LM-G03 · GRC · Practitioner tier

Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)

AUSTRAC obligations, KYC, SMRs, and Tranche 2

📝 30-question assessment🎯 3 scoring tiers (Foundation / Practitioner / Leader)

What you'll be able to do

  • 1.Identify the designated services in section 6 of the AML/CTF Act 2006 (Cth), including the Tranche 2 services regulated from 1 July 2026, and the obligations each one triggers.
  • 2.Apply initial and ongoing customer due diligence, enhanced due diligence, and reporting obligations (SMR, TTR, IFTI) to realistic Australian financial services scenarios.
  • 3.Analyse transaction patterns and behavioural indicators to determine whether a suspicious matter report is required and lodge it within the statutory timeframe under section 41.
  • 4.Evaluate a documented ML/TF risk assessment and AML/CTF policies against the reformed obligations in force from 31 March 2026 and AUSTRAC guidance.
  • 5.Construct a governed AI workflow that drafts AML/CTF artefacts from de-identified inputs with human review, tipping off checks, and audit-ready logging.
  • 6.Assess Tranche 2 readiness and reporting group arrangements and brief a Board or Senior Manager with quantified gap evidence.

THE AI COMMAND

LEARNING MODULE

TAIC-LM-G03

Anti-Money Laundering and

Counter-Terrorism Financing

Act 2006 (Cth)

From AUSTRAC obligations to AI-enabled compliance practice

FieldValue
Module IDTAIC-LM-G03
DomainGovernance, Risk and Compliance (GRC)
Audience tierPractitioner (with Foundation primer and Leader extension)
Estimated reading timeModule: 23 minutes (5,000 module body words at 220 words per minute, excluding cover and references). Allow 10 to 15 additional minutes for visuals and reflection. Assessment: 25 to 30 minutes.
PrerequisitesTAIC-LM-G01 Corporations Act 2001 (recommended). Working familiarity with the Australian financial services regulatory perimeter, customer onboarding processes, and risk-based controls.
Cross-referencesTAIC-LM-G02 Privacy Act 1988 and APPs. TAIC-LM-G05 APRA CPS 230 Operational Risk Management. TAIC-LM-G07 APRA CPS 220 Risk Management. Sanctions screening and the DFAT Consolidated List are covered within this module and its further reading list.
Learning outcomes1. Identify designated services and the obligations they trigger under the AML/CTF Act 2006 (Cth) (Bloom: Remember, Understand). 2. Apply customer identification and ongoing due diligence to a realistic scenario (Bloom: Apply). 3. Analyse a transaction pattern to determine whether a Suspicious Matter Report is required (Bloom: Analyse). 4. Evaluate the design of a documented ML/TF risk assessment and AML/CTF policies against regulator expectations (Bloom: Evaluate). 5. Construct an AI-assisted workflow that drafts SMR narratives and program updates while preserving privacy and audit-trail integrity (Bloom: Create). 6. Assess Tranche 2 readiness gaps for an extended reporting entity (Bloom: Evaluate).
Authoring dateApril 2026 (post Tranche 2 commencement signal date)

Executive Summary

Stylised night-time Australian harbour city with luminous transaction light trails converging on a single monitored gateway, representing the expanded AML/CTF regulatory perimeter after the 2024 reforms
The AML/CTF perimeter after the 2024 reforms: one gateway of obligations, a much larger regulated population.

The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (the AML/CTF Act) is the Commonwealth statute that obliges Australian reporting entities to detect, deter, and disrupt the movement of illicit funds and the financing of terrorism. The Act is administered by the Australian Transaction Reports and Analysis Centre (AUSTRAC), which is both Australia's anti-money laundering regulator and its financial intelligence unit. The Act sits over a layered regime of customer due diligence, transaction monitoring, mandatory reporting, governance program design, and record-keeping. The regime was substantially reformed by the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024: since 31 March 2026 every reporting entity must maintain a documented money laundering and terrorism financing (ML/TF) risk assessment and AML/CTF policies in place of the former Part A and Part B program structure. From 1 July 2026 the Act extends to Tranche 2 reporting entities including law practices, accounting practices, real estate professionals, and dealers in precious metals and stones, materially enlarging the regulated population.

Why this matters

Australian financial services entities sit at the centre of the AML/CTF perimeter. Civil penalties for systemic breach run to tens of millions of dollars per contravention, and recent enforcement outcomes have crossed the billion-dollar threshold for Australian Authorised Deposit-taking Institutions (ADIs). Beyond the financial exposure, Boards and Senior Managers are accountable under the Financial Accountability Regime (FAR) for the soundness of AML/CTF controls, and APRA prudential standard CPS 230 captures AML/CTF reporting as a critical operation. The cost of getting this wrong is compounding: regulator action, FAR consequences, capital impact, and reputational loss.

What you will be able to do

  1. Read the AML/CTF Act 2006 (Cth) and identify which obligations apply to a given product, service, or business line.
  2. Decompose a customer or transaction scenario into the right obligation pathway (CDD, ECDD, SMR, TTR, IFTI, sanctions screening).
  3. Draft, review, and stress-test an ML/TF risk assessment and AML/CTF policies against AUSTRAC published guidance.
  4. Stand up a governed AI workflow in Claude or ChatGPT that drafts compliance artefacts without leaking customer data.
  5. Brief a Board or Senior Manager on Tranche 2 readiness with quantified gap evidence.

Regulatory and Strategic Context

Timeline of AML/CTF milestones from commencement on 13 December 2006, through the reformed tipping off offence on 31 March 2025 and the new risk assessment and policies structure on 31 March 2026, to Tranche 2 commencement on 1 July 2026
Four dates define the reformed regime: 13 December 2006, 31 March 2025, 31 March 2026, and 1 July 2026.

