Compliance11 min read

AUSTRAC Is Investigating Western Union. The Test It Named Is 'Known Patterns', and It Has Already Published Yours.

On 1 September 2026 AUSTRAC opened an enforcement investigation into Western Union and, unusually, published both the file behind the decision and the three tests it will run: does the program work, does monitoring catch known patterns, and who really makes the decisions. Here is each test at the scale of a four-person practice, and why the sequence that led here matters more than the name on the release.

2026-09-04· AML Mate Team
AUSTRAC Is Investigating Western Union. The Test It Named Is 'Known Patterns', and It Has Already Published Yours.

On 1 September 2026 AUSTRAC announced an enforcement investigation into Western Union Financial Services Australia Pty Ltd and The Western Union Company, citing concerns about how the company manages high-risk payment channels, customers and affiliates. It is not an investigation into the affiliates themselves. AUSTRAC CEO Brendan Thomas put the reason in one sentence: "We have launched this investigation because we have serious concerns that Western Union has failed to adequately manage those risks." (AUSTRAC, initiates investigation into Western Union)

A remitter moving cash across borders is about as far from a suburban conveyancer as the regime gets. Read the release anyway, because AUSTRAC did something with it that the market did not get when Tabcorp disclosed its own investigation in May: it published the file behind the decision. What it weighed before deciding, and the three things it will test now. Both halves translate down to a practice of four people better than you would expect.

The Investigation Was the Fourth Step, Not the First

The release says AUSTRAC opened the investigation "having considered a range of factors including data and intelligence holdings, prior regulatory engagements and an external audit of Western Union ordered by AUSTRAC in 2025." It also notes that Western Union has committed to addressing the issues raised in that audit report. The commitment did not stop the investigation.

So the order was: watch, talk, order an audit, then investigate. Each step has an equivalent at your scale.

Data and intelligence holdings. For a global remitter that means the reports flowing through AUSTRAC's systems every day. For a small firm it means the reports you have lodged, and the reports you have not. We wrote in July about why a zero SMR count is itself a data point once the regulator can compare you with firms that look like you.

Prior regulatory engagement. Last week's section 167 notices to businesses that never enrolled are what engagement looks like from the outside: a compulsory question, with a covering letter that explains which section of the Act authorises it, why it was issued and what happens if you ignore it. (AUSTRAC, information-gathering powers, updated 25 June 2026) How a firm answers that question becomes part of the file.

An external audit AUSTRAC ordered. This is the step most newly regulated firms have never heard of, and it is not reserved for remitters. AUSTRAC can issue a reporting entity a written notice requiring it to appoint an external auditor, either to review its compliance with the Act, the regulations and the Rules where AUSTRAC has reasonable grounds to suspect non-compliance, or to undertake an ML/TF risk assessment where it suspects the business has not taken appropriate action to identify, assess, mitigate or manage its risks. The notice sets out what must be audited, the format of the report and what it must contain. The auditor reports to you, and you must give AUSTRAC a copy. (AUSTRAC, consequences of not complying, updated 25 June 2026)

Read that against the Western Union timeline. The audit was ordered in 2025. The investigation came in September 2026. An audit notice is not the end of a matter. It is the regulator collecting evidence for its next decision, on your time. What an AUSTRAC examination asks for is the same set of documents an external auditor will want, which is a good reason to have them in one place before anyone asks.

The Word to Underline Is "Known"

Of the three things AUSTRAC says it will examine, the second is the one to read twice. The investigation will look at Western Union's transaction monitoring program, "including whether it can identify known money laundering typologies, particularly those associated with child sexual exploitation and terrorism financing." The release adds that AUSTRAC's 2025 supervisory campaign into payment providers "identified significant weaknesses in how some businesses detected and managed transactions linked to child sexual exploitation."

The test is not whether Western Union caught everything. It is whether it caught the patterns AUSTRAC had already described to the sector. That is a narrower, fairer and much harder question, because the regulator can hold up its own publication and ask why the monitoring did not reflect it.

Your version of that question is already written down. AUSTRAC's guidance on what you must monitor for says it publishes indicators of criminal activity, that it expects you to use them "to inform your monitoring program, where they're relevant to your business," and that it expects you to update your monitoring procedures when it produces new indicators or new assessments of risk. (AUSTRAC, what you must monitor, updated 31 March 2026) There are dedicated indicator pages for accountants, legal professionals, the real estate sector and dealers in precious metals and stones. (AUSTRAC, risks and indicators of suspicious activity, updated 10 July 2026)

The same page lists the offences you must monitor for, and the list is longer than most firms expect. Alongside money laundering and terrorism financing it names crimes relating to taxation, bribery, fraud including scams, human trafficking and, in the same words AUSTRAC used about Western Union, sexual exploitation including exploitation of children. Some of the unusual transactions and behaviours it describes could have been written for a professional services firm:

  • transactions put through a service provider such as a lawyer or accountant for no apparent commercial or other reason
  • trust structures used as a vehicle to move funds, or companies registered with no apparent commercial activity
  • legal entity structures used to obscure ownership
  • a client who appears to be directed by a third party, or whose answers seem coached or rehearsed
  • a client who asks staff whether the firm reports to government authorities, or asks for a transaction not to be reported

None of those need software to spot. They need a person who has read the list, and a file where the observation gets written down.

