AML Compliance Guide

AML/CTF program for Accountants — 2026 AUSTRAC Guide

If your accounting practice provides a designated service from 1 July 2026, you must have a written AML/CTF program that fits the way your firm actually works. For accountants, this usually matters where you are involved in higher-risk transactional work or structures, not routine tax return preparation on its own. If you miss this obligation, AUSTRAC can take enforcement action, civil penalties can reach $33.5 million per contravention, and intentional breaches can also lead to criminal penalties.

Your AML/CTF program is the document set that explains how your practice will identify and manage money laundering, terrorism financing and proliferation financing risk. It has two parts. First is your written ML/TF risk assessment, covering your customers, services, delivery channels and geographic exposure. Second is your AML/CTF policies, procedures, systems and controls that deal with customer due diligence, beneficial owner checks, sanctions screening, suspicious matter reporting, record keeping, staff training and governance. AUSTRAC expects it to be approved by senior management and to reflect the real services your accounting firm provides, not a generic template.

Deadline and sequencing

You must complete the ML/TF risk assessment before you finalise the AML/CTF program, and the program must be finalised by 31 December 2026. If your firm is newly regulated, you also need to enrol with AUSTRAC by 29 July 2026, or within 28 days of first providing a designated service if you start later.

How an accounting practice should build its program

  • Map which services are actually designated services. Do not assume every engagement is caught. Tax return preparation alone is generally not a designated service for accountants.
  • Write a risk assessment based on your client base and work types, such as private company structures, trust arrangements, cross-border ownership, cash-intensive businesses, or instructions coming through intermediaries.
  • Set customer onboarding rules: what ID you collect from individuals, how you verify companies through ASIC, when you obtain trust deeds, and how you identify beneficial owners at the 25%+ threshold or people exercising effective control.
  • Document when your team must escalate matters for enhanced due diligence, including politically exposed persons, high-risk countries, unusual source of funds, complex ownership chains, or transactions that do not match the client’s profile.
  • Assign responsibility clearly: who signs off on onboarding exceptions, who reviews alerts, who files suspicious matter reports, who keeps records for 7 years, and who delivers staff training.

For accountants, the most common mistake is building the program around the profession instead of the designated service. A suburban tax practice that only prepares individual returns will not need the same controls as a firm helping clients establish companies, manage trust structures, or move funds in connection with transactions. Another common error is copying a template written for lawyers or real estate agencies. Your program should refer to accounting engagement letters, client acceptance processes, trust and company file checklists, ASIC searches, source-of-funds questions, and who in the practice can approve higher-risk matters.

Practical tips for a small firm

  • Use your existing client onboarding workflow instead of creating a separate AML process no one follows.
  • Add risk prompts to engagement acceptance forms, especially for new entities, family groups, offshore links, nominee arrangements and unexplained urgency.
  • Keep a simple decision tree for staff: proceed, escalate for enhanced due diligence, or stop and consider an SMR.
  • Train partners, managers, bookkeepers and admin staff differently based on what they actually handle, and document the training.
  • Review the program whenever the practice changes materially, such as adding business structuring work, taking on foreign clients, or opening a new office.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Does my firm need an AML/CTF program if we only prepare tax returns and BAS statements?
Not necessarily. Tax return preparation alone is generally not a designated service for accountants. The starting point is to check whether your firm provides any designated service listed in Schedule 1 of the AML/CTF Act; if not, you are not a reporting entity and do not need the program.
Can I buy a template and use it without changing much?
No. A template can help you start, but your final program must match your actual accounting services, client types, ownership structures you deal with, and internal processes. If it reads like a generic legal or real estate document, it will not properly manage your practice’s risks.
Who in a small accounting practice should approve and own the program?
Senior management must approve it, so in a small firm that will usually be the principal, director or partners. AUSTRAC guidance also says businesses may need to appoint an AML/CTF compliance officer and senior managers, so responsibility should be clearly allocated rather than left informal.
What if we outsource parts of onboarding or ID checks to software or an external provider?
You can use outsourced tools or providers, but your firm still remains responsible for compliance. Your program should say what is outsourced, how results are reviewed, who handles exceptions, and what happens if the provider cannot verify a company, trust or beneficial owner properly.
How expensive does this need to be for a small suburban practice?
The law is risk-based and proportionate, so a smaller accounting practice with limited designated services should not build a large-bank compliance framework. Keep it practical: a focused risk assessment, clear onboarding steps, sanctions screening, escalation rules, record retention, and documented training are the essentials.