Compliance13 min read

Two Entities, One Program: The Reporting Group You Might Already Be In

If your practice sits under a trust or holding company that owns something else, you may already be in a reporting group without having chosen one. Business groups become reporting groups automatically, a lead entity has to be appointed in writing within 28 days, and the entity that ends up carrying the group program may be one that has never provided a designated service in its life. Here is the test, the clock, and what you actually get in return.

2026-08-08· AML Mate Team
Two Entities, One Program: The Reporting Group You Might Already Be In

Most Australian professional practices are not one entity. They are three or four.

A trading company that does the work. A family trust that owns it. A service entity that employs the staff and invoices the trading company. Maybe a second company for the SMSF administration, or the conveyancing arm, or the rent roll. Your accountant built that structure for tax and asset protection reasons a decade ago and nobody has thought about it since.

The AML/CTF Act thinks about it. As of 1 July, that structure may have become a reporting group, and you were not asked.

You do not elect into a business group

There are two ways to be a reporting group. One of them you choose. The other happens to you.

The one you choose is an elective reporting group: two or more reporting entities agree in writing to form one. Franchises, agency and distribution networks, joint ventures. Nothing happens unless everyone signs.

The one that happens to you starts with a business group, and AUSTRAC's definition is short:

Control is the main principle to the existence of business groups. You're in a business group if your business is in a control structure. This is where one person controls one or more persons.

(AUSTRAC, forming reporting groups, updated 26 June 2026.)

Then the second half:

Your business group will automatically be a reporting group if one or more persons in the group provide a designated service.

Automatically. There is no form, no election, no letter from AUSTRAC. Control relationship plus one designated service, and the group exists.

Control is wider than the shareholder register

This is where firms get the answer wrong, because they check who owns what and stop.

Under section 11 of the Act, a person controls a company if any of the following apply (AUSTRAC, determining ownership and control structures, updated 31 March 2026):

  • Voting power. They can cast, or control the casting of, more than 50% of votes at a general meeting.
  • Shareholding. They hold, directly or indirectly, more than 50% of issued share capital.
  • Board control. They can control the composition of the board or governing body.
  • Practical influence. They can determine the outcome of decisions about financial and operating policies, taking into account practical influence rather than rights that could be enforced, and any established pattern of behaviour.

For anything that is not a company, a trust or a partnership, only the last two limbs apply: control of the governing body, or practical influence.

AUSTRAC then adds the sentence that catches people:

You don't need to own another person to have control.

So the family trust that appoints the directors controls the company. The individual who is the sole director of the corporate trustee and also the sole director of the trading company probably controls both. A structure that looks like separate businesses on the ASIC extract can be one control structure in substance. If you have been through the beneficial ownership exercise on a client, it is the same test, pointed at yourself.

Two useful negatives from AUSTRAC's own worked examples. Minority shareholders are not in the business group: owning less than 50% with no control over the board or decisions does not put you in. And a majority shareholder with no casting votes, no board control, no say over financial and operating policies and share capital that gives no rights beyond distributions is also outside it. Ownership on paper is not the test. Control is.

Everyone in the structure is a member, not just the ones doing AML work

Once the group exists, membership is not limited to the entities that provide designated services. The members are all persons within the control structure. That includes:

  • entities that provide no designated services at all, such as your holding company or service trust
  • entities that are offshore and have no link to Australia
  • the parent of your lead entity, and anything else that parent controls

You also cannot carve it up. Per AUSTRAC:

Your business group can't be split into more than one reporting group. It becomes one reporting group, with all members within the business group.

All in, or the group is not a group.

The 28 days, and what actually happens if you missed them

A reporting group must have a lead entity appointed within 28 days, in writing, by one of exactly two routes:

  • the person who controls all members appoints it, in writing, or
  • all eligible members agree on it, in writing

Miss that, and here is the consequence, which is not the one people brace for:

Your business group won't be a reporting group if either: no lead entity is in place within 28 days; a reporting entity in the group opts out, in writing.

