The implementation of the AUSTRAC Tranche 2 reforms represents a steep learning curve for around 100,000 Australian businesses. Lawyers, accountants, conveyancers, real estate agents, trust and company service providers, precious metals dealers, and virtual asset service providers are now required to operate within a highly regulated anti-money laundering framework.
While AUSTRAC has indicated it will take a supportive approach during the early transition phase, businesses are still expected to act in good faith and establish compliant systems. This guide highlights the fifteen most common AML compliance mistakes made by newly regulated entities and explains how your business can avoid them.
Mistakes 1 to 5: Onboarding & Enrolment Errors
1. Failing to Enrol with AUSTRAC
Many businesses assume they only need to comply if they detect suspicious activity. This is incorrect. You must actively enrol as a reporting entity with AUSTRAC if you provide designated services. The deadline was 29 July 2026; failing to enrol is a direct breach of the law.
2. Conducting KYC After the Service Has Commenced
A common error is onboarding a client, starting the work (such as drafting a contract or setting up a company structure), and asking for identity documents later. Under the Act, you must complete the Know Your Customer (KYC) verification **before** providing any designated service.
3. Accepting Photocopied ID Without Verification
Simply asking a client to email a photocopy or scan of their driver's licence is not sufficient. You must verify that the document is authentic and belongs to the client. This can be achieved by using certified copies, seeing the original in person, or using a digital verification tool that matches the document against government records.
4. Failing to Trace Ultimate Beneficial Owners (UBOs)
For corporate clients, verifying the company registration is only the first step. Many businesses fail to identify and verify the UBOs—the individuals who ultimately own or control 25% or more of the company. You must trace the ownership structure up to the living individuals who hold the power.
5. Neglecting PEP and Sanctions Screening
Failing to screen clients against the DFAT Consolidated Sanctions List and checking for Politically Exposed Person (PEP) status is a high-risk mistake. PEPs and sanctioned individuals require Enhanced Due Diligence (EDD) and senior management sign-off before you can act for them.
Warning: Providing services to a sanctioned individual, even unintentionally due to lack of screening, is a serious criminal offence carrying severe penalties and reputational ruin.
Mistakes 6 to 10: Program & Risk Assessment Flaws
6. Copying a Generic AML/CTF Program Template
While templates are useful starting points, simply signing off on a generic program that does not reflect your actual business operations, services, and risk profile is inadequate. AUSTRAC expects your written program to be tailored to your specific business.
7. Treating the Risk Assessment as a One-Off Exercise
An AML/CTF risk assessment is a living document. Many firms complete it once at the start of their compliance journey and archive it. You must review and update your risk assessment at least annually, and whenever you introduce new services or target new customer segments.
8. Not Appointing a Dedicated Compliance Officer
Every reporting entity must formally appoint an AML/CTF Compliance Officer. This person is responsible for maintaining the compliance program and acts as the liaison with AUSTRAC. Leaving this role vacant or undefined is a major compliance failure.
9. Failing to Train Staff
Compliance is not just the responsibility of the Compliance Officer. All staff who interact with clients or handle transactions must receive regular training to identify red flags and understand internal reporting procedures. You must maintain a register of this training.
10. Rating All Risks as 'Low' Without Justification
In an attempt to minimize compliance paperwork, some businesses rate all their customer and service risks as "low." During an audit, AUSTRAC will scrutinize these ratings; if you cannot produce evidence justifying why a service is low-risk, your program will be deemed non-compliant.
Mistakes 11 to 15: Operational & Reporting Failures
11. Breaching the 'Tipping-Off' Prohibition
If you submit a Suspicious Matter Report (SMR) to AUSTRAC regarding a client, it is a criminal offence to inform the client (or any unauthorised third party) that a report has been made. This is known as "tipping off" and carries penalties of up to two years' imprisonment.
12. Failing to Keep Records for 7 Years
All compliance-related records—including KYC documents, risk assessments, SMR decisions, and staff training logs—must be kept securely for a minimum of 7 years. These records must be easily retrievable in the event of an AUSTRAC audit.
13. Assuming Industry Association Guides are Sufficient
Many professional associations provide helpful AML/CTF guidelines. However, simply reading these guides does not satisfy your legal obligations. You must have your own documented, approved, and operational AML/CTF Program in place.
14. Not Having a Transaction Monitoring Program
Once a client is onboarded, you cannot assume they remain low-risk. You must have a process to monitor ongoing transactions and client behaviour to ensure they align with the client's established profile and do not exhibit suspicious patterns.
15. Failing to Lodge SMRs in Time
If you form a suspicion regarding a transaction or client, you must lodge an SMR with AUSTRAC within 3 business days (or within 24 hours if it relates to terrorism financing). Delaying the submission of an SMR is a breach of the Act.
Note: Having a clear, documented internal escalation path—where staff report suspicions to the Compliance Officer, who then decides whether to lodge the SMR—is essential to meeting these tight deadlines.
How CompliDesk Prevents Compliance Failures
CompliDesk is designed specifically to prevent these common compliance mistakes. The software guides your team through every onboarding checklist, traces beneficial ownership automatically, screens against global PEP and sanctions lists, generates compliant risk assessments, and maintains a secure, searchable 7-year audit trail.
Protect Your Business from Compliance Penalties
CompliDesk automates your AML compliance, ensuring you never miss a KYC check, PEP screen, or risk assessment. Sign up free today.
Get Started FreeFrequently Asked Questions
Related reading: Customer due diligence explained · AUSTRAC record keeping requirements · KYC requirements in Australia · Frequently asked questions