AML compliance Australia
Aug 25, 2026
11min read

What Are AML Starter Kits? A Complete Guide for Australian Businesses Preparing for AML/CTF Compliance

AML/CTF Compliance Australia

For thousands of Australian businesses, 2026 marks the first time they have ever had to think seriously about anti-money laundering obligations. Real estate agents, lawyers, conveyancers, accountants, trust and company service providers, and dealers in precious metals and stones are now part of a regulatory system that once applied almost exclusively to banks and financial institutions. Many of these businesses are asking the same question: where do we even start?

That question is exactly why AUSTRAC created AML Starter Kits. As Australia's anti-money laundering and counter-terrorism financing reforms extend obligations to a much broader group of "Tranche 2" businesses, AUSTRAC recognised that most newly regulated entities are small, low-complexity operations without an in-house compliance team. Building an AML/CTF program from scratch, using only the legislation and regulatory guidance, is a genuinely daunting task for a five-person accounting practice or a suburban real estate agency.

This guide explains exactly what AML Starter Kits are, why they matter, what Australian businesses need to know about the current reforms, how the approach compares with international AML frameworks, and the practical steps required to turn a starter kit into a genuine, working compliance program rather than a document that sits unused in a filing cabinet.

What Are AML Starter Kits?

AML Starter Kits are pre-built, sector-specific template resources developed by AUSTRAC to help newly regulated businesses understand and implement their Anti-Money Laundering and Counter-Terrorism Financing Act obligations. Rather than requiring every small business to draft an AML/CTF program entirely from first principles, the kits provide a structured starting template covering risk assessment, policies, procedures and customer due diligence processes tailored to a specific industry.

The kits exist because the AML/CTF reforms significantly expand the range of businesses considered "reporting entities" under Australian law. From 1 July 2026, professions including real estate agents, lawyers, conveyancers, accountants, and dealers in precious metals and stones are required to enrol with AUSTRAC and maintain a compliant AML/CTF program. Without practical guidance, many of these newly regulated sectors would have faced significant cost and confusion trying to interpret complex legislation without any compliance background.

AML Starter Kits primarily affect small and low-complexity businesses in these newly regulated sectors, though larger or higher-risk businesses within these sectors are expected to build more tailored, comprehensive programs rather than relying solely on the starter kit template. Sector-specific kits have been developed for groups including the legal profession, conveyancing practices, accounting, and real estate, with each kit reflecting the typical risk profile and customer interactions common to that industry.

Organisations need to understand these kits because using a starter kit incorrectly, or assuming it works "as is" without customisation, creates a false sense of compliance. AUSTRAC has been clear that the kits are a foundation, not a finished product, and every business remains responsible for tailoring the material to reflect its own risk exposure, customer base and service offering.

Why Are AML Starter Kits Important for Australian Businesses?

The business impact of getting AML/CTF compliance wrong extends well beyond a single regulatory notice. Reporting entities that fail to maintain an adequate AML/CTF program can face significant civil penalties, reputational damage, and in serious cases, loss of professional licensing or referral for criminal investigation. For a small law firm or real estate agency, a poorly managed compliance failure can be existential.

From a compliance standpoint, the starter kits reduce one of the biggest early barriers newly regulated businesses face: not knowing where to begin. According to AUSTRAC's own guidance, the reforms are designed to close gaps that serious and organised crime has been exploiting, with related financial crime estimated by the Australian Institute of Criminology to cost the Australian economy tens of billions of dollars annually. Because so much of that harm flows through legitimate-looking transactions in property, legal and financial services, extending AML/CTF obligations to these sectors closes a well-known regulatory gap.

There are genuine workplace benefits too. Staff who understand customer due diligence requirements are better equipped to recognise red flags in everyday client interactions, rather than treating a large cash property purchase or an unusually complex trust structure as "just another transaction." A well-implemented program also gives business owners more confidence when engaging with new or unfamiliar clients, because the due diligence steps are built into the onboarding process rather than left to individual judgment.

Consider a practical example common to the real estate sector: a buyer's agent is engaged by a client purchasing an investment property through a newly established trust structure, with funds coming from an overseas source. Without a functioning AML/CTF program, front-line staff may have no clear process for verifying beneficial ownership or assessing source-of-funds risk. With a properly customised starter kit in place, staff know exactly what due diligence steps are required, what documentation to collect, and when a matter needs to be escalated to the appointed AML/CTF compliance officer.

The risks of ignoring these requirements, or treating the starter kit as a "set and forget" document, are significant. AUSTRAC has indicated it does not expect perfection immediately from newly regulated entities, but it does expect to see genuine, risk-based implementation, including enrolment, an appointed compliance officer, a tailored program, and evidence of staff training and ongoing review.

