AUSTRAC Reform 2026: AML/CTF Compliance Guide for Newly Regulated Businesses in Australia

AML/CTF REFORM IN AUSTRALIA news post

Last updated: July 2026

Australia has entered a new AML/CTF compliance phase. From 1 July 2026, thousands of additional businesses are now regulated under Australia’s anti-money laundering and counter-terrorism financing laws, including legal services, accounting, conveyancing, real estate, and dealers in precious metals and stones. Newly regulated businesses must enrol with AUSTRAC by 29 July 2026.

For many firms, this is not just a regulatory update. It is a shift in how client onboarding, risk assessment, identity checks, screening, suspicious matter reporting, and record-keeping must be managed. Manual checks and fragmented documentation may no longer be enough for firms that need a reliable, audit-ready AML/KYC process.

This 2026 guide explains what the AUSTRAC reform means, who is affected, what obligations apply, and how newly regulated firms can prepare.

What Is the AUSTRAC AML/CTF Reform?

The AUSTRAC reform expands Australia’s AML/CTF regime to additional high-risk services that can be exploited for money laundering, terrorism financing, and proliferation financing. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 amended the AML/CTF Act and was passed by Parliament on 29 November 2024.

The reform has three broad objectives:

  • Expand AML/CTF regulation to additional high-risk services.
  • Modernize regulation for virtual assets and payment technologies.
  • Simplify and clarify the AML/CTF framework so obligations are more risk-based and outcomes-focused.

AUSTRAC has described the 2026 expansion as a major milestone in Australia’s AML/CTF framework, with newly regulated sectors now required to meet obligations such as AML/CTF programs, customer due diligence, suspicious matter reporting, and record-keeping.

Key Date: AUSTRAC Enrolment by 29 July 2026

The most urgent date for newly regulated businesses is 29 July 2026. AUSTRAC states that businesses newly regulated under the reforms must enrol by this date if they provide new designated services that commenced on 1 July 2026.

Most newly regulated businesses only need to enrol. However, businesses providing remittance or virtual asset designated services may need to enrol and apply for registration.

AUSTRAC’s transitional rules also give newly regulated businesses additional time to notify AUSTRAC of their AML/CTF compliance officer. The deadline is the later of 14 days after enrolment or 29 July 2026.

Who Is Affected by the AUSTRAC Reform?

The reform applies to businesses that provide certain designated services. It does not automatically apply to every business in an affected profession. The AML/CTF regime uses a designated services model, meaning the specific service provided determines whether AML/CTF obligations are triggered.

Newly regulated sectors include:

  • Legal professionals
  • Accountants
  • Conveyancers
  • Real estate professionals
  • Dealers in precious metals, stones and related products
  • Trust and company service providers
  • Certain virtual asset service providers beyond existing digital currency exchange obligations

For firms in these sectors, the practical question is no longer only “Are we in scope?” It is also “Can we evidence how we identify, assess, manage, and monitor financial crime risk?”

Why Australia Has Expanded AML/CTF Regulation

AUSTRAC has stated that criminals exploit Australia’s real estate market and complex company structures to hide and move illicit money. AUSTRAC also notes that newly regulated sectors play a role in transactions that can be misused, including property purchases and the use of trust and company structures to obscure ownership and source of funds.

The reform also aligns with international expectations. The Department of Home Affairs states that the Amendment Act was needed to help Australia deter, detect, and disrupt money laundering and terrorism financing and meet Financial Action Task Force standards.

For firms entering AML/CTF regulation for the first time, the message is clear: compliance must be proportionate, risk-based, and operationally embedded.

Core AML/CTF Obligations for Newly Regulated Businesses

Newly regulated firms should prepare for obligations across governance, onboarding, monitoring, reporting, and recordkeeping.

1. Develop and Maintain an AML/CTF Program

AUSTRAC says an AML/CTF program must include a risk assessment and AML/CTF policies, procedures, systems, and controls to manage and mitigate money laundering, terrorism financing, and proliferation financing risks.

In practice, this means documenting:

  • Your customer types
  • Your services and delivery channels
  • Geographic risk
  • Transaction risk
  • Beneficial ownership risk
  • Screening and monitoring controls
  • Escalation and reporting procedures
  • Governance and oversight responsibilities

A strong AML/CTF program should be usable by staff, not simply stored as a policy document.

2. Establish Governance and Appoint Responsible Roles

AUSTRAC guidance identifies key governance responsibilities, including a governing body, senior manager, and AML/CTF compliance officer. These roles support oversight, approval of AML/CTF decisions, and day-to-day implementation of policies and procedures.

Smaller businesses may have one person performing multiple responsibilities, but accountability still needs to be clear. Firms should document who owns AML/CTF decisions, who reviews escalations, and who signs off on high-risk client relationships.

3. Conduct Customer Due Diligence

Customer due diligence helps firms understand who their customers are before providing designated services and throughout the business relationship. AUSTRAC describes CDD as including initial CDD, ongoing CDD, and enhanced CDD where risk is high or specified circumstances apply.

A practical CDD process should cover:

  • Customer identity verification
  • Beneficial ownership checks
  • Purpose and nature of the relationship
  • Risk rating
  • Politically exposed person screening
  • Sanctions and adverse media screening
  • Source of funds and source of wealth where appropriate
  • Ongoing monitoring and periodic review

For real estate, legal and accounting firms, this may require a cultural shift. Client onboarding is no longer only an administrative step. It becomes a regulated risk assessment process.

