Accountants

AUSTRAC AML obligations for accountants

AUSTRAC AML/CTF obligations for Australian accounting practices, covering designated services, enrolment, CDD, governance, monitoring and reporting.

Last reviewed

Coverage depends on the service and its Australian connection

Australia's expanded anti-money laundering and counter-terrorism financing regime applies to accounting practices according to the services they provide. Coverage also requires a geographical link to Australia. The professional title used by a business, the type of qualification held by its staff and the industry label attached to an engagement do not determine the result.

As at 6 August 2026, the professional designated services introduced by the reforms have been in force since 1 July 2026. An accounting practice should therefore begin each assessment by documenting the activity it performs and the facts that establish the Australian geographical link. Work delivered through Australian operations will commonly require close attention. Cross-border engagements need their own analysis because an overseas customer, asset or transaction can still be connected to a service supplied in Australia.

Services that can bring an accounting practice within the regime

The designated-service definitions are profession neutral. An accountant can be covered when the engagement includes active steps that directly advance a specified transaction or arrangement. General discussion or advice that merely influences a later decision will usually be outside these categories. The facts and the accountant's authority matter.

  • Assisting to plan or carry out the creation or legal restructuring of a company, express trust, partnership or other covered arrangement can be a designated service. Drafting formation documents, preparing applications and taking steps that enable the structure to be created are relevant examples.
  • Assisting with the sale, purchase or transfer of a company, controlling interest, legal arrangement or real estate can be covered when the work directly advances an identified transaction. Negotiating terms, preparing transaction documents, conducting due diligence in anticipation of the sale and preparing for settlement can fall within scope.
  • Receiving, holding and controlling client money or other property, including disbursing it, can be covered when the activity directly advances a transaction. Managing money, accounts, securities, virtual assets or other property can also be covered where the practice has authority and discretion over how the property is dealt with.
  • Helping to organise, plan or execute equity or debt financing for a company or legal arrangement can be covered. This can include work that directly advances capital contributions, share issues, loans or another identified financing transaction.
  • Selling or transferring a shelf company, providing a registered office or principal place of business address, and acting or arranging for another person to act in specified company, partnership or trust roles can also be designated services.

Routine bookkeeping, tax preparation, statutory audit and ordinary accounting work supplied on their own do not trigger coverage merely because an accountant performs them. Routine payment processing under fixed instructions, with no discretion to redirect funds or alter their purpose, is less likely to amount to managing client money. Relevant exemptions can also apply to payments reasonably incidental to a non-designated service.

Mixed engagements require closer classification. Tax advice about the consequences of a proposed company sale may sit outside the designated-service definition. The same file can move into scope if the practice then represents the client in negotiations, prepares sale documents, handles settlement funds or arranges the financing. Engagement letters, matter codes and handover procedures should show when a covered activity starts.

Enrolment, commencement and implementation timing

The reforms commenced on 1 July 2026. Enrolment is completed through the AUSTRAC Business Profiles Portal, which opened on 31 March 2026, and covers the practice's identifying details, the designated services it provides and its AML/CTF compliance officer. A newly regulated business that was already providing designated services at commencement was required to enrol by 29 July 2026. A practice starting a designated service later must generally apply no later than 28 days after the day it starts.

A practice that already held an AUSTRAC enrolment for other reasons should confirm its business profile reflects the newly regulated services rather than assume the existing record is sufficient. Enrolment and operational controls remain separate requirements, so CDD, program and reporting processes need to function when the relevant obligation applies.

Transitional rules can adjust the timing of particular steps according to the service, enrolment date and circumstances. A practice relying on a transitional provision should record the rule, the obligations affected and its expiry. A general assumption that implementation has been deferred would leave gaps in customer acceptance and reporting processes.

Build the program from the practice risk assessment

The AML/CTF program should be based on a documented assessment of money laundering, terrorism financing and proliferation financing risk. The assessment should consider the practice's designated services, customer types, ownership structures, countries, transaction characteristics and delivery channels. It should identify inherent risk, evaluate the controls used to reduce that risk and record the remaining risk accepted by the practice.

Examples requiring closer attention can include opaque ownership, unexplained use of multiple entities, nominee arrangements, third-party funding, transactions with no clear commercial purpose, remote onboarding, unexpected high-risk country exposure and requests for the practice to control funds beyond the stated engagement. The assessment should be reviewed after material changes and on a planned cycle.

Governance, the compliance officer and personnel

The governing body or senior management should approve the program, oversee its operation and receive useful information about control performance. The practice must appoint an AML/CTF compliance officer who meets the applicable eligibility requirements and has enough authority, access and resources to perform the role. Responsibilities should cover advice, escalation, reporting, control testing, remediation and communication with AUSTRAC.

Personnel due diligence and training should reflect each role. Client-facing staff need to recognise when an ordinary engagement adds a designated service. Onboarding teams need clear evidence standards. Partners and the compliance officer need documented escalation and decision processes. Training records should show attendance, content, assessment and follow-up.

