Fintech businesses can fall within Australia’s anti-money laundering and counter-terrorism financing (AML/CTF) regime where they provide a designated service under Section 6 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (‘AML/CTF Act’). Depending on the business model, this can include lending, payments, remittance, custody and virtual asset services.
Australia’s reformed AML/CTF framework commenced for existing reporting entities on 31 March 2026, while businesses providing newly regulated designated services became regulated from 1 July 2026, subject to transitional arrangements.
In this article, we explain when AML/CTF obligations apply to fintechs, the key compliance requirements under the current regime, and the practical steps fintech businesses should take to manage their financial crime risks.
Interactive Tool: Check Your Fintech AML/CTF Obligations & Compliance Steps
AML/CTF Fintech Compliance Checker
Quickly assess if your fintech business has AML/CTF obligations and what steps you must take to comply under Australia’s 2026 reforms.
Does your fintech business provide any of the following designated services?
Have you started providing a designated service since 31 March 2026?
Are you providing remittance or virtual asset services?
✅ AML/CTF Obligations Apply Now
You must enrol with AUSTRAC, implement a compliant AML/CTF program, conduct customer due diligence, and meet ongoing reporting and record-keeping requirements. If you provide remittance or virtual asset services, you must also register on the AUSTRAC VASP Register.
Key obligations:
- Enrolment within 28 days of commencing a designated service (Section 51B(1) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth))
- AML/CTF program and risk assessment (Sections 26B, 26C, 26F of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth))
- Customer due diligence (Section 28 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth))
- Ongoing monitoring and reporting (Sections 30, 41, 43, 46, 46A of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth))
- Personnel, training, and independent evaluation (Section 26F(4) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth))
- Record keeping (Sections 107, 111, 116 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth))
Legal References:
- Section 6 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 51B(1) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Sections 26B, 26C, 26D, 26F, 26H, 26J, 26K, 28, 30, 32, 41, 43, 46, 46A, 107, 111, 116 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- AML/CTF Rules 2025 (Cth)
⚖️ Transitional Relief May Apply
Existing reporting entities and those providing newly regulated virtual asset services before 1 July 2026 may have extended deadlines for enrolment, registration, and customer due diligence.
Check your enrolment date and service commencement to confirm your obligations and deadlines. Transitional relief applies to initial CDD and certain reporting requirements until 31 March 2029 if conditions are met.
Legal References:
- Section 51B(1) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 28 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 46A of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
❌ AML/CTF Obligations Unlikely
However, if your business model changes or you begin handling funds, value, or customer assets, you must reassess your obligations.
Legal References:
- Section 6 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
When Do AML/CTF Obligations Apply to a Fintech?
Identify the Designated Services Your Fintech Provides
Being a fintech—or holding an Australian Financial Services Licence (AFSL)—does not automatically make a business subject to the AML/CTF regime. The starting point is whether the business provides a designated service listed in Section 6 of the AML/CTF Act (Cth), and if that analysis is unclear, you can speak with our AML/CTF lawyers.
Depending on the business model, designated services relevant to fintechs can include:
- opening or operating certain accounts;
- making loans in the course of a loans business;
- issuing certain stored-value products;
- transferring value or providing remittance services;
- providing custodial or depository services;
- exchanging virtual assets for money;
- exchanging one virtual asset for another;
- providing virtual asset safekeeping services; and
- in some circumstances, an AFSL holder arranging for another person to receive a designated service.
The analysis should focus on what the fintech actually does, rather than labels such as “payments platform”, “crypto app” or “technology provider”.
Enrolment & Registration Requirements
Under Section 51B(1) of the AML/CTF Act (Cth), a person that starts providing a designated service and is not already enrolled must generally apply for enrolment within 28 days after commencing the service.
Separate registration obligations apply to certain remittance and virtual asset businesses. A business providing registrable virtual asset services must also be registered on the Australian Transaction Reports and Analysis Centre‘s (AUSTRAC) Virtual Asset Service Provider (VASP) Register.
Existing registered digital currency exchange providers transitioned into the VASP regime from 31 March 2026. Providers that had already begun providing newly regulated virtual asset services before 1 July 2026 had until 29 July 2026 to apply under the transitional arrangements.
Fintech Business Models That Commonly Raise AML/CTF Issues
Payment & Remittance Fintechs
Payment and money-transfer businesses can fall within designated services dealing with accounts, stored-value products and transfers of value.
Remittance businesses can also be subject to separate registration requirements. Fintechs involved in transfers of value should consider the payment transparency requirements in Part 5 of the AML/CTF Act (Cth) and Part 8 of the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth) (‘AML/CTF Rules 2025‘), which regulate information accompanying relevant transfers.
Lending & Credit Fintechs
Making a loan in the course of carrying on a loans business is a designated service under Section 6 of the AML/CTF Act (Cth).
A digital lender can therefore have AML/CTF obligations even where customer onboarding, credit assessment and loan management are conducted entirely online.
AML/CTF regulation should be assessed separately from financial services and consumer credit licensing. Holding—or not holding—an AFSL or Australian Credit Licence does not by itself determine whether the fintech is an AML/CTF reporting entity.