Issuer and statutory authority

The AML/CTF Act 2006 (Cth) is an Act of the Commonwealth Parliament. It is supplemented by the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (the AML/CTF Rules), made under section 229 of the Act, which replaced the 2007 Rules Instrument from 31 March 2026 and carry binding regulatory detail. AUSTRAC publishes guidance, regulator priorities, and typology bulletins which, while not binding instruments, set the operational expectations a reasonable reporting entity should meet. The Financial Action Task Force (FATF) sets the international standards that Australia implements through this Act, and Australia is subject to FATF Mutual Evaluations on its compliance posture.

Scope of application

The Act applies to a person who provides a designated service. Section 6 of the Act lists the designated services in a series of tables. The longstanding tables cover financial services, bullion, and gambling, and the Tranche 2 reforms added services covering real estate, professional services, and dealers in precious metals and stones, with obligations commencing 1 July 2026. Item numbering has been amended over the life of the Act and practitioners should always work from the current consolidated version. The financial sector table is the longest and captures account-based services, lending, foreign exchange, derivatives, custodial services, life insurance investment products, superannuation services, and virtual asset services, the term that replaced digital currency exchange under the 2024 amendments. Since 31 March 2026 corporate groups operate as reporting groups, the structure that replaced designated business groups. A reporting group may nominate a lead entity to maintain group-wide AML/CTF policies, and members may share functions such as ongoing customer due diligence, but each reporting entity remains accountable for the obligations attaching to the designated services it provides.

The geographical reach of the Act is extra-territorial in two important ways. First, a service provided at or through a permanent establishment of the entity in Australia falls within scope even if the customer is overseas. Second, services provided by an Australian permanent establishment to a customer outside Australia carry full obligations. This matters for offshore branches, foreign subsidiaries, and cross-border product distribution.

Key dates and transitional periods

The Act commenced on 13 December 2006 with a phased implementation through 2008. Successive amendments expanded the regime, including the introduction of digital currency exchange registration effective 3 April 2018, later absorbed into the broader virtual asset service provider regime, and the strengthening of beneficial ownership and politically exposed person (PEP) requirements through Rules amendments.

The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 delivered the most substantial reform of the regime since commencement. Three dates matter.

  • 31 March 2025. The reformed tipping off offence in section 123 commenced. The old blanket prohibition was replaced with an outcomes-based test: disclosing SMR-related information is prohibited where the disclosure would, or could reasonably be expected to, prejudice an investigation.
  • 31 March 2026. For existing reporting entities, the prescriptive Part A and Part B program structure was replaced by a documented ML/TF risk assessment and AML/CTF policies. Reporting groups replaced designated business groups. The virtual asset service provider regime replaced digital currency exchange registration. The Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 replaced the 2007 Rules Instrument.
  • 1 July 2026. Tranche 2 entities, including law practices, accounting practices, conveyancers, real estate professionals, and dealers in precious metals and stones, became reporting entities when they provide listed designated services. A new reporting entity must enrol with AUSTRAC within 28 days of first providing a designated service, and enrolment opened for the new population on 31 March 2026.

AUSTRAC's transitional posture favours entities that can demonstrate a good faith program build, a documented ML/TF risk assessment, and active engagement with the regulator. Entities that treated 31 March 2026 as a re-badging exercise rather than a redesign carry the highest supervisory risk.

If your program artefacts predate 31 March 2026, run the prompt below before your next governance committee. Upload only redacted, de-identified documents.

Prompt
Role: AML/CTF program reviewer for an Australian [ENTITY_TYPE, e.g. ADI, general insurer, superannuation trustee].
Context: I have uploaded our pre-reform Part A and Part B program documents (redacted, no customer data).
Task: Map every element of these documents to the reformed structure in force since 31 March 2026: a documented ML/TF risk assessment and AML/CTF policies under the AML/CTF Act 2006 (Cth) as amended and the AML/CTF Rules 2025.
Produce:
1. A conversion table: pre-reform element, reformed home (risk assessment or policies), status (carries over, needs rewrite, no longer required, new obligation not covered).
2. A gap register for anything the reformed regime requires that the old documents do not cover, including reporting group arrangements, virtual asset services if relevant, and the reformed section 123 tipping off controls.
3. A remediation plan with owner role, priority, and a target date placeholder for each gap.
Constraints: cite the Act or the AML/CTF Rules 2025 for every reformed obligation. Flag anything you are not certain of as OPEN QUESTION rather than guessing. Do not include any real customer data. Output is a draft for human review.

Interplay with adjacent frameworks

Three adjacent frameworks are essential to operate this Act in a financial services environment. The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) (TAIC-LM-G02) regulate the collection, use, disclosure, and storage of customer information used in CDD and SMR processes; APP 3 (collection), APP 6 (use and disclosure), and APP 11 (security) carry specific operational consequences. APRA prudential standard CPS 230 Operational Risk Management (TAIC-LM-G05) requires regulated entities to identify AML/CTF reporting and sanctions screening as critical operations and to set tolerance levels for disruption. The Charter of the United Nations Act 1945 (Cth) and the Autonomous Sanctions Act 2011 (Cth) impose a parallel sanctions screening regime against the DFAT Consolidated List that sits beside the AML/CTF Act and is enforced by DFAT, not AUSTRAC. ASIC market integrity rules interact at the trading and surveillance layer.

In practice, AML/CTF Compliance must operate as a node in a wider control mesh, not a stand-alone function. The largest enforcement outcomes have arisen where the AML node was structurally disconnected from product, technology, and risk reporting paths.

Core Concepts and Defined Terms

Diagram tracing a section 6 designated service trigger through customer due diligence, enhanced due diligence, and reporting obligations, all supported by the ML/TF risk assessment and AML/CTF policies
Every obligation starts at section 6. The designated service trigger feeds CDD, ECDD, and reporting, underpinned by the risk assessment and policies.