4. Report Suspicious Matters

AUSTRAC states that newly regulated businesses must report suspicious matters when required. Updated suspicious matter report forms are available in AUSTRAC Online as part of the new reporting regime.

A firm should be able to show how staff identify red flags, escalate concerns internally, assess suspicion, and submit reports where required. Training is essential because suspicious activity is often detected by frontline teams before it reaches compliance.

5. Keep Relevant Records

Record keeping is one of the most important practical obligations because it demonstrates what happened, when it happened, and why a decision was made. AUSTRAC lists record keeping as one of the obligations for newly regulated businesses under the updated laws.

Good AML/KYC records should include identity evidence, risk assessments, screening results, approvals, enhanced due diligence notes, monitoring outcomes, and suspicious matter decisions.

AML/CTF Compliance by Industry

Legal Services

Law firms may be in scope when providing designated services connected to transactions, entities, trusts, or other high-risk arrangements. The reform also clarifies how legal professional privilege is treated under the AML/CTF Act, with Home Affairs stating that the Amendment Act preserves the core intention of legal professional privilege while enabling compliance.

Accounting and Trust Services

Accountants and trust and company service providers may face risk where they help create, manage, or administer structures that can obscure beneficial ownership. Firms should focus on beneficial ownership, source of funds, source of wealth, and the purpose of complex structures.

Real Estate and Conveyancing

Real estate and conveyancing businesses are central to the reform because property transactions can be used to place or integrate illicit funds. AUSTRAC has highlighted criminal exploitation of the real estate market and complex company structures as a key concern.

Precious Metals and Stones

Dealers in precious metals, stones, and related products may face risks linked to high-value, portable assets. Firms should pay close attention to cash exposure, unusual purchasing patterns, third-party payments, and customers who are reluctant to provide identity or ownership information.

Practical AML/CTF Readiness Checklist

Newly regulated businesses should prioritize operational readiness before the 29 July 2026 enrolment deadline.

âś… Confirm whether your services are designated services under the AUSTRAC reform.
âś… Enrol with AUSTRAC by 29 July 2026 if in scope.
âś… Appoint and notify an AML/CTF compliance officer within the applicable deadline.
âś… Complete a money laundering and terrorism financing risk assessment.
âś… Build an AML/CTF program with documented policies, procedures, systems, and controls.
âś… Implement customer due diligence and enhanced due diligence workflows.
âś… Screen customers, beneficial owners, and relevant parties for sanctions, PEP, and adverse media risk.
âś… Train staff to identify and escalate suspicious activity.
âś… Prepare suspicious matter reporting procedures.
âś… Centralize AML/KYC records so decisions are traceable and audit-ready.

How Technology Can Support AUSTRAC Compliance

For newly regulated firms, the main challenge is often operational. AML/CTF obligations require consistent client onboarding, risk scoring, screening, monitoring, reporting, and documentation. Spreadsheets, email folders, and manual evidence collection can create gaps, delays, and inconsistent decisions.

Cascade’s AML Software (SaaS Platform) can support regulated firms in building a more structured AML/KYC process across client onboarding, risk assessment, screening, ongoing monitoring, and documentation.

Cascade modules should be considered as add-ons to the core platform, not standalone products:

  • Automated Treatment of Name Screening Alerts, an add-on module that requires the core AML Software (SaaS Platform).
  • Digital Communication Bridge for Client Onboarding, an add-on module that requires the core AML Software (SaaS Platform).
  • BI Module for AML Reporting and Analytics, an add-on module that requires the core AML Software (SaaS Platform).

For Australian firms preparing for AUSTRAC obligations, technology can help turn policy into a repeatable process. The goal is not only to complete checks but also to provide evidence of why decisions were made.

FAQ: AUSTRAC Reform 2026

What is the AUSTRAC enrolment deadline for newly regulated businesses?

Newly regulated businesses must enrol with AUSTRAC by 29 July 2026 if they provide designated services that commenced on 1 July 2026.

When did the new AUSTRAC obligations start?

The new obligations for tranche two entities providing new designated services started on 1 July 2026.

Which sectors are newly regulated under the AUSTRAC reform?

Newly regulated sectors include legal professionals, accountants, conveyancers, real estate professionals, dealers in precious metals and stones, trust and company service providers, and certain virtual asset service providers.

Do all legal, accounting, and real estate businesses need to enrol?

Not necessarily. The AML/CTF regime is based on designated services, so firms need to assess whether the specific services they provide fall within scope.

What are the main AML/CTF obligations?

Core obligations include implementing an AML/CTF program, conducting customer due diligence, reporting suspicious matters, and keeping relevant records.

Related Reading

Explore Cascade’s AML Software for AUSTRAC Readiness

Australia’s AML/CTF reform marks a new compliance phase for firms that may never have been regulated by AUSTRAC before. The next step is practical readiness: enrol, assess your risks, document your AML/CTF program, train your teams, and build a reliable AML/KYC process.

Explore Cascade’s KYA capabilities to see how the AML software (SaaS platform) can support structured onboarding, risk assessment, screening, monitoring, and AML/KYC documentation for regulated firms.

This article is for general information only and based on publicly available sources at the time of writing. We’ve done our best to make it accurate and useful, but AML rules and business needs can change. Always double-check key details and speak with a qualified expert before making compliance or vendor decisions.

Ready to Get Started?

Empower your compliance with the leading end-to-end AML KYC platform Cascade