Customer Event | MCO Customer Roadshow Europe 2026 – Registration is now open
Customer Event | MCO Customer Roadshow Europe 2026 – Registration is now open
When a fire alarm sounds in your firm's office building, an appointed fire warden acts immediately. They check each room and ensure the whole firm makes it to safety. Across the Asia-Pacific (APAC) region, AML regulations and the enforcement actions behind them are telling a similar story. Red flags are raised, alerts fired, and report filings required, yet in many cases, someone failed to address those red flags in time.
On top of that, regulators keep adding rooms to the floor plan. Since 1 July 2026, Australia's AML/CTF regime has applied to lawyers and accountants, along with several other industries that previously sat outside it. In Singapore, proliferation financing now forms part of a firm's money laundering risk assessment, while Hong Kong is working on legislation that would bring virtual asset dealers and custodians into its licensing regime. For compliance teams, checking that the alarm works is still necessary. However, they also need to know whether it reaches the rooms that have only recently been built.
Our article explores the AML regulations across APAC, what has changed with AML/CFT regulation in 2026, and what 2027 is likely to bring.
If your firm also operates within Europe, read more about EU AML/CFT regulations and enforcement in our article, AML Compliance and Regulatory Enforcement Across the European Union.
Australia has made the APAC region's largest structural change. The amended AML/CTF Act and new Rules took effect for existing reporting entities on 31 March 2026. The regime then extended to Tranche 2 sectors (including legal, accounting, real estate, conveyancing, trust and company services, and dealers in precious stones and metals) on 1 July 2026.¹ Entities already enrolled on 30 March 2026 can keep using their existing customer identification procedures for some or all customer classes until 31 March 2029, provided their AML/CTF policies set out those classes and their transition dates by 1 July 2026. The new ongoing customer due diligence obligations, however, have applied to every customer since 31 March 2026.²
AUSTRAC was blunt about expectations during the transition: "Failure to manage your ML/TF risks is a serious regulatory concern now and when the AML/CTF reforms commence in 2026."¹
Enforcement has followed a familiar pattern of warnings left unanswered. In December 2025, AUSTRAC began civil penalty proceedings against two financial services businesses that had failed to lodge their annual compliance reports for 2023. Each had received an infringement notice in September 2024 and neither paid it. Katie Miller, then acting chief executive, said: "Businesses with weak AML/CTF controls are at an increased risk of criminal abuse. AML/CTF obligations are not optional."³ Both firms later admitted the contraventions, and on 26 May 2026 the Federal Court ordered them to pay penalties of AUD 50,000 and AUD 45,000 respectively, plus costs.⁴
The newly regulated sectors are getting a similar message. Since 1 July 2026, the regime has covered tens of thousands of additional businesses, and AUSTRAC has made enrolment a key focus. AUSTRAC started issuing section 167 notices to unenrolled businesses on 28 August, with CEO Brendan Thomas warning: "The time for preparation has passed."⁵
For banks, advisers and other established reporting entities, Tranche 2 matters too. Many of their clients and counterparties now carry AML/CTF obligations of their own, and some of those firms are only beginning to build the controls to meet them.
In Singapore, revised AML/CFT notices from the Monetary Authority of Singapore (MAS) have applied since 1 July 2025. Under the changes, proliferation financing is part of a financial institution's money laundering risk assessment. Firms have five business days to lodge a suspicious transaction report once suspicion is established, although that shrinks to one business day if a sanctioned party is involved.⁶ MAS has also set out when the five days begin, which is the point at which the firm concludes a report is warranted, rather than the moment an alert first appears.
In May 2026, MAS handed a Singapore trust company an SGD 300,000 composition penalty. Among the breaches, the firm had not scrutinised unusual transactions closely enough or filed the suspicious transaction reports it should have, and its staff showed a poor grasp of the risks and red flag scenarios they were meant to be watching for.⁷
Singapore's FATF/APG mutual evaluation, published on 6 May 2026, was broadly positive. It found "a competent and coordinated regime" but said the system "must be sharper in producing demonstrable and consistent risk-based results". Assessors also pointed to a relatively low number of supervisory enforcement actions, and to proliferation financing measures that were general rather than proportionate to risk.⁸ Under regular follow-up, Singapore must now report on its progress against the recommended actions, including more risk-proportionate proliferation financing measures.
