You're offline — showing the last version we saved.

For accountants who provide designated services, the AML/CTF obligations began on 1 July 2026. What many firm owners now have is a starter program in a folder and a sense that nobody has changed how a new client gets onboarded.

This is the operating guide for the first 90 days after go-live: what running it looks like inside a practice, and how to do it without eating the margin. Whether you are caught at all is covered in Am I caught by AML Tranche 2?

Where the rules live. AUSTRAC is the source of truth for your obligations: its accountant program starter kit and obligations guidance, read alongside CA ANZ, CPA Australia or IPA member guidance. Everything below is as at September 2026. This is journalism, not legal advice; check anything that affects your obligations against AUSTRAC or a qualified adviser.

What changed

  1. 1 July 2026Obligations start for accountants who provide designated services.
  2. 20 July 2026TPB updates its proof of identity guidance.
  3. 29 July 2026Enrolment due for most firms.
  4. 30 June 2027First reporting period ends. It runs from 1 July 2026.
  5. 1 July to 30 September 2027First annual compliance report submitted to AUSTRAC.
  6. 30 June 2029 to 31 December 2030First independent evaluation due, set by the last two digits of your AUSTRAC account number.

Where you should be right now

AUSTRAC set out what it expected from newly regulated firms by 1 July 2026: enrolled (the enrolment deadline for most was 29 July 2026), an AML/CTF program in place, a compliance officer, staff trained on the program, and being ready to ask clients questions and report suspicious activity. Your compliance officer had to be notified to AUSTRAC by the later of 29 July 2026 or 14 days after you enrolled.

AUSTRAC has said it does not expect perfection on day one, and that its enforcement focus in the new sectors is on businesses that wilfully ignore enrolment or are complicit with, or wilfully blind to, money laundering. That is breathing room for honest effort, not permission to leave the program in the folder. If you have not enrolled, do that first.

Know which jobs trigger it

The regime attaches to services, not to your firm. AUSTRAC’s list of professional designated services includes helping a client buy, sell or transfer real estate or a company or trust, creating or restructuring a company or trust, managing client property for a transaction, selling shelf companies, acting as (or arranging) an officeholder, and providing a registered office address. In AUSTRAC’s own example, tax advice on the implications of selling a company does not, on its own, advance a transaction.

The regime attaches to services, not to your firm.

Trent McLaren, in this article

Make this visible in your systems. Create a “designated service” flag or job type in Xero Practice Manager (XPM), FYI, Kloud Connect or whatever you run, so a company setup or trust restructure cannot open as a job until due diligence is complete.

The program: a risk assessment plus policies

Your AML/CTF program has two parts: a risk assessment of the money laundering and terrorism financing risks your practice faces, and the policies and controls that manage them. Senior management approves it and the governing body oversees it; in a small practice that can be one person.

AUSTRAC’s starter kit is built for practices with 15 or fewer personnel (admin staff included) that provide only professional designated services and mostly act for Australian-resident individuals, among other criteria. Fall outside any of them and AUSTRAC says you must adapt it. The risk assessment is where firms stall; our write-up of generating AML risk assessments using AI and the summit session on the same topic cover a faster first draft that you then own.

What it means for your firm

Customer due diligence at the front door

Initial customer due diligence (CDD) has to be completed before you start providing a designated service, with limited exceptions for delayed CDD. If you cannot establish the required matters on reasonable grounds, you must not start the service. That is why the check belongs in onboarding.

Initial customer due diligence (CDD) has to be completed before you start providing a designated service, with limited exceptions for delayed CDD.

Trent McLaren, in this article

The starter kit scales the work to risk. Low-risk clients get simplified CDD, medium risk gets full initial CDD, and high risk (foreign politically exposed persons, unexplained wealth, opaque structures, unusual cash) gets enhanced CDD with source of funds checks and senior manager approval. The kit suggests reviewing client information annually for high risk, every 2 years for medium and every 3 for low; those cadences are the kit’s, not the Act’s, so set your own. For what to collect by client type, see KYC for accounting firms.

Existing clients: relief with two triggers

A client you were already providing designated services to at 1 July 2026 is a pre-commencement customer, and you can keep acting without initial CDD. Two things end that: a suspicious matter reporting obligation arising, or a significant change in the nature and purpose of the relationship that makes the client medium or high risk. Either one means full initial CDD before you provide the next designated service.

AUSTRAC’s guidance says you still monitor these clients for unusual behaviour, review their information at an appropriate frequency, and watch for that significant change. Tag them in your system and make “new structure, new country, new controller” a prompt at every job opening.

Compliance officer, training and records

The compliance officer must be at management level, an Australian resident (for services provided through an Australian establishment) and a fit and proper person, and must report to the governing body in writing at least once every 12 months. They need not be an AML expert.

Anyone in an AML/CTF role needs personnel due diligence and role-appropriate training before they start, including on tipping off. Keep records of your program, CDD, transactions and training for 7 years for most obligations.

Suspicious matters and tipping off

If you suspect on reasonable grounds that a person is not who they claim to be, or that a matter is linked to crime, a suspicious matter report (SMR) is due within 3 business days, or 24 hours if it relates to terrorism financing. Separately, a threshold transaction report is required when a single transaction involves A$10,000 or more in physical currency, within 10 business days.

Tipping off is a criminal offence, with a maximum of 2 years’ imprisonment, 120 penalty units, or both. Asking a client reasonable questions before an SMR obligation has arisen is not tipping off. Telling them you have reported them, or letting them work out that you suspect them, can be. If you end a relationship, AUSTRAC suggests giving genuine reasons that do not mention the suspicion, and documenting them.

