Australia KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Australia.
- Last reviewed
- Last reviewed:
- Version
- Version 1.3

Portable implementation guide
Get the PDF checklist
11 control areas · 40 implementation checks
Last reviewed: 23 September 2026 · Version 1.3
Download the checklistDirect answer
What does the Australia compliance checklist cover?
The Australia checklist translates primary KYC, KYB and AML rules into 11 control areas and 40 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU and AML/CTF regulator
- Australian Transaction Reports and Analysis Centre (AUSTRAC)
- Primary AML rules
- AML/CTF Act 2006 and AML/CTF Rules 2025, as in force
- SMR timing
- 24 hours for terrorism-financing suspicion; otherwise 3 business days after the day suspicion is formed; limited LPP claims may have 5 business days
- Cash threshold report
- A$10,000 or more in physical currency, including foreign-currency equivalent; generally within 10 business days
- AML retention
- Generally 7 years, with the statutory start event depending on record type
- Reform transition
- New regime in force; eligible legacy ACIP transition may continue by customer class until no later than 31 March 2029
- Privacy
- Privacy Act 1988 and Australian Privacy Principles where coverage applies; biometrics used for automated identification or verification are sensitive information
- FATF public lists
- Not listed at 19 June 2026
Implementation detail
Australia compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and registrationClassify every service, geographic link and transition before relying on a control.4 items+
Determine whether each activity is a designated service with an Australian geographic link.
- Implementation action
- Map financial, remittance, gambling, bullion, virtual-asset, real-estate, precious-metals-and-stones and professional services to the current Act tables and exclusions before launch or material change.
- Evidence to retain
- Entity and service map, customer and funds flows, geographic-link analysis, statutory citations and counsel sign-off.
- Primary citation
- AML/CTF Act 2006, sections 6, 6A and 6B and current designated-service tables
Enrol with AUSTRAC and register where the Act requires a register entry.
- Implementation action
- Apply for enrolment within 28 days after commencing a designated service unless a specific earlier transitional deadline applies. Obtain approved remittance or VASP registration before service, subject to the limited 2026 transitional application rule for new VASP services; keep details current.
- Evidence to retain
- AUSTRAC Online submission, enrolment confirmation, registration decision, conditions, renewal and change log.
- Primary citation
- AML/CTF Act 2006, Parts 6 and 6A; AUSTRAC enrolment and registration guidance
Apply the tranche-2 perimeter from 1 July 2026.
- Implementation action
- For lawyers, conveyancers, accountants, trust and company service providers, real-estate businesses and dealers in precious metals or stones, identify whether the actual service is designated rather than treating an occupation as automatically covered.
- Evidence to retain
- Matter-type inventory, designated-service assessment, exclusions, enrolment and scoped procedures.
- Primary citation
- AML/CTF Act 2006, section 6 and Tables 5-8; AUSTRAC new-regime guidance
Document each transitional rule relied upon.
- Implementation action
- For eligible pre-31 March 2026 entities, record customer classes, legacy ACIP end dates and the implementation plan; do not combine the legacy and new initial-CDD approaches for one class.
- Evidence to retain
- Transition eligibility memo, approved policies, class schedule, end dates, implementation milestones and monitoring.
- Primary citation
- Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026, Parts 3-4
02Governance and ML/TF risk assessmentThe program must be risk-based, governed by accountable senior management and independently evaluated.4 items+
Maintain a documented ML/TF/PF risk assessment.
- Implementation action
- Assess customers, countries, products, services, transactions, delivery channels, technology and outsourcing; update before material change and when AUSTRAC information changes the risk picture.
- Evidence to retain
- Methodology, current assessment, data sources, approval, residual-risk decisions and remediation plan.
- Primary citation
- AML/CTF Act 2006, Part 1A; AML/CTF Rules 2025, Part 4
Maintain an effective AML/CTF program appropriate to the business.
