AUSTRAC has issued infringement notices to several businesses that have failed to enrol with AUSTRAC. The infringement notice penalty is $21,840 for corporate entities and $4,368 for individuals.
Businesses that provide a designated service under the AML/CTF Act must enrol with AUSTRAC within 28 days of providing that designated service. For many, this means they should have enrolled by 29 July 2026.
AUSTRAC is actively looking for businesses that have not enrolled and will issue more infringement notices where necessary. All practices that provide designated services and have not already done so, should enrol.
Read more about the enforcement action AUSTRAC is taking against non-enrolled businesses.
AUSTRAC expects members who are reporting entities to:
- understand how the AML/CTF laws apply to their business
- assess the ML/TF risks associated with their customers and services
- develop and apply an AML/CTF program
- train staff to identify and respond to risks and suspicious activity
- use their guidance, education resources and program starter kits where appropriate
- submit complete, accurate and timely reports when required.
What’s new
AUSTRAC has updated its professional designated services guidance to include an example on notaries and notary services. Read the update to the professional services guidance on notaries under the “Activities related to providing a table 6 designated service” section.
See AUSTRAC’s latest guidance updates page to stay up to date on changes. We recommend that practitioners bookmark this page and suggest that their AML/CTF Compliance Officer should be checking this on a regular basis.
AUSTRAC advises that members should also have appropriate controls in place to avoid tipping off in certain circumstances. Practices can refer to their guidance on tipping off.
AUSTRAC is working with the Department of Home Affairs to finalise the Legal Professional Privilege Guidelines 2026, which aim to support businesses by providing greater clarity on balancing legal professional privilege with obligations under the AML/CTF Act. Read more about the draft legal professional privilege guidelines on the Home Affairs website.
AUSTRAC RegTech Insights
AUSTRAC notes that while reporting entities may outsource operational support to RegTech providers, it is not a substitute for effective governance, risk management or business judgement. Reporting entities remain responsible for meeting their AML/CTF obligations.
Please see AUSTRAC’s outsourcing guidance on engaging RegTechs and ensuring appropriate oversight.
Businesses may breach privacy laws if they share customer information with industry associations or AUSTRAC outside of their reporting obligations under the AML/CTF Act. Where possible, practices should de-identify customers (client) information before submitting enquiries. This includes removing personal information that could reasonably identify an individual.
The Office of the Australian Information Commissioner has guidance on this topic.



Share this article