Skip to main content
CCassandra AML
Scope checkGuidesPricingSecurityAboutSign inStart free
Menu
Scope checkGuidesPricingSecurityAboutSign inStart free
Guides/BAS agents

For BAS agents

Payroll, supplier and bank-payment authority: AML/CTF for BAS agents

5 min read · Updated 1 August 2026

Payment authority is one of the most fact-sensitive AML/CTF issues for a BAS practice. A staff member may upload a bank file without choosing any payment, while another engagement may authorise the practice to decide which creditor is paid, when and from which account. Table 6 item 3 is concerned with receiving, holding and controlling or managing property as part of directly advancing a transaction. System access alone does not resolve the question, and neither does calling the work payroll or accounts payable. The assessment must describe the legal mandate, practical discretion, payment flow, transaction connection and any statutory boundary relied on.

See the bas agents AML/CTF workspace

On this page

  1. Document the authority before analysing the service
  2. Apply receiving and controlling or managing correctly
  3. Test the transaction and direct-advancement elements
  4. Evaluate each statutory boundary without overextending it
  5. Design controls that preserve the assessed boundary
  6. Official sources
  7. Frequently asked questions

Document the authority before analysing the service

Collect the signed engagement, bank authority, system roles, approval limits and any standing instructions. Identify who creates a payment, who can edit it, who approves it, who can substitute a recipient, and whether the practice can change amount, date, source account, purpose or conditions. Confirm actual practice with staff and a sample transaction because permissions and written mandates can diverge.

Classify each payment stream separately. Payroll generated from an approved payroll record may have different controls from ad hoc supplier payments, director reimbursements, tax liabilities or transfers between related entities. Note whether the practice ever receives or holds property itself, whether it controls disbursement, or whether it directs the customer's bank or another person while exercising substantive discretion.

Apply receiving and controlling or managing correctly

AUSTRAC treats receiving, holding and controlling as a composite concept. A practice that receives money, retains it and controls its disbursement may meet that limb. Managing does not require possession; it focuses on substantive authority and discretion over the way another person's property is handled. The facts should show more than general influence or clerical implementation.

A fixed instruction can constrain discretion. If the client has pre-determined the creditor, liability, amount or calculation method, timing and purpose, and the practice cannot materially alter them, the work is less likely to be management. Authority to choose among creditors, defer or accelerate payment based on the practice's judgment, redirect money or decide its purpose points the other way. Dual approval is relevant but does not erase discretion that the practice actually exercises.

Test the transaction and direct-advancement elements

Contact with an account or payment is not sufficient by itself. The activity must form part of assisting the person in planning or executing a transaction, or otherwise acting for them in a transaction, and must directly advance it. Describe the relevant transaction rather than assuming every accounting entry qualifies. The payment may settle a supplier purchase, implement payroll, transfer an asset or support another commercial transaction.

The conclusion can differ across workflows. Preparing an aged-payables report may inform a client's decision without advancing a particular payment. Uploading approved instructions may be an administrative step but still requires analysis of the authority and statutory boundaries. Deciding how limited funds should be allocated across creditors and directing the resulting payments may involve substantive management. Record the complete test, not a single conclusion about bank access.

Evaluate each statutory boundary without overextending it

Item 3 contains boundaries for payment for the practice's own goods or services, certain payments reasonably incidental to non-designated work, payments under court or tribunal orders, specified payments involving government bodies and other listed recipients, another designated service, and Rules-based circumstances. A payment to the ATO may fall within a government-payment boundary, but that does not make every tax-related transfer or surrounding service outside scope.

The reasonably-incidental boundary has a business-level condition in AUSTRAC's guidance. Consider all services provided by the legal entity, not just its payroll department or the individual engagement. State the precise payment activity, the non-designated service to which it is incidental, the entity-wide service position and the provision relied on. Escalate uncertain or mixed payment flows rather than using a generic exemption code.

Design controls that preserve the assessed boundary

If the assessment relies on fixed instructions and limited authority, configure roles and approvals to preserve those facts. Prevent staff from creating unapproved recipients, changing destination accounts or varying the purpose of payments without documented client approval. Use callbacks or another risk-based control for bank-detail changes, segregate preparation and approval where appropriate, and log changes to mandates and permissions.

Trigger a new AML/CTF review when discretion expands, unexpected third-party funds appear, the practice is asked to conceal or split payments, destinations change without a credible reason, payments move across unexplained jurisdictions or activity is inconsistent with the known customer. Keep the authority analysis, flow diagrams, service classification, boundary reasoning, approvals and monitoring evidence with the customer file.

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

  • AUSTRAC — Professional designated services
  • Federal Register of Legislation — AML/CTF Act 2006 (current compilation)
  • AUSTRAC — Accountants industry guidance

Frequently asked questions

Does a bank login make the BAS agent a manager of client money?

Not by itself. Assess substantive authority and actual discretion, as well as the transaction and direct-advancement elements. A login restricted to preparing fixed payments differs from authority to choose, redirect or vary how the client's money is dealt with.

Does client approval always keep payment work outside item 3?

No. Client approval is relevant, but the practice may still exercise substantive discretion in selecting, structuring or directing payments before approval. Analyse the complete workflow, mandate and actual decisions instead of relying on one approval step.

Can all ATO payments be marked exempt?

Do not use a blanket label. AUSTRAC identifies tax payments to the ATO within a statutory government-payment boundary, but the actual activity and surrounding services must be assessed. Record the recipient, payment purpose, transaction and legal basis for the conclusion.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

Run the free scope checkCreate a free workspace

Keep reading

For BAS agents

AML/CTF guide for BAS agents

Read
For BAS agents

Bookkeeping versus designated services

Read
For tax agents

Client money and tax-payment boundaries

Read

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.

CCassandra AML

AML/CTF compliance workspace for Australian tax agents, accountants, lawyers, conveyancers, real estate professionals, trust and company service providers, and precious-metals and stones dealers — with designated-service decisions and review-ready records.

Owned and operated by Cassandra Research Pty Ltd, an Australian company based in Melbourne, Victoria.

Product

Create workspaceFree scope checkSign inPricingSecurity

AML/CTF guides

All guidesTranche 2 foundationsCore obligationsTax agentsBAS agentsAccountantsLawyersConveyancersReal estateTrust & company servicesPrecious-items dealersKnowledge RSS feed

Company

AboutContactEditorial standards

Legal

Privacy PolicyTerms of ServiceCookie NoticeAccessibility

Cassandra AML assists compliance work. It does not provide legal advice, guarantee compliance or imply AUSTRAC endorsement.

© 2026 Cassandra Research Pty Ltd, Melbourne, Australia. All rights reserved.