AML/CTF Programs for Accounting Firms in Australia: What Accountants Should Have in Place After 1 July 2026

AML/CTF reforms

Australian accounting firms that provide certain professional services are now within the expanded AML/CTF regime. From 1 July 2026, a firm that provides a designated service with a geographical link to Australia may need an AML/CTF program, customer due diligence procedures, staff training, reporting processes and records that match the way the practice actually works.

The AML/CTF Tranche 2 reforms now represent a live compliance issue, not a future reform project. For partners, principals and practice managers, the immediate task is to identify which service lines are regulated, confirm whether the firm is a reporting entity, and turn AUSTRAC’s requirements into file-opening and matter-management processes that staff can follow.

Short answer

From 1 July 2026, an accounting firm that provides one or more professional designated services with a geographical link to Australia may be a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). The firm may need to enrol with AUSTRAC, have an AML/CTF program before providing designated services, conduct customer due diligence, appoint and notify AUSTRAC of an AML/CTF compliance officer, monitor and report suspicious matters where required, train staff, and keep records.

The legal trigger is the service provided, not the professional label. A firm that only provides ordinary tax compliance work may have a different position from a firm that forms companies and trusts, acts as registered office, assists with business sales, helps execute restructuring transactions, or manages client property for a transaction.

Why accounting firms should review AML/CTF compliance now

The expanded AML/CTF regime is now in force for newly regulated accounting, legal, real estate and related professional services. AUSTRAC opened enrolment for new professions on 31 March 2026, and the relevant tranche 2 obligations commenced on 1 July 2026 for businesses that provide designated services.

For accounting firms, the practical risk is that regulated work may sit inside familiar service lines. Company formation, trust establishment, SMSF structuring, registered office services, business sale support, restructuring, equity or debt financing assistance, and transaction-related asset handling may be treated internally as routine advisory or administration. Under the AML/CTF regime, some of that work may need documented customer due diligence, risk assessment, escalation and record-keeping controls.

Small and mid-sized practices can face particular implementation pressure. Many firms rely on partner judgement, long-standing client relationships and informal onboarding knowledge. The new regime expects documented processes that can be applied consistently by partners, managers, bookkeepers, offshore teams and administrative staff.

Practical point

A service-line map should come before policy drafting. If the firm has not identified which services may be designated services, the AML/CTF program may be too broad to use or too narrow to manage the real risk.

Accounting services that may trigger AML/CTF obligations

AUSTRAC’s professional designated services guidance explains that obligations depend on whether the business provides one or more designated services with a geographical link to Australia. The professional services category can include services commonly provided by lawyers, accountants, conveyancers, insolvency practitioners, financial advisers and other professional service providers.

For accounting firms, the services most likely to require review include:

  • planning or executing a transaction to sell, buy or transfer real estate;
  • planning or executing a transaction to sell, buy or transfer a body corporate or legal arrangement (such as a trust or partnership);
  • receiving, holding, controlling or managing a person’s property to help plan or execute a transaction;
  • organising, planning or executing equity or debt financing for a body corporate or legal arrangement (such as a trust or partnership);
  • selling or transferring a shelf company;
  • creating or restructuring a company, trust, SMSF or other legal arrangement (such as a partnership);
  • acting, or arranging for another person to act, in certain positions in a body corporate or legal arrangement; and
  • providing a registered office address or principal place of business address for a body corporate or legal arrangement (such as a trust or partnership).

The boundary can be fact-dependent. A general discussion about the tax effect of a proposed restructure may raise different issues from preparing documents, arranging parties, forming entities or otherwise helping execute the restructure. Firms should assess actual work performed, not only engagement descriptions or website service categories.

What an AML/CTF program should contain

An AML/CTF program should be tailored to the business. AUSTRAC describes the program as including a money laundering and terrorism financing risk assessment and AML/CTF policies that manage and mitigate those risks.

For an accounting firm, the risk assessment should consider the firm’s clients, services, delivery channels and geographic exposure. A practice that mainly prepares local tax returns for individuals will usually have a different risk profile from a practice that establishes companies and trusts, supports business acquisitions, has offshore clients, handles complex ownership structures, or deals with clients exposed to virtual assets or high-value property transactions.

