AML for accounting firms
AML questions accounting firms ask
Plain answers to 204 questions about AUSTRAC’s rules, from the questions firms have sent us and from AUSTRAC’s own guidance and webinars. Every answer links to its source.
Checked against AUSTRAC’s guidance as at 5 October 2026. General information, not advice for your firm’s AML/CTF program.
- Does AML apply to your firm?
- Enrolling with AUSTRAC
- Existing clients
- Onboarding: CDD and ID
- Beneficial owners, PEPs and sanctions
- Customer risk assessments
- Your AML/CTF program
- Compliance officer and staff
- Record keeping
- Relying on others, and using software
- Reporting to AUSTRAC
- Suspicious matters and tipping off
- How AUSTRAC approaches newly regulated firms
- Using Seamlss for AML
Does AML apply to your firm?
Your obligations follow the services you provide, not your job title.
Only designated services do. For most accounting firms the common ones are acting as a client’s registered office, setting up or restructuring a company, trust or partnership, and in some circumstances handling a client’s money as part of a transaction. Others include selling shelf companies and acting as, or arranging, a nominee director, shareholder or trustee. Setting up a sole trader isn’t one of them on its own.
Read more: AML scope for accounting firms AUSTRAC: professional designated services
Not on its own. Preparing a tax return isn’t a designated service. A client comes into scope when you provide them a designated service, such as acting as their registered office or setting up a company or trust for them.
Read more: AUSTRAC: professional designated services Customer due diligence for accounting firms
Sole trader: no, not on its own. Partnership: yes.
Creating a company or a legal arrangement is a designated service, and AUSTRAC’s definition of a legal arrangement includes a partnership, alongside express trusts, joint ventures and unincorporated associations. Drafting a partnership agreement is one of the preparatory steps AUSTRAC lists. A sole trader isn’t a company or a legal arrangement, so registering one isn’t that service. Other services you provide to a sole trader, such as acting as their registered office or handling their money, could still be.
Read more: AUSTRAC: professional designated services
Yes. Providing a registered office or principal place of business address for a company or other legal arrangement is a designated service, whether or not you charge for it. Many firms are reviewing whether to keep providing it.
Read more: Should your firm still be the registered office? AUSTRAC: professional designated services
You can, and plenty of firms are. It changes your revenue. Your obligations stay where they are, because the service is caught whether you charge for it or do it for nothing.
Read more: AML scope for accounting firms AUSTRAC: professional designated services
No. Ceasing a service stops obligations accruing from that point. Records you were required to keep still have to be kept, a reporting obligation that already arose does not disappear, and a suspicious matter reporting obligation can still arise. Provide the service once more after deciding to stop, and you are in the regime anyway.
Read more: AML scope for accounting firms AUSTRAC: professional designated services
AUSTRAC’s guidance says a person acting only as a filing agent, nominee or representative to carry out administrative or procedural steps does not, by that fact alone, fall within the nominee officeholder item. Company formation is a separate item and stays fact dependent: drafting or reviewing the documents that create a company is caught, lodging a change of address for an existing one looks nothing like that.
Read more: AML scope for accounting firms AUSTRAC: professional designated services
No. It’s the services you provide that matter, not your role or job title. You’re a reporting entity if you provide one or more designated services, such as acting as a client’s registered office or setting up a company, trust or partnership. AUSTRAC lists accountants among the businesses that typically provide these services, so check yours against the list, and AUSTRAC suggests getting independent advice if you’re not sure.
Read more: AUSTRAC: Who and what we regulate AML scope for accounting firms
In AUSTRAC’s example, tax advice on the implications of selling a body corporate is not regulated at that point, because it does not directly advance a transaction and no transaction exists yet. The designated service begins if the firm is instructed to act for the client to sell to an identified buyer or, where many potential buyers have been identified, when negotiations begin with one or more of them.
Read more: AUSTRAC: Professional designated services AML scope for accounting firms
AUSTRAC says the preparatory steps taken to assist in the sale of a body corporate are regulated, including representing the client in negotiations, preparing or reviewing sale contracts, due diligence and valuation of assets and liabilities in anticipation of the sale, preparing for financial settlement and preparing documents for an authority such as ASIC. Item 2 only applies where the sale, purchase or transfer relates to a controlling interest.
Read more: AUSTRAC: Professional designated services AML scope for accounting firms
AUSTRAC says being connected to a transaction or outcome is generally not enough: your service must involve active steps that directly advance it. Merely influencing how the customer proceeds, providing general advice or providing ancillary services is not sufficient.
Read more: AUSTRAC: Professional designated services AML scope for accounting firms
In AUSTRAC’s example, an accounting practice receives a client’s money into its bank account and pays the client’s business lease and a family member’s school fees on the client’s instructions. AUSTRAC says the practice is likely to be receiving, holding and controlling the client’s money, and would be providing an item 3 designated service unless an exemption in subsection 6(5C) applies.
Read more: AUSTRAC: Professional designated services AML scope for accounting firms
AUSTRAC says a bookkeeper processing routine payments on fixed client instructions, with no discretion to redirect funds, substitute beneficiaries or vary the purpose, is less likely to be managing the client’s money for item 3. Even if it were, those dealings would generally be reasonably incidental to the bookkeeping and covered by the exception in paragraph 6(5C)(b), provided the practice does not provide other designated services such as item 9 business address services or item 7 arranging for a person to act in a role.
Read more: AUSTRAC: Professional designated services AML scope for accounting firms
No. AUSTRAC says the paragraph 6(5C)(b) exception applies at the business level, so you must consider all services provided by the same entity across practice areas, and it only applies if you provide no designated services other than item 3. It does not apply if a client is using your trust account as a de facto bank account.
Read more: AUSTRAC: Professional designated services AML scope for accounting firms
Item 6 covers assisting a person to plan or execute, or acting on their behalf in, the creation or restructuring of a body corporate or legal arrangement. AUSTRAC says it extends to preparatory steps such as drafting company constitutions and trust deeds, and registering applications and forms with ASIC, for example to register a company or a business name.
Read more: AUSTRAC: Professional designated services AML scope for accounting firms
For item 6, restructuring means changing the legal form of the body corporate or legal arrangement, including through a merger or demerger. It does not extend to matters unrelated to legal form, such as staffing, IT systems or debt restructuring for small businesses under the Corporations Act 2001, although item 4 may separately apply to some debt restructuring.
Read more: AUSTRAC: Professional designated services AML scope for accounting firms
Unless your firm holds a limited AFSL, the question is whether you’re helping create the fund’s trust. You provide that designated service if you take steps to directly create it, such as drafting the trust deed and the paperwork to appoint trustees, or give advice comprehensive enough for the client to set it up without further professional help. In AUSTRAC’s example, advising on an SMSF, explaining the steps and referring the client to a solicitor only influenced the trust’s creation, so it wasn’t that service; the solicitor who drafted the deed provided it.
If your firm does hold a limited AFSL, there’s one more point: AUSTRAC notes that an AFSL holder arranging for a client to receive a designated service is providing one under item 54 of table 1.
Read more: AUSTRAC: Professional designated services AML scope for accounting firms
Item 7 covers acting as, or arranging for another person to act as, a company director or secretary, a power of attorney of a body corporate or legal arrangement, a partner in a partnership or a trustee of an express trust, on behalf of a person (the nominator), who is the customer. AUSTRAC says making preparations, such as drafting appointment documents or identifying or introducing a person for the role, is also providing the service.
Read more: AUSTRAC: Professional designated services AML scope for accounting firms
AUSTRAC says a service can be provided in the course of carrying on a business even if it is not the only service the business provides, or is only provided once. It also considers that a service provided by a business for a fee or for free to otherwise further that business is provided in the course of a business.
Read more: AUSTRAC: Professional designated services AML scope for accounting firms
Yes. AUSTRAC says a reporting entity can be an individual, including a sole trader, as well as a company, trust, partnership or other legal entity. What matters is whether you provide designated services.
Read more: AUSTRAC: Who and what we regulate AML scope for accounting firms
In AUSTRAC’s conveyancing example, an accounting firm giving financial advice on the implications of pulling out of settlement may influence whether the transaction proceeds but does not directly advance it, so it is not regulated under item 1 of table 6.
