FAQ

What AML/CTF obligations start on 31 March 2026 in Australia?

From 31 March 2026, AUSTRAC expects existing reporting entities to comply with updated AML/CTF program, customer due diligence and risk assessment requirements under the reformed regime. This date marks the transition to the new AML/CTF framework for current entities, while newly regulated tranche 2 sectors begin preparing but are not yet fully subject to obligations.

Expanded Answer

The 31 March 2026 start date applies primarily to existing reporting entities already regulated under the AML/CTF Act. From this point, AUSTRAC expects entities to operate under updated AML/CTF program requirements, including clearer risk-based frameworks, revised customer due diligence (CDD) processes, and more structured governance and oversight. The reforms aim to simplify program design while strengthening how firms identify, assess and manage financial crime risk.

In practice, this means firms should have updated their AML/CTF programs, refreshed risk assessments, and aligned onboarding and monitoring processes with the new rules by this date. AUSTRAC’s position is principles-based, focusing on whether systems are effective and risk-aligned rather than prescriptive checklists. Existing reporting obligations such as suspicious matter reporting continue, but within the updated framework.

Risk increases where firms treat the date as administrative rather than operational. Weak documentation, outdated risk assessments, or poorly understood customer risk profiles are common failure points in reviews and audits. For advisers and licensees, AML settings must integrate with broader compliance systems, not sit as standalone policies. See What’s changing in 2026 under the AML/CTF reforms? and Why AML programs fail adviser audits.

Why it matters

31 March 2026 is a transition point, not a grace period. AUSTRAC is likely to assess whether firms have genuinely embedded updated AML/CTF controls, not just documented them. Failure to operationalise changes increases the risk of enforcement, remediation costs and adverse audit outcomes.

Practical guidance

  • Update AML/CTF programs to reflect revised risk-based requirements and governance expectations.
  • Align customer onboarding, KYC and monitoring processes with updated CDD settings.
  • Test staff understanding of customer risk, escalation and reporting obligations.

Further reading

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?