FAQs
The Anti-Money Laundering and Counter-Terrorism Act 2006 (Cth) (AML/CTF Act) provides the means to deter, detect and disrupt money laundering (ML), terrorism financing and proliferation financing.
Money laundering (ML) is the process by which illegally obtained funds are given the appearance of being legitimate. It has 3 layers:
- Placement – illegal funds or assets are placed in the financial system e.g. bank account,
- Layering – illegal funds or assets are moved or disguised to distance the proceeds from the original crime e.g. placing funds into a solicitor's trust account, and
- Integration – once the illegal funds are distanced from the origin, they are used to fund further criminal activity or to purchase high-value assets such as real estate and luxury goods making those funds seem legitimate.
Terrorism financing (TF) is the funding of acts, individuals and organisations associated with terrorism.
Proliferation financing (PF) is the financing of illegal activities intended to facilitate the creation and supply of weapons of mass destruction, whether the activities occur or are just attempted.
“Tranche 2” reforms refer to the Commonwealth Government’s expansion of Australia’s Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) regime to include gatekeeper professions – certain professional service providers such as lawyers, conveyancers, accountants, real estate agents and precious stone and metal dealers – that provide a “designated service”, as defined by AML/CTF Act.
See FAQ 6 below for more information about designated services.
The Commonwealth Government wants to strengthen Australia’s AML/CTF regime so that it continues to effectively deter, detect and disrupt ML, TF, and PF. The regime is based on international standards set by the global financial crime watchdog, the Financial Action Task Force (FATF). FATF is currently conducting an assessment of Australia’s compliance with the international standards.
- AML/CTF Act
- AML/CTF Rules
- AUSTRAC Guidance. See in particular AUSTRAC guidance relevant to Professional Services (Professional Services Core Guidance)
- AML/CTF Program Starter Kits.
A law practice that provides one or more designated services will become a “reporting entity” and have obligations under the AML/CTF Act.
AUSTRAC has developed a tool to help you determine whether you provide a designated service.
Designated services are defined under section 6 of the AML/CTF Act.
They include certain services, such as assisting clients to:
- Buy, sell or transfer real estate
- Buy, sell or transfer legal entities
- Receive, hold, control or manage their funds and/or property, for example, money, accounts, securities
- or assets
- Sell or transfer a shelf company
- Carry out some transactional work, including equity and debt financing, and
- Create or restructure a legal entity or legal arrangement.
AUSTRAC provides further details in its Professional Services Guidance on what it considers in and out of scope for professional services.
The Law Council of Australia has developed the National Legal Profession Anti-Money Laundering and Counter-Terrorism Financing Guidance—Legal profession designated services Guidance Note (dated 4 June 2026) to assist firms work out whether the legal services they provide are captured.
The Law Society of NSW has also produced the following resources to help practices consider whether they provide a designated service:
• AML/CTF Implementation Guide: for sole practitioners and small practices (particularly pages 10 to 15), and
• Understanding designated services: when legal services trigger Tranche 2 AML/CTF obligations.
Reporting entities will need to:
- Enrol with AUSTRAC,
- Conduct customer due diligence,
- Develop and maintain an AML/CTF Program,
- Have trained their staff on the AML/CTF program and internal process ,
- Be ready to report certain transactions and suspicious activity,
- Keep records,
- Designate someone as their AML Compliance Officer (AMLCO).
You can find more details on AUSTRAC’s webpage.
You must enrol with AUSTRAC within 28 days of providing a designated service.
No, you do not. Registration is an additional step, only relevant for entities who are a remittance network provider, independent remitter or virtual asset service provider.
The AML Compliance Officer (AMLCO) has to:
- Be an Australian resident
- Be a fit and proper person
- Be employed or engaged at management level
- Have sufficient authority, independence and access to information and resources to undertake their role effectively.
The AMLCO must, among other things, oversee and coordinate:
- The practice’s day-to-day compliance with the AML/CTF legislative scheme
- The effective operation of, and compliance with the practice’s AML/CTF policies.
