Australia's financial system is under more regulatory scrutiny than ever before. Whether you run a small remittance business in Melbourne, a digital currency exchange in Sydney, or a law firm about to enter the compliance fold for the first time, understanding your obligations under AUSTRAC is no longer optional — it is fundamental to operating legally and ethically in this country.
This guide cuts through the complexity. It explains who must report, what they must report, when it needs to be submitted, and what happens when things go wrong. And with the biggest reforms to Australia's anti-money laundering framework in nearly two decades now taking effect, there has never been a more important time to get across the detail.
What Is AUSTRAC and Why Does It Matter?
The Australian Transaction Reports and Analysis Centre — most people just call it AUSTRAC — is both a financial intelligence agency and a regulatory body. It operates under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act), collecting financial data from businesses that provide what the law calls "designated services."
The reports that AUSTRAC receives from businesses are not just ticking boxes. They form part of a national intelligence picture that helps law enforcement track money trails connected to everything from tax evasion to human trafficking. A suspicious matter report filed by a bank teller in Brisbane, for instance, might link to an investigation running out of the Australian Federal Police in Canberra.
That interconnection is precisely why AUSTRAC's reporting framework carries so much weight.
Who Is a Reporting Entity?
A reporting entity is any business or individual that provides one or more designated services with a geographical link to Australia. The legal structure — whether you are a company, trust, partnership, or sole trader — is irrelevant. What matters is the activity.
Designated services cover a wide range, including banking and deposit-taking, currency exchange, remittance transfers, life insurance, securities and derivatives dealing, and gambling services, among others. Until recently, this framework largely covered financial institutions and related businesses.
That changed significantly with the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, which brought thousands of new businesses into the regime. From 1 July 2026, real estate agents, lawyers, accountants, and dealers in precious metals and stones became regulated for the first time — a long-overdue step that brings Australia into line with global standards set by the Financial Action Task Force (FATF).
The distinction matters in the new framework. An accountant who helps a client establish a discretionary trust falls within the regime. An accountant preparing a standard tax return does not. It is the specific activity, not the profession, that triggers the obligation.
Core Reporting Obligations at a Glance
Once a business qualifies as a reporting entity, several obligations kick in. The reporting requirements are the most visible part of that picture.
Suspicious Matter Reports (SMRs)
An SMR must be submitted when a reporting entity forms a suspicion on reasonable grounds — whether about a customer's identity, a transaction pattern, or underlying criminal activity. The obligation arises not only when a service is actually provided, but also when someone is merely asked to provide one.
There is no dollar amount attached to this obligation. A $200 cash transaction can trigger an SMR if the circumstances are suspicious enough. The report must be submitted as soon as practicable after the suspicion is formed. For most reporting entities, that means same-day or next-day lodgement in AUSTRAC Online.
What makes a good SMR? The grounds for suspicion need to clearly explain the what, the who, and the why. AUSTRAC expects the first sentence to summarise the suspicious activity and the indicators that gave rise to concern. Generic reports that simply state "customer behaved oddly" will not cut it.
From 1 July 2026, new SMR forms are available through AUSTRAC Online with expanded data fields. Current reporting entities that were enrolled on 30 March 2026 can choose to use either the old or the new form until 30 March 2029, giving them a multi-year transition window to update their systems. Businesses entering the regime for the first time on 1 July 2026 must use the new form from day one.
Threshold Transaction Reports (TTRs)
The TTR obligation is more straightforward. Reporting entities must submit a TTR for each physical currency transaction of $10,000 or more, with the $10,000 threshold also applying to equivalent amounts in foreign currency.
A common misconception is that businesses can aggregate smaller transactions to stay under the threshold. That is not how it works. Each transaction is assessed individually. However, reporting entities should remain alert to structuring — where customers deliberately break up payments to avoid the $10,000 mark. That behaviour itself can trigger an SMR obligation.
TTRs must be submitted within 10 business days after the transaction date. These are lodged through AUSTRAC Online.
A practical scenario: a customer walks into a currency exchange with AUD 11,500 in cash to convert into US dollars. The exchange must submit a TTR. The same customer splitting that same amount across two visits on the same day in an attempt to avoid reporting is a different matter entirely — the exchange should consider whether an SMR is warranted.
International Value Transfer Service (IVTS) Reports
Previously known as International Funds Transfer Instructions (IFTI reports), this obligation covers the movement of money, virtual assets, or other property across Australian borders. No minimum monetary threshold exists for this reporting category — every cross-border transfer instruction must be reported.
The IVTS framework, which replaced IFTI reporting from 31 March 2026, improves the tracking of international transfers by requiring more accurate customer information to be included. Notably, the reporting obligation now falls on the reporting entity closest to the Australian customer, rather than being passed along the chain.
Currency exchange providers and some gambling services are also now covered by IVTS rules, expanding the scope of who must report international value movements.
Cross-Border Movement (CBM) Reports
This obligation applies to anyone — not just reporting entities — who physically moves cash or monetary instruments of $10,000 or more into or out of Australia. Banks and exchange providers often encounter this obligation indirectly when assisting customers who have declared or should have declared such movements.
