For trust & company services
Refusing or exiting TCSP clients after suspicious activity
A suspicious event does not produce one automatic customer outcome. An Australian trust and company service provider may need to pause instructions, seek more information, apply enhanced CDD, restrict a service, refuse new work, continue under controls or end the relationship. Separately, reasonable grounds for a suspicion may trigger a suspicious matter report. AUSTRAC guidance makes clear that submitting an SMR does not automatically require a reporting entity to stop serving the customer, but the entity must manage the risk and consider whether continuing is appropriate if it cannot do so. The difficult operational task is to make a defensible risk decision without revealing protected SMR information. This guide separates investigation, reporting and commercial exit so staff do not improvise at the point of concern.
See the trust and company services AML/CTF workspacePause and preserve before making the relationship decision
When unusual activity is identified, preserve the instruction, documents, communications, customer history, ownership information and relevant system records. Limit access to personnel who need the information and keep potential-SMR analysis out of routine notes or customer-visible systems. A rushed closure can destroy context, increase the risk of a prejudicial disclosure or leave ongoing obligations unmanaged.
Triage any immediate sanctions, fraud, asset or safety issue under the appropriate procedure. Decide whether the requested act can be paused without creating another legal or contractual problem. The AML/CTF officer should coordinate the suspicion assessment, while authorised operational or senior personnel make the service and risk-acceptance decision under documented delegations.
Assess suspicion separately from customer risk appetite
Review all relevant material promptly and ask whether there are reasonable grounds for a suspicion described by section 41 of the AML/CTF Act. Relevant facts may include opaque ownership, false or inconsistent documents, unexplained nominee arrangements, implausible formation purposes, use of a registered address to conceal activity, unexplained source of funds or instructions from an undisclosed controller. These are indicators, not automatic findings: one strong fact can be sufficient while several indicators can have a coherent innocent explanation. Assess the totality and do not wait for proof once reasonable grounds exist.
A customer can exceed the organisation's risk appetite without creating an SMR obligation, and an SMR can be required even if the organisation can continue under enhanced controls. Keep the two decisions linked but distinct. Record the evidence, analysis, time the suspicion was formed, decision-maker and basis for the service outcome without circulating the protected report more widely than necessary.
Meet the SMR deadline and tipping-off controls
An SMR relating to terrorism financing is generally due within 24 hours of forming the suspicion; other suspicions are generally due within three business days after the day the suspicion is formed. Submit through AUSTRAC Online using the form applicable to your enrolment position. The narrative should distinguish facts from inference, identify the relevant parties and explain why the activity is unusual for this customer and service.
The current section 123 offence is prejudice based. It applies to disclosure of specified protected information where the disclosure would or could reasonably be expected to prejudice an investigation. Assess what information would be disclosed, to whom, how and when; it is not necessary to know that an investigation has started. As a core control, do not tell a customer that an SMR is being considered, is required or has been submitted where that disclosure could prejudice an investigation, and do not expose internal material from which the same could be inferred. Ordinary KYC enquiries, legitimate service communications and permitted disclosures can still occur when they are framed and controlled so they do not create that prejudice risk; other confidentiality and privacy laws still apply.
Choose to continue, restrict, refuse or exit
If the risk can be managed, conditions might include senior approval, enhanced CDD, verification from additional sources, tighter service limits, removal of role or money-handling services, more frequent monitoring or a requirement that instructions come through verified channels. Enhanced CDD is required where an SMR must be submitted in relation to the customer and the TCSP intends to continue providing a designated service. Design the measures and customer communications so they do not disclose protected information in a way that would or could reasonably be expected to prejudice an investigation.
If the risk cannot be managed, document the decision not to commence or continue the designated service. Check contractual, professional, corporate, privacy and record-retention duties before ending appointments or registered-office arrangements. Plan statutory filings, transfer of records and handover controls without assisting concealment or obstructing an investigation. Where possible, give a genuine neutral reason consistent with your terms and risk policy, not a statement that refers to suspicious conduct or reporting.
Close the operational loop
An exit does not erase AML/CTF records or the need to respond to AUSTRAC. Retain the scope, CDD, monitoring, investigation, approval, reporting and exit evidence for the applicable period and restrict SMR material appropriately. Remove access, authorities and service permissions at the correct time, monitor residual transactions or correspondence and verify that required corporate or address changes have been completed.
Review the event for wider control lessons. Similar customers, nominee arrangements, staff practices or formation channels may need additional monitoring. Update risk assessments, policies, training and alert logic where the event exposed a gap, but avoid using details that unnecessarily disclose protected SMR information.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Must a TCSP terminate every customer after submitting an SMR?
No. An SMR does not automatically require termination. The TCSP must manage the ML/TF risk and apply enhanced CDD where an SMR is required in relation to the customer and it intends to continue providing a designated service. It should consider restriction or exit where the risk cannot be appropriately mitigated. Other legal, professional and contractual duties may also affect the decision.
Can the TCSP tell a client it is leaving because of suspicious activity?
Apply the current prejudice-based test. Do not disclose specified SMR-related information where the disclosure would or could reasonably be expected to prejudice an investigation. A business can communicate genuine service, documentation or risk-policy requirements and may give an accurate neutral reason for exit, but the audience, content, timing and channel must be checked for prejudice risk and other confidentiality duties.
Can an enquiry or refused instruction still require an SMR?
Potentially. The section 41 test is not limited to successfully completed work. Assess what the person requested, the information obtained and whether reasonable grounds for a relevant suspicion arose. Refusing the service does not by itself remove a reporting obligation.
Who should approve a high-risk TCSP exit?
Your AML/CTF policies and governance delegations should identify the authorised decision-maker. The AML/CTF officer commonly manages the suspicion and reporting process, while a senior manager or other authorised person approves high-risk continuation, restriction or exit. Keep access to protected SMR information narrower than access to the ordinary service decision.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.