The July 2026 Deadline: What Changed
The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) came into force and extended Australia's AML/CTF regime to "Tranche 2" designated services — most significantly, professional service providers who were previously exempt. Accounting firms, law firms, and real estate agents providing trust or company services now fall within the AUSTRAC regulatory framework.
The commencement date for most accounting firm obligations under the expanded regime is July 2026. Firms that provide services including trust and company administration, estate management with financial transactions, or business sale and purchase advisory with financial facilitation must have enrolled with AUSTRAC and have a compliant AML/CTF program in place.
Australia is one of the last FATF (Financial Action Task Force) member countries to extend AML/CTF obligations to professional services. The FATF has identified designated non-financial businesses and professions (DNFBPs) — including accounting and legal services — as key vulnerability points for money laundering and terrorism financing. Regulated entities in these professions have been used, knowingly or unknowingly, to move illicit funds through trust accounts, company formations, and property transactions.
The expanded regime is not a minor compliance tweak. It imposes substantive obligations: enrolment, a formal AML/CTF program, ongoing customer due diligence, suspicious matter reporting, and record-keeping. Firms that treat it as a one-time form to fill in are making a significant error.
What AUSTRAC Requires: The Core Obligations
Enrolment
Every reporting entity must enrol with AUSTRAC via the AUSTRAC Online portal. Enrolment is a legal requirement — not a voluntary registration. Operating a designated service without being enrolled is itself a contravention of the AML/CTF Act.
AML/CTF Program
You must have a written, board-approved (or principal-approved) AML/CTF program that identifies and assesses your firm's money laundering and terrorism financing risks, and sets out the controls you have implemented to manage those risks. The program must be reviewed annually and updated when your business changes.
Customer Due Diligence (CDD)
Before providing a designated service, you must identify and verify the identity of every customer (and beneficial owner of legal entities). This means collecting and verifying: name, address, date of birth (for individuals), and ACN/ABN and beneficial ownership for companies and trusts.
Enhanced Due Diligence (EDD)
For high-risk customers — politically exposed persons (PEPs), customers from high-risk jurisdictions, complex ownership structures — you must conduct Enhanced Due Diligence: deeper scrutiny of the business relationship, source of wealth, and source of funds.
Suspicious Matter Reports (SMRs)
If you have reasonable grounds to suspect that a transaction or customer is connected to money laundering, tax evasion, or another financial crime, you must file a Suspicious Matter Report with AUSTRAC before completing the service (or as soon as practicable). There is a "tipping off" prohibition — you must not tell the customer or any other person that you have filed or intend to file an SMR.
Record-Keeping
Retain all transaction records, CDD documents, and AML/CTF program documents for 7 years. These records must be available for AUSTRAC examination on request.
The Cybersecurity Component of AML/CTF Compliance
Many accounting firms focus exclusively on the procedural aspects of AML/CTF compliance — enrolling with AUSTRAC, drafting an AML/CTF program, training staff on CDD procedures. What is frequently overlooked is that cybersecurity is now directly embedded in your AML/CTF obligations.
Your AML/CTF program must include controls for the integrity and security of your compliance processes. This means: the customer data you collect for CDD must be protected against unauthorised access; your suspicious matter reporting capability must be available and functional (not ransomwared); and your 7-year record retention obligation requires secure, reliable, and accessible storage — which is not achievable without adequate cybersecurity controls.
Why a Cyber Breach Makes You an AML/CTF Risk
A compromised accounting firm's trust account or client management system can be actively exploited for money laundering — not by the firm's principals, but by attackers who have gained control. An attacker who has compromised your email may intercept client payment instructions and redirect funds in a way that constitutes a financial crime, without your knowledge. If your systems facilitated a financial crime because you lacked reasonable security controls, AUSTRAC may investigate the firm as well as the perpetrator.
This is not hypothetical. Internationally, professional service firms have faced regulatory scrutiny after BEC (Business Email Compromise) attacks resulted in their accounts being used as pass-through channels for laundered funds. The connection between cyber weakness and AML risk is real, documented, and increasingly on AUSTRAC's radar.
