Australia’s Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (‘AML/CTF Rules 2025’) form part of the major overhaul of Australia’s AML/CTF framework from 31 March 2026. The Rules work alongside the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (‘AML/CTF Act’). While the Act establishes the core legal obligations, the Rules provide much of the detail about how businesses must implement them, including AML/CTF programs, customer due diligence, governance, reporting groups, transfers of value and reporting.
In this article, we explain the key changes under the AML/CTF Rules 2025 (Cth), what they mean for reporting entities in practice, and which transitional arrangements businesses still need to consider in 2026.
Interactive Tool: See If Your Business Meets the New AML/CTF 2025 Rules
AML/CTF 2025 Compliance Readiness Checker
Quickly assess if your business is meeting the new AML/CTF Rules 2025 requirements and identify your next compliance steps.
Is your business already regulated by AUSTRAC, or are you newly regulated under the Tranche 2 reforms (legal, accounting, real estate, precious metals/stones)?
Have you documented and updated your ML/TF risk assessment and AML/CTF program to align with the AML/CTF Rules 2025?
Have you scheduled or completed an independent evaluation of your AML/CTF program since the reforms?
✅ You appear to be on track with AML/CTF 2025 compliance
Legal References:
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- AML/CTF Rules 2025
- Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Rule 5-10 of the AML/CTF Rules 2025
⚠️ Partial compliance – action required to meet AML/CTF 2025 obligations
Legal References:
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- AML/CTF Rules 2025
- Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Rule 5-10 of the AML/CTF Rules 2025
❌ Not compliant – urgent action required
Legal References:
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- AML/CTF Rules 2025
- Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Rule 5-10 of the AML/CTF Rules 2025
What Are the AML/CTF Rules 2025?
The AML/CTF Rules (Cth) are legislative instruments made under the AML/CTF Act (Cth). They supplement the Act by prescribing more detailed requirements for matters such as enrolment, registration, AML/CTF programs, CDD, correspondent banking, transfers of value and regulatory reporting.
The new AML/CTF Rules 2025 (Cth) were originally made in 2025 and were amended shortly before the major reforms commenced. The March 2026 amendments were designed to fully operationalise the reformed AML/CTF Act (Cth), correct technical issues and reduce administrative burden, including through changes to the reporting group framework.
For businesses already regulated by Australian Transaction Reports and Analysis Centre (AUSTRAC), the updated obligations generally commenced on 31 March 2026. Newly regulated businesses in sectors including legal, accounting, real estate and precious metals and stones became subject to the regime from 1 July 2026, subject to applicable transitional arrangements.
How Have AML/CTF Programs Changed?
One of the central changes is the move to a more clearly structured, risk-based AML/CTF program. The program now consists of two core elements:
- an ML/TF risk assessment; and
- AML/CTF policies, procedures, systems and controls designed to manage and mitigate those risks.
Risk Assessments Must Drive the Program
Under Sections 26C–26E of the AML/CTF Act (Cth), reporting entities must identify and assess the ML/TF/PF risks they reasonably face.
The AML/CTF Rules 2025 (Cth) then support how those risks are managed through Part 5, including requirements dealing with CDD, targeted financial sanctions, governance, suspicious matter assessment and transfers of value.
In practical terms, the risk assessment should consider factors relevant to the particular business, including its services, customers, delivery channels, jurisdictions, and use of new or emerging technologies. The methodology should be proportionate to the nature, size, and complexity of the business.
Programs Must Be Reviewed & Updated
Reporting entities must review their entire risk assessment and AML/CTF policies at least once every three years, as well as when specified changes affect their risk exposure, and can seek advice from Click Legal’s AML/CTF compliance program review and update lawyers when reviewing or updating the program. Where a significant change is within the business’s control, the risk assessment may need to be reviewed before the change is implemented.
