
AUSTRAC penalties in 2026 follow a structure, not a price list. The AML/CTF Act makes its core obligations civil penalty provisions, sets the maximum penalty in penalty units, and leaves the Federal Court to decide the amount in each case. AUSTRAC’s tools run from remedial directions and enforceable undertakings to infringement notices and civil penalty proceedings. For firms regulated from 1 July 2026, one provision matters more than any figure: section 26G requires you to comply with your own AML/CTF policies, and it is a civil penalty provision.
TL;DR:
- Civil penalties are based on penalty units, with the dollar amount depending on the date of the contravention, not the court’s decision date.
- AUSTRAC can use remedial directions, enforceable undertakings, infringement notices or civil penalty proceedings, and the Act does not require it to use them in order.
- Under section 26G, failing to follow your own AML/CTF policies is itself a civil penalty contravention, so what your staff actually do has to match your policies.
- Raw dollar fines are misleading because the actual penalty depends on penalty unit values at the time of contravention and case-specific factors, not fixed amounts.
- Effective preparation requires current, senior-manager-approved policies, documented staff training, and organised records that stand up to a review or an AUSTRAC examination.
Table of Contents
- AUSTRAC’s enforcement approach and escalation ladder
- How penalty amounts actually work under the AML/CTF Act
- Civil penalty provisions and the court’s role under Part 15
- What happens if you get an infringement notice or a direction?
- Which obligations create the most enforcement exposure?
- How to prepare for governance reviews and AUSTRAC examinations
- A practical example: keeping program documents consistent under one system
- Where compliance officers should focus first
- How AML Guard helps Tranche 2 entities meet these obligations
- Sources
- FAQ
AUSTRAC’s enforcement approach and escalation ladder
The Act gives AUSTRAC a graduated set of tools, from a written notice to fix a problem up to an application to the Federal Court for a civil penalty order. The ladder is a range, not a sequence: nothing in the Act requires AUSTRAC to use a lower tool before a higher one, and it can use more than one at once.
AUSTRAC publishes the enforcement actions it has taken. Each tool has its own basis in the Act:
- External audit notices (section 162): where AUSTRAC suspects non-compliance, a written notice requiring you to appoint an external auditor to review your compliance and give AUSTRAC the audit report.
- Remedial directions (section 191): where AUSTRAC is satisfied a civil penalty provision has been contravened, a written direction to take specified action so it does not happen again or, for certain missed reports, to lodge the report within a set period. Not complying with a direction is itself a civil penalty contravention.
- Enforceable undertakings (section 197): a written commitment you offer and the AUSTRAC CEO accepts, to take or refrain from specified action. AUSTRAC can publish it, and can apply to the Federal Court to enforce it if it is breached.
- Infringement notices (Part 15, Division 3): a written notice to pay a set penalty for certain listed contraventions, such as failing to enrol, lodge a required report or keep required records. Paying within 28 days discharges the liability for that contravention.
- Civil penalty proceedings (Part 15, Division 2): AUSTRAC applies to the Federal Court for a civil penalty order, and the court decides whether a contravention occurred and what penalty to impose.
- Injunctions (section 192): on AUSTRAC’s application, the Federal Court can restrain conduct that contravenes a civil penalty provision, or require a person to do something.
For businesses regulated from 1 July 2026, AUSTRAC’s May 2026 statement of expectations is specific. It expects you to be enrolled, to have an AML/CTF program and an AML/CTF compliance officer, to have trained your staff on the program, and to be ready to have a go at reporting when a suspicious matter arises. It expects “effort, not perfection” during 2026-27, and it says it will take early enforcement action against businesses that fail to enrol and those it suspects of complicity in money laundering.
How penalty amounts actually work under the AML/CTF Act
The Act does not put a dollar figure on a civil penalty. Section 175 sets the maximum in penalty units, with a higher maximum for a body corporate than for other persons. The dollar value of a unit is the one in force on the date the contravention occurred, not the date the case is decided.
That is why a fixed dollar fine quoted for 2026 goes out of date the moment the unit value next changes. AUSTRAC’s guidance on the consequences of not complying confirms that the unit value is set by the date of the contravention, and that it is the Federal Court, on AUSTRAC’s application, that orders a civil penalty.
Contraventions also multiply. Providing a designated service without an up-to-date risk assessment (section 26E), or without AML/CTF policies that meet the Act’s requirements (section 26F), is a separate contravention for each service provided, and each day an enrolment stays overdue is a separate contravention (section 51B). That is how exposure grows without any single figure changing.
