What Is AML/CTF Transaction Monitoring & How to Build Effective Monitoring Rules

Published By:

Hannah Deuk

Founder & Principal Lawyer

Key Takeaways:

  • Risk-based monitoring: Build rules around your business’s ML/TF/PF risks, customers, transaction data and designated services.
  • Alerts prompt assessment: Investigate unusual activity against customer circumstances; an alert alone does not establish an SMR obligation.
  • Tailored triggers: Use transaction size, frequency, velocity, patterns, geography and counterparties rather than relying only on fixed monetary thresholds.
  • SMR deadlines: Submit to the AUSTRAC CEO within 24 hours for TF, three business days for non-TF matters, or five where privilege applies.
Jump to...
October 3, 2026

Introduction

Australian reporting entities must monitor customers receiving designated services to identify, assess, manage and mitigate money laundering, terrorism financing and proliferation financing (ML/TF/PF) risks. Transaction monitoring focuses on unusual customer transactions and behaviour, including activity that may lead to a suspicious matter reporting (SMR) obligation.

Effective monitoring rules and monitoring scenarios should reflect the business’s risks and circumstances and may use manual or automated processes. This article covers risk-based thresholds, alerts and reviews, while distinguishing an alert that prompts investigation from an SMR obligation.

Interactive Tool: See If Your Alert Requires an SMR

AML/CTF Transaction Monitoring Rule Checker

Quickly assess if your transaction monitoring rules meet Australian AML/CTF legal standards and identify when an alert may trigger a Suspicious Matter Report (SMR) obligation.

What type of transaction or behaviour triggered your alert?

Has your review identified a legitimate explanation for the activity?

Does the suspicious activity relate to terrorism financing, money laundering, or another criminal offence?

✅ No SMR Required – Document Your Review

You have identified a legitimate explanation for the unusual transaction or behaviour. Under Section 30(5) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), an unusual transaction does not automatically trigger a Suspicious Matter Report (SMR) obligation. Document your assessment and continue monitoring as required by your AML/CTF program.
  • Section 30(5) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
  • Section 30(2)(a) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Get AML/CTF Legal Advice

⚠️ Further Assessment Needed – Consider Enhanced Due Diligence

You have not found a legitimate explanation, but the activity does not clearly relate to terrorism financing, money laundering, or another criminal offence. Apply enhanced customer due diligence (ECDD) as required by Section 32(a) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and continue monitoring. If new information arises, reassess for SMR obligations.
  • Section 32(a) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
  • Section 30(5)(d) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Speak to an AML/CTF Lawyer

❌ SMR Required – Suspicion on Reasonable Grounds

Your review has not identified a legitimate explanation and the activity may relate to terrorism financing, money laundering, or another criminal offence. You must submit a Suspicious Matter Report (SMR) to AUSTRAC within the statutory timeframe under Section 41(1) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). For terrorism financing, the SMR must be lodged within 24 hours; for other matters, within 3 business days.
  • Section 41(1) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
  • Section 30(2)(a) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Speak to an AML/CTF Lawyer Now

⚖️ Need Help Interpreting the Rules?

AML/CTF transaction monitoring and SMR obligations are complex and fact-specific. For tailored guidance, contact Click Legal’s AML/CTF lawyers to review your scenario and ensure your program meets AUSTRAC requirements.
  • Section 30 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
  • Rule 6-35 of the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth)
Get AML/CTF Legal Advice

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

What Is AML/CTF Transaction Monitoring For Australian Reporting Entities

Section 30(1) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (‘AML/CTF Act‘) requires a reporting entity to monitor customers receiving designated services to appropriately identify, assess, manage and mitigate the ML/TF/PF risks it may reasonably face. Under Section 30(2)(a), a reporting entity providing designated services through a permanent establishment in Australia must also monitor unusual customer transactions and behaviours that may give rise to an SMR obligation.

Rule 6-35 of the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth) (‘AML/CTF Rules‘) specifies the monitoring that is taken to comply with Section 30(2)(a), including monitoring for unusual transactions and behaviours that may give rise to the matters in Sections 41(1)(d)–(j).

For the purposes of Section 30, Section 30(5)(a)–(d) of the AML/CTF Act expressly provides that unusual transactions and behaviours include the following:

  • large or complex transactions;
  • unusual transaction patterns;
  • activity with no apparent economic or lawful purpose; or
  • conduct inconsistent with what the reporting entity knows about the customer, relationship, risk, source of funds or source of wealth.

An unusual transaction does not automatically mean illegal conduct, so the reporting entity should assess whether there is a legitimate explanation and whether further action is required.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

What Must Reporting Entities Monitor For

Unusual Transaction Size or Frequency

A reporting entity should assess whether the size, frequency, or pattern of a customer’s transactions is consistent with the customer’s profile and expected activity. A high transaction volume may be ordinary for one customer but unusual for another, depending on the customer’s circumstances, the designated service and the business relationship.

Monitoring may identify the following:

  • unusually large or complex transactions;
  • large cash deposits or withdrawals;
  • rapid transfers; or
  • activity inconsistent with the customer’s previous transaction history.

