Skip to main content
CCassandra AML
Scope checkGuidesPricingSecurityAboutSign inStart free
Menu
Scope checkGuidesPricingSecurityAboutSign inStart free
Guides/BAS agents

For BAS agents

AML/CTF for BAS agents: a service-based compliance guide

5 min read · Updated 1 August 2026

From 1 July 2026, a BAS agent can fall within Australia's expanded AML/CTF regime when the business provides a professional designated service with the required Australian link. Registration as a BAS agent does not itself create the obligation, and routine bookkeeping or BAS preparation is not automatically regulated. The practical test is the service actually delivered. Work involving company or trust creation, a change to the legal form of a body corporate or legal arrangement, specified transaction assistance, discretionary management of client property, nominee roles or registered-office services may be captured. Every practice therefore needs a documented service inventory before deciding whether it must enrol with AUSTRAC and operate an AML/CTF program.

See the bas agents AML/CTF workspace

On this page

  1. Start with services, not professional labels
  2. Decide the reporting-entity position before the service starts
  3. Put CDD at the correct point in the workflow
  4. Monitor the service and keep evidence of decisions
  5. Use the AUSTRAC starter materials with practice-specific judgment
  6. Official sources
  7. Frequently asked questions

Start with services, not professional labels

Review each service from instruction to completion and compare the active steps with table 6 of the AML/CTF Act. A broad label such as bookkeeping, virtual CFO, business advisory or company secretarial work is not decisive. Identify the legal or commercial outcome, what authority the practice accepts, whether the work directly advances that outcome and which person receives the service. Keep a reasoned in-scope or outside-scope record for each material service line.

Common review points for a BAS practice include forming a company or express trust, changing the legal form of a body corporate or legal arrangement, helping execute a sale or transfer of a business vehicle, arranging specific entity-related equity or debt finance, receiving and controlling or managing property for a transaction, acting or arranging for someone to act as a nominee officer or trustee, and allowing an address to be used as a registered office or principal place of business. The facts, not how the invoice is worded, determine the result.

Decide the reporting-entity position before the service starts

If the same legal entity carries on a business providing a designated service, it must address the applicable enrolment, program and operational obligations. Do not assess teams as though they were separate businesses when they operate through one entity. Conversely, do not assume every client and every bookkeeping task becomes regulated merely because the business has one captured service. Scope the designated service and its customer population accurately.

Build the AML/CTF program before providing the captured service. The program should reflect the practice's real customers, services, delivery channels and countries, explain how risk is assessed, and set out initial and ongoing CDD, enhanced CDD, transaction monitoring, suspicious-matter escalation, reporting, record keeping, personnel controls, training, oversight and independent evaluation. A generic policy that does not match the practice's mandates or payment workflows is not an operational program.

Put CDD at the correct point in the workflow

Establish the customer before collecting documents. Identify anyone acting for the customer and verify their authority. For an entity, collect and verify the information required for its customer type, understand ownership and control, identify relevant beneficial owners, and understand the purpose and intended nature of the relationship. Apply PEP and targeted-financial-sanctions checks and the practice's risk assessment at the points required by the program.

Initial CDD is ordinarily completed before the designated service is provided. That means the workflow needs an effective hold before formation documents are lodged, a regulated transaction is advanced or discretionary authority is exercised. Define what evidence permits release, who can approve a higher-risk customer, how incomplete or inconsistent information is escalated, and when the practice will decline, delay or stop work while considering its reporting duties.

Monitor the service and keep evidence of decisions

Ongoing controls should focus on the designated-service relationship. Compare actual activity with the customer's expected purpose and profile, keep customer information current, review unusual payment or instruction patterns and trigger enhanced CDD when the legal threshold is met. Staff need a confidential route to the AML/CTF compliance officer for facts that may require a suspicious matter report. Avoid telling the customer about a report or investigation in a way that could breach tipping-off restrictions.

Retain service-scope decisions, CDD evidence, representative authority, risk assessments, monitoring and screening outcomes, internal escalations, reporting records, approvals, program versions and training evidence for the applicable retention periods. Schedule review triggers for new service lines, new banking authority, entity creation, registered-address offers, ownership changes or work that moves from general advice into a specific transaction. Those triggers keep an earlier outside-scope conclusion from becoming stale.

Use the AUSTRAC starter materials with practice-specific judgment

AUSTRAC's accountant starter kit can help some small accounting practices structure a program, but it is not a universal substitute for analysing a BAS practice's services and risk. Check the kit's suitability criteria and customise every control. A practice with complex structures, extensive offshore work, unusual payment authority or services beyond the kit's assumptions may need a different or more extensive program.

Assign a responsible owner, map the services, decide the enrolment position, remediate customer and payment workflows, train affected staff and test the controls against realistic files. Review the current Act, Rules and AUSTRAC guidance whenever a service changes. The compliance result should remain explainable from the underlying law and facts rather than from a marketing label or software setting.

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

  • AUSTRAC — Professional designated services
  • Federal Register of Legislation — AML/CTF Act 2006 (current compilation)
  • AUSTRAC — Accountants industry guidance
  • AUSTRAC — Accountant program starter kit

Frequently asked questions

Does every registered BAS agent need to enrol with AUSTRAC?

No. The trigger is carrying on a business that provides a designated service with the required geographical link, not holding a BAS agent registration. Inventory the actual services and document the legal conclusion. A practice that provides a captured table 6 service must then address the applicable obligations.

Is ordinary BAS preparation a designated service?

Ordinary BAS preparation is not automatically designated. However, the surrounding engagement may include a separate captured service, such as discretionary management of client funds, company or trust creation, transaction execution, a nominee arrangement or a registered-office service. Assess each component on its facts.

When did the expanded professional-services regime apply?

The expanded regime for newly regulated professional designated services commenced on 1 July 2026. Use current AUSTRAC guidance, the current compilation of the AML/CTF Act and the Rules when classifying services and setting operational deadlines.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

Run the free scope checkCreate a free workspace

Keep reading

For BAS agents

Bookkeeping versus designated services

Read
For BAS agents

Payment authority for BAS agents

Read
For BAS agents

Small-business KYB for BAS agents

Read

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.

CCassandra AML

AML/CTF compliance workspace for Australian tax agents, accountants, lawyers, conveyancers, real estate professionals, trust and company service providers, and precious-metals and stones dealers — with designated-service decisions and review-ready records.

Owned and operated by Cassandra Research Pty Ltd, an Australian company based in Melbourne, Victoria.

Product

Create workspaceFree scope checkSign inPricingSecurity

AML/CTF guides

All guidesTranche 2 foundationsCore obligationsTax agentsBAS agentsAccountantsLawyersConveyancersReal estateTrust & company servicesPrecious-items dealersKnowledge RSS feed

Company

AboutContactEditorial standards

Legal

Privacy PolicyTerms of ServiceCookie NoticeAccessibility

Cassandra AML assists compliance work. It does not provide legal advice, guarantee compliance or imply AUSTRAC endorsement.

© 2026 Cassandra Research Pty Ltd, Melbourne, Australia. All rights reserved.