ML, TF and PF under Australia’s AML/CTF Act: Definitions, Risks and Compliance Implications

Published By:

Hannah Deuk

Founder & Principal Lawyer

Key Takeaways:

  • Risk-based program: The reformed AML/CTF program now has two core elements — an ML/TF risk assessment plus policies and controls — and you must review the entire program at least every three years, documenting updates within 14 days.
  • Governance and independent evaluation: Compliance now sits with the governing body and senior managers, the AML/CTF compliance officer must report at least every 12 months, and independent reviews are replaced by whole-of-program independent evaluations due at least every three years.
  • Risk-based CDD: Customer due diligence is split into initial and ongoing CDD with simplified, enhanced and delayed pathways, so a one-size-fits-all workflow is inadequate — and eligible existing entities can only keep old ACIP for initial CDD until 31 March 2029.
  • Staggered transitional deadlines: Existing reporting entities’ obligations generally commenced 31 March 2026 and newly regulated sectors on 1 July 2026, but each obligation has its own transitional deadline — do not assume all relief runs until 2029.
Jump to...
September 1, 2026

Introduction

Reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (‘AML/CTF Act‘) need to distinguish between money laundering (ML), terrorism financing (TF) and proliferation financing (PF). Each concept has its own statutory meaning and can present differently through customers, transactions and business relationships.

These distinctions have direct compliance implications. Section 26C of the AML/CTF Act requires a reporting entity’s ML/TF risk assessment to identify and assess the risks of ML/TF/PF it may reasonably face in providing designated services. In this article, we explain what each concept means and how reporting entities should translate those differences into their AML/CTF risk assessments and controls.

Interactive Tool: Check Your Money Laundering, Terrorism or Proliferation Financing Risk

AML/CTF Risk Type Identifier

Quickly determine whether your scenario involves money laundering, terrorism financing, or proliferation financing risks under Australia’s AML/CTF Act.

What is the main concern or activity you are assessing?

Is the source of funds clearly legitimate (e.g., salary, business revenue) or potentially criminal?

Does the transaction involve high-risk jurisdictions, sanctioned persons, or controlled goods/services?

⚖️ Money Laundering Risk Identified

Your scenario indicates potential money laundering (ML) risk.

Under Section 5 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), money laundering includes dealing with money or property derived from crime or intended to disguise criminal proceeds. Controls should focus on identifying suspicious sources, complex structures, and unexplained third-party involvement.

Section 26C and Section 26F require reporting entities to assess and manage these risks through appropriate AML/CTF controls.

Legal References:

  • Section 5 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
  • Division 400 of the Criminal Code Act 1995 (Cth)
  • Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
  • Section 26F of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Speak to a lawyer about money laundering compliance

⚠️ Terrorism Financing Risk Identified

Your scenario indicates potential terrorism financing (TF) risk.

Section 5 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) covers terrorism financing, including funds from legitimate sources used for terrorist purposes. Controls should focus on the destination, recipient, and purpose of funds, not just their origin.

Section 30 requires ongoing monitoring to identify and mitigate TF risks.

Legal References:

  • Section 5 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
  • Section 102.6 and Division 103 of the Criminal Code Act 1995 (Cth)
  • Sections 20 and 21 of the Charter of the United Nations Act 1945 (Cth)
  • Section 30 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Get legal advice on terrorism financing controls

❌ Proliferation Financing Risk Identified

Your scenario indicates potential proliferation financing (PF) risk.

Section 5 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and the Anti-Money Laundering and Counter-Terrorism Financing (Proliferation Financing) Regulations 2026 (Cth) define PF to include dealing with funds, assets, or services connected to weapons proliferation, sanctions, or controlled goods. Controls must consider exposure to high-risk jurisdictions, sanctioned persons, and dual-use goods.

Section 26C(3) and Section 26F(11) outline risk assessment and control obligations.

Legal References:

  • Section 5 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
  • Anti-Money Laundering and Counter-Terrorism Financing (Proliferation Financing) Regulations 2026 (Cth)
  • Section 26C(3) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
  • Section 26F(11) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Speak to a lawyer about proliferation financing controls

✅ Low AML/CTF Risk Detected

Your scenario appears to present a low risk of money laundering, terrorism financing, or proliferation financing under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).

However, you should regularly review your AML/CTF risk assessment and controls to ensure ongoing compliance.

Legal References:

  • Section 26D of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Get legal advice on AML/CTF compliance

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

The Legal Meaning of Money Laundering

Statutory Definition under the Criminal Code

Section 5 of the AML/CTF Act defines ML as conduct that amounts to an offence against Division 400 of the Criminal Code Act 1995 (Cth) (‘Criminal Code‘). The definition also extends to corresponding offences under state, territory and foreign law.

ML is therefore not confined to conduct occurring in Australia. Relevant activity can involve an Australian offence or corresponding criminal conduct in another jurisdiction.

How Money Laundering Risk Can Present

ML can involve dealing with money or property that is wholly or partly derived from crime or used in connection with crime. It can also involve conduct intended to disguise the source, ownership, or movement of criminal proceeds.

