Mongolian fintech pioneer chooses ThirdEye to power its Australian compliance operations.
This month, we unpack AUSTRAC’s dual role as both guide and enforcer – the guidance built to help you comply, the tranche 2 enrolment milestone now behind us, and the recent enforcement action against bet365, Sportsbet and Cryptolink for those who didn’t.
Why this matters
AUSTRAC’s mission is simple: preventing, detecting and responding to criminal abuse of the financial system. In practice, that has two faces – a supportive side offering guidance and starter kits, and an enforcement side of suspensions, undertakings and civil penalties.
Most businesses should never see that second side. Follow the guidance, understand what it means for your business, and you’ll never need to find out what AUSTRAC’s hard side looks like.
Start with the guidance
AUSTRAC’s obligations and guidance hub has grown substantially over the past year or two, and it’s the right place to start. It’s also precise about its language: “you must” means exactly that, “we expect” means you most likely need to do it (unless you can justify an alternative under audit), and “you may” or “you should” signals good practice rather than a hard requirement.
Ignoring an obligation isn’t an option in any of these cases. Advisors can help if interpreting the guidance yourself isn’t feasible, and newly regulated tranche 2 entities can also draw on AUSTRAC’s sector-specific “starter kits.”
Tranche 2: the enrolment deadline has passed
The good news, according to AUSTRAC CEO Brendan Thomas: 62,000 tranche 2 entities have enrolled, and some are already submitting suspicious matter reports.
The less good news: the enrolment deadline passed a few weeks ago, and a large number of businesses still haven’t enrolled. AUSTRAC has made clear it’s ready to act against those that haven’t. Enrolment itself isn’t hard – tick that box and avoid enforcement action. Building your full AML/CTF programme is the bigger job, but that shouldn’t delay enrolling.
When guidance goes unheeded
AUSTRAC’s “consequences of not complying” page isn’t hypothetical. In the past month alone, three cases show what the hard side looks like:
AUSTRAC suspended Cryptolink’s registration for three months, taking its 96 crypto ATMs offline after the company failed basic reporting obligations – despite already having been through one enforceable undertaking.
AUSTRAC started an enforceable undertaking with bet365, requiring the bookmaker to “overhaul its systems” and rebuild its risk assessment approach from the ground up – a major, costly and disruptive programme of work.
AUSTRAC finalised its enforceable undertaking with Sportsbet, more than two years after it was first put in place.
An enforceable undertaking is legally binding – and, as these cases show, not a quick fix. It’s far more effective to put your own programme in place, on your own terms, than to have AUSTRAC force your hand.
Staying on top of what comes next
Keeping up to date with your regulator is critical. Follow AUSTRAC and CEO Brendan Thomas on LinkedIn, along with ACAMS’ active Australasian chapter and its regular webinars. It’s also worth watching New Zealand’s DIA and bodies like the FATF, since the common ground across jurisdictions outweighs the differences.
What this means for your AML programme
The message this month is simple: there’s plenty of guidance and plenty of advisors to help you apply it and use technology effectively. You can either do the job properly, on your own terms – or be prepared to face the consequences.
This blog is based on the August 2026 episode of ThirdEye View, hosted by Jing Zhang, Business Development Manager, and Colin Dixon, CAMS-certified AML Solutions Specialist at ThirdEye. Colin has been with ThirdEye since its inception in 2012 and works closely with clients to help them maximise their platform capabilities.