The Australian Context: Laws, Regulators and Business Responsibilities

Australia's AML/CTF framework is built around the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, regulated by AUSTRAC, Australia's financial intelligence agency and AML/CTF regulator. The current reform program, often referred to as the "Tranche 2" reforms, extends reporting entity obligations to sectors that were previously outside the regime, including legal practitioners, conveyancers, accountants, real estate professionals, and dealers in precious metals and stones.

The reform timeline has been staged carefully to give newly regulated businesses time to prepare. AUSTRAC released sector-specific guidance and starter kits in the lead-up to the reforms, with enrolment for newly regulated entities opening on 31 March 2026. Businesses providing a designated service under the reformed Act must enrol with AUSTRAC within 28 days of first providing that service, and full AML/CTF obligations for Tranche 2 entities commenced on 1 July 2026.

Australian businesses newly captured by these reforms carry several concrete responsibilities, including:

  • Confirming whether their services meet the definition of a "designated service" under the AML/CTF Act, and enrolling with AUSTRAC within the required timeframe.

  • Appointing an AML/CTF compliance officer with delegated responsibility for oversight, and customising a risk assessment and program that reflects the business's actual operations and risk exposure.

  • Conducting customer due diligence, including identity verification, beneficial ownership checks and source-of-funds assessment, and maintaining records that demonstrate an active, reviewed compliance program.

Industry-specific considerations matter considerably here. A small conveyancing practice handling straightforward residential property transfers faces a very different risk profile to a legal practice regularly involved in complex commercial structuring or trust arrangements. AUSTRAC's guidance acknowledges this by producing distinct starter kits for different sectors, such as the Legal Profession Starter Kit and Conveyancing Starter Kit, each reflecting the typical transaction types and risk indicators relevant to that profession. Businesses that provide more than one type of designated service, such as a firm offering both legal and conveyancing work, may need to combine or adapt more than one sector kit.

It is worth noting that using a starter kit is not mandatory. AUSTRAC has been explicit that businesses are free to build a fully bespoke AML/CTF program instead, provided it meets the same regulatory requirements. For most small, low-complexity businesses, however, starting from the sector-specific kit and customising it is significantly more efficient than starting from a blank page.

Global Perspective: How Australia's Approach Compares Internationally

Australia's decision to extend AML/CTF obligations to "gatekeeper" professions such as lawyers, accountants and real estate agents brings the country into closer alignment with international standards long recommended by the Financial Action Task Force, the global standard-setter for anti-money laundering and counter-terrorism financing policy. FATF has for years identified designated non-financial businesses and professions as a common weak point in national AML frameworks, since criminals frequently use professional services to disguise the origin of illicit funds.

Many comparable jurisdictions, including the United Kingdom, Canada and members of the European Union, already regulate legal, accounting and real estate professionals under their AML frameworks, often with sector-specific guidance similar in spirit to AUSTRAC's starter kits. The UK's approach through its Money Laundering Regulations, for example, similarly requires regulated professions to conduct customer due diligence and maintain risk-based policies, with professional bodies often producing supplementary sector guidance.

What distinguishes Australia's approach is the relatively coordinated, staged rollout supported by free, sector-specific starter templates developed in consultation with industry peak bodies. Rather than leaving thousands of newly regulated small businesses to interpret dense legislative requirements unaided, AUSTRAC's model reflects a broader global trend toward regulators providing practical implementation support alongside enforcement powers, recognising that genuine compliance uplift across an entire newly regulated population takes time, education and accessible resources.

Common Challenges and Mistakes Businesses Make

Even with a starter kit in hand, many newly regulated businesses run into predictable problems during implementation.

One of the most common mistakes is treating the starter kit as a finished, ready-to-use document rather than a customisable template. AUSTRAC's guidance is explicit that businesses must adapt the risk assessment and program to reflect their own operations, client base and service types. A firm that simply inserts its business name into the template without genuinely assessing its own risk profile has not met its compliance obligations, regardless of how complete the document appears.

Another frequent gap is failing to appoint a genuinely empowered AML/CTF compliance officer. Some smaller businesses nominate a compliance officer on paper but never give that person real authority, time, or resources to manage the program, review transactions, or escalate concerns. This creates an ongoing compliance risk because the person notionally responsible for oversight has no practical ability to fulfil the role.

Underestimating customer due diligence requirements is also common, particularly among businesses used to working with long-standing clients on a trust-based relationship. Firms sometimes assume that an established client relationship removes the need for formal identity verification or source-of-funds checks, when in fact the AML/CTF program must apply consistently, with due diligence intensity scaled to risk rather than to familiarity.

