Introduction
Australia’s reformed anti-money laundering and counter-terrorism financing (AML/CTF) framework changed the obligations of existing reporting entities on 31 March 2026. Their AML/CTF program must now reflect a statutory structure built around money laundering and counter-terrorism financing (ML/TF) risk assessment and AML/CTF policies, including requirements addressing proliferation financing (PF) and governance.
The article covers how to review the risk assessment, update AML/CTF policies and governance arrangements, and revise customer due diligence procedures. It also explains how to document and approve the updated program, apply targeted transitional arrangements, and plan the required independent evaluation.
Interactive Tool: Check If Your AML/CTF Program Meets the 2026 Reforms
AML/CTF Program Transition Checker
Quickly check if your AML/CTF program meets the 2026 reforms and transitional requirements.
1 of 3 | Has your AML/CTF program been updated to address money laundering, terrorism financing, and proliferation financing risks under the 2026 reforms?
✅ Your AML/CTF Program Appears Compliant
Legal References:
- Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 26F of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 26H of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 26J of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 26N of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 26P of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026 (Cth)
⚠️ Proliferation Financing Risk Not Addressed
Legal References:
- Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 26F(11)-(12) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
❌ Program Not Updated for 2026 Reforms
Legal References:
- Section 26G of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026 (Cth)
⚠️ CDD Procedures Require Urgent Update
Legal References:
- Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026 (Cth)
⚖️ Governance and Oversight Gap Identified
Legal References:
- Section 26H of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 26J of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
What Changed Under the New AML/CTF Program Framework?
ML/TF Risk Assessments
Under Sections 26C(1) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (‘AML/CTF Act‘), a reporting entity’s ML/TF risk assessment must identify and assess the ML/TF/PF risks it may reasonably face when providing designated services. Section 26C(2) requires the steps taken in undertaking that assessment to be appropriate to the nature, size, and complexity of the business.
For an entity providing designated services through an Australian permanent establishment, Section 26C(3)(a)-(f) of the AML/CTF Act requires consideration of several factors. These include its:
- the kinds of designated services it provides or proposes to provide, including new or emerging technologies relating to those services;
- the kinds of customers to whom those services are or will be provided;
- its delivery channels, including new or emerging technologies relating to those delivery channels;
- the countries with which it deals, or will deal, in providing designated services;
- relevant risk information communicated directly or indirectly by AUSTRAC; and
- any matters specified in the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth) (‘AML/CTF Rules’).
Under Section 26D(1) of the AML/CTF Act, the risk assessment must be reviewed after specified changes or information and at least once every three years. For a significant change within the reporting entity’s control, Section 26D(2)(a) requires the review to occur before the change occurs. Further, Section 26D(4) requires issues identified by a review to be addressed in an updated assessment. Rule 5-1 of the AML/CTF Rules also requires a review following adverse findings about the risk assessment in an independent evaluation report.
AML/CTF Policies
Under Section 26F(1) of the AML/CTF Act, a reporting entity must develop and maintain AML/CTF policies comprising policies, procedures, systems and controls. These must:
- appropriately manage and mitigate the ML/TF/PF risks the business may reasonably face;
- ensure compliance with the AML/CTF Act and AML/CTF Rules; and
- suit the nature, size, and complexity of the business.
The risk assessment and AML/CTF policies must operate together. The risk assessment identifies the relevant risks, while the policies, procedures, systems and controls explain how the reporting entity will manage them. Under Section 26G of the AML/CTF Act, the reporting entity must comply with its AML/CTF policies.
Step 1: Review & Update Your ML/TF Risk Assessment
Adding Proliferation Financing Risk
As discussed above, risk assessment must identify and assess PF risk alongside ML/TF risks. As a result, a pre-reform program that addressed only ML/TF should be updated to assess proliferation financing risk.
Section 26F(11) of the AML/CTF Act does not require policies, procedures, systems, and controls that specifically deal with PF if the entity reasonably assesses that its PF risk is low and reasonably assesses that it can be appropriately managed and mitigated through its existing ML/TF controls. Under Section 26F(12), a person relying on the Section 26F(11) exception bears the legal burden.
Linking Controls to Identified Risks
The AML/CTF program should show how its policies, procedures, systems, and controls respond to the risks identified in the ML/TF risk assessment. A higher-risk scenario may require additional measures, including:
- enhanced customer due diligence;
- additional transaction monitoring;
- more frequent customer risk reviews; and
- senior management approval.
The assessment should be checked against the controls that operate in the business. If the assessment identifies higher risks, but the same procedures apply to every customer, product or transaction, the entity should examine whether its AML/CTF policies appropriately manage and mitigate those risks.
Step 2: Update Governance & Accountability
Governing Body Oversight
Under Section 26H(1)(b) of the AML/CTF Act, the governing body must exercise appropriate ongoing oversight of the entity’s ML/TF risk assessment and compliance with its AML/CTF policies and legal framework.
The governing body must also take reasonable steps to ensure the entity identifies, assesses, manages and mitigates its ML/TF/PF risks. Its oversight may include:
- receiving regular reports;
- reviewing compliance issues; and
- monitoring remedial actions.
AML/CTF Compliance Officer
Under Section 26J(1)-(3) of the AML/CTF Act, a reporting entity must designate an individual at management level as its AML/CTF compliance officer. The officer must be fit and proper and have sufficient authority, independence, resources, and access to information to perform the role effectively.