Section 5-12 of the AML/CTF Rules requires a reporting entity’s AML/CTF policies to enable timely review of material relevant to reportable matters under Section 41 of the AML/CTF Act. This ensures a determination is made as soon as practicable as to whether the reporting entity suspects on reasonable grounds any matter in Sections 41(1)(d)–(j). Accordingly, a transaction monitoring alert prompts assessment; it does not itself establish that an SMR obligation has arisen.

Structuring & Threshold Avoidance

AUSTRAC guidance identifies transactions that appear structured to avoid threshold transaction reporting obligations as an indicator that may warrant further investigation.

Under Section 5 of the AML/CTF Act, a ‘threshold transaction’ includes a transaction involving the transfer of physical currency of at least $10,000, and other indicators include:

  • frequent structured cash payments;
  • multiple transactions where one transaction would be sufficient;
  • cash deposits made across different branches or ATMs; and
  • several low-value international transfers.

Section 43(2) requires a reporting entity to report a threshold transaction to the AUSTRAC CEO within 10 business days. Separately, Section 142 creates an offence concerning two or more non-reportable transactions conducted, or caused to be conducted, in a manner or form for the sole or dominant purpose of avoiding threshold transaction reporting requirements.

These patterns should be assessed alongside the customer’s profile, transaction history and stated purpose.

High-Risk Jurisdictions & Parties

AUSTRAC guidance identifies transactions involving high-risk countries or regions, sanctioned persons and other unexpected counterparties as examples that may warrant further investigation. Politically exposed person (PEP) status and high-risk jurisdiction exposure may also affect customer ML/TF risk and enhanced CDD obligations under Section 32 of the AML/CTF Act.

Reporting entities may also consider activity involving persons or entities linked through open-source information to criminal activity, terrorism or sanctions concerns. A single indicator may not establish suspicious activity, so the transaction and surrounding customer circumstances require further assessment.

Transactions With No Apparent Economic Purpose

Section 30(5)(c) of the AML/CTF Act expressly includes transactions and behaviours that have no apparent economic or lawful purpose within the meaning of unusual transactions and behaviours. Section 30(5)(d) also covers activity inconsistent with what the reporting entity reasonably knows about the customer, the nature, and purpose of the business relationship, the customer’s ML/TF risk and, where relevant, the customer’s source of funds or source of wealth.

Relevant activity may include:

  • unnecessarily complex transfers;
  • rapid movement of funds between multiple accounts;
  • transfers involving third parties without an apparent commercial reason; or
  • legal entity structures, corporate vehicles or trust arrangements used without an apparent commercial reason or in a way that may obscure ownership.

Higher-Risk Customers & Services

Under Section 32(a) of the AML/CTF Act, a reporting entity must apply enhanced CDD measures appropriate to the customer’s ML/TF risk where the customer’s ML/TF risk is high.

AUSTRAC guidance separately states that higher-risk customers may require more intensive transaction monitoring than lower-risk customers. Depending on the customer’s ML/TF risk, this may include:

  • additional alerts to review activity more closely; and
  • more frequent manual reviews of transactions.

In addition, the monitoring approach should reflect the nature, size, and complexity of the business and the designated services it provides. Furthermore, changes in a customer’s ML/TF risk during the business relationship should inform how their activity is monitored.

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Practical Tips To Build & Test Effective Transaction Monitoring Rules

Manual vs Automated Transaction Monitoring

Neither Section 30 of the AML/CTF Act nor Section 6-35 of the AML/CTF Rules prescribes manual or automated transaction monitoring. Transaction monitoring may be manual, automated or a combination of both. Section 26F(1)(c) requires the reporting entity’s AML/CTF policies, procedures, systems and controls to be appropriate to the nature, size, and complexity of its business.

Manual transaction monitoring may involve trained personnel reviewing transactions at scheduled intervals, comparing activity with the customer’s history and escalating unusual activity for further review.

Automated transaction monitoring may be appropriate where transaction volumes make manual review ineffective and software can identify unusual patterns, large transactions, activity spikes, possible structuring, high-risk jurisdictions or sanctioned parties. AUSTRAC expects automated monitoring where transactions cannot effectively be monitored manually.

Identify Relevant Risk Scenarios

Start with the business’s ML/TF risk assessment and identify customer transactions or behaviour that may require review. Australian Transaction Reports and Analysis Centre’s (AUSTRAC) industry-specific suspicious activity indicators, such as that for the banking sector, can help identify relevant scenarios involving ML/TF/PF and other criminal activity.

Relevant scenarios may include:

  • unusual transaction patterns;
  • large or complex transactions;
  • structured activity;
  • unexplained international transfers;
  • high-risk jurisdictions;
  • sanctions concerns; and
  • behaviour inconsistent with a customer’s profile.

The indicators should be relevant to the business, its customers and the designated services it provides.

Set Appropriate Thresholds & Triggers

A transaction monitoring rule should use information that may indicate unusual activity. Relevant factors can include:

  • transaction amount and frequency;
  • transaction velocity and patterns;
  • countries, regions, and counterparties involved; and
  • changes in customer behaviour or activity.