December 2025 brought Malaysia some welcome news. After roughly ten years under enhanced measures, the country's FATF/APG mutual evaluation placed it on regular follow-up, which is the strongest category available. Even so, the assessors found that money laundering investigations were struggling to turn into prosecutions and convictions.⁹
A reminder of the work still to do arrived eight months later. In August 2026, Bank Negara Malaysia (BNM) and the Labuan Financial Services Authority announced compounds totalling MYR 10 million against an investment bank, made up of MYR 9 million under the Anti-Money Laundering,
Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 and MYR 1 million under the Labuan Financial Services and Securities Act 2010. During 2023 and 2024, the bank had been slow to submit 53 suspicious transaction reports, and its customer due diligence at onboarding in 2023 fell short.¹⁰ In announcing the action, BNM said: "Reporting institutions are cautioned against the risks of being exploited by criminals, whether through negligence or deliberate complicity on their part."
One late report might be blamed on a bad week. Fifty-three, on the other hand, suggests the escalation process itself broke down somewhere along the way, and nobody picked it up.
In February 2026, the Securities and Futures Commission (SFC) reprimanded and fined a Hong Kong asset manager HKD 9 million. Between August 2018 and July 2021, the firm failed to manage and disclose conflicts of interest arising from loans to its sub-funds, lacked adequate know-your-client and suitability controls, and did not maintain AML/CTF compliance records. The SFC said the failures had "the potential to undermine public confidence and damage market integrity".¹¹ Two senior individuals were also held responsible. AML/CFT failings rarely turn up on their own, and here they sat alongside wider weaknesses in governance and conflicts of interest management.
The perimeter is moving as well. On 24 December 2025, the Financial Services and the Treasury Bureau and the SFC published consultation conclusions on licensing regimes for virtual asset dealing and custodian services, with "a target of introducing the relevant bill into the Legislative Council in 2026". A further consultation on separate regimes for virtual asset advisers and portfolio managers closed in January 2026.¹² Each new licence type will bring AML/CFT obligations with it under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance.
Japan's Financial Services Agency (FSA) published revised AML/CFT guidelines on 31 March 2026. They put more weight on a risk-based approach, ongoing customer monitoring, the three lines of defence and senior management accountability. They also recognise the use of AI and machine learning in transaction monitoring, provided people retain oversight.¹³
A few months later, in July 2026, the FSA published its latest report on AML/CFT initiatives and challenges. It found varying degrees of progress among financial institutions on staffing, budgets, coordination between divisions and internal audit. The same report recorded losses from online and telephone scams of JPY 325.7 billion in 2025, 1.6 times the previous year.¹⁴ Against numbers like those, the FSA is asking a harder question than before: not whether a framework exists on paper, but whether it actually works.
The next 18 months look busier than the last. A few dates and themes stand out.
Australia's mutual evaluation. Australia is due to undergo its next FATF mutual evaluation across 2026 and 2027.¹⁵ Assessors will want to see the reformed regime working in practice, so AUSTRAC is likely to keep up the pressure on new and established reporting entities alike.
Follow-up in Singapore and Malaysia. Both jurisdictions are now on regular follow-up and will need to show progress against their recommended actions. In Singapore's case, the list includes beneficial ownership transparency and more risk-proportionate proliferation financing measures.⁸
Hong Kong's virtual asset bill. If the bill reaches the Legislative Council as planned, 2027 could see virtual asset dealers and custodians moving through licensing, with advisers and managers not far behind.¹²
Japan's effectiveness checks. Japan's next mutual evaluation is not scheduled until later in the decade,¹⁶ which leaves the FSA free to keep testing whether firms' controls do what they claim to do.
Across all four, proliferation financing is moving from footnote to firm requirement. Firms that have not yet written down how they assess it may find 2027 is the year a supervisor asks to see it.
None of the cases above turned on an obscure rule. Reports were filed late, records went unkept and red flags passed without anyone recognising them. In each one, the gap existed between a written process and what actually happened on an ordinary working day.
How firms operationalise regulatory expectations matters more than ever, as supervisors across APAC want evidence behind every policy. MCO (MyComplianceOffice) brings employee oversight and transaction oversight together for compliance teams. For example, policy attestations and training certifications can be collected alongside disclosures of conflicts of interest and outside business activities. Surveillance alerts, meanwhile, move through escalation workflows into case management. Because each step is time-stamped in an audit trail, a firm can show a regulator who reviewed an alert and what happened next.
