What would you do if a seemingly normal customer transaction turned out to be linked to money laundering?
For many Australian businesses, that is no longer a question they can afford to ignore.
AML/CTF compliance is the framework regulated businesses use to identify, assess and manage the risks of money laundering, terrorism financing and other forms of financial crime. In practice, that can mean checking who your customers are, understanding where risks may arise, monitoring activity, maintaining appropriate controls and knowing when something needs to be escalated or reported.
These responsibilities now affect a broader range of Australian businesses. Since 1 July 2026, Australia’s AML/CTF reforms have expanded the regime to cover additional designated services commonly provided across legal, accounting, real estate, conveyancing and other professional-service sectors.
If terms such as designated services, customer due diligence or AML/CTF programme still sound unfamiliar, that is exactly where this guide comes in. We will break down what AML/CTF compliance actually means, who it applies to and how the main requirements fit together in practice.
For the wider regulatory landscape, you can also read our complete guide to anti-money laundering in Australia.
If you want a broader view of how Australia’s AML/CTF framework works, including the legislation, regulatory changes and key obligations for businesses, read our complete guide to anti-money laundering in Australia.
What Is AML/CTF Compliance?
At its simplest, AML/CTF compliance is about preventing a business from being used to move, hide or legitimise money connected to crime or terrorism.
That sounds straightforward, but in practice the risk can be difficult to spot. A customer may appear legitimate, a transaction may look routine and the business relationship may seem perfectly normal. AML/CTF compliance gives organisations a structured way to recognise when something does not quite fit and decide what action may be needed.
The acronym itself combines two closely related areas.

AML, or anti-money laundering, focuses on preventing criminals from disguising the origins of illegally obtained money and making those funds appear legitimate. Money laundering can involve moving funds through businesses, accounts, assets or transactions in ways designed to make the money look as though it came from a lawful source.
CTF, or counter-terrorism financing, focuses on preventing money or other assets from being collected, transferred or used to support terrorist activity. One important difference is that terrorism financing does not always begin with criminal proceeds. The money itself may originally come from a legitimate source, but the way it is ultimately used creates the risk.
If you want to understand that distinction in more detail, we have broken it down in our guide to the difference between money laundering and terrorism financing.
So where does compliance come into the picture?
For Australian businesses covered by the AML/CTF regime, compliance means understanding the financial-crime risks connected to the services they provide and putting appropriate controls in place to manage those risks.
This can include identifying where risks are most likely to arise, carrying out customer due diligence, verifying customer information, monitoring business relationships, maintaining records, reporting certain matters and making sure relevant employees understand what is expected of them.
The approach is deliberately risk based. A business should not simply apply the same process to every customer or situation without considering the actual level of risk involved. AUSTRAC's current guidance makes clear that AML/CTF programmes should reflect the specific ML/TF risks, nature, size and complexity of the reporting entity.
For example, a straightforward customer relationship may require standard controls, while a more complex ownership structure, unusual transaction pattern or higher-risk jurisdiction could require greater scrutiny. The purpose is not to assume that unusual behaviour is criminal. It is to make sure the business knows when further questions or additional action may be appropriate.
This is why AML/CTF compliance should not be viewed as one form, one identity check or one policy sitting in a folder. It is an ongoing system of risk assessment, policies, procedures, monitoring and decision-making that needs to remain relevant as customers, services and risks change.
Australia's AML/CTF framework is regulated by AUSTRAC, Australia's financial intelligence agency and AML/CTF regulator. AUSTRAC oversees reporting entities and provides guidance on areas such as AML/CTF programmes, customer due diligence, reporting and risk management.
In practical terms, good AML/CTF compliance helps a business answer three basic questions: What risks do we face? What controls do we have in place? And will our people know what to do when something looks unusual?
Those questions sit at the centre of an effective AML/CTF framework.
Who Needs AML/CTF Compliance in Australia?
Seeing your industry mentioned in an AML/CTF article does not automatically mean that every business in that industry has exactly the same obligations.
The more important question is: does your business provide a service that Australia's AML/CTF laws classify as a designated service?
This distinction matters because the Australian regime is primarily built around the services a business provides, not simply the industry label attached to that business.

