Skip to content
Reference · The legislation

Australia’s AML/CTF law explained

What the Act says it does

The whole Act, in twelve bullets

Section 4 is a simplified outline of the entire Act, written by the drafter. It is the shortest accurate description of the regime that exists, and it is the legislation rather than a commentary on it.

The following is a simplified outline of this Act:

  • A reporting entity is a person who provides designated services. (Designated services are listed in section 6.). Lead entities of certain business groups (known as reporting groups) are also reporting entities.
  • A reporting entity must have and comply with an AML/CTF program.
  • A reporting entity must undertake initial customer due diligence before providing a designated service to the customer. However, in special cases, initial customer due diligence may be carried out after the provision of the designated service.
  • Certain pre-commencement customers are subject to modified customer due diligence.
  • Simplified customer due diligence may be undertaken in certain low risk circumstances as part of initial and ongoing customer due diligence.
  • Reporting entities must report the following to the Chief Executive Officer of AUSTRAC (the Australian Transaction Reports and Analysis Centre): (a) suspicious matters; (b) certain transactions above a threshold.
  • Certain information about international value transfer services must be reported to the AUSTRAC CEO.
  • Cross-border movements of monetary instruments must be reported to the AUSTRAC CEO, a customs officer or a police officer if the total amount moved is above a threshold.
  • Transfers of value must include certain information about the origin of the transferred value.
  • Providers of registrable remittance services or registrable remittance network services must be registered with the AUSTRAC CEO.
  • Providers of registrable virtual asset services must be registered with the AUSTRAC CEO.
  • Financial institutions are subject to restrictions in connection with entering into correspondent banking relationships.
s 4 Simplified outline, verbatim · Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) — Compilation No. 62 (C2026C00274), compilation date 1 July 2026

Inside the Act

Every Part, as the Act describes itself

Nearly every Part of the Act opens with a simplified outline of that Part. Each one below is quoted from the section that carries it. Parts 7 and 14 are absent because the Act gives them no outline.

Illustration: a large open book with a row of tab markers along its edge, one tab picked out in gold
Twenty Parts, each summarised by the Act itself
Part 1AAML/CTF programss 26A
  • A reporting entity must have and comply with an AML/CTF program. An AML/CTF program comprises the reporting entity’s ML/TF risk assessment and AML/CTF policies.
  • The ML/TF risk assessment is an assessment of the risks of money laundering, financing of terrorism and proliferation financing that the reporting entity may reasonably face in providing its designated services.
  • The AML/CTF policies must appropriately manage and mitigate those risks and ensure the reporting entity complies with this Act and instruments under this Act.
  • The AML/CTF program must be appropriate to the nature, size and complexity of the reporting entity’s business. For a lead entity of a reporting group, it must be appropriate to the nature, size and complexity of the business of each reporting entity in the reporting group.
  • The governing body of the reporting entity has responsibilities relating to the AML/CTF program, including relating to overseeing and ensuring the reporting entity complies with the AML/CTF policies, this Act and instruments under this Act.
  • The reporting entity must have an AML/CTF compliance officer. The AML/CTF compliance officer has various functions, including to oversee and coordinate the effective operation of, and compliance with, the AML/CTF policies.

s 26A Simplified outline, verbatim

See the practical AML/CTF program guide →
Part 2Customer due diligences 27
  • A reporting entity must undertake initial customer due diligence before providing a designated service to a customer. However, in special cases, initial customer due diligence may be carried out after the provision of the designated service.
  • A reporting entity must undertake ongoing customer due diligence in relation to the provision by the reporting entity of designated services.
  • Simplified customer due diligence may be undertaken in certain low risk circumstances as part of initial and ongoing customer due diligence.
  • Enhanced customer due diligence must be undertaken in certain circumstances as part of initial and ongoing customer due diligence.
  • Certain pre-commencement customers are subject to modified customer due diligence.
  • Exemptions from initial customer due diligence, and ongoing customer due diligence, apply in certain circumstances.

s 27 Simplified outline, verbatim

Part 3Reporting obligationss 40
  • A reporting entity must give the AUSTRAC CEO reports about suspicious matters.
  • If a reporting entity provides a designated service that involves a threshold transaction, the reporting entity must give the AUSTRAC CEO a report about the transaction.
  • If a person provides an international value transfer service, the person must give the AUSTRAC CEO a report about the provision of the service.
  • If a person provides a designated service involving a transfer of virtual assets to or from an unverified self hosted virtual asset wallet, the person must give the AUSTRAC CEO a report about the provision of the service.
  • A reporting entity may be required to give AML/CTF compliance reports to the AUSTRAC CEO.

