#AMLCompliance
Sep 24, 2026
22min read

Anti-Money Laundering in Australia: Complete Guide for 2026

Anti-money laundering in Australia concept image with compliance, risk monitoring and financial-crime prevention visuals.

Money laundering might sound like a problem limited to banks and financial institutions. In Australia, that is no longer the full picture.

The Australian AML/CTF regime now reaches a much broader range of businesses, particularly after major reforms took effect in 2026. Real estate professionals, accountants, legal service providers and other newly regulated sectors may now have responsibilities that previously sat outside their day-to-day compliance work.

But what does AML/CTF compliance actually involve?

At its core, it is about knowing who you are dealing with, understanding where the risks are, spotting activity that does not make sense and having clear processes for responding to it.

This guide breaks down how anti-money laundering works in Australia, what businesses need to understand, and how the 2026 AML/CTF reforms changed the compliance landscape.

AML/CTF in Australia in 60 Seconds

Here’s the simple version: Australia’s AML/CTF system is designed to make it harder for criminals to use legitimate businesses to move, hide or disguise illicit money.

Infographic showing how Australia’s AML/CTF system works in six simple parts.

The system is overseen by AUSTRAC and applies to businesses that provide certain designated services. That distinction matters—not every business in a particular industry is automatically regulated.

How the system fits together

Part

What it means

Law

The AML/CTF Act and supporting Rules set the framework.

Regulator

AUSTRAC supervises compliance and receives financial intelligence.

Who is covered

Businesses providing designated services may become reporting entities.

Risk controls

Businesses assess their ML/TF/PF risks and maintain an AML/CTF program.

Customer checks

Customer due diligence helps businesses understand who they are dealing with and the risk involved.

Reporting & records

Certain transactions and suspicious matters must be reported, with appropriate records kept.

In practice, the flow is much easier to understand:

Know your risks → know your customers → monitor activity → investigate concerns → report when required → keep evidence.

Those steps sit behind many of the AML/CTF compliance obligations Australian businesses need to understand.

What is anti-money laundering in Australia?

Anti-money laundering refers to the laws, systems and controls used to prevent, detect and respond to money laundering and related financial crime. In Australia, these controls form part of the broader AML/CTF regime and are applied according to the risks a regulated business faces.

What Is Anti-Money Laundering and Why Does Australia Have AML/CTF Laws?

Money laundering is essentially about making illegally obtained money look legitimate.

Criminal proceeds can come from fraud, drug trafficking, corruption, organised crime and other illegal activities. The problem for criminals is using that money without exposing where it came from. Money laundering is the process used to hide or disguise that connection.

Australia’s AML/CTF framework is designed to make that process harder by requiring regulated businesses to understand financial-crime risks, know who they are dealing with and identify activity that may warrant closer attention.

What is money laundering?

Money laundering can take many forms, but the goal is usually similar: distance money or assets from their criminal origin so they appear legitimate.

A useful way to understand the process is through three commonly recognised stages:

Placement: Illicit funds first enter the financial or commercial system.

Layering: Transactions, transfers or other arrangements are used to make the money more difficult to trace back to its source.

Integration: The funds re-enter the economy appearing to have a legitimate origin.

Real cases are not always this neat. The stages can overlap, happen in a different order or involve complex structures across multiple businesses and jurisdictions.

What is counter-terrorism financing?

Terrorism financing is related to money laundering, but there is one important difference.

Money laundering generally focuses on hiding the criminal origin of funds. Terrorism financing focuses on how funds or assets are used to support terrorist activity—and those funds can come from legitimate as well as illegal sources.

We cover this distinction in more detail in our guide to money laundering vs terrorism financing.

What is proliferation financing?

Australia’s AML/CTF framework also considers proliferation financing, often shortened alongside money laundering and terrorism financing as ML/TF/PF risk.

In simple terms, proliferation financing involves providing assets, financial services or transactions that facilitate the proliferation of weapons of mass destruction.

For businesses, the point is not to become financial-crime investigators. It is to understand the risks connected with the services they provide and apply appropriate controls when those risks arise.

That is the foundation of Australia’s risk-based approach to AML/CTF compliance: understand the risk first, then apply controls that make sense for the level and type of risk involved.

How Australia's AML/CTF System Works

Australia’s AML/CTF system is built around one simple idea: businesses facing different financial-crime risks should apply controls that match those risks.

