Australia's AML/CTF Reforms Are Now in Force. Here's What Changed for Remitters.
On 31 March 2026, the substantive provisions of the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 were brought into force for existing reporting entities. The Act had been passed on 29 November 2024 and assented to on 10 December 2024; Schedules 1 to 3 — the new program structure, the rewritten customer due diligence regime and the regulation of additional services — were given effect on 31 March, and a further set of provisions was commenced on 1 July 2026, the date from which the newly regulated “tranche 2” professions were also brought under AUSTRAC’s supervision.
Most of what has been written about the reforms has been aimed at the professions being regulated for the first time. This version is written for a compliance officer at a remittance service provider — a sector that was already regulated, and for which the reforms changed the work rather than the fact of being supervised. The changes that affect day-to-day operations are set out below, and two dates that have already passed are flagged.
The AML/CTF Program Was Restructured Around a Risk Assessment
The familiar Part A / Part B split has gone. An AML/CTF program is now required to contain two things — a money laundering and terrorism financing risk assessment, and the AML/CTF policies that respond to it. In AUSTRAC’s words, “an effective program must be ‘risk based’ and designed to address the specific risks of your business.” The risk assessment is no longer a preamble to the controls; it is the document the controls have to be traced back to.
Independent reviews of Part A have been replaced by independent evaluations of the whole program. For a business that was already a reporting entity, the first evaluation is required by the later of four years after the most recent independent review or 31 March 2027 — and it will be of the program as a whole, the risk assessment included.
The shift was described by AUSTRAC directly: the reforms “mark a regulatory shift – from regulation that primarily checks for compliance, to one focused on substantive risks and harms.” A quick guide to the ML/TF risk assessment framework for remittance service providers was published in January 2026 and is the reference the assessment should be built against.
The Remittance Sector Is Rated High-Risk
That assessment is written into a known context. In its 2022 assessment of independent remittance dealers, the overall ML/TF risk of the subsector was rated high by AUSTRAC, with 88 per cent of the subsector’s suspicious matter reports found to have come from the largest of its 816 dealers. The position was restated in August 2025, when a “use it or lose it” review of more than 900 registered remitters was announced and the sector was described by AUSTRAC’s chief executive as high risk “because of its exposure to cash and the fast, low-cost way funds can be transferred across borders.” A risk assessment that rates a remittance business as low-risk without engaging with that view will not be read as risk-based.
Working out what the amended Act now requires?An Australian question like "when must initial CDD be completed for a new customer" is answered by ARGOS with a citation to the Act, not a summary of it.
Try a free questionCustomer Due Diligence Was Rewritten, and Two Transition Dates Were Set
Initial customer due diligence is now required to be completed before a designated service is started — not within a window after it. For customers already on the books, most of the burden has been removed: a business that was a reporting entity before 31 March 2026 will, in most circumstances, not be required to conduct initial CDD again.
The obligation that changed for everyone is ongoing CDD. Compliance with the new ongoing CDD obligations was required from 31 March 2026, with no transition period — monitoring and the refreshing of customer information when risk changes are already being assessed against the new standard.
The ACIP Grandfathering Runs to 2029
A long transition has been allowed for one thing only. A remittance service provider that was enrolled on 30 March 2026 may keep using its existing applicable customer identification procedures, on two conditions: transitional policies — listing which classes of customer remain on the old procedures and when each will be moved — were required to be in place by 1 July 2026, and the whole transitional period ceases to have effect on 31 March 2029. A business still identifying customers under pre-reform procedures without a written transitional policy behind it is, as of July, not in transition. It is out of step.
The Suspicious Matter Report Form Changed on 1 July 2026
New threshold transaction report and suspicious matter report forms were introduced in AUSTRAC Online from 1 July 2026. Who is required to use the new SMR form depends on when the business was enrolled: an entity enrolled after 30 March 2026 has been required to use it since 1 July, while an entity that was already reporting may transition at any time between 1 July 2026 and 30 March 2029.
The content has been expanded, not just the layout. The new form asks for the information required under Division 1 of Part 9 of the AML/CTF Rules 2025 — now including the individual who completed the report and who can speak to the suspicion, and, where relevant, online activity, the products or instruments involved, transfers of property, and virtual assets. For a remitter, the last two are the fields that will need thought: a corridor payment through an affiliate network has a structure the old free-text form let a reporter leave implicit.
The Deadlines Have Not Moved, but the Quality Bar Has
The statutory clock is unchanged. Under section 41(2) of the Act, a suspicious matter report is required within three business days after the day on which the suspicion is formed, or within 24 hours where it relates to terrorism financing. What has been raised is the expectation of what is submitted inside that window. Among AUSTRAC’s stated outcomes for 2026–27 is that “reporting entities provide higher quality suspicious matter reports,” with the reasoning given plainly — “High-quality, accurate and timely reports give us and our partners the best chance to detect, deter and disrupt criminal and terrorist activity” — and the follow-through stated too: “We will engage with reporting entities and cohorts whose SMRs are consistently poor quality.”
