Logo
コラム

AML/CTF Reforms – What Existing Reporting Entities Need to Do before 31 March 2026

ケネス・ホン, Nicholas Lim, ローラ・オー · 2026年2月27日

1. Overview of the Reforms

Significant changes to Australia’s Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) regime are taking effect under the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (the Amendment Act) and the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (the Rules). These reforms represent a fundamental shift toward an outcomes-based, risk-oriented framework, aligned with international standards set by the Financial Action Task Force. The core pillars of the reform include:

  • Stronger governance and oversight, with clearer accountability for the board and senior management;
  • Expanded risk assessments, including explicit coverage of Proliferation Financing (PF) risk; and
  • New transitional measures, including a three-year transition period for initial Customer Due Diligence (CDD) obligations.

2. Who Do These Reforms Apply To?

The AML/CTF reforms affect a broad range of businesses. If your business provides any of the designated services regulated under the AML/CTF Act, you are a “reporting entity” and must comply with the reformed regime.

Existing Reporting Entities (Tranche 1)

Entities already regulated under the AML/CTF Act must comply with the reformed regime from 31 March 2026. These include:

  • banks, building societies, and credit unions;
  • life insurers and friendly societies;
  • securities dealers, futures brokers, and managed investment scheme operators;
  • remittance service providers;
  • gambling service providers, including casinos and online wagering operators;
  • bullion dealers; and
  • virtual asset service providers (formerly digital currency exchange providers).

Newly Regulated Entities (Tranche 2)

A major expansion of the AML/CTF regime will bring approximately 90,000 new businesses under AUSTRAC regulation from 1 July 2026. These “Tranche 2” entities include:

  • lawyers and law practices;
  • accountants;
  • real estate agents;
  • trust and company service providers; and
  • dealers in precious metals and stones (jewellers).

Tranche 2 entities will be able to enrol with AUSTRAC from 31 March 2026 and must be enrolled by 29 July 2026. AUSTRAC has released sector-specific guidance and program starter kits to assist newly regulated entities in preparing for their obligations.

3. Governance and Oversight: New Statutory Obligations

A central feature of the reforms is the introduction of defined roles for the “Governing Body” and “Senior Manager”, together with heightened expectations for effective internal controls.

Governing Body

The “Governing Body” refers to the individuals or body (such as a Board of Directors) with primary responsibility for the governance of the reporting entity. The Governing Body is expected to maintain ongoing oversight of AML/CTF compliance and be sufficiently informed of Money Laundering (ML), Terrorism Financing (TF), and Proliferation Financing (PF) risks to ensure that the AML/CTF Program is identifying and mitigating those risks in practice. Under the Amendment Act, the Governing Body has proactive obligations to provide “appropriate ongoing oversight”. The Australian Transaction Reports and Analysis Centre (AUSTRAC) has indicated that this may be demonstrated by:

  • including AML/CTF compliance and ML/TF/PF risk as a regular standing agenda item in board or management meetings;
  • reviewing relevant matters in AML/CTF compliance officer and independent evaluation reports;
  • questioning how the business will address any adverse findings in those reports; and
  • interrogating the root causes of non-compliance and the effectiveness of existing controls.

Senior Manager

A “Senior Manager” is an individual who makes, or participates in making, decisions affecting the whole or a substantial part of the reporting entity. The reforms sharpen accountability by making them legally responsible for approving the ML/TF/PF Risk Assessment, AML/CTF policies, and any material updates to those documents. The Senior Manager's approval is also required for high-risk individual matters, including:

  • providing designated services where politically exposed persons are involved; or
  • establishing or maintaining a nested services relationship.

Both of these roles must be held by individuals with greater active governance, oversight and executive decision-making responsibility.

4. Proliferation Financing (PF)

A key reform is the explicit requirement for reporting entities to identify, assess, and manage PF risk. PF involves financing activities linked to the development or acquisition of weapons of mass destruction. While many institutions are already familiar with sanctions compliance and screening requirements, the reforms clarify that PF must be treated as a distinct AML/CTF risk category. PF should be integrated into the ML/TF/PF Risk Assessment as part of routine risk management. For many entities, this will require refining existing methodologies to ensure PF is assessed with sufficient specificity (for example, through jurisdictional exposure, transaction typologies, and counterparty risk indicators), rather than being subsumed within broader AML/CTF risk settings. Where an entity reasonably assesses PF risk as low, a standalone Counter-Proliferation Financing policy is not required, provided the risk is appropriately managed through existing ML/TF controls. However, any low-risk assessment must be properly documented to satisfy AUSTRAC’s expectations for an auditable process. If PF is not addressed at all in the Risk Assessment and AML/CTF Program documentation, the framework may be non-compliant.