That is why the regime is described as risk-based, rather than a one-size-fits-all checklist.

The AML/CTF Act sets the legal framework

The main law is the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, supported by the AML/CTF Rules.

Together, they set out the obligations that regulated businesses need to follow, including requirements around risk assessment, customer due diligence, reporting, record keeping and AML/CTF programs. The current compilation of the Act took effect on 1 July 2026.

AUSTRAC is the regulator and financial intelligence unit

AUSTRAC plays two roles.

It regulates businesses covered by the AML/CTF regime and checks that they have appropriate systems and controls in place. It also collects and analyses financial information that can help detect and disrupt money laundering, terrorism financing, proliferation financing and other serious crime.

Australia uses a designated-services model

One of the easiest AML concepts to misunderstand is who is actually regulated.

Australia does not simply regulate every business because it belongs to a certain industry. Instead, the regime focuses on whether a business provides a designated service covered by the legislation.

That means two businesses operating in the same industry may not always have identical AML/CTF obligations.

AML/CTF compliance is risk-based

Once a business falls within the regime, it needs to understand the money laundering, terrorism financing and proliferation financing risks connected with its customers, services, delivery methods and jurisdictions.

Those risks then shape the controls it puts in place.

In practical terms:

Higher risk → stronger controls and closer scrutiny.
Lower risk → controls that remain appropriate to the circumstances.

The goal is not to perform the maximum possible checks on every customer. It is to understand the risks the business reasonably faces and manage them through an effective AML/CTF compliance framework.

Who Must Comply With AML/CTF Laws in Australia?

Not every Australian business needs to follow the AML/CTF regime.

The key question is usually not what industry you work in, but whether your business provides a designated service covered by the law.

Infographic showing which businesses may fall under AML/CTF laws in Australia and how designated services determine coverage.

That distinction became even more important in 2026, when Australia expanded the regime to thousands of additional businesses.

Businesses already covered by the AML/CTF regime

Australia’s AML/CTF laws have long applied to businesses providing certain services across areas such as:

  • banking and financial services
  • remittance and money transfer
  • gambling
  • virtual asset services
  • other financial activities listed as designated services

A business providing a covered service generally becomes a reporting entity and must meet the AML/CTF obligations relevant to that service.

You can read the broader requirements in our guide to AML/CTF compliance obligations for Australian businesses.

Which businesses were added under the 2026 reforms?

From 1 July 2026, the regime expanded to designated services commonly provided by:

  • legal professionals
  • accountants
  • conveyancers
  • real estate professionals
  • trust and company service providers
  • dealers in precious metals, stones and related products
  • businesses providing certain additional virtual asset services

These groups are often associated with the term “Tranche 2”, although the reforms are now in force rather than an upcoming change. AUSTRAC’s current reform guidance explains which newly regulated services are covered.

For the property sector specifically, our AML/CTF compliance checklist for Australian real estate agencies looks at the requirements in more detail.

Being in a regulated industry does not automatically mean you are covered

This is where businesses can easily get confused.

An accountant, lawyer or real estate professional is not necessarily regulated simply because of their job title. The actual service being provided matters.

For example, AUSTRAC explains that some professional activities fall within the new designated-service rules while others do not, depending on what the business is actually doing for the customer. You can check the regulator’s guidance on professional designated services for specific examples.

Does AML/CTF apply to your business?

A quick way to think about it is:

  1. What services does your business provide?
    ↓
    2. Is any of that activity a designated service?
    ↓
    3. Are you providing that service in circumstances covered by the AML/CTF Act?
    ↓
    4. If yes, what enrolment, risk, CDD, reporting and record-keeping obligations apply?

If the answer is unclear, avoid relying on an industry label alone. Check your exact services against AUSTRAC’s current guidance and the legislation.

That matters because once a business is within the regime, AML/CTF is no longer just an awareness issue. It creates practical obligations around how the business assesses risk, deals with customers, monitors activity and reports certain matters.

What Are the Main AML/CTF Compliance Obligations in Australia?

Being covered by Australia’s AML/CTF regime means more than checking a customer’s ID.

Infographic summarising the main AML/CTF compliance obligations for regulated businesses in Australia.

