Before the service: scope and enrol
Routine tax return preparation, BAS lodgement and general tax advice are not designated services on their own. The practice becomes a reporting entity when it provides a designated service - for example, taking active steps that directly advance creation of a company or express trust, including the trust component of an SMSF.
- Test each engagement against table 6: entity formation, restructuring, specified transactions, item 7 and 8 roles, and item 9 address services
- Record the service decision and the boundary for routine tax work
- Confirm enrolment with AUSTRAC and the compliance officer appointment
- Check whether the practice risk assessment covers the services actually offered
Onboarding: identify before you act
Verification does not require buying electronic checks. A documented manual path can satisfy the obligation, but the file must show what was verified, from which source, and when. Keep the identity evidence connected to the exact client and the service.
- Identify the client and verify identity before providing the designated service
- For companies and trusts, map beneficial owners and controllers
- Screen customers and beneficial owners for PEPs, sanctions and adverse media
- Record the risk rating and the reason for it
During the relationship: monitor and report
Tax practices are not immune to suspicious activity: a client's 'restructure' can be a layering exercise, and a trust can be a shell. The obligation is to assess the pattern, not to assume the professional relationship explains it.
- Apply ongoing CDD on risk-based cycles and trigger events
- Review source-of-funds explanations where the engagement or payments are unusual
- Lodge an SMR within three business days (24 hours for terrorism financing) where suspicion forms
- Report a TTR for A$10,000 or more of physical currency connected to a designated service
- Protect SMR-related information from tipping off
Records and training
AUSTRAC can ask a tax practice to demonstrate how a scope decision was made and why a file was or was not escalated. A checklist is only as good as the evidence it produces, so treat every step as a record to keep, not a box to tick.
- Retain CDD, transaction, reporting and training records for the required period
- Store evidence with restricted access and an audit trail
- Deliver role-based AML/CTF training and record completion
- Set the independent-evaluation and review calendar
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Does every tax engagement need AML/CTF checks?
No. The trigger is a designated service. Routine tax returns and BAS lodgements are not designated on their own. Each engagement should be tested and the decision recorded.
What is the most common AML gap in tax practices?
Treating an SMSF or company 'setup' as routine administration when the practice's active steps directly advance the creation of the legal structure. The scope analysis and the CDD file must match.
Can we verify identity after the return is lodged?
Initial CDD must be completed before providing the designated service, subject to limited delayed-CDD rules and transitional provisions. Delayed CDD is not a general convenience.
What records should a tax practice keep for AUSTRAC?
The service-scope record, risk assessment, program, CDD and verification evidence, transaction and report records, and training records for the applicable retention periods - commonly seven years.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.