There is a date sitting in a lot of newly regulated firms' calendars that should not be there: 31 March 2027, pencilled in as the deadline for the first AUSTRAC compliance report. It is a forgivable mistake. It was