A regulated business needs a system for understanding its financial-crime risks, knowing who it is dealing with, monitoring what happens over time and responding when something does not look right.

The exact requirements depend on the business and the designated services it provides, but the main obligations generally fit into the following framework.

Obligation

What it means in practice

Enrolment and registration

Make sure your business is appropriately enrolled or registered with AUSTRAC where required.

Risk assessment

Identify how your business could be exposed to money laundering, terrorism financing or proliferation financing.

AML/CTF program

Put documented policies, procedures and controls around those risks.

Customer due diligence

Understand who your customers are and the risks associated with them.

Ongoing monitoring

Watch for changes in customer risk and unusual activity.

AUSTRAC reporting

Report certain transactions and suspicious matters when required.

Record keeping

Keep evidence of important AML/CTF checks, decisions and actions.

Governance and training

Make sure the right people oversee AML/CTF compliance and staff understand their responsibilities.

1. Enrol with AUSTRAC where required

Businesses providing regulated designated services may need to enrol with AUSTRAC before providing those services.

Some businesses may also have additional registration requirements depending on the services they provide.

The important part is not to treat enrolment as the end of the process. It is simply the starting point for the wider AML/CTF obligations that follow.

2. Understand your ML/TF risks

A good AML/CTF system starts with one question:

How could someone misuse our business or services to move, hide or disguise illicit funds?

Businesses need to assess their money laundering and terrorism financing risks and use that assessment to shape their controls.

Risk can come from several directions, including:

  • the types of customers you deal with
  • the products or services you provide
  • how those services are delivered
  • the countries or geographic areas involved
  • transaction behaviour
  • ownership structures
  • other risk factors relevant to the business

The goal is not to label every customer as suspicious. It is to understand where exposure is higher so the business can respond proportionately.

3. Develop and maintain an AML/CTF program

Regulated businesses generally need an AML/CTF program that turns the risk assessment into practical controls.

Think of the risk assessment as answering:

“Where could we be exposed?”

The AML/CTF program then answers:

“What are we going to do about it?”

That program can bring together policies for customer due diligence, monitoring, escalation, reporting, governance, record keeping and staff responsibilities.

It should also be a working system rather than a document that is written once and forgotten. AUSTRAC’s current guidance requires businesses to review and update their risk assessment and AML/CTF policies when relevant triggers occur and, in any case, at least every three years.

4. Know your customers through CDD

Customer due diligence (CDD) is one of the foundations of AML/CTF compliance.

It involves more than collecting a name and an identity document. Depending on the customer and risk involved, a business may need to understand matters such as:

  • who the customer is
  • whether their identity can be verified
  • who ultimately owns or controls an entity
  • the nature and purpose of the relationship
  • the customer’s ML/TF risk
  • whether additional checks are needed

This is where Know Your Customer (KYC) fits into the wider AML process.

KYC often refers to identifying and verifying customers, while CDD is broader. It considers the customer, their risk and the ongoing relationship rather than stopping at identity verification.

5. Keep monitoring after onboarding

A customer who appeared low risk on day one may not stay that way.

That is why AML/CTF compliance continues after onboarding.

Ongoing customer due diligence can involve monitoring transactions and behaviour, keeping relevant customer information up to date and reassessing risk when something changes.

For example, a business may need to look more closely when transaction behaviour suddenly becomes inconsistent with what it knows about the customer.

The useful mindset is: Know the customer at the start — then notice when the picture changes.

6. Report certain matters to AUSTRAC

Some information must be reported to AUSTRAC when the relevant legal requirements are met.

Two important reporting concepts are:

  • Suspicious Matter Reports (SMRs) — where circumstances give rise to relevant suspicion
  • Threshold Transaction Reports (TTRs) — for certain cash transactions at or above the applicable threshold

Other reporting requirements may apply depending on the service and transaction involved.

Our guide to AUSTRAC reporting requirements for Australian reporting entities goes deeper into the different reporting obligations.

A useful rule here is simple: not every unusual transaction is automatically money laundering, but unusual activity should not be ignored simply because there is no obvious explanation yet.

7. Keep records that show what you did

AML/CTF compliance needs an audit trail.

Depending on the obligation involved, records may include customer identification information, risk assessments, transaction information, monitoring decisions, reports, AML/CTF program documents and evidence of staff training.

Record keeping matters because businesses may need to demonstrate not only what decision was made, but also how and why it was made.

