Obligations

AUSTRAC enforcement: audits, penalties and enforceable undertakings

AUSTRAC supervises reporting entities under the AML/CTF Act and takes a graduated approach: guidance, education, remediation, and then formal action where conduct is serious or repeated. Formal tools include audits, enforceable undertakings, infringement-style measures where available, civil penalty proceedings and criminal prosecution for the most serious failures. With Tranche 2, professional practices now sit inside that framework. This guide explains what supervision looks like in practice and how a firm should respond, without treating enforcement history as a prediction of what any particular business will face.

How AUSTRAC supervises

AUSTRAC monitors compliance through lodgements, information requests, data analytics, and engagement with individual businesses and industry bodies. It publishes guidance and risk insights, and it can examine a business's records and systems under its statutory powers. A compliance review can cover the risk assessment, the AML/CTF program, CDD records, training, reporting and the governance arrangements behind them.

Supervision is not limited to suspicious matter reporting. AUSTRAC routinely asks reporting entities to show how a customer was identified, how a risk was rated and why an SMR was or was not lodged. The quality of the retained evidence, not the software brand, determines whether a file survives that scrutiny.

The enforcement toolkit

AUSTRAC publishes enforcement outcomes, including enforceable undertakings and penalty decisions, and explains the consequences of non-compliance on its website. The pattern across published matters is consistent: failures in program design, CDD, reporting and record-keeping attract the most scrutiny, especially where a business knew of problems and did not fix them.

  • Audits and inspections of records, systems and controls
  • Enforceable undertakings that require specific remediation
  • Remedial directions and other formal directions where available
  • Civil penalty proceedings under the AML/CTF Act
  • Criminal prosecution for serious or reckless conduct
  • Published enforcement outcomes, which carry reputational cost

The penalty framework

Civil penalties under the AML/CTF Act are calculated in penalty units. From 1 July 2026, the maximum for a body corporate is 100,000 penalty units and 20,000 for another person, which AUSTRAC's published guidance states as A$36.4 million and A$7.28 million respectively. Some provisions carry criminal offences with imprisonment. Penalties are maximums; courts and AUSTRAC consider seriousness, duration, cooperation and remediation.

Individual professionals can be personally exposed. Officers who knowingly or recklessly cause a body corporate to contravene the Act can face civil penalty proceedings, so 'the firm is the reporting entity' is not a complete answer to personal accountability.

Responding to an enquiry

A well-run practice can turn an AUSTRAC enquiry into evidence of its control environment. The response should show the risk assessment, the program, the CDD file, the reporting logic and the training records - the same evidence the program was always supposed to retain.

  • Treat every AUSTRAC request seriously and respond within the stated timeframe
  • Gather the exact records requested; do not produce a selective subset
  • Involve the compliance officer and, where appropriate, external advisers
  • Remediate promptly and document what was fixed, when and how
  • Do not delete, alter or conceal records; that is a separate and serious problem

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

Frequently asked questions

What is the maximum civil penalty under the AML/CTF Act?

From 1 July 2026 the maximum is 100,000 penalty units for a body corporate and 20,000 for another person, stated by AUSTRAC as A$36.4 million and A$7.28 million. Courts determine penalties in individual cases.

Can an individual officer be penalised?

Yes. The Act includes accessorial and officer liability provisions, and civil penalties can apply to persons involved in a contravention. Officers should understand the controls rather than delegate blindly.

What is an enforceable undertaking?

A formal, published commitment by a business to take specified remediation steps. It is one of AUSTRAC's enforcement tools and can include independent reviews, program upgrades and reporting obligations.

How do we prepare for an AUSTRAC audit?

Keep the risk assessment, program, CDD evidence, training records and reporting decisions current and retrievable. When a request arrives, respond completely and on time, and fix anything the review reveals.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.