Businesses that provide designated services covered by the regime are generally known as reporting entities. Depending on the services they provide, they may need to enrol with AUSTRAC and meet requirements relating to risk management, customer due diligence, reporting, record keeping, governance and staff training.
For example, a business may operate within an industry that is commonly associated with AML/CTF regulation but only provide certain services that fall within the regime. Another business in the same industry may offer a different range of services and therefore have different compliance responsibilities.
Australia's AML/CTF regime has long covered businesses operating in areas such as banking, financial services, remittance, gambling and certain virtual asset services. These sectors have traditionally been considered vulnerable to money laundering and terrorism financing because they can involve the movement, transfer or conversion of significant amounts of money or other assets.
However, the scope of the regime expanded significantly on 1 July 2026, bringing certain designated services commonly provided by additional professional and commercial sectors into the AML/CTF framework.
These include:
- legal services;
- accounting services;
- real estate and conveyancing;
- trust and company services; and
- dealers in precious metals and precious stones.
The expansion reflects the fact that financial crime risks are not limited to banks or other traditional financial institutions. Criminals may also attempt to misuse legitimate professional services to purchase property, establish companies or trusts, move assets or make the ownership of funds more difficult to trace.
That is why the distinction between an industry and a designated service is so important.
For example, simply being an accountant or legal practitioner does not automatically mean that every activity you perform falls within the AML/CTF regime. A professional may provide several different services, but only particular activities may meet the legal definition of a designated service.
The same principle applies to businesses in real estate, conveyancing and other newly regulated sectors. What matters is not only what type of organisation you are, but what service you are providing, who you are providing it to and whether that service is captured by the legislation.
AUSTRAC provides detailed guidance to help businesses check whether their activities are designated services. Businesses entering the AML/CTF regime should use this guidance to assess their own activities rather than assuming that the rules either automatically apply or do not apply based solely on their industry.
Once a business determines that it provides a covered service, AML/CTF compliance becomes much more than a general awareness issue. The organisation may need to establish formal systems for assessing financial-crime risk, understanding customers, monitoring activity, maintaining records and ensuring that employees know how to respond when something unusual occurs.
For businesses that have only recently come within the expanded regime, this can represent a significant change in day-to-day operations. AML/CTF responsibilities may affect customer onboarding, internal approval processes, documentation, staff responsibilities and the way higher-risk situations are handled.
The first step, therefore, is not to ask, “Is my industry regulated?” It is to ask, “Which services does my business provide, and are any of them designated services under Australia's AML/CTF regime?”
That question determines what comes next.
How Does AML/CTF Compliance Work?
AML/CTF compliance works through a risk-based approach. In other words, businesses are not expected to apply identical controls to every customer, service or situation. They need to understand where their money laundering, terrorism financing and proliferation financing risks are highest, then put proportionate controls in place to manage them.
For reporting entities, that usually starts with an AML/CTF programme tailored to the nature, size and complexity of the business. AUSTRAC explains that the programme should bring together the organisation’s risk assessment with the policies, procedures, systems and controls used to manage those risks.

Start by understanding the risks
Before a business can control financial crime risk, it needs to know where that risk may arise.
An AML/CTF risk assessment should consider factors such as the designated services the business provides, the types of customers it deals with, how those services are delivered and any countries or jurisdictions connected to the relationship.
This matters because a higher-risk customer or transaction may require a different response from one presenting relatively low risk.
Know who you are dealing with
Customer due diligence, or CDD, is another central part of AML/CTF compliance.
It involves identifying and verifying customers, understanding relevant risks and continuing to monitor the relationship over time. You may also see this described as Know Your Customer (KYC).
AUSTRAC describes identification, verification and monitoring as the three core elements of customer due diligence.
Importantly, this is not simply a check completed when the customer first walks through the door. Customer circumstances, ownership structures and behaviour can change, which is why ongoing monitoring matters.
Monitor activity and respond to concerns
Suppose a customer's behaviour suddenly changes, transactions no longer appear consistent with what the business knows about them, or new information changes their risk profile.
That does not automatically mean criminal activity has occurred. It does mean the business may need to investigate further, reassess the risk and follow its internal AML/CTF procedures.
Depending on the circumstances, certain matters may also need to be reported to AUSTRAC.