Defined terms

TermDefinition
Reporting entityA person who provides a designated service. Defined in s5 of the Act and identified by reference to s6.
Designated serviceA service listed in s6 of the Act and the AML/CTF Rules. Each line item carries its own customer scope and trigger.
Reporting groupA group structure that replaced designated business groups from 31 March 2026. A lead entity may maintain group-wide AML/CTF policies and members may share compliance functions, but each member remains accountable for its own obligations.
Customer due diligence (CDD)The process of identifying and verifying a customer, beneficial owner, and PEP status. Combines initial CDD before the designated service is provided and ongoing CDD across the life of the relationship.
Enhanced customer due diligence (ECDD)Additional measures triggered by high-risk indicators, such as foreign PEP status, complex ownership, high-risk jurisdictions, or unusual patterns. Required under the Act as amended and the AML/CTF Rules 2025.
Suspicious Matter Report (SMR)A report under s41 of the Act when a reporting entity forms a suspicion on reasonable grounds. Filed with AUSTRAC.
Threshold Transaction Report (TTR)A report under s43 for cash or e-currency transactions of $10,000 AUD or foreign currency equivalent.
International Funds Transfer Instruction (IFTI)A report under s45 for funds transfer instructions sent or received internationally.
Tipping offAn offence under s123, reformed from 31 March 2025: disclosing SMR-related information where the disclosure would, or could reasonably be expected to, prejudice an investigation.
AML/CTF program (risk assessment plus policies)Since 31 March 2026, a documented ML/TF risk assessment together with AML/CTF policies covering the procedures, systems, and controls that manage and mitigate the risks identified. This structure replaced the former Part A and Part B program.
Politically exposed person (PEP)A person who holds, or has held, a prominent public position, defined across foreign, domestic, and international organisation categories under the AML/CTF Rules.

Central obligations

Designated service trigger

Obligations attach to the act of providing a designated service. Identification of which Item in s6 applies, and to what type of customer, is the first decision in any control design. Onboarding flows must be wired to the Item, not just to the product code; the same product can fall under different Items depending on customer type, channel, or jurisdiction.

Customer due diligence and ongoing CDD

Initial CDD must be carried out before the designated service is provided to a new customer, and ongoing CDD applies throughout the relationship. Identity must be verified using reliable and independent documentation or electronic data sources, and beneficial owners, being the individuals who ultimately own 25 per cent or more of the customer or exercise effective control, must be identified and verified. Under the reformed framework the detailed CDD requirements sit in the Act as amended and the AML/CTF Rules 2025. The former stand-alone Part B ACIP document is gone, but the entity's AML/CTF policies must still record how identification and verification are performed. Ongoing CDD includes transaction monitoring, periodic reviews, and event-driven reviews on red flags.

Enhanced due diligence triggers

ECDD is mandatory where the customer or transaction is rated as higher-risk, where a PEP relationship is identified, where a correspondent banking relationship is established, where the customer is in or transacting with a high-risk jurisdiction, or where the entity forms a suspicion. Senior management approval is required before a foreign PEP relationship is established or continued. The ECDD measures must be documented and proportionate to the risk, consistent with the AML/CTF Rules 2025.

Reporting obligations

SMRs are filed under s41 when a suspicion forms on reasonable grounds. The deadline is 24 hours for any matter that raises a suspicion of terrorism financing and 3 business days for all other suspicions. TTRs under s43 apply to transfers of physical currency of $10,000 or more, and IFTIs under s45 apply to international funds transfer instructions; both follow a 10 business day rule. All reports are filed through AUSTRAC Online and must contain the customer, transaction, and reasoning fields. The tipping off offence in s123 was reformed with effect from 31 March 2025: it now prohibits disclosing SMR-related information where the disclosure would, or could reasonably be expected to, prejudice an investigation, with a maximum penalty of two years imprisonment, 120 penalty units, or both. Disclosures for legitimate purposes, such as obtaining legal advice from an external lawyer, are permitted.

AML/CTF program design

Since 31 March 2026 the Act requires every reporting entity to document an ML/TF risk assessment and to maintain AML/CTF policies. The risk assessment must consider the entity's customer types, designated services, delivery channels, and the foreign jurisdictions it deals with, and must be kept up to date against defined review triggers. The AML/CTF policies are the enterprise-wide policies, procedures, systems, and controls that manage and mitigate the risks identified, proportionate to the nature, size, and complexity of the business. They must cover customer due diligence, transaction monitoring, reporting, employee due diligence and training, governance oversight, the AML/CTF compliance officer role, and independent evaluation. The governing body must approve both artefacts. This structure replaced the former Part A and Part B program required under the pre-reform Act.

Reporting groups

Reporting groups replaced designated business groups from 31 March 2026. A reporting group may nominate a lead entity that maintains group-wide AML/CTF policies, and members may share functions such as ongoing customer due diligence. Sharing the performance of a function does not transfer accountability: each reporting entity remains responsible for the obligations attaching to the designated services it provides and must evidence oversight of shared arrangements through assurance and escalation.

Sanctions screening interplay

Sanctions screening operates against the DFAT Consolidated List under a separate statute. AML/CTF systems generally house the screening engine because of overlapping data flows, but the legal authority and the obligation set are different. DFAT, not AUSTRAC, takes enforcement action for sanctions breaches. Many enforcement matters surface a hybrid AML/sanctions failure pattern.

Practical Application in Australian Financial Services

Five step flow from trigger event to the reasonable suspicion test, then the 24 hour or 3 business day SMR branch, lodgement through AUSTRAC Online, and tipping off controls
Alert to SMR: the reasonable suspicion test splits the clock, 24 hours for terrorism financing and 3 business days for everything else.

The next four worked examples translate the obligation set into operational artefacts. Each uses de-identified scenarios with merge field placeholders. No real customer data.

