FAQ

What are the updated suspicious matter reporting rules in Australia?

AUSTRAC expects reporting entities to continue lodging suspicious matter reports (SMRs) promptly where there are reasonable grounds to suspect financial crime, with timing based on the risk involved. Under the 2026 reforms, the core SMR framework remains, but expectations increase around timely detection, escalation, and well-documented reasoning.

Expanded Answer

Suspicious matter reporting remains a central obligation under Australia’s AML/CTF regime. Reporting entities must submit an SMR to AUSTRAC when they form a suspicion that a matter may involve money laundering, terrorism financing, or other serious offences. Timeframes are risk-based: generally within 24 hours for terrorism-related matters and within three business days for other suspicions.

The 2026 reforms do not fundamentally change SMR triggers or timing, but AUSTRAC’s expectations around quality and governance are increasing. Firms are expected to detect suspicious behaviour through effective monitoring, escalate concerns internally without delay, and clearly document the basis for suspicion. This includes linking customer risk, transaction activity and behavioural indicators in a coherent assessment.

Risk increases where firms treat SMRs as reactive or compliance-driven rather than risk-driven. Common issues include delayed escalation, poor documentation of suspicion, and failure to connect monitoring alerts to customer risk profiles. For advisers and licensees, SMR processes should align with broader breach-reporting and incident-management frameworks. See AML/CTF financial planners Australia and Five AML questions you must be able to answer.

Why it matters

SMRs are a key focus for AUSTRAC supervision. Weak detection, delayed reporting or poorly evidenced decisions can signal broader control failures, increasing the likelihood of regulatory scrutiny and enforcement action.

Practical guidance

  • Define clear escalation pathways for suspicious activity and train staff to recognise triggers.
  • Document the rationale for suspicion, linking customer risk, behaviour and transaction patterns.
  • Test monitoring systems to ensure alerts are reviewed, escalated and resolved in a timely way.

Further reading

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?