5. Implementation Timeline and Transitional Measures

The compliance deadline for existing reporting entities is 31 March 2026. Entities should use the remaining time to finalise necessary structural and governance updates.

Three-Year Transition for Initial CDD

On 22 January 2026, AUSTRAC announced that existing reporting entities will be granted an additional three years (i.e. until 30 March 2029) to comply with the new initial CDD obligations. During this period, entities may choose either to:

  • continue applying their existing Applicable Customer Identification Procedures when onboarding new customers; or
  • transition to the reformed initial CDD obligations at any time before 30 March 2029.

Entities must apply whichever framework they choose consistently across all new customers and customer types. Once an entity formally transitions to the reformed CDD obligations, it must apply the new requirements from that point forward. The three-year transition applies only to initial CDD (i.e. new customer onboarding). Ongoing CDD obligations under section 30 of the AML/CTF Act must be implemented from 31 March 2026 with no deferral.

Other Transitional Measures

AUSTRAC has also confirmed the following transitional arrangements:

  • existing reporting entities have until 30 May 2026 to notify AUSTRAC of their AML/CTF Compliance Officer;
  • staggered deadlines will apply for entities that have recently completed an independent review; and
  • on 9 February 2026, AUSTRAC released exposure draft amendments to the AML/CTF Rules for industry consultation. The transitional rules being developed by the Department of Home Affairs under Schedule 12 of the Amendment Act are expected to be finalised shortly.

6. Your Compliance Readiness Checklist

With the 31 March 2026 deadline imminent, each reporting entity should assess its current position against the following:

  1. Integrating PF as a distinct risk category in your ML/TF/PF Risk Assessment, ensuring the assessment methodology is sufficiently specific to identify threats;
  2. Clearly designate the Senior Manager responsible for statutory approvals of policies and risk assessments and define the Governing Body's duty to exercise “appropriate ongoing oversight”;
  3. Assess whether the AML/CTF Compliance Officer meets the new statutory criteria, including being an Australian resident (where applicable), a fit and proper person, and possessing sufficient authority and independence;
  4. Refresh AML/CTF Programs and controls to align with the updated Rules and the outcomes-based framework;
  5. Align evaluation schedules with the new statutory requirement to test Program effectiveness at least every three years, noting that any adverse findings now trigger an immediate review of the Risk Assessment;
  6. Implement ongoing CDD processes under section 30 of the AML/CTF Act; and
  7. Document transitional implementation steps, including approvals, milestones, and remediation activity.

The immediate task for existing reporting entities is not to start from scratch, but to ensure that existing frameworks are updated to meet the new expectations in governance accountability, PF risk assessment, and CDD obligations. AUSTRAC has made clear that its approach to compliance will be “pragmatic and proportionate” but has also signalled that entities that fail to manage their ML/TF risks or ignore their obligations will face regulatory action. Having a documented implementation plan in place by 31 March 2026 is essential.

7. How We Can Assist

H & H Lawyers has extensive experience advising reporting entities on AML/CTF compliance, risk assessments, and governance frameworks. We understand the practical challenges these reforms present, particularly for businesses operating across multiple jurisdictions. Our team can assist with:

  • reviewing and updating your ML/TF/PF Risk Assessments and AML/CTF Programs;
  • advising on governance structures, including the designation of Senior Manager and Governing Body roles;
  • assessing AML/CTF Compliance Officer suitability under the new statutory criteria;
  • preparing documented implementation plans and transitional strategies; and
  • providing ongoing compliance support as the reforms take full effect.

To discuss how these reforms affect your business, please do not hesitate to contact us.

Key Contacts

ケネス・ホン profile image

ケネス・ホン

主任弁護士

Nicholas Lim profile image

Nicholas Lim

弁護士

Related Insights

もっと見る

商取引及び会社法,コーポレートガバナンス,企業アドバイザリー、M & A,独占禁止法及び消費者保護法,フランチャイズ法

2026年8月7日

Future-Proofing Australia’s Automotive Laws: Dr Jenny Buchan’s Review of the Australian Consumer Law and Franchising Code

UNSW Emeritus Professor Dr Jenny Buchan, Senior Advisor at H & H Lawyers, has completed a comprehensive review of the operation of the Australian Consumer Law and the Franchising Code of Conduct in Australia's new car market commissioned by the Australian Automotive Dealer Association. The Root and Branch Review of the Australian Consumer Law (ACL) and the Franchising Code of Conduct (Code) as they apply to Buyers of New Cars (Consumers), Manufacturers (Franchisor/OEMs) and New Car Dealers (Franchisees), examines how Australia's consumer protection and franchising laws operate across the relationships between consumers, car manufacturers and franchised dealers. Commissioned by the Australian Automotive Dealer Association (AADA), the Issues Paper constitutes Stage 1 of a broader project examining the legal and practical challenges experienced in the new car sector.