- Implementation action
- Translate identified risks into policies for CDD, monitoring, reporting, transfers, sanctions escalation, records, personnel, training, third parties and regulatory response.
- Evidence to retain
- Approved program, control mapping, procedures, training records, testing and issue closure.
- Primary citation
- AML/CTF Act 2006, Part 1A; AML/CTF Rules 2025, Parts 3-5
Assign senior-manager oversight and notify the governing body.
- Implementation action
- Name accountable senior managers, give them sufficient authority and resources, record approvals and ensure material non-compliance and risk changes reach the governing body.
- Evidence to retain
- Appointments, role descriptions, approval minutes, reporting packs and escalation records.
- Primary citation
- AML/CTF Act 2006, Part 1A; AML/CTF Rules 2025, governance provisions
Arrange independent evaluation of the program.
- Implementation action
- Use a suitably independent and competent evaluator, scope the entire program at the risk-based frequency, provide access and track findings to verified closure, including applicable transition timing.
- Evidence to retain
- Independence assessment, plan, report, management response and closure tests.
- Primary citation
- AML/CTF Act 2006, Part 1A; AML/CTF Rules 2025; Transitional Rules 2026, Part 7
03Natural-person identificationInitial CDD must establish prescribed matters on reasonable grounds before service, except where a controlled statutory exception applies.4 items+
Complete initial CDD before commencing a designated service.
- Implementation action
- Establish identity, relevant represented or acting persons, authority, PEP and sanctions status, purpose and relationship or transaction risk before service unless a specific delayed-verification rule applies.
- Evidence to retain
- CDD record, sources, verification results, risk decision, timestamp and exception approval.
- Primary citation
- AML/CTF Act 2006, sections 28-30; AML/CTF Rules 2025, Part 6
Identify and verify each individual customer on reasonable grounds.
- Implementation action
- Collect risk-appropriate KYC information and use reliable and independent data or documents to establish that the person is who they claim to be; resolve inconsistencies.
- Evidence to retain
- Identity attributes, source provenance, verification result, fraud checks and discrepancy resolution.
- Primary citation
- AML/CTF Act 2006, section 28; AML/CTF Rules 2025, sections 6-1 and 6-5
Verify representatives, authority and persons behind the service.
- Implementation action
- Identify a person acting for the customer and establish authority; identify any person on whose behalf the customer receives the service and apply risk-appropriate verification.
- Evidence to retain
- Representative KYC, mandate, underlying-person record, scope limits and activity log.
- Primary citation
- AML/CTF Act 2006, section 28(2)(b)-(c); AML/CTF Rules 2025, sections 6-5 and 6-6
Control delayed, simplified and enhanced CDD separately.
- Implementation action
- Use only an express rule, satisfy every condition, apply transaction restrictions and completion deadlines, and withdraw simplified treatment when risk or suspicion changes.
- Evidence to retain
- Eligibility checklist, legal source, approval, restriction tests, completion timestamp and withdrawal trigger.
- Primary citation
- AML/CTF Act 2006, sections 29-33; AML/CTF Rules 2025, sections 6-12 to 6-22
04KYB, registries, and beneficial ownershipEstablish legal existence, authority and the natural persons who ultimately own or control the customer.4 items+
Verify legal-person or arrangement identity and existence.
- Implementation action
- Collect current name, type, identifiers, registered address, governing documents, officers or trustees and reliable registry evidence appropriate to the customer type.
- Evidence to retain
- ASIC or other registry extract, constitutional or trust documents, identifier checks, officer list and discrepancies.
- Primary citation
- AML/CTF Act 2006, section 28; AML/CTF Rules 2025, sections 6-2 to 6-4
Identify each natural person who ultimately owns or controls the customer.
- Implementation action
- Follow ownership chains to individuals and assess control by other means; where the Rules require it and no owner or controller is identified, establish the prescribed senior manager rather than inventing a universal percentage.
- Evidence to retain
- Layered ownership chart, registry sources, control analysis, verified identities and fallback rationale.