Read more: AUSTRAC: Professional designated services AML scope for accounting firms
AUSTRAC says an accounting or legal firm that supports an insolvency practitioner, for example with staff, systems or administrative support, does not provide a designated service just because of that support. The firm is only a reporting entity if it provides a designated service in its own capacity, and it may also be one if it is the lead entity of a reporting group.
Read more: AUSTRAC: How designated services apply to insolvency practitioners AML scope for accounting firms
Enrolling with AUSTRAC
When and how to enrol, and keeping your details current.
You must apply to enrol no later than 28 days after the day you start providing a designated service. Once enrolled, your business is on AUSTRAC’s Reporting Entities Roll.
Read more: AUSTRAC: Enrol with us overview
You need a user account in AUSTRAC Online. After creating it, log in and complete the enrol a new business form, which you can save and return to for up to 14 days; on submission you get a receipt number and your AUSTRAC Account Number (AAN).
Read more: AUSTRAC: Enrol with us overview
AUSTRAC lists the designated services you provide, business identifiers such as ABN and ACN, your business structure and details of key people such as directors, trustees or partners, beneficial owners, contact details, operational details such as employee numbers, turnover and small business entity status, your AML/CTF officer’s details, and earnings information used for the industry levy.
Generally no. AUSTRAC says registration typically only applies to money remitters and specialised virtual asset service providers, that accountants generally won’t need to register, and that sending or receiving money or virtual assets incidentally to your other services generally does not require registration.
Read more: AUSTRAC: Enrol with us overview
You must keep your enrolment details up to date. If details about your business or designated services change, you must update them within 14 days of the change occurring.
Read more: AUSTRAC: Enrol with us overview
AUSTRAC announced on 28 August 2026 that it had begun issuing section 167 notices to businesses, including accountants, that appear to be providing designated services but have not enrolled. The notices require them to provide information to help AUSTRAC determine whether they provide regulated services and are meeting their obligations.
Read more: AUSTRAC: AUSTRAC issues notices to non-enrolled businesses
Yes. AUSTRAC’s May 2026 statement of expectations says it will take early enforcement action against businesses who fail to enrol, and against regulated businesses it suspects have been complicit in money laundering.
Read more: AUSTRAC: Update to regulator statement of expectations: May 2026
Existing clients
Clients you already acted for on 1 July 2026.
Mostly, no. Clients you were providing a designated service to on 1 July 2026, or had an ongoing business relationship with that involved designated services before then, are pre-commencement customers. You can keep acting for them without initial CDD unless a suspicious matter report obligation arises, or a significant change in the nature and purpose of the relationship makes the client medium or high risk. AUSTRAC’s example is a client asking for a new service in a way that’s different from your existing relationship.
Ongoing CDD still applies: watching for unusual activity and keeping their details current.
Read more: AUSTRAC: transitioning existing customers The 7 AML questions firms are asking
Not necessarily. AUSTRAC looks at how long and how recently you’ve provided designated services, and whether there’s a pattern of ongoing services or an expectation of more. A client you set up a company for years ago, with no ongoing relationship since, may not qualify, so initial CDD would apply before any new designated service.
Read more: AUSTRAC: transitioning existing customers
It depends on the structure. A company, trust or partnership: yes. A sole trader: no, not on its own.
Creating a company, trust or partnership is a designated service: AUSTRAC’s definition of a legal arrangement includes partnerships as well as express trusts. Setting up as a sole trader doesn’t create any of those.
If the new work is a designated service and the client has only ever had tax advice from you, they aren’t a pre-commencement customer, because personal tax advice isn’t a designated service. Complete initial CDD before you start. AUSTRAC’s May 2026 webinar uses this example (tax advice since 2021, then help to set up a new business in August 2026).
Read more: AUSTRAC: Initial and Simplified Customer Due Diligence (CDD Essentials webinar) The 7 AML questions firms are asking AUSTRAC: professional designated services
These rules apply to pre-commencement customers: clients you were providing a designated service to on 1 July 2026, or had a business relationship with that involved a designated service provided before then. Clients who only ever received services that are not designated services are not pre-commencement customers. For pre-commencement customers you must monitor for unusual transactions and behaviours that may give rise to an SMR, review, update and reverify their KYC information at an appropriate frequency (including if you doubt its adequacy or veracity), and monitor for significant changes in the relationship that make their ML/TF risk medium or high.
Read more: AUSTRAC: Transitioning existing customers The 7 AML questions firms are asking
Yes. AUSTRAC’s webinar says your AML/CTF program must explain how you assess these customers and record those decisions, and if you decide not to complete initial CDD on a pre-commencement customer, you should document the reasons in a way that reflects your risk-based assessment.
Read more: AUSTRAC: Initial and Simplified Customer Due Diligence (CDD Essentials webinar) The 7 AML questions firms are asking
Not if you took over all or part of another reporting entity’s business and received copies of its transaction records and its initial and ongoing CDD records for the client. If you don’t receive those records, you must complete initial CDD before providing the client with a designated service. You must still conduct ongoing CDD, and complete initial CDD if a possible SMR matter or a significant change raising their risk to medium or high arises.
Read more: AUSTRAC: Transitioning existing customers The 7 AML questions firms are asking
Onboarding: CDD and ID
What you need to establish before you start the work.
An ID check covers one part of it. Initial CDD also means establishing who the beneficial owners are, whether anyone involved is a politically exposed person or sanctioned, and the nature and purpose of the relationship, on reasonable grounds and verified to a level that suits the client’s risk. If you can’t establish those matters, AUSTRAC says you must not provide the designated service.
Read more: AUSTRAC: overview of initial CDD Customer due diligence for accounting firms
Before. AUSTRAC expects you to establish the client’s identity and their ML/TF risk before you start providing the designated service. There are limited exceptions that allow delaying parts of it, and they come with conditions.
Read more: AUSTRAC: overview of initial CDD AUSTRAC: delayed initial CDD
It’s an objective test: would a reasonable person in your position be satisfied with what you had? Your customer risk assessment is where you record that reasoning, so a check result on its own isn’t the whole answer.
Read more: AUSTRAC: overview of initial CDD
Australian ID isn’t required. AUSTRAC lists a passport or a foreign national identity card as acceptable government-issued photo ID, alongside a driver’s licence. Alternative identification procedures are for someone who can’t obtain or access standard ID because of circumstances beyond their control. Living overseas isn’t one of those on its own, and your AML/CTF program needs to cover when and how you use them.
Read more: AUSTRAC: initial CDD for individuals AUSTRAC: individuals without standard ID
In some cases, yes. If the other firm is also a reporting entity, or an equivalently regulated firm overseas, you can rely on the identity and KYC information it collected and verified. An ongoing CDD arrangement must be in writing, approved by a senior manager and reassessed at least every two years. Case by case reliance is also possible. Either way, keep a record showing why relying on them was appropriate, and the client’s risk rating for your service is still your firm’s call.
Read more: AUSTRAC: reliance on a third party AUSTRAC: CDD arrangements
You must establish on reasonable grounds the client’s identity; anyone the client is receiving the service on behalf of; anyone acting for the client and their authority to act; any beneficial owners if the client isn’t an individual; whether any of these people is a PEP or designated for targeted financial sanctions; and the nature and purpose of the relationship or transaction. Source of funds and source of wealth are also required for foreign PEPs and high-risk domestic or international organisation PEPs, and under enhanced CDD where relevant to the client’s risk.
Read more: AUSTRAC: Overview of initial customer due diligence
Not necessarily. AUSTRAC says you may not need to verify every piece of KYC information, but it expects you to verify at least one piece for each matter you must establish (unless a Rules exception applies), and to verify more in high-risk situations, for persons associated with high-risk clients and for unusual requests.
Read more: AUSTRAC: Overview of initial customer due diligence
Yes. You can use third-party digital identity services to verify KYC information if the data they return is reliable and independent. AUSTRAC expects you to consider whether the data is independent and reliable, who maintains it (such as a government body), whether the system is secure and kept up to date, and any other relevant factors.
Read more: AUSTRAC: Overview of initial customer due diligence
AUSTRAC suggests collecting enough to distinguish the client from others with similar details (such as full name, other names, date of birth, residential address and any unique identifier) and verifying full name and date of birth. You could use a government-issued primary photographic ID, or a primary non-photographic document such as a birth certificate together with a secondary document showing name and address, such as a utility bill or government notice.