Scale is part of why. More than 450,000 SMRs and more than two million threshold transaction reports were received by AUSTRAC in the last year, and a 77 per cent increase in SMRs from payment platforms was recorded in 2025–26. Volume is not the problem being solved; reports that cannot be acted on are. A point about triage is added by AUSTRAC’s own guidance: “What’s timely depends on the level of risk. We expect you to prioritise reviewing and responding to higher risk matters more urgently.”
International Transfers: IFTI Continues, the Travel Rule Applies Now
International funds transfer instruction reporting was not changed by the 1 July forms and continues until 31 March 2029, when the transition to international value transfer service reporting is scheduled. The travel rule, by contrast, is already live for remittance service providers: payer information and the payee’s full name are required to be collected and verified before a transfer message is passed on, and records kept for seven years. If those fields are populated after the message is sent, or from a field the system does not verify, the rule is being met on paper only.
Two Smaller Items, One of Them Already Overdue
Enrolment and registration. Between 31 March and 30 May 2026, enrolment details — including the AML/CTF compliance officer — were required to be updated in AUSTRAC Online. That window has closed. Registration details are also required to be updated with the additional information the new laws call for, before the next scheduled renewal.
Tipping off. This one is easy to get the date wrong on. The rewritten offence — disclosure that “would or could reasonably be expected to prejudice an investigation,” carrying imprisonment for two years or 120 penalty units — commenced on 31 March 2025, a year before the main reforms. What arrived in 2026 is the obligation to maintain AML/CTF policies to prevent tipping off, as part of the program itself. The exception for disclosure between reporting entities under section 123(5) is not yet in operation.
What Should Be Done This Month
- The program should be checked for its two required parts — a risk assessment and the policies that flow from it — and the assessment should engage with AUSTRAC’s published high-risk rating, corridor by corridor.
- If the enrolment update due by 30 May was missed, it should be completed now; registration details should be updated before the next renewal.
- Transitional CDD policies should be confirmed as written and dated on or before 1 July 2026, with a class-by-class switch-over plan ahead of 31 March 2029.
- SMR templates and system fields should be mapped to Division 1 of Part 9 of the Rules, and higher-risk-first triage written into the escalation procedure.
- The travel rule should be tested, not assumed: payer and payee data verified before a message is released, seven-year retention confirmed.
- The first independent evaluation should be scheduled against the later of the four-year mark and 31 March 2027.
A closing note on posture. AUSTRAC’s words were balanced in both directions: “AUSTRAC does not expect perfection on day one,” and, in the same statement, “Failing to manage your ML/TF risk is a serious regulatory concern now.” The 2026–27 intervention focus was named as entities in sectors regulated before 31 March “who don’t manage their ML/TF risks effectively” — a remitter is squarely in that sentence. What is being asked for is not more rules followed but more reasoning shown, and more weight is therefore put on the audit trail behind each decision than on the rulebook itself.
The same shift from fixed rules to documented judgement was seen in the UK’s June 2026 amendments, and what moved there for payment firms is set out in a companion post. Cited regulatory answers of exactly this kind, across both jurisdictions, are provided by ARGOS.
Cited answers, an audit-ready trail, and PEP & sanctions screening.A free workspace can be started in minutes, no sales call required.
Start freeSources
- Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (No. 110, 2024), Federal Register of Legislation. Assent and the commencement table are in section 2.
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006, Compilation No. 62 (1 July 2026), Federal Register of Legislation. SMR deadlines are in section 41(2); the tipping-off offence is in section 123.
- Anti-Money Laundering and Counter-Terrorism Financing (Transitional) Rules 2026, Federal Register of Legislation. ACIP transition in section 7; IFTI/IVTS transition in sections 9 and 10; independent evaluation timing in section 16; enrolment update in section 18.
- About the AML/CTF reforms, AUSTRAC.
- AML/CTF Transitional Rules 2026, AUSTRAC.
- Your AML/CTF program — overview and Overview of customer due diligence, AUSTRAC.
- Suspicious matter reports, New AUSTRAC Online reporting forms are coming (30 June 2026), and Changes to transaction reporting from 1 July 2026 (28 May 2026), AUSTRAC.
- Our regulatory priorities 2026–27 and AUSTRAC regulatory expectations: implementation of the AML/CTF reforms (4 July 2025), AUSTRAC.
- Tipping off, Travel rule — overview, and Register with us — remittance or virtual asset service provider, AUSTRAC.
- Independent remittance dealers in Australia — ML/TF risk assessment (2022) and Quick guide: ML/TF risk assessment framework for remittance service providers (January 2026), AUSTRAC.
- Independent remitters told to “use it or lose it” in AUSTRAC registration blitz (6 August 2025), Federal Court imposes penalties after businesses fail to pay AUSTRAC infringement notices (27 May 2026), and Consequences of not complying, AUSTRAC.
AUSTRAC website material is quoted under AUSTRAC’s Creative Commons licence and attributed as requested: © AUSTRAC for the Commonwealth of Australia 2019. The independent remittance dealers risk assessment is licensed under Creative Commons Attribution 4.0 International. Statutory text is quoted briefly and attributed to the Commonwealth of Australia via the Federal Register of Legislation.
This post is a summary of the reforms as they have been read here and does not constitute legal advice. The Act, the Rules and AUSTRAC’s guidance should be checked before any control is changed.