Example 1: Authorised Deposit-taking Institution (ADI)

Trigger event: A new business banking customer (Customer A, an Australian-incorporated private company with a parent in a high-risk jurisdiction) opens a transaction account and immediately receives a series of structured deposits totalling $148,000 over four business days.

Obligation activated: the relevant account-based designated service Item under s6. Section 41 triggers an SMR if a reasonable suspicion arises that the structured deposits may constitute structuring (a Division 400 Criminal Code offence). Section 43 triggers a TTR for any single deposit at or above the $10,000 threshold.

Artefact produced: A draft SMR narrative populated with Customer A's identifiers, the deposit pattern, the analyst's reasoning, and the attached transaction monitoring alert ID. A TTR record is generated automatically through the core banking system. The entity's AML/CTF policies trigger an ECDD review of beneficial ownership given the foreign parent.

Audit trail expected: Transaction monitoring alert metadata, analyst reasoning notes, supervisor approval, AUSTRAC submission receipt, ECDD case file, and the link back to the customer's ongoing CDD record. The artefact must be retained for seven years under s107 of the Act.

Example 2: General insurer

Trigger event: A new commercial property policy is issued to Customer B, a single-purpose entity. The premium is paid in cash by a third party at the broker's office and the insured property is in a regional area with limited recent claims activity.

Obligation activated: the relevant general insurance designated service Item under s6 is engaged for some general insurance products through specified channels. The cash premium triggers a TTR. The third-party payer triggers an ECDD enquiry into the source of funds and the relationship between the payer and the insured.

Artefact produced: An ECDD case file summarising the source-of-funds enquiry, third-party payer rationale, and approval trail. A TTR. Where suspicion crystallises, an SMR. The broker is reminded of its own AML/CTF obligations under any joint program arrangement.

Audit trail expected: The case file must show what was asked, what was answered, what evidence was sighted, and who approved continuation of the policy.

Example 3: Superannuation trustee

Trigger event: A member (Customer C) requests an early release of superannuation under compassionate grounds and provides supporting documentation that, on review, contains internal inconsistencies (different signatures, a recent address change, and a beneficiary nomination change in the prior month).

Obligation activated: the relevant superannuation designated service Item under s6 is engaged. ECDD triggers because of indicia consistent with elder abuse, identity-takeover fraud, or laundering of stolen funds. SMR consideration is mandatory.

Artefact produced: An ECDD memorandum, a fraud and abuse referral to the trustee's vulnerability framework, an SMR if the suspicion is reasonably held, and a hold on payment. Member-facing communication must be drafted carefully to avoid breaching s123 (tipping off).

Audit trail expected: Documented reasoning, version history of member communications, evidence of the fraud and abuse referral, AUSTRAC submission receipt, and a clear link to ongoing CDD updates.

Example 4: AFSL holder (managed investment scheme operator)

Trigger event: A wholesale investor (Customer D) subscribes to a unit trust through an Australian Financial Services Licence (AFSL) holder. The subscription is funded from a foreign jurisdiction with which Australia has a high-risk advisory in place. The investor's beneficial owners include a foreign PEP.

Obligation activated: the relevant managed investment scheme and securities designated service Items under s6. ECDD applies due to foreign PEP and high-risk jurisdiction. The entity's AML/CTF policies require senior management approval to enter or continue the relationship.

Artefact produced: An ECDD pack including beneficial ownership chart, source-of-wealth and source-of-funds evidence, screening results against the DFAT Consolidated List, foreign PEP risk acceptance memorandum signed by the senior manager, and ongoing monitoring profile.

Audit trail expected: Approval trail, screening match metadata, ongoing monitoring frequency, and a control linkage to FAR-accountable Senior Managers under the Financial Accountability Regime.

Visual Pack

The six visuals below are inline within the regulatory, conceptual, application, and AI workflow sections. Each is rendered as a designer-ready specification that a learning experience designer can take into Lucidchart, Whimsical, or Figma without further interpretation.

Visual 1: Regulatory authority map

Specification for a jurisdictional flowchart. Eight nodes, three layers, top-down vertical orientation.

LayerNodeFunction and connection
Statute layerAML/CTF Act 2006 (Cth)Source authority. Connects down to AUSTRAC and to the AML/CTF Rules.
Statute layerAML/CTF Rules 2025Binding rules under s229. Connects down to AUSTRAC.
Regulator layerAUSTRAC (regulator and FIU)Receives reports, regulates, and shares intelligence. Connects laterally to ASIC, APRA, ATO, and AFP.
Regulator layerDFATSanctions enforcement. Sits beside AUSTRAC, not under it.
Regulator layerFATF (international)Sets standards. Connects to AUSTRAC and Treasury.
Entity layerReporting entity (financial sector)Receives obligations from AUSTRAC. Connects to reporting group nodes.
Entity layerReporting entity (Tranche 2 from 1 July 2026)New cohort: lawyers, accountants, real estate, precious metals dealers.
Entity layerCustomerEnd point. Subject to CDD, ECDD, and ongoing monitoring.

Visual 2: SMR decision tree

Specification for a process diagram with a single entry point and four terminal states. Render as Mermaid flowchart for the designer.

flowchart TD

A[Trigger event: alert, transaction, customer behaviour, employee tip] --> B{Reasonable suspicion?}

B -- No --> C[Document and close. Update monitoring rules.]

