Australian AML/CTF law

AML/CTF Act 2006

A concise guide to Australia's AML/CTF Act 2006, including designated services, reporting entities, risk-based programs and the 2026 expansion.

How the AML/CTF Act operates

The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 is the principal Commonwealth framework for preventing and detecting money laundering, terrorism financing and proliferation financing through regulated services. AUSTRAC administers the Act as Australia's AML/CTF regulator and financial intelligence unit. The Act operates with the AML/CTF Rules, Regulations and other relevant legislation.

Designated services and reporting entities

Coverage is determined by designated services listed in the Act. A person or business that provides a designated service in the circumstances specified by the legislation is a reporting entity. Its duties relate to those regulated activities and the risks associated with them.

This service-based test matters for banks, remitters, digital currency exchanges, gambling businesses and bullion providers, as well as the sectors added through the 2024 reforms. A professional title alone does not bring every member of a profession within the framework. A lawyer, accountant, conveyancer, real estate professional or dealer is covered only when providing a designated service to which the Act applies.

Risk-based AML/CTF programs

A reporting entity must identify and assess the risks that its business could be misused for money laundering, terrorism financing or proliferation financing. Its AML/CTF program then sets out governance, controls and procedures for managing those risks. The program should reflect the entity's services, customers, delivery channels, countries of operation, size and complexity.

Senior management oversight, an appointed AML/CTF compliance officer, staff training, employee due diligence, independent evaluation and regular review support the program. Changes to services, customers, technology or risk exposure should prompt an updated assessment and, where needed, revised controls.

Customer due diligence

Customer due diligence begins before or when a designated service is provided, subject to the limited timing rules in the legislation. Reporting entities collect and verify information about customers and, for organisations and trusts, identify relevant beneficial owners and controllers. They also determine whether additional checks are needed for politically exposed persons or other higher-risk circumstances.

Ongoing due diligence keeps customer information current and tests whether transactions remain consistent with what the entity knows about the customer, the purpose of the relationship and its risk rating. Enhanced due diligence applies where the assessed risk or specified circumstances require stronger measures.

Reporting obligations

The Act requires prescribed reports to AUSTRAC. Depending on the service and transaction, these can include suspicious matter reports, threshold transaction reports for qualifying physical currency transfers, and reports about international value transfers. Each report has its own trigger, required information and deadline.

Transaction monitoring should support these decisions by identifying activity that requires review. A reporting entity must assess the facts, document its reasoning and lodge a report when the statutory test is met. Confidentiality and tipping off restrictions apply to suspicious matter reporting information.

Records and evidence

Reporting entities must keep records that show how they met their obligations. These include relevant customer identification, beneficial ownership, transaction, program, risk assessment, due diligence and reporting records. The Act and Rules prescribe retention periods, commonly seven years for core customer identification and transaction material. Records must be retrievable and protected from unauthorised access or alteration.

AUSTRAC supervision

AUSTRAC supervises reporting entities, provides regulatory guidance and receives prescribed reports for financial intelligence purposes. Its supervisory work can include information requests, risk assessments, inspections and reviews of an entity's systems and records. Where AUSTRAC identifies non-compliance, available responses range from education and remediation requirements to formal enforcement action under the legislation.

The 2024 reforms and 2026 expansion

Parliament amended the framework in 2024 to revise existing obligations and extend regulation to additional designated services. Changes affecting existing reporting entities took effect on 31 March 2026. Coverage of specified services provided by lawyers, conveyancers, accountants, real estate professionals, trust and company service providers, and dealers in precious metals and stones began on 1 July 2026.

As at 6 August 2026, those commencement dates have passed. Businesses in the added sectors must assess the actual services they provide against the designated service definitions. Those that meet the test must enrol with AUSTRAC and apply the obligations relevant to their regulated work. Activities outside the designated service definitions do not become regulated solely because they are performed by someone in a listed sector.

Core elements of the AML/CTF Act

  • Designated services

    Coverage follows the regulated services a person or business provides.

  • Reporting entities

    Providers of designated services must meet the obligations that apply to their activities.

  • Risk-based program

    Controls must respond to the nature, size, complexity and risk profile of the business.

  • Customer due diligence

    Reporting entities identify customers, understand ownership and conduct ongoing due diligence.

  • Reports and records

    The framework sets transaction reporting and record-keeping requirements.

  • AUSTRAC supervision

    AUSTRAC administers the framework and supervises reporting entity compliance.

Common questions

What is the AML/CTF Act 2006?

It is the principal Commonwealth legislation for preventing and detecting money laundering, terrorism financing and proliferation financing through regulated services. AUSTRAC administers the framework alongside the AML/CTF Rules and Regulations.

Who is covered by the Act?

A person or business becomes a reporting entity when it provides a designated service in circumstances covered by the Act. Coverage is based on the service provided, so membership of a profession alone does not make every practitioner a reporting entity.

What are the main obligations?

Applicable obligations include enrolment or registration, an ML/TF risk assessment, a risk-based AML/CTF program, customer due diligence, transaction monitoring, prescribed reports, record keeping and cooperation with AUSTRAC supervision.

What changed in 2026?

Reforms passed in 2024 changed obligations for existing reporting entities from 31 March 2026. From 1 July 2026, the Act also covered specified designated services provided in sectors including real estate, professional services and precious metals and stones.