It may facilitate offences such as:

  • fraud and scams;
  • drug, human, and sex trafficking;
  • child exploitation;
  • corruption and other serious crime; and
  • terrorism or weapons proliferation.

For reporting entities, the laundering activity may be separate from the underlying crime. The business may never see the original fraud, trafficking or other offence. It may instead encounter the proceeds when they are transferred, converted, invested, moved through third parties or presented as legitimate wealth.

Practical Implications for Reporting Entities

AML controls should therefore look beyond obviously criminal transactions and consider how the reporting entity’s designated services could be used to obscure the source, ownership, or destination of funds.

Depending on the business and its risk profile, relevant factors may include:

  • transactions inconsistent with the customer’s known circumstances;
  • unexplained changes in transaction size, frequency or behaviour;
  • unnecessarily complex ownership or transaction structures;
  • unexplained third‑part involvement; and
  • transaction patterns that make the origin or destination of funds difficult to understand.

These are risk indicators, not separate statutory tests for ML. The reporting entity’s obligation is to identify and assess the ML risks it may reasonably face and establish controls appropriate to those risks under Sections 26C and 26F of the AML/CTF Act.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

Terrorism Financing Fundamentals

Statutory Definition

Section 5 of the AML/CTF Act defines financing of terrorism by reference to specified offences and corresponding offences in other jurisdictions.

The definition includes:

  • conduct amounting to an offence against Section 102.6 or Division 103 of the Criminal Code;
  • conduct amounting to an offence against Sections 20 or 21 of the Charter of the United Nations Act 1945 (Cth); and
  • corresponding state, territory and foreign offences.

Terrorist Funds Can Come from Legitimate Sources

A key distinction from conventional ML is that TF can involve funds from legitimate as well as criminal sources.

Funds may, for example, be used to:

  • acquire weapons, vehicles or other resources;
  • prepare for a terrorist act; or
  • provide financial or other support to a terrorist organisation.

The lawful origin of funds therefore does not, by itself, remove TF risk. The destination, recipient and intended use of the funds may be more important.

Practical Implications for Reporting Entities

A monitoring framework focused only on suspicious sources of wealth or funds can miss TF risk.

Depending on the reporting entity’s exposure, relevant considerations may include:

  • the recipient or counterparty;
  • the destination of funds;
  • geographic exposure;
  • customer associations;
  • unusual payment patterns; and
  • the stated and apparent purpose of a transaction.

Section 30 of the AML/CTF Act requires reporting entities to monitor customers to appropriately identify, assess, manage and mitigate ML, TF and PF risks. For Australian permanent establishments, monitoring must also support the identification of unusual transactions and behaviour relevant to suspicious matter reporting.

In practice, staff should understand that a transaction can create TF concerns even where the money itself appears to have come from a legitimate source.

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Proliferation Financing Framework

The 2026 Proliferation Financing Framework

Section 5 of the AML/CTF Act defines PF by reference to specified sanctions offences, weapons‑related laws and corresponding offences.

The Anti-Money Laundering and Counter-Terrorism Financing (Proliferation Financing) Regulations 2026 (Cth) (‘PF Regulations‘), which commenced on 31 March 2026 as part of Australia’s 2026 AML/CTF reforms, prescribe additional offences and Commonwealth laws for that definition.

The concept is broader than directly transferring money to a weapons program.It can extend to the provision of assets, funds or financial services and other dealings connected with prohibited proliferation activity.

United Nations and Autonomous Sanctions

Sections 5 and 6 of the PF Regulations prescribe relevant conduct under United Nations and Australian autonomous sanctions applying to the Democratic People’s Republic of Korea (DPRK) and Iran. These provisions capture specified conduct involving sanctioned supplies, services, commercial activities and assets.

For reporting entities, geographic exposure is therefore particularly relevant to PF risk, but it should not be treated as the entire analysis.The customer, counterparties, ownership structure, goods or services and wider transaction can also affect the level of risk.

Commonwealth Weapons Laws

Section 7 of the PF Regulations prescribes five Commonwealth laws:

These laws address conduct involving chemical, biological and nuclear weapons, nuclear material and goods or services capable of contributing to weapons proliferation.

Overseas, Import and Export Conduct

The definition can also extend to corresponding state, territory and foreign offences.

Section 8 of the PF Regulations additionally prescribes specified offences under Part XIII of the Customs Act 1901 (Cth) involving prohibited imports and exports, including certain controlled goods and dealings connected with the DPRK and Iran.

PF risk can therefore arise through the wider commercial transaction rather than through a payment that expressly refers to weapons‑related activity.

Practical Implications for Reporting Entities

PF should not be treated solely as a sanctions‑screening exercise. Depending on the business, the risk assessment may need to consider exposure to:

  • higher‑risk jurisdictions;
  • sanctioned persons and counterparties;
  • complex cross‑border transaction chains;
  • controlled or dual‑use goods;
  • opaque corporate or beneficial ownership structures; and
  • industries or transactions with potential proliferation exposure.