Pro Tip: Never rely on a dollar figure you’ve seen quoted for an AUSTRAC penalty. Check the penalty unit value current at the date of the alleged contravention, because that’s the figure a court will actually apply, not whatever number was circulating when the article was written.
| What varies | Why it matters |
|---|---|
| Penalty unit value | Set by date of contravention, not date of judgment |
| Maximum penalty | Expressed in penalty units in section 175, with a higher maximum for a body corporate |
| Actual penalty imposed | Set by the Federal Court case by case, having regard to the nature and extent of the contravention, any loss or damage, the circumstances and any prior court finding of similar conduct |
Civil penalty provisions and the court’s role under Part 15
The statutory basis for all of this sits in Part 15 of the AML/CTF Act, which sets out the enforcement mechanisms: Division 2 (civil penalties), Division 3 (infringement notices), Division 5 (remedial directions), Division 6 (injunctions) and Division 7 (enforceable undertakings). AUSTRAC applies to the Federal Court; it does not impose civil penalties itself.
The court’s role has three parts. First, it decides whether the contravention occurred, applying the rules of evidence and procedure for civil matters (section 179). Second, if satisfied, it may order a pecuniary penalty within the statutory maximum, having regard to the nature and extent of the contravention, any loss or damage it caused, the circumstances in which it took place and whether the person has previously been found to have engaged in similar conduct (section 175). Third, on AUSTRAC’s application, it can grant an injunction restraining conduct or requiring a person to act (section 192).

For compliance officers, the practical takeaway is preparation. If a matter reaches this stage, you’ll need dated evidence of your risk assessment, your policies, senior manager approvals, and records showing what staff actually did in practice, not just what the policy said they should do. Under section 26G, a gap between the two can itself be the contravention.
What happens if you get an infringement notice or a direction?
Each tool comes with its own deadline or terms, and how you respond matters more than the first notice.
- Infringement notice issued. The notice sets out the alleged contravention and the penalty. Pay within 28 days, or any longer period AUSTRAC allows, and the liability is discharged: no criminal or civil penalty proceedings can be brought for that contravention.
- Remedial direction issued. The direction specifies the action you must take and, for certain missed reports, the period for lodging it. Keep evidence of each step, because not complying with a direction is a separate civil penalty contravention.
- Enforceable undertaking accepted. You commit in writing to specific actions, and AUSTRAC may publish the undertaking. You can vary or withdraw it only with AUSTRAC’s consent, and a breach can be enforced in the Federal Court.
- Non-payment or non-compliance. If an infringement notice is not paid, AUSTRAC can seek a civil penalty order instead, and the court is not limited to the amount in the notice.
Ignoring a notice or a direction closes off the cheaper outcome: an unpaid infringement notice can become a civil penalty application, and a breached direction is a contravention in its own right.
Which obligations create the most enforcement exposure?
AUSTRAC has said where it will focus. Its regulatory priorities for 2026-27 expect newly regulated businesses to have enrolled, completed ML/TF risk assessments, appointed governance roles, and established AML/CTF policies embedded in daily operations. Three obligations deserve attention first for firms still building their programs.
- Annual compliance reports now run on a financial year reporting period, with a lodgement window from 1 July to 30 September. Missing or late submission of your annual compliance report can trigger enforcement action on its own, including a remedial direction or an infringement notice. The current reporting period runs from 1 July 2026 to 30 June 2027, so the report for it is due between 1 July and 30 September 2027.
- Enrolment and core reporting carry fixed statutory deadlines, summarised in AUSTRAC’s Tranche 2 obligations factsheet: enrol within 28 days of first providing a designated service, report a suspicious matter within 3 business days of forming the suspicion (24 hours for terrorism financing), and report a threshold transaction within 10 business days. Failing to enrol is the compliance gap AUSTRAC’s May 2026 statement singles out for early enforcement action.
- Internal policy non-compliance is the obligation that changes the calculus for every newly regulated firm. Section 26G requires you to comply with your own AML/CTF policies, and it is a civil penalty provision, so a policy sitting unused in a drawer is a liability in its own right, not just a paperwork gap.
If you’re still mapping which of these applies to your service, our Tranche 2 obligations explainer breaks down enrolment and reporting duties by sector.
How to prepare for governance reviews and AUSTRAC examinations
Reducing enforcement exposure comes down to three habits: current documents, defensible records, and knowing how to handle an examination if one arrives.
Keep your risk assessment and AML/CTF policies under active review, not filed away after initial approval. The Act requires both to suit the nature, size and complexity of your business. It requires the risk assessment to be reviewed when a significant change occurs (before the change, if it is within your control), when AUSTRAC gives you information about the risks of your services, in other circumstances the AML/CTF Rules specify, and in any event at least every three years (section 26D). It also requires a senior manager to approve each version (section 26P). Providing a designated service without an up-to-date risk assessment is itself a contravention, and because your policies must provide for their own review, a stale document usually breaches your own policies as well. Keep the approval trail alongside the document itself.

Pro Tip: If AUSTRAC issues a written notice under section 172A, you can be required to produce documents or to appear before an examiner and answer questions on oath, and failing to comply is an offence. Self-incrimination is not an excuse for refusing to answer (section 172K), but if an individual claims that protection before answering, and the answer might in fact incriminate them or expose them to a penalty, it is not admissible against them in later proceedings, other than proceedings about whether it was false. Your lawyer may attend the examination (section 172F), so get advice as soon as a notice arrives, not during the examination.
