Skip to main content
AML/CTF Compliance

AML/CTF Obligations for Accounting Firms: The 2026 Compliance Checklist

The July 2026 deadline has passed or is imminent. Australian accounting firms that have not enrolled with AUSTRAC face penalties of up to $22 million.

By ShieldForce Editorial Team  | 

The July 2026 Deadline: What Changed

The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) came into force and extended Australia's AML/CTF regime to "Tranche 2" designated services — most significantly, professional service providers who were previously exempt. Accounting firms, law firms, and real estate agents providing trust or company services now fall within the AUSTRAC regulatory framework.

The commencement date for most accounting firm obligations under the expanded regime is July 2026. Firms that provide services including trust and company administration, estate management with financial transactions, or business sale and purchase advisory with financial facilitation must have enrolled with AUSTRAC and have a compliant AML/CTF program in place.

Australia is one of the last FATF (Financial Action Task Force) member countries to extend AML/CTF obligations to professional services. The FATF has identified designated non-financial businesses and professions (DNFBPs) — including accounting and legal services — as key vulnerability points for money laundering and terrorism financing. Regulated entities in these professions have been used, knowingly or unknowingly, to move illicit funds through trust accounts, company formations, and property transactions.

The expanded regime is not a minor compliance tweak. It imposes substantive obligations: enrolment, a formal AML/CTF program, ongoing customer due diligence, suspicious matter reporting, and record-keeping. Firms that treat it as a one-time form to fill in are making a significant error.

What AUSTRAC Requires: The Core Obligations

Enrolment

Every reporting entity must enrol with AUSTRAC via the AUSTRAC Online portal. Enrolment is a legal requirement — not a voluntary registration. Operating a designated service without being enrolled is itself a contravention of the AML/CTF Act.

AML/CTF Program

You must have a written, board-approved (or principal-approved) AML/CTF program that identifies and assesses your firm's money laundering and terrorism financing risks, and sets out the controls you have implemented to manage those risks. The program must be reviewed annually and updated when your business changes.

Customer Due Diligence (CDD)

Before providing a designated service, you must identify and verify the identity of every customer (and beneficial owner of legal entities). This means collecting and verifying: name, address, date of birth (for individuals), and ACN/ABN and beneficial ownership for companies and trusts.

Enhanced Due Diligence (EDD)

For high-risk customers — politically exposed persons (PEPs), customers from high-risk jurisdictions, complex ownership structures — you must conduct Enhanced Due Diligence: deeper scrutiny of the business relationship, source of wealth, and source of funds.

Suspicious Matter Reports (SMRs)

If you have reasonable grounds to suspect that a transaction or customer is connected to money laundering, tax evasion, or another financial crime, you must file a Suspicious Matter Report with AUSTRAC before completing the service (or as soon as practicable). There is a "tipping off" prohibition — you must not tell the customer or any other person that you have filed or intend to file an SMR.

Record-Keeping

Retain all transaction records, CDD documents, and AML/CTF program documents for 7 years. These records must be available for AUSTRAC examination on request.

The Cybersecurity Component of AML/CTF Compliance

Many accounting firms focus exclusively on the procedural aspects of AML/CTF compliance — enrolling with AUSTRAC, drafting an AML/CTF program, training staff on CDD procedures. What is frequently overlooked is that cybersecurity is now directly embedded in your AML/CTF obligations.

Your AML/CTF program must include controls for the integrity and security of your compliance processes. This means: the customer data you collect for CDD must be protected against unauthorised access; your suspicious matter reporting capability must be available and functional (not ransomwared); and your 7-year record retention obligation requires secure, reliable, and accessible storage — which is not achievable without adequate cybersecurity controls.

Why a Cyber Breach Makes You an AML/CTF Risk

A compromised accounting firm's trust account or client management system can be actively exploited for money laundering — not by the firm's principals, but by attackers who have gained control. An attacker who has compromised your email may intercept client payment instructions and redirect funds in a way that constitutes a financial crime, without your knowledge. If your systems facilitated a financial crime because you lacked reasonable security controls, AUSTRAC may investigate the firm as well as the perpetrator.

This is not hypothetical. Internationally, professional service firms have faced regulatory scrutiny after BEC (Business Email Compromise) attacks resulted in their accounts being used as pass-through channels for laundered funds. The connection between cyber weakness and AML risk is real, documented, and increasingly on AUSTRAC's radar.

