Reforms to Australia’s AML/CTF regime have been passed and will for the most part commence in 2026. For existing reporting entities, the reforms and the new AML/CTF Rules introduce changes to various AML/CTF obligations and requirements which are contained in the original AML/CTF Act 2006. While many of these changes do not start until 31 March 2026, existing reporting entities should become familiar with these changes so that they are on track to implement them. This will help ensure reporting entities continue to stay compliant with the AML/CTF regime in its next iteration.
Key AML/CTF Reforms applicable to existing reporting entities
AML/CTF Programs
Under the reforms, an AML/CTF Program no longer needs to be separated into Part A and Part B. A reporting entity can choose how it wants to structure their AML/CTF Program, so long as the AML/CTF Program documents the reporting entity’s:
- assessment of money laundering, terrorism financing and proliferation financing (“ML/TF/PF“) risks specific to its business (ML/TF risk assessment);
- procedures and measures appropriate to manage and mitigate the ML/TF/PF risks specific to its business; and
- procedures and measures to ensure it complies with its obligations and requirements under the AML/CTF Act.
A failure to comply with the procedures and requirements as outlined in a reporting entity’s own AML/CTF Program will be a breach attracting civil penalties. This means reporting entities need to not only have an AML/CTF Program, but also implement what they say they will do in their AML/CTF Program.
Customer due diligence ("CDD") procedures
The reforms give a reporting entity more flexibility when conducting CDD procedures.
| When? | What? | How? | Outcome |
|---|---|---|---|
| Initial CDD (at the onboarding stage) |
| The reporting entity must determine the CDD procedures to apply based on their risk assessment. Simplified CDD can be applied in certain circumstances, when the ML/TF risk of the customer is low. Enhanced CDD must be applied where:
| The reporting entity must be satisfied about factors such as:
|
| Ongoing CDD (on an ongoing basis) |
| The reporting entity must appropriately identify, assess, manage and mitigate the ML/TF risks associated with providing designated services to the customer. |
The terms “simplified CDD” and “enhanced CDD” are not specifically defined in the legislation, although some enhanced CDD procedures are mandated for certain customer types. A reporting entity will have the flexibility to decide what constitutes simplified and enhanced CDD procedures, so long as enhanced CDD involves more rigorous checks and monitoring on the customer when compared to simplified CDD.
From 'Designated Business Group' to 'Reporting Group'
The reforms replace the existing “Designated Business Group” regime with the “Reporting Group” concept. If a reporting entity is part of a reporting group, the AML/CTF governance structure is set out as follows:
| Business Group | Either:
|
| Elective Reporting Group | A group of 2 or more persons who have elected to form a group as permitted by the AML/CTF Rules. |
| Lead Entity | The method for determining the lead entity of a reporting group is to be defined in the AML/CTF Rules. The lead entity will likely be the entity which controls all other members of a Business Group who provide a designated service OR the other members have agreed that it does not control any other members of the Elective Reporting Group. It must have a connection to Australia, and the capability and authority to develop and maintain the AML/CTF Policies required by other Members of the Reporting Group. |
Reporting Groups
AML/CTF Compliance Officer
The reforms set out specific eligibility requirements for a person to be an AML/CTF Compliance Officer, including that they must:
- have sufficient authority, independence and access to resources and information to ensure they can oversee and coordinate the reporting entity’s AML/CTF compliance on a day-to-day basis;
- be an employee of the reporting entity or otherwise engaged at management level;
- be a fit and proper person – some factors when considering fitness and propriety are competence, character, integrity, criminal history, records of misconduct, bankruptcy, and conflict of interest.
Further, if a reporting entity provides designated services through a permanent establishment in Australia, the AML/CTF Compliance Officer must be a resident of Australia.
Offence of "Tipping Off"
Previously, the tipping off provision was very broad such that a reporting entity could not share information about suspicious matters to anyone other than AUSTRAC, except in very limited circumstances.
The reforms have amended the offence such that it will be an offence only if the person discloses information about suspicious matters or in relation to AUSTRAC’s request for further information, to a person other than AUSTRAC, where the disclosure would or could reasonably be expected to prejudice an investigation of an offence.
Key Elements of the New "Tipping Off" Offence
Note: the changes to the offence of “tipping off” came into effect on 31 March 2025. Further information is available here.
AUSTRAC's New Powers
The reforms give AUSTRAC a new ‘examination power’ which allows AUSTRAC to issue a notice to a person, requiring the person to produce documents or appear before an examiner to answer questions and produce documents. The examination must be relevant to compliance with the AML/CTF regime or a criminal offence that relates to the AML/CTF regime. A failure to comply with the notice, whether intentionally or recklessly, is an offence.
The reforms also amend AUSTRAC’s ‘information gathering’ power, to allow AUSTRAC to issue a notice to a person, requiring the person to provide certain information or documents, in circumstances that do not relate to suspicious matter, threshold transaction or international funds transfer instruction reports. This enables AUSTRAC to conduct investigations into a reporting entity’s regulatory compliance with the AML/CTF regime or to gather information to support its other functions like financial crime analysis and intelligence. A failure to comply with a notice of this type constitutes a breach attracting civil penalties.
Note: the changes to AUSTRAC’s powers came into effect in January 2025.
Virtual Asset Service Providers
Under the Reforms, the terms ‘virtual asset service provider’ and ‘virtual asset’ replace the previously used terms ‘digital currency exchange’ and ‘digital currency’. Currently, only the exchange of virtual assets for money (and vice versa) is a designated service under the AML/CTF Act. Virtual asset service providers who provide this designated service are required to enrol and register with AUSTRAC.
The Reforms have expanded the list of designated services that would apply to virtual asset service providers to include the following:
- Exchanging a virtual asset for another virtual asset of the same or different kind – this includes mixing and tumbling activities.
- Transferring virtual assets from payer to payee (the payer and payee can be the same person).
- Providing a virtual asset safekeeping service (i.e. ability to hold/trade/transfer/spend the virtual asset per the user’s instructions) – this designated service captures those who administer digital wallets, but does not capture those who provide ancillary infrastructure to support the safekeeping services.
- Participating in and providing financial services related to an issuer’s offer and/or sale of a virtual asset (e.g. initial coin offerings).
Further Reading
This article only provides a high-level overview of some of the changes introduced under the reforms. Further detail can be found in the AML/CTF Amendment Act 2024, as well as the upcoming new AML/CTF Rules and AUSTRAC’s core guidance.
AUSTRAC's AML/CTF Reforms Hub
AML/CTF Amendment Act 2024
Explanatory Memorandum
Supplementary Explanatory Memorandum
Future Law Compilation of the AML/CTF Act
AML/CTF Rules 2025
If you have any questions about how these changes affect you, please contact us.