Read more: AUSTRAC: Initial CDD for individuals
No. AUSTRAC says you could match the client’s appearance to their photo ID in person or online, for example in person, on a live video call, or using biometric technology from an ID verification provider. If you verified identity with non-photographic ID, you could confirm the person is who they claim to be with a reference from an independent and reliable source.
Read more: AUSTRAC: Initial CDD for individuals
You must establish the identity of both the individual and their business. Where the service relates to the business, you must collect at least the individual’s full name, any business name, other names, a unique identifier for the business (typically the ABN) and the principal place of business address. AUSTRAC suggests the business name and ABN could be verified using the Australian Business Register, and if there is no separate business name and no ABN, no further verification may be needed unless the risk warrants it.
Read more: AUSTRAC: Initial CDD for sole traders
Yes. A rural bakery owner asks an accountant to help move to a company structure, then reveals they want the company to send high-value payments to high-risk overseas jurisdictions unrelated to the bakery and to appoint unidentified third parties as directors. Because this doesn’t align with the stated nature and purpose, the accountant rates the client high risk and applies enhanced CDD, including checks on source of funds and source of wealth.
Read more: AUSTRAC: Initial CDD for sole traders
You must at least collect the company’s full name, any business names and other names, its unique identifier (generally the ABN or ACN), its principal place of business, any separate registered office, evidence of its existence, the powers that bind and govern it, and the names of the individuals responsible for governance and executive decisions, such as the directors. For bodies corporate you must also collect any director identification number where applicable. AUSTRAC suggests verifying an Australian company’s name and ACN using ASIC registers or a certificate of registration.
Read more: AUSTRAC: Initial CDD for body corporate, partnership or unincorporated association
For a trust you must establish the trust’s identity (including its name, kind of trust, any ABN, address, evidence of existence such as the trust deed, and governing powers), its beneficiaries or, if they can’t be individually identified, each class of beneficiaries, the trustees and other representatives and their authority, its beneficial owners (including settlors, appointors, guardians and protectors), PEP and sanctions status, and the nature and purpose of the relationship.
Read more: AUSTRAC: Initial CDD for trust
AUSTRAC suggests verifying trust details (other than the principal place of business) with the trust deed and any amendments, plus ABN information where relevant. Alternatively, letters or documents from the trust’s professional services firm can be used, provided they come from someone who doesn’t play a role in the trust, such as an independent lawyer or accountant rather than the trustee.
Read more: AUSTRAC: Initial CDD for trust
Not always. AUSTRAC says these matters are taken to be established without verification if you identified the trust’s ML/TF risk before starting the service, the risk is low and enhanced CDD doesn’t apply, you collected KYC information about the matter appropriate to the risk, and there are no reasonable grounds to doubt that information. You still have to collect the information.
Read more: AUSTRAC: Initial CDD for trust
You can apply simplified CDD if the client’s ML/TF risk is low, you aren’t required to conduct enhanced CDD, and your AML/CTF policies deal with how you’ll apply simplified measures. It isn’t an exemption: you must still collect all the required KYC information, and collect or verify enough to identify the client’s risk and establish the matters on reasonable grounds.
Read more: AUSTRAC: Overview of initial customer due diligence
In AUSTRAC’s webinar example, an Australian resident teacher who attends in person for help setting up a simple family trust for his child, with no links to high-risk countries and no suspicious funds, may qualify for simplified CDD, provided your risk assessment supports this approach.
Read more: AUSTRAC: Initial and Simplified Customer Due Diligence (CDD Essentials webinar)
Only in limited circumstances. Before you start, you must determine on reasonable grounds that delaying initial CDD is essential to avoid interrupting the ordinary course of business and that there is a low additional ML/TF risk in delaying, and you must have AML/CTF policies to complete CDD and manage the associated risks. AUSTRAC says it isn’t a sufficient reason that doing CDD first would be inconvenient for you or the client.
For services provided at or through a permanent establishment in Australia, you can start after collecting, but before verifying, KYC information about beneficial owners, persons the client receives the service on behalf of, PEP and sanctions status, and (where enhanced CDD applies) nature and purpose. You must complete initial CDD as soon as reasonably practicable and no later than 20 business days after starting, and before you transfer or otherwise make available money, property or virtual assets for the client.
You can use alternative identification options for individuals who can’t obtain or access standard ID because of circumstances beyond their control, or whose ID details are inconsistent. Options may include a referee statement, government correspondence, recently expired ID or, as a last resort, self-attestation. You must identify and manage the ML/TF risk of accepting alternative ID, and keep records of what you did and the alternative ID used.
Read more: AUSTRAC: Identifying individuals who don’t have standard ID
You must review, and where appropriate update and reverify, a client’s KYC information at a frequency appropriate to their ML/TF risk, and your AML/CTF policies must set out how often you’ll do this for different kinds of clients. You must also review it if you doubt the information is adequate or true, or if the client or a related person becomes a foreign PEP, or a high-risk domestic or international organisation PEP.
Read more: AUSTRAC: Reviewing and updating customers’ ML/TF risk and KYC information
You must review, and where appropriate update, a client’s ML/TF risk if there’s a change to your business risk assessment, the type of customer (such as becoming a PEP or changing corporate structure or beneficial owners), the services you provide or are asked to provide, the delivery channels, or the countries involved. You must also do so if the client is involved in unusual transactions or behaviour that may give rise to an SMR obligation.
Read more: AUSTRAC: Reviewing and updating customers’ ML/TF risk and KYC information
Yes. If the client is low risk, enhanced CDD isn’t required and your AML/CTF policies deal with simplified CDD, you may apply simplified ongoing measures. You must still meet your ongoing CDD obligations, but may be satisfied you can do so through less intensive monitoring or by updating and reverifying KYC information less frequently.
Read more: AUSTRAC: Overview of ongoing customer due diligence
Monitoring can be manual, automated or both, depending on the nature, size and complexity of your business. AUSTRAC expects an automated system if you can’t monitor effectively manually, for example with a high volume of transactions. Manual monitoring could include training staff, scheduling regular reviews such as weekly or monthly, comparing activity with the client’s history and similar clients, and escalating unusual activity.
Read more: AUSTRAC: How to monitor your customers
AUSTRAC’s examples of unusual transactions include transactions through a service provider such as lawyers or accountants for no apparent commercial or other reason, using legal entity structures to obscure ownership, using trusts as a vehicle to move funds, and registering companies or businesses with no apparent commercial activity. Unusual behaviour includes being evasive, giving coached answers, appearing directed by a third party and frequently changing KYC information.
Read more: AUSTRAC: What you must monitor for
Unusual doesn’t always mean illegal. AUSTRAC expects you to consider whether there’s a legitimate explanation, based on what you know about the client, the relationship and their source of funds or wealth, and then decide next steps. These may include updating KYC information or the risk rating, applying enhanced CDD, escalating, submitting an SMR, or limiting or stopping services. Keep a record of the alert, how you reviewed it and how you responded.
Read more: AUSTRAC: Responding to unusual transactions and behaviour
No. AUSTRAC says you don’t need to collect and reverify an individual client’s identity information just because the verification data, such as an identity document, has expired, as this doesn’t change the client’s identity or their ML/TF risk.
Read more: AUSTRAC: Reviewing and updating customers’ ML/TF risk and KYC information
AUSTRAC’s public guidance says digital driver’s licences are an acceptable form of identification, and that in some circumstances one photo ID showing full name, residential address and date of birth will be enough. The business decides what identification it will accept.
Read more: AUSTRAC: Why you might be asked for ID
You must apply enhanced CDD when the customer’s ML/TF risk is high; when you must submit an SMR and intend to keep providing the service; for unusually complex or large transactions, transactions with no apparent economic or legal purpose, or an unusual pattern of transactions; for nested services relationships; when the customer, a beneficial owner, a person acting for them or a person they receive the service for is a foreign PEP; and when any of those is physically present in, or formed in, a high-risk jurisdiction for which FATF has called for enhanced CDD.
Read more: AUSTRAC: Enhanced customer due diligence
In AUSTRAC’s webinar example, an accounting practice onboarding a client finds several layers of companies and trusts, with a purpose that isn’t clear and a structure more complex than the services require. This suggests the client may be high risk, so the practice applies enhanced CDD as part of initial CDD to understand the structure, reassess the risk and apply the controls needed.