s 40 Simplified outline, verbatim

Part 3AReporting Entities Rolls 51A
  • Reporting entities must be entered on the Reporting Entities Roll.

s 51A Simplified outline, verbatim

Part 4Reports about cross-border movements of monetary instrumentss 52
  • Cross-border movements of monetary instruments must be reported to the AUSTRAC CEO, a customs officer or a police officer if the total value moved is $10,000 or more.

s 52 Simplified outline, verbatim

Part 5Obligations relating to transfers of values 63
  • An ordering institution, a beneficiary institution and an intermediary institution in a transfer of value must fulfil certain obligations in relation to the transfer.
  • The obligations of an ordering institution relate to the information the institution collects, verifies and provides as part of the transfer.
  • The obligations of a beneficiary institution relate to the information the institution receives or otherwise obtains as part of the transfer.
  • The obligations of an intermediary institution relate to the information the institution receives and provides as part of the transfer.
  • Additional obligations apply if the transfer of value is a transfer of a virtual asset.

s 63 Simplified outline, verbatim

Part 6The Remittance Sector Registers 73
  • This Part provides for a tiered system of registration for providers of registrable remittance network services and providers of registrable remittance services.
  • Division 2 sets out offences and civil penalties in relation to the provision of registrable remittance network services and registrable remittance services by persons who are not registered.
  • Division 3 requires the AUSTRAC CEO to maintain the Remittance Sector Register and sets out the process of applying for registration.

s 73 Simplified outline, verbatim

Part 6AThe Virtual Asset Service Provider Registers 76
  • This Part provides for a system of registration for providers of virtual asset services.
  • Division 2 sets out offences and civil penalties in relation to the provision of registrable virtual asset services by persons who are not registered.
  • Division 3 requires the AUSTRAC CEO to maintain the Virtual Asset Service Provider Register and sets out the process of applying for registration.

s 76 Simplified outline, verbatim

Part 8Correspondent bankings 94
  • A financial institution must not enter into a correspondent banking relationship with: (a) a shell bank; or (b) another financial institution that has a correspondent banking relationship with a shell bank; or (c) another financial institution that permits its accounts to be used by a shell bank.
  • A financial institution must carry out due diligence assessments before it enters into, and while it is in, a correspondent banking relationship with another financial institution involving a vostro account.

s 94 Simplified outline, verbatim

Part 9Countermeasuress 101
  • The regulations may prohibit or regulate the entering into of transactions with residents of prescribed foreign countries.

s 101 Simplified outline, verbatim

Part 10Record-keeping requirementss 104
  • The AML/CTF Rules may provide that a reporting entity must make a record of a designated service. The reporting entity must retain the record for 7 years.
  • If a customer of a reporting entity gives the reporting entity a document relating to the provision of a designated service, the reporting entity must retain the document for 7 years.
  • A reporting entity must retain records relating to: (a) customer due diligence; and (b) assessments it carries out of agreements or arrangements it has entered into relating to its reliance on the collection and verification of KYC information about a customer, or other procedures, carried out by another person.
  • A reporting entity must retain records relating to its AML/CTF program.

s 104 Simplified outline, verbatim

Part 11Secrecy and accesss 120
  • Except as permitted by this Act, an AUSTRAC entrusted person must not access, make a record of, authorise access to, disclose or otherwise use AUSTRAC information.
  • A reporting entity must not disclose: (a) that the reporting entity has given, or is required to give, a report under subsection 41(2); or (b) any information from which it could reasonably be inferred that the reporting entity has given, or is required to give, that report.
  • Certain persons must not disclose information relating to the giving or production of certain reports, information or other documents.
  • The AUSTRAC CEO may authorise officials of Commonwealth, State or Territory agencies to access AUSTRAC information for the purposes of performing the agency’s functions and duties and exercising the agency’s powers.
  • In certain circumstances, AUSTRAC information may be disclosed to governments of foreign countries or to foreign agencies.
  • There are restrictions on persons using or disclosing AUSTRAC information where the information was disclosed to the persons in contravention of this Part.