The AML/CTF policies should explain how the firm applies the risk assessment in everyday work. Useful policies usually address:

  1. Governance: who approves the program, who owns it day to day, and how partners receive reports about material AML/CTF issues.
  2. Customer due diligence: what information is collected before providing a designated service, how identity and beneficial ownership are verified, and when simplified or enhanced due diligence may apply.
  3. Matter risk assessment: how staff identify higher-risk work, including unusual structures, complex ownership, offshore entities, source of funds concerns, politically exposed persons and virtual asset exposure.
  4. Escalation: when staff must escalate concerns, who decides whether further work can proceed, and how suspicious matter reporting is handled without breaching tipping-off restrictions.
  5. Training: which staff need role-specific training, how often training occurs, and how attendance and understanding are recorded.
  6. Records and review: what records are retained, where they are stored, who can access them, and how the firm reviews and updates the program.

A useful AML/CTF program should tell a manager exactly what to do when opening a new trust client, verifying a beneficial owner, dealing with a reluctant client, identifying unusual source of funds information, or escalating a suspicious transaction request.

Governance and the AML/CTF compliance officer

The current AML/CTF Act contains specific provisions dealing with AML/CTF programs, governing body responsibilities and AML/CTF compliance officers. AUSTRAC guidance states that a reporting entity must appoint an AML/CTF compliance officer within 28 days of providing designated services and notify AUSTRAC within 14 days of the appointment.

For newly regulated entities, AUSTRAC states that notification must occur no later than the later of 29 July 2026 or 14 days after enrolling. The compliance officer must satisfy eligibility requirements, including management-level engagement, Australian residency where the relevant designated services are provided at or through a permanent establishment in Australia, and fit and proper considerations.

In a small accounting firm, the compliance officer may be a partner, principal, practice manager or another person with enough authority to coordinate compliance. In a larger group, the role may sit with a risk, operations or compliance leader. Outsourcing support can assist with drafting, training or review, but the firm should still identify who has internal responsibility for decisions and escalation.

A practical service-line review for accountants

The service-line review should connect legal classification to operational change. Each service should be assessed against the designated services, the firm’s actual work steps, the client types involved and the systems used to open and manage files.

Service line AML/CTF issue to assess Implementation priority
Company, trust or SMSF formation Whether the firm assists in the creation or restructuring of a body corporate or legal arrangement (such as a trust or partnership), and how beneficial ownership is verified. High priority
Registered office or principal place of business services Whether address services are provided for a body corporate or legal arrangement (such as a trust or partnership) and how ongoing client monitoring is managed. High priority
Business sale, acquisition or restructuring support Whether the firm assists in planning or executing a transaction involving a company, trust, assets, real estate, equity or debt financing. High priority
Tax compliance and BAS work Whether the work remains ordinary compliance work or expands into regulated structuring, transaction execution or asset handling. Medium priority
General business advisory Whether the advice directly advances a relevant transaction or structure, or remains general strategic or financial advice. Medium priority
Bookkeeping and payroll Whether the firm also receives, holds, controls or manages client property for a transaction, or provides other designated services alongside bookkeeping. Lower priority

The output should be a working classification for each service: likely regulated, likely outside the regime, uncertain and needing legal review, or not currently offered but planned. That classification should then inform engagement letters, onboarding questions, client risk ratings, staff training and file review procedures.

Privacy and record-keeping issues

AML/CTF compliance increases the amount of personal information an accounting firm may collect. That does not create permission to collect or retain every identity document or client record indefinitely.

The OAIC has published updated privacy guidance for AML/CTF reporting entities. It states that, from 1 July 2026 for tranche 2 entities, businesses should not retain copies of full identity documents for AML/CTF record-keeping purposes unless another law requires it. The privacy analysis should cover what information is reasonably necessary, how collection notices and privacy policies describe AML/CTF handling, who can access verification records, and when information is deleted.