Read more: AUSTRAC: Enhanced Customer Due Diligence (CDD Essentials webinar)
Yes. AUSTRAC says you can still provide designated services to customers requiring enhanced CDD, but you must have AML/CTF policies that appropriately manage and mitigate the risk. It expects enhanced CDD to include active steps to manage the risk, not just more monitoring, which may include choosing not to provide a service that falls outside your risk appetite.
Read more: AUSTRAC: Enhanced customer due diligence
Source of funds is how and where the funds for a specific transaction were obtained, such as salary, business income, investment income, sale proceeds, gifts or inheritance. It is not the account the money was transferred from. Source of wealth is where the customer’s entire wealth and assets come from.
In initial CDD you must establish both on reasonable grounds for a foreign PEP and for a high ML/TF risk domestic or international organisation PEP, and for a customer where it is relevant to the nature of their high ML/TF risk. Your AML/CTF policies must also set out when you’ll collect, or collect and verify, this information in other situations.
Read more: AUSTRAC: Enhanced customer due diligence
If you can’t establish it when required during initial CDD, you must not provide the designated service. In other cases where you propose to continue, AUSTRAC expects you to consider whether to submit an SMR, document why continuing is appropriate, and manage the risk, for example by raising the risk rating and monitoring more closely.
No. You must verify it as appropriate to the customer’s ML/TF risk, with more detailed verification expected when the risk is high or activity doesn’t fit what you know. If an explanation is consistent with the customer’s risk profile and you have no other concerns, it may be appropriate to simply document the explanation and monitor that future activity is consistent with it.
AUSTRAC’s guidance for the public lists a signed letter from the customer’s accountant confirming their source of funds, or their sources of wealth, as an example of acceptable evidence. Its guidance for businesses also lists written confirmation from a legal practitioner or accountant among documents that could be used.
Read more: AUSTRAC: Proof of source of funds and source of wealth
No. AUSTRAC says it does not expect the same level of controls for all customers irrespective of risk, and expects businesses to meaningfully consider whether simplified due diligence is appropriate rather than taking a one size fits all approach.
Read more: AUSTRAC: Update to regulator statement of expectations: May 2026
The starter kit rates clients low, medium or high. Low risk clients get simplified CDD and a review every 3 years, medium risk clients get initial CDD and a review every 2 years, and high risk clients get enhanced CDD, source of funds and wealth checks, an adverse media check, senior manager approval and an annual review.
Read more: AUSTRAC: Step 2: Use your accounting program
Not automatically. If you established the client’s identity and ML/TF risk on reasonable grounds before the breach, you may decide this hasn’t changed and continue ongoing CDD. You must re-verify if you suspect on reasonable grounds they aren’t who they claim to be, or you doubt the truth or adequacy of the information used to verify them.
Read more: AUSTRAC: Data breaches and AML/CTF considerations
Beneficial owners, PEPs and sanctions
Who sits behind the client, and whether any of them is on a list.
Work through that company to the people who own or control it, and check them as individuals in your risk assessment. They don’t need to become clients of your firm.
Read more: AUSTRAC: determining ownership and control Customer due diligence for accounting firms
A background check using what you know from the ASIC extract (name and address, plus date of birth if they’re also an officeholder) can confirm some details from other sources. Whether that’s enough is a decision for your AML program and whoever signs off the client. AUSTRAC lists refusing to provide information as a risk indicator, and if you can’t establish who the beneficial owners are on reasonable grounds, you can’t provide the service. If the refusal comes with anything unusual, consider whether a suspicious matter report is needed.
Read more: AUSTRAC: overview of initial CDD AUSTRAC: suspicious matter reports
Not necessarily. If one person sits behind three companies, a recent result can be used across all three risk assessments, as long as your AML program allows it and nothing has changed. Sanctions lists are updated often, so how recent is recent enough is a decision your program should set.
Read more: What an AML check looks like for an accounting firm AUSTRAC: politically exposed persons
AUSTRAC requires senior manager approval where the client, a beneficial owner or a beneficiary is a foreign PEP, or a domestic or international organisation PEP and the client is high risk. Source of funds and source of wealth also have to be established in those cases.
Read more: AUSTRAC: politically exposed persons
A beneficial owner is an individual who directly or indirectly owns 25% or more of the customer, or who controls the customer. Ownership can be direct, such as through shareholding, or indirect, such as through another company or an intermediary. Control can come from practical influence and patterns of behaviour, and you don’t need to own a person to control it.
Read more: AUSTRAC: Determining ownership and control structures Our CDD guide: beneficial ownership
Yes. There may be a chain of owners, and you must follow it until you can determine the individual or individuals who are the beneficial owners. AUSTRAC says ASIC registers and extracts, constitutions, trust deeds and partnership agreements can help, and you may also choose third party services that provide beneficial ownership information at a cost.
Read more: AUSTRAC: Determining ownership and control structures Our CDD guide: beneficial ownership
You’re taken to have established this matter on reasonable grounds if you’ve taken all reasonable steps to identify them, recorded the steps taken and any difficulties, collected information about the identity of the chief executive officer (or equivalent), and verified information as appropriate to the customer’s ML/TF risk.
Read more: AUSTRAC: Initial CDD for body corporate, partnership or unincorporated association Our CDD guide: beneficial ownership
AUSTRAC says the beneficial owners of a trust may include trustees (or the individual beneficial owners of corporate trustees), settlors, appointors, guardians, protectors, and any individual with control over the trust, typically including beneficiaries in a bare trust. You must also collect information about the trust’s control structure and the identity of any settlor, appointor, guardian or protector.
Read more: AUSTRAC: Initial CDD for trust Our CDD guide: beneficial ownership
You must collect information about the identity of each beneficiary. If you can’t identify each beneficiary because of the nature of the trust, for example an extremely high number of beneficiaries or no named beneficiaries, you must instead collect a description of each class of beneficiary. You could verify a class of beneficiaries using the trust deed or evidence of trust activity such as disbursements.
Read more: AUSTRAC: Initial CDD for trust Our CDD guide: beneficial ownership
PEPs are individuals entrusted with significant public responsibilities and power, and individuals with a particular connection to them. There are 3 types: foreign PEPs, domestic PEPs and international organisation PEPs. AUSTRAC notes this doesn’t mean PEPs are automatically involved in unlawful activity, and each customer’s risk must be assessed case by case.
Read more: AUSTRAC: Politically exposed persons (PEP) Our CDD guide: beneficial ownership
Domestic PEPs include members of Commonwealth, state or territory parliaments, members of the governing body of a political party represented in those parliaments, the Governor-General, state Governors, senior judges, heads of state or territory departments or agencies with a prominent public function, the head of a local government council, and senior defence officers, among other listed offices. It also includes certain Commonwealth offices overseas appointed by the Governor-General, such as Ambassador and High Commissioner.
Read more: AUSTRAC: Politically exposed persons (PEP) Our CDD guide: beneficial ownership
A foreign PEP holds a prominent office, position or public function in or for the legislature, executive or judiciary of a foreign country. Examples listed include heads of state or government, ministers, members of a legislature, senior judges, ambassadors, high ranking military officers, heads or board members of government bodies or state owned companies or banks, and members of a governing body of a political party represented in a legislature.
Read more: AUSTRAC: Politically exposed persons (PEP) Our CDD guide: beneficial ownership
Yes. Each PEP category also includes a family member of the office holder, and an individual known (based on public or readily available information) to have joint beneficial ownership of a body corporate or legal arrangement with them, sole beneficial ownership of one on their behalf or for their benefit, or any other close business relations with them.
Read more: AUSTRAC: Politically exposed persons (PEP) Our CDD guide: beneficial ownership
Before you provide a designated service, you must establish on reasonable grounds whether your customer, anyone acting on their behalf, any beneficial owner, and any person on whose behalf the customer is receiving the service is a PEP. How you do this can depend on the size, nature and complexity of your business, for example asking during onboarding, checking online, or using third party databases. You must also take reasonable steps to monitor whether any of them becomes a PEP during the relationship.
Read more: AUSTRAC: Politically exposed persons (PEP) Our CDD guide: beneficial ownership
Not necessarily. In AUSTRAC’s example, an accounting firm finds a low risk client has been elected mayor, making them a domestic PEP, and reassesses them as medium risk under the firm’s AML/CTF policies. The firm does source of funds and source of wealth checks under its own policy and, in line with its policies, does not need senior manager approval to continue.