The group simply does not exist. That is a lapse, not a contravention. There is no penalty for failing to appoint a lead entity, because forming a group was never compulsory.

Do the arithmetic on your own dates. If your group became a reporting group when the obligations commenced on 1 July 2026, the 28 days ran out on 29 July, which is the same day the enrolment deadline landed. If you started providing designated services later than that, your 28 days runs from then instead.

The real risk in this is not the missed window. It is the firm that assumed a group program covered every entity, never appointed a lead entity, and therefore has two or three reporting entities each running on a program that does not legally apply to them. Each of those entities has its own obligations either way. AUSTRAC is explicit that until a lead entity is in place, members of a new group comply with their own individual AML/CTF policies.

If you want a group now and the automatic window has passed, the guidance does not spell out whether the business-group route retriggers, so that is a question for AUSTRAC or your adviser rather than something to assume. The elective route is described clearly and is available by written agreement. One catch: if you are in a business group, the entire business group has to join or leave with you.

Who is allowed to be the lead entity

Not whoever volunteers. The lead entity must be all of the following:

  • not controlled by another member that provides a designated service, which usually rules out the trading company where the actual AML work happens
  • connected to Australia: an Australian resident, a body corporate incorporated in Australia, a registered foreign company, or a trust with at least one Australian-resident trustee
  • capable and authorised to develop and maintain the group's AML/CTF policies

That authority does not have to be a signed mandate. AUSTRAC accepts it as direct, by consent of members, or implied by how the group is structured, and says there is no requirement for explicit consent where the lead entity's authority is clear.

Now the part worth sitting with. Your holding company or trust has never provided a designated service and never will. Make it the lead entity and:

The Act defines a lead entity as being a reporting entity. This applies even if your business doesn't usually provide designated services... As a lead entity you must enrol with us.

(AUSTRAC, obligations for lead entities and members, updated 22 April 2026.)

An entity that was outside this regime entirely is now enrolled with AUSTRAC and carrying the group's risk assessment and policies. That is not a trap, it is the deal, but it should be a decision rather than a discovery.

The catch: you are on the hook for each other

The lead entity is the central point of accountability. It owns the group-wide ML/TF risk assessment, the group-wide policies, oversight of members' compliance, and the information-sharing rules. Its governing body has to exercise oversight across the whole group, and its compliance officer has to support that.

And when a member gets it wrong:

If you breach a civil penalty provision as a member, both you and your lead entity are considered to have breached a requirement of the Act.

Both. Against penalties of up to $36.4 million per contravention for a company, that is a sentence worth reading twice before you nominate anyone. If your group includes an entity whose AML practice you cannot actually see, you are underwriting it.

Members are not off the hook either. A member that is a reporting entity must comply with its own policies and the lead entity's policies that apply to it. And the lead entity is taken to provide the same designated services, in the same way, as every reporting entity member, which is why the group risk assessment has to cover each member's real operations rather than the lead entity's. AUSTRAC's example is a small franchisor with ten franchisees: the program must reflect the full operational and risk profile of each franchisee, not just the franchisor.

What you get in return

Real things, not theoretical ones.

One risk assessment and one set of policies instead of one per entity. For a three-entity practice that is the whole argument.

Members can discharge each other's obligations. Any member can do the work for another, including members that are not reporting entities. AUSTRAC lists suspicious matter reports, threshold transaction reports, annual compliance reports, record keeping, and CDD on behalf of all members. So the service entity that already does your bookkeeping can run the AML function for the group. The entity whose obligation it is stays responsible for it, and you have to document who is discharging what and keep the records immediately accessible to the entity you are doing it for.

Information can move between members. Including, in some circumstances, information about SMRs, which is otherwise the fastest way to walk into the tipping-off offence. Group-wide policies have to make sure shared information is used appropriately, stays confidential, and is not disclosed in a way that would lead to tipping off. It reduces the risk. It does not switch the offence off.