Good documentation turns compliance from “we think we did it” into “here is what we did and why.”

8. Put clear governance and accountability around AML/CTF

AML/CTF cannot sit with one employee while the rest of the organisation ignores it.

The framework requires appropriate governance, including roles for the governing body, senior management and an AML/CTF compliance officer where the requirements apply.

Staff whose work can affect AML/CTF compliance also need appropriate training and clear escalation pathways.

That creates a simple chain of accountability:

Staff identify concerns → the right people assess them → decisions are documented → action is taken when required.

When those pieces work together, AML/CTF becomes part of normal business risk management rather than a compliance exercise that only receives attention when something goes wrong.

What Changed Under Australia’s 2026 AML/CTF Reforms?

Australia’s AML/CTF framework changed significantly in 2026.

The reforms did two big things: they updated the rules for businesses already regulated by AUSTRAC and brought thousands of additional businesses into the AML/CTF regime.

If you have seen the term “Tranche 2” everywhere, this is where it fits.

31 March 2026: obligations changed for existing reporting entities

Updated AML/CTF obligations for businesses already regulated by AUSTRAC took effect on 31 March 2026.

The core purpose of AML/CTF compliance did not suddenly change. Businesses still need to identify and manage financial-crime risks, maintain effective controls and report relevant matters.

What changed was how parts of the framework operate, including areas such as:

  • AML/CTF programs and risk assessments
  • customer due diligence
  • governance and accountability
  • compliance officer responsibilities
  • independent evaluation
  • enrolment information
  • transfer-related requirements

Existing reporting entities therefore need to make sure their AML/CTF systems reflect the current rules, rather than continuing to rely on procedures built entirely around the pre-2026 regime.

AUSTRAC provides current guidance on the changes to AML/CTF obligations and what reporting entities need to do.

1 July 2026: Tranche 2 businesses entered the regime

The second major milestone came on 1 July 2026.

Designated services provided by newly regulated sectors—including certain legal, accounting, conveyancing, real estate and precious-metals and stones businesses—became subject to Australia’s AML/CTF regime.

This dramatically expanded the number and range of businesses dealing with AML/CTF obligations.

So when people talk about Tranche 2 AML, they are generally referring to this expansion of the regime into professions and services that had previously sat outside much of the framework.

Our guide to Australia’s AML/CTF reforms in 2026 explores those changes in more detail.

“Tranche 2” is no longer an upcoming deadline

This is an important distinction in late 2026.

You may still find articles telling businesses to “prepare for Tranche 2” or get ready for the 1 July deadline. That advice reflects an earlier stage of the reform process.

The commencement date has now passed.

For affected businesses, the question has shifted from:

“Will the new AML laws apply to us?”

to:

“Are we meeting the obligations that now apply to the services we provide?”

That includes understanding designated services, maintaining an appropriate AML/CTF program, conducting customer due diligence, training relevant staff and meeting applicable reporting and record-keeping requirements.

Transitional arrangements still matter

The fact that the reforms have commenced does not mean every transition happened overnight.

The AML/CTF Transitional Rules 2026 provide specific transitional arrangements for parts of the new framework.

Depending on the business and obligation involved, these rules can affect matters such as the move from older customer-identification procedures to the new CDD framework, compliance-officer notifications and the timing of independent evaluations.

That is why businesses should check the rules that apply to their own circumstances, rather than assuming every 2026 obligation follows exactly the same deadline.

For newly regulated businesses still building out their systems, our guide to AML Starter Kits for Australian businesses also explains how AUSTRAC’s starter resources can support implementation.

What Does Good AML/CTF Compliance Look Like Day to Day?

A good AML/CTF framework should not only exist in a policy document.

It should influence what happens when a customer arrives, when their behaviour changes, when something unusual appears and when staff need to decide what to do next.

In other words, AML/CTF compliance should work during normal business—not only during an audit or regulatory review.

Before onboarding a customer

The first step is understanding who you are dealing with and what risk the relationship may create.

Depending on the designated service and customer, this may involve:

  • collecting and verifying relevant identity information
  • identifying beneficial owners or other relevant persons
  • understanding the purpose of the relationship
  • assessing the customer’s ML/TF risk
  • applying additional checks where the risk is higher

AUSTRAC’s customer due diligence guidance makes an important point: CDD is not simply about proving that a customer exists. It also helps the business understand the risk involved in providing them with a designated service.

