AUSTRAC is Australia's financial intelligence unit and anti-money laundering regulator: it collects reports from regulated businesses, analyses them and supervises reporting entities under the AML/CTF Act.
Also known as: Australian Transaction Reports and Analysis Centre, financial intelligence unit, AML/CTF regulator
Key points
- Its statutory basis is the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 and the rules made under it.
- Reporting entities must enrol with AUSTRAC, run a risk-based AML/CTF program and verify customers (know your customer).
- They must lodge suspicious matter reports, international funds transfer instructions and threshold transaction reports through AUSTRAC Online.
- It shares intelligence with the AFP, ASIC, the ATO and overseas counterparts, so one report can trigger a multi-agency response.
- It can seek civil penalties, issue infringement notices, accept enforceable undertakings and refer intentional conduct for prosecution.
What AUSTRAC does
AUSTRAC has two jobs that feed each other. As a financial intelligence unit it receives suspicious matter reports, cross-border transfer instructions and high-value transaction reports from regulated businesses, analyses that data and passes intelligence to the Australian Federal Police, ASIC, the ATO and counterpart agencies overseas. As a regulator it supervises the businesses that must lodge those reports.
The supervisory side includes publishing guidance for banks, remitters, casinos, digital currency exchanges and other sectors, running compliance assessments and audits, and enforcing the Act when a business falls short. Because the intelligence is shared, a single report from a small lender can end up supporting a police investigation or a tax recovery action.
Who is a reporting entity
A reporting entity is any business caught by the AML/CTF framework because of the designated services it provides. The usual categories are banks, credit unions and other deposit-takers; remitters and payment service providers; casinos and gaming operators; digital currency exchanges and wallet providers; dealers in high-value goods, including precious metals and stones; trustees and custodians; and certain loan providers, foreign exchange dealers and money changers. Real estate professionals, conveyancers, lawyers, accountants and trust and company service providers are caught when they provide specified services such as conveyancing or trust work.
You must enrol with AUSTRAC within the statutory window after you start providing a designated service, and remitters and digital currency exchanges must be registered before they begin. Operating without the registration you need is a breach in itself. The obligations are proportionate: a small remitter runs a scaled-down program compared with a major bank, but the core principles are the same. To confirm whether you are caught, check the statutory definitions in the Act and AUSTRAC's industry guidance.
Obligations and reports
Every reporting entity must maintain a documented AML/CTF program approved by senior management, assess its money laundering and terrorism financing risk across customers, services, channels and countries, identify and verify customers and their beneficial owners with enhanced due diligence for higher-risk relationships, monitor transactions, screen and train staff, keep auditable records for the statutory period and test the program independently.
Three reports matter most, all lodged through AUSTRAC Online. A suspicious matter report goes in as soon as practicable once you form a reasonable suspicion that a transaction or customer is linked to crime, money laundering or terrorism financing. An international funds transfer instruction captures sender and recipient details for cross-border transfers. Threshold transaction reports cover cash and other transactions above the set limits. AUSTRAC may also ask for compliance reports during audits.
Enforcement and how to respond
AUSTRAC's tools run from compliance notices and remedial directions, through infringement notices and enforceable undertakings, to civil penalty proceedings and criminal referral for intentional or reckless conduct. In deciding how hard to go it weighs the scale and duration of the failure, whether controls were absent or merely ineffective, the harm to the financial system, and how quickly and openly the business fixed the problem.
Its published cases follow a pattern: a large institution with transaction monitoring nobody tuned, a remitter with poor customer identification, a crypto exchange lodging transfer reports late. If you receive a compliance notice, engage legal and compliance advice, preserve evidence, hand over what is requested and implement the agreed remediation. Transparency and speed reduce the severity of the outcome.
Example
A small remittance business registers with AUSTRAC, writes a short risk-based AML/CTF program and trains its two staff. One month a regular customer starts sending several transfers a week to a high-risk country, each just under the cash reporting threshold, and cannot explain where the money comes from. Staff escalate to the compliance officer, who lodges a suspicious matter report through AUSTRAC Online without telling the customer. AUSTRAC analyses the report alongside data from banks and other remitters and, if it fits a wider pattern, passes it to the Australian Federal Police.
Not to be confused with
- ASIC
- ASIC licenses and regulates the conduct of financial services and credit providers; AUSTRAC supervises their AML/CTF obligations and analyses financial intelligence
- Anti-money laundering (AML)
- anti-money laundering is the regime of laws and controls; AUSTRAC is the agency that enforces it
Frequently asked questions
What does AUSTRAC do?
AUSTRAC collects and analyses financial transaction reports to detect money laundering and terrorism financing, and shares that intelligence with police, tax and regulatory agencies in Australia and overseas. It also supervises reporting entities under the AML/CTF Act, publishing guidance, auditing compliance and taking enforcement action against businesses that fail to meet their obligations.
Who has to register with AUSTRAC?
Any business that provides a designated service under the AML/CTF Act: banks and other lenders, remitters, foreign exchange dealers, casinos, digital currency exchanges, high-value dealers, trustee services and, for specified services, real estate professionals, conveyancers, lawyers and accountants. Enrol within the statutory window after you start; remitters and digital currency exchanges must register first.
When do I have to lodge a suspicious matter report with AUSTRAC?
As soon as practicable after you form a reasonable suspicion that a transaction, attempted transaction or customer is linked to crime, money laundering or terrorism financing. Include the customer identifiers, transaction details, why it looks suspicious and any steps you took. Where there is an immediate threat, contact law enforcement first.
What is the difference between AUSTRAC and ASIC?
ASIC regulates conduct: licensing, disclosure and fair treatment of customers in financial services and credit. AUSTRAC regulates financial crime risk: whether a business identifies its customers, monitors transactions and reports suspicious activity under the AML/CTF Act. A lender answers to both, and the two agencies share intelligence.
What can AUSTRAC do if a business breaks the rules?
It can issue compliance notices and remedial directions, require independent audits, issue infringement notices, accept enforceable undertakings, seek civil penalties in court and refer intentional or reckless conduct for criminal prosecution. Penalties scale with the size and duration of the failure and with how quickly the business cooperated and remediated.
Related terms
Anti-money laundering (AML)
Anti-money laundering (AML) is the set of laws, controls and processes designed to stop criminals turning the proceeds of crime into apparently legitimate funds, enforced in Australia by AUSTRAC.
Read definitionCounter-terrorism finance (CTF)
Counter-terrorism finance (CTF) is the set of controls that prevent, detect and cut off funds flowing to terrorists, which Australian reporting entities must apply under the AML/CTF Act.
Read definitionMoney laundering
Money laundering is the process of disguising the origin, movement or ownership of money made from crime so that it appears legitimate and can be used openly.
Read definitionKnow your customer (KYC)
Know your customer (KYC) is the process a reporting entity uses to identify and verify a customer, understand their business and assess the money laundering and terrorism financing risk.
Read definitionSanctions checks
Sanctions checks are screening steps that test whether a person, company or transaction is subject to government sanctions, such as asset freezes, before a lender deals with them.
Read definitionPolitically exposed person (PEP) checks
Politically exposed person (PEP) checks are screening steps that flag customers who hold prominent public positions, so a lender can apply extra due diligence under anti-money laundering laws.
Read definitionGo deeper
Sources
This article is general information only and is not financial advice.