The 10-Item Practical Compliance Checklist
Enrol with AUSTRAC
Register at austrac.gov.au via AUSTRAC Online. This is the first and non-negotiable step. Operating without enrolment is a standalone contravention.
Document your designated services
Identify specifically which services your firm provides that fall within the AML/CTF Act's designated service categories. Not all accounting services are designated — be specific about what triggers your obligations.
Conduct an ML/TF risk assessment
Formally assess your firm's exposure to money laundering and terrorism financing risk. Consider: your client base, jurisdictions involved, transaction volumes, complexity of services. Document this assessment annually.
Draft and adopt an AML/CTF program
Your program must address: identification and verification of customers, ongoing due diligence, staff training, suspicious matter reporting, record-keeping, and the roles and responsibilities for AML/CTF compliance within your firm.
Implement CDD procedures for every new client
Collect and verify name, address, and identity documentation for all new clients. For companies: identify beneficial owners (persons holding or controlling 25%+). Document everything in your client file.
Train all fee-earning and administrative staff
Every staff member involved in providing designated services must understand what AML/CTF requires, how to identify suspicious matters, and what to do when they identify red flags. Training must be documented.
Enable MFA on all systems handling client data
Email, practice management software, cloud storage, banking — all require MFA. This is both a cybersecurity control and an AML/CTF program integrity requirement.
Implement trust account security controls
Require dual authorisation for trust disbursements above a threshold. Implement callback verification for new payee bank accounts. Monitor trust transactions against expected patterns.
Establish an SMR reporting process
Know how to file a Suspicious Matter Report in AUSTRAC Online. Designate a responsible officer for AML/CTF compliance. Brief all staff on the tipping-off prohibition.
Set up 7-year secure record retention
Implement a document management system that retains CDD records, transaction records, and AML/CTF program documentation for 7 years in encrypted, access-controlled storage.
Penalties for Non-Compliance
The AML/CTF Act provides for serious civil and criminal penalties for non-compliance. For accounting firms, the relevant penalties include:
For corporations found to have contravened substantive AML/CTF obligations. AUSTRAC has previously issued civil penalties of this magnitude against major financial institutions and has signalled intent to hold professional service firms to the same standard.
AUSTRAC publishes enforcement actions on its website. Being named in an enforcement action causes significant reputational damage for a professional services firm — particularly damaging given client relationships and referral networks are a core part of most accounting practices.
Knowing contraventions — deliberately not enrolling, deliberately not filing SMRs, deliberately tipping off a suspect — can result in criminal referrals with potential imprisonment for responsible individuals.
AUSTRAC non-compliance may be referred to professional bodies (CPA Australia, CA ANZ, IPA), which have their own disciplinary processes. Membership suspension or cancellation has career-ending implications.
Common Mistakes Accounting Firms Make
Enrolling with AUSTRAC and filing an AML/CTF program without integrating it into day-to-day practice is the most common failure mode. The AUSTRAC audit process looks for evidence that your AML/CTF program is actually implemented, not just documented.
Not all accounting services trigger AML/CTF obligations. Standard tax return preparation is not a designated service. Trust and company administration, business sale advisory with financial facilitation, and real property conveyancing support can be. Map your services carefully.
AML/CTF compliance requires that your trust account data, CDD records, and SMR-filing capability are secure and available. A ransomware attack that takes down your practice management system may simultaneously create an AML/CTF compliance failure if you cannot access or file required reports.
Many accounting firm staff are unaware that once a suspicious matter report decision is made, discussing it with the client — even inadvertently — is a criminal offence. All staff must understand this rule, not just the AML/CTF compliance officer.
Is Your Accounting Firm AML/CTF Compliant?
ShieldForce helps Australian accounting firms integrate cybersecurity controls into their AML/CTF programs and achieve AUSTRAC compliance with a practical, business-focused approach.
Book a Free AML/CTF Compliance ReviewRelated Articles
References
See our full author credentials