詳しく見る

取締役の責任に関する紛争,不動産開発,役員の責任,不動産関連の紛争,契約に関する紛争

2026年8月7日

Design and Building Practitioners Act 2020 (NSW) 法に基づき取締役が個人責任を負うのはどのような場合か

ニューサウスウェールズ州最高裁判所は、Strata Plan 92183 v Samdora Pty Ltd [2026] NSWSC 406 において、Design and Building Practitioners Act 2020 (NSW)(DBP法)の施行以来、実務上大きな関心を集めてきた論点の一つ、「建設会社やデベロッパーの取締役が、欠陥工事について個人的な責任を負うのはどのような場合か」について重要な指針を示しました。 本判決は、取締役という肩書だけで責任が認められるわけではなく、実際に建設工事へどのように関与していたかが重要な判断要素となることを明確にしました。 なぜこの判決が重要なのか DBP法第37条では、「建設工事(construction work)」を行う者は、建物の欠陥又は建設工事に起因する欠陥によって生じる経済的損失を回避するための法定の注意義務(statutory duty of care)を負うと定められています。さらに、DBP法第36条では、「建設工事」を行う者とは、実際に建築作業を行う者だけを意味するものではありません。 例えば、以下のような役割を担っていた者も、「建設工事を行った者」に該当する可能性があります。 このように「建設工事」の定義が広く定められていることから、近年では、建設会社やデベロッパーだけでなく、その取締役個人に対してもDBP法に基づく請求が提起されるケースが増えています。 事案の概要 本件は、NSW州のMangertonに所在するタウンハウスに生じた建築上の欠陥を巡る事案です。管理組合(Owners Corporation)は、建設会社およびデベロッパーに加え、それぞれの取締役に対しても訴訟を提起し、DBP法第37条に基づく注意義務に違反したと主張しました。もっとも、裁判所は、両取締役について異なる結論に至りました。 デベロッパーの取締役に責任が認められなかった理由 裁判所は、デベロッパーの取締役について、建設工事への関与は極めて限定的であったと認定しました。例えば、現場検査に時折立ち会うことはあったものの、それはあくまで付随的な関与に過ぎませんでした。 裁判所は、この取締役について、 又は、上記のような役割を担うために雇用されていたことを示す十分な証拠は存在しないと判断しました。 その結果、この取締役はDBP法上の「建設工事を行った者」には該当せず、管理組合の請求は退けられました。 建設会社の取締役に責任が認められた理由 これに対し、建設会社の取締役については事情が異なりました。 同取締役は建設会社の指名監督者(Nominated Supervisor)であり、建設工事を監督していたことについて当事者間に争いはありませんでした。 そのため裁判所は、この取締役がDBP法上の注意義務を負うことを前提に、その義務に違反したかどうかを検討しました。同検討をする上で裁判所は、欠陥を一括して判断するのではなく、個々の欠陥ごとに証拠を精査しました。 その結果、一部の欠陥については、取締役が適切に現場を監督し、定期的な点検・確認を行っていれば容易に発見できたはずであるとして、注意義務違反が認められましたが、その他の欠陥については、仮に適切な監督を行っていたとしても発見できたとは認められないとして、これらについては取締役の責任は否定されました。 実務上のポイント 本判決から得られる重要な実務上の示唆は次のとおりです。 まとめ 本判決は、DBP法に基づく取締役の個人責任は、「取締役であること」ではなく、「実際に何をしていたのか」によって判断されることを改めて示した重要な判例です。そのため、DBP法に基づく請求を提起する場合も、これを防御する場合も、取締役の日常的な業務内容、現場への関与の程度、意思決定権限、監督責任の有無などを裏付ける具体的な証拠が、極めて重要となります。もっとも、本判決は個別事案における事実認定に基づく第一審判決であり、これによってDBP法における役員等の責任範囲に関する法理が最終的に確立されたものと理解することは適切ではありません。今後、控訴審における判断や他の裁判例の蓄積により、その解釈が発展又は変更される可能性も十分に考えられます。そのため、現時点では、本判決はDBP法の適用範囲を考える上で重要な指針ではあるものの、将来にわたり確立した法理として扱うのではなく、今後の判例の動向を注視する必要があります。

詳しく見る

契約に関する紛争,会社更生、会社清算、破産,契約書・商業契約全般,債権回収、債権行使及び差し押さえ

2026年3月3日

Debt Recovery in Australia

Debt recovery is rarely a straightforward exercise. In the current economic climate, businesses and individuals frequently encounter difficulties in recovering outstanding accounts. This can result in interrupted cash flow and heightened financial pressure.

