AML/CTF Guide for Remittance Service Providers in Australia
Australian remittance providers must generally enrol and register with AUSTRAC, maintain a suitable AML/CTF program and meet CDD, monitoring, reporting and record duties. This guide explains scope, sector risks, practical controls, examples and official sources in plain English.
How this guide was researched and reviewedOn this page
Short answer
Australian remittance providers must generally enrol and register with AUSTRAC, maintain a suitable AML/CTF program and meet CDD, monitoring, reporting and record duties.
Scope is based on each designated service, the business test and the geographical link. Check current exemptions and modifications before relying on a result.
At a glance
Start With These Four Checks
Map the service
Write down exactly what is done for the customer and match it to section 6.
Know the customer
Identify the customer, beneficial owners, people acting for them and the purpose of the work.
Follow the sector risk
Build controls around how money, property, structures, products and instructions move in this sector.
Keep the evidence
Scope, CDD, risk, monitoring, reports, training and review should be easy to prove.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- Designated service
- A service listed in section 6 of the Australian AML/CTF Act.
- Reporting entity
- A person or business that must meet AML obligations for the covered service or activity.
- Beneficial owner
- The individual who ultimately owns or controls the customer or on whose behalf the work is done.
- Enhanced CDD
- Extra customer and source checks used when the law or higher risk requires them.
- SMR
- A suspicious matter report submitted to AUSTRAC when reasonable grounds for suspicion exist.
Part 1
When AML/CTF May Apply
Remittance services move value for customers, often across borders and through agents or networks. The provider’s role and registration category should be clear.
- Accepting instructions to transfer money or value for a customer.
- Operating as a remittance network provider.
- Providing remittance as an affiliate of a network.
- Operating as an independent remittance dealer.
- Providing another payment, account or virtual-asset designated service.
A business should not assume a banking partner, network provider or software platform carries its duties. Registration, program and reporting responsibilities depend on the role and legal arrangement.
Part 2
Main Risks in This Sector
These are starting points, not a ready-made risk rating. The business still needs to assess its own customers, services, countries, channels, transactions and technology.
- Fast cross-border transfers can move criminal proceeds before they are detected.
- Agents, affiliates and third-party accounts can reduce visibility and control.
- Structuring, identity fraud and mule customers can spread activity across transactions.
- High-risk corridors and cash funding can make source and purpose harder to confirm.
- A sender, funder and beneficiary may be different people with no clear relationship.
Part 3
A Practical Control Plan
- Step 1
Confirm scope
Confirm the remittance role, designated services, enrolment and registration status.
- Step 2
Build the customer process
Map the full flow of value, instructions, agents, systems and settlement accounts.
- Step 3
Set the risk controls
Set CDD, sanctions, customer-risk and transaction-monitoring rules for each channel and corridor.
- Step 4
Train and connect people
Control agents and affiliates through onboarding, training, monitoring and enforceable agreements.
- Step 5
Test and improve
Reconcile SMR, IFTI, threshold and compliance reporting with transaction data.
Part 4
Worked Examples
These examples show how the scope and risk questions can be joined. They do not replace the law or the facts of a real matter.
| Situation | Why it matters | Practical response |
|---|---|---|
| One sender makes repeated transfers just below an internal threshold. | The pattern may be structuring or an attempt to avoid attention. | Join the transactions across channels, review purpose and counterparties and assess an SMR. |
| An affiliate uses a personal bank account to settle customer transfers. | The flow may be hidden from the network, bank and monitoring systems. | Investigate immediately, apply contractual controls and assess customer, affiliate and reporting impacts. |
| Several unrelated senders pay the same overseas beneficiary. | The beneficiary may be part of a scam, mule network or criminal collection point. | Aggregate beneficiary activity, review relationships and use corridor and network intelligence. |
Part 5
Evidence That Should Be Easy to Find
- The designated-service and geographical-link analysis.
- The current sector risk assessment and the official sources used.
- Current AUSTRAC enrolment and registration records.
- A network map of affiliates, agents, settlement accounts and systems.
- Monitoring that joins customers, devices, accounts, beneficiaries and corridors.
- Reconciliation between transaction records and regulatory reports.
- Customer, beneficial ownership, risk, monitoring and reporting records.
- Training, internal review, independent assurance and remediation records.
Part 6
Common Mistakes
- Assuming registration alone meets the broader AML/CTF duties.
- Monitoring transactions one by one rather than across the customer and network.
- Failing to oversee affiliates and agents.
- Using a bank account that is not transparent about the remittance activity.
- Treating IFTI reporting as a substitute for suspicious matter assessment.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Does every business in this sector have AML/CTF duties?
No. The exact service and the other legal tests decide the answer. A business may provide both designated and non-designated services.
What should the business do first?
Confirm the remittance role, designated services, enrolment and registration status.
Can the sector risk assessment replace our own?
No. Official national and sector assessments are important sources, but the reporting entity must assess the risks it reasonably expects to face in its own business.
Can a generic AML/CTF template be used?
A template can help with structure, but it must be matched to the business’s scope, risks, people, systems and evidence. A document that is not implemented is not enough.
Do remittance providers need registration as well as enrolment?
Yes, remittance service providers generally need both, with the registration category matched to the role. Current AUSTRAC requirements should be checked.
Does a network provider remove an affiliate’s duties?
No. Some reporting arrangements may be agreed, but each party should understand and document its legal duties, controls and access to information.
Reference
Official Sources
This guide cites the following sources.
- Primary lawFederal Register of LegislationAnti-Money Laundering and Counter-Terrorism Financing Act 2006
The current Australian AML/CTF Act, including program, CDD, reporting, governance and record-keeping duties.
- Regulator guidanceAUSTRACRemittance service providers
Current AUSTRAC guidance and resources for remittance network providers, affiliates and independent dealers.
- Regulator guidanceAUSTRACWho and what we regulate
The activities-based test for deciding whether a business is a reporting entity.
- Regulator guidanceAUSTRACDevelop your AML/CTF program
The five-part process for governance, risk assessment, policies, review and independent evaluation.
- Regulator guidanceAUSTRACCustomer due diligence
Current guidance on initial, ongoing, simplified and enhanced customer due diligence.