AML Compliance Guide

AML/CTF program for Trust and company service providerss — 2026 AUSTRAC Guide

If your business provides trust and company services that are designated services from 1 July 2026, you must have a written AML/CTF program. For trust and company service providers, this matters because your work can involve setting up companies, acting through corporate structures, managing trusts, or arranging nominee or directorship services that can be misused to hide ownership or move criminal wealth. If you do not put a compliant program in place by 31 December 2026, AUSTRAC can take enforcement action, civil penalties can reach $33.5 million per contravention, and intentional breaches can also lead to criminal penalties.

Your AML/CTF program is the written system your business uses to identify risk and control it in day-to-day work. It has two parts. The first is your ML/TF risk assessment, which must identify and assess the money laundering, terrorism financing and proliferation financing risks in your customer base, service lines, delivery channels and jurisdictions. The second is your AML/CTF policies, procedures, systems and controls that manage those risks when you form companies, provide registered office or business address services, act as a trustee or nominee, arrange shareholders or directors, or provide similar trust and company services that are designated services.

Deadline and approval

Your AML/CTF program must be written and approved by senior management, and it must be finalised by 31 December 2026. You need to complete the ML/TF risk assessment before you finalise the program.

What a trust and company service provider should do now

  • Map exactly which of your services are designated services. Do not assume every corporate or administrative job is covered, but do identify services involving company formation, trust structures, nominee arrangements, office address services and control over client entities.
  • Write a risk assessment that reflects how your practice actually works: private company setups, shelf company transfers, discretionary trusts, foreign controllers, use of mail or virtual office addresses, and instructions received remotely through intermediaries.
  • Build procedures for customer due diligence, beneficial owner checks, PEP and sanctions screening, escalation of unusual structures, suspicious matter reporting, and seven-year record retention.
  • Get the program approved by the owner, directors or other senior managers who control the business, then train staff who onboard clients, prepare entity documents, handle client funds or maintain company and trust records.
  • Update the program when your business changes materially, such as expanding into overseas client work, adding nominee services, or taking instructions through referral networks or digital platforms.

A common mistake in this sector is using a generic template that talks about banking-style transactions but says nothing about layered company ownership, trust deeds, settlors, protectors, nominee shareholders, or informal controllers. Another is treating ASIC extracts as the full answer on ownership and control. Your program needs a practical process for finding the real natural person behind the structure, including anyone who holds 25% or more or exercises effective control even if they are not obvious from the register. It also needs clear triggers for enhanced due diligence where there are politically exposed persons, high-risk countries, unexplained complexity, or a client asking for secrecy features without a credible commercial reason.

Practical tips for making the program workable

  • Create separate onboarding checklists for companies, trusts and other legal arrangements so staff ask for the right documents the first time.
  • Add a red-flag section for this sector, such as frequent changes in directors, chains of entities across multiple jurisdictions, backdated documents, or requests for nominee arrangements with no clear business purpose.
  • Decide who in the business can approve higher-risk clients and who can stop onboarding if beneficial ownership is unclear.
  • Keep sample file notes for how staff should record source of instructions, ownership explanations, trust relationships and reasons for escalating a matter.
  • Review the program against your actual files every few months so it reflects the clients and structures you really see, not an idealised process.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need an AML/CTF program if I only form companies occasionally for existing business clients?
If you provide a designated service, even occasionally, your business is a reporting entity and must have an AML/CTF program. The program can be proportionate to your size and risk, but it still needs to be written, approved by senior management, and based on your actual trust and company service work.
Can I buy a template AML/CTF program and use it as-is?
No. A template can help you start, but your final program must match your services, clients, delivery channels and geographic exposure. For trust and company service providers, a generic document that does not deal with beneficial ownership, trust structures, nominee arrangements and entity control is unlikely to be fit for purpose.
What if I do not provide nominee director or shareholder services, but I do provide registered office or business address services?
You still need to assess whether that service is a designated service and, if it is, include it in your AML/CTF program. Address services can create ML/TF risk because they can be used to give legitimacy to opaque or short-lived entities, so your program should cover verification, beneficial ownership checks and escalation of unusual patterns.
How much detail does the risk assessment need for a small TCSP practice?
It needs enough detail to show that you have genuinely assessed your risks rather than copied broad statements. A small practice should still document the kinds of entities it forms or administers, whether it deals with foreign owners, whether instructions are given remotely, and what controls it uses when ownership or control is hard to verify.
Who in my business should approve the AML/CTF program if I run a small firm?
Senior management must approve it. In a small practice, that will usually be the owner, directors, partners or another person with real authority over the business. Approval should be documented so you can show AUSTRAC that the program was formally adopted and is not just a draft sitting on file.