AML Compliance Guide

What are my AML/CTF obligations?

Once you're captured by Tranche 2, your AML/CTF obligations break down into a handful of concrete activities: enrol with AUSTRAC, assess your risk, write a program, check your customers' identities, keep records, and report anything suspicious. None of these require legal training to understand at a working level — here's what each one actually means.

Last updated 13 July 2026

Sound familiar?

  • Every explanation you find is written in legal or regulatory language.
  • You don't know if 'customer due diligence' means the same thing for your business as it does for a bank.
  • You're worried you'll miss an obligation buried in a 200-page act.

The core obligations, in plain English

  • Enrol with AUSTRAC — register your business details in AUSTRAC Online so the regulator knows you exist and what services you provide.
  • Appoint a compliance officer — nominate someone (often the business owner, for small firms) responsible for AML/CTF compliance.
  • Assess your ML/TF risk — write down the money laundering and terrorism financing risks specific to your clients, services, and delivery channels.
  • Build an AML/CTF program — a written policy describing how you'll manage the risks you identified.
  • Verify customer identity (CDD) — check who your clients and their beneficial owners actually are before providing services.
  • Keep records for 7 years and report suspicious matters to AUSTRAC when something doesn't add up.

Does all of this apply equally to every business?

No. The AML/CTF regime is risk-based and proportionate — a sole trader conveyancer with a handful of local clients has a much simpler program than a national real estate franchise. The obligations are the same in name, but the depth of documentation and process scales with your risk and size.

Glossary shortcut

If a term like 'designated service', 'beneficial owner', or 'reporting entity' doesn't make sense, the terminology glossary defines every term used across AUSTRAC guidance.

Where this leaves you

You have a working mental model of the five to six things AML/CTF compliance actually requires, in the order you'd normally do them.

Still not sure if any of this actually applies to your business? Check if you're a reporting entity →

Am I covered by Tranche 2? →

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need transaction monitoring software?
Not necessarily. For most Tranche 2 professions such as accountants and lawyers, a proportionate manual process — reviewing client instructions against their known profile — is enough, provided it's consistent and documented.
Is 'customer due diligence' the same as verifying an ID?
ID verification is part of it, but CDD also includes identifying beneficial owners, understanding the purpose of the relationship, and monitoring it over time — not just a one-off check.
Who can be my compliance officer?
AUSTRAC requires someone at management level with the authority and access to fulfil the role. For sole practitioners and small firms, this is typically the owner or a partner.
What counts as a 'suspicious matter'?
Anything that gives you reasonable grounds to suspect a client is involved in money laundering, terrorism financing, or another relevant offence — it must be reported to AUSTRAC within set timeframes, and you cannot tell the client you've made the report.

This is general information, not legal advice. Always verify current requirements on the AUSTRAC website or seek professional advice for your specific situation.