Read more: AUSTRAC: Domestic PEP examples Our CDD guide: beneficial ownership
Yes. Before providing a designated service you must establish on reasonable grounds whether your customer, any beneficial owner (except in limited circumstances), anyone acting for them and anyone they receive the service for is designated for targeted financial sanctions, and check whether any become designated during the relationship. You can search DFAT’s Consolidated List; sanctions change often, so check the most recent list and consider alternative spellings or fuzzy searching.
Read more: AUSTRAC: Persons designated for targeted financial sanctions (TFS) Our CDD guide: beneficial ownership
An international organisation PEP is an individual entrusted with a prominent public function, position or office of a public international organisation, including a head, deputy head or board member, for example of a United Nations body. Their family members and known close business associates are also international organisation PEPs.
Read more: AUSTRAC: Politically exposed persons (PEP) Our CDD guide: beneficial ownership
Yes. When a person leaves their position they’re no longer a PEP, but their former position can still affect their ML/TF risk, and you must apply enhanced CDD if the customer’s risk is high. AUSTRAC also says your AML/CTF policies must ensure senior manager approval is received to provide a service or continue a relationship if the customer, a beneficial owner or a person the customer receives the service for was previously a PEP.
Read more: AUSTRAC: Politically exposed persons (PEP) Our CDD guide: beneficial ownership
Customer risk assessments
Rating the client and recording why.
When you provide a designated service, and before you start providing it. It’s separate from your firm’s own ML/TF risk assessment, which is part of your AML/CTF program.
Read more: AUSTRAC: overview of initial CDD AUSTRAC: professional designated services
Your admin team can prepare most of them. Medium and high ratings should go to a partner or your AML/CTF compliance officer to sign off and decide whether to keep acting, and for some PEP cases AUSTRAC requires senior manager approval. Complex groups, with entities owning entities, are where someone senior usually needs to step in.
Read more: AUSTRAC: politically exposed persons AML risk assessment for accounting firms
AUSTRAC’s quick guide for accountants says you must consider four risk categories: the services you provide, the customers you deal with, the channels you use to deliver services and the countries you deal with. You must also consider information AUSTRAC communicates about ML/TF risks, such as its risk products, national risk assessments, sector guidance and any direct feedback.
Read more: AUSTRAC: ML/TF risk assessment framework: Quick guide for accountants (January 2026)
AUSTRAC says you must conduct your risk assessment before you provide a designated service, or before you plan to provide a new designated service, because it identifies your ML/TF risks and informs the controls you need.
Read more: AUSTRAC: Conducting your risk assessment (webinar)
AUSTRAC’s examples include significant changes within your control (new designated services, new customer types, a new delivery channel or a new country), changes outside your control (such as changes to AML/CTF legislation or Rules, or to a country’s ML/TF risk), relevant AUSTRAC communications, and an independent evaluation with adverse findings about your risk assessment. For a significant change within your control, the review and update must take place before the change occurs.
Read more: AUSTRAC: Conducting your risk assessment (webinar)
AUSTRAC says the approach should suit the size and complexity of your business. A small, low complexity business could assess inherent risk by focusing only on the potential impact if a vulnerability were exploited, while a medium complexity business could consider both likelihood and impact using a risk matrix.
Read more: AUSTRAC: ML/TF risk assessment framework: Quick guide for accountants (January 2026)
The accountants’ quick guide gives examples: high net worth individuals using complex business and financial arrangements, including offshore accounts or trusts; clients connected to high-risk jurisdictions; clients with unexplained sources of wealth; and clients who regularly change company ownership or structures without a clear reason.
Read more: AUSTRAC: ML/TF risk assessment framework: Quick guide for accountants (January 2026)
List all the countries your business deals with when providing designated services, including where individual clients live and where corporate clients or legal arrangements are registered or formed, then rate each one. AUSTRAC expects a high-risk rating for any country on the FATF grey or black list or subject to Australian sanctions.
Read more: AUSTRAC: ML/TF risk assessment framework: Quick guide for accountants (January 2026)
Your risk assessment must assess proliferation financing risk. You don’t need separate proliferation financing policies if you’ve reasonably assessed that this risk is low and that your policies appropriately manage it. AUSTRAC says you are less likely to face this risk if you only operate in Australia, don’t serve customers connected to high-risk jurisdictions, don’t move money or sensitive or dual-use goods or technologies, and don’t offer a service relevant to proliferation financing.
A client risk rating is different from your business-wide risk assessment, but you must use the information and factors in your risk assessment (kind of customer, services, delivery channels and countries) and consider how they apply to each client. AUSTRAC expects you to rate each risk factor and include a method in your AML/CTF policies that staff can use to check which factors are present, balance them into an overall rating and consider any indicators of unusual or criminal activity. It suggests the impact ratings from your risk assessment may be a good starting point.
Read more: AUSTRAC: Assigning customer risk ratings
AUSTRAC’s examples: a low-risk client is an Australian resident seeking a low-risk service involving only low-risk jurisdictions, with no red flags or enhanced CDD triggers. Medium risk might involve a medium-risk service, a multi-layered (but not unduly complex) control structure, links to medium-risk jurisdictions or a low-profile domestic PEP. High risk includes an unusually complex control structure, a foreign PEP, ties to high-risk jurisdictions, or a service with no clear economic or lawful purpose. AUSTRAC says these are examples and you should adopt an approach appropriate to your business.
Read more: AUSTRAC: Assigning customer risk ratings
AUSTRAC’s money laundering national risk assessment found services provided by accountants pose a high money laundering risk in Australia. Criminals can exploit professional services and use an accountant’s expertise to give an impression of respectability and legitimacy, and you may not be aware you are helping them.
Read more: AUSTRAC: Risk insights and indicators of suspicious activity for accountants
AUSTRAC lists services including financial and tax advice, bookkeeping, creating corporations or complex legal arrangements, requests for nominee shareholders, trustees or directors, buying or selling properties or businesses, managing funds or assets, providing a registered address, and introductions to banks.
Read more: AUSTRAC: Risk insights and indicators of suspicious activity for accountants
AUSTRAC says countries may be high risk if FATF deems them high risk or non-cooperative, they are prescribed foreign countries (currently Iran and North Korea), they are subject to sanctions, they are known tax havens, or they are known to support terrorist organisations. Enhanced CDD is mandatory if the customer, a beneficial owner, a person the customer receives the service for, or a person acting for them is physically present in, or formed in, a high-risk jurisdiction for which FATF has called for enhanced CDD.
Your AML/CTF program
The documents and roles behind the day to day work.
With AUSTRAC’s accountant program starter kit. It’s free and designed for practices of 15 or fewer people that only provide professional designated services. If your firm is larger or more complex, AUSTRAC says you can’t rely on it as it stands, though you can adapt parts of it.
Read more: AUSTRAC: accountant program starter kit Our post on the starter kit
AUSTRAC expects you to have considered whether your business aligns with the characteristics the kit describes. If it does and you prepare your program using the kit, AUSTRAC says its regulatory engagement will focus on how you apply your program, and its position is that the kit’s risk assessment, policies and procedures are appropriate to manage the common risks those businesses face.
Read more: AUSTRAC: Update to regulator statement of expectations: May 2026
AUSTRAC expects you to turn your own mind to the question and develop your own position, which may involve external advice, and to document that position, why it is reasonable and any advice that informed it. If AUSTRAC interprets the law differently, it says it will engage in conversation, not enforcement, in the first instance.
Read more: AUSTRAC: Update to regulator statement of expectations: May 2026
For newly regulated businesses, the transitional rules set the deadline by the last two digits of your AUSTRAC account number (AAN): 30 June 2029 if both are odd, 31 December 2029 if the second last is odd and the last is even, 30 June 2030 if both are even, and 31 December 2030 if the second last is even and the last is odd. You should update your program so your evaluation schedule aligns with that deadline.
Read more: AUSTRAC: AML/CTF transitional rules 2026
You must assess whether the starter kit is appropriate for your practice and identify any changes you need to make. AUSTRAC says you cannot rely on the kit to meet its expectations of an appropriate program, although you can consider adapting parts of it when developing your own program.
Read more: AUSTRAC: Accounting program starter kit: Getting started
You customise the risk assessment, policy document and process document so they reflect your practice model, services, clients and risks. Once customised and approved, those documents become your AML/CTF program.
Read more: AUSTRAC: Step 1: Customise your accounting program using the starter kit
AUSTRAC says this will usually be your AML/CTF compliance officer, who oversees day-to-day compliance, and for accounting practices that will typically be the office manager.