CDD, beneficial ownership and enhanced measures

Initial CDD should ordinarily be completed before the practice starts providing a designated service. The practice must identify its customer, verify identity using reliable and independent information, understand the nature and purpose of the relationship and identify beneficial owners where relevant. Company and trust files often require information about ownership, control, directors, trustees, settlors or beneficiaries, depending on the service and customer definition.

Screening for politically exposed person status and applicable sanctions should cover the relevant customer and connected persons identified by the firm's procedures. Results need human review and a clear audit trail. A possible sanctions match should be escalated promptly because sanctions laws can impose separate restrictions.

Higher risk or a prescribed trigger can require enhanced measures. These may include additional identity checks, independent ownership evidence, a clearer explanation of the structure and transaction, source of funds or source of wealth information, senior approval and more frequent review. The file should connect each extra measure to the risk it addresses.

Monitoring, SMRs and records

Ongoing CDD and transaction monitoring should test activity against what the practice knows about the customer and the engagement. Reviews should detect changes in ownership, unexplained third-party payments, unusual movement of funds, unexpected jurisdictions, transaction splitting, unnecessary complexity and instructions that conflict with the stated purpose.

If the practice forms reasonable grounds for suspicion under the Act, it must submit a suspicious matter report within the applicable period. The usual period is 24 hours for a terrorism financing suspicion and three business days for other reportable suspicions. Staff should preserve the reasoning, restrict access to the report and comply with the tipping-off prohibition.

Records should allow the practice and AUSTRAC to reconstruct what occurred. This includes the service classification, geographical-link analysis, risk assessment, program approvals, CDD evidence, beneficial ownership work, screening, monitoring alerts, enhanced measures, reporting decisions, training and control reviews.

AUSTRAC has a range of supervisory and enforcement options for non-compliance, and the Act sets civil penalties in penalty units rather than fixed dollar amounts. A practice assessing its exposure should work from the current penalty provisions and AUSTRAC's published enforcement approach.

A practical sequence for accounting practices

  1. Inventory current services and client workflows, then mark the point at which each covered activity starts.
  2. Confirm enrolment status, the Australian geographical link and any specific transitional provision being used.
  3. Approve the risk assessment, governance framework, compliance officer appointment and AML/CTF program.
  4. Configure engagement acceptance, CDD, beneficial ownership, screening, enhanced review, monitoring and SMR workflows.
  5. Train personnel using examples from the practice, then test whether files are classified and escalated consistently.
  6. Review a sample of completed matters, correct control failures and report results to the governing body.

Core controls for accounting practices

  • Classify each service

    Review the work actually performed and identify any activity that directly advances a designated transaction or arrangement.

  • Confirm the Australian connection

    Record how each designated service satisfies the statutory geographical link to Australia.

  • Confirm enrolment

    Check the practice's AUSTRAC enrolment is current and that its designated services and contact details are accurate.

  • Know the customer

    Identify and verify customers and beneficial owners before the designated service starts, subject to limited exceptions.

  • Set accountable governance

    Give the governing body and AML/CTF compliance officer clear authority, information and review responsibilities.

  • Monitor and report

    Review activity against the customer profile, investigate unusual conduct and submit SMRs when the legal test is met.

Common questions

Do routine accounting services trigger AUSTRAC obligations?

Routine bookkeeping, tax return preparation, audit and ordinary accounting advice do not, by themselves, fall within the professional designated-service categories. A mixed engagement can still contain a designated service, so the practice should classify each activity rather than assign one status to the whole client file.

How does an accounting practice enrol with AUSTRAC?

Enrolment is completed through the AUSTRAC Business Profiles Portal, which opened on 31 March 2026. The practice supplies its ABN, contact details, the designated services it provides and its AML/CTF compliance officer details. A business already providing newly regulated services at commencement was required to enrol by 29 July 2026. A practice that starts later must generally apply no later than 28 days after it first provides a designated service.

When did the accountant reforms commence?

The new professional designated services commenced on 1 July 2026. Enrolment and operational controls are separate requirements, so customer due diligence, program and reporting processes need to work when the relevant obligation applies. Any transitional relief should be checked against the current rules and the firm's circumstances.

Who is the customer when a company or trust is created?

The answer depends on the designated service. For company creation, AUSTRAC guidance identifies the person giving instructions and may also treat proposed beneficial owners and directors as customers. For an express trust, the proposed trustee, settlor and beneficiaries may be relevant. The file should record the service, each customer and the verification completed.

When are enhanced customer due diligence measures required?

Enhanced measures apply when the statutory triggers or the firm's risk assessment require them. Measures can include obtaining further identity evidence, establishing source of funds or source of wealth, clarifying ownership and purpose, seeking senior approval and increasing monitoring. The response should match the identified risk.

How long should an accounting practice keep AML/CTF records?

The Act and Rules set retention periods for different records, and many core CDD and transaction records must be retained for seven years. The practice should maintain a retention schedule covering its program, risk assessment, customer evidence, beneficial ownership work, monitoring reviews, reporting decisions and training records.