B -- Yes, terrorism financing indicia --> D[Lodge SMR within 24 hours under s41]

B -- Yes, other AML indicia --> E[Lodge SMR within 3 business days under s41]

D --> F[Apply tipping off controls under s123]

E --> F

F --> G[Update transaction monitoring scenarios and customer risk rating]

Visual 3: Comparative table (AML/CTF Act vs FATF vs EU 6AMLD)

DimensionAML/CTF Act 2006 (Cth)FATF 40 RecommendationsEU 6AMLD
IssuerCommonwealth of AustraliaFATF inter-governmental bodyEuropean Union (Directive 2018/1673)
Binding forceStatute and Rules under s229Soft law, evaluated through Mutual Evaluation ReportsDirective transposed by member states
Designated service modelItemised list in s6Risk-based, sectoral focusDefined obliged entities in Articles 2 to 4
Customer due diligenceMandatory initial CDD plus ongoing CDD plus ECDD triggersRisk-based CDD, ECDD for high-risk customersRisk-based, harmonised standards
Beneficial ownershipRequired under the Act and the AML/CTF Rules 2025Recommendation 24 and 25Mandatory central registers
SMR equivalentSMR under s41, 24 hours / 3 business daysRecommendation 20 STR obligationSuspicious Activity Report
Tipping offOffence under s123Recommendation 21Member state offence
Penalty ceiling (illustrative)Civil penalty calculated by reference to penalty units under the Crimes Act 1914 (Cth); per-contravention exposure for a body corporate is in the tens of millions of dollars and aggregate exposure across systemic matters has exceeded $1 billion in landmark settlementsNo direct penalty (peer review)Up to 10% of group turnover (criminal cases up to 4 years imprisonment)
Tranche 2 statusLive from 1 July 2026Already in scope (Designated Non-Financial Businesses)Already in scope

Visual 4: AML/CTF RACI

ActivityBoardAML/CTF Compliance OfficerSenior Manager (FAR-accountable)First Line
Approve ML/TF risk assessment and AML/CTF policiesARCI
Maintain ML/TF risk assessmentIRCC
Lodge SMR under s41IACR
Lodge TTR or IFTIIAIR
Sign foreign PEP relationship approvalICA/RI
Independent reviewACII
Tranche 2 readinessARCC
Sanctions screening governanceICA/RR

RACI key: R = Responsible, A = Accountable, C = Consulted, I = Informed.

Visual 5: Quantitative chart (illustrative)

Specification for a bar and line combination chart. X axis: financial year (FY22 to FY26). Y axis (left): AUSTRAC enforcement action volume (count). Y axis (right): aggregate civil penalty exposure ($m, illustrative). All figures must be labelled "illustrative" in the rendered visual.

Financial yearEnforcement actions (illustrative count)Civil penalties imposed ($m, illustrative)Headline driver theme
FY2231,300Programme failure, large reporting backlog
FY235350Customer identification and ongoing CDD failures
FY2471,800Cross-border transaction reporting and IFTI
FY259950Programme governance and Senior Manager accountability
FY26 (YTD)6600Tranche 2 readiness and sanctions screening interplay

Numbers in this table are illustrative only. They are not drawn from AUSTRAC enforcement data.

Visual 6: Five things to remember

The Five Things to Remember 1. Section 6 designated services are the gateway. If you cannot identify the Item, you cannot design the control. 2. SMR timing is non-negotiable: 24 hours for terrorism financing suspicion, 3 business days for everything else. 3. ECDD is the highest-leverage control. Foreign PEPs, complex ownership, and high-risk jurisdictions all trigger it. 4. Tipping off (s123) is a separate offence. Member-facing communication must be sanitised at source. 5. Tranche 2 commences 1 July 2026. The build window is now.

Operating the AML/CTF Framework With AI

A glowing zero surrounded by orbiting labels for pseudonyms, placeholders, human review, and tenant logging, representing the de-identification rule for AI prompts in AML/CTF work
The non-negotiable number in AI-assisted AML/CTF work: zero real customer identifiers ever enter a model prompt.

This section explains how to run the AML/CTF Act day to day with large language model support (Claude or ChatGPT, Enterprise tier) without ceding judgement, leaking customer data, or creating an audit-trail vacuum.

Use cases at scale

  1. Drafting SMR narratives from de-identified case data: analyst supplies structured indicators, model assembles the narrative.
  2. Mapping s6 designated service Items against a product catalogue to surface onboarding control gaps.
  3. Programme gap analysis: comparing the ML/TF risk assessment and AML/CTF policies against AUSTRAC guidance and flagging missing components.
  4. Control narrative drafting for new product approvals from a controls library.
  5. Board paper distillation: producing a 250 word executive summary from a 30 page program update.
  6. Regulator response triage: drafting first-pass replies to AUSTRAC RFIs ready for legal and senior manager review.
  7. Typology synthesis: pulling AUSTRAC bulletins and FATF reports into a single internal briefing.
  8. Tranche 2 readiness: comparing capability against new obligations and producing a remediation roadmap.

Project space setup

Claude Project

Step 1. In Claude.ai, create a Project "AUSTRAC AML CTF Workspace" on Enterprise or Team. Step 2. Upload knowledge sources: redacted ML/TF risk assessment and AML/CTF policies, AML/CTF Act 2006 (Cth) consolidated text, AML/CTF Rules 2025, AUSTRAC compliance guide, FATF 40 Recommendations, and a controls library extract. Step 3. Set the system prompt: "You are an AML/CTF compliance analyst for an Australian reporting entity. You operate under the AML/CTF Act 2006 (Cth), the AML/CTF Rules, AUSTRAC guidance, and FATF Recommendations. You never reproduce real customer identifiers. You always flag tipping off risk under s123. You always cite section, rule, or guidance for every conclusion. You produce drafts for human review." Step 4. Naming: TAIC-{entity}-{type}-{YYYYMMDD}-{version}. Step 5. Configure a Skill "smr-narrative" codifying the narrative template and validation rules.

ChatGPT Project or Custom GPT

Step 1. Create a Project (Plus, Team, or Enterprise) "AUSTRAC AML CTF Workspace". Step 2. Upload the same knowledge sources. Step 3. Use the same system prompt scaffold. Step 4. For Custom GPT, set Capabilities to file search only and disable web browsing for sensitive workflows. Step 5. On Enterprise, confirm no-training at workspace level and identity-provider integration with Microsoft 365 or Google Workspace. Step 6. Naming convention is identical.