This can be relevant where a business:
- launches a new designated service;
- enters a new jurisdiction;
- changes how services are delivered;
- introduces new technology;
- begins serving new customer groups; or
- receives relevant new risk information from AUSTRAC.
Rule 5-15 also requires the initial risk assessment and AML/CTF policies to be documented before the entity first starts providing a designated service. Updates to the program must be documented within 14 days after the update occurs.
What Are the New AML/CTF Governance Requirements?
The reformed framework places more explicit responsibility on senior decision-makers rather than treating AML/CTF compliance as solely the responsibility of the compliance team. The three key governance roles:
- the governing body, which oversees AML/CTF compliance at the highest level;
- senior managers, who perform specified approval and oversight functions; and
- the AML/CTF compliance officer, who oversees and coordinates day-to-day compliance.
Governing Body Oversight
Rules 5-6 and 5-7 of the AML/CTF Rules 2025 (Cth) require AML/CTF policies to ensure the governing body receives sufficient information to perform its oversight responsibilities.
Rule 5-7 generally requires the AML/CTF compliance officer to report to the governing body at least once every 12 months. The report must address compliance with the entity’s AML/CTF policies, whether those policies appropriately manage its risks and compliance with the Act, Rules, and regulations. Limited exceptions apply where, for example, the reporting entity is an individual.
Personnel Due Diligence & Training
Rule 5-8 of the AML/CTF Rules 2025 (Cth) requires applicable personnel due diligence to assess both:
- the person’s relevant skills, knowledge, and expertise; and
- their integrity.
That assessment must occur before employment or engagement and during the person’s employment or engagement.
Rule 5-9 separately requires both initial and ongoing AML/CTF training. The training must be appropriate to the person’s function, the ML/TF risks relevant to that function and their responsibilities under the AML/CTF policies.
For businesses, this means a generic annual AML training presentation may not be enough where different roles face materially different risks.
How Have Independent Reviews Changed?
The reforms replace the previous independent review model with independent evaluations of the entire AML/CTF program.
Rule 5-10 of the AML/CTF Rules 2025 (Cth) requires the evaluation to examine:
- how the business conducted and reviewed its risk assessment;
- the design of its AML/CTF policies;
- whether it actually complies with those policies; and
- whether it appropriately identifies, assesses, manages and mitigates its ML/TF risks.
The evaluator must produce a written report and provide it to the governing body and relevant senior managers.
Independent evaluations must occur at a frequency appropriate to the nature, size, and complexity of the business and at least once every three years.
However, transitional deadlines apply to the first post-reform evaluation. Existing reporting entities enrolled on 30 March 2026 that had already completed a pre-reform independent review generally have until the later of four years after their most recent review or 31 March 2027. Newly regulated businesses have staggered first-evaluation deadlines extending through 2029 and 2030 depending on their AUSTRAC Account Number (AAN).
How Have Customer Due Diligence Requirements Changed?
Part 6 of the AML/CTF Rules 2025 (Cth) contains a significantly restructured customer due diligence (CDD) framework. Rather than relying principally on the old applicable customer identification procedure model, the new framework separates CDD into initial CDD and ongoing CDD, with the level of information and verification depending on the customer’s ML/TF risk.
Initial CDD
Rules 6-1 to 6-11 of the AML/CTF Rules 2025 (Cth) contain detailed requirements for different customer types and related persons, including:
- sole traders;
- companies and other bodies;
- trusts;
- government bodies;
- persons acting for customers;
- persons on whose behalf a service is provided;
- beneficial owners; and
- the nature and purpose of the relationship or transaction.
The objective is therefore broader than simply checking a customer’s name against identification documents. Businesses need enough information to understand who the customer is, who ultimately owns or controls them and why the relationship exists.
Simplified, Enhanced & Delayed CDD
The AML/CTF Rules 2025 (Cth) provide more structured pathways for adjusting CDD according to risk. Rules 6-16 to 6-19 deal with simplified CDD in eligible lower-risk circumstances. Rules 6-20 to 6-22 impose additional requirements for enhanced CDD, including unusual services or transactions, source-of-funds or source-of-wealth enquiries in specified circumstances and particular virtual asset services.