The business’s ML/TF risk assessment should guide the thresholds and triggers. An alert should identify activity that requires further review, rather than treating every transaction above a fixed amount as suspicious.

For a checklist to support AML/CTF compliance work, see AML/CTF Compliance Checklist (Free).

Managing False Positives & Missed Activity

Customer monitoring should be checked regularly to confirm that alerts identify unusual transactions and behaviour and that staff respond appropriately. Reviews should assess whether the business has enough customer information, whether relevant activity generates alerts and whether identified issues are addressed promptly.

A business should adjust rules that generate excessive irrelevant alerts without weakening coverage of the risks identified in its ML/TF risk assessment. Alert reviews, investigation steps, decisions, and rule changes should be documented.

Responding to Emerging Risks

Transaction monitoring should be updated when the business identifies new indicators of criminal activity or when AUSTRAC publishes relevant indicators or ML/TF risk information. Changes in services, customer behaviour or the business’s risk assessment may also require monitoring scenarios to be revised.

Changes should be approved by relevant senior managers where they may affect AML/CTF compliance. The business should check that updates do not affect reporting obligations, use assurance processes while changes are made and document the updated monitoring measures.

Avoid Generic Rules & Fixed Monetary Thresholds

Monitoring rules should be based on the business’s ML/TF risk assessment, customer information, transaction data and the nature of its designated services. A single rule applied to every customer can miss activity that is unusual for a particular customer while generating unnecessary alerts for others.

Fixed monetary thresholds should not be the only basis for transaction monitoring. The size, frequency, pattern, velocity, geography, and counterparties involved may all be relevant when identifying unusual transactions and behaviour. Excessive irrelevant alerts should be addressed without weakening coverage of the identified ML/TF risks.

Alert Review & Escalation

A transaction monitoring alert signals activity that requires assessment; it does not establish that suspicious activity or illegal conduct has occurred. Depending on its alert review findings, the business may:

  • review or update KYC information and the customer’s ML/TF risk;
  • apply enhanced customer due diligence measures;
  • escalate the matter to senior managers or an AML/CTF compliance officer; or
  • decide whether to continue providing designated services.

The alert, review steps, decisions, and reasons for the response should be documented. These records help show how the business responded to unusual transactions and behaviour.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

When Does a Transaction Monitoring Alert Require an SMR

A transaction monitoring alert does not automatically require an SMR. An alert identifies activity that requires further assessment. An SMR obligation arises only where the reporting entity forms a suspicion on reasonable grounds and the requirements of Section 41(1) of the AML/CTF Act are satisfied.

The reporting entity should therefore review the customer, transaction, or behaviour that generated the alert and consider the available information, including the customer’s profile, transaction history, ML/TF risk, business relationship and any apparent economic or lawful purpose for the activity.

Where the assessment results in a suspicion on reasonable grounds and the requirements of Section 41(1) are satisfied, the reporting entity must submit an SMR to the AUSTRAC CEO:

  • within 24 hours after forming the suspicion where the suspected matter concerns TF, including where the service appears preparatory to a TF offence or information concerning the service may be relevant to investigating or prosecuting such an offence;
  • within 3 business days after the day the suspicion is formed where the suspicion concerns false identity, suspected tax evasion or other criminal offending, proceeds-of-crime enforcement, or ML, including where the service appears preparatory to a ML offence or information concerning the service may be relevant to investigating or prosecuting ML; or
  • within 5 business days after the day the suspicion is formed for those non-TF matters where the reporting entity reasonably believes that some, but not all, of the information required in the report may be protected by legal professional privilege and the privilege belongs to another person.

Accordingly, transaction monitoring should be designed to identify activity requiring investigation, rather than treating every unusual transaction or alert as automatically reportable.

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Conclusion

AML/CTF transaction monitoring requires reporting entities to monitor customers and their behaviour in a way that identifies, assesses, manages and mitigates ML/TF/PF risks. A sound approach uses risk-based thresholds, monitoring scenarios and alerts suited to the business, while recognising that an alert prompts review and an SMR obligation arises only when Section 41 of the AML/CTF Act is met.

To apply these requirements to your business, contact the AML/CTF compliance lawyers at Click Legal for clear regulatory guidance on transaction monitoring, customer risk and AML/CTF processes. Our regulatory lawyers can help you develop monitoring measures suited to your business and respond appropriately when unusual activity is identified.

Frequently Asked Questions

JUMP TO...
Table of Contents

Published By:

Hannah Deuk

Founder & Principal Lawyer

Request A Free Consultation

Our senior lawyers will contact you to discuss your situation & outline next steps.

Insights Library

Legal & Compliance Insights

Browse practical articles, guides & updates from our lawyers on key legal & compliance issues.

Join our Newsletter

Subscribe to our newsletter for the latest legal updates, insights, and firm news delivered straight to your inbox.

What Our Clients Say About Working With Us

Ready-to-Use Legal & Compliance Templates

Lawyer‑drafted legal templates in downloadable Word format.

CONTACT

Request A Consultation

Not sure which matter or service is right for you? Leave your details & our lawyers will contact you to discuss your situation & outline next steps.

Inquire Now

Tell us briefly what you need help with & we’ll reply within 1 business day.