- Primary citation
- AML/CTF Act 2006, sections 5 and 28; AML/CTF Rules 2025, sections 6-7 and 6-8
Identify relevant trust and legal-arrangement parties.
- Implementation action
- For trusts or foreign equivalents, establish the trust, trustees, settlors or contributors, beneficiaries or classes, appointors, protectors and other controllers as required by the current Rules and risk.
- Evidence to retain
- Trust deed, party schedule, control powers, verification and change monitoring.
- Primary citation
- AML/CTF Rules 2025, sections 6-3 and 6-7
Keep AML beneficial ownership separate from company-register disclosure.
- Implementation action
- Use ASIC registers and company member records as evidence inputs, resolve nominee or non-beneficial holdings, and do not assume a public extract proves ultimate ownership or control.
- Evidence to retain
- ASIC extract, member register, declarations, independent corroboration and unresolved-gap escalation.
- Primary citation
- Corporations Act 2001, sections 168-178; ASIC members-register guidance; AML/CTF Act 2006, section 28
05PEPs, enhanced due diligence, and remote onboardingPEP, sanctions, high-risk and non-face-to-face exposure require risk-sensitive measures.3 items+
Establish whether relevant persons are PEPs.
- Implementation action
- Screen customers, beneficial owners, represented persons and representatives for foreign, domestic and international-organisation PEP status and applicable family or close-associate relationships.
- Evidence to retain
- Screening result, source, relationship map, rationale and refresh history.
- Primary citation
- AML/CTF Act 2006, section 28(2)(e); AML/CTF Rules 2025, sections 1-5 and 6-23
Apply enhanced CDD when the Act or Rules require it.
- Implementation action
- Obtain senior approval where required, corroborate source of wealth and funds, gather additional information, increase monitoring and manage unusual or high-risk services.
- Evidence to retain
- Trigger, approval, source corroboration, enhanced monitoring plan and reviews.
- Primary citation
- AML/CTF Act 2006, section 32; AML/CTF Rules 2025, sections 6-20 to 6-22
Control remote identity fraud and biometric processing.
- Implementation action
- Test document authenticity, liveness, impersonation and device risk; collect biometrics only where lawful, necessary and appropriately consented or otherwise authorised, and protect templates as sensitive information.
- Evidence to retain
- Method assessment, test results, notices, consent or authority, vendor diligence and exception review.
- Primary citation
- AML/CTF Act 2006, section 28; Privacy Act 1988, section 6 and APPs 3 and 11
06Monitoring and suspicious matter reportingOngoing CDD and prompt suspicion decisions must feed timely AUSTRAC reporting.4 items+
Conduct ongoing CDD and transaction monitoring.
- Implementation action
- Keep KYC and beneficial-ownership information current and scrutinise transactions against expected purpose, behaviour and risk; escalate material inconsistencies promptly.
- Evidence to retain
- Monitoring scenarios, alerts, case analysis, refresh record and dispositions.
- Primary citation
- AML/CTF Act 2006, section 30, and section 32 where enhanced CDD applies; AML/CTF Rules 2025, section 6-35
Form and document suspicion without waiting for proof.
- Implementation action
- Review relevant information as soon as practicable, record when reasonable grounds arose and assess provided, proposed, requested and attempted services within the statutory test.
- Evidence to retain
- Alert chronology, information reviewed, suspicion decision, decision-maker and legal basis.
- Primary citation
- AML/CTF Act 2006, section 41; AUSTRAC suspicious-matter-report guidance
Submit SMRs within the applicable statutory clock.
- Implementation action
- Report through AUSTRAC Online within 24 hours for terrorism-financing suspicion or within three business days after the day other suspicion is formed; apply the limited five-business-day LPP claim timing only when its conditions are met.
- Evidence to retain
- Suspicion timestamp, classification, SMR, submission receipt and LPP assessment if used.
- Primary citation
- AML/CTF Act 2006, section 41(2); AUSTRAC suspicious-matter-report guidance
Protect SMR information and avoid tipping off.