s 120 Simplified outline, verbatim

Part 12Offencess 135
  • It is an offence to: (a) produce false or misleading information; or (b) produce a false or misleading document; or (c) forge a document for use in customer due diligence under Part 2; or (d) provide or receive a designated service using a false customer name or customer anonymity; or (e) structure a transaction to avoid a reporting obligation under this Act.

s 135 Simplified outline, verbatim

Part 13Audits 144
  • An authorised officer may enter any reporting entity business premises: (a) with the occupier’s consent; or (b) under a monitoring warrant.
  • An authorised officer who enters any reporting entity business premises may exercise monitoring powers.
  • The AUSTRAC CEO may require a reporting entity to carry out an external audit or a money laundering and terrorism financing risk assessment.

s 144 Simplified outline, verbatim

Part 15Enforcements 173
  • Pecuniary penalties are payable for contraventions of civil penalty provisions.
  • Authorised officers, customs officers and police officers may issue infringement notices for unreported cross-border movements of monetary instruments.
  • The AUSTRAC CEO is to monitor compliance by reporting entities with their obligations under this Act, the regulations and the AML/CTF Rules.
  • The AUSTRAC CEO may give a remedial direction to a reporting entity that has contravened a civil penalty provision.
  • The Federal Court may grant injunctions in relation to contraventions of civil penalty provisions.
  • The AUSTRAC CEO may accept enforceable undertakings.
  • Customs officers and police officers may exercise powers of questioning, search and arrest in connection with a cross-border movement of monetary instruments.

s 173 Simplified outline, verbatim

Part 16Administrations 208
  • AUSTRAC is continued in existence.
  • There is to be a Chief Executive Officer of AUSTRAC.
  • The AUSTRAC CEO’s functions include the compilation and analysis of AUSTRAC information.
  • The AUSTRAC CEO may arrange for the use of computer programs for any purposes for which the AUSTRAC CEO may take certain administrative action under this Act, the AML/CTF Rules or other instruments made under this Act.
  • The AUSTRAC CEO may make AML/CTF Rules.

s 208 Simplified outline, verbatim

Part 17Vicarious liabilitys 230
  • This Part deals with the proof of matters that involve employees, agents etc.

s 230 Simplified outline, verbatim

Part 17AReview of decisionss 233A
  • Certain decisions of delegates of the AUSTRAC CEO may be reviewed by the Administrative Review Tribunal following a process of internal reconsideration by the AUSTRAC CEO.
  • Certain decisions of the AUSTRAC CEO may be reviewed by the Administrative Review Tribunal.

s 233A Simplified outline, verbatim

Part 17BExemptionss 233H
  • This Part provides that certain provisions of this Act do not apply to certain persons, or in certain circumstances.

s 233H Simplified outline, verbatim

Part 18Miscellaneouss 234
  • Proceedings do not lie against a person in relation to anything done, or omitted to be done, in compliance, or in purported compliance, with a requirement under this Act, the regulations or the AML/CTF Rules.
  • In proceedings for a contravention of this Act or the regulations, it is a defence if the defendant proves that the defendant took reasonable precautions, and exercised due diligence, to avoid the contravention.
  • There is a defence to a contravention of certain civil penalty provisions relating to the law of a foreign country preventing compliance.
  • Provision is made in relation to how this Act applies to reporting groups.
  • Partnerships, trusts and unincorporated associations are to be treated as persons for the purposes of this Act.
  • This Act is not intended to affect the concurrent operation of State and Territory laws.
  • This Act does not affect the law relating to legal professional privilege.
  • A contravention of this Act does not affect the validity of any transaction.
  • Provision is made in relation to the making of reports to the AUSTRAC CEO etc.
  • Provision is made in relation to the performance of non-judicial functions by magistrates.
  • This Act does not apply to a designated service specified in the AML/CTF Rules.
  • The AUSTRAC CEO may exempt a person from this Act, or modify the application of this Act to a person.
  • There is to be a review of the operation of this Act.
  • The Governor-General may make regulations for the purposes of this Act.

s 234 Simplified outline, verbatim

Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) — Compilation No. 62 (C2026C00274), compilation date 1 July 2026

The three instruments

The Act, the Amendment Act, and the Rules

Everything above is the Act. Two other instruments sit beside it, made by different bodies at different times: the Amendment Act 2024, which rewrote it, and the AML/CTF Rules 2025, which carry the operational detail and bind exactly as the Act does.