MCO also delivers more than AML/CFT controls alone. Our complete compliance platform covers all aspects of compliance, including Employee Conflicts of Interest, MNPI and Control Room Compliance, and Compliance Program Management. Having these areas together on one platform helps firms keep oversight in one place, respond as risks change, and show supervisors that their compliance programme is working the way it should.
MCO’s AML suite helps firms strengthen their financial crime defences with automation, risk-based screening, and workflows that link each step together. Key features include:
Partner Screening: Automated matching against global sanctions and watchlists. Includes configurable rules to minimise false positives while ensuring robust coverage.
UBO Screening: Identification and verification of Ultimate Beneficial Owners, including complex ownership structures, to satisfy transparency and due diligence obligations.
Adverse Media Screening: Continuous monitoring of global news sources to detect reputational or regulatory risk signals linked to individuals or entities.
Risk-based classification: Dynamic scoring of alerts and entities based on multiple factors, allowing prioritisation of higher-risk cases.
Transaction Monitoring: Detection of unusual or suspicious transaction patterns using configurable rules and behavioural analysis, with escalation workflows to support timely investigation.
To find out how your firm can safely pass the next fire drill, learn more about MCO's compliance solutions.
The main frameworks include Australia's amended AML/CTF Act and Rules, the MAS AML/CFT notices in Singapore, Malaysia's AMLA, Hong Kong's Anti-Money Laundering and Counter-Terrorist Financing Ordinance and the FSA's AML/CFT guidelines in Japan. Each was updated or assessed in 2025 or 2026, with a shared focus on risk-based controls, timely suspicious transaction reporting and proliferation financing.
Australian financial institutions that provide designated services must enrol with AUSTRAC and maintain an AML/CTF program built on a documented assessment of their money laundering, terrorism financing and proliferation financing risks, with key decisions approved by a senior manager. They must also appoint an AML/CTF compliance officer and carry out initial and ongoing customer due diligence. On the reporting side, they lodge suspicious matter reports, threshold transaction reports and international funds transfer instructions with AUSTRAC, as well as an annual compliance report. Record keeping and regular independent evaluations of the program round out the core obligations.
Tranche 2 is the extension of Australia's AML/CTF regime to sectors including lawyers, accountants, real estate agents, conveyancers, trust and company service providers, and dealers in precious stones and metals. These businesses became regulated on 1 July 2026 and must enrol with AUSTRAC. Newly regulated businesses had until the later of 29 July 2026 or 14 days after enrolment to notify AUSTRAC of their AML/CTF compliance officer.
Under the revised MAS notices, financial institutions must file a suspicious transaction report no later than five business days after suspicion is established, or within one business day where a sanctioned party is involved.
Firms should expect Australia's FATF mutual evaluation, follow-up on recommended actions in Singapore and Malaysia, new virtual asset licensing in Hong Kong and continued effectiveness reviews in Japan. Practical priorities include documenting proliferation financing risk, testing internal escalation timelines, and keeping evidence of employee training and attestations.
Start with a written assessment of the money laundering, terrorism financing and proliferation financing risks your firm actually faces, and build policies and controls in proportion to them. From there, give each obligation a named owner, train staff to recognise red flags, and set up an escalation route that gets alerts to a decision inside the reporting deadline, for example the five business days MAS allows for suspicious transaction reports. Keep evidence as you go, including attestations, alert reviews and filing decisions, and have the framework tested through an independent review or evaluation. Smaller firms can begin with manual processes, although most move to dedicated software once volumes and evidence requests grow.
AML compliance software usually covers one or more of the following: sanctions, PEP and adverse media screening, beneficial ownership checks, transaction monitoring, and case management. Some providers specialise in a single area, while others offer broader compliance platforms. MCO (MyComplianceOffice), trusted by more than 1,500 firms, offers partner and UBO screening, adverse media screening, risk-based classification and transaction monitoring alongside employee compliance tools covering conflicts of interest, personal trading and attestations. When comparing providers, firms in APAC tend to look at regional data coverage, how alerts move through to case management, and whether the system keeps an audit trail that a regulator can review.