During the customer relationship

AML checks should not stop once onboarding is complete.

Customers, transactions and risk profiles can change over time.

Ongoing CDD may therefore involve:

  • monitoring transactions and behaviour
  • keeping relevant KYC information current
  • reassessing customer risk when circumstances change
  • identifying unusual patterns
  • applying stronger controls where new risks emerge

A customer whose activity suddenly looks very different from what the business reasonably expected may require further attention.

The practical principle is simple:

Know what normal looks like so you have a better chance of noticing when something is not.

AUSTRAC requires reporting entities to continuously monitor customers in a way that is appropriate to the ML/TF risks they face.

When something does not look right

An unusual transaction is not automatically evidence of money laundering.

But it should not simply be ignored.

A useful internal process looks like this:

Notice → review → investigate → escalate → decide → document → report when required

Staff should know who to contact, what information to preserve and when an issue needs to move beyond frontline review.

This is also why recognising workplace fraud and suspicious-behaviour red flags can support a stronger compliance culture.

At organisation level

Good AML/CTF compliance also needs to work above individual customer files.

That means regularly asking whether the overall framework is still effective.

For example:

  • Are risk assessments still current?
  • Are monitoring controls identifying the behaviour they were designed to detect?
  • Do employees understand escalation procedures?
  • Are AML/CTF policies actually being followed?
  • Are important decisions documented?
  • Are changes in legislation, services or customer risk reflected in the program?

A useful reality check is this:

Could your business explain not only what its AML controls are, but show how those controls work in practice?

If the answer is difficult, the problem may be bigger than missing paperwork.

AML Red Flags and Common Compliance Failures

AML red flags are warning signs, not proof that money laundering has occurred.

One unusual transaction may have a perfectly reasonable explanation. The real concern is whether the behaviour, transaction or customer profile creates enough uncertainty to justify closer review.

AUSTRAC makes the same distinction in its guidance on suspicious activity indicators: indicators should help businesses recognise potential risk, but they need to be considered in context.

Infographic showing a practical step-by-step process for responding to AML red flags in an Australian business.

Common AML red flags

Red flags will vary by industry, customer and designated service, but common examples can include:

  • transactions that do not match the customer’s known profile
  • unusually large, complex or frequent transactions
  • sudden changes in transaction behaviour
  • reluctance to provide identification or ownership information
  • difficulty identifying the true beneficial owner
  • unexplained third-party involvement
  • complex business structures with no clear commercial reason
  • transactions involving higher-risk jurisdictions without an obvious connection
  • attempts to avoid normal KYC or customer due diligence processes

AUSTRAC specifically identifies unusual transaction patterns, evasive customer behaviour, inconsistent identification information and unclear beneficial ownership among the indicators businesses may need to examine more closely.

The important point is:

A red flag should trigger a question, not an automatic accusation.

Depending on the circumstances, the business may need to investigate further, update the customer’s risk profile, apply enhanced due diligence, escalate the matter internally or consider whether an AUSTRAC Suspicious Matter Report is required.

Common AML compliance failures

Sometimes the biggest AML risk is not a sophisticated criminal technique. It is a weak compliance process.

Common failures can include:

  • treating KYC as a one-off onboarding task
  • using a generic risk assessment that does not reflect the business
  • failing to update customer information when circumstances change
  • weak beneficial-owner checks
  • unclear escalation procedures
  • ignoring unusual activity because there is no immediate proof of wrongdoing
  • poor record keeping
  • AML policies that employees do not understand
  • training that is too generic to reflect employees’ actual roles

A business can have a detailed AML/CTF policy and still struggle if staff do not know what to notice, when to ask questions or who to escalate concerns to.

That is why red-flag awareness needs to connect directly with day-to-day procedures.

For a broader look at warning signs employees may encounter, see our guide to workplace fraud red flags every Australian employee should recognise.

The strongest AML systems do not rely on employees memorising endless lists. They give people enough context to recognise when something does not fit the expected picture—and a clear process for what happens next.

Privacy, Data and AML/CTF Compliance

AML/CTF compliance can require businesses to collect more information about customers, beneficial owners and transactions.

But collecting information for AML purposes does not remove your privacy responsibilities.