Annual Compliance Reports
Reporting entities must submit an annual compliance report detailing how they met their AML/CTF obligations for the preceding reporting period. These reports are due between 1 January and 31 March each year. Missing the deadline is not a minor administrative slip — it can lead to enforcement action including remedial directions and infringement notices.
The Risk-Based Shift: What the 2024 Reforms Actually Mean
Talking to compliance professionals around the country, one theme keeps coming up: the reformed framework is less about following a checklist and more about genuinely understanding risk.
AUSTRAC's guidance emphasises an outcomes-focused, risk-based approach. Entities must assess money laundering, terrorism financing, and proliferation financing risks across their customers, products, delivery channels, and jurisdictions, and apply controls proportionate to those risks.
This is a meaningful departure from the old compliance-based model, where a business could effectively tick boxes and satisfy regulators even if its actual risk controls were weak. Under the reformed regime, if your business operates in a higher-risk sector — say, you deal in high-value goods or work with international clients — your AML/CTF program needs to reflect that reality.
AUSTRAC expects current reporting entities to develop and document implementation plans that manage ML/TF/PF risks while transitioning policies, procedures, and systems to meet the new obligations, and to show sustained effort and progress against those plans.
In other words, AUSTRAC does not expect perfection on day one. But it does expect momentum.
Recordkeeping: The Obligation That Often Gets Overlooked
Reporting is only part of the picture. Recordkeeping sits alongside it as an equally important obligation that often receives less attention.
Reporting entities are required under Part 10 of the AML/CTF Act to retain records related to customer identification, transactions, their AML/CTF program, and submitted reports for a minimum of seven years. For customer identification records, this period begins after the business relationship ends; for transaction records, it begins from the transaction date.
Seven years is a long time. Systems need to be designed from the start to accommodate this requirement. A business that destroys records after three years because "nothing happened" is still in breach, even if it never had a suspicious transaction in its history.
What must be retained? This includes customer identity documents and verification records, transaction records, the AML/CTF program itself (including any risk assessments), and copies of all reports submitted to AUSTRAC.
For businesses transitioning into the regime for the first time in July 2026, building a robust document management system from day one is far less painful than trying to reconstruct records under pressure later.
Customer Due Diligence: The Foundation Behind the Reports
No conversation about AUSTRAC reporting is complete without addressing customer due diligence (CDD). The reports that get filed are often only as good as the information collected at the point of customer onboarding.
Under the reformed regime, reporting entities must complete initial CDD before or when providing a designated service. This means verifying who the customer is, understanding the nature of the business relationship, and assessing their money laundering and terrorism financing risk.
Higher-risk customers — including Politically Exposed Persons (PEPs), clients from high-risk jurisdictions, and those with complex ownership structures — require enhanced CDD. AUSTRAC's AML/CTF Rules require enhanced ongoing CDD for PEPs, including senior management sign-off and periodic review.
One important clarification for businesses transitioning to the new regime: customer identification procedures completed under the old rules before 31 March 2026 are recognised as compliant under the new framework. Existing customers do not need to be re-verified from scratch.
What Happens When Reporting Entities Fall Short?
AUSTRAC is not a passive regulator. It has enforcement powers and uses them.
Non-compliance can result in fines running into millions of dollars per breach for corporations. Beyond financial penalties, AUSTRAC can issue remedial directions requiring businesses to fix identified gaps, impose conditions on operations, or refer matters for civil or criminal prosecution.
Australia has seen high-profile enforcement action against large financial institutions in recent years. The message was clear: size and reputation do not provide shelter from accountability. Smaller reporting entities sometimes assume AUSTRAC focuses only on banks. That assumption is wrong.
The reputational damage of being publicly named in AUSTRAC enforcement action can be equally devastating, particularly for professional services firms entering the regime for the first time.
A Practical Compliance Checklist for 2026
Getting AUSTRAC compliance right does not require a law degree. It requires structure, consistency, and a genuine commitment to understanding your risks. Here are the fundamentals every reporting entity should have in place:
-
Enrol on the Reporting Entities Roll via AUSTRAC Online — mandatory before providing any designated service
-
Appoint an AML/CTF Compliance Officer and notify AUSTRAC within 14 days of the appointment
-
Develop and maintain a written AML/CTF program that reflects your actual risk profile
-
Establish customer identification and verification procedures before onboarding clients
-
Submit SMRs promptly when suspicion arises — never delay because you are uncertain
-
Submit TTRs within 10 business days of any qualifying physical currency transaction
-
File your annual compliance report between January and March each year
-
Maintain all relevant records for a minimum of seven years
Take the Next Step: Build Real Compliance Knowledge
Understanding the obligations is one thing. Applying them correctly in day-to-day operations is another skill entirely. For compliance officers, business owners, and anyone stepping into a regulated role for the first time, foundational training makes an enormous difference.
AUSTRAC Reporting and Recordkeeping Basics – Australian Compliance Training is a course designed specifically for Australian reporting entities navigating these obligations. It covers the core reporting types — SMRs, TTRs, IVTSs, and compliance reports — alongside recordkeeping requirements, practical scenarios, and the common mistakes that land businesses in trouble with AUSTRAC.
If you are new to the regime, transitioning under the 2024 reforms, or simply want to make sure your team is up to speed, this is the course to start with. Enrol today and build the practical knowledge your compliance program needs.
