anti money laundering
Oct 03, 2026
12min read

AML Red Flags in Australia: 10 Warning Signs to Watch for in 2026

Australian compliance professional reviewing AML red flags and suspicious transaction activity

AML red flags are behaviours, transaction patterns or circumstances that may indicate money laundering, terrorism financing or other suspicious activity. They can include inconsistent identity information, unusual transactions, unexplained sources of funds, complex ownership structures and activity that simply does not fit what a business reasonably knows about a customer.

But a red flag is not proof of wrongdoing.

AUSTRAC makes this distinction clear. An individual indicator may have a legitimate explanation, and suspicious activity needs to be assessed in context. Several warning signs appearing together, or activity that is inconsistent with a customer's known circumstances, may warrant closer examination.

That distinction matters even more in 2026 as Australia's AML/CTF framework changes. Rather than treating red flags as a checklist of “bad customers”, businesses need staff who can recognise unusual activity, understand the context and escalate concerns appropriately.

What is an AML red flag?

An AML red flag is information, behaviour or activity that may indicate increased concern about money laundering or terrorism financing risk.

Three related ideas are worth separating:

  • Risk factor: a characteristic or circumstance associated with increased money laundering or terrorism financing risk.

  • Red flag: behaviour, information or activity that appears unusual and may need further examination.

  • Reasonable grounds for suspicion: an objective assessment based on the available facts and circumstances that can become relevant to a reporting entity's Suspicious Matter Report obligations.

According to AUSTRAC guidance on suspicious matter reports, reasonable grounds require more than a vague feeling that something is wrong. The assessment considers the facts, circumstances and information available.

A useful starting point is inconsistency. Does the customer's behaviour match their profile? Does the transaction make sense given what is known about them? Can the source of the money be reasonably explained? Does the ownership structure have an apparent commercial purpose?

Businesses that need a broader explanation of the regulatory framework can read ACT's guide to AML/CTF compliance obligations for Australian businesses.

10 common AML red flags Australian businesses should recognise

The following warning signs reflect themes in current AUSTRAC guidance. They are indicators, not automatic evidence that a customer has committed an offence. Their significance depends on the circumstances, the business's risk profile and what else is known about the customer.

10 common AML red flags Australian businesses should recognise in 2026

1. A customer avoids or resists identity checks

Difficulty completing legitimate customer identification can be an important warning sign.

For example, a customer may:

  • Resist providing requested identification;

  • Give vague or inconsistent information;

  • Provide documents containing unexplained differences in names, addresses or dates of birth;

  • Submit documents that appear altered or unusual; or

  • Suddenly end the relationship when further information is requested.

AUSTRAC identifies attempts to avoid know your customer processes, reluctance to prove identity and inconsistent identification information among potential suspicious-activity indicators.

The important issue is not that a customer asks questions about identification requirements. It is whether their behaviour or information creates an unexplained inconsistency that requires further attention.

2. Customer behaviour does not fit their stated circumstances

Sometimes the concern is not a single transaction but the wider picture.

A customer might claim to operate a particular business but appear unable to explain basic aspects of that business. Their transactions may not align with their occupation, financial position or stated commercial activity. They may also appear to be following the instructions of an undisclosed third party.

AUSTRAC's suspicious activity indicators include behaviours such as secrecy, evasiveness, inconsistent information and unexplained third-party involvement.

Staff should focus on objective inconsistencies rather than stereotypes. Nationality, ethnicity, or simply appearing nervous should never be treated as proof of suspicious activity.

3. Transactions are unusual for the customer

A transaction becomes more noteworthy when it is significantly different from what the business would reasonably expect.

Examples could include:

  • Sudden high-value activity after a long inactive period;

  • A sharp change in transaction frequency;

  • Unusually large transactions compared with the customer's normal activity;

  • Rapid movement of money between accounts or parties; or

  • Repeated transactions with no apparent commercial purpose.

The key question is not simply, “Is this transaction large?”

It is, “Does this activity make sense given what we know about this customer?”

A legitimate customer may have a perfectly reasonable explanation for a change in activity. The role of the red flag is to prompt appropriate review, not to predetermine the outcome.

4. Transactions appear deliberately structured

Structuring generally involves splitting transactions into smaller amounts, potentially to avoid reporting or detection.

For example, instead of conducting one transaction, a person may make a series of smaller transactions over several days or through different accounts without a clear reason.

AUSTRAC's current suspicious matter guidance gives examples of payments deliberately divided into amounts below $10,000. It also describes a scenario involving repeated cash deposits between $7,000 and $9,900 where other information about the customer's circumstances strengthened the concern.

A transaction being below $10,000 is not itself suspicious. The relevant issue is the pattern, surrounding behaviour and whether there is a reasonable explanation.

5. The source of funds or wealth does not make sense

An unexplained source of money can be one of the more important AML warning signs.

