Compliance8 min read

AUSTRAC's 2026-27 Regulatory Priorities: The Five-Line Checklist It Expects You to Finish by Mid-2027

AUSTRAC's regulatory priorities for 2026-27 spell out what newly regulated firms should have done by mid-2027, and who it will intervene against first. The five-line checklist ends with the hard part: policies embedded in daily operations. Here is the document read from a small firm's desk, what each line means, and the three moves worth making this week.

2026-08-26· AML Mate Team
AUSTRAC's 2026-27 Regulatory Priorities: The Five-Line Checklist It Expects You to Finish by Mid-2027

Regulators do not usually hand out the marking guide before the exam. On 19 August 2026 AUSTRAC did. Its regulatory priorities for 2026-27, the areas where it says it will focus most of its regulatory effort over the next 12 months, include a five-line description of what a business regulated from 1 July will have done by the end of the financial year (AUSTRAC, our regulatory priorities for 2026-27, 19 August 2026).

After a fortnight of enforcement stories, Operation Claw on the mortgage books and the tobacco strike with its seizure-list sector map, this is a quieter document. It is also the more useful one, because it is about you specifically, and it is short enough to hold in your head.

The checklist, in AUSTRAC's own words

During FY2026-27, AUSTRAC says, businesses in sectors regulated from 1 July 2026 will have:

  • enrolled, and registered where required
  • completed ML/TF risk assessments
  • appointed governance roles
  • established appropriate AML/CTF policies
  • embedded them in daily operations.

(AUSTRAC, our regulatory priorities for 2026-27)

Read the verb tense. "Will have" is the regulator describing the state of your firm at 30 June 2027. None of these lines creates a new legal deadline; the obligations behind them have been in force since 1 July. What the document adds is the supervisory expectation: this is the finish line AUSTRAC will be measuring the new sectors against, and it has told you a year in advance.

Four of the five lines are setup. Enrolment closed as a deadline on 29 July, and the standing rule is that you must apply to enrol no later than 28 days after the day you first provide a designated service (AUSTRAC, enrol with us, updated 30 July 2026). The risk assessment is a document you write once and then keep honest, which is harder than it sounds when the default answer is "low". Governance roles means, at minimum, an AML/CTF compliance officer appointed within 28 days of providing designated services and notified to AUSTRAC within 14 days of the appointment, someone at management level and fit and proper (AUSTRAC, AML/CTF compliance officer, updated 31 March 2026). We walked the who-wears-which-hat question for small firms in August. Policies are the program documents themselves, and AUSTRAC's starter kits exist so that a small practice does not have to draft them from a blank page. The priorities even commit to refining those starter kits through the year based on industry engagement, so the kit you downloaded in June is not the final word.

The fifth line is the year's work. "Embedded them in daily operations" is the one you cannot finish in an afternoon, because it is not a document, it is a routine: the monitoring review that actually happens, the risk rating that gets revisited when something changes, the escalation that gets written down. AUSTRAC's monitoring guidance describes what embedded looks like at small scale, scheduling regular time, weekly or monthly, to review customer activity against what you know about the customer (AUSTRAC, how to monitor your customers, updated 27 March 2026). It is the same argument we made in operating your program from 1 July: the program on paper was the entry ticket, the operating rhythm is the compliance.

Who AUSTRAC says it will intervene against

The priorities name two groups for regulatory intervention, and the wording repays a careful read (AUSTRAC, our regulatory priorities for 2026-27):

  1. Reporting entities in sectors regulated before 31 March "who don't manage their ML/TF risks effectively. This includes those with AML/CTF programs that are not applied in their daily operations."
  2. Reporting entities in newly regulated sectors "who haven't enrolled or are recklessly involved in, or complicit with, criminal activity."

For a Tranche 2 firm, the second line is the immediate one. The intervention bar for your sector this year is not an imperfect risk assessment or a training register with a gap in it. It is not enrolling at all, or being part of the crime. If you missed 29 July, the answer is still the one we gave in what happens if you missed the enrolment deadline: enrol now, late, rather than stay off the roll while the regulator is naming non-enrolment as its trigger for intervention.

The first line is worth reading anyway, because it is your future. The named failure mode for the established sectors is a program that exists as a PDF and is not applied in daily operations. That is AUSTRAC telling everyone, in a public document, which gap between paper and practice it goes looking for once a sector is past its first year. The rest of the new-entity plan is deliberately soft: understanding new sectors "through engagement, education and supervision", refining guidance and starter kits. Enrolled and genuinely operating puts you in that lane, which is exactly where you want to be. We made the same point the day after the deadline in triggers, not deadlines; it is pleasant to see the regulator's planning document agree.