The 10-Item Practical Compliance Checklist

1

Enrol with AUSTRAC

Register at austrac.gov.au via AUSTRAC Online. This is the first and non-negotiable step. Operating without enrolment is a standalone contravention.

2

Document your designated services

Identify specifically which services your firm provides that fall within the AML/CTF Act's designated service categories. Not all accounting services are designated — be specific about what triggers your obligations.

3

Conduct an ML/TF risk assessment

Formally assess your firm's exposure to money laundering and terrorism financing risk. Consider: your client base, jurisdictions involved, transaction volumes, complexity of services. Document this assessment annually.

4

Draft and adopt an AML/CTF program

Your program must address: identification and verification of customers, ongoing due diligence, staff training, suspicious matter reporting, record-keeping, and the roles and responsibilities for AML/CTF compliance within your firm.

5

Implement CDD procedures for every new client

Collect and verify name, address, and identity documentation for all new clients. For companies: identify beneficial owners (persons holding or controlling 25%+). Document everything in your client file.

6

Train all fee-earning and administrative staff

Every staff member involved in providing designated services must understand what AML/CTF requires, how to identify suspicious matters, and what to do when they identify red flags. Training must be documented.

7

Enable MFA on all systems handling client data

Email, practice management software, cloud storage, banking — all require MFA. This is both a cybersecurity control and an AML/CTF program integrity requirement.

8

Implement trust account security controls

Require dual authorisation for trust disbursements above a threshold. Implement callback verification for new payee bank accounts. Monitor trust transactions against expected patterns.

9

Establish an SMR reporting process

Know how to file a Suspicious Matter Report in AUSTRAC Online. Designate a responsible officer for AML/CTF compliance. Brief all staff on the tipping-off prohibition.

10

Set up 7-year secure record retention

Implement a document management system that retains CDD records, transaction records, and AML/CTF program documentation for 7 years in encrypted, access-controlled storage.

Penalties for Non-Compliance

The AML/CTF Act provides for serious civil and criminal penalties for non-compliance. For accounting firms, the relevant penalties include:

Civil Penalties
Up to $22 million

For corporations found to have contravened substantive AML/CTF obligations. AUSTRAC has previously issued civil penalties of this magnitude against major financial institutions and has signalled intent to hold professional service firms to the same standard.

Named Enforcement Actions
Public

AUSTRAC publishes enforcement actions on its website. Being named in an enforcement action causes significant reputational damage for a professional services firm — particularly damaging given client relationships and referral networks are a core part of most accounting practices.

Criminal Referrals
Criminal prosecution

Knowing contraventions — deliberately not enrolling, deliberately not filing SMRs, deliberately tipping off a suspect — can result in criminal referrals with potential imprisonment for responsible individuals.

Loss of Professional Accreditation
Practice impact

AUSTRAC non-compliance may be referred to professional bodies (CPA Australia, CA ANZ, IPA), which have their own disciplinary processes. Membership suspension or cancellation has career-ending implications.

Common Mistakes Accounting Firms Make

⚠️ Treating AML/CTF as a tick-box exercise

Enrolling with AUSTRAC and filing an AML/CTF program without integrating it into day-to-day practice is the most common failure mode. The AUSTRAC audit process looks for evidence that your AML/CTF program is actually implemented, not just documented.

⚠️ Assuming all accounting services are designated

Not all accounting services trigger AML/CTF obligations. Standard tax return preparation is not a designated service. Trust and company administration, business sale advisory with financial facilitation, and real property conveyancing support can be. Map your services carefully.

⚠️ Failing to connect cybersecurity to AML/CTF

AML/CTF compliance requires that your trust account data, CDD records, and SMR-filing capability are secure and available. A ransomware attack that takes down your practice management system may simultaneously create an AML/CTF compliance failure if you cannot access or file required reports.

⚠️ Not training staff on the tipping-off prohibition

Many accounting firm staff are unaware that once a suspicious matter report decision is made, discussing it with the client — even inadvertently — is a criminal offence. All staff must understand this rule, not just the AML/CTF compliance officer.

Is Your Accounting Firm AML/CTF Compliant?

ShieldForce helps Australian accounting firms integrate cybersecurity controls into their AML/CTF programs and achieve AUSTRAC compliance with a practical, business-focused approach.

Book a Free AML/CTF Compliance Review

Related Articles

References

SF
ShieldForce Editorial Team
ShieldForce Australia — Cybersecurity & Compliance for Professional Services
Published

See our full author credentials