AML/CTF Guide for Superannuation in Australia
Australian superannuation businesses can be reporting entities for designated account, investment, payment and related services provided to members and other customers. This guide explains scope, sector risks, practical controls, examples and official sources in plain English.
How this guide was researched and reviewedOn this page
Short answer
Australian superannuation businesses can be reporting entities for designated account, investment, payment and related services provided to members and other customers.
Scope is based on each designated service, the business test and the geographical link. Check current exemptions and modifications before relying on a result.
At a glance
Start With These Four Checks
Map the service
Write down exactly what is done for the customer and match it to section 6.
Know the customer
Identify the customer, beneficial owners, people acting for them and the purpose of the work.
Follow the sector risk
Build controls around how money, property, structures, products and instructions move in this sector.
Keep the evidence
Scope, CDD, risk, monitoring, reports, training and review should be easy to prove.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- Designated service
- A service listed in section 6 of the Australian AML/CTF Act.
- Reporting entity
- A person or business that must meet AML obligations for the covered service or activity.
- Beneficial owner
- The individual who ultimately owns or controls the customer or on whose behalf the work is done.
- Enhanced CDD
- Extra customer and source checks used when the law or higher risk requires them.
- SMR
- A suspicious matter report submitted to AUSTRAC when reasonable grounds for suspicion exist.
Part 1
When AML/CTF May Apply
The legal entity, product and service role should be mapped across trustees, administrators, custodians and other service providers.
- Opening or operating relevant superannuation or investment interests.
- Accepting contributions and processing transfers or rollovers where designated.
- Holding, investing or paying member money through a listed service.
- Making benefit, release or other designated payments.
- Providing related custody, account, financial or payment services.
The superannuation label does not decide which entity performs each designated service. Outsourcing administration or custody does not automatically transfer the trustee’s responsibilities.
Part 2
Main Risks in This Sector
These are starting points, not a ready-made risk rating. The business still needs to assess its own customers, services, countries, channels, transactions and technology.
- Identity theft and account takeover can redirect benefits or early-release payments.
- Third-party contributions, rollovers and refunds can hide source or beneficial control.
- Complex employer, member and related-party activity can obscure who is funding whom.
- Self-managed and other structures can be misused to move or disguise assets.
- Outsourced administrators and fragmented data can delay detection and reporting.
Part 3
A Practical Control Plan
- Step 1
Confirm scope
Map designated services and responsibilities across the trustee, fund, administrator and custodian.
- Step 2
Build the customer process
Connect member identity, contribution, rollover, payment and fraud information.
- Step 3
Set the risk controls
Set event-driven CDD and monitoring for changed bank accounts, contact details, access and release requests.
- Step 4
Train and connect people
Control outsourced work through data access, testing, incidents and reporting duties.
- Step 5
Test and improve
Test high-risk member journeys and reconcile regulatory reports with source systems.
Part 4
Worked Examples
These examples show how the scope and risk questions can be joined. They do not replace the law or the facts of a real matter.
| Situation | Why it matters | Practical response |
|---|---|---|
| A member changes contact and bank details before a large release request. | The account may have been taken over and the payment redirected. | Use an independent verification path, review access and device history and assess linked activity. |
| Large contributions come from an unrelated third party. | The contribution may not fit the member’s profile or lawful purpose. | Identify the funder and relationship, assess source and purpose and update monitoring and risk. |
| An administrator handles onboarding and alerts for the trustee. | The trustee may lack visibility of control quality, backlogs or suspicious matters. | Define responsibilities, data access, measures, escalation and independent testing in the arrangement. |
Part 5
Evidence That Should Be Easy to Find
- The designated-service and geographical-link analysis.
- The current sector risk assessment and the official sources used.
- A responsibility map across trustees, funds, administrators and custodians.
- Joined member, contribution, rollover, access and payment information.
- Testing of identity-change, bank-change and release controls.
- Service-provider measures, incident records and reporting reconciliations.
- Customer, beneficial ownership, risk, monitoring and reporting records.
- Training, internal review, independent assurance and remediation records.
Part 6
Common Mistakes
- Assuming the administrator owns every AML/CTF duty.
- Treating a verified member identity as permanent despite account changes.
- Monitoring payments without contributions and rollovers.
- Separating fraud cases from suspicious matter assessment.
- Failing to test outsourced data and alert quality.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Does every business in this sector have AML/CTF duties?
No. The exact service and the other legal tests decide the answer. A business may provide both designated and non-designated services.
What should the business do first?
Map designated services and responsibilities across the trustee, fund, administrator and custodian.
Can the sector risk assessment replace our own?
No. Official national and sector assessments are important sources, but the reporting entity must assess the risks it reasonably expects to face in its own business.
Can a generic AML/CTF template be used?
A template can help with structure, but it must be matched to the business’s scope, risks, people, systems and evidence. A document that is not implemented is not enough.
Can AML/CTF work be outsourced to an administrator?
Tasks can be outsourced, but the legal responsibilities, information access, oversight and evidence should be mapped. Outsourcing does not remove accountability.
Are fraud and AML/CTF the same control?
They overlap but are not the same. Fraud indicators may create an SMR duty, while AML/CTF adds its own CDD, reporting, governance and record requirements.
Reference
Official Sources
This guide cites the following sources.
- Primary lawFederal Register of LegislationAnti-Money Laundering and Counter-Terrorism Financing Act 2006
The current Australian AML/CTF Act, including program, CDD, reporting, governance and record-keeping duties.
- Regulator guidanceAUSTRACSuperannuation industry
Current AUSTRAC guidance and resources for superannuation trustees, funds and administrators.
- Regulator guidanceAUSTRACWho and what we regulate
The activities-based test for deciding whether a business is a reporting entity.
- Regulator guidanceAUSTRACDevelop your AML/CTF program
The five-part process for governance, risk assessment, policies, review and independent evaluation.
- Regulator guidanceAUSTRACCustomer due diligence
Current guidance on initial, ongoing, simplified and enhanced customer due diligence.