AML/CTF Guide for Financial Services Providers in Australia

Australian financial service providers may be reporting entities when they provide one or more financial designated services, including accounts, loans, payments, custody, exchange or investment-related services. This guide explains scope, sector risks, practical controls, examples and official sources in plain English.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. Start With These Four Checks
  3. Key words explained
  4. Part 1: When AML/CTF May Apply
  5. Part 2: Main Risks in This Sector
  6. Part 3: A Practical Control Plan
  7. Part 4: Worked Examples
  8. Part 5: Evidence That Should Be Easy to Find
  9. Part 6: Common Mistakes
  10. Common questions
  11. Official sources

Short answer

Australian financial service providers may be reporting entities when they provide one or more financial designated services, including accounts, loans, payments, custody, exchange or investment-related services.

Scope is based on each designated service, the business test and the geographical link. Check current exemptions and modifications before relying on a result.

At a glance

Start With These Four Checks

  • Map the service

    Write down exactly what is done for the customer and match it to section 6.

  • Know the customer

    Identify the customer, beneficial owners, people acting for them and the purpose of the work.

  • Follow the sector risk

    Build controls around how money, property, structures, products and instructions move in this sector.

  • Keep the evidence

    Scope, CDD, risk, monitoring, reports, training and review should be easy to prove.

Plain English

Key Words Explained

These words are used in the law and official guidance. This is what they mean on this page.

Designated service
A service listed in section 6 of the Australian AML/CTF Act.
Reporting entity
A person or business that must meet AML obligations for the covered service or activity.
Beneficial owner
The individual who ultimately owns or controls the customer or on whose behalf the work is done.
Enhanced CDD
Extra customer and source checks used when the law or higher risk requires them.
SMR
A suspicious matter report submitted to AUSTRAC when reasonable grounds for suspicion exist.

When AML/CTF May Apply

The financial designated-service list is detailed. A product name is not enough; each service and condition should be matched to section 6.

  • Opening or operating certain accounts and deposit products.
  • Making loans, providing finance or issuing relevant credit products.
  • Sending, receiving, clearing or settling payments.
  • Safekeeping, custody, exchange or dealing services.
  • Issuing or dealing in relevant securities, derivatives or stored value.
  • Other financial services listed in section 6 with an Australian link.
Check the boundary

A financial services licence, registration or broad industry label does not decide AML/CTF scope. The exact product, role, customer and flow of value should be mapped.

Main Risks in This Sector

These are starting points, not a ready-made risk rating. The business still needs to assess its own customers, services, countries, channels, transactions and technology.

  • Accounts and payment rails can move criminal funds quickly and at scale.
  • Identity fraud, mule accounts and stolen businesses can defeat onboarding controls.
  • Layered legal entities and intermediaries can hide beneficial owners.
  • Cross-border activity can involve high-risk countries, sanctions or weak transparency.
  • Automated decisions and large alert volumes can create blind spots and backlogs.

A Practical Control Plan

  1. Step 1

    Confirm scope

    Build a designated-service inventory for every product, channel and legal entity.

  2. Step 2

    Build the customer process

    Connect customer risk, CDD, sanctions, fraud and transaction monitoring data.

  3. Step 3

    Set the risk controls

    Set risk-based rules for onboarding, ongoing review, alerts and enhanced CDD.

  4. Step 4

    Train and connect people

    Measure backlogs, false positives, missed data and control overrides.

  5. Step 5

    Test and improve

    Test end-to-end customer journeys rather than isolated policy steps.

Worked Examples

These examples show how the scope and risk questions can be joined. They do not replace the law or the facts of a real matter.

Financial Services Providers: common situations and responses
SituationWhy it mattersPractical response
A new company account receives many unrelated small deposits and sends them overseas.The account may be a mule or layering vehicle that does not match its stated purpose.Review ownership, purpose, counterparties and source, then apply enhanced CDD and assess an SMR.
A customer takes over an old dormant company.The entity’s history may hide a new controller and changed risk.Refresh beneficial ownership, authority, purpose and risk before relying on old CDD.
A monitoring rule creates a large unresolved backlog.Important suspicious activity may not be assessed within a reasonable time.Prioritise higher risk, add resources, tune with evidence and assess whether reports were missed.

Evidence That Should Be Easy to Find

  • The designated-service and geographical-link analysis.
  • The current sector risk assessment and the official sources used.
  • A product and designated-service inventory with legal owners.
  • Data lineage showing what feeds screening and monitoring controls.
  • Alert, case, customer-risk and regulatory-report quality measures.
  • Testing of model rules, manual controls, overrides and backlogs.
  • Customer, beneficial ownership, risk, monitoring and reporting records.
  • Training, internal review, independent assurance and remediation records.

Common Mistakes

  • Using the licence category as the AML/CTF scope decision.
  • Separating fraud and AML information that should be assessed together.
  • Relying on automated screening without data-quality checks.
  • Refreshing low-risk files on a calendar while missing event-driven high-risk change.
  • Measuring alert closure speed without measuring decision quality.

Common Questions

Short answers to the questions businesses ask most often.

Does every business in this sector have AML/CTF duties?

No. The exact service and the other legal tests decide the answer. A business may provide both designated and non-designated services.

What should the business do first?

Build a designated-service inventory for every product, channel and legal entity.

Can the sector risk assessment replace our own?

No. Official national and sector assessments are important sources, but the reporting entity must assess the risks it reasonably expects to face in its own business.

Can a generic AML/CTF template be used?

A template can help with structure, but it must be matched to the business’s scope, risks, people, systems and evidence. A document that is not implemented is not enough.

Does every licensed financial service create AML/CTF duties?

Not necessarily. Each service should be matched to section 6 and the geographical-link rules. Other legal obligations can still apply even where one service is not designated.

Can fraud monitoring be used for AML/CTF?

Shared data and alerts can help, but the AML/CTF program must still meet its own legal tests, governance, reporting and record requirements.

Official Sources

This guide cites the following sources.

  1. Primary lawFederal Register of Legislation
    Anti-Money Laundering and Counter-Terrorism Financing Act 2006

    The current Australian AML/CTF Act, including program, CDD, reporting, governance and record-keeping duties.

  2. Regulator guidanceAUSTRAC
    Financial service providers

    Current AUSTRAC guidance and resources for banks, lenders, payment businesses and other financial service providers.

  3. Regulator guidanceAUSTRAC
    Who and what we regulate

    The activities-based test for deciding whether a business is a reporting entity.

  4. Regulator guidanceAUSTRAC
    Develop your AML/CTF program

    The five-part process for governance, risk assessment, policies, review and independent evaluation.

  5. Regulator guidanceAUSTRAC
    Customer due diligence

    Current guidance on initial, ongoing, simplified and enhanced customer due diligence.

This guide provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Need advice for your situation?

Turn the Guidance Into a Clear Next Step.

Tell us what your Australia business does and where the uncertainty sits. We will help you work out the practical AML/CTF response.

Tell us about your situation