Obligations

Refusing or exiting an AML/CTF relationship: obligations for Australian firms

The AML/CTF regime does not only tell firms what to do when onboarding works. It also requires them to stop. A reporting entity must not provide a designated service unless applicable customer identification procedures have been carried out, and it may need to exit a relationship where CDD cannot be completed, the customer will not cooperate, or the risk cannot be managed. Refusal and exit are compliance events with their own evidence and reporting implications. This guide explains the boundaries and how to record them without creating tipping-off risk.

When refusal is required

AUSTRAC's core guidance on customer identification is explicit: a reporting entity must not provide a designated service to a customer unless applicable customer identification procedures have been carried out. If the practice cannot establish the required matters on reasonable grounds - because documents are missing, the structure cannot be explained or the customer will not cooperate - the service must not start.

Refusal is not a penalty on the customer; it is the consequence of failing the legal precondition. Record the steps taken to complete CDD, the information received, the gaps and the decision. That record matters more than the wording of any letter.

Exiting an existing relationship

Exit is a business decision made under the program's risk framework. The firm should define who decides, what steps precede exit and how the decision is evidenced. In some cases exit follows or accompanies a suspicious matter assessment; in others it is purely a risk-management call.

  • Where ongoing CDD reveals the relationship cannot be managed at the assessed risk
  • Where the customer provides false or inconsistent information
  • Where the customer refuses to provide updated KYC or source-of-funds evidence
  • Where a suspicious-matter assessment and the program support exit

Reporting and tipping-off

If refusal or exit creates a reasonable suspicion, the SMR obligation applies and protected SMR-related information must not be disclosed where disclosure could prejudice an investigation. Do not write 'we lodged an SMR' in the exit letter or tell the client the reason is a report. Use the operational reason - incomplete verification or unmanageable risk - and keep the SMR analysis in the restricted workflow.

A TTR, by contrast, is a routine report and can generally be explained in ordinary terms. The two report types remain separate, and the exit record should not blur them.

A defensible exit file

Examiners understand that exits happen. The file that explains the sequence - what was asked, what was received, what was assessed and who decided - is far stronger than a letter alone.

  • The CDD steps completed and the evidence held
  • The risk assessment and the trigger that led to refusal or exit
  • Communications with the customer, without protected SMR details
  • The decision maker, date and any management approval
  • The reporting decision: SMR, TTR, or neither, with reasons

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

Frequently asked questions

Can we provide a service while CDD is incomplete?

Generally no. Applicable customer identification procedures must be completed before providing the designated service, subject to limited delayed-CDD rules and transitional provisions. Incomplete CDD is not an inconvenience; it is a legal blocker.

Do we have to tell the customer why we refused?

Provide the operational reason where appropriate, but do not disclose protected SMR-related information. The tipping-off prohibition applies where disclosure would or could reasonably be expected to prejudice an investigation.

Is every exit a suspicious matter?

No. Exit can be a routine risk decision. Assess the facts against the statutory suspicion test and lodge an SMR only where it is met, within the applicable deadline.

What should the exit letter say?

Keep it factual and operational: the service will not proceed or the relationship will end, what happens to documents and any outstanding obligations. Do not reference reports or protected information.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.