01

The Act

Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)

The primary legislation. It defines who is regulated, which services trigger obligations, what a reporting entity must do, and the consequences of not doing it. Whether the regime speaks to you at all is decided here, in section 6.

Made by
Parliament
When
Enacted 2006, substantially amended 2024
02

The Amendment Act

Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth)

The change that created Tranche 2. It extended the regime to real estate, legal, accounting, conveyancing, and dealers in precious metals and stones, rewrote customer due diligence, modernised virtual asset regulation, and repealed the Financial Transaction Reports Act 1988. It is an amending Act, so its work now lives inside the Act above — you read it to understand what changed, not to find your obligations.

Made by
Parliament
When
Passed 29 November 2024, assent 10 December 2024
03

The Rules

Anti-Money Laundering and Counter-Terrorism Financing Rules 2025

The operational detail. The Act says what must happen; the Rules say what it has to look like — enrolment, what an AML/CTF program must contain, how customer due diligence is carried out, and the compliance officer requirements. Made by the AUSTRAC CEO rather than the Minister, which is a common slip, and it binds exactly as the Act does.

Made by
the AUSTRAC CEO, under s 229(1) of the Act
When
Registered 29 August 2025
Compilation
F2026C00274

What changed in 2024

The Amendment Act, schedule by schedule

Schedule 3 is the one that created Tranche 2. The rest matter because they changed obligations that already existed — most of all schedule 2, which rewrote customer due diligence for everybody, not only the new sectors.

Illustration: two stacks of sheets, the right stack taller by several added sheets picked out in gold
An amending Act adds to the Act. Its work now lives inside the first one
The schedules of the AML/CTF Amendment Act 2024 and what each changed
SchSubjectWhat it did
1AML/CTF programs and reporting groupsReplaces the designated business group model with a reporting group structure, and puts named responsibilities on the governing body and the AML/CTF compliance officer.
2Customer due diligenceRedesigns CDD: initial before the service, ongoing through the relationship, enhanced for higher risk such as foreign PEPs and complex structures, simplified where risk is demonstrably low.
3Additional high-risk servicesThe core of Tranche 2. Adds table 5 for real estate (2 items), expands table 2 for dealers in precious metals and stones, and adds table 6 for professional services (9 items covering lawyers, accountants, conveyancers and trust and company service providers).
4Legal professional privilegeThe compromise that ended a twenty-year standoff. Lawyers are caught for specific designated services — property, client money, company and trust formation — and not for legal advice or representation as such.
5Tipping off and disclosureRecasts the tipping-off offence around prejudicing an investigation, with clearer room for permitted disclosures inside a reporting group.
6Virtual assetsReplaces “digital currency exchange” with “virtual asset service provider”, and reaches asset-to-asset exchange, transfer, custody and related services.
7Bearer negotiable instrumentsUpdates the definitions for cross-border movement of physical instruments such as cheques, money orders and traveller’s cheques.
8Transfers of valueAligns with FATF Recommendations 15 and 16 — payer and payee information must accompany transfers, virtual asset transfers included.
9Powers and definitionsNew examination and information-gathering powers for AUSTRAC, and modernised definitions through the Act.
10ExemptionsA framework for AUSTRAC to exempt where compliance would not be proportionate to the risk, exercised through the Rules.
11Repeal of the FTR Act 1988Repeals the Financial Transaction Reports Act 1988, the predecessor regime, so the obligations sit under one Act.

AML/CTF Amendment Act 2024 (Cth) — Act No. 110, 2024

The question this page cannot answer

Whether the Act applies to you. That turns on the services you provide, which is section 6 and its tables — not on your profession, your size or your ABN. Two firms with the same shingle can land on opposite sides of it.

Sources

Read the instruments themselves

This content is general information only. It is not legal, financial or compliance advice. Organisations should check AUSTRAC guidance, legislation, their own AML/CTF Program and professional advice where needed. Published by GetPost Labs Pty Ltd, a technology company building compliance software. Compilation IDs last checked against the Federal Register on 18 August 2026. If you spot an error, tell us at australia@getpostlabs.io.

From the Act to a working program

Lex-AML helps organise the obligations this legislation creates — program management, customer onboarding, due diligence, and the records and evidence behind each decision.

Book a demo