Our program documents guide covers how to keep your risk assessment, policies, and training records aligned as one evidentiary set.
A practical example: keeping program documents consistent under one system
Section 26G raises the stakes on something firms often treat as paperwork: whether your risk assessment, policies, action plan, and training actually agree with each other.
An integrated platform reduces that mismatch risk by generating all four documents from the same underlying answers, so a control described in your policy traces back to a risk identified in your assessment.
- Automated customer due diligence and sanctions and PEP screening create a timestamped record of checks performed, not just checks intended.
- Officer approval workflows mean a human approves each determination before CDD proceeds, keeping the judgement with your team.
- A tamper-evident retention schedule keeps records accessible for audit rather than scattered across spreadsheets and inboxes.
Software supports the evidence trail. It doesn’t replace governance, senior sign off, or the officer’s own judgement call on each file.
Where compliance officers should focus first
Documented, senior-approved policies that are visibly followed count for more than policies that merely exist. For newly regulated businesses, AUSTRAC has set a clear floor for 2026-27: be enrolled, have an AML/CTF program and compliance officer, train your staff on the program, and be ready to have a go at reporting.
Review your enrolment, your policy approvals, your evidence of staff training, and your annual compliance reporting schedule this week, not next quarter.
How AML Guard helps Tranche 2 entities meet these obligations
Real estate agencies, law firms, accounting practices, and trust and company service providers now carry the same civil penalty exposure as longer-regulated sectors, with less time to build mature systems. AML Guard is built specifically for Australian Tranche 2 reporting entities, not adapted from banking software, so the workflows match obligations you actually have to meet.
The platform generates your risk assessment, AML/CTF policies, compliance action plan, and staff training manual as one linked set, so a supervisor reviewing your file finds consistency rather than contradictions between documents. Customer due diligence, document and biometric verification, and sanctions and PEP screening run in one workflow, and beneficial ownership determination resolves companies against their ACN, with trusts and SMSFs reached through their corporate trustee’s own determination. An officer approves each determination before CDD proceeds, and every check sits inside an 8-year tamper-evident audit trail.
AML Guard isn’t self-service. You start by booking a demo, and your tenant is then configured to your designated services and risk profile, with monthly or 12-month subscription terms depending on what suits your firm. See the full feature set on the features page or check current plans and pricing before your call.
Sources
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) | Federal Register of Legislation
- Enforcement actions taken | AUSTRAC
- Update to regulator statement of expectations, May 2026 | AUSTRAC
- Consequences of not complying | AUSTRAC
- Our regulatory priorities for 2026-27 | AUSTRAC
- AML/CTF obligations factsheet for tranche 2 reporting entities | AUSTRAC
- Annual compliance reports | AUSTRAC
FAQ
What are the new AML regulations in 2026?
The AML/CTF reforms took effect in two stages in 2026. On 31 March 2026, reformed obligations began for businesses already regulated, including new requirements for AML/CTF programs and customer due diligence. From 1 July 2026, obligations extended to services typically provided by real estate agents, lawyers, conveyancers, accountants, trust and company service providers, and dealers in precious metals and stones. Under the reformed Act, failing to comply with your own AML/CTF policies is a contravention of a civil penalty provision (section 26G).
What is the current threshold for reporting a transaction to AUSTRAC?
A threshold transaction is a transfer of physical currency (cash) of $10,000 or more, or the foreign currency equivalent, as part of a designated service. It must be reported to AUSTRAC within 10 business days (section 43). Suspicious matter reporting is a separate duty with no dollar threshold.
What are the fines for AML breaches in Australia?
There is no fixed fine for a civil penalty order. The Act sets a maximum in penalty units (section 175), and the Federal Court sets the penalty within that maximum, using the penalty unit value in force on the date of the contravention. Infringement notices, available for certain listed contraventions, carry a set penalty instead, and paying one within 28 days ends liability for that contravention.
What transactions are reported to AUSTRAC?
Reporting entities must report suspicious matters within 3 business days of forming the suspicion (24 hours for terrorism financing, and 5 business days in some legal professional privilege cases), and threshold transactions involving $10,000 or more in physical currency within 10 business days. Businesses that provide international value transfer services also report those transfers. Annual compliance reports are lodged between 1 July and 30 September each year.
Does AML Guard have publicly listed pricing?
Yes. Current subscription and per-check prices are published on the pricing page. AML Guard isn’t self-service: firms start with a demo, and each tenant is then configured to the firm’s designated services and risk profile.
Recommended
- Tranche 2 AML Australia: your compliance obligations explained
- Tranche 2 customer due diligence in Australia
- AML/CTF Program Documents for Tranche 2
- AML/CTF policy template for Tranche 2 firms
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.