The AMLCO can be employed internally, or be otherwise engaged by the law practice. They can also have other roles.
Yes, if you provide a designated service, you will need to designate an AMLCO. If you are a sole practitioner, or in a senior management position at your practice, it can be you. See FAQ 10, above, for more information on what is required of an AMLCO.
There are several places we recommend you go to get up to date on the reforms.
- AUSTRAC’s website, which has information about the AML/CTF reforms
- Explore our complimentary courses on AML/CTF. We particularly recommend our most recent offering, ‘Complying with your Anti-Money Laundering and Counter-Terrorism Financing obligations’. You can claim CPD points on all of our LawInform courses.
- Explore resources, links to background papers, current legislation, articles and complimentary AML/CTF CPD courses across the AML/CTF Hub.
To support small businesses, AUSTRAC has developed a Program Starter Kit (Starter Kit) for small businesses. The Starter Kit is the AML/CTF program for a typical low complexity small business. Larger firms can use the Starter Kit as a baseline for their own AML/CTF compliance.
The Starter Kit contains a:
- Risk assessment,
- Policy document, and
- Process document.
For many firms, particularly smaller practices, the Starter Kit provides a compliant AML/CTF program once customised to their particular business.
To be effective, firms will still need to make sure the Starter Kit is appropriate for their practice, and that it is properly implemented.
Use of the Starter Kit is not mandatory, but it is recommended.
We have published the following implementation guides to assist firms customise the Starter Kit:
- AML/CTF Implementation Guide: for sole practitioners and small practices, and
- AML/CTF Implementation Guide: for medium and large practices.
We recommend that these resources are read in conjunction with AUSTRAC issued guidance.
No. The AML/CTF reforms do not require you to engage an external entity. However, if you do choose to engage an external entity to assist with your AML/CTF compliance, please remember that while the AML/CTF framework allows reporting entities to outsource their compliance obligations, they cannot outsource their liability under the AML/CTF Act.
These are private entities that provide services to assist reporting entities to comply with their AML/CTF obligations. They are usually referred to as ‘AML solutions’ providers or ‘RegTechs’. Often, these providers use technology to assist with compliance. Please also see FAQ 17.
Yes, you can. The AML/CTF regime allows you to outsource your functions under the AML/CTF either on a one-off or on-going basis.
However, AUSTRAC has made clear that outsourcing to a third party is not a substitute for understanding the ML or TF risks of your practice. AUSTRAC has also warned that reporting entities may incur ML/TF risk as well as AML/CTF compliance risk if the outsourced service provider:
- does not tailor its services to your practice’s unique ML/TF risks,
- lacks the expertise or resources to conduct the relevant AML/CTF functions on your behalf,
- is unaware of the legal restrictions on information sharing under the AML/CTF Act, and
- is not subject to adequate oversight and monitoring during the arrangement.
This means, for example, that while you can outsource certain functions relating to your compliance with the AML/CTF Act, such as client due diligence or employee due diligence, you will remain liable to AUSTRAC if that work is not undertaken properly.
Before engaging with an AML solutions provider, you may wish to review the following AUSTRAC resources:
- Using outsourcing to help meet your AML/CTF obligations,
- Guidance for Engaging a RegTech,
- Expectations of RegTech, and
- Sample checklist for engagement of AML/CTF adviser.
Within the AML/CTF framework, entering into a reliance arrangement typically involves agreeing with a third party that one of you will rely on the other party to carry out know your client (KYC) and/or customer due diligence (CDD) obligations on a mutual client (or prospective mutual client).
Often, this arrangement is undertaken to enhance the customer experience, and lower the administrative burden, potentially making AML/CTF compliance less costly for the parties to the transaction.
Ultimately, whether it is advantageous for your practice to enter into a reliance arrangement is a commercial decision, that you will need to make sure aligns with the AML/CTF framework and other relevant regulations. To assist you make the right decision for your practice, here are a few important points to bear in mind.
