 Entities.
Compliance Portal

Sign up to the Compliance Portal and receive the template AML/CTF Program Package, and obtain access to updated documents in light of any updates we make as new guidance or amended legislation is released. Choose between:

  • document-only plans;
  • consultation-only plans;
  • video and regulatory update plans; or
  • a combination of all three.
Tailored Documents

Sophie Grace can assist you to prepare the AML/CTF Program package based on your business’ specific requirements. Contact us to discuss further. 

Find everything you need in relation to the AML/CTF Reforms

Sophie Grace Compliance Portal

Sign up today for up-to-date compliance policies and regular consultation with our staff. Watch our demonstration video now!

Recent Updates

Contact Us

We will get in touch as soon as possible

=
Tranche 1 AML/CTF Program
Check out our AML/CTF Program for Tranche 1 Entities.
 
You can purchase it through our:
 
The portal includes 1 hour of consultation time with one of our senior staff members and any updates that are made so you have the latest version.