AML/CTF Guide for Financial Services Providers in Australia
Australian financial service providers may be reporting entities when they provide one or more financial designated services, including accounts, loans, payments, custody, exchange or investment-related services. This guide explains scope, sector risks, practical controls, examples and official sources in plain English.
How this guide was researched and reviewedOn this page
Short answer
Australian financial service providers may be reporting entities when they provide one or more financial designated services, including accounts, loans, payments, custody, exchange or investment-related services.
Scope is based on each designated service, the business test and the geographical link. Check current exemptions and modifications before relying on a result.
At a glance
Start With These Four Checks
Map the service
Write down exactly what is done for the customer and match it to section 6.
Know the customer
Identify the customer, beneficial owners, people acting for them and the purpose of the work.
Follow the sector risk
Build controls around how money, property, structures, products and instructions move in this sector.
Keep the evidence
Scope, CDD, risk, monitoring, reports, training and review should be easy to prove.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- Designated service
- A service listed in section 6 of the Australian AML/CTF Act.
- Reporting entity
- A person or business that must meet AML obligations for the covered service or activity.
- Beneficial owner
- The individual who ultimately owns or controls the customer or on whose behalf the work is done.
- Enhanced CDD
- Extra customer and source checks used when the law or higher risk requires them.
- SMR
- A suspicious matter report submitted to AUSTRAC when reasonable grounds for suspicion exist.
Part 1
When AML/CTF May Apply
The financial designated-service list is detailed. A product name is not enough; each service and condition should be matched to section 6.
- Opening or operating certain accounts and deposit products.
- Making loans, providing finance or issuing relevant credit products.
- Sending, receiving, clearing or settling payments.
- Safekeeping, custody, exchange or dealing services.
- Issuing or dealing in relevant securities, derivatives or stored value.
- Other financial services listed in section 6 with an Australian link.
A financial services licence, registration or broad industry label does not decide AML/CTF scope. The exact product, role, customer and flow of value should be mapped.
Part 2
Main Risks in This Sector
These are starting points, not a ready-made risk rating. The business still needs to assess its own customers, services, countries, channels, transactions and technology.
- Accounts and payment rails can move criminal funds quickly and at scale.
- Identity fraud, mule accounts and stolen businesses can defeat onboarding controls.
- Layered legal entities and intermediaries can hide beneficial owners.
- Cross-border activity can involve high-risk countries, sanctions or weak transparency.
- Automated decisions and large alert volumes can create blind spots and backlogs.
Part 3
A Practical Control Plan
- Step 1
Confirm scope
Build a designated-service inventory for every product, channel and legal entity.
- Step 2
Build the customer process
Connect customer risk, CDD, sanctions, fraud and transaction monitoring data.
- Step 3
Set the risk controls
Set risk-based rules for onboarding, ongoing review, alerts and enhanced CDD.
- Step 4
Train and connect people
Measure backlogs, false positives, missed data and control overrides.
- Step 5
Test and improve
Test end-to-end customer journeys rather than isolated policy steps.
Part 4
Worked Examples
These examples show how the scope and risk questions can be joined. They do not replace the law or the facts of a real matter.
| Situation | Why it matters | Practical response |
|---|---|---|
| A new company account receives many unrelated small deposits and sends them overseas. | The account may be a mule or layering vehicle that does not match its stated purpose. | Review ownership, purpose, counterparties and source, then apply enhanced CDD and assess an SMR. |
| A customer takes over an old dormant company. | The entity’s history may hide a new controller and changed risk. | Refresh beneficial ownership, authority, purpose and risk before relying on old CDD. |
| A monitoring rule creates a large unresolved backlog. | Important suspicious activity may not be assessed within a reasonable time. | Prioritise higher risk, add resources, tune with evidence and assess whether reports were missed. |
Part 5
Evidence That Should Be Easy to Find
- The designated-service and geographical-link analysis.
- The current sector risk assessment and the official sources used.
- A product and designated-service inventory with legal owners.
- Data lineage showing what feeds screening and monitoring controls.
- Alert, case, customer-risk and regulatory-report quality measures.
- Testing of model rules, manual controls, overrides and backlogs.
- Customer, beneficial ownership, risk, monitoring and reporting records.
- Training, internal review, independent assurance and remediation records.
Part 6
Common Mistakes
- Using the licence category as the AML/CTF scope decision.
- Separating fraud and AML information that should be assessed together.
- Relying on automated screening without data-quality checks.
- Refreshing low-risk files on a calendar while missing event-driven high-risk change.
- Measuring alert closure speed without measuring decision quality.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Does every business in this sector have AML/CTF duties?
No. The exact service and the other legal tests decide the answer. A business may provide both designated and non-designated services.
What should the business do first?
Build a designated-service inventory for every product, channel and legal entity.
Can the sector risk assessment replace our own?
No. Official national and sector assessments are important sources, but the reporting entity must assess the risks it reasonably expects to face in its own business.
Can a generic AML/CTF template be used?
A template can help with structure, but it must be matched to the business’s scope, risks, people, systems and evidence. A document that is not implemented is not enough.
Does every licensed financial service create AML/CTF duties?
Not necessarily. Each service should be matched to section 6 and the geographical-link rules. Other legal obligations can still apply even where one service is not designated.
Can fraud monitoring be used for AML/CTF?
Shared data and alerts can help, but the AML/CTF program must still meet its own legal tests, governance, reporting and record requirements.
Reference
Official Sources
This guide cites the following sources.
- Primary lawFederal Register of LegislationAnti-Money Laundering and Counter-Terrorism Financing Act 2006
The current Australian AML/CTF Act, including program, CDD, reporting, governance and record-keeping duties.
- Regulator guidanceAUSTRACFinancial service providers
Current AUSTRAC guidance and resources for banks, lenders, payment businesses and other financial service providers.
- Regulator guidanceAUSTRACWho and what we regulate
The activities-based test for deciding whether a business is a reporting entity.
- Regulator guidanceAUSTRACDevelop your AML/CTF program
The five-part process for governance, risk assessment, policies, review and independent evaluation.
- Regulator guidanceAUSTRACCustomer due diligence
Current guidance on initial, ongoing, simplified and enhanced customer due diligence.