- Implementation action
- Restrict report, suspicion and AUSTRAC-request information to authorised need-to-know use and review any disclosure against the statutory exceptions before release.
- Evidence to retain
- Access controls, disclosure register, legal review, training and incident record.
- Primary citation
- AML/CTF Act 2006, sections 123 and 124
07Threshold reports, transfers, and virtual assetsReporting amounts, forms and transition dates are report-specific.4 items+
Report covered A$10,000 physical-currency transactions.
- Implementation action
- For a designated service involving A$10,000 or more in physical currency or foreign-currency equivalent, submit a TTR within 10 business days and do not apply the amount to non-cash activity.
- Evidence to retain
- Cash data, currency conversion, report, submission receipt and exception analysis.
- Primary citation
- AML/CTF Act 2006, sections 5 and 43; AUSTRAC TTR guidance
Apply the correct international-transfer reporting transition.
- Implementation action
- Until the entity's IVTS reporting transition date, continue applicable legacy IFTI reporting; prepare for section 46 IVTS reporting and document any substitute transition date.
- Evidence to retain
- Transition analysis, transfer map, forms, submission receipts, nominated date and tests.
- Primary citation
- AML/CTF Act 2006, section 46; Transitional Rules 2026, Part 4
Carry prescribed transfer information and manage missing data.
- Implementation action
- Collect, transmit and retain required originator and beneficiary information for relevant money, property and virtual-asset transfers and apply repair, restriction or rejection procedures.
- Evidence to retain
- Field matrix, message samples, validation rules, exception queue and disposition.
- Primary citation
- AML/CTF Act 2006, Part 5; AML/CTF Rules 2025, transfer-of-value provisions
Register and control covered virtual-asset services.
- Implementation action
- Obtain AUSTRAC registration before providing a registrable VASP service, except where Transitional Rules 2026 section 14 permits a provider of only newly registrable services that applied by 29 July 2026 to continue pending AUSTRAC's decision; map services and travel-rule controls.
- Evidence to retain
- Service analysis, application timing, registration or transition eligibility, conditions, wallet and funds flows, travel-rule tests and renewal calendar.
- Primary citation
- AML/CTF Act 2006, Parts 6 and 6A; Transitional Rules 2026, section 14; AUSTRAC VASP guidance
08Targeted financial sanctionsAustralian sanctions are distinct from AML screening and require immediate control of covered assets.3 items+
Screen against the current Australian Consolidated List.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, during the relationship and when DFAT updates the list; assess ownership and control beyond exact names.
- Evidence to retain
- List version, update logs, configuration tests, match analysis and disposition.
- Primary citation
- Charter of the United Nations Act 1945; Autonomous Sanctions Act 2011; DFAT Consolidated List
Freeze and report a covered asset as soon as possible.
- Implementation action
- Do not use, deal with or make assets available to a designated person or entity; hold a suspected freezable or controlled asset, inform the Australian Sanctions Office and notify the AFP through the official route.
- Evidence to retain
- Match and ownership-control analysis, freeze timestamp, ASO and AFP notifications and system blocks.
- Primary citation
- Charter of the United Nations (Dealing with Assets) Regulations 2008, regulation 42; Autonomous Sanctions Regulations 2011, regulation 24
Use permits and releases only under verified authority.
- Implementation action
- Identify the specific sanctions framework, obtain any required DFAT permit before activity and document licence conditions, expiry, reporting and release authority.
- Evidence to retain
- Framework analysis, permit application and decision, conditions, monitoring and release record.
- Primary citation
- DFAT sanctions framework and permit guidance
09Records and regulator accessStart each seven-year clock from the record-specific statutory event.3 items+
Retain CDD records for seven years from the correct trigger.
- Implementation action
- For a business relationship, retain CDD records for seven years after it ends; for an occasional transaction, retain them for seven years after completion.