Read more: AUSTRAC: Accounting program starter kit: Getting started
Your senior manager approves the program. For a typical accounting practice, AUSTRAC says this could be a senior member of the leadership team or the practice owner.
Read more: AUSTRAC: Step 1: Customise your accounting program using the starter kit
Yes. The process document notes where you may use automated systems or tools instead of manual processes, but any automated system you choose must meet or exceed those processes.
Read more: AUSTRAC: Step 1: Customise your accounting program using the starter kit
You can keep your own forms or systems and build the required information into them instead. Where you do, the Customise guide says to update your policy and process documents to describe the systems you use and how you use them.
Read more: AUSTRAC: Accountants – Customise guide (Customise the program starter kit guide)
AUSTRAC updates the kit when new risks are identified, risks or obligations change, or small practices change how they operate. If you built your program from the kit, you must review the updates and decide whether to incorporate them.
Read more: AUSTRAC: Step 3: Maintain and review your accounting program
At least once every 3 years, and also when certain triggers occur, such as a significant change to your services, delivery channels, customer types, countries or technologies, information AUSTRAC communicates, or adverse independent evaluation findings.
Read more: AUSTRAC: Step 4: Review and update your AML/CTF program
Moving from in-person to online delivery is a significant change within your control, so you must review and, if needed, update your risk assessment before the change occurs. You must then review your AML/CTF policies in light of that review, and document the updates in your program within 14 days after making them.
Read more: AUSTRAC: Step 4: Review and update your AML/CTF program
Your program, including your risk assessment and AML/CTF policies, must be documented before you start providing a designated service and approved by a senior manager. Updates must be documented within 14 days after they occur, and certain updates also need senior manager approval: risk assessment updates about new or significantly changed risks, and material changes to your policies. AUSTRAC says routine administrative changes, such as a software update, don’t need that approval.
Read more: AUSTRAC: Step 3: Manage and mitigate your risks: AML/CTF policies
Your policies must set a frequency that suits the nature, size and complexity of your business, and at a minimum an evaluation must occur at least once every 3 years. Transitional rules provide staggered deadlines for the first evaluation, and AUSTRAC suggests newly enrolled entities may wish to consider doing it earlier.
Read more: AUSTRAC: Step 5: Conduct an independent evaluation
AUSTRAC expects the evaluator not to be involved in developing, implementing or maintaining the program, and to be independent of the areas they evaluate, so not your compliance officer or compliance team. The evaluator can be internal or external if sufficiently independent.
Read more: AUSTRAC: Step 5: Conduct an independent evaluation
AUSTRAC expects you to avoid using template or global programs without amending them, because they are generally not tailored to your business and its risks. Adopting one could lead to serious and systemic compliance failures.
Read more: AUSTRAC: Using outsourcing to help meet your obligations
AUSTRAC says enrolment is only the beginning: build an AML/CTF program that reflects how your business operates, understand your risks through a risk assessment, use AUSTRAC guidance or a starter kit, train staff, and review the program as the business changes.
Read more: AUSTRAC: You’ve enrolled. What next?
Yes. The accounting starter kit says accountants must have an AML/CTF program in place before they provide certain professional services, known as designated services, to a client.
Read more: AUSTRAC: Accounting program starter kit: Getting started
It includes a risk assessment covering common risks for the profession, policies setting out what you must do and when, processes for day to day AML/CTF tasks, and forms to record information. Once customised, these documents work together as your AML/CTF program.
Read more: AUSTRAC: Accounting program starter kit: Getting started
One of the characteristics the starter kit was designed around is that the practice does not offer fully remote self-service options that let clients obtain designated services without interacting with its personnel. A practice that does not meet all the characteristics must assess whether the kit is appropriate and identify the changes it needs.
Read more: AUSTRAC: Accounting program starter kit: Getting started
No. The kit is designed for accounting practices, and AUSTRAC says being an accounting practice could be evidenced by membership of one of those bodies but does not necessarily require it.
Read more: AUSTRAC: Accounting program starter kit: Getting started
Compliance officer and staff
Who does what, and the checks and training your people need.
Not on their own. AUSTRAC says reporting entities must provide training for personnel who perform or will perform AML/CTF roles, and participating in AUSTRAC’s education activities alone does not meet the personnel training requirement. AUSTRAC provides its education activities free of charge and issues certificates of completion, but you and your CPD issuer decide whether they count for CPD. AUSTRAC’s e-learning can be part of your training, but training must be tailored to each person’s AML/CTF functions, the risks of those functions and their responsibilities under your policies.
Read more: AUSTRAC: Continuing professional development
Under the starter kit, you don’t need to complete the collect and verify information step when assessing yourself if you are a single employee practice, or both the compliance officer and governing body. You complete a different form to assess your own suitability.
Read more: AUSTRAC: Accountants – Customise guide (Customise the program starter kit guide)
If the person is a member of a professional accounting body and you have no reasonable doubts about their integrity or identity, the starter kit says you only need to collect and verify their membership. The compliance officer role also needs a national criminal history check.
Read more: AUSTRAC: Accountants – Customise guide (Customise the program starter kit guide)
Yes. When collecting and verifying information about personnel, the Customise guide says you must also carry out a national criminal history check on the person in the compliance officer role.
Read more: AUSTRAC: Accountants – Customise guide (Customise the program starter kit guide)
Yes. For sole traders or micro businesses one person often acts in all 3 roles. They don’t need to report to themselves, but they remain responsible for the other duties of each role.
Read more: AUSTRAC: Governance and oversight for sole traders and micro businesses
The requirement to give regular updates to the governing body does not need to be met if your business is an individual or you hold both the governing body and compliance officer roles. Otherwise, AUSTRAC suggests setting aside time to review and reflect on AML/CTF issues and keeping notes.
Read more: AUSTRAC: Governance and oversight for sole traders and micro businesses
You can outsource governance roles, though it isn’t required. If you do, you remain responsible for making sure the provider meets the requirements of the role, including the compliance officer eligibility requirements.
Read more: AUSTRAC: Governance and oversight for sole traders and micro businesses
They must be employed or engaged at management level, be a fit and proper person, and be a resident of Australia if you provide designated services at or through a permanent establishment in Australia. In a smaller business this may be the owner, a director or the person managing broader risks or operations.
Read more: AUSTRAC: AML/CTF compliance officer
No. For a small business AUSTRAC says you appoint someone at management level with the required competence and judgement, who has the general skills to learn the business’s ML/TF risks and will learn further skills through training and on the job.
Read more: AUSTRAC: AML/CTF compliance officer
You must appoint a compliance officer within 28 days of providing designated services and notify AUSTRAC within 14 days of the appointment through the enrolment form on AUSTRAC Online. The same applies if the compliance officer leaves or becomes ineligible.
Read more: AUSTRAC: AML/CTF compliance officer
A senior manager is an individual who makes, or is involved in making, decisions affecting all or a substantial part of the business. In a smaller business this could be the owner, a director or the person managing broader risks or operations. Senior managers must meet their obligations personally and can’t delegate them.
Read more: AUSTRAC: Senior manager
At least once every 12 months, covering compliance with your AML/CTF policies and obligations and how ML/TF risk is being managed and mitigated. The governing body must also get written notice of any risk assessment update as soon as practicable.
Read more: AUSTRAC: Governing body
Anyone who performs, or will perform, roles relevant to your AML/CTF obligations. That includes employees and people you otherwise engage, such as contractors, consultants, volunteers, interns and people employed by service providers you use, as well as the governance roles.
Read more: AUSTRAC: Identifying personnel roles that require due diligence and training
Yes. AUSTRAC expects newly regulated entities to conduct due diligence checks on current personnel, which may involve considering checks already done, identifying any additional checks needed and making sure records are sufficient.
Read more: AUSTRAC: Personnel due diligence (PDD)
You must give initial training when a person starts and ongoing training after that. AUSTRAC gives examples only, such as every 6 to 12 months for compliance officers and senior management and every 12 months for customer-facing staff, and says frequency must suit your business.
Read more: AUSTRAC: AML/CTF training
Record keeping
What to keep and for how long.
No. You must keep records showing how you met your initial CDD obligations, including the type and content of the data you collected and your risk decisions, for 7 years after the business relationship ends or after the last occasional transaction. You aren’t required to keep scanned copies or photocopies of the identity documents themselves.