Keep records and clear accountability
Effective AML/CTF compliance also depends on being able to show what the business did and why.
That means maintaining appropriate records, assigning governance responsibilities and ensuring relevant decisions are properly documented. Reporting entities must also establish responsibilities for senior management, the governing body and an AML/CTF compliance officer as part of their governance framework.
Make sure staff know what to do
Even a strong AML/CTF programme can fail if the people expected to apply it do not understand their role.
Relevant staff need to know the risks associated with their work, the procedures they are expected to follow and what to do when something unusual occurs. This is why employee awareness and AML/CTF training form an important part of an effective compliance framework.
For a more detailed breakdown of these requirements, see our guide to AML/CTF compliance obligations for Australian businesses.
What Does AML/CTF Compliance Look Like in Practice?
The rules make more sense when you see how they could play out in an ordinary business situation.

Imagine an Australian accounting firm is asked to provide a designated service to a new corporate client. At first glance, nothing appears unusual. But during customer due diligence, the firm discovers a complex ownership structure involving several entities in different jurisdictions, and the information provided about the people who ultimately control the company is incomplete.
That does not automatically mean the customer is involved in money laundering or terrorism financing. It does, however, give the firm a reason to look more closely.
The business may need to reassess the customer's risk, obtain further information, follow its AML/CTF procedures and document the steps it takes. If unusual transactions or behaviour later emerge, those issues may need to be internally escalated and reviewed.
AUSTRAC requires reporting entities to monitor customers for unusual transactions and behaviour as part of ongoing customer due diligence. Where there are reasonable grounds for suspicion, a suspicious matter report may also be required.
That is AML/CTF compliance in practice: notice the risk, investigate appropriately, follow the business's controls, document the decision and escalate or report when the legal requirements are met.
The goal is not to expect employees to become investigators. It is to make sure they can recognise when something does not fit the expected picture and know what to do next.
What Changed for Australian Businesses in 2026?
The biggest change in 2026 is that Australia’s AML/CTF regime now reaches far beyond the sectors traditionally associated with financial crime compliance.
Changes for businesses already regulated under the AML/CTF Act began on 31 March 2026, including updates to programme requirements and customer due diligence. Then, from 1 July 2026, the regime expanded to certain designated services commonly provided by legal professionals, accountants, conveyancers, real estate professionals, trust and company service providers, dealers in precious metals and stones, and some virtual asset businesses.
For newly regulated businesses, that means AML/CTF compliance is no longer something to prepare for in the future. The obligations are now in force.
Depending on the services provided, businesses may need to maintain an AML/CTF programme, conduct customer due diligence, appoint an AML/CTF compliance officer, train relevant staff, keep appropriate records and report certain matters to AUSTRAC. You can read AUSTRAC’s overview of the 2026 AML/CTF reforms and the businesses affected.
The reforms also reinforce a broader shift towards risk-based compliance. Rather than treating AML/CTF as a box-ticking exercise, businesses are expected to understand the specific money laundering, terrorism financing and proliferation financing risks they face and apply controls that are appropriate to those risks.
For organisations that were already regulated before 2026, this also means reviewing existing systems rather than assuming previous processes will automatically satisfy the updated framework.
Why AML/CTF Training Matters
An AML/CTF programme is only useful if the people expected to follow it understand what they are looking for and what they need to do next.
Think about the employees who onboard customers, verify identities, monitor transactions, handle unusual activity or escalate concerns. If they do not understand the risks relevant to their role, even well-designed policies can break down in practice.
That is why AML/CTF training is a core part of the compliance framework. AUSTRAC requires businesses to provide AML/CTF training to personnel whose roles are relevant to their obligations. Training should be appropriate to the employee’s responsibilities and the money laundering, terrorism financing and proliferation financing risks they may encounter.
For example, customer-facing staff may need to recognise suspicious behaviour and understand escalation procedures, while employees responsible for customer due diligence may require deeper knowledge of identity verification, beneficial ownership and customer risk.
Training should also be ongoing rather than treated as a one-off induction exercise. Regulatory changes, emerging risks and updates to internal AML/CTF procedures can all change what employees need to know.
For organisations building this capability, our Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) training is designed to help learners understand Australian AML/CTF requirements and apply the core concepts in a workplace context.