Virtual Asset & Crypto Fintechs
The 2026 reforms significantly expanded virtual asset regulation. Section 6 now covers services including:
- exchanging virtual assets for money or money for virtual assets;
- exchanging one virtual asset for another;
- virtual asset safekeeping; and
- specified transfers of virtual assets.
Virtual asset-to-money exchange was already regulated. The reformed obligations applying to newly regulated virtual asset services commenced from 1 July 2026, subject to the transitional framework.
Investment, Wealth & Custody Platforms
Certain custody services can also be designated services. Item 54 of Table 1 in Section 6 of the AML/CTF Act (Cth) additionally covers an AFSL holder arranging for another person to receive another designated service.
Where all of a reporting entity’s designated services fall within Item 54, Section 26T modifies parts of the standard AML/CTF program requirements. AFSL fintechs should therefore identify their exact designated services instead of assuming every licensee has identical obligations.
What Are the Core AML/CTF Obligations for Fintechs?
Develop an ML/TF Risk Assessment & AML/CTF Program
Once a fintech becomes a reporting entity, compliance extends beyond customer identification, making AML/CTF compliance services for fintechs relevant to the broader compliance framework. The current framework requires a risk-based AML/CTF program supported by governance, customer due diligence, monitoring, reporting and record keeping.
Under Section 26B of the AML/CTF Act (Cth), an AML/CTF program comprises the reporting entity’s ML/TF risk assessment and AML/CTF policies.
Section 26C of the AML/CTF Act (Cth) requires the business to identify and assess the ML/TF/PF risks it may reasonably face when providing designated services.
For Australian operations, relevant risk factors include:
- designated services;
- customer types;
- delivery channels;
- relevant countries;
- new or emerging technologies; and
- relevant risk information communicated by AUSTRAC.
Section 26F then requires policies, procedures, systems, and controls that appropriately manage and mitigate those risks and are appropriate to the nature, size and complexity of the business.
Review the Risk Assessment as the Fintech Changes
Under Section 26D of the AML/CTF Act (Cth), the ML/TF risk assessment must be reviewed when specified risk changes occur and, in any event, at least once every three years.
Where a significant change is within the fintech’s control, the review must occur before the change takes place.
This means a regulatory review may be required before launching a new product, payment method, virtual asset service, delivery technology or customer segment.
Establish AML/CTF Governance
Section 26H of the AML/CTF Act (Cth) requires the governing body to exercise ongoing oversight of the reporting entity’s ML/TF risk assessment and AML/CTF compliance.
The fintech must also designate an AML/CTF compliance officer under Sections 26J and 26K. The officer must be at management level and have sufficient authority, independence, and access to resources and information.
Rule 5-7 of the AML/CTF Rules 2025 (Cth) also generally requires the AML/CTF compliance officer to report to the governing body at least once every 12 months.
Conduct Initial Customer Due Diligence
Under Section 28 of the AML/CTF Act (Cth), the new initial customer due diligence (CDD) framework generally requires specified matters about a customer to be established before a designated service begins, subject to limited exceptions.
Depending on the customer, this can require the fintech to establish:
- customer identity;
- beneficial ownership;
- persons acting on behalf of the customer;
- politically exposed person and sanctions status;
- the nature and purpose of the relationship; and
- the customer’s ML/TF risk.
However, transitional rules apply to some existing reporting entities. An entity enrolled on 30 March 2026 may continue using its pre-reform applicable customer identification procedures for specified customer classes until 31 March 2029, provided the transitional requirements are satisfied.
This relief applies to initial CDD. Eligible existing reporting entities have been subject to the new ongoing CDD requirements since 31 March 2026.
Conduct Ongoing CDD & Transaction Monitoring
Section 30 of the AML/CTF Act (Cth) requires ongoing monitoring of customers and transactions.
Relevant activity can include:
- unusually large or complex transactions;
- unusual transaction patterns;
- transactions with no apparent economic or lawful purpose; and
- behaviour inconsistent with the customer’s known profile, business activities or source of funds or wealth.
For fintechs processing large volumes of transactions, automated monitoring may be necessary. However, alerts still need to be properly investigated, escalated and documented.
Apply Enhanced CDD Where Required
Section 32 of the AML/CTF Act (Cth) requires enhanced customer due diligence (ECDD) in specified higher-risk circumstances.
The AML/CTF Rules 2025 (Cth) impose further ECDD requirements for matters including unusually complex or large transactions, unusual patterns of transactions and certain source-of-funds or source-of-wealth enquiries.
Fintechs should ensure their onboarding and monitoring systems can escalate higher-risk customers and transactions into enhanced review processes.
What Reports Must Fintechs Submit to AUSTRAC?
Suspicious Matter Reports
Section 41 of the AML/CTF Act (Cth) requires suspicious matter reports (SMRs) where the statutory requirements for suspicion are met.
An SMR must generally be submitted within:
- 3 business days after the relevant suspicion is formed; or
- 24 hours where the suspicion relates to terrorism financing.