Read more: AUSTRAC: Overview of initial customer due diligence
You must keep AML/CTF program records, customer due diligence (CDD) records and transaction records related to a designated service. They must be reasonably necessary to show you are meeting your CDD and program obligations and sufficient to reconstruct individual transactions.
Read more: AUSTRAC: Record keeping overview
7 years from when the business relationship ends, or from when an occasional transaction is complete. AML/CTF program records are kept until 7 years after the record is no longer relevant to show compliance, and transaction records for 7 years.
Read more: AUSTRAC: Record keeping overview
Yes. AUSTRAC says you can meet your record keeping obligations by making or keeping records yourself or by using an external provider. Records may be hard copy or electronic, at your premises or offsite.
Read more: AUSTRAC: Record keeping overview
AUSTRAC says all reporting entities must comply with the Privacy Act 1988, and even a small business has Privacy Act obligations because it is a reporting entity under the AML/CTF Act.
Read more: AUSTRAC: Record keeping overview
Relying on others, and using software
Other firms’ checks, outsourcing and RegTech.
Yes. A senior manager must approve entering into any written agreement or arrangement with a third party that will collect and verify CDD information for you.
Read more: AUSTRAC: Senior manager
Yes. If you outsource AML/CTF functions you remain responsible for complying with your obligations, and your business will generally remain legally liable for any breach and incur any penalty.
Read more: AUSTRAC: Using outsourcing to help meet your obligations
AUSTRAC’s outsourcing guidance says it does not cover using technology, such as software applications, that helps you meet your obligations in-house, and refers readers to separate guidance on engaging a RegTech. It also excludes using government databases such as the Australian Sanctions Office Consolidated List.
Read more: AUSTRAC: Using outsourcing to help meet your obligations
No. AUSTRAC says it does not endorse solutions or products to help reporting entities meet their obligations, and warns that some providers may claim AUSTRAC endorsement.
Read more: AUSTRAC: Outsourcing (AML/CTF Essentials webinar series)
No. AUSTRAC clarified in its webinar that using services such as Equifax or Dow Jones lists is using a data source, not engaging a person or service to perform an AML/CTF function. It does not trigger personnel due diligence or training requirements and is not considered outsourcing.
Read more: AUSTRAC: Initial and Simplified Customer Due Diligence (CDD Essentials webinar)
You do. AUSTRAC’s webinar says that even when you rely on another entity, you remain responsible for ensuring the third party implements appropriate measures to comply with its AML/CTF obligations, and for making sure any CDD arrangement complies with the Act and Rules. Your initial CDD, including enhanced CDD if required, must still be appropriate to the risks the customer presents to your business.
Read more: AUSTRAC: Initial and Simplified Customer Due Diligence (CDD Essentials webinar)
No. Reliance doesn’t include a KYC or outsourced service provider, because they aren’t subject to oversight and supervision under Australia’s AML/CTF laws. You can outsource functions to third parties that aren’t reporting entities, but you remain liable for any breaches of CDD and record keeping obligations.
Read more: AUSTRAC: Overview of reliance on customer identification by a third party
It must be in writing, such as a contract, MOU or standard operating procedures, and approved by a senior manager. It must set out each party’s responsibilities, including for record keeping, let you obtain all the KYC information before you provide the service (or within the delayed CDD timeframe), and let you get copies of the verification data immediately or as soon as practicable on request; AUSTRAC would not expect delays beyond one business day.
Read more: AUSTRAC: Reliance under customer due diligence arrangements
While an arrangement is in force you must assess it regularly, at least every 2 years or more often as appropriate, and when there’s a significant change in circumstances, and prepare a written record within 10 business days after completing each assessment. If you’re not satisfied it complies with the Rules, you must conduct your own initial CDD, and failure to conduct regular assessments may result in civil penalties.
Read more: AUSTRAC: Reliance under customer due diligence arrangements
Not necessarily. AUSTRAC notes the other firm’s risk assessment and policies may not match yours, and the customer may pose a different level of risk to your business, for example because you provide different services. Initial CDD, including enhanced CDD if required, must be conducted in a manner appropriate to the risks the customer presents to your business, and for case by case reliance you must document why the reliance is appropriate.
Read more: AUSTRAC: Reliance on a case-by-case basis
Reporting to AUSTRAC
Compliance reports, cash reports and what goes in them.
Three main reports, on different timetables: an annual compliance report, suspicious matter reports when they arise, and threshold transaction reports if you handle $10,000 or more in physical cash for a designated service.
Read more: AUSTRAC: compliance reports AUSTRAC: suspicious matter reports
Reporting periods follow the financial year. The next one runs from 1 July 2026 to 30 June 2027, and the report is due by 30 September 2027.
Read more: AUSTRAC: compliance reports
Within 3 business days of forming the suspicion, or within 24 hours if it relates to terrorism financing.
Read more: AUSTRAC: suspicious matter reports Tranche 2 for accountants
No. Telling the client you’ve made one, or are going to, is tipping off, which is an offence. Keep your team’s observations about a client internal.
Read more: AUSTRAC: suspicious matter reports Tranche 2 for accountants
Not because of their takings. A threshold transaction report applies when a designated service you provide involves $10,000 or more in physical cash, and it’s due within 10 business days. A client telling you about cash for their BAS or tax return is different from you handling the cash yourself.
Read more: AUSTRAC: threshold transaction reports The 7 AML questions firms are asking
No. AUSTRAC asks you not to include TFNs in reports, because the AML/CTF Act doesn’t authorise you to disclose TFNs to AUSTRAC.
Read more: AUSTRAC: Suspicious matter reports
AUSTRAC says a strong SMR explains not just what happened but why the activity raised concern and how you formed your suspicion. If you don’t know a detail, don’t guess; provide what you have and leave non-mandatory fields blank.
Read more: AUSTRAC: What a high-quality SMR looks like
No. AUSTRAC says that if you are newly regulated it isn’t expecting perfection; it wants to see that you are using your AML/CTF program.
Read more: AUSTRAC: How to get your reporting right
No. AUSTRAC says electronic transfers, cheques and card payments don’t trigger the TTR requirement, even in larger amounts. TTRs are about physical currency.
Read more: AUSTRAC: How to get your reporting right
Suspicious matters and tipping off
When to report, how fast, and what you can and can’t say.
You must submit an SMR if you suspect on reasonable grounds that information you have may be relevant to crime, that a customer, future customer or their agent isn’t who they claim to be, or that a person is planning an ML/TF offence using a designated service. AUSTRAC says this includes information that concerns money laundering, terrorism financing, offences such as tax evasion, and Commonwealth, state or territory offences.
Read more: AUSTRAC: Suspicious matter reports Tranche 2 for accountants
No. AUSTRAC says you only need to form a suspicion on reasonable grounds, and you don’t need every detail before you submit.
Read more: AUSTRAC: What a high-quality SMR looks like Tranche 2 for accountants
Yes. SMR obligations apply when you start or propose to provide a designated service, or someone asks for one, and they apply even if you don’t end up providing the service. AUSTRAC says this is because criminals may ‘test the market’ to find vulnerabilities.
Read more: AUSTRAC: Suspicious matter reports Tranche 2 for accountants
Yes. You must submit an SMR each time you form a new suspicion on reasonable grounds, even if you have already reported that person. AUSTRAC asks you to include the reference numbers of any previous SMRs on the same customer.
Read more: AUSTRAC: Suspicious matter reports Tranche 2 for accountants
Yes. You don’t have to end the relationship, but you must appropriately mitigate or manage the ML/TF risks, which includes applying enhanced CDD. If you can’t appropriately manage the risk, AUSTRAC expects you to consider whether to keep providing designated services.
Read more: AUSTRAC: Suspicious matter reports Tranche 2 for accountants
No, not once you have formed the suspicion. AUSTRAC says you must not delay submitting your SMR to complete enhanced CDD if you have already formed a suspicion on reasonable grounds.
Read more: AUSTRAC: Suspicious matter reports Tranche 2 for accountants
Tipping off is disclosing certain information to another person where it would or could reasonably be expected to prejudice an investigation, for example information that establishes you submitted an SMR or that a requirement to submit one has been triggered. It is a criminal offence, with a maximum penalty of 2 years’ imprisonment or 120 penalty units, or both.