Accounting firms should also consider confidentiality and professional duties. Suspicious matter reporting and tipping-off restrictions can affect how the firm communicates with a client, records internal concerns and manages disengagement from a matter. Those processes should be built into the AML/CTF program before staff are expected to make judgement calls under pressure.

Where AUSTRAC’s accountant starter kit fits

AUSTRAC has released an accountant program starter kit for small practices. The starter kit can be useful where the firm satisfies the suitability criteria and is prepared to customise the documents to its own services, clients and risks.

The starter kit should be treated as a starting point. AUSTRAC’s own material states that practices that do not meet all the relevant characteristics must assess whether the starter kit is appropriate and identify changes required. Larger practices, multidisciplinary groups, firms with offshore teams, firms with complex clients and firms providing transaction-heavy services may need stronger or additional controls.

A useful review question is: would a staff member know from the program exactly what evidence to collect, what risk rating to apply, and when to escalate a new client who wants a company, family trust and asset transfer completed urgently?

Implementation checklist

Accounting firms that have not completed implementation should move from general awareness to documented controls. The following checklist is a practical starting point.

  • Confirm whether the firm provides any designated services with a geographical link to Australia.
  • Enrol with AUSTRAC if the firm is required to do so.
  • Appoint an eligible AML/CTF compliance officer and diarise AUSTRAC notification timing.
  • Prepare or update the ML/TF risk assessment for actual client types, services, delivery channels and geographic exposure.
  • Draft AML/CTF policies that staff can apply during onboarding and file management.
  • Update engagement letters, onboarding forms, privacy notices and client identification workflows.
  • Build customer due diligence and beneficial ownership checks into file-opening procedures.
  • Set escalation rules for red flags, enhanced due diligence and suspicious matter reporting.
  • Train partners, managers, client-facing staff, administrators and offshore teams according to their roles.
  • Review data retention settings so the firm does not keep unnecessary copies of identity documents.
  • Schedule periodic program review and independent evaluation where required.

Frequently asked questions

Do all accountants need an AML/CTF program in Australia?

No. AML/CTF obligations depend on whether the business provides designated services with a geographical link to Australia. Many accounting firms should still conduct a careful service-line review because corporate, trust, registered office, transaction, restructuring and asset-related work may bring the firm within the regime.

When did AML/CTF obligations start for accounting firms?

The expanded regime commenced for newly regulated accounting and related professional services on 1 July 2026. AUSTRAC opened enrolment for new professions on 31 March 2026. As at 12 July 2026, accounting firms that provide designated services should treat implementation as a current compliance issue.

What should an AML/CTF program for accountants include?

It should include an ML/TF risk assessment and written AML/CTF policies, procedures, systems and controls. For an accounting firm, this usually means governance, customer due diligence, beneficial ownership checks, matter risk ratings, enhanced due diligence triggers, suspicious matter escalation, staff training, record keeping and program review.

Can an accounting firm use AUSTRAC’s accountant starter kit?

Yes, if the firm is within the intended scope and customises the kit to its own practice. The starter kit is not a substitute for assessing the firm’s actual services, clients, systems and risks. Firms with more complex work may need additional controls.

Are company and trust formation services covered?

They are likely to be. AUSTRAC guidance identifies professional designated services that include assisting in the planning or execution of the creation or restructuring of a body corporate or legal arrangement (such as a trust or partnership). The answer depends on the facts, the service provided and the connection to Australia.

Does an accounting firm need an AML/CTF compliance officer?

A reporting entity must appoint an eligible AML/CTF compliance officer. AUSTRAC guidance states that newly regulated entities must notify AUSTRAC no later than the later of 29 July 2026 or 14 days after enrolling.

Sources

Disclaimer

This article provides general information only and is not legal advice. AML/CTF obligations depend on the services provided, the structure of the business, the firm’s geographical links, the clients involved and the facts of each engagement. Accounting firms should obtain advice on their specific circumstances before relying on this information.

Set up, grow, scale or sell your business with expert legal guidance.

Book a free consultation with us and let’s talk about how we can help your business succeed and stay competitive in the market.