- Evidence to retain
- Relationship and transaction end dates, retention calculation, archive sample and deletion approval.
- Primary citation
- AML/CTF Act 2006, section 111
Retain transaction and AML/CTF program records for their statutory periods.
- Implementation action
- Keep designated-service transaction records for seven years from completion and program records until seven years after they cease to be relevant to demonstrating compliance.
- Evidence to retain
- Record-class schedule, trigger logic, retrieval test, legal holds and deletion log.
- Primary citation
- AML/CTF Act 2006, Part 10, including sections 107 and 116
Keep records accessible in English and producible to AUSTRAC.
- Implementation action
- Use stable identifiers and controlled access so the full customer, transaction, monitoring, reporting and governance trail is promptly retrievable and convertible into English.
- Evidence to retain
- Sample case pack, language and conversion test, access review, request log and delivery receipt.
- Primary citation
- AML/CTF Act 2006, sections 111 and 116
10Privacy, biometrics, and data breachesMap Privacy Act coverage and applicable exceptions before processing identity or biometric data.4 items+
Collect and use KYC data under an applicable privacy basis.
- Implementation action
- Determine whether the entity is an APP entity, collect only information reasonably necessary for functions or activities, provide required notice and limit use or disclosure to the primary purpose or an applicable exception.
- Evidence to retain
- Coverage memo, data inventory, purpose and authority map, notice, consent and access controls.
- Primary citation
- Privacy Act 1988; APPs 1, 3, 5 and 6
Apply heightened controls to biometrics and other sensitive information.
- Implementation action
- Treat biometric information used for automated identification or verification and biometric templates as sensitive information; obtain consent unless a statutory exception applies and document necessity and proportionality.
- Evidence to retain
- Biometric assessment, consent or exception, minimisation, accuracy tests, security and deletion controls.
- Primary citation
- Privacy Act 1988, section 6; APP 3
Protect data and assess eligible breaches promptly.
- Implementation action
- Take reasonable security steps, contain incidents, conduct a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days after becoming aware of grounds for suspicion; notify the OAIC and affected individuals as soon as practicable when required.
- Evidence to retain
- Security controls, incident chronology, assessment, OAIC statement, notices and remediation.
- Primary citation
- Privacy Act 1988, APP 11 and Part IIIC, including section 26WH
Control cross-border disclosure and vendors.
- Implementation action
- Before overseas disclosure, take reasonable steps to ensure the recipient does not breach the APPs unless an exception applies; contract and monitor security, incidents, subprocessing, return and deletion.
- Evidence to retain
- Data-flow map, APP 8 assessment, contract, recipient diligence, monitoring and incident cooperation.
- Primary citation
- Privacy Act 1988, sections 16C and APP 8
11Practical evidence packsEvidence should reconstruct onboarding, reporting and launch decisions end to end.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, authority, KYB, beneficial ownership, PEP and sanctions screening, purpose, risk, privacy records, approvals and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack and retrieval result.
- Primary citation
- Operational control supporting AML/CTF Act 2006, Part 2 and section 111
Maintain a reconstructable reporting and sanctions pack.
- Implementation action
- Link transaction, alert, suspicion chronology, statutory clock, submission, acknowledgement, confidentiality, freeze actions and authority communications.
- Evidence to retain
- Complete sampled case pack, timeline and controlled-access record.
- Primary citation
- Operational control supporting AML/CTF Act 2006, sections 41 and 43 and Australian sanctions laws
Maintain a transition-aware launch pack.
- Implementation action
- Record the service perimeter, enrolment and registration, current or legacy CDD regime, program approval, reporting forms, transfer rules, sanctions, privacy, vendors and validation before launch.
- Evidence to retain
- Signed launch pack, source register, transition matrix, uncertainty log, tests and approvals.
