Upcoming Changes to AML/CTF Legislation: What You Need to Know

by | Feb 9, 2026 | Uncategorized | 0 comments

Australia is implementing one of its most significant overhauls of the Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) regime since the Act was introduced in 2006.

The AML/CTF Rules 2025, tabled in Parliament on 29 August 2025, will take effect from 31 March 2026 for existing reporting entities and 1 July 2026 for newly regulated sectors.

The reforms aim to:

  • Align Australia’s framework with Financial Action Task Force (FATF) global standards
  • Modernise compliance obligations to address emerging risks such as virtual assets, politically exposed persons (PEPs), and cross-border transactions
  • Expand coverage to professional services (law, accounting, real estate) and strengthen governance for AFSL holders.

The traditional Part A/Part B program structure is being reshaped into a more dynamic, single, risk‑based, and outcomes‑focused model. Under this modernised approach, integrated risk assessment becomes a central obligation within the amended Act, encouraging programs that demonstrate genuine effectiveness rather than relying on documentation alone.

Governance and accountability will be strengthened across business groups, particularly for AFSL licensees operating across multiple entities, while customer due diligence and reporting obligations broadened, including the introduction of new “value transfer” reporting for virtual assets.

This shift aims to support organisations in building more agile, responsive, and truly risk‑aligned compliance programs.

As a result of these program updates, AUSTRAC expects entities to maintain and strengthen their existing AML/CTF controls while taking a proactive, risk‑focused approach to improvement. Organisations are encouraged to develop a clear implementation plan that prioritises updates targeting their highest ML/TF risks, ensuring effort is directed where it has the greatest impact.

Moving forward, programs should be genuinely tailored to the realities of each business, supporting stronger, more resilient frameworks that meet both regulatory expectations and operational needs.

Australian Financial Service Licence (AFSL) holders remain key reporting entities under the AML/CTF Act, and this continued responsibility gives them a valuable opportunity to not only meet the updated compliance requirements but to strengthen their frameworks in a way that builds confidence, supports good governance and positions their business for long‑term success.

This will look like:

  1. Enrolment and Registration

AFSL holders must ensure enrolment details are updated with AUSTRAC by 31 March 2026 for any new designated services provided.

  1. Develop a Risk-Based AML/CTF Program

AFSLs are expected to take a proactive and well‑considered approach to their obligations by conducting a comprehensive ML/TF risk assessment that reflects the nature of their services, customer profiles, delivery channels and operating jurisdictions.

This strengthened approach also involves incorporating AUSTRAC’s national priorities and emerging risks, such as proliferation financing and exposure to crypto assets, so programs remain aligned with broader regulatory expectations and the evolving risk environment.

At the same time, clearly documenting governance arrangements and ensuring strong board oversight helps reinforce accountability and positions AFSLs to build confident, resilient compliance frameworks that support both regulatory outcomes and long‑term organisational success.

  1. Customer Due Diligence and Reporting

AFSLs are encouraged to strengthen their onboarding and ongoing monitoring processes to ensure they can confidently identify and respond to potential risks as they arise. As well as preparing for expanded reporting obligations, including suspicious matter reports and the new international value transfer service (IVTS) reporting, will help them stay ahead of regulatory expectations and maintain a robust, future‑ready compliance posture.

  1. Training and Awareness

AFSLs will need to take an active and forward‑looking approach by updating their staff training programs to reflect the new legislative requirements and emerging risk indicators, helping teams feel confident and well equipped to navigate the evolving compliance landscape.

It is equally important that compliance officers and responsible managers understand the revised framework in depth, supporting strong oversight, informed decision‑making and a culture of proactive, risk‑aware compliance across the organisation.

  1. Governance and Documentation

AFSLs should aim to move away from prescriptive templates and adopt more dynamic, risk‑focused documentation that genuinely reflects their operations and evolving risk profile.

AFSLs should also demonstrate the effectiveness of this approach through regular reviews and independent audits will also be important, helping to build confidence in their frameworks and fostering a strong, accountable and forward‑looking compliance culture.

Failure to comply with the updated AML/CTF regime can lead to serious civil and criminal penalties, reputational harm and potential implications for an AFSL holder’s licence, highlighting the importance of staying ahead of these changes.

With deadlines approaching, this is a timely opportunity for AFSL licensees to review their existing programs, engage with AUSTRAC’s guidance and broader industry resources, and ensure they have the right support and resourcing in place for implementation and staff training.

Taking these proactive steps now will not only reduce compliance risk but also help build stronger, more resilient frameworks that set organisations up for ongoing success under the enhanced regulatory environment.

GRC Essentials is well positioned to help AFSL licensees navigate the strengthened AML/CTF regime with confidence by providing tailored, practical support across every stage of uplift.

Our team can assist with updating and enhancing AML/CTF policies and frameworks, so they align with the new risk‑based, outcomes‑focused requirements, while our comprehensive training courses ensure staff, compliance officers and responsible managers clearly understand their obligations and emerging risk indicators. We also offer guidance for entities delivering new designated services, as well as those preparing to enter the regime under Tranche 2, helping them build effective, scalable programs from the outset.

With a focus on clarity, capability and continuous improvement, GRC Essentials can empower licensees to meet AUSTRAC’s expectations and strengthen their compliance culture for the long term.

If you would like to discuss your upcoming AML/CTF obligations, have any questions about relevance to your business, or would like to access updated Aml/CTF Policies or Training, please contact us at support@grcessentials.com.au

Written By

undefined

Explore More on Governance and Compliance

Digital Technologies and Financial Services

Background Information The Australian Securities and Investments Commission (ASIC) has intensified its focus on cyber security and artificial intelligence (AI) in response to the evolving digital landscape and increasing reliance on technology across financial...

read more

ASIC’s Limited No-Action for Fee Consents

Summary ASIC has granted a limited no-action position for licensees that have entered into an ongoing fee arrangement (OFA) with clients between 10 January 2025 to 5 September 2025 where an account number was not included in the consent form. Background Information On...

read more

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *