By Nick Boudrie, Co-founder and CEO, LAB Group
The reformed AML/CTF obligations commenced for existing reporting entities on 31 March 2026. For most stockbroking, wealth management and advice firms, the months either side of that date were spent on documents: a new risk assessment, rewritten policies, a governance structure, an AML/CTF compliance officer named and a board briefed.
That work was necessary, and for many firms it is done. The harder phase is now underway. In its 2026-27 regulatory priorities, published in August, AUSTRAC said it wants evidence that programs work in daily practice rather than on paper, and that suspicious matter reporting will be judged on quality rather than volume. The message to firms that treated 31 March as a finish line is not subtle.
Three areas are worth a second look before year end.
The transitional relief is narrower than it looks
AUSTRAC’s transitional rules let existing reporting entities defer the reformed initial customer due diligence (CDD) requirements until 31 March 2029, which leaves a two and a half year runway. In practice it is shorter. Allow for a Christmas change freeze each year and a buffer for testing and remediation, and a firm starting now has closer to two years of usable time.
The common misreading is that the deferral covers everything. It does not. It covers only initial CDD, the checks you run when you take on a new client. It does not cover ongoing CDD, the checks you run on the clients you already have. Those changed on 31 March 2026, with no transition at all.
There is a second catch. You can move different groups of clients onto the new checks at different times, which helps. What you cannot do is run one group under both sets of rules at once, so the move has to be planned group by group.
That plan is not optional. Since 1 July 2026, any firm relying on the deferral has needed its AML/CTF policies to name the groups still on the old checks and the date each group moves across. Without that in writing, the deferral does not apply, whatever the firm is doing in practice.
So your onboarding may look unchanged for now. The requirement to write down when it changes is new, and the way you look after existing clients has changed a great deal.
The legacy book is where the exposure sits
Broking and advice firms carry long client relationships. Accounts opened a decade ago, holdings untraded in years, family trusts and SMSFs identified under the old procedures, and beneficial ownership recorded once and never revisited.
Where identification was completed under the applicable customer identification procedure before 31 March 2026, the firm is treated as having met initial CDD for that customer. Ongoing CDD still applies in full: monitoring for unusual transactions and behaviours, reviewing, updating and reverifying KYC information at an appropriate frequency, re-screening for politically exposed persons, sanctions and adverse media, and watching for significant changes in the nature and purpose of the relationship. If such a change takes a customer’s risk to medium or high, initial CDD must be completed under the current rules before further services are provided. One dormant account waking with an unusual instruction turns a legacy record into a live remediation task.
Sanctions deserves attention. From 31 March 2026 targeted financial sanctions obligations sit inside the AML/CTF Rules rather than alongside them, and the list changes continually. A client screened clean in 2019 has not been screened against today’s list.
Two further details catch firms out. Initial CDD is now conducted on the trust rather than the trustee, which changes the target for trust and SMSF remediation. And reliance on a licensed financial adviser’s identification continues under section 38, but only where it stays appropriate to the customer’s risk, documented rather than assumed.
Records are the deliverable, not the policy
The reforms are heavier on evidence than the one they replaced. Firms must record what was collected, how it was verified, how customer risk was assessed, the rationale for those decisions, and the outcomes of reviews and monitoring.
At the same time, OAIC guidance requires reporting entities to stop retaining full copies of identity documents from 31 March 2026, recording only specific extracted fields. Many firms hold licence and passport scans across email, shared drives and client files, and need a documented plan for them. The two pull in opposite directions unless evidence is captured as structured data at the point of verification rather than as a stored image.
This gets tested sooner than the 2029 dates suggest. The independent evaluation that replaces the old Part A review covers the entire program, and is due by the later of four years after your last review or 31 March 2027.
That is the theme running through all of it. A program that produces its own audit trail as a by-product of doing the work will meet AUSTRAC’s practical test. A program that depends on someone reconstructing decisions later will not.
LAB Group provides onboarding, verification and ongoing due diligence technology for Australian regulated entities, including wealth managers, brokers, platforms and fund administrators. We were a sponsor of SIAA2026 in May. To discuss how firms are approaching ongoing CDD and legacy book remediation, visit labgroup.com.au.
