Major AML/CTF Reforms (“Reforms“) commence in 2026. We have put together a summary of each of the changes and how they will impact your business. The Reforms, are divided into two major parts:
The vast majority of the amendments to the AML/CTF Act and AML/CTF Rules commence on 31 March 2026. From this date, all existing reporting entities must comply with the Reforms.
Currently, AML/CTF Programs must be split into two parts:
Under the Reforms, it is no longer a requirement to divide your AML/CTF Program into two parts. It is now up to businesses to organise their AML/CTF Program in a way that meets their needs. The reforms aim to shift the focus from a prescriptive approach to a risk-based one.
The updated requirements for AML/CTF Programs are:
Customer due diligence is a core obligation in the current regime and involves entities carrying out documented procedures to identify and verify customers before they commence providing a designated service. The Reforms to the customer due diligence requirements ensure a more targeted and flexible approach, that focus on a business’ risk assessment of their customers. The Reforms, which come into effect on 31 March 2026, break down customer due diligence into two categories:
When beginning a relationship with a customer, you must collect KYC information to identify the customer and verify the KYC information you have collected. The extent of the information collected and verified will depend on the risk categorisation of the customer. All businesses must conduct a risk assessment on each of their customers, taking into account the services being provided, the type of customer they are, the countries they are associated with and the delivery channels utilised to provide your services to them. Screening must also be completed to determine if the customer is the subject of any financial sanctions, or is a politically exposed person.
The Reforms include some specific requirements for certain customer types, for example:
may be applied in situations where the ML/TF/PF risk of the customer is low and no enhanced customer due diligence triggers apply.
must be applied where the ML/TF/PF risk has been identified as high or in situations where there are inherent risks associated with a customer relationship.
do not need to be subject to initial customer due diligence again, but must be monitored for significant changes that would increase their risk classification to medium or high or trigger a suspicious matter reporting obligation. If this were to occur, initial and ongoing customer due diligence must be completed.
Over the course of your relationship with a customer, you must monitor and manage the ML/TF/PF risks of the customer. This includes:
Exemptions to customer due diligence obligations have been streamlined so that law enforcement can now issue notices directly to reporting entities, allowing them to ‘keep open’ customer accounts if closing them could alert the customer to a law enforcement investigation.
The reforms replace the existing “Designated Business Group” regime with the “Reporting Group” concept. Reporting Groups are groups of persons where one (or more) is a reporting entity. Reporting Groups can be:
All Reporting Groups must have a Lead Entity. The method for determining the Lead Entity is detailed in the AML/CTF Rules.
The Reforms set out specific eligibility requirements for a person to be an AML/CTF Compliance Officer, including that they must:
Further, if a reporting entity provides designated services through a permanent establishment in Australia, the AML/CTF Compliance Officer must be a resident of Australia.
The Tipping Off offence aims to deter regulated entities from disclosing information that may reveal the existence of a suspicious matter report (“SMR“) which could compromise a law enforcement investigation. The previous regime allowed a number of exemptions to the offence of Tipping Off, however these exemptions have not kept up to date with changes in supporting compliance, the transition to a globalised risk management approach and the increasingly complex business structures of regulated entities.
Changes to the tipping off offence came into effect on 31 March 2025 and focus on a harm prevention approach to the offence. The changes focus on whether disclosing information protected by the tipping off offence would or could reasonably be expected to prejudice an investigation.
It is now a criminal offence to disclose certain types of information to another person, where it could or would reasonably be expected to prejudice an investigation. The AUSTRAC website has provided a number of strategies reporting entities could use to reduce the risk of disclosing protected information. Some of these strategies include:
Sign up today for up-to-date compliance policies and regular consultation with our staff. Watch our demonstration video now!
We will get in touch as soon as possible