Tipping off is a criminal offence, with a maximum of 2 years’ imprisonment, 120 penalty units, or both.

Trent McLaren, in this article

What recurs every year

AUSTRAC is moving annual compliance reports to financial years: the next period runs from 1 July 2026 to 30 June 2027, with reports submitted between 1 July and 30 September. Update your enrolment details within 14 days of a change. Your first independent evaluation falls due between 30 June 2029 and 31 December 2030, set by the last two digits of your AUSTRAC account number.

What to do this week

The 90-day plan

WhenWhat to doDone looks like
Weeks 1-2Confirm enrolment and compliance officer notification. Get the program approved in writing. Flag designated-service jobs and pre-commencement clients.No designated-service job opens without a CDD step.
Weeks 3-6Run CDD live on new designated-service work. Train everyone in an AML/CTF role, including tipping off. Update engagement letters.Training records exist and the first CDD files are complete.
Weeks 7-12Review the first CDD files against your policy. Time the work by client type and risk tier. Diarise the annual cycle.A short review note, a cost picture you trust, and next year’s dates booked.

Build it into onboarding and the engagement letter

The workflow that holds up: the intake form asks what service is wanted, a designated-service answer triggers the CDD form, the risk rating sets how much evidence you collect, and the job stays closed until the file is complete. Identity checks can sit in the same flow using tools such as Annature or IdentityCheck. The tool matters less than the gate.

Then update the engagement letter, with your lawyer’s review: the client agrees to provide identity and ownership information when asked; certain services cannot start until due diligence is complete; you may cease to act without always giving reasons; and records are kept as the law requires. Registered tax practitioners should also check the TPB’s proof of identity guidance, TPB(GS) 42/2022, which the TPB updated on 20 July 2026 to align with the AML/CTF changes.

Scope and recover the cost

You cannot recover a cost you have not measured. For a few weeks, record the time per CDD file by client type (individual, company, trust) and risk tier. Separate the fixed cost of running the program (reviews, training, the compliance officer’s time, the annual report) from the variable cost on each designated-service engagement.

Then decide whether to absorb it, build it into the scope of designated-service work, or show it as its own line. What to charge for AML compliance walks through the models firms are using and how to introduce them. Any published benchmark is only a guide; the number is yours to set from your own data.

For your practice

What it means for your fees

The work it creates

CDD before every designated service, enhanced checks for high-risk clients, and the fixed cost of running the program.

How to scope it

Time each CDD file by client type and risk tier for a few weeks. Keep fixed program cost apart from per-engagement cost.

How to price it

Absorb it, build it into designated-service scope, or show it as its own line. Set the number from your own data.

For the client letter

The law changed on 1 July 2026 for certain services we provide. Before we start them we must confirm your identity, and the work cannot begin until that is done.

Existing clients who won’t provide ID

First, check whether you need it. A pre-commencement client with no trigger may not need initial CDD yet, and a client who only gets tax returns may not receive a designated service at all.

Where you do need it, the rule is plain: no completed CDD, no designated service. Explain that the requirement is legal and offer an easy verification route. If the client still refuses, record it and consider whether it forms a suspicion to escalate to your compliance officer. Whether you keep doing their non-designated work is a risk decision your policies should answer, ideally with input from your professional body.

Whether you keep doing their non-designated work is a risk decision your policies should answer, ideally with input from your professional body.

Trent McLaren, in this article

Where we could be wrong

The assumption most likely to be wrong is AUSTRAC’s day-one tolerance. This guide takes AUSTRAC at its word that early enforcement targets wilful non-compliance, not honest firms bedding the program in. That is a statement of focus, not a safe harbour, and it can change.

What would change the advice: new AUSTRAC guidance on the reporting cycle (the dates above follow its current guidance), or professional body guidance on non-designated work for clients who refuse ID.

What we could not verify: how AUSTRAC will treat a starter-kit program at a firm just outside the kit’s criteria.

Frequently asked questions

Do I need to re-identify every existing client now?

No. Pre-commencement clients can continue without initial CDD until an SMR obligation arises or a significant change makes them medium or high risk. Ongoing monitoring still applies, so the task is tagging them, not collecting documents from everyone.

Can the owner be the compliance officer?

Yes. AUSTRAC says the compliance officer, senior manager and governing body can all be the same person, provided they meet the management level, residency and fit and proper requirements. The annual report to the governing body works differently when one person holds every role.

Is the AUSTRAC starter kit enough on its own?

Only if your practice meets every suitability criterion AUSTRAC lists, including 15 or fewer personnel and only professional designated services. Outside those, AUSTRAC says you must assess what to change, and larger firms will usually need stronger controls.

What if a client asks why we need their ID now?

Tell them the law changed on 1 July 2026 and applies to certain services you provide. That is safe. What you must not do is suggest you suspect them or have reported them, which risks tipping off.

When is our first compliance report due?

AUSTRAC’s current guidance puts the first financial-year reporting period at 1 July 2026 to 30 June 2027, with submission between 1 July and 30 September 2027. Keep your AUSTRAC Online contacts current so the reminders reach you.

Sponsored

RadiusCore — Xero-connected Excel workflows. Start your 30-day free trial.

AML/CTFAUSTRACTranche 2Customer Due DiligenceClient OnboardingEngagement Letters

Was this useful?
Thanks — noted.

Sponsored

Easy Business App
Read next
Related