AML/CTF for Accountants

AML/CTF obligations for Australian accountants: a practical 2026 guide

Certain services provided by accountants have been brought within Australia's anti-money laundering and counter-terrorism financing regime from 1 July 2026.

That does not mean every accounting firm is automatically regulated for everything it does. The starting point is the services the firm actually provides. If an accounting business provides one or more designated services with the required geographical link to Australia, AML/CTF obligations can apply to that part of the practice.

For many firms this creates a new compliance layer alongside existing obligations to the Tax Practitioners Board, professional bodies, privacy law and normal client acceptance procedures.

This guide gives accounting firms a practical starting point. It is general information and should be read with AUSTRAC's current guidance and the legislation that applies to the firm's circumstances.

Published 23 August 2026. Last reviewed 23 August 2026. Technically reviewed by the Taxpartna tax team.

Start with the services, not the job title

An accountant is not regulated merely because the business describes itself as an accounting firm. The question is whether the business provides a service that is listed as a designated service under the AML/CTF legislation.

For professional services, the categories include certain work involving:

  • buying, selling or transferring real estate
  • buying, selling or transferring a body corporate or legal arrangement
  • receiving, holding, controlling or managing another person's property to help with a transaction
  • organising or assisting with equity or debt financing involving a body corporate or legal arrangement
  • selling or transferring a shelf company
  • creating or restructuring a body corporate or legal arrangement
  • acting, or arranging for a person to act, in certain positions in a body corporate or legal arrangement
  • providing a registered office or principal place of business address in specified circumstances

A firm that prepares annual financial statements and tax returns may have a different AML/CTF position from a firm that regularly establishes trusts and companies, assists with business acquisitions, restructures ownership arrangements or handles client money.

The detail matters. Firms should map their actual service lines against AUSTRAC's current designated service guidance rather than assume that all accounting work is either in or out. Our companion page on which accounting services are AML/CTF designated services works through the common service lines.

What changes when an accounting firm is regulated?

Where a firm provides a designated service, the AML/CTF regime is not simply an extra identity check at onboarding. It requires a risk-based framework for how the business identifies, understands and responds to money laundering, terrorism financing and proliferation financing risk.

The main areas a firm needs to deal with are set out below.

Enrolment with AUSTRAC

A business that provides a designated service must consider its enrolment obligations with AUSTRAC.

For newly regulated businesses that were providing a designated service from 1 July 2026, AUSTRAC identified 29 July 2026 as the usual enrolment date. A firm that starts providing a designated service later should check the current enrolment timeframe that applies to it.

Enrolment is not the end of the process. It is the point at which the business enters a regulated framework with continuing obligations.

An AML/CTF program

A regulated accounting firm needs an AML/CTF program that is appropriate to the nature, size and complexity of the business.

For a smaller practice, the program should still be a working document. It should explain how the firm:

  • identifies the money laundering and terrorism financing risks relevant to its services
  • assesses customers and services by risk
  • assigns responsibility for AML/CTF compliance
  • completes customer due diligence
  • deals with higher-risk situations
  • monitors customers where ongoing obligations apply
  • identifies and escalates suspicious activity
  • keeps required records
  • trains relevant staff
  • reviews whether the program is actually operating as intended

AUSTRAC has published accountant-specific material and a starter kit intended to help smaller firms build a program proportionate to their circumstances.

Customer due diligence

Initial customer due diligence is more than verifying a driver's licence or passport.

Depending on the customer and the service, a firm may need to establish matters including:

  • the customer's identity
  • the identity and authority of a person acting for the customer
  • beneficial owners where the customer is not an individual
  • whether relevant people are politically exposed persons
  • whether relevant people are designated for targeted financial sanctions
  • the nature and purpose of the business relationship or transaction
  • source of funds or source of wealth where the rules require it

The firm should be able to show how those matters were established on reasonable grounds. Our customer due diligence checklist for accounting firms sets out a practical order of work.

Customer risk assessment

The AML/CTF framework is risk based. That means the same level of checking will not necessarily be appropriate for every customer.

Risk factors can include the type of service, ownership structure, jurisdiction, transaction pattern, delivery channel and other facts known to the practice.

A simple Australian family business with transparent ownership may present a different risk from a newly formed structure with foreign beneficial owners, unexplained third-party funding and an urgent transaction involving multiple jurisdictions.

The important point is not to label every unusual client as suspicious. It is to have a consistent process for identifying risk, recording the assessment and applying extra controls when the circumstances justify them.

Politically exposed persons and sanctions

A regulated firm needs procedures for establishing whether relevant people are politically exposed persons and whether targeted financial sanctions apply.

A PEP result is not automatically a reason to refuse a client. It is a risk factor that may trigger additional requirements depending on the circumstances and the type of PEP involved.

Sanctions are different. A sanctions match can have serious legal consequences and should be escalated immediately under the firm's procedures.

Ongoing customer due diligence

AML/CTF is not limited to the first day of the relationship. Where ongoing customer due diligence applies, firms need processes to identify material changes and unusual activity over time.