Information concerning an SMR is also subject to the tipping-off restrictions in section 123.
Threshold Transaction Reports
Under Section 43 of the AML/CTF Act (Cth), a reporting entity providing a designated service involving a threshold transaction must generally report it to AUSTRAC within 10 business days.
Existing reporting entities have transitional arrangements concerning the reporting form used through to 2029, but the underlying threshold transaction reporting obligation continues.
International Transfers
Section 46 of the AML/CTF Act (Cth) establishes the reformed international value transfer service reporting (IVTS) regime. However, transitional arrangements mean it is not yet generally operative.
Affected existing reporting entities generally continue submitting international funds transfer instruction reports under the pre-reform framework until their transition date. The standard transition date is 31 March 2029, subject to limited alternative arrangements.
Self-Hosted Wallet Reporting
Section 46A of the AML/CTF Act (Cth) reporting entities providing certain virtual asset transfer services must report transactions involving unverified self-hosted wallets. This applies when a regulated service under items 29 or 30 involves sending or receiving virtual assets via a self-hosted wallet whose ownership or control has not been verified by the entity’s AML/CTF program
However, where the relevant designated service starts before 31 March 2029, the transitional rules defer this reporting obligation until 31 March 2029.
Personnel, Training & Independent Evaluation
Section 26F(4) of the AML/CTF Act (Cth) requires AML/CTF policies addressing personnel due diligence, training and independent evaluation.
Rule 5-8 of the AML/CTF Rules (Cth) addresses personnel due diligence, while Rule 5-9 requires initial and ongoing AML/CTF training appropriate to a person’s role and responsibilities.
Section 26F(4)(f) requires independent evaluations at a frequency appropriate to the nature, size, and complexity of the business and at least once every three years.
However, transitional deadlines apply to the first evaluation under the new regime. For an existing reporting entity enrolled on 30 March 2026 that had already completed a pre-reform independent review, the first evaluation is generally due by the later of:
- four years after the most recent independent review; or
- 31 March 2027.
Different transitional deadlines apply to certain newly regulated entities.
What AML/CTF Records Must a Fintech Keep?
Record keeping is an important part of demonstrating compliance. Section 107 of the AML/CTF Act (Cth) generally requires transaction records to be retained for seven years. Section 111 imposes seven-year retention requirements for relevant CDD records, while Section 116 requires records necessary to demonstrate compliance with the AML/CTF program obligations.
For fintechs, compliance records can include:
- customer identification and verification information;
- customer risk assessments;
- transaction-monitoring records;
- alert investigations and decisions;
- AML/CTF program approvals;
- risk-assessment updates;
- training records; and
- records explaining compliance decisions.
The objective is not simply to retain documents, but to demonstrate what the fintech did and why.
Common AML/CTF Compliance Risks for Fintechs
Treating KYC as a One-Off Exercise
Customer verification at onboarding is only one part of CDD. Section 30 of the AML/CTF Act (Cth) requires ongoing monitoring and, where appropriate, review of customer risk assessments and KYC information.
Launching Products Without Updating the Risk Assessment
Under Section 26D of the AML/CTF Act (Cth), significant changes affecting ML/TF risk can require the risk assessment to be reviewed before the change occurs.
Product development and AML/CTF compliance should therefore operate together rather than treating compliance review as a post-launch exercise.
Relying on Automated Alerts Without Decision Records
Technology can identify unusual transactions, but an automated alert does not complete the compliance process.
Fintechs should document the information reviewed, conclusions reached, reasons an alert was closed and whether the matter was escalated for potential suspicious matter reporting.
Outsourcing Compliance Without Maintaining Oversight
Fintechs can use external KYC providers, transaction-monitoring systems and blockchain analytics tools.
However, outsourcing these functions does not generally transfer the reporting entity’s statutory responsibilities. External providers should therefore be subject to appropriate governance, testing and oversight.
When Should a Fintech Review Its AML/CTF Framework?
A fintech should consider reviewing its AML/CTF framework when it:
- launches a new product or designated service;
- introduces a new payment or transfer method;
- expands into virtual assets;
- changes customer onboarding processes;
- enters a new jurisdiction;
- begins serving new customer types;
- introduces new or emerging technology;
- identifies weaknesses in transaction monitoring; or
- receives relevant new risk information from AUSTRAC.
Regular review is particularly important for fintechs because product functionality and transaction flows can change quickly.
Conclusion
AML/CTF compliance for fintechs involves considerably more than verifying customer identity. Businesses providing designated services need a framework covering ML/TF risk assessment, governance, CDD, transaction monitoring, reporting, personnel, independent evaluation and record keeping.
For fintechs, these controls should be integrated into product and technology systems from the outset. The 2026 reforms also make it important to distinguish between obligations already in force and transitional requirements continuing through 2029.
Contact Click Legal’s AML/CTF compliance lawyers for fintech businesses to determine whether your services are regulated, assess AUSTRAC enrolment and registration requirements, develop or review AML/CTF programs and ensure your compliance arrangements reflect the current Australian regime.