Industry Insights
What is the AML/CTF Act? A plain English guide to Australia's anti-money laundering law

What is the AML/CTF Act? A plain English guide to Australia's anti-money laundering law
If you've spent any time on this site, you've seen "the AML/CTF Act" mentioned constantly, in the starter kit guide, in our breakdown of DNFBPs, in every mention of Tranche 2. Here's the piece that's been missing: what the Act actually is, what it requires, and how it's different from the AML/CTF Rules AUSTRAC keeps updating.
What is the AML/CTF Act?
The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 is the primary Australian law that requires certain businesses, called reporting entities, to help detect and prevent money laundering and terrorism financing. It sets out who has to comply, what a compliance program needs to cover, and what AUSTRAC can do to enforce it.
The Act itself is old. What's new is the AML/CTF Amendment Act, passed by Parliament in November 2024, which rewrote large sections of it to close gaps the Financial Action Task Force had flagged in Australia's regime for years, most notably the absence of AML/CTF obligations for lawyers, accountants, real estate agents and similar professions. That's the change most people mean when they talk about the Tranche 2 reforms.
The Act versus the Rules: what's the difference?
This trips a lot of people up. The Act is primary legislation, passed by Parliament, and it sets out the framework in broad terms. The AML/CTF Rules are a separate legislative instrument that AUSTRAC issues under the Act, filling in the operational detail: exact thresholds, specific customer due diligence steps, how reporting groups work, and so on.
AUSTRAC finalised the current Rules on 29 August 2025, then amended them again on 25 March 2026 to fix issues identified after the first version took effect. If a piece of guidance cites "the Act," it's describing your legal obligation. If it cites "the Rules," it's describing how AUSTRAC expects you to meet it in practice. You need both for the full picture, and the Rules change more often than the Act does.
Who does the Act regulate?
Reporting entities, businesses that provide what the Act calls a designated service. That splits into two waves:
Tranche 1: banks, other financial institutions, casinos, and remittance and bullion dealers, regulated since the Act began.
Tranche 2: real estate professionals, precious metals and stones dealers, virtual asset service providers, and professional services like lawyers and accountants, newly regulated from 1 July 2026. Here's the full breakdown of who counts.
Whether you fall into either group depends entirely on the specific service you provide, not your job title or industry generally. A lawyer doing conveyancing work might be a reporting entity; the same lawyer doing unrelated litigation work isn't, for that part of their practice.
What the Act requires of you
Once you're a reporting entity, the core obligations are:
Enrol with AUSTRAC before you start providing the designated service, and register if you're a remittance or virtual asset provider.
Have a written AML/CTF program setting out your risk assessment and the controls, governance and training you'll use to manage it. We've written a full guide to what that program needs to cover.
Carry out customer due diligence, verifying who you're dealing with before and during the relationship, and applying stronger checks for higher-risk customers.
Report to AUSTRAC, including suspicious matters, and threshold transactions of $10,000 or more in cash.
Keep records, generally for seven years.
Appoint an AML/CTF compliance officer accountable for the program.
Reporting groups: what changed in 2026
If your business operates as part of a corporate group, the Rules changed significantly here in March 2026. The old "designated business group" concept is gone, replaced by reporting groups, and the model flipped from opt-in to opt-out. Related entities within a corporate structure now form a reporting group automatically, sharing a single AML/CTF program under one lead entity, unless a member specifically declines membership in writing. AUSTRAC's own quick guide to reporting groups sets out exactly how that works.
The lead entity carries responsibility for AML/CTF compliance across the whole group. Individual members can rely on the group's program but still carry some obligations of their own. If your business sits inside a group structure, this is worth checking now rather than assuming your existing designated business group arrangement still applies. It doesn't, automatically, past 31 March 2026.
What happens if you don't comply
AUSTRAC's penalties are real, and it enforces them even against businesses that self-report. Revolut Payments Australia disclosed its own failure to submit international funds transfer instructions on time and still received a $187,800 infringement notice. As AUSTRAC's CEO put it when announcing the penalty, reporting failures carry regulatory consequences even where reporting entities detect, disclose and report the failures themselves.
Key dates at a glance
2006: the AML/CTF Act commences
November 2024: the AML/CTF Amendment Act passes, authorising the Tranche 2 reforms
29 August 2025: AUSTRAC finalises the new AML/CTF Rules
25 March 2026: the Rules are amended, including the shift to opt-out reporting groups
31 March 2026: changes to obligations start for existing (Tranche 1) reporting entities
1 July 2026: obligations start for Tranche 2 entities, the date we mean whenever we talk about Tranche 2 taking effect
30 September 2027: first annual compliance report due under the new financial-year reporting cycle
Frequently asked questions
The Act is the primary law Parliament passed. The Rules are a more detailed legislative instrument AUSTRAC issues under the Act, covering operational specifics like thresholds and due diligence steps. AUSTRAC updates the Rules far more often than Parliament updates the Act.
Only if you provide what the Act calls a designated service, industry alone doesn't decide it. Check our guide to who counts as newly regulated under Tranche 2, or AUSTRAC's own online tool, to confirm.
A structure that lets related entities in a corporate group share a single AML/CTF program under one lead entity. Since March 2026, businesses form a reporting group by default unless they opt out in writing.
AUSTRAC can issue civil penalties and infringement notices, and it enforces them even when a business self-reports its own failure. Record keeping and program obligations exist specifically so failures can be identified and fixed before they become bigger problems.