Monitoring at the Scale of a Small Firm

A four person practice does not run a transaction monitoring system, and AUSTRAC does not ask it to. Its guidance says customer monitoring can be manual, automated or both, and that what is appropriate depends on the nature, size and complexity of the business. Automated monitoring is expected where transactions cannot be monitored effectively by hand, which describes a remitter, not a conveyancer. (AUSTRAC, how to monitor your customers, updated 27 March 2026)

What AUSTRAC describes for manual monitoring is a routine, not a product: train the relevant people to recognise unusual transactions and behaviour, schedule regular time, weekly or monthly, to review clients against the indicators, compare each client's activity with their own history and with similar clients, and escalate anything unusual to the compliance officer. Then it says the thing that decides examinations: without a process to review and respond to unusual transactions or behaviour, "it's unlikely that you'll be able to show that you're managing or mitigating your customers' ML/TF risks."

The evidence of that routine is small and dated. A diary entry for the monthly review. A file note when an indicator appeared and what you decided. A record of the escalation. And when the decision is that there are reasonable grounds for suspicion, the clock starts: an SMR within 24 hours where the suspicion relates to terrorism financing, and within three business days after the day the suspicion formed for anything else. (AUSTRAC, suspicious matter reports, updated 8 July 2026) "Strong compliance systems and timely suspicious matter reporting" was the CEO's closing line on Western Union, and the word timely is doing real work in it.

Does the Program Work, or Does It Exist?

AUSTRAC's first test is whether Western Union's program "effectively enables the company to identify, assess and mitigate" its risks. The verb is enables. The program is not being asked whether it is written. It is being asked whether it produces decisions.

For a newly regulated firm the same test starts at the risk assessment, which must identify and assess the inherent risks the business reasonably faces before any controls are applied, and must take into account information AUSTRAC communicates about the risks attached to your designated services. (AUSTRAC, identify and assess your risks, updated 31 March 2026) That last requirement quietly connects the first two tests. The sector indicators are information AUSTRAC has communicated. A risk assessment that never mentions them and a monitoring procedure that never uses them fail the same question from two directions.

We have written before about the program that exists only as a low risk rating nobody can explain, and about running the program as a routine rather than a binder. This investigation is a global company being asked exactly that question, in public.

Who Actually Decides?

The third test has no obvious small firm parallel until you look for it. AUSTRAC will examine Western Union's governance arrangements, "including the role of its global head office in decisions affecting the Australian entity's compliance with its AML/CTF obligations." In plain terms: when a decision about the Australian program was made, who made it, and was the Australian entity in the room?

Now name the head office in your own structure. A franchisor that supplies the CRM and the ID checking vendor. A national brand that hands down a template program. An outsourced compliance consultant. A software provider. Every one of them can shape your program, and none of them carries your obligations.

AUSTRAC's guidance is unambiguous about where accountability sits. A senior manager must personally approve your risk assessment, your AML/CTF policies and any update to either, and cannot delegate that approval. You must keep records showing who approved each decision, when, and why. (AUSTRAC, senior manager, updated 25 March 2026) Outsourcing a governance role is allowed, but "you're responsible for meeting your obligations even where you outsource AML/CTF functions." (AUSTRAC, governance for sole traders and micro businesses, updated 25 March 2026) And the governing body, which in a small firm is usually the owner, must exercise ongoing oversight, must receive the compliance officer's report at least once every 12 months, and must make sure nobody else amends or removes significant findings before they reach it. (AUSTRAC, governing body, updated 25 March 2026)

If a network genuinely wants to centralise compliance, there is a lawful way to do it. AUSTRAC's reporting group guidance names franchises and agency or distribution networks as arrangements that can elect to form a reporting group, which puts a lead entity and defined member obligations on paper. (AUSTRAC, understanding reporting groups, updated 10 July 2026) We covered how that works in August. What does not work is the informal version, where head office decides and the local office signs nothing. Ask the Western Union question about the last change to your own program: when the vendor changed, or the template was updated, who approved it, on what date, and where is the record? The three governance roles may all be you, but the decision still needs your name and a date on it.

What to Do This Week

  1. Pull AUSTRAC's indicator page for your sector and read it beside your monitoring procedure. Every indicator relevant to your services should be something your people would recognise and know where to record. If the procedure predates the current indicators, update it. AUSTRAC expects that.
  2. Put the review in the diary. Weekly or monthly, per AUSTRAC's own description of manual monitoring, with a one line note each time it happens. Six months of those notes is what "we monitor our clients" looks like as evidence.
  3. Write down who decides. For every part of your program that comes from outside the firm, record which senior manager approved adopting it and when. If the honest answer is "head office sent it and we use it", that is the gap.
  4. Check the SMR clock is in the procedure. Twenty-four hours for terrorism financing, three business days for everything else, counted from the day the suspicion formed. Timely was the regulator's word, not ours.

Where AML Mate Fits

AML Mate carries AUSTRAC's suspicious activity indicators for your industry inside the dashboard, keeps client risk reviews and approvals as dated records, and exports the trail when someone asks for it. The free compliance check takes five minutes and shows which of the four items above is already in place.

AUSTRAC will decide what action to take, if any, only once the investigation is finished, and the release says so. But it has already told every reporting entity what the questions are. The useful thing about a published test is that you can sit it early.


This article is general information, not legal advice. For advice specific to your circumstances, consult a qualified AML/CTF professional.

austracwestern-unionenforcementinvestigationtransaction-monitoringongoing-cddsuspicious-activity-indicatorsgovernanceexternal-audittranche-2accountantslegalreal-estateconveyancersjewellers

Ready to build your AML/CTF program?

AML Mate generates your AML/CTF program in 15 minutes using AUSTRAC's official templates. Start a 14-day free trial, cancel anytime.

This article is based on AUSTRAC's publicly available guidance. It does not constitute legal or compliance advice. Consult a licensed compliance professional for complex situations.