Rules 6-12 to 6-15 separately prescribe circumstances in which a designated service can commence before all required verification has been completed. These are specific exceptions rather than a general permission to delay customer verification.
Ongoing CDD & Transaction Monitoring
Rule 6-35 supports the ongoing CDD obligation by addressing monitoring for unusual transactions and behaviours.
In practice, businesses need systems capable of identifying behaviour that is inconsistent with what they know about the customer, including unusual transaction sizes, patterns, complexity or activity lacking an apparent lawful or economic purpose.
Do Existing Customers Need to Be Re-Verified Immediately?
Not necessarily. The transitional rules allow certain reporting entities that were enrolled on 30 March 2026 to continue using their pre-reform applicable customer identification procedures (ACIP) for specified classes of customers during a transitional period running until 31 March 2029.
To rely on that transition, the entity had to establish transitional AML/CTF policies identifying which customer classes would remain under ACIP and when they would transition to the new initial CDD framework. Those policies were required to be in place by 1 July 2026.
This transition concerns initial CDD. It does not generally postpone the new ongoing CDD requirements for eligible existing reporting entities.
Businesses should therefore avoid assuming that the 2029 transition date means they can continue operating entirely under the old CDD framework until then.
What Has Changed for Reporting Groups?
The March 2026 amendments introduced an “opt-out” reporting group model. Under the amended framework, related entities within a qualifying corporate group or other control structure may form a reporting group by default unless an entity formally declines membership in writing. The change was intended to reduce the administrative burden associated with forming reporting groups.
Part 2 of the AML/CTF Rules 2025 (Cth) now deals with:
- reporting groups formed as business groups;
- groups formed by election;
- the circumstances in which one group member can discharge obligations for another; and
- conditions applying where group members are not themselves reporting entities.
A reporting group can allow entities to share aspects of AML/CTF risk management and compliance through a group program led by a lead entity, but it does not simply remove each entity’s regulatory responsibilities.
What Are the New Transfer-of-Value & Travel Rule Requirements?
Part 8 of the AML/CTF Rules 2025 (Cth) supports the reformed transfer-of-value or “travel rule” framework. Rules 8-3 to 8-5 prescribe requirements for:
- ordering institutions to collect, verify and pass on specified information;
- beneficiary institutions to monitor whether required information has been received; and
- intermediary institutions to monitor and transmit relevant information.
These rules are particularly important for payment businesses, banks, remittance providers and virtual asset service providers because compliance may require changes to the information captured and transmitted through transaction systems.
Rule 8-6 also contains transitional provisions relating to revised FATF payment-transparency requirements. March 2026 amendments extended certain transitional verification relief for transfers conducted before 1 July 2030.
Separate transitional arrangements also defer the new international value transfer service reporting regime for affected businesses until their applicable transition date, generally 31 March 2029. Until then, affected reporting entities continue using the pre-reform international funds transfer instruction reporting framework.
What Has Changed for Virtual Asset Businesses?
The AML/CTF Rules 2025 (Cth) now expressly support the expanded regulation of virtual asset service providers (VASPs).
Part 4 includes detailed information requirements for VASP registration applications, while Rule 6-22 contains enhanced CDD requirements for specified virtual asset services. Part 8 also extends transfer-of-value requirements to relevant virtual asset transfers.
Some obligations for newly regulated virtual asset services were deferred until 1 July 2026 under the transitional rules. Those deferred obligations included AML/CTF programs, CDD, reporting, virtual asset transfer requirements and specified record-keeping obligations. They are therefore now operative as at August 2026.
However, certain later transitions remain. For example, reporting under Section 46A of the AML/CTF Act (Cth) for relevant transfers involving unverified self-hosted wallets is deferred until 31 March 2029 for entities that began providing the relevant services before that date.