Concerns may arise where:

  • A customer's funds do not match their known income or financial position;

  • High-value assets appear without an understandable funding source;

  • The customer cannot or will not explain where money came from;

  • Supporting information conflicts with other available information; or

  • Unusually complex or large transactions have no apparent legitimate purpose.

AUSTRAC distinguishes source of funds, meaning how the money for a particular transaction was obtained, from source of wealth, meaning how a person's overall wealth was accumulated.

Its guidance on source of funds and source of wealth explains that checks should be proportionate to the customer's risk and can be particularly relevant where activity does not align with what is already known about the customer.

6. Third-party payments have no clear explanation

Third-party involvement is common in legitimate business. It becomes more important when nobody can clearly explain why the third party is involved.

Examples include an unrelated person funding a transaction, payments moving to or from parties with no apparent connection to the customer, or a customer appearing to act entirely under another person's instructions.

The right response is not to assume the arrangement is improper. It is to understand the relationship and determine whether the explanation makes commercial and factual sense.

Unexplained third-party involvement can become more significant when combined with other AML red flags, such as inconsistent identification or unclear beneficial ownership.

7. Ownership or business structures are unnecessarily complex

Complex structures are not automatically suspicious. Companies, trusts and layered ownership arrangements can have legitimate tax, investment, succession or commercial purposes.

Concern can arise when complexity appears to serve no clear legitimate purpose or makes it unnecessarily difficult to understand who ultimately owns or controls an entity.

Potential indicators include:

  • Difficulty identifying the beneficial owner;

  • Multiple layers of companies or trusts without a clear rationale;

  • Nominee arrangements that cannot be reasonably explained;

  • Frequent or unexplained changes of ownership; or

  • Shell or shelf companies appearing alongside other warning signs.

AUSTRAC highlights arrangements that obscure beneficial ownership and complicated structures without an apparent legitimate or economic reason as relevant risk indicators.

8. International activity has no obvious connection to the customer

International transactions are a routine part of Australian business and are not inherently suspicious.

The concern is unexplained international activity.

For example, a customer may transfer money to countries with no apparent connection to their residence, family, investments or business. They may use several foreign bank accounts without a clear purpose, move funds through multiple jurisdictions, or make unusual payments to offshore entities.

The level of concern can increase where transactions also involve jurisdictions associated with elevated financial-crime risks or sanctions.

Again, context matters. A company importing goods from overseas will naturally have international payments. The question is whether the activity is consistent with the customer's known business and circumstances.

9. Sanctions, PEP or adverse information raises additional risk

Some factors signal that additional risk assessment may be necessary, but they should not be confused with proof of criminal conduct.

A politically exposed person, or PEP, is not automatically suspicious. Nor is a foreign customer suspicious because of their nationality.

However, PEP status, relevant and credible adverse information, connections to higher-risk jurisdictions or sanctions exposure can affect the level of customer due diligence required. AUSTRAC's current customer due diligence guidance treats these as matters that may require additional controls depending on the customer's circumstances and risk.

These factors become more meaningful when they appear alongside unusual transactions, unexplained wealth, inconsistent customer information or other concerns.

For a broader distinction between financial-crime risks, see ACT's guide to Money laundering vs terrorism financing.

10. The customer requests unusual or unnecessarily complex arrangements

Sometimes the requested service itself does not appear to make sense.

A customer might:

  • Repeatedly change instructions without a reasonable explanation;

  • Demand unusual urgency;

  • Request unnecessary layers of intermediaries;

  • Seek anonymity without a credible reason; or

  • Prefer a highly complex structure when a straightforward arrangement would achieve the stated commercial objective.

AUSTRAC lists unusual requests with no clear economic reason, repeated unexplained changes to instructions and unnecessarily complex arrangements among relevant suspicious indicators.

The strongest warning sign is often not complexity by itself. It is complexity that cannot be sensibly connected to the customer's stated objective.

One red flag does not automatically mean money laundering

AML compliance works poorly when every unusual event is treated as proof of misconduct.

AUSTRAC expressly notes that one indicator on its own may not amount to suspicious activity because there may be legitimate reasons for a customer's behaviour or transaction. Depending on the circumstances, several indicators may need to be considered together.

Consider the difference:

One unusually large transaction:
The customer may have sold an asset, received an inheritance or completed a legitimate business deal.

An unusually large transaction + unexplained funds + inconsistent identification + an unexplained third party:
The combination raises more questions and may justify closer examination.

Comparison showing one AML red flag versus multiple suspicious activity indicators

Businesses should therefore consider the customer's risk, transaction history, source of funds and wealth, known circumstances and any reasonable explanation for the activity.

The aim is not to label customers. It is to spot inconsistencies, assess them objectively and respond appropriately.

What should staff do when they notice an AML red flag?

Frontline employees are often the first people to notice that something does not fit. They do not necessarily need to decide whether money laundering has occurred.

