Australia's overhaul of its anti-money laundering and counter-terrorism financing (AML/CTF) framework is no longer an approaching deadline — it is current law. While "Tranche 2" businesses (lawyers, accountants, real estate agents, and other newly captured sectors) drew most of the media attention, the reforms also reshaped the compliance obligations of Australian Financial Services Licence (AFSL) holders who are already subject to AUSTRAC regulation.
March 31, 2026 marked the start of a stricter regulatory regime for existing reporting entities. The days of a "set and forget" AML program are over. The relevant question for AFSL holders is no longer whether the business is ready for the changes — it's whether the business is actually compliant with them now.
The 2026 Reform Timeline
The reforms rolled out across several dates rather than a single cutover:
- March 31, 2026 — the core AML/CTF Amendment Act reforms commenced. Existing reporting entities, including AFSL holders already registered with AUSTRAC, moved to a single, risk-based AML/CTF program, and the former digital currency exchange (DCE) registration category was replaced by the broader virtual asset service provider (VASP) framework.
- July 1, 2026 — Tranche 2 obligations commenced, extending AML/CTF requirements to lawyers, conveyancers, accountants, real estate professionals, property developers, dealers in precious metals and stones, and trust and company service providers.
- July 29, 2026 — the enrolment deadline passed for Tranche 2 entities, and existing DCE registrants were required to have completed their transition to VASP status and updated their details with AUSTRAC by this date.
For a detailed breakdown of who must enrol with AUSTRAC, who must additionally register, and what changed for existing reporting entities, see our guide AUSTRAC Registration Requirements: Who Needs to Register in Australia in 2026.
The Old Structure Is Gone
The AML/CTF Amendment Act 2024 and its accompanying regulations streamlined the system while raising its compliance bar. The most significant change for existing reporting entities is the elimination of the split between Part A and Part B of the AML/CTF Program.
That divided structure ended on March 31, 2026. Reporting entities now operate under a single, results-driven AML/CTF Program — a substantive requirement that clearly connects risk assessments to controls, not an administrative exercise in merging two documents into one. A program that has simply been carried over from the old structure and reviewed only by an independent third party is unlikely to meet the current requirements.
Business Risk Assessment Is Now a Living Document
The Business Risk Assessment sits at the centre of the reforms. Under the current regime, the Risk Assessment functions as a dynamic, ongoing part of the governance framework rather than a static document reviewed once a year.
The scope of risk has also expanded. Alongside money laundering (ML) and terrorism financing (TF), entities must now specifically identify, assess, and manage risks connected to proliferation financing (PF).
Customer bases, jurisdictions, and distribution channels all need a thorough review against this wider scope. Does the current risk approach account for weapons-of-mass-destruction financing or sanctions evasion? If the answer is no, that is a compliance gap that already exists under current law, not a future risk to plan for.
Governance: The "Reasonable Steps" Standard
The amendments place the responsibility to take "reasonable steps" toward compliance squarely on senior management and governing bodies. A Board noting the AML/CTF Program in its meeting minutes is not, on its own, sufficient.
Active oversight is required of senior management now. This means understanding the specific ML/TF/PF risks the business faces and confirming that the AML/CTF Program has the resources and effectiveness to manage them. The AML/CTF Officer's position is also under scrutiny: this person must be fit and proper and hold genuine independence and authority. A governance structure where the AML Officer sits several levels below the Board with no direct reporting line is not compliant under the current standard.
Designated Business Groups Have Been Replaced
Designated Business Groups (DBGs) were replaced by Reporting Groups as part of the reforms — a practical but consequential operational change. Existing DBGs expired on March 31, 2026.
That transition was not automatic. Corporate groups that rely on pooled compliance resources needed to proactively establish a Reporting Group, backed by a formal agreement and a designated lead entity responsible for the group's AML/CTF compliance. Any group that has not completed this transition is now operating with individual entities exposed to legal risk and technical non-compliance, not facing a future risk.
Culture and Training Have to Reflect the Current Rules
New definitions and obligations came with the reforms, and every employee working in an AML/CTF function needs to be identified and properly trained. Training programs built under the old framework are now out of date.
The "tipping off" provisions changed back in March 2025, and the current Customer Due Diligence (CDD) standards require updated operational expertise, particularly around value transfers and the Travel Rule. Training plans for the rest of 2026 should reflect both the mechanics of the current Act and the shift toward proactive risk management that AUSTRAC now expects from frontline staff, compliance teams, and the Board alike.
Where This Stands Today
The core deadlines have now passed. For AFSL holders, that means the gap between the 2026 requirements and whatever framework was in place before March 31 is no longer a future planning problem — it is a present compliance question.
AFSL holders should take the following steps now:
- Gap Analysis: Compare the current AML/CTF Program against the reforms that took effect March 31, 2026.
- Risk Assessment Review: Confirm the Risk Assessment reflects the business's current risk profile, including proliferation financing.
- Governance Check: Verify the AML Officer's independence, formal appointment, and fit-and-proper status, and confirm the Board understands its expanded liability.
- DBG Transition: Confirm the Reporting Group replacing any former Designated Business Group is formally in place.
- AUSTRAC Cross-Check: Where the business also provides remittance or virtual asset services, confirm the separate AUSTRAC registration obligations — distinct from AFSL licensing — are up to date.
The purpose of the reforms is to prevent the financial system from being used for illicit purposes, and the bar for AFSL holders has been raised accordingly. Compliance with the current framework is a baseline license-to-operate requirement, not an item to check off once and file away.