Prompt library

The six prompt patterns below cover the recurring artefacts. Start with the one you will use most this week: drafting an SMR narrative from de-identified case data. De-identify every input first, pseudonyms and placeholders only, with the identity link held outside the model.

Prompt
Role: AML/CTF analyst for an Australian reporting entity drafting a suspicious matter report narrative for human review.
Context: case [CASE_ID]. Customer pseudonym [CUSTOMER_PSEUDONYM]. Structured indicators:
- Account type and opening date: [ACCOUNT_TYPE], [DATE]
- Alert trigger: [ALERT_DESCRIPTION, e.g. structured cash deposits below $10,000 across multiple branches]
- Transaction pattern: [AMOUNTS, DATES, CHANNELS]
- Customer behaviour: [BEHAVIOUR, e.g. repeated questions about reporting thresholds]
- Prior history: [PRIOR_ALERTS_OR_REPORTS, summarised]
Task: Draft the SMR narrative covering who, what, when, where, how, and why the suspicion is held on reasonable grounds, in the order AUSTRAC Online expects.
Constraints: use only the indicators supplied; do not invent facts. No real names, account numbers, or dates of birth. Plain English, Australian spelling, past tense, no speculation beyond the grounds stated. Flag any gap in the indicator set as [ANALYST TO CONFIRM].
Quality bar: a reviewer must be able to trace every sentence back to a supplied indicator. The draft is not lodged until a human analyst and supervisor have reviewed and approved it.

Prompt 1: Obligation mapping

Role: AML/CTF analyst. Context: an Australian {{ENTITY_TYPE}} is launching {{PRODUCT}}. Task: Map the product to the designated services Items in s6 of the AML/CTF Act and identify the obligations triggered. Constraints: cite section and Rules reference. Do not include any real customer data. Output Format: a table with columns Item, Service description, Customer scope, Obligations triggered, Open questions. Quality Bar: every Item must have an explicit citation. Any obligation flagged must reference the underlying section or Rule. Open questions must be specific.

Prompt 2: Control narrative drafting

Role: AML/CTF control owner. Context: control identifier {{CONTROL_ID}} sits in the {{DOMAIN}} pillar of the entity's AML/CTF policies. Task: Draft a control narrative covering objective, design, performance, evidence, and key risk indicator. Constraints: 350 to 450 words. No customer identifiers. Reference the relevant section of the Act or Rules and any AUSTRAC guidance. Output Format: structured headings as listed. Quality Bar: each section must contain at least one specific evidence artefact reference and one named owner role.

Prompt 3: Gap or maturity assessment

Role: AML/CTF program reviewer. Context: the entity's current ML/TF risk assessment and AML/CTF policies are uploaded. Task: Compare them against AUSTRAC compliance guide expectations and FATF Recommendations 9 to 23. Constraints: produce a maturity rating (1 to 5) per pillar and a remediation pack. Output Format: pillar table plus a remediation roadmap with priority, owner, due date placeholder. Quality Bar: every gap finding must cite the source. No score may be awarded without supporting evidence.

Prompt 4: Board paper executive summary

Role: AML/CTF Compliance Officer drafting for a Risk Committee. Context: the attached program update runs to 30 pages and covers risk, controls, incidents, and Tranche 2 readiness. Task: Produce a 250 word executive summary plus three recommendations. Constraints: plain English. Australian spelling. Cite all materially negative findings. Output Format: heading, summary, three numbered recommendations with named accountable owner. Quality Bar: every recommendation must be SMART and traceable to the underlying program finding.

Prompt 5: Regulator response drafting

Role: AML/CTF Compliance Officer drafting a response to an AUSTRAC notice. Context: the notice requests information on {{TOPIC}}. Task: Draft a first-pass response. Constraints: cite the request, the controlling Act provisions, and any prior correspondence. No customer-level data. Output Format: response letter with section headings matching the regulator's questions. Quality Bar: every paragraph supports a named claim. No speculative content. Marked DRAFT FOR LEGAL REVIEW.

Prompt 6: Self-disclosure drafting

Role: AML/CTF Compliance Officer. Context: an internal control failure may amount to a contravention. Task: Draft a self-disclosure letter to AUSTRAC. Constraints: facts only, no legal opinion. Reference timeline, customer impact, remediation, and root cause status. Output Format: letter with annexed timeline. Quality Bar: every fact sourced from the internal investigation file.

Governance, audit, privacy, and risk appetite controls

De-identification is mandatory. Real customer identifiers (name, customer number, account number, date of birth, address) must never be entered into a model prompt. Use stable pseudonyms and merge field placeholders. Where the analyst needs the link from pseudonym to underlying customer, that link is held outside the model context.

Human-in-the-loop checkpoints apply at every output stage. No SMR, regulator response, or board paper is filed or sent without a documented human review and senior manager sign-off. The model output is the draft, not the artefact.

Prohibited inputs include PII, market sensitive data, sanctions intelligence (DFAT-restricted material), claimant medical or financial vulnerability data, and any information protected by tipping off restrictions under s123. If a workflow requires this content, escalate to a controlled environment under the entity's data classification policy.

Retention and logging: every model interaction relevant to AML/CTF activity is logged through the Enterprise tenant logging facility, retained in line with the seven-year obligation in Part 10 of the Act (s107 and related), and made available to internal audit on request. Model selection: Enterprise SaaS with no-training is the standard; on-prem or private cloud is required where the workflow handles customer-level data; public consumer-tier is prohibited.

CPS 230: AML/CTF reporting is generally a critical operation for an APRA-regulated entity. The model workflow must therefore have a documented service provider risk assessment, a disruption tolerance, and an evidenced operational resilience test that includes failover to a non-AI workflow. APP alignment: APP 3, APP 6, and APP 11 drive the prompt hygiene rules above; APP 1 governs disclosure of AI assistance to customers where appropriate.