Section 26C(3) of the AML/CTF Act requires Australian reporting entities, when conducting their risk assessment, to have regard to matters including designated services, customers, delivery channels, countries dealt with, and relevant information communicated by the Australian Transaction Reports and Analysis Centre (AUSTRAC).

Importantly, the AML/CTF Act does not necessarily require every reporting entity to maintain separate PF‑specific controls. Under Section 26F(11), a reporting entity is not required to maintain policies, procedures, systems, and controls specifically addressing PF if it reasonably assesses its PF risk as low and reasonably assesses that the risk can be appropriately managed through its ML or TF controls. The reporting entity bears the legal burden if it relies on that exception.

The practical question is therefore not simply whether the business has a separate PF policy. It is whether PF risk has actually been assessed and whether the controls chosen are appropriate to that assessment.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

What “Money” Means under the AML/CTF Act

Cash, Accounts and Deposits

Section 5 of the AML/CTF Act defines money broadly. It includes:

  • physical currency;
  • money held in an account; and
  • money held on deposit,

whether denominated in Australian or foreign currency.

The framework is therefore not limited to physical cash. Funds held or transferred through ordinary accounts and deposit arrangements can fall within the statutory definition.

Government‑Issued Digital Value

The definition also includes a digital representation of value where it is:

  • issued by, or under the authority of, a government body; and
  • intended to function as money.

A central bank digital currency is given as an example.

This should be distinguished from the separate concept of a virtual asset under Section 5B AML/CTF Act. That definition generally covers certain transferable or tradeable digital representations of value that are not issued by or under the authority of a government body and expressly excludes “money”.

For businesses dealing with digital assets, internal classifications should therefore reflect the statutory character of the asset rather than treating all digital value as the same category.

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Turning the Definitions into AML/CTF Controls

The statutory definitions matter because they should shape the reporting entity’s AML/CTF program, with AML/CTF compliance services available to support its design and implementation.

Under Section 26B of the AML/CTF Act, an AML/CTF program comprises the reporting entity’s ML/TF risk assessment and AML/CTF policies. Section 26C requires the assessment to identify and assess ML, TF and PF risks, while Section 26F requires policies, procedures, systems and controls to appropriately manage and mitigate those risks.

A practical review should include the following steps:

  1. Map each designated service against ML, TF and PF separately. A service may present different levels or types of exposure to each risk.
  2. Consider the statutory risk factors. For Australian permanent establishments, this includes services, customers, delivery channels, countries, relevant technologies and risk information communicated by AUSTRAC.
  3. Check whether transaction monitoring reflects the differences. ML risk may be visible in the source or movement of criminal proceeds, TF risk in the destination or use of legitimate funds, and PF risk through countries, counterparties or the wider commercial transaction.
  4. Review the assessment when risk changes. Section 26D requires review where relevant risks materially change and at least once every three years. Where a significant change within the reporting entity’s control affects the assessment, the review must occur before that change is implemented.
  5. Decide whether dedicated PF controls are necessary. Where PF risk is genuinely low, Section 26F(11) may permit the business to manage it through existing ML or TF controls.
  6. Train staff on how the risks differ. Section 26F(4) requires AML/CTF policies to address staff training on the ML, TF and PF risks the reporting entity may reasonably face. Training should therefore explain how each risk can present in the business rather than treating financial crime as a single generic category.

The objective is not to create three disconnected compliance systems.It is to ensure that the reporting entity understands each risk sufficiently to design controls that respond to how that risk can actually arise through its services.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

Conclusion

Money laundering, terrorism financing and proliferation financing overlap, but they are not interchangeable. ML commonly concerns criminal proceeds or property connected with crime; TF can involve legitimate funds; and PF introduces sanctions, weapons‑proliferation and certain cross‑border trade risks into the AML/CTF framework.

For reporting entities, these distinctions should be reflected in the ML/TF risk assessment, customer monitoring and AML/CTF controls, and businesses needing help implementing them can contact Click Legal’s AML/CTF compliance lawyers. A program that refers to all three risks but assesses them in the same way may miss how those risks actually arise in the business.

Frequently Asked Questions

JUMP TO...
Table of Contents

Published By:

Hannah Deuk

Founder & Principal Lawyer

Request A Free Consultation

Our senior lawyers will contact you to discuss your situation & outline next steps.

Insights Library

Legal & Compliance Insights

Browse practical articles, guides & updates from our lawyers on key legal & compliance issues.

Join our Newsletter

Subscribe to our newsletter for the latest legal updates, insights, and firm news delivered straight to your inbox.

What Our Clients Say About Working With Us

Ready-to-Use Legal & Compliance Templates

Lawyer‑drafted legal templates in downloadable Word format.

CONTACT

Request A Consultation

Not sure which matter or service is right for you? Leave your details & our lawyers will contact you to discuss your situation & outline next steps.

Inquire Now

Tell us briefly what you need help with & we’ll reply within 1 business day.