A reliance arrangement must:
- be documented
- set out the responsibilities of each party, including responsibilities for record keeping
- be appropriate to the money laundering, terrorism financing, or proliferation financing risk (ML/TF risk) that the first reporting entity reasonably faces in providing designated services
- only be entered into between reporting entities, or, if one (or more) of the parties is a foreign entity, regulated by law of a foreign country that gives effect to the FATF Recommendations relating to CDD and record keeping.
Where you are relying on a third party to collect and/or verify KYC information
It is important to remember that reliance arrangements do not divest parties of their AML/CTF obligations. (1)
Before entering into a reliance arrangement, you must be satisfied that you have ‘reasonable grounds’ to believe that each of the requirements of the applicable AML/CTF Rules are met. These include AML/CTF Rules 6-29, 6-30 and 6-31, which, among other things, specify that:
- the third-party being relied upon to collect and verify KYC information must be a reporting entity under the AML/CTF Act,
- the reliance arrangement must be appropriate to your ML/TF risk. For example, you must consider whether the third party has the capacity to do the requisite level of due diligence, given the ML/TF risks your business may reasonably face when providing designated services. This means that, before entering into a reliance arrangement, you will need to carry out due diligence on the third party, to ensure that they:
- have a suitable AML/CTF program that is sufficiently sophisticated, given the ML/TF risk your practice is likely to face, and
- have implemented their AML/CTF program
- your AML/CTF policies must set out how and when you will use reliance, and how you will regularly assess that the reliance arrangements remain appropriate. These regular assessments must:
- be conducted at least once every two years
- be conducted if there is a significant change in the circumstances that may affect the arrangement, or whether the arrangement continues to meet the requirements of section 6-29 of the AML/CTF Rules
- have a written record prepared within 10 business days after the day the assessment is completed.
- you must keep evidence (such as records) to demonstrate that it was appropriate to rely on that third party.
AUSTRAC guidance provides that, after completing an assessment, if you are not satisfied that the arrangement complies with the AML/CTF Rules, you must conduct your own CDD on a client.(2)
Where you are carrying out KYC activities on behalf of a third party
Under the AML/CTF framework, a law practice may enter into a commercial arrangement and carry out KYC activities on behalf of another reporting entity. In such situations, we suggest taking care to understand the third party’s business, including the ML/TF risks that they would reasonably face, and ensuring that your AML/CTF program is appropriate, given those (and your practice’s) ML/TF risks.
We suggest that you also:
- ensure that the entity you are acting as agent for is able to obtain all the KYC information collected by you before they commence to provide a designated service, or, if delayed CDD applies, that the information is provided as soon as reasonably practicable, or within a period specified by the AML/CTF Rules
- regularly (that is, at least every two years) assess whether the arrangement meets the requirements at section 6-29 of the AML/CTF Rules
- ensure that you’re complying with your obligations under the Privacy Act 1988 (Cth), for example, that the customer is aware that you are disclosing their information to the third party that has engaged you as an agent to carry out KYC activities.
As a law practice’s professional indemnity insurance only covers claims made in connection with the provision of legal services, consider whether you are providing KYC services in connection with, or separate to, the provision of legal services, and consider whether you might wish to obtain separate professional indemnity insurance for claims arising from the provision of the KYC services. This may be an issue if a law practice is considering providing KYC or CDD information in relation to a party who is not a client receiving legal services.
Further guidance
For more information, please refer to AUSTRAC’s guidance on reliance:
- Overview of reliance on customer identification by a third party
- Reliance under customer due diligence arrangements
- Reliance on a case-by-case basis
- Managing risk and assessing foreign jurisdictions.
(1) The note at section 37(1) of the AML/CTF Act provides that the reporting entity (and not its agent) will be liable for penalties for providing designated services to its customers without collecting or verifying KYC information about the customer that is appropriate to their ML/TF risk.