For an accounting practice, that may mean paying attention when the client's ownership, controllers, activities, transaction profile or jurisdictions change materially from what was originally understood.

Suspicious matter reporting

A firm that forms a suspicion in the circumstances covered by the legislation may have a suspicious matter reporting obligation.

The firm's procedures should make it clear how staff raise concerns internally, who reviews them, how the decision is documented and how reports are submitted where required.

Staff should not be left to decide these matters informally or make their own disclosures to the client. The firm's policy should address escalation, confidentiality and tipping-off risks.

Record keeping

A regulated firm needs records that demonstrate the steps taken under its AML/CTF program.

Useful records may include:

  • identity and verification material
  • beneficial ownership information
  • PEP and sanctions checks
  • customer risk assessments
  • enhanced due diligence material
  • source of funds or source of wealth evidence where relevant
  • internal escalations and decisions
  • training records
  • program reviews and updates

The point of the record is not simply to prove that a box was ticked. A future reviewer should be able to understand what the firm knew, what it checked and why it reached the position it did.

Existing clients need to be considered separately

Firms should not assume that every long-standing client needs to be onboarded from scratch in exactly the same way as a new client.

AUSTRAC has specific rules for pre-commencement customers and circumstances that can trigger additional due diligence. The correct treatment depends on the relationship, the designated services provided and subsequent risk events.

For firms with a large existing client base, this is an important implementation issue. A sensible approach is to identify which existing clients actually receive designated services and then apply the transitional rules and the firm's risk-based procedures to that group.

AML/CTF and normal tax work are different compliance systems

Accounting firms already complete client verification for tax practice purposes and many have detailed client acceptance processes.

Those controls are useful, but they should not be treated as automatically satisfying the AML/CTF regime.

TPB client verification is directed to tax practitioner obligations and identity risks in the tax system. AML/CTF customer due diligence is directed to financial crime risk and includes matters such as beneficial ownership, customer risk, PEPs, sanctions and, in some cases, source of funds and source of wealth. We compare the two regimes in AML/KYC vs TPB client verification.

There will be overlap in the information collected. The legal purpose and the required process are not the same.

Where Taxpartna fits

Taxpartna includes AML/KYC screening as part of its broader quality assurance platform for Australian accounting firms.

The screening can assist a practitioner by bringing together information relevant to areas such as beneficial ownership, sanctions, PEPs, industry risk and adverse media for the firm's assessment.

It does not create the firm's AML/CTF program, decide whether a service is designated, make a suspicious matter reporting decision or make the firm compliant by itself.

Those responsibilities remain with the reporting entity and the people responsible for its AML/CTF program.

Taxpartna is most useful as a supporting control inside a process the firm has already designed. The software can help organise and surface information. The firm still decides what the information means and what action is required. Learn more about Taxpartna's features.

A practical starting list for accounting firms

For a firm that has not yet completed its implementation work, a sensible starting list is:

  1. 1Map every service the practice provides against AUSTRAC's professional designated services.
  2. 2Identify which entities within the group actually provide those services.
  3. 3Confirm enrolment obligations and status.
  4. 4Appoint responsibility for the AML/CTF program.
  5. 5Document the firm's risk assessment.
  6. 6Build or adapt the AML/CTF program.
  7. 7Set the customer due diligence procedure for each relevant customer type.
  8. 8Decide how beneficial ownership, PEPs and sanctions will be checked.
  9. 9Establish an escalation process for higher-risk or suspicious matters.
  10. 10Train the people who provide or support designated services.
  11. 11Decide what records will be retained and where.
  12. 12Set a timetable for monitoring and review of the program.

Authoritative sources

AML/CTF obligations depend on current legislation and AUSTRAC guidance. The following primary sources should be checked when this page is technically reviewed or materially updated.

Frequently asked questions

No. The regime applies by reference to designated services. An accounting firm needs to consider the services it actually provides and whether those services meet the legislative requirements. See which accounting services are AML/CTF designated services.

Yes. The expanded regime applies from 1 July 2026 to relevant designated services provided by newly regulated sectors including certain accounting and professional service providers.

Not necessarily. A firm should compare its work against the designated services rather than assume that ordinary tax compliance work is itself regulated. Related transaction, structuring or entity services can change the position.

No. Screening can support customer due diligence and risk assessment, but compliance requires the firm's broader AML/CTF program, governance, procedures, reporting and record keeping.

No. Taxpartna can assist with information gathering and risk indicators. The reporting entity remains responsible for assessing suspicious matters and meeting any reporting obligation.

Important information. This page provides general information only and is not legal advice. AML/CTF obligations depend on the services provided and the circumstances of the business and customer. Accounting firms should use AUSTRAC's current guidance and obtain professional advice where required. Taxpartna is a quality assurance assistance platform. It does not provide legal advice, tax agent services or AML/CTF compliance certification. Professional judgements and regulatory decisions remain with the relevant practitioner and reporting entity.