Finally, many businesses stop at documentation and never move to genuine implementation. A written program that is never trained on, tested, or reviewed provides limited protection if a regulator later examines actual practice rather than paperwork. AUSTRAC has signalled it does not expect perfection immediately, but it does expect visible evidence of a functioning, risk-based program, not just a completed template sitting in a drawer.

Preventing these issues starts with treating the starter kit as day one of an ongoing compliance journey rather than the final deliverable, supported by real training, periodic review, and a compliance officer with genuine authority to act.

How Organisations Can Effectively Implement an AML/CTF Program

Turning a starter kit into a genuine, working compliance program requires coordinated effort across the business, not just a single compliance task ticked off a list.

For business owners and senior leaders, effective implementation starts with genuine ownership. This means confirming whether the business provides a designated service under the AML/CTF Act, enrolling with AUSTRAC within the required window, and appointing a compliance officer with real authority and adequate time to manage the role. Owners should also budget for ongoing review, since AML/CTF obligations are not a one-off project but a continuing responsibility as the business, its clients and the regulatory guidance evolve.

For managers and team leaders, implementation means embedding the program into day-to-day workflows rather than treating it as a separate compliance exercise. This includes building customer due diligence steps directly into client onboarding processes, ensuring escalation pathways for higher-risk clients are clearly understood, and checking that the risk assessment genuinely reflects how the team actually works with clients.

For employees and front-line staff, the practical focus is recognising when a transaction or client relationship needs closer scrutiny. This means understanding basic identity verification and source-of-funds requirements relevant to their role, knowing how to escalate concerns to the compliance officer, and feeling confident asking questions when a client relationship does not fit the usual pattern.

For compliance professionals, the priority is proving that the program is genuinely operating, not just documented. This includes:

  • Scheduling regular reviews of the risk assessment and program to reflect changes in client base, services or emerging AUSTRAC guidance, and maintaining clear records of staff training completion.

  • Testing due diligence processes periodically against real client files to confirm they are being followed consistently, rather than relying solely on the written procedure.

Businesses looking to build genuine capability around these obligations, rather than relying on a template alone, often benefit from structured training. Australian Compliance Training's AML CTF Compliance Essentials Australia course provides practical guidance to help business owners, managers and compliance officers understand key AML/CTF requirements and apply them consistently across everyday client interactions.

Bringing It Together

AML Starter Kits give newly regulated Australian businesses a genuinely useful head start on a complex compliance obligation, but they are the beginning of the process rather than the end of it. The kits provide structure, but genuine compliance depends on honest risk assessment, an empowered compliance officer, consistent customer due diligence, and ongoing review as guidance and business circumstances change.

As the 1 July 2026 compliance deadline settles in and AUSTRAC continues refining sector guidance, businesses that treat their AML/CTF program as a living part of how they operate, rather than a document produced once and forgotten, will be far better placed to demonstrate genuine compliance if their program is ever reviewed. Early, thoughtful engagement with the starter kit, backed by real staff understanding, remains the most practical path through this significant regulatory change.

Frequently Asked Questions

The NDIS Code of Conduct is a set of legally enforceable behavioural standards under the National Disability Insurance Scheme (Code of Conduct) Rules 2018. It requires people delivering NDIS supports to act safely, respectfully, honestly and with integrity, and to take reasonable steps to prevent harm, exploitation and abuse of people with disability.

It protects participants and directly affects a provider's ability to operate. Breaches can lead to significant civil penalties, banning orders, and reputational damage that undermines participant trust. Providers who embed the Code into daily practice generally experience fewer complaints and stronger workforce culture.

The Code applies to registered and many unregistered providers, key personnel, employees, contractors and volunteers who deliver NDIS supports or services. This includes support workers, coordinators, allied health professionals, managers and directors.

Risks include regulatory investigation, civil penalties, individual banning orders, and in serious cases, criminal referral. Beyond formal penalties, ignoring the Code erodes participant trust and can damage a provider's reputation within their local disability community.

Organisations should move beyond one-off induction training toward ongoing, role-specific education, strong incident and complaints management systems, visible concern-raising pathways, and leadership that actively models expected behaviour rather than delegating compliance entirely to HR.

Yes. The Code applies broadly across the NDIS market, including many unregistered providers, particularly as mandatory registration requirements have expanded for higher-risk support types under recent reforms.

The Code of Conduct focuses on individual behaviour and ethics, while the NDIS Practice Standards focus on organisational systems and processes. Together, they form the two main pillars the NDIS Quality and Safeguards Commission uses to assess provider quality and safety.