Equilex
Back to News

AFSL Holders: Get Ready for Significant Changes in AML/CTF Compliance by 2026

AFSL holders face stricter AML/CTF rules by March 31, 2026. Reforms require a single risk-based program, expanded risk assessments (including proliferation financing), stronger governance, and updated training—making compliance an ongoing priority.

March 27, 2026
4 min read
AFSL Holders: Get Ready for Significant Changes in AML/CTF Compliance by 2026

The countdown has begun. While "Tranche 2" businesses—lawyers, accountants, and real estate agents—receive the majority of media attention surrounding Australia's anti-money laundering and counter-terrorism financing (AML/CTF) reforms, a seismic shift for current reporting companies is also imminent.

March 31, 2026, is more than just a date on the calendar for Australian Financial Services Licence (AFSL) holders who are already subject to AUSTRAC regulation. It signifies the start of an updated, stricter regulatory system. The days of "set and forget" compliant AML programs are long gone. "Is the business ready for the AML/CTF changes?" is currently the most crucial question.

#
The Status Quo's End

The AML/CTF Amendment Act 2024 and its accompanying regulations bring about modifications intended to streamline the system while raising its efficacy burden. The legislative change that eliminates the distinction between Part A and Part B of the AML/CTF Program is important for current reporting entities.

The divided structure vanishes on March 31, 2026. Reporting organizations must replace it with a single, results-driven AML/CTF Program. This is a basic requirement for a program that clearly connects risk assessments to controls, not an administrative exercise in document merging. The current program will probably fall short of the new requirements if it is kept on a shelf and only examined by an impartial third party.

#The Evaluation of Dynamic Business Risk

The Business Risk Assessment is the central component of the reforms. The Risk Assessment becomes a dynamic, living part of the governance framework under the new regime, rather than a static document.

Most importantly, the range of danger has increased. Along with money laundering (ML) and terrorism financing (TF), entities are also required to specifically identify, evaluate, and manage risks associated with proliferation financing (PF).

Customers, jurisdictions, and distribution channels must all be thoroughly examined. Does the existing risk approach take into consideration the financing of weapons of mass destruction or the evasion of sanctions? If the response is "no," the gap analysis needs to start right away.

#Governance: The Standard of "Reasonable Steps"

The responsibility to take "reasonable steps" to guarantee compliance is placed firmly on top management and governing bodies by the amendments. It is no longer sufficient for a Board to merely mention the AML/CTF Program in meeting minutes.

Active oversight is now required of senior management. This entails being aware of the particular ML/TF/PF threats the company confronts and making sure the AML/CTF Program has the resources and efficacy to reduce them. The selection of the AML/CTF Officer is also scrutinized; this person must be "fit and proper" and possess adequate autonomy and power. The governance structure might not be in compliance if the AML Officer is positioned three levels below the board and has no direct access to it.

#The Designated Business Groups' Disintegration

Replacing Designated Business Groups (DBGs) with Reporting Groups is a practical but crucial operational shift. On March 31, 2026, current DBGs will expire.

This rollover is not automated. The new regulations require corporate groupings that depend on pooled compliance resources to proactively create a Reporting Group. This calls for a formal agreement and the identification of a lead organization in charge of the group's AML/CTF compliance. Individual entities within a group may become legally vulnerable and technically non-compliant if a formal transition is not made.

#Culture and Training

New definitions and responsibilities accompany new regulations. It is necessary to identify and properly train every employee working in AML/CTF. Programs for staff training that were created years ago will become outdated.

For instance, as of March 2025, the "tipping off" provisions have already changed, and the new Customer Due Diligence (CDD) standards necessitate updated operational expertise, especially with regard to value transfers and the "Travel Rule."

Now is the time to design a training plan for 2026. It should guarantee that every employee, including frontline employees, compliance teams, and the Board, is aware of both the new Act's mechanics and the cultural shift toward proactive risk management that AUSTRAC mandates.

The Immediacy of Today

Now that 2026 has arrived, there is not much time left to assess these additional responsibilities. It's possible that the gap between the 2026 criteria and the existing frameworks will be greater than expected.

#AFSL holders should take the following immediate actions:

  • Gap Analysis: Examine the new requirements in relation to the existing AML/CTF Program.
  • Risk Assessment Review: Make sure the Risk Assessment represents current business reality by updating it to include recognized risks and Proliferation Financing.
  • Governance Check: Confirm the AML Officer's independence, official appointment, and fit and suitable status. Inform the Board of their increased liabilities.
  • DBG Transition: Arrange for the Reporting Group to replace the Designated Business Group.

The goal of the changes is to prevent illicit abuse of Australia's financial system. This indicates that the bar has been raised for AFSL holders. Compliance is now a fundamental license-to-operate requirement rather than just a box to be checked.

AFSL holders are receiving assistance from MIntegrity in managing this change. There is a set deadline. The responsibilities are obvious. Now is the moment to take action.

Need Help with Licensing?

If your business requires legal assistance in preparing for the upcoming AML/CTF reforms for AFSL holders, we invite you to complete the inquiry form on our website. Our team at Equilex will review your request, and one of our specialists will contact you within 24 hours to discuss the most suitable AML/CTF compliance, governance, and regulatory solutions for your business.

Related Services

Explore our services that can help you achieve your licensing goals.

Crypto licenses

AUSTRAC DCE in Australia

Crypto-regulated company to start business in Oceania.

BSP/DASP in El Salvador

The first country that legalized Bitcoin in 2021 under the Bitcoin Law, and it has since emerged as the hub of Latin America's cryptocurrency market.

MSB Registration in Canada

Multiglobal company to work with crypto, money remittance, and processing of payments.

VASP in Georgia

Georgian VASP is ideal for operational crypto businesses that want speed, flexibility, and reasonable compliance—without the cost and rigidity of EU-level regulation.

CASP in Malta

Your gateway to EU-wide crypto-asset services: a Malta-based MiCA authorisation lets you passport crypto-asset services to all 27 EU Member States without requiring a physical presence in each host state, leveraging Malta's experienced financial services ecosystem.

Payment & Fintech licenses

AFSL in Australia

An Australian Financial Services (AFS) license is a legal authorization for an individual or business to conduct financial services operations in Australia and is required for businesses that deal with, advise on, or manage financial products.

MSB in USA

A US Montana MSB registration is a FinCEN-registered money services business incorporated in Montana, commonly used by fintech, payment, remittance, and crypto companies seeking a streamlined US regulatory structure.

MSO in Hong Kong

A person or organization that runs a money exchange or remittance business is known as an MSO. As MSO suggests, the money-changing service involves changing several currencies.

PIS in Mauritius

Providing payment accounts or wallets, money remittance, PSP collating payments from cards and remittance to merchants.

SPI (MIP) in Poland

Fast-track Polish payment institution regime for PSPs that need regulated status to launch payment flows (transfers, cards, acquiring, remittance) without going straight into full EMI.

SRO regulated asset management company in Switzerland

A pragmatic Swiss AML-supervised setup for crypto/fiat payment and exchange, brokerage, and credit businesses via membership in a FINMA-authorized SRO.