ThirdEye View

Beyond compliance: What effective AML really means

With Australia’s AML/CTF reform deadlines approaching, we examine what reporting entities need to know about critical dates, AUSTRAC’s guidance, and what it means to build a truly effective, risk-based programme.Ā 

Key dates for AML reforms

Two critical dates are approaching for Australian reporting entities: 31 March 2026 for enrolment and reforms for existing entities, and 1 July 2026 when Tranche 2 obligations take effect.Ā 

AUSTRACĀ doesn’tĀ expect perfection by these deadlines, but they do expect you to have a programme in place and be actively implementing it.Ā 

Guidance for Tranche 2 reporting entities

AUSTRAC has released comprehensive guidance centralised under the ‘Reforms’ menu onĀ AUSTRAC’s website. Tranche 2 entities should start with the starter kits designed specifically for each business type.Ā 

Here’sĀ what’sĀ critical:Ā you’reĀ building a programme that suits your business, assesses your specific risks, and puts policies in place that work for you. ThisĀ isn’tĀ about copying templates or mimickingĀ apparently similarĀ businesses.Ā We’veĀ heard stories of documentation that includes another reporting entity’s name—don’tĀ fall into that trap. Your programme needs to reflect your business’s actual risk profile.Ā 

Changes for existing reporting entities

The reforms section on AUSTRAC’s website includes extensive information for existing reporting entities. Assess which changes are relevant to your business and what you need to do about them.Ā 

What matters most is AUSTRAC’s shift towards programmes that are effective, risk-based, and outcomes-focused, in addition to being compliant.Ā 

Outcomes-focused:Ā Your programme should prevent, detect, and report financial crimes rather than just ticking compliance boxes. The real measure is whetherĀ you’reĀ actually helpingĀ to stop crime.Ā 

Risk-based:Ā Focus resources on higher risks. Not all risks deserve equal attention.Ā 

Effective:Ā You needĀ appropriate controlsĀ thatĀ actually preventĀ or detect risks, and you must continually tune them toĀ maintainĀ effectiveness. Having controls in placeĀ isn’tĀ enough ifĀ they’reĀ not producing results.Ā 

The upcoming FATF mutual evaluation will assess technical compliance and effectiveness separately, highlighting this distinction.Ā 

What effective compliance looks like

An effective programmeĀ ultimately aimsĀ to send reports to AUSTRAC that help create intelligence for law enforcement.Ā 

From aĀ transaction monitoringĀ perspective, this means having rules that cover your risks, particularly your higher risks.Ā Let’sĀ use cash transactions as an example.Ā 

It’sĀ easy to implement basic rules and claim they cover your risks. But what are those rulesĀ actually uncovering?Ā 

The tuning challenge:Ā If thresholds are too low, you swamp your team with noise and analysts become complacent. Too high and you miss genuine threats. Treating all customers equallyĀ fails toĀ address expected differences between individuals and businesses, or high-wealth and low-wealth customers.Ā 

Tune in two ways:Ā First, reduce unnecessary alerts to give analysts more time per alert. Second, uncover more reportable cases so your team focuses on what matters.Ā 

When you detect something reportable, report it promptly. Quick reporting enables AUSTRAC and other agencies to act sooner, reducing the harm caused by these crimes.Ā 

Checking the three values:Ā 

Risk-based:Ā Cash monitoring is proportionate if cash is high-risk for your business. Segment based on actual risk—business customers mightĀ warrantĀ different rules than personal customers.Ā 

Effective:Ā You’reĀ picking up transactions that need reporting without excessive noise, andĀ you’reĀ actively tuning rules as you learn.Ā 

Outcomes-focused:Ā You’reĀ reporting promptly to help prevent further crimes. The test is whether your work stops financial crime, not just satisfies compliance.Ā 

The analyst question:Ā When your rule raises an alert, do your analysts know how to investigate it effectively? Do they have the knowledge, skills, and time to do the job properly, or are they rushing through without proper consideration?Ā 

Key takeaways

Compliance is important—you need policies, processes, and procedures to detect and report money laundering, terrorism financing, and proliferation financing. But complianceĀ isn’tĀ enough. Your programme must produce the right outcomes:Ā 

  • Meet deadlines with genuine progress:Ā AUSTRAC expects implementation underway, not perfectionĀ 
  • Build your own programme:Ā Use guidance to create one that reflects your actual risks, not copied templatesĀ 
  • Focus on effectiveness:Ā Ask whether your controlsĀ actually preventĀ and detect financial crimeĀ 
  • Tune continuously:Ā Rules and processes should evolve as you learn what worksĀ 
  • Invest in your team:Ā Ensure analysts have the knowledge, skills, and time to investigate properlyĀ 

The reforms are an opportunity to build programmes that genuinely protect our communities.Ā 

 This blog is based on the February 2026 episode of ThirdEye View, hosted by Jing Zhang, Business Development Manager, and Colin Dixon, CAMS-certified AML Solutions Specialist at ThirdEye. Colin has been with ThirdEye since its inception in 2012 and works closely with clients to help them maximise their platform capabilities.

Latest intelligence

Stay sharp with expert insights, tools, and intelligence that keeps you ahead of financial crime threats.