Quality assurance loop

The tipping off check in the rubric below deserves its own tool. Run every customer-facing draft connected to a live matter through this scan before it leaves the team.

Prompt
Role: AML/CTF reviewer testing a draft communication against the tipping off offence in s123 of the AML/CTF Act 2006 (Cth), as reformed from 31 March 2025.
Context: the draft below will be sent to [AUDIENCE, e.g. the customer, their representative, a branch team].
Draft: [PASTE DRAFT TEXT, DE-IDENTIFIED]
Task:
1. Identify every word or phrase that could disclose, or allow the reader to infer, that a suspicious matter report exists or that an investigation may be on foot.
2. For each, explain how the disclosure could reasonably be expected to prejudice an investigation.
3. Rewrite the draft so it remains accurate and courteous without carrying that risk.
4. Give a final verdict: SEND, REDRAFT, or ESCALATE TO AML BEFORE SENDING.
Constraints: err on the side of ESCALATE. Do not add explanations of the AML process to the customer text. Output the marked-up findings first, then the clean rewrite.

Run this five-step QA rubric against every AI output before it leaves the analyst's desk.

  1. Source check. Every factual claim has a citable source. Every section or rule reference is correct.
  2. Privacy check. No real customer identifiers, no third-party PII, no sanctions intelligence.
  3. Tipping off check. No language that could disclose the existence of an SMR or a related investigation.
  4. Material accuracy check. The output's central conclusion would survive an internal audit interview.
  5. Evidence check. The output is annotated with the supporting evidence artefacts and would stand up at an AUSTRAC enforcement interview.

Red team prompt

Red team prompt to stress-test your own draft: "You are an AUSTRAC investigator reviewing this output. Identify five reasons it could be non-compliant, evasive, or unsupported. Cite the section or guidance you are testing against. Score 1 to 10 on credibility. Recommend the smallest edits that would lift the score by 3 points."

Scaling pattern

Operationalise across the team as follows. First, codify each prompt as a versioned template in the project space (v1.0, v1.1) with a change log. Second, run a weekly evaluation cadence sampling outputs against the QA rubric. Third, set KRIs: percentage of outputs failing the source check, percentage failing the privacy check, percentage requiring three or more revisions before sign-off. Fourth, treat each model release as a change event: re-run the evaluation set and only promote at parity or better with a rollback path. Fifth, maintain a register of accepted and rejected use cases with rationale and review date.

Common Pitfalls and Watch-outs

Six common failure modes recur in AML/CTF supervision and enforcement outcomes. Each is followed by a one-line corrective action.

  1. Treating the program as a static document rather than a living system. Corrective action: bind the program to the risk assessment, review at every material change, and date-stamp every revision.
  2. Confusing legal coverage with operational coverage. Corrective action: trace every Item in s6 from product approval to onboarding, monitoring, and reporting.
  3. Late SMR lodgement on terrorism financing matters. Corrective action: build a hard 24-hour SLA into the case management workflow with auto-escalation.
  4. Outsourcing transaction monitoring without retaining accountability. Corrective action: maintain a Senior Manager owner under FAR with documented service provider risk and a quarterly assurance pack.
  5. Over-reliance on screening engines without periodic recalibration. Corrective action: document the calibration cycle, false positive rate, and the threshold change governance.
  6. Tipping off through customer service scripts. Corrective action: require AML approval of any customer-facing communication where an investigation is in flight.
  7. Misclassifying virtual asset or cross-border services. Corrective action: re-walk s6 designations whenever a product, channel, or jurisdiction changes.

Decision Frameworks and Tools

Large numeral reading 24 hours inside a thin ring of light, marking the statutory deadline for terrorism financing suspicious matter reports under section 41
24 hours is the section 41 deadline for a terrorism financing SMR. Every other suspicion gets 3 business days.

Decision tree: Should I lodge an SMR?

Render as Mermaid for the designer.

flowchart TD

Q1[Has an alert, behaviour, or transaction triggered enquiry?] -- No --> Close[Document and close]

Q1 -- Yes --> Q2[Is the suspicion held on reasonable grounds?]

Q2 -- No --> Investigate[Investigate further. Document.]

Q2 -- Yes --> Q3{Indicia of terrorism financing?}

Q3 -- Yes --> SMR24[Lodge SMR within 24 hours under s41]

Q3 -- No --> SMR3[Lodge SMR within 3 business days under s41]

SMR24 --> S123[Apply tipping off controls under s123]

SMR3 --> S123

Maturity ladder for an AML/CTF program

Use this prompt with the ladder below to locate your program and draft the uplift case.

Prompt
Role: AML/CTF program reviewer.
Context: I will describe our current AML/CTF arrangements: [SUMMARISE: risk assessment date and coverage, policies scope, monitoring approach, reporting volumes, governance cadence, independent evaluation date, Tranche 2 or reporting group exposure]. No customer data is included.
Task:
1. Rate the program against a five-tier maturity ladder (Initial, Repeatable, Defined, Managed, Optimised) with a one-paragraph justification per dimension: risk assessment, CDD and ECDD, monitoring and reporting, governance and accountability, AI and automation governance.
2. Identify the two lowest-scoring dimensions and draft an uplift plan for each: actions, owner role, evidence artefact, and a realistic timeframe.
3. Write a 150 word summary a Risk Committee chair could read aloud.
Constraints: justify every rating with evidence from my description; where evidence is missing, score conservatively and say why. Australian regulatory context throughout. Draft for human review.
TierLabelIndicators
1InitialProgram exists on paper. Risk assessment is generic. Reporting volumes are low and unexplained.
2RepeatableProgramme is reviewed annually. Risk assessment maps to s6 Items. Some Senior Manager visibility.
3DefinedRisk-based design across CDD, ECDD, monitoring, and reporting. FAR accountability mapped. Independent review every two years.
4ManagedQuantitative KRIs feed Risk Committee. Sanctions and AML controls are integrated. Tranche 2 readiness in flight.
5OptimisedAI-enabled drafting and analytics with human-in-the-loop. Real-time monitoring. Continuous improvement and AUSTRAC engagement.