The OAIC’s privacy guidance for AML/CTF reporting entities makes it clear that personal information collected for AML/CTF obligations must still be handled in line with the Privacy Act.

That means businesses need to think about:

  • collecting only information that is reasonably necessary
  • explaining how personal information will be handled
  • keeping sensitive customer information secure
  • controlling who can access it
  • managing overseas disclosures where relevant
  • retaining and destroying information appropriately

This is especially important after the 2026 reforms, because newly regulated businesses may now hold identity and due-diligence data they did not routinely collect before.

The practical balance is simple: collect what AML/CTF compliance requires, but protect that information like the valuable data it is.

Why AML/CTF Training Matters

Even a well-designed AML/CTF program can fall apart if the people using it do not understand what they are supposed to do.

That is why training is not just a nice-to-have. AUSTRAC requires businesses to provide AML/CTF training to personnel whose roles are relevant to their AML/CTF obligations, both when they start and on an ongoing basis. AUSTRAC’s AML/CTF training guidance also makes it clear that training should be tailored to the person’s role, responsibilities and the ML/TF risks they may encounter.

What should AML/CTF training cover?

The exact content will depend on the role, but relevant staff may need to understand:

  • the organisation’s AML/CTF obligations
  • the ML/TF risks connected with their work
  • customer due diligence and KYC procedures
  • common suspicious-activity indicators
  • how and when to escalate concerns
  • internal AML/CTF policies
  • reporting procedures
  • changes to laws, risks or business processes

A customer-facing employee, for example, may need strong red-flag and escalation awareness, while someone investigating suspicious matters may need much deeper technical knowledge.

Who needs AML/CTF training?

Not everyone needs exactly the same level of training.

AUSTRAC expects businesses to identify the roles that perform AML/CTF functions and tailor training accordingly. That can include employees, contractors, consultants and others engaged in relevant work.

For a closer look at different roles, see our guide to who needs AML training in Australia.

The goal should be practical capability, not simply completing a module. Staff should finish training knowing what to look for, what their responsibilities are and what to do when something does not look right.

If you want to build a stronger foundation in this area, our Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) course covers the core Australian AML/CTF framework, including AUSTRAC requirements, customer due diligence, risk management, reporting and record keeping.

Frequently Asked Questions

Anti-money laundering refers to the laws, controls and processes used to prevent criminals from using legitimate businesses to hide or move illicit funds. In Australia, AML sits within the broader AML/CTF regime regulated by AUSTRAC.

AML/CTF stands for Anti-Money Laundering and Counter-Terrorism Financing. Australia’s framework also addresses proliferation-financing risk, which is why businesses may see the broader term ML/TF/PF risk used in current regulatory guidance.

AUSTRAC is Australia’s AML/CTF regulator and financial intelligence unit. It oversees reporting entities, provides regulatory guidance and receives financial reports that can help authorities identify and investigate financial crime.

Businesses generally come within the regime when they provide a designated service covered by the AML/CTF Act. This can include services across financial services, gambling, virtual assets, real estate, conveyancing, legal and accounting services, trust and company services, and precious metals and stones. For a broader breakdown, see our guide to AML/CTF compliance obligations for Australian businesses.

An AML/CTF program is the framework a reporting entity uses to identify, assess and manage its money laundering, terrorism financing and proliferation financing risks. It brings together the business’s risk assessment, customer due diligence procedures, monitoring, reporting, governance, staff responsibilities and other controls.

KYC, or Know Your Customer, commonly refers to identifying customers and verifying who they are. Customer Due Diligence (CDD) is broader. It considers the customer’s identity, beneficial ownership, purpose of the relationship, risk level and ongoing activity. So KYC can be thought of as an important part of the wider CDD process.

A Suspicious Matter Report (SMR) is a report submitted to AUSTRAC when a reporting entity has reasonable grounds for a relevant suspicion, such as concerns about crime, customer identity or the possible misuse of a designated service. You can explore this further in our guide to AUSTRAC reporting requirements.

Yes. New AML/CTF obligations for Tranche 2 designated services commenced on 1 July 2026, bringing thousands of additional businesses—including certain real estate, legal, accounting, conveyancing and precious-metals and stones businesses—into the regime. For the full reform picture, see our 2026 guide to Australia’s AML/CTF reforms.