- Primary citation
- Official sources listed below
Primary-source register
22 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 - current compilationFederal Register of Legislation · Primary legislation
- Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 - current compilationFederal Register of Legislation · Primary delegated legislation
- Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026 - current compilationFederal Register of Legislation · Primary delegated legislation
- AML/CTF transitional rules 2026AUSTRAC · Official transition guidance
- Changes to AML/CTF obligations from 2026AUSTRAC · Official regulator guidance
- Initial customer due diligence overviewAUSTRAC · Official regulator guidance
- Ongoing customer due diligence overviewAUSTRAC · Official regulator guidance
- Suspicious matter reportsAUSTRAC · Official reporting guidance
- Threshold transaction reportsAUSTRAC · Official reporting guidance
- Record keeping overviewAUSTRAC · Official regulator guidance
- Virtual asset service providers overviewAUSTRAC · Official registration guidance
- ASIC company and organisation registersAustralian Securities and Investments Commission · Official registry guidance
- Company members-register requirementsAustralian Securities and Investments Commission · Official registry guidance
- Australian sanctions Consolidated ListDepartment of Foreign Affairs and Trade · Authoritative sanctions list
- Privacy Act 1988 - current compilationFederal Register of Legislation · Primary legislation
- Australian Privacy PrinciplesOffice of the Australian Information Commissioner · Official privacy guidance
- Australian Privacy Principles guidelinesOffice of the Australian Information Commissioner · Official privacy guidance
- FATF Australia country profile and follow-up reportsFATF · Authoritative current assessment
- Australia's fifth-round FATF mutual evaluationDepartment of Home Affairs · Official evaluation-cycle guidance
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
- Use of the Australian National FlagDepartment of the Prime Minister and Cabinet · Official national-symbol guidance
Direct answers
Australia KYC, KYB and AML questions
Who receives suspicious matter reports?+
AUSTRAC, Australia's financial intelligence unit and AML/CTF regulator, through the current AUSTRAC Online reporting route.
When must an SMR be filed?+
Within 24 hours of forming a terrorism-financing suspicion, or within three business days after the day another suspicion is formed. A limited five-business-day timing applies to qualifying legal-professional-privilege claims, but not terrorism-financing suspicion.
What cash transactions are threshold-reportable?+
A designated service involving A$10,000 or more in physical currency, including foreign-currency equivalent, generally requires a TTR within 10 business days after the transaction day.
Is there one universal CDD transaction threshold?+
No. Initial CDD is driven by commencing a designated service and the service context. Separate cash, gambling, transfer and other rules have their own scoped amounts and conditions.
How is beneficial ownership determined?+
Follow the ownership chain to natural persons and assess control by other means under the current Act and Rules. Do not substitute a company extract or an assumed universal percentage for the required analysis.
How long are AML/CTF records retained?+
Generally seven years, but the clock differs. CDD records run from relationship end or occasional-transaction completion; transaction records run from transaction completion; program records run until seven years after they cease to be relevant.
Do professional-services and real-estate businesses now have AML/CTF duties?+
From 1 July 2026, specified designated services provided by newly regulated professional, real-estate and precious-metals-and-stones businesses are covered. The service, not the occupation label alone, determines scope.
Must virtual-asset businesses register?+
Generally, a provider must be registered with AUSTRAC before providing a registrable virtual-asset service in Australia and must maintain and renew registration. Transitional Rules 2026 section 14 permits a qualifying provider of only newly registrable services that applied by 29 July 2026 to continue while AUSTRAC decides the application.
What happens on an Australian sanctions match?+
Do not deal with or make covered assets available. Hold or freeze the asset, inform the Australian Sanctions Office and notify the AFP as soon as possible through the official routes, subject to legal advice and any permit.
Is Australia on a FATF public list?+
No. Australia was absent from both FATF public lists dated 19 June 2026. It remains in FATF follow-up and absence from a list is not a low-risk finding.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 23 September 2026. Confirm the designated-service perimeter, transitional position, current Rules, AUSTRAC forms and guidance, sector licensing, sanctions measures, state or territory professional rules and privacy coverage with the competent authority and qualified Australian counsel before launch.