Self-check questionnaire

  1. Can I produce a current, dated, and governing body approved ML/TF risk assessment and AML/CTF policies in under 30 minutes?
  2. Can I trace any product or service in my entity to a specific Item in s6 of the Act?
  3. Have I lodged an SMR in the past 12 months and can I evidence the reasoning behind the decision?
  4. Has the program been independently reviewed within the last two to three years?
  5. Have I run a Tranche 2 readiness assessment if my entity, or its clients, are in scope from 1 July 2026?
  6. Is my AML/CTF AI workflow logged, governed, and consistent with APP 3, APP 6, and APP 11?
  7. Can my Senior Manager (FAR-accountable) speak to the entity's AML risk profile in their own words?

Further Reading and Authoritative Sources

Primary statute and rules

  • Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).
  • Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (current compilation).
  • Charter of the United Nations Act 1945 (Cth) and Autonomous Sanctions Act 2011 (Cth) (sanctions regime).
  • Criminal Code Act 1995 (Cth) Division 400 (money laundering offences) and Division 102 (terrorist organisation offences).

Regulator and government publications

  • AUSTRAC, AML/CTF Compliance Guide (current edition).
  • AUSTRAC, Suspicious Matter Reports: A Guide for Reporting Entities.
  • AUSTRAC, Reporting Groups Guidance.
  • Attorney-General's Department, Tranche 2 Reform package and explanatory materials.
  • APRA, CPS 230 Operational Risk Management.
  • ASIC, Information Sheet 225 Digital Assets: Financial Products and Services.

International standards

  • FATF, International Standards on Combating Money Laundering and the Financing of Terrorism and Proliferation (the 40 Recommendations).
  • FATF, Mutual Evaluation Report Australia (most recent edition).
  • Wolfsberg Group, Anti-Money Laundering Principles for Correspondent Banking.

Professional bodies

  • Association of Certified Anti-Money Laundering Specialists (ACAMS) Australasia chapter resources.
  • Governance Institute of Australia, Risk and Compliance Practice resources.
  • Risk Management Institution of Australasia (RMIA), AML risk papers.

Closing

This module is one of the foundation modules in TheAICommand learning library for Australian financial services governance, risk, and compliance. It pairs with the AML/CTF assessment (TAIC-LM-G03-AMLCTFAct-Assessment) and with the cross-referenced modules listed on the cover.

Practical takeaways

Do this Monday

  1. Pull your current program artefacts and check the labels. If the documents still say Part A and Part B, schedule the conversion to a documented ML/TF risk assessment and AML/CTF policies; the reformed structure has applied since 31 March 2026.
  2. Trace one product from its s6 designated service Item through onboarding, monitoring, and reporting. If you cannot name the Item, neither can your controls.
  3. Test your SMR clock. Ask the team what happens when terrorism financing indicia appear at 4pm on a Friday; the 24 hour deadline under s41 is measured in hours, not business days.
  4. Review one recent customer-facing communication connected to an investigation against the reformed s123 test: could the wording reasonably be expected to prejudice an investigation?
  5. If your corporate group shares compliance functions, confirm the reporting group arrangement is documented and that each member can evidence its own accountability.

The compliance checklist

  • Current, dated ML/TF risk assessment approved by the governing body, covering customer types, designated services, delivery channels, and foreign jurisdictions.
  • AML/CTF policies proportionate to the nature, size, and complexity of the business, with a named AML/CTF compliance officer.
  • Every product and service mapped to its designated service Item in s6, re-walked whenever a product, channel, or jurisdiction changes.
  • Initial CDD completed before any designated service is provided; ongoing CDD, periodic reviews, and event-driven reviews evidenced.
  • ECDD triggers documented, with senior management approval on file for every foreign PEP relationship.
  • SMR workflow with a hard 24 hour escalation path for terrorism financing suspicions and 3 business days for all others.
  • TTR and IFTI reporting reconciled against source systems, with the 10 business day deadlines monitored.
  • Customer-facing scripts and template letters cleared against the reformed s123 tipping off test.
  • Records retained for seven years under Part 10 of the Act, including logs of any AI-assisted drafting.
  • Independent evaluation scheduled, with findings tracked to closure and reported to the governing body.

Your prompt library

The four prompt boxes in this module cover the reform gap review, SMR narrative drafting, the tipping off language scan, and the maturity assessment, and the six prompt patterns in the AI section run from obligation mapping to self-disclosure. Save them into your project space as versioned templates. When you need a fast answer in a meeting, this one earns a place on a sticky note:

Prompt
You are an AML/CTF analyst for an Australian reporting entity. In under 150 words, tell me which reporting obligation applies and its deadline: [DESCRIBE THE TRANSACTION OR BEHAVIOUR, DE-IDENTIFIED]. Choose from SMR (s41: 24 hours for terrorism financing suspicion, 3 business days otherwise), TTR (s43: physical currency of $10,000 or more, 10 business days), IFTI (s45: 10 business days), or no report. Cite the section, state the deadline, and flag any tipping off risk under s123 in what I say to the customer. If facts are missing, ask for them instead of guessing.

Test your knowledge

LM-G03 assessment. 30 questions

25-30 minutes. One question per screen. Your progress is saved locally for 30 days, so you can pick up where you left off. Submit anytime to see your score, tier, and per-question rationale.

Loading assessment…

General information and education only. Not legal, compliance, financial, or professional advice. Verify any time-sensitive obligation against the primary source.

TheAICommand. Intelligence, At Your Command.