In addition, under Section 26L of the AML/CTF Act, the officer:
- oversees day-to-day compliance;
- coordinates the operation of the AML/CTF policies; and
- communicates with AUSTRAC.
Under Section 26M(1), the Australian Transaction Reports and Analysis Centre (AUSTRAC) must ordinarily be notified within 14 days of the designation. For entities enrolled on 30 March 2026, the transitional notification date was 30 May 2026, which has now passed.
Step 3: Update Customer Due Diligence Procedures
Transitioning From ACIP to Initial CDD
Eligible reporting entities enrolled on 30 March 2026 may continue using the applicable customer identification procedures (ACIP) for selected customer classes during the transition to initial customer due diligence (CDD). Under the Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026 (Cth) (‘Transitional Rules‘), this transitional period runs until 31 March 2029.
By 1 July 2026, eligible entities were required to document the relevant customer classes and transition dates in their policies. Specifically, the reporting entity’s AML/CTF policies must identify:
- the customer classes that will continue under ACIP; and
- the date each class will move to the initial CDD framework.
Each customer class must be subject to either ACIP or initial CDD at any given time.
Ongoing CDD Requirements
The ACIP transition applies only to initial CDD. Existing reporting entities have been required to comply with the revised ongoing CDD requirements from 31 March 2026.
Their AML/CTF program should support ongoing monitoring of customers and relevant transactions, including:
- identifying unusual transactions or behaviour that may require further assessment;
- reviewing and updating customer ML/TF risk assessments when required;
- reviewing, updating and, where appropriate, reverifying customer information; and
- responding to doubts about the adequacy or accuracy of customer information.
Step 4: Finalise Your Updated AML/CTF Program
Review Supporting AML/CTF Policies & Systems
The AML/CTF program should be supported by systems and procedures that reflect the entity’s updated ML/TF risk assessment and the AML/CTF policies described above (Section 26F(1) of the AML/CTF Act).
The review should cover:
- transaction monitoring and suspicious matter escalation;
- enhanced CDD;
- personnel controls and training;
- record keeping; and
- reporting processes.
Sections 26F(4)(d)–(e) of the AML/CTF Act require policies addressing personnel due diligence and training.
Documenting & Approving the Updated Program
Under Section 26N of the AML/CTF Act, a reporting entity must document its AML/CTF program and any other prescribed matters. The documentation should accurately record the updated ML/TF risk assessment, AML/CTF policies and supporting controls.
Under Section 26P(1) of the AML/CTF Act, the ML/TF risk assessment and AML/CTF policies, including updates to either, must be approved by a senior manager. In addition, updates to the ML/TF risk assessment must be notified in writing to the governing body as soon as practicable after the update under Section 26P(2) of the AML/CTF Act.
Planning for AML/CTF Independent Evaluations
The reformed framework replaces independent reviews of Part A with independent evaluations of the entire AML/CTF program. Under Section 26F(4)(f) of the AML/CTF Act, AML/CTF policies must address the evaluation process and its frequency.
The independent evaluation frequency must suit the nature, size, and complexity of the business and must be at least once every three years. The evaluation should assess both the design of the program and how effectively the entity operates its risk assessment, policies, procedures, systems, and controls.
When Is the First Evaluation Due?
For an entity enrolled on 30 March 2026 that had completed at least one qualifying independent review under the pre-reform framework, Rule 16 of the Transitional Rules allows the first independent evaluation to occur by the later of:
- four years after the most recent qualifying independent review; or
- 31 March 2027.
Entities that do not meet these criteria must determine their evaluation timing under the ordinary framework described above.
Common AML/CTF Program Transition Mistakes
A reporting entity should avoid treating the transition as a document-renaming exercise. Common errors include:
- rebadging former Part A and Part B documents without updating their substance;
- failing to update the ML/TF risk assessment;
- omitting proliferation financing risk;
- retaining outdated CDD procedures;
- failing to involve the governing body in ongoing oversight;
- relying on transitional arrangements without recording the affected customer classes and transition dates; and
- treating AUSTRAC templates as a substitute for a business-specific AML/CTF program.
AUSTRAC templates and starter kits may assist with understanding the framework, but the program must reflect the reporting entity’s nature, size, complexity, designated services and reasonably faced risks.
A Practical AML/CTF Program Transition Checklist
A compliance team reviewing its program should check whether it has:
- completed a gap analysis;
- updated the ML/TF risk assessment;
- assessed proliferation financing risk;
- mapped controls to identified risks;
- reviewed governance and compliance officer arrangements;
- updated initial and ongoing CDD procedures;
- reviewed systems, reporting processes, training and record keeping;
- documented transitional arrangements;
- obtained required approvals;
- notified the governing body of risk assessment updates; and
- identified the applicable independent evaluation deadline.
Conclusion
Australia’s 2026 reforms require existing reporting entities to update their AML/CTF program under the AML/CTF Act, including the ML/TF risk assessment, AML/CTF policies, governance, CDD and independent evaluation arrangements. Targeted transitional arrangements, such as ACIP for eligible customer classes and delayed first evaluations for qualifying entities, do not postpone the reformed framework as a whole.
For assistance with the transition, contact Click Legal for AML/CTF compliance services to review your program, identify gaps and address the requirements that apply to your business. Click Legal’s regulatory lawyers can provide clear guidance on risk assessments, governance, CDD, documentation and transitional arrangements.