From 31 March 2026, AUSTRAC expects existing reporting entities to comply with updated AML/CTF program, customer due diligence and risk assessment requirements under the reformed regime. This date marks the transition to the new AML/CTF framework for current entities, while newly regulated tranche 2 sectors begin preparing but are not yet fully subject to obligations.
Expanded Answer
The 31 March 2026 start date applies primarily to existing reporting entities already regulated under the AML/CTF Act. From this point, AUSTRAC expects entities to operate under updated AML/CTF program requirements, including clearer risk-based frameworks, revised customer due diligence (CDD) processes, and more structured governance and oversight. The reforms aim to simplify program design while strengthening how firms identify, assess and manage financial crime risk.
In practice, this means firms should have updated their AML/CTF programs, refreshed risk assessments, and aligned onboarding and monitoring processes with the new rules by this date. AUSTRAC’s position is principles-based, focusing on whether systems are effective and risk-aligned rather than prescriptive checklists. Existing reporting obligations such as suspicious matter reporting continue, but within the updated framework.
Risk increases where firms treat the date as administrative rather than operational. Weak documentation, outdated risk assessments, or poorly understood customer risk profiles are common failure points in reviews and audits. For advisers and licensees, AML settings must integrate with broader compliance systems, not sit as standalone policies. See What’s changing in 2026 under the AML/CTF reforms? and Why AML programs fail adviser audits.
Why it matters
31 March 2026 is a transition point, not a grace period. AUSTRAC is likely to assess whether firms have genuinely embedded updated AML/CTF controls, not just documented them. Failure to operationalise changes increases the risk of enforcement, remediation costs and adverse audit outcomes.
Practical guidance
- Update AML/CTF programs to reflect revised risk-based requirements and governance expectations.
- Align customer onboarding, KYC and monitoring processes with updated CDD settings.
- Test staff understanding of customer risk, escalation and reporting obligations.
Further reading