What Has Changed With Reporting?
Part 9 of the AML/CTF Rules 2025 (Cth) specifies information requirements for reports including:
- suspicious matter reports;
- threshold transaction reports;
- AML/CTF compliance reports;
- reports from registered remittance affiliates; and
- cross-border movement reports.
The March 2026 amendments also changed the annual AML/CTF compliance reporting timetable to align the reporting and lodgement periods with the Commonwealth Performance Framework.
However, reporting entities should check the transitional provisions carefully. Parts of the new reporting framework continue to preserve pre-reform reporting arrangements for particular existing entities and reporting types rather than switching every reporting process to the new format immediately on 31 March 2026.
Common Compliance Risks Under the New Rules
Treating the Risk Assessment as a Static Document
The new framework expects the risk assessment to drive the AML/CTF program. It must be reviewed when relevant risks change and at least once every three years.
A business that launches new products or technology without assessing the associated ML/TF risk may therefore create a gap between its actual operations and its documented program.
Keeping the AML/CTF Program Within the Compliance Team
Rules 5-6 and 5-7 of the AML/CTF Rules 2025 (Cth) reinforce that AML/CTF governance extends to the governing body. Compliance reporting and material risk information need to reach the people responsible for oversight and strategic decisions.
Applying the Same CDD to Every Customer
The new CDD structure is expressly risk-based. Simplified CDD may be available in qualifying low-risk circumstances, while enhanced CDD is mandatory in specified higher-risk situations.
A single customer-verification workflow may therefore be inadequate where it does not respond to differing customer risks.
Assuming All Transitional Relief Runs Until 2029
Different transitional rules have different eligibility requirements and deadlines. Some obligations began on 31 March 2026, newly regulated sectors generally entered on 1 July 2026, initial CDD transition can continue until 2029 for eligible existing entities, and first independent evaluation dates vary by entity.
Businesses need to identify the transition that applies to each particular obligation, rather than relying on one general reform deadline, and can seek advice from Click Legal’s AML/CTF lawyers advising on transitional obligations.
What Should Reporting Entities Do Now?
Reporting entities should consider whether they have:
- documented a current ML/TF risk assessment;
- updated AML/CTF policies to reflect the reformed framework;
- established appropriate governing body and senior management oversight;
- designated an appropriate AML/CTF compliance officer;
- implemented personnel due diligence and role-appropriate training;
- updated initial, ongoing, simplified and enhanced CDD processes;
- assessed applicable reporting group arrangements;
- updated transaction-monitoring and suspicious matter assessment processes;
- identified any applicable travel rule requirements;
- diarised their first independent evaluation deadline; and
- identified exactly which transitional arrangements they are relying on and when those arrangements expire.
AUSTRAC has stated that during FY2026–27 it expects reporting entities to be managing their ML/TF risks, complying with reporting requirements and making sustained progress in embedding the reforms. AUSTRAC has described its approach during this period as expecting effort and continued improvement, rather than perfection, but that regulatory position does not remove the underlying statutory obligations.
Conclusion
The AML/CTF Rules 2025 (Cth) significantly reshape how Australian reporting entities put their AML/CTF obligations into practice. The framework places greater emphasis on business-specific risk assessment, governance, ongoing CDD, personnel controls and independent evaluation, while also modernising reporting groups and transfer-of-value requirements.
For businesses already regulated on 31 March 2026, most of the reformed framework is now in operation, although important transitional arrangements continue. Newly regulated entities have also entered the regime from 1 July 2026. Understanding which rules apply now—and which obligations remain subject to transition—is therefore an essential part of maintaining compliance.
Speak with Click Legal’s AML/CTF compliance lawyers to interpret the new Rules, review and update AML/CTF programs, assess CDD and governance arrangements, and identify the transitional deadlines applicable to your business.