Internal services stop being designated services. Services provided between members of a business group are not designated services, because members provide them to each other within the group. Your service entity invoicing the trading company is not a designated service. Note the boundary: this covers business group members. Services between members of an elective group who are not in the same business group can still be designated services.

One consequence of pooling the AML function that firms miss: if a member that is not a reporting entity discharges obligations for one that is, that member still has to run personnel due diligence and training on its own people, to a standard that satisfies the policies of the reporting entity whose obligations it is doing.

If you would rather not

Opting out is available and mechanical. You must be a reporting entity in the business group, and you must:

  • give written notice to all reporting entities in the group, including the lead entity, that you do not want to be a member
  • not withdraw that notice
  • continue to be a reporting entity

Reasonable steps to give that notice scale with the size and complexity of the group. One opt-out and the business group is not a reporting group at all.

The cost of opting out is that you develop and maintain your own program, on your own, and share nothing.

Tell AUSTRAC either way

Your enrolment has to state whether you are a member of a reporting group, or the lead entity of one (AUSTRAC, understanding reporting groups, updated 10 July 2026).

If you are the lead entity, your enrolment has to name each reporting entity member, with any identifier AUSTRAC has given it and another unique identifier such as an ABN or ACN. If you are an ordinary member, you name the lead entity the same way.

Changes to those details go to AUSTRAC within 14 days of the change. Appointing a lead entity, a member joining, a member leaving, an entity ceasing to provide designated services: all of it updates your enrolment. The enrolment guide covers where those fields live.

One note for anyone who was already regulated: reporting groups replaced designated business groups from 31 March 2026. If you were in a DBG and did not move across, you cannot rely on the joint program made under it.

Where AML Mate fits

AML Mate is built around one business: one risk assessment, one program, one client register, one audit pack. That maps to a reporting group cleanly, because the whole point of forming one is that the group has a single program with the lead entity's name on it. Firms that stay separate run separate programs, and that means separate accounts.

What AML Mate will not do is decide the structure question. Whether your service trust controls your trading company is a question about your constitution, your trust deed and who actually makes the decisions, and it belongs with your accountant or lawyer. Bring the answer back and the program follows from it.

If you are not yet sure whether any entity in your structure provides a designated service at all, start with the designated service test, because none of this matters until at least one of them does.

The short version

  • A business group is a control structure. One person controlling one or more persons, tested on voting power, shareholding, board control or practical influence. Ownership is not the test.
  • If one member of that structure provides a designated service, the whole group is automatically a reporting group. Nobody asks you.
  • Members are every person in the control structure, including entities that do no AML work and entities offshore. You cannot include only some of them.
  • A lead entity must be appointed in writing within 28 days or the group ceases to exist. That is a lapse, not a fine.
  • The lead entity cannot be controlled by another member that provides a designated service, must be connected to Australia, and becomes a reporting entity that must enrol even if it has never provided a designated service.
  • The upside is one risk assessment, one set of policies, members discharging each other's obligations, lawful information sharing, and internal services that are not designated services.
  • The price is joint exposure. A member's breach is the lead entity's breach too.
  • Either way, your enrolment has to say which you are, and changes go in within 14 days.

The structure your accountant built for tax reasons is now a compliance fact. Worth ten minutes with the constitution before it is worth a conversation with AUSTRAC.


This article is general information, not legal advice. For advice specific to your circumstances, consult a qualified AML/CTF professional.

reporting-groupslead-entitygroup-structureenrolmentaustractranche-2

Ready to build your AML/CTF program?

AML Mate generates your AML/CTF program in 15 minutes using AUSTRAC's official templates. Start a 14-day free trial, cancel anytime.

This article is based on AUSTRAC's publicly available guidance. It does not constitute legal or compliance advice. Consult a licensed compliance professional for complex situations.