A practical response usually follows five steps. 

Five-step process for staff responding to AML red flags in Australia

1. Notice and document the unusual activity

Record the relevant facts in line with your organisation's AML/CTF policies and procedures. Avoid assumptions or subjective conclusions where objective information is available.

2. Escalate the concern internally

Follow the organisation's reporting pathway. Depending on the business, this may mean referring the matter to an AML/CTF compliance officer, manager or specialist financial-crime team.

3. Review the activity in context

The responsible person may consider the customer's risk rating, transaction history, identity information, source of funds or wealth, possible third-party involvement and whether there is a legitimate explanation.

4. Determine whether reasonable grounds for suspicion exist

For reporting entities, this is an objective assessment based on the available facts and circumstances. AUSTRAC states that certainty that a crime occurred is not required before an SMR obligation can arise.

5. Report where legally required

Where a reporting entity forms a suspicion on reasonable grounds in circumstances covered by the AML/CTF Act, a Suspicious Matter Report may be required.

AUSTRAC's current approach can be summarised as identify → review → determine whether reasonable grounds exist → submit where required. Its guidance also expects customer-facing personnel generally to be trained to recognise suspicious activity and refer it to the appropriate person.

For the detailed reporting framework, see ACT's guide to AUSTRAC reporting requirements for Australian reporting entities and AUSTRAC's suspicious matter reporting guidance.

Why AML red-flag awareness matters more in Australia's 2026 environment

Australia AML CTF 2026 timeline showing 31 March and 1 July commencement datesAustralia's AML/CTF framework changed significantly in 2026.

Reformed requirements affecting existing reporting entities commenced on 31 March 2026, although transitional arrangements apply to some obligations. The AML/CTF Transitional Rules provide, among other things, transitional arrangements for initial customer due diligence.

Newly regulated Tranche 2 entities providing relevant designated services became subject to AML/CTF obligations from 1 July 2026. The expansion includes certain designated services provided by legal professionals, accountants, real estate professionals, dealers in precious metals and stones, and other newly regulated businesses.

The Australian Government overview of the AML/CTF reforms explains the wider changes and commencement arrangements.

For a fuller ACT explanation without repeating it here, see Australia's AML/CTF reforms in 2026.

AML red-flag training helps staff recognise when something does not fit

Good AML awareness is not about memorising a list and assuming every listed behaviour is criminal. It is about helping staff recognise when activity does not fit the expected pattern, then follow the right internal process.

Training can help employees:

  • Identify relevant customer and transaction warning signs;

  • Distinguish unusual activity from automatic wrongdoing;

  • Recognise when several indicators together deserve attention;

  • Understand internal escalation responsibilities; and

  • Know when to seek guidance rather than making unsupported assumptions.

AUSTRAC states that AML/CTF policies must support personnel in recognising suspicious activity and following reporting processes. Its current guidance also says it generally expects customer-facing personnel to be trained to identify suspicious activity and refer to it appropriately.

ACT's guide explains more about who needs AML training in Australia.

For organisations building staff capability, Australian Compliance Training's Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) course provides structured learning on AML/CTF risks, suspicious activity and practical compliance awareness.

Recognise the pattern, not just the individual warning sign

AML red flags are most useful when they help staff recognise activity that deserves closer attention, not when they are treated as automatic evidence of wrongdoing.

A single unusual transaction may be legitimate. Concern becomes stronger when activity does not fit the customer's known profile, explanations do not make sense, or several warning signs appear together.

For Australian businesses subject to AML/CTF obligations, the practical goal is straightforward: recognise unusual activity, assess it in context, document relevant facts and escalate concerns through the correct process.

Frequently Asked Questions

There is no single red flag that is always the most common or important. A recurring theme in AUSTRAC guidance is activity that does not fit what is known about the customer, such as unusual transactions, inconsistent identity information, unexplained funding or behaviour that differs significantly from the customer's expected profile.

No. A single AML red flag may have a legitimate explanation. AUSTRAC advises that one indicator may not amount to suspicious activity and that multiple indicators may need to be assessed depending on the circumstances. A red flag should prompt appropriate attention and review, not an automatic conclusion.

Examples include unusual transaction size or frequency, abrupt changes in activity, rapid movement of funds, unexplained third-party transactions, transactions inconsistent with the customer's profile and apparent structuring. These indicators should always be considered in context.

Not necessarily. Employees should follow their organisation's internal escalation procedures. For reporting entities, the relevant personnel then assess whether there are reasonable grounds for suspicion and whether an SMR is required. ACT's guide to AUSTRAC reporting requirements covers the reporting process in more detail.

No. Being a politically exposed person is a risk factor, not proof of money laundering or other criminal activity. PEP status can affect the customer due diligence required under Australia's AML/CTF framework, but businesses still need to assess the customer's circumstances and risk rather than treating PEP status itself as suspicious.