Overview of the AML/CTF Requirements

AdBlock

Tranche 2 AML/CTF Program
Check out our AML/CTF Program for Tranche 2 Entities.
 
You can purchase it through our:
 
The portal includes 1 hour of consultation time with one of our senior staff members.
 
Additionally, If you would like to receive Tranche 2 related updates, please sign up to our mailing list below.
 

Major AML/CTF Reforms (“Reforms“) commence in 2026. We have put together a summary of each of the changes and how they will impact your business. The Reforms, are divided into two major parts:

  1. Simplifying and Modernising the AML/CTF Regime; and
  2. Extending the regime to additional high-risk professions (known as Tranche Two entities) (to read more about this, click here).

The vast majority of the amendments to the AML/CTF Act and AML/CTF Rules commence on 31 March 2026. From this date, all existing reporting entities must comply with the Reforms.

Tranche 1 Generic Newsletter

AML/CTF Programs

Currently, AML/CTF Programs must be split into two parts:

Sign Up Any changes to key personnel or your contact details (6)

Under the Reforms, it is no longer a requirement to divide your AML/CTF Program into two parts. It is now up to businesses to organise their AML/CTF Program in a way that meets their needs. The reforms aim to shift the focus from a prescriptive approach to a risk-based one.

The updated requirements for AML/CTF Programs are:

  • ML/TF/PF Risk Assessment – businesses must identify and assess risks related to money laundering, terrorism financing, and proliferation financing (ML/TF/PF) risks.
  • Risk Management Policies – businesses must outline ways to manage and mitigate the ML/TF/PF risks identified by the business. If your proliferation financing risk is classified as ‘low’ and is adequately addressed by your ML/TF policies, there is no need to implement specific counter-proliferation financing policies.
  • Internal compliance procedures – businesses must specify procedures and measures to ensure they comply with their obligations and requirements under the AML/CTF Act and the new AML/CTF Rules. This includes having clear compliance governance structures and reporting lines, conducting personnel due diligence and training, and reviewing policies and procedures.

Customer Due Diligence

Customer due diligence is a core obligation in the current regime and involves entities carrying out documented procedures to identify and verify customers before they commence providing a designated service. The Reforms to the customer due diligence requirements ensure a more targeted and flexible approach, that focus on a business’ risk assessment of their customers. The Reforms, which come into effect on 31 March 2026, break down customer due diligence into two categories:

1. Initial Customer Due Diligence

When beginning a relationship with a customer, you must collect KYC information to identify the customer and verify the KYC information you have collected. The extent of the information collected and verified will depend on the risk categorisation of the customer. All businesses must conduct a risk assessment on each of their customers, taking into account the services being provided, the type of customer they are, the countries they are associated with and the delivery channels utilised to provide your services to them. Screening must also be completed to determine if the customer is the subject of any financial sanctions, or is a politically exposed person.

The Reforms include some specific requirements for certain customer types, for example:

Simplified customer due diligence

may be applied in situations where the ML/TF/PF risk of the customer is low and no enhanced customer due diligence triggers apply.

Enhanced customer due diligence

must be applied where the ML/TF/PF risk has been identified as high or in situations where there are inherent risks associated with a customer relationship.

Pre-commencement customers

do not need to be subject to initial customer due diligence again, but must be monitored for significant changes that would increase their risk classification to medium or high or trigger a suspicious matter reporting obligation. If this were to occur, initial and ongoing customer due diligence must be completed.

2. Ongoing Customer Due Diligence

Over the course of your relationship with a customer, you must monitor and manage the ML/TF/PF risks of the customer. This includes:

  • Updating your customer risk assessment;
  • Collecting further or enhanced KYC information;
  • Reverifying KYC information;
  • Conducting transaction monitoring.

Exemptions to customer due diligence obligations have been streamlined so that law enforcement can now issue notices directly to reporting entities, allowing them to ‘keep open’ customer accounts if closing them could alert the customer to a law enforcement investigation.

The structure of Reporting Groups

The reforms replace the existing “Designated Business Group” regime with the “Reporting Group” concept. Reporting Groups are groups of persons where one (or more) is a reporting entity. Reporting Groups can be:

  1. a Business Group (where one of the persons in the group controls the others); or 
  2. a Reporting Group which is formed by election. 


All Reporting Groups must have a Lead Entity. The method for determining the Lead Entity is detailed in the AML/CTF Rules.

AML/CTF Compliance Officers

The Reforms set out specific eligibility requirements for a person to be an AML/CTF Compliance Officer, including that they must:

Tranche 2

Further, if a reporting entity provides designated services through a permanent establishment in Australia, the AML/CTF Compliance Officer must be a resident of Australia.

Amended Tipping Off Offence

The Tipping Off offence aims to deter regulated entities from disclosing information that may reveal the existence of a suspicious matter report (“SMR“) which could compromise a law enforcement investigation. The previous regime allowed a number of exemptions to the offence of Tipping Off, however these exemptions have not kept up to date with changes in supporting compliance, the transition to a globalised risk management approach and the increasingly complex business structures of regulated entities.

Changes to the tipping off offence came into effect on 31 March 2025 and focus on a harm prevention approach to the offence. The changes focus on whether disclosing information protected by the tipping off offence would or could reasonably be expected to prejudice an investigation. 

It is now a criminal offence to disclose certain types of information to another person, where it could or would reasonably be expected to prejudice an investigation. The AUSTRAC website has provided a number of strategies reporting entities could use to reduce the risk of disclosing protected information. Some of these strategies include:

  • Implementing information controls such as restricting information to those with a genuine need to know, de-identifying any information that is distributed more widely across your business, or implementing and reviewing audit trails of who accesses information and when;
  • Providing regular training on preventing tipping off to all staff who have access to information;
  • Making reasonable inquiries into unusual customer activity and providing the customer with genuine reasons for making such inquiries that would not cause them to be suspicious, for example you could tell the customer you are taking steps to comply with legislation, updating your customer files, or collecting additional information as part of your company’s standard processes in certain situations;
  • Providing genuine reasons for ending a business relationship with a customer that would not indicate you are suspicious of that customer. Reasons may include, the nature of the customer’s activities fall outside your business’ risk appetite, or your business has made the decision not to fund the additional systems that are needed to manage the obligations associated with their account.
If you would like to receive updates related to the AML/CTF reforms, please subscribe to our newsletter below

Subscribe

* indicates required
Subscription (select one or more options)
Further Reading

Sophie Grace Compliance Portal

Sign up today for up-to-date compliance policies and regular consultation with our staff. Watch our demonstration video now!

Recent Updates

Contact Us

We will get in touch as soon as possible

=

AdBlock

Tranche 2 AML/CTF Program
Check out our AML/CTF Program for Tranche 2 Entities.
 
You can purchase it through our:
 
The portal includes 1 hour of consultation time with one of our senior staff members.
 
Additionally, If you would like to receive Tranche 2 related updates, please sign up to our mailing list below.
 

AdBlock

Tranche 2 AML/CTF Program
Check out our AML/CTF Program for Tranche 2 Entities.
 
You can purchase it through our:
 
The portal includes 1 hour of consultation time with one of our senior staff members.
 
Additionally, If you would like to receive Tranche 2 related updates, please sign up to our mailing list below.