AML/CTF Reforms 2026: What your business needs to know now

Key contacts

Australia’s Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) reforms represent one of the most significant regulatory expansions in over a decade.

For the first time, a broader range of professional and non-financial sectors often referred to as “gatekeeper professions” will fall within the scope of AML/CTF obligations.

If your business operates in accounting, legal services, real estate, trust and company services, or high value goods (such as jewellers), the reforms may directly impact you.

 

Why is the reform happening?

AUSTRAC and international regulatory bodies have identified that certain professions can be used knowingly or unknowingly to facilitate:

  • Complex corporate structuring
  • Concealment of beneficial ownership
  • Property based money laundering
  • High value asset transfers
  • Cross border financial movements

 

To strengthen Australia’s financial integrity framework and align with international standards, AML/CTF obligations are being extended to additional sectors.

This is not a short-term compliance initiative. It is a structural regulatory shift.

 

Who is impacted?

The reforms are expected to affect businesses that provide designated services in sectors such as:

  • Accountants and Tax Agents
  • Law Firms (Legal Practitioners)
  • Real Estate Agents and Conveyancers
  • Trust and Company Service Providers (TCSPs)
  • Dealers in high value goods (including jewellers)

 

Each sector carries different risk profiles, but the underlying regulatory framework will be broadly consistent.

 

What obligations may apply?

Where captured under the regime, businesses may be required to:

  • Enrol with AUSTRAC
  • Develop and maintain a documented, risk-based AML/CTF Program
  • Appoint an AML/CTF Compliance Officer
  • Conduct customer due diligence, including verification of beneficial ownership
  • Monitor higher risk clients and transactions
  • Submit suspicious matter reports where required
  • Maintain detailed record-keeping procedures
  • Ensure compliance with the Privacy Act

 

These obligations are ongoing and governance based. They extend beyond initial setup.

 

The practical business impact

So, what does this mean in practice for your business?

Governance and accountability

Directors, partners and senior management will be expected to formally oversee AML/CTF compliance. Regulatory expectations extend beyond administrative compliance to active governance oversight.

Cultural and operational change

Client onboarding processes may need adjustment. Additional identity verification, documentation and monitoring procedures may introduce friction into fast-paced or relationship-driven environments.

Increased documentation

Risk assessments, compliance programs, internal registers and reporting frameworks must be documented, reviewed and maintained.

Additional privacy obligations

Small businesses, which were previously exempt from the Privacy Act, will need to ensure business practices comply with the Australian Privacy Principles. Significant uplift may be required to check data flows and develop a compliant Privacy Policy, collection notices, data retention procedure, and more.

Resource pressure

Many affected businesses do not have dedicated compliance teams. This means implementation and ongoing management can put a strain on internal resources.

 

Sector specific considerations

While the framework is consistent, sector risk profiles do vary:

  • Accounting and Legal Services: Corporate structuring, trust arrangements and high net worth advisory create heightened scrutiny.
  • Real Estate and Conveyancing: Property transactions remain a primary channel for money laundering risk.
  • Trust and Company Service Providers: Beneficial ownership transparency and international exposure increase regulatory attention.
  • Jewellers and High-Value Goods Dealers: Cash-intensive and high-value transactions elevate monitoring obligations.

 

Understanding how the reforms intersect with your specific service offering is critical. Please get in touch with us and one of our Source compliance specialists will be in contact to talk through the specific considerations for your business.

 

What businesses should do now

Preparation should begin well before enforcement intensifies.

Practical first steps include:

  • Confirming whether your services fall within designated categories
  • Conducting a preliminary risk exposure assessment
  • Identifying an appropriate AML/CTF Compliance Officer
  • Reviewing governance and reporting lines
  • Assessing existing client onboarding processes
  • Planning for training and policy updates

 

Early preparation reduces the risk of reactive, high-pressure implementation later. If you need help with any of these actions, our team of experts are here to help.

 

Privacy readiness

From 1 July 2026, businesses newly regulated by the AML/CTF reforms will also become regulated by the Privacy Act. The ‘small business’ exemption will no longer apply to AML/CTF regulated entities.

Businesses should prepare by:

  • Drafting collection notices and a Privacy Policy
  • Assessing data flows for compliance with the Australian Privacy Principles
  • Ensuring data retention procedures are appropriate
  • Training staff in their privacy obligations

The reform direction

Under recent amendments, the formal “Part A / Part B” structure of AML/CTF Programs is being removed. However, this does not reduce obligations.

Businesses must still maintain a documented, risk-based program addressing:

  • Governance arrangements
  • Risk assessment
  • Customer due diligence
  • Ongoing monitoring
  • Reporting obligations
  • Compliance oversight

 

The structure is becoming more flexible; however, the accountability is not.

 

How Source can help

Our team of compliance specialists work with professional services firms and regulated businesses to:

  • Determine whether obligations apply
  • Conduct gap assessments
  • Develop tailored AML/CTF Programs
  • Establish governance frameworks
  • Support AUSTRAC enrolment and reporting
  • Provide ongoing compliance oversight

 

Our approach is practical and proportionate, meeting regulatory expectations without unnecessarily disrupting your business operations.

Our colleagues at Helios Salinger offer specialist advice, resources and training in privacy, AI and data governance, including:

  • The Small Business Privacy Pack
  • Privacy Act compliance training
  • A Privacy Self-Assessment Toolkit

 

Need support?

If you would like to discuss general compliance or AML/CTF uplift packages for your business, or if you require industry specific advice tailored to your risk profile and regulatory exposure, please contact us.

 

 

Disclaimer

This article is provided for general information and thought leadership purposes only and does not constitute legal, compliance or regulatory advice. It is not intended to function as formal training or continuing professional development material.