AML/CTF Guide for Trust and Company Service Providers in Australia
Australian trust and company service providers are regulated when their formation, restructuring, shelf-company, nominee, office-holder or address services meet a designated professional service. This guide explains scope, sector risks, practical controls, examples and official sources in plain English.
How this guide was researched and reviewedOn this page
Short answer
Australian trust and company service providers are regulated when their formation, restructuring, shelf-company, nominee, office-holder or address services meet a designated professional service.
Scope is based on each designated service, the business test and the geographical link. Check current exemptions and modifications before relying on a result.
At a glance
Start With These Four Checks
Map the service
Write down exactly what is done for the customer and match it to section 6.
Know the customer
Identify the customer, beneficial owners, people acting for them and the purpose of the work.
Follow the sector risk
Build controls around how money, property, structures, products and instructions move in this sector.
Keep the evidence
Scope, CDD, risk, monitoring, reports, training and review should be easy to prove.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- Designated service
- A service listed in section 6 of the Australian AML/CTF Act.
- Reporting entity
- A person or business that must meet AML obligations for the covered service or activity.
- Beneficial owner
- The individual who ultimately owns or controls the customer or on whose behalf the work is done.
- Enhanced CDD
- Extra customer and source checks used when the law or higher risk requires them.
- SMR
- A suspicious matter report submitted to AUSTRAC when reasonable grounds for suspicion exist.
Part 1
When AML/CTF May Apply
TCSP work can create or operate the legal structures used to own and move assets. The exact service, customer and Australian link decide whether the law applies.
- Creating or restructuring a company, trust or other legal arrangement.
- Selling or transferring a shelf company.
- Acting or arranging for a person to act as a director, secretary, partner, trustee or nominee.
- Providing a registered office or principal place of business.
- Handling client property or helping with a relevant company or trust transaction.
Software, mail forwarding or ordinary administrative work is not automatically covered. A bundled service may still include one or more designated services, so its components should be separated and mapped.
Part 2
Main Risks in This Sector
These are starting points, not a ready-made risk rating. The business still needs to assess its own customers, services, countries, channels, transactions and technology.
- Layered companies and trusts can hide beneficial ownership and control.
- Nominee officers and registered addresses can create a false appearance of substance.
- Shelf companies can give a new business an older history.
- Cross-border structures can separate assets, controllers and records across countries.
- A provider may know each entity but miss the full network controlled by one customer.
Part 3
A Practical Control Plan
- Step 1
Confirm scope
Map every formation, restructuring, nominee, trustee and address service.
- Step 2
Build the customer process
Identify the customer, beneficial owners, controllers and the purpose of each structure.
- Step 3
Set the risk controls
Join related entities and appointments so the full customer network can be seen.
- Step 4
Train and connect people
Set enhanced approval for opaque, cross-border, nominee and high-risk arrangements.
- Step 5
Test and improve
Monitor changes to owners, officers, addresses, funding and activity over the life of the service.
Part 4
Worked Examples
These examples show how the scope and risk questions can be joined. They do not replace the law or the facts of a real matter.
| Situation | Why it matters | Practical response |
|---|---|---|
| A client asks for several companies with nominee directors and one address. | The structure may hide control, create false substance or support movement of assets. | Map the full network, identify controllers and purpose, and apply enhanced checks and approval. |
| A provider sells a shelf company to an overseas buyer. | The company’s age and history may be used to create false credibility. | Complete CDD before the transfer, understand intended use and assess source and country risk. |
| Ownership changes soon after onboarding. | The original CDD and risk rating may no longer describe the real customer. | Update beneficial ownership, purpose and risk, then consider enhanced CDD and reporting. |
Part 5
Evidence That Should Be Easy to Find
- The designated-service and geographical-link analysis.
- The current sector risk assessment and the official sources used.
- A complete register of entities, arrangements, officers, nominees and addresses.
- Network diagrams linking related customers and beneficial owners.
- Purpose, source, country and approval records for higher-risk structures.
- Ongoing reviews of ownership, control, officers and service use.
- Customer, beneficial ownership, risk, monitoring and reporting records.
- Training, internal review, independent assurance and remediation records.
Part 6
Common Mistakes
- Checking each company separately and missing the wider network.
- Accepting nominee arrangements without understanding the real controller.
- Treating a registered-office service as low risk because no money is handled.
- Failing to update CDD when owners or officers change.
- Relying on formation documents produced by the provider as independent proof.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Does every business in this sector have AML/CTF duties?
No. The exact service and the other legal tests decide the answer. A business may provide both designated and non-designated services.
What should the business do first?
Map every formation, restructuring, nominee, trustee and address service.
Can the sector risk assessment replace our own?
No. Official national and sector assessments are important sources, but the reporting entity must assess the risks it reasonably expects to face in its own business.
Can a generic AML/CTF template be used?
A template can help with structure, but it must be matched to the business’s scope, risks, people, systems and evidence. A document that is not implemented is not enough.
Is a registered-office service covered?
It can be a designated professional service when the legal conditions are met. The exact service and customer should be checked against current AUSTRAC guidance.
Must related companies be viewed together?
The risk assessment and monitoring should be capable of seeing related entities, common controllers and linked activity. Reviewing each entity in isolation can miss the real risk.
Reference
Official Sources
This guide cites the following sources.
- Primary lawFederal Register of LegislationAnti-Money Laundering and Counter-Terrorism Financing Act 2006
The current Australian AML/CTF Act, including program, CDD, reporting, governance and record-keeping duties.
- Regulator guidanceAUSTRACProfessional designated services
Current AUSTRAC guidance and resources for trust and company service providers.
- Regulator guidanceAUSTRACWho and what we regulate
The activities-based test for deciding whether a business is a reporting entity.
- Regulator guidanceAUSTRACDevelop your AML/CTF program
The five-part process for governance, risk assessment, policies, review and independent evaluation.
- Regulator guidanceAUSTRACCustomer due diligence
Current guidance on initial, ongoing, simplified and enhanced customer due diligence.