Australia's AML/CTF Framework Has Entered a New Era

Australia's AML/CTF Framework Has Entered a New Era
Australia's AML/CTF reforms are now live. Learn what changed, who is affected, and why risk-based monitoring is becoming essential for regulated businesses.

Australia's anti-money laundering and counter-terrorism financing framework has changed significantly.

On 1 July 2026, thousands of additional businesses became subject to AML/CTF obligations, extending the regime into sectors including real estate, conveyancing, legal services, accounting, and dealers in precious stones and metals. These businesses must now establish AML/CTF programs, conduct customer due diligence, report suspicious matters, and maintain relevant records.

For newly regulated businesses, this is more than a policy exercise. It introduces an ongoing operational responsibility: understanding financial crime risk and demonstrating that appropriate controls are actually working.

The question is no longer whether AML/CTF compliance applies.

It is whether the organisation's processes, people, data, and monitoring capabilities are ready to support it.


What Changed on 1 July 2026?

The reforms introduced a broader reporting population and updated obligations across Australia's AML/CTF framework.

For newly regulated sectors, the changes include requirements to:

  • Establish and maintain an AML/CTF program
  • Conduct appropriate customer due diligence
  • Identify and report suspicious matters
  • Maintain relevant records
  • Appoint an AML/CTF compliance officer
  • Train staff on the organisation's AML/CTF program

Newly regulated businesses were required to enrol with AUSTRAC by 29 July 2026. Businesses providing remittance or virtual asset designated services have additional registration requirements.

The reporting environment has also changed. New Threshold Transaction Report (TTR) and Suspicious Matter Report (SMR) forms became available in AUSTRAC Online from 1 July.

The scale is significant. AUSTRAC reports that it received more than 2 million TTRs and over 450,000 SMRs in the previous year. The expansion of regulated industries adds another layer of reporting activity to an already substantial financial intelligence environment.


Why the Expansion Matters

The reforms bring sectors into the AML/CTF regime that can be exposed to sophisticated money laundering activity.

Real estate transactions, professional services, corporate structures, trust arrangements, and high-value goods can all create opportunities for illicit funds to enter legitimate economic activity.

AUSTRAC estimates that financial crime costs Australia up to $82 billion each year. The purpose of the reforms is therefore broader than increasing reporting. They are designed to strengthen Australia's ability to identify and disrupt financial crime across more parts of the economy.

For newly regulated businesses, the challenge is building controls that work in practice rather than simply documenting that controls exist.


AUSTRAC's Standard Is Risk-Based

One of the most important messages in AUSTRAC's updated regulatory expectations is that AML/CTF compliance is not a one-size-fits-all exercise.

AUSTRAC states that businesses must take a risk-based approach to managing money laundering, terrorism financing, and proliferation financing risks. Controls should differ according to the level and type of risk, rather than being applied identically to every customer.

For a real estate professional handling high-value property transactions, the relevant risk indicators may look very different from those faced by an accountant managing complex corporate structures or legal practice handling client funds.

The compliance model therefore needs to understand context.

That is where monitoring becomes important.


Why Manual Monitoring Creates a Growing Gap

Many organisations entering AML/CTF regulation have not previously operated a dedicated financial crime monitoring function.

Their starting point may be:

  • Spreadsheets
  • Manual reviews
  • Periodic customer checks
  • Static rules
  • Email-based escalation
  • Disconnected reporting processes

These approaches can provide a foundation, but they become harder to manage as transaction volumes and customer relationships increase.

The problem is not simply the number of transactions.

It is the relationships between them.

A single transaction may look legitimate in isolation while becoming significantly more suspicious when viewed alongside a customer's previous activity, related accounts, unusual timing, geographic behaviour, or other connected transactions.

This is where traditional monitoring can struggle.


Where AI-Powered Monitoring Can Help

AUSTRAC does not mandate artificial intelligence.

The regulatory requirement is for businesses to understand and manage their risks through effective AML/CTF controls.

However, organisations facing complex or high-volume transaction environments can use AI and anomaly detection to strengthen those controls.

AI-powered monitoring can help organisations:

  • Establish behavioural baselines
  • Identify unusual transaction patterns
  • Detect anomalies that rules may miss
  • Prioritise higher-risk activity
  • Connect related behavioural and transaction signals
  • Reduce unnecessary investigation workload
  • Provide more consistent evidence for review

This does not replace compliance professionals.

It gives them better intelligence with which to make decisions.


The Monitoring Gap for Newly Regulated Businesses

For many businesses newly captured by the reforms, the immediate challenge is building an AML/CTF operating model from the ground up.

AUSTRAC's expectations for FY2026–27 recognise that businesses will continue embedding new processes after the reforms take effect. The regulator expects newly regulated businesses to be enrolled, have an AML/CTF program and compliance officer, train staff, and be ready to report when a suspicious matter arises. It also states that it expects effort, not perfection, during the transition year.

That transition period should not be treated as a reason to delay.

It is an opportunity to build the right monitoring architecture from the beginning rather than creating manual processes that later need to be replaced.


What Regulated Businesses Should Do Now

For organisations affected by the 2026 reforms, five priorities should be on the agenda:

1. Confirm your regulatory position

Identify the designated services your organisation provides and understand which obligations apply.

2. Review your AML/CTF program

Ensure your program reflects the organisation's actual ML/TF/PF risks rather than relying on generic policies.

3. Strengthen monitoring

Assess whether current processes can identify unusual activity and support timely investigation and reporting.

4. Establish clear accountability

Ensure the AML/CTF compliance officer, operational teams, investigators, and senior management understand their responsibilities.

5. Build for continuous improvement

Treat monitoring as an evolving capability. Financial crime risks change, and AUSTRAC expects businesses to improve the quality of their controls and reporting over time.


Conclusion

Australia's 2026 AML/CTF reforms have changed the compliance landscape for thousands of businesses.

For newly regulated organisations, the priority is not simply creating an AML/CTF policy. It is building an operating model capable of identifying risk, monitoring customer and transaction behaviour, investigating suspicious activity, and demonstrating how decisions were made.

Manual processes may provide a starting point, but they become increasingly difficult to scale as transaction volumes, customer relationships, and financial crime techniques become more complex.

The organisations that invest in effective monitoring now will be better positioned to meet AUSTRAC's expectations, strengthen operational resilience, and respond as financial crime continues to evolve.

The regulatory requirement is risk-based. The strategic opportunity is intelligent monitoring.


Frequently Asked Questions

1. Who is affected by the 2026 AML/CTF reforms?

Newly regulated sectors include real estate, conveyancing, legal services, accounting, and dealers in precious stones and metals. Other designated services may also fall within the expanded regime.

2. Does AUSTRAC require AI?

No. AUSTRAC requires effective, risk-based AML/CTF controls. AI is one technology organisations can use to strengthen monitoring, anomaly detection, and investigation capabilities.

3. What should a newly regulated business do first?

Confirm which designated services apply, maintain an appropriate AML/CTF program, appoint the required compliance officer, train staff, and ensure the organisation can identify and report suspicious activity.