SMR quality is a named priority, with receipts

A full section of the priorities is about suspicious matter reports, and the outcome AUSTRAC wants is not more reports, it is better ones: "higher quality suspicious matter reports". The document also shows what happens when AUSTRAC decides a cohort is under-reporting. In FY2025-26 it ran supervision and education campaigns on sectors submitting lower than expected SMR volumes, and it publishes the results like a before-and-after: a 77% increase in SMRs from payment platforms, including a 264% increase in reports relating to possible child sexual exploitation, and a 37% increase from mutual banks, where five reporting entities lodged SMRs for the first time in years (AUSTRAC, our regulatory priorities for 2026-27).

Two things follow for a first-year firm. AUSTRAC measures sector-level reporting and follows up on cohorts that look too quiet, which is the machinery behind why a permanent zero can read as under-reporting. And quality is specific: the SMR guidance asks you to include as much detail as possible, because your insights are what make the report usable, and the clock is 3 business days after the day you form the suspicion, or 24 hours if it relates to terrorism financing (AUSTRAC, suspicious matter reports, updated 8 July 2026). The priorities add one more wrinkle: AUSTRAC will explore advanced SMR analytics to get more value out of what entities lodge. Your reports are increasingly read by machines before people, which is one more reason a defensible, detailed SMR beats a terse one.

The compliance report is being redesigned. The year it covers is already running.

Tucked into the productivity section: AUSTRAC will "review and redesign the annual compliance report" using its co-design approach, aiming at clarity and user experience (AUSTRAC, our regulatory priorities for 2026-27).

Do not let the redesign read as a reprieve. The reporting period the redesigned form will ask about is 1 July 2026 to 30 June 2027, and the report is lodged between 1 July and 30 September 2027 (AUSTRAC, annual compliance reports, updated 1 April 2026). The questions may get clearer; the facts they ask for will not change character. They will still be dates, counts and approvals that either exist in your records or do not. We listed the registers that answer each question last week, and the redesign changes nothing about the advice: the report is a mirror of the year, and the year is eight weeks old.

Three moves this week

  1. Score yourself against the five lines, honestly. Enrolled, risk assessment done, roles appointed and notified, policies established, embedded in daily operations. The first four are fixable in days if something is missing, and fixing them now costs almost nothing. Being unable to say yes to line one is the single item on this year's intervention list you can control.
  2. Make "embedded" mean a calendar entry. A weekly or monthly monitoring review, per AUSTRAC's own description of manual monitoring, plus a one-line record that it happened. Twelve such entries are the difference between a program that is applied in daily operations and a PDF, which is precisely the distinction AUSTRAC's intervention wording draws.
  3. Keep feeding the compliance report. The registers from our record-what-you-do walkthrough: training completions, ECDD events, high-risk clients, escalations. Whatever the co-designed form looks like, those registers answer it.

Where AML Mate fits

AML Mate is built for the fifth line. The program and risk assessment live next to the client records they are supposed to govern, monitoring reviews and risk-rating changes leave a dated trail, and the audit export reads the year back when the compliance report, or the regulator, asks. The free check at /check takes five minutes and scores you against essentially the same five lines AUSTRAC just published.

The regulatory priorities run to about two pages of plain language, and they are worth those ten minutes of your week. It is not often the examiner publishes the rubric. It is rarer still that the rubric is five lines long and four of them are already behind you.

Five days after the priorities were published, the intervention line stopped being a plan: AUSTRAC began issuing section 167 notices to businesses that appear to provide designated services but never enrolled. What a notice compels and what to do if one arrives: the letters have started.


This article is general information, not legal advice. For advice specific to your circumstances, consult a qualified AML/CTF professional.

austracregulatory-prioritiestranche-2aml-ctf-programsmrannual-compliance-reportgovernanceaccountantslawyersconveyancersreal-estatejewellers

Ready to build your AML/CTF program?

AML Mate generates your AML/CTF program in 15 minutes using AUSTRAC's official templates. Start a 14-day free trial, cancel anytime.

This article is based on AUSTRAC's publicly available guidance. It does not constitute legal or compliance advice. Consult a licensed compliance professional for complex situations.