Skip to main content
Compliance Guide — Updated August 2026

AML/CTF Cybersecurity Obligations for Accounting Firms

AUSTRAC cybersecurity requirements under the AML/CTF Amendment Act 2024. What Australian accounting firms must implement to achieve compliance.

July 2026 Deadline: AML/CTF Amendment Act 2024

The AML/CTF Amendment Act 2024 extended AML/CTF obligations to accounting firms, lawyers, real estate agents, and other "tranche two" entities from 1 July 2026. Cybersecurity controls are now a mandatory component of every AML/CTF program. Non-compliance triggers AUSTRAC enforcement.

What the AML/CTF Act Requires from Accountants

The Australian Transaction Reports and Analysis Centre (AUSTRAC) is the government body responsible for detecting, deterring, and disrupting criminal abuse of the financial system. Under the expanded AML/CTF framework, accounting firms that provide "designated services" (tax advice, financial planning, trust administration, company formation) must:

  • Enrol with AUSTRAC as a reporting entity
  • Develop and maintain an AML/CTF program (Part A: governance; Part B: customer due diligence)
  • Conduct ongoing customer due diligence (CDD) and enhanced due diligence (EDD) for high-risk clients
  • Submit suspicious matter reports (SMRs) and threshold transaction reports (TTRs) to AUSTRAC
  • Implement cybersecurity controls to protect AML/CTF program systems from compromise
  • Train staff on AML/CTF obligations, red flags, and cybersecurity awareness

Cybersecurity as an AML/CTF Control

This is the critical new element for 2026: cybersecurity is explicitly embedded in AML/CTF compliance. An accounting firm that suffers a cyberattack compromising its AML/CTF transaction monitoring or client records can face simultaneous AUSTRAC and cyber incident investigations.

Risk Assessment of AML/CTF Systems

Identify and document cybersecurity threats to your AML/CTF systems: client databases, transaction monitoring tools, trust account software, AUSTRAC reporting systems. A formal cyber risk assessment is required as part of your AML/CTF program.

Protect Transaction Monitoring Integrity

Your transaction monitoring systems must be protected from tampering. If an attacker modifies thresholds, suppresses alerts, or corrupts data, your AML/CTF program is effectively blind — which creates criminal liability risk for the firm and its principals.

Multi-Factor Authentication on Financial Systems

All systems used for AML/CTF compliance — AUSTRAC portal, trust account software, client CDD records — must be protected with MFA. Business Email Compromise (BEC) targeting accounting staff is the leading vector for trust account fraud in Australia.

Incident Response for AML/CTF Breaches

Your incident response plan must include specific procedures for: detecting compromise of AML/CTF systems, notifying AUSTRAC if transaction monitoring was compromised, and preserving evidence for investigation. A standard IT incident response plan is insufficient without AML-specific procedures.

The Biggest Cyber Threats to Accounting AML/CTF Compliance

Business Email Compromise (BEC)

Attacker compromises partner or senior staff email, monitors correspondence, then intercepts or redirects client payments and trust account transfers. Average BEC loss in AU: $50K–$500K per incident.

Ransomware on Practice Systems

Ransomware encrypts accounting software, client records, and AML/CTF program documentation. The firm cannot prepare reports, access CDD records, or submit SMRs — triggering AUSTRAC compliance failures even if not directly at fault.

Insider Threat — Compromised Staff Accounts

An attacker using compromised staff credentials can access client financial data, submit fraudulent SMRs, or suppress legitimate STR reports — creating criminal facilitation risk for the firm.

Supply Chain Compromise via Accounting Software

Accounting software providers (MYOB, Xero, QuickBooks) are high-value targets. A compromised update to widely-used accounting software could affect thousands of firms simultaneously, compromising AML/CTF data at scale.

AML/CTF Cybersecurity Compliance Checklist

Enrolment with AUSTRAC completed and AML/CTF program documented
Cyber risk assessment of AML/CTF systems completed and filed
MFA enabled on AUSTRAC portal, trust account software, and client CDD systems
Transaction monitoring alerts protected from suppression or modification
Incident response plan includes AML/CTF-specific breach procedures
Staff trained annually on AML/CTF obligations and BEC risk
Access controls limit AML/CTF system access to need-to-know staff
Audit logging enabled on all AML/CTF-related systems
Accounting software (MYOB, Xero, etc.) patched and monitored
Multi-person approval required for wire transfers above set threshold

AUSTRAC Enforcement Risk

AUSTRAC has significantly increased enforcement actions. The civil penalty regime for AML/CTF breaches includes:

  • Civil penalty notices up to $22 million for large firms, $4.5 million for individuals
  • Enforceable undertakings requiring third-party audits and remediation programs
  • Court-ordered remediation with ongoing monitoring by AUSTRAC-appointed external auditor
  • Public enforcement actions — AUSTRAC names non-compliant firms in media releases
  • Criminal referral to AFP for facilitating money laundering through inadequate controls

Related Resources

Get AML/CTF Compliant Before the Deadline

ShieldForce helps accounting firms build AUSTRAC-compliant AML/CTF programs with integrated cybersecurity controls. We work with your compliance team to ensure both regulatory and technical requirements are met.

Book Your AML/CTF Compliance Assessment

References

Authors: ShieldForce Editorial Team, led by Obi Ibeto, Founder & CEO, ShieldForce Australia

Published: August 2026 | Last Updated: August 2026

See our full author credentials