詳しく見る

契約に関する紛争,異議申し立て,契約書・商業契約全般

2025年9月26日

小規模事業者再編制度(Small Business Restructuring)

小規模事業者再編制度(Small Business Restructuring) 2021年に導入された小規模事業者再編制度(Small Business Restructuring=SBR)は、オーストラリア全土の小規模事業者、特に近年の経済低迷の影響を受けた企業にとって、会社清算に代わる重要な選択肢となっています。 特にファミリービジネスを含む小規模企業の事業継続を支援するために設計されたSBRは、企業が営業を続けながら、法的に財務状況をリセットできる仕組みです。 事業継続のための法的手段 SBRは、債務超過に直面した小規模事業者が、従来の清算手続きによる会社閉鎖を回避できるように設けられました。 SBRを利用することで、該当企業は債権者に対して再編計画を提案し、会社法(Corporations Act)に基づき、債務の削減や免除を求めることが可能です。 このプロセスにより、企業は営業を継続しながら、法的に整理された形で財務問題に対処できます。 利用資格と手続き SBRを利用するには、総債務額が100万ドル以下であり、未払いの従業員賃金や年金(superannuation)は含まれていないことが条件になります。 SBRの実行には債権者の承認が必要です。債権者の投票権は貸している金額によって決まり、債務全体の51%以上を持つ債権者が最終決定権を持つことになります。 利用増加とその影響 ASICの最新データによると、SBRの申請件数は大幅に増加しており、昨年は約3,000件が債権者に提示されました。 この増加は、SBRの認知度向上と、多くの小規模事業者が厳しい経営環境に直面していることを反映しています。 特に飲食業界は大きな打撃を受けており、同業界の10社に1社が昨年清算されました。 多くの再編計画では、債務額が20万〜40万ドルの範囲で、債務の最大80%の免除を債権者に求めています。 SBRの約80%が承認されているのも注目すべき点です。 オーストラリア税務局(ATO)の役割 SBR案件の93%に関与しているオーストラリア税務局(ATO)は、最大の債権者(GST) として重要な役割を果たしています。 ATOはこれまでに約2,500件のSBR計画を承認しており、2024-25会計年度3月時点では、ATOが債権者となった再編計画の約80%に賛成票を投じています。 宿泊業および飲食業(カフェ、レストラン、テイクアウトサービスを含む)は、SBR全体の22%を占めています。 ATOの関与が大きいため、再編計画の可否はほとんどの場合、ATOの判断に左右されます。 ATOが再編計画に賛成すれば、他の小口債権者もその計画に組み込まれる形となります。 制度のセーフガードと除外規定 制度の健全性を保つため、過去7年以内に清算や再編に関与した取締役がいる企業は、SBRの申請資格がありません。

詳しく見る

契約に関する紛争,労働法訴訟,裁判に代わる紛争解決(ADR),契約書・商業契約全般

2025年9月17日

Artificial Intelligence (AI) and International Arbitration

International arbitration has long been valued for its flexibility, neutrality, and adaptability. In recent years, however, the emergence of artificial intelligence (AI) has introduced a new set of opportunities and challenges that are likely to reshape arbitral practice. Unlike earlier waves of technological change, AI has a particularly pervasive impact: it is capable of touching almost every stage of the arbitral lifecycle; from pre-dispute planning and arbitrator selection to evidentiary and document review, hearings, award drafting, and enforcement.

詳しく見る

契約に関する紛争,企業アドバイザリー、M & A,法人税および個人税に関するアドバイス,裁判に代わる紛争解決(ADR),契約書・商業契約全般,コーポレートガバナンス,コンプライアンスおよびアドバイザリーサービス

2025年8月13日

Ad hoc and Institutional Arbitration

Arbitration is an increasingly preferred alternative to traditional litigation, particularly in commercial and international disputes. For businesses engaged in cross-border transactions, especially within the Asia-Pacific region, choosing between institutional and ad hoc arbitration can significantly influence the efficiency, cost and enforceability of dispute resolution. This article outlines key differences and practical considerations to help parties make informed decisions.

詳しく見る