Customer Event | MCO Customer Roadshow Europe 2026 – Registration is now open
Customer Event | MCO Customer Roadshow Europe 2026 – Registration is now open
AUSTRAC (The Australian Transaction Reports and Analysis Centre) has released its regulatory priorities for 2026-27, revealing a practical message for financial firms. A compliance programme on paper will not survive scrutiny. AUSTRAC wants proof that it works in everyday operations.
This is the first full year with Tranche 2 inside the regime. The reforms extend Australia's anti-money laundering and counter-terrorism financing (AML/CTF) rules to additional financial and professional services firms. Trust and company service providers, accountants and tax practitioners, and virtual asset service providers (VASPs) all came into scope on 1 July 2026. They now sit alongside thousands of already-regulated firms, judged against the same logic: show that controls run in daily practice, not just in a document.
The shift is subtle but decisive. Holding a policy is the starting point. Proving it works is the obligation, and that is what the year ahead will measure.
AUSTRAC has framed its expectations as a short checklist. Newly regulated entities must complete the following:
It’s a short list, but each item has to be real. Through these steps, AUSTRAC wants to see effective risk management by reporting entities, not a set of documents produced for inspection.
The enrollment window closed on 29 July 2026. A firm that begins providing a designated service now has 28 days to apply to enrol, and 14 days to notify AUSTRAC once it appoints its compliance officer. AUSTRAC expects the checklist to be complete by 30 June 2027, with the first compliance report due between 1 July and 30 September 2027.
AUSTRAC has said where it will look first. Its sharpest attention falls on entities that have failed to enrol, on any business recklessly involved in, or complicit with, criminal activity. AUSTRAC is making it known that firms in newly regulated sectors will not quietly avoid regulatory focus.
Established sectors are not exempt. The regulator says it will keep watching long-regulated firms for “AML/CTF programs that are not applied in their daily operations”. A programme written years ago can drift from practice as products, clients and channels change. That gap, between the document and the day-to-day, is exactly what supervision now targets.
AUSTRAC reads suspicious matter reports (SMRs) as a signal of how well a programme works, and the volume is climbing. Reports from payment platforms rose 77 per cent in the 2025-26 financial year, and reports from mutual banks rose 37 per cent. Higher volume alone does not satisfy the regulator.
AUSTRAC wants better reports, not just more of them. It says it will “engage with reporting entities and cohorts whose SMRs are consistently poor quality”. Quality means detail and timeliness. A firm must submit an SMR within three business days of forming a suspicion, or within 24 hours where the suspicion relates to terrorism financing.3 Late or thin reporting is now a supervisory flag in its own right.
The reforms retire the old “digital currency exchange” label and replace it with the broader “virtual asset service provider”. However, the change is much more than a cosmetic one. As AUSTRAC Chief Executive Brendan Thomas put it, the shift “reflects how this sector has evolved”, and the expanded definition now captures custody, brokerage and other virtual asset services, not only exchanges.
“This is more than a name change. It reflects how this sector has evolved.”
Brendan Thomas, AUSTRAC Chief Executive
AUSTRAC has already moved from words to supervision. Two campaigns are live. A “Ramps and Rails” campaign examines 36 over-the-counter crypto-to-cash operators, and a second campaign assesses 27 local exchanges on reform readiness and governance.4 The regulator is testing customer due diligence, transaction monitoring, crypto-specific risk assessments and the effectiveness of the wider programme. VASPs also face travel rule obligations on virtual asset transfers. For providers, the message is direct. Confirm whether you meet the VASP definition, refresh your AUSTRAC registration, and build risk management that reflects genuine crypto typologies rather than a generic template.
How firms operationalise AUSTRAC's expectations will make the difference between a programme that passes inspection and one that does not. Regulatory technology (RegTech) is what turns a written AML/CTF programme into one a regulator can see running.
Compliance teams often ask which tools help them evidence a programme in daily operation. A purpose-built RegTech platform, such as MCO (MyComplianceOffice), brings obligation mapping, policy governance and transaction controls into one auditable system.
MCO's KYC and AML compliance solution connects the programme layer to the execution layer. With MCO, firms can:
With obligations, policy, monitoring and evidence in one place, firms can show AUSTRAC not only that controls exist, but that they work.
Ready to turn AML obligations into demonstrated assurance? See the MCO complete compliance suite in action.
1 AUSTRAC, “Our regulatory priorities for 2026-27.” https://www.austrac.gov.au/about-us/policies-and-governance/our-policies/our-regulatory-expectations-and-priorities/our-regulatory-priorities-2026-27
2 AUSTRAC, “AML/CTF reform.” https://www.austrac.gov.au/business/amlctf-reform
3 AUSTRAC, “Suspicious matter reports,” updated 8 July 2026. https://www.austrac.gov.au/node/1338
4 AUSTRAC, “AUSTRAC steps up supervision of virtual assets sector as reforms take effect.” https://www.austrac.gov.au/new-and-media/news/austrac-steps-supervision-virtual-assets-sector-reforms-take-effect
MCO (MyComplianceOffice) KYC and AML compliance solution. https://mco.mycomplianceoffice.com/solutions/kyc-aml-compliance
MCO white paper, “Evidencing Compliance.” https://mco.mycomplianceoffice.com/resources/white-papers/evidencing-compliance
AUSTRAC's 2026-27 regulatory priorities ask firms to show that their AML/CTF programme runs in daily operations, not only on paper. Newly regulated Tranche 2 entities must enrol, complete a risk assessment, appoint an AML/CTF compliance officer and governance roles, establish policies, and embed them in practice. AUSTRAC also focuses on suspicious matter reporting quality and on supervising virtual asset service providers.
Tranche 2 entities are the sectors brought into the AML/CTF regime on 1 July 2026, including trust and company service providers, accountants and tax practitioners, and virtual asset service providers (VASPs). They must enrol with AUSTRAC, assess their money laundering and terrorism financing risk, appoint the required governance roles, and operate an AML/CTF programme that matches their risk.
AUSTRAC expects suspicious matter reports (SMRs) to be timely and high in quality, not merely frequent. A firm must submit an SMR within three business days of forming a suspicion, or within 24 hours where it relates to terrorism financing. AUSTRAC has said it will engage with reporting entities whose SMRs are consistently poor quality.
Compliance solutions that map obligations, govern policy, monitor transactions and evidence controls help businesses meet AUSTRAC's anti-money laundering priorities. MCO (MyComplianceOffice) offers a KYC and AML compliance solution that ties obligation mapping, policy governance and risk assessment to transaction monitoring, screening and instant payment screening, with a dated audit trail. Together these help firms show that an AML/CTF programme runs in daily operations and support timely, high-quality suspicious matter reporting.