(2) AUSTRAC, Reliance under customer due diligence arrangements, https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/customer-due-diligence/reliance-customer-identification-third-party/reliance-under-customer-due-diligence-arrangements
The AML/CTF Act contains protections for client legal privilege (CLP). AUSTRAC’s guidance states that the AML/CTF Act ‘doesn’t affect the right of a person to refuse to give information where that information would be privileged from being given or produced on the grounds of LPP [legal professional privilege]’.
If some of the information you are required to give to AUSTRAC is subject to CLP, and you withhold information on this basis, you will be required to submit a form (i.e. an LPP form).
You will not be required to submit an LPP form if all the information that make up the grounds of suspicion in a suspicious matter report is subject to LPP.
Please also see our guidance on CLP, Protecting your clients’ claim to client legal privilege.
Prompted by the new AML/CTF obligations, the Australian Solicitors’ Conduct Rules (Conduct Rules) and the Solicitors’ Practice Rules (Practice Rules) have been amended from 1 July 2026.
The changes include:
- amendment to Rule 8.1 of the Conduct Rules (a solicitor must only accept and follow a client’s lawful, proper and competent instructions),
- amendment to Rule 13 of the Conduct Rules (definition of just cause), and
- introduction of a new Practice Rule 12 (amendments to retainer).
The Australian Solicitors’ Conduct Rules, in particular rule 9.22, allow a solicitor to disclose information which is confidential to a client, if the solicitor is compelled by law to disclose it.
We have prepared a Costs disclosure and costs agreement which the firm can customise. These are available on our costs precedents page. You can also speak to one of our Costs Solicitors on 02 9926 0116 or costs@lawsociety.com.au if you have any questions.
The Legal Services Council has also prepared general guidance on AML/CTF Act compliance and billing practices under the Uniform Law.
We are aware that solicitors have noticed the insertion of 'AML/CTF special conditions' in contracts for the sale and purchase of land. These special conditions may contain clauses requesting, for example, that the agreeing party warrants that:
- it has not taken any action that would cause the other party to be in breach of their AML/CTF obligations
- its operations have been conducted in compliance with the AML/CTF regime at all times
- neither they nor their representative are subject to, or pending investigation, by AUSTRAC.
In our view, such conditions are an ineffective way to reduce money laundering and counter-terrorism financing risk, and may be an attempt to outsource responsibility for AML/CTF compliance, which is not permitted under the AML/CTF regime. It is also not appropriate to seek a warranty that purports to bind a non-party (such as the party’s representative) to a contract. Such a provision may produce uncertainty regarding the parties’ enforceable rights and obligations, as it is likely inconsistent with the doctrine of privity of contract.
Generally, the AML/CTF regime imposes obligations on providers of designated services, who in most transactions will be the parties’ representatives, not the parties themselves.
In addition, any person who has submitted a suspicious matter report, is aware of an investigation by AUSTRAC, or has been requested to provide information to AUSTRAC, is likely subject to the tipping off prohibition at section 123 of the AML/CTF Act. Insistence on the inclusion of a special condition that a party, for example, is not subject to an investigation by AUSTRAC, therefore, could risk encouraging that person to breach their AML/CTF obligations.
However, parties to a contract may choose to include additional terms in a contract to clearly set out and support the discharge of AML/CTF responsibilities of the parties. For example, such terms may specify that the person seeking the designated service must provide their customer due diligence information within a specified time.
While conditions in a contract are ultimately a matter for the parties involved, the Law Society encourages solicitors to, as they would with all contractual clauses, carefully consider the provisions. If the other party insists on including the clauses, the solicitor should seek clarification as to their purpose, and consider whether the wording can be narrowed to address any legitimate concern without creating unnecessary contractual risks, as noted above.
Yes! Please contact the Law Society’s Professional Support Unit for guidance either at amlctf@lawsociety.com.au or on (02) 9926 0249.
In addition, you may wish to contact AUSTRAC on 1300 021 037, or submit a query online to AUSTRAC’s Contact Centre.