Read more: AUSTRAC: Tipping off Tranche 2 for accountants
AUSTRAC says you will not generally breach the tipping off offence if you disclose information to appropriately manage ML/TF risks in your business, for example to staff or senior management, a reporting entity in your designated business group or corporate group, or external service providers for this purpose. AUSTRAC suggests controls such as restricting access to those with a genuine need to know.
Read more: AUSTRAC: Tipping off Tranche 2 for accountants
Generally yes. AUSTRAC lists disclosures to meet your AML/CTF obligations or manage ML/TF risks, such as to consultants supporting AML/CTF remediation and uplift or to your lawyer for advice on your AML/CTF obligations, as not likely to be tipping off. It notes the offence doesn’t authorise such disclosures and other laws, such as the Privacy Act 1988, may still apply.
Read more: AUSTRAC: Tipping off Tranche 2 for accountants
Not by itself. Reasonable enquiries are not considered tipping off, and you can tell a client you need further information to comply with your AML/CTF obligations. AUSTRAC suggests giving genuine reasons that don’t indicate you are suspicious, such as needing up to date details or standard processes, and documenting the interaction.
Read more: AUSTRAC: Tipping off Tranche 2 for accountants
Under section 123(4), it isn’t an offence for a qualified accountant, or a business that uses qualified accountants to provide professional accountancy services, to disclose information in good faith to dissuade a client from activities that could be an offence. You should focus on how the activities could break the law and the possible penalties, and must not disclose the existence of an SMR or notice or that you are required to report or have reported.
Read more: AUSTRAC: Tipping off Tranche 2 for accountants
AUSTRAC says disclosures to Australian law enforcement, intelligence or regulatory agencies will not generally breach the tipping off offence. Its list of examples includes the Australian Taxation Office, the National Anti-Corruption Commission, the Australian Border Force and the Australian Criminal Intelligence Commission.
Read more: AUSTRAC: Tipping off Tranche 2 for accountants
Where possible, give genuine reasons that don’t indicate you are suspicious, and don’t disclose protected information. AUSTRAC’s examples include the client’s activities falling outside your risk appetite, the client not responding to requests for further details within a reasonable time, or another commercial basis for ending the relationship.
Read more: AUSTRAC: Tipping off Tranche 2 for accountants
Yes. You must train employees so they understand the tipping off offence. AUSTRAC says you should give regular training to all staff with access to the information and specific training for staff in customer facing roles, and you must have AML/CTF policies to prevent tipping off.
Read more: AUSTRAC: Tipping off Tranche 2 for accountants
AUSTRAC’s red flags for accountants include a client who avoids face to face meetings, is secretive or defensive, ends the relationship after you ask for more information, appears to follow a third party’s instructions, avoids KYC, has an unusual level of knowledge about AML/CTF requirements, or is prepared to pay higher fees without clear reasons.
Read more: AUSTRAC: Risk insights and indicators of suspicious activity for accountants Tranche 2 for accountants
Not necessarily. AUSTRAC says one indicator on its own may not suggest suspicious activity. If you’re unsure whether there are reasonable grounds for a suspicion, you should monitor and examine further, including applying enhanced customer due diligence.
Read more: AUSTRAC: Risk insights and indicators of suspicious activity for accountants Tranche 2 for accountants
Structuring to avoid threshold reporting is a criminal offence. If you have reasonable grounds to suspect a client is structuring to avoid TTR reporting, you must submit an SMR, and if you keep providing the service you must conduct enhanced CDD.
Read more: AUSTRAC: Threshold transaction reports Tranche 2 for accountants
How AUSTRAC approaches newly regulated firms
Expectations, penalties and where to get help.
AUSTRAC can apply to the Federal Court for a civil penalty order, for example up to 100,000 penalty units for a body corporate and up to 20,000 penalty units for persons other than bodies corporate; a penalty unit is $364 for contraventions on and from 1 July 2026. AUSTRAC can also accept enforceable undertakings, issue infringement notices (including for obligations such as enrolling, appointing a compliance officer and customer due diligence) and issue remedial directions.
Read more: AUSTRAC: Consequences of not complying
AUSTRAC’s CEO says contacting AUSTRAC for help isn’t a red flag, and that the Contact Centre exists to help businesses comply, not to catch out those making a genuine effort. The Contact Centre number given is 1300 021 037.
Read more: AUSTRAC: AUSTRAC issues notices to non-enrolled businesses
For FY26/27 AUSTRAC expects newly regulated businesses to be enrolled, have an AML/CTF program and AML compliance officer, have trained staff on the program and be ready to have a go at reporting when a suspicious matter arises. It expects the quality of controls and reports to improve over time and says it expects effort, not perfection, during FY26/27.
Read more: AUSTRAC: Update to regulator statement of expectations: May 2026
‘You must’ means an obligation, or an action AUSTRAC considers necessary in all circumstances. ‘We expect’ is an action likely necessary to comply, but AUSTRAC remains open to other ways of demonstrating compliance and may ask you to show how an alternative approach meets your obligations; ‘you may’ or ‘you could’ are good practice suggestions.
Read more: AUSTRAC: Learn how to use this guidance
Usually only medium to large businesses pay the levy: currently those with earnings of A$100 million or more, or a large number or high total value of transaction reports relative to other entities. AUSTRAC is reviewing the levy model and has asked businesses to complete a voluntary survey in AUSTRAC Online on turnover and earnings; if you receive an invoice you must pay it.
Read more: AUSTRAC: Industry contribution levy
Yes. AUSTRAC runs an induction program of 4 webinars on Microsoft Teams covering AML/CTF fundamentals, risk assessments, quality reporting (SMRs, TTRs and the annual compliance report) and IFTI reporting, and newly enrolled businesses receive an email invitation. The IFTI session is for businesses that submit international funds transfer instruction reports, such as banks, remitters and casinos. AUSTRAC asks that attendance be limited to 2 people per reporting entity, and the sessions are live events that are not recorded.
Read more: AUSTRAC: Induction program for new reporting entities
AUSTRAC’s data breach guidance points elsewhere for reporting the breach itself: you may have reporting responsibilities outside the AML/CTF regime, such as the OAIC’s notifiable data breaches scheme, and as good practice you could also notify the Australian Cyber Security Centre. Separately, AUSTRAC asks you to consider whether activity linked to the breach means you must submit an SMR.
Read more: AUSTRAC: Data breaches and AML/CTF considerations
Using Seamlss for AML
What the Seamlss AML tools do. Step by step guidance sits inside the app.
As one record, from onboarding to a filed PDF. The client is onboarded and ID checked, the PEP and sanctions checks run inside the risk assessment, the risk questions are answered by your team or sent to the client, and the finished assessment gives a rating, the reason for it, who signed off and the next review date, with a PDF for your file.
Read more: AML risk assessment for accounting firms Using the AML risk assessment tool
Yes. A shareholder or other person who isn’t a client can be ID checked on their own, without onboarding them, or sent the risk assessment questionnaire to fill in their own details. For existing clients, Seamlss can sync and copy their details across from the client record.
Read more: AML risk assessment for accounting firms
PEP and sanctions matching is more reliable with a date of birth and address. Seamlss can copy those across from a client’s record, or the person can fill them in through the risk assessment questionnaire.
Read more: AML risk assessment for accounting firms
Yes. In Seamlss you can choose an earlier result for a person instead of running and paying for a new one, if your AML program allows it.
Read more: What an AML check looks like for an accounting firm
The ID check accepts identity documents from most countries, and you can also send a source ID request asking the client to upload documents for your team to review.
Read more: Verifying your identity with Stripe Source verification guide for clients Client verification step by step
Yes, as a PDF for the client’s file. Everything else is exportable too.
Read more: AML risk assessment for accounting firms
Your firm does. Seamlss shows what fed the rating and who signed it off, and records the determination against the client with a timestamp. The tool doesn’t decide your risk appetite for you.
Read more: AML risk assessment for accounting firms
On Microsoft Azure infrastructure in Australia, with encryption in transit and at rest, multi factor authentication and role based access.
Read more: Security at the core of Seamlss
The risk assessment tool is part of your Seamlss plan, not an add on. AML and identity check rates are charged separately.
Read more: Seamlss pricing
Start with the help guide on using the AML risk assessment tool. The step by step guidance for each screen sits inside the app.
Read more: Using the AML risk assessment tool
Not answered here?
Send it to us and a person will read it. Good questions end up on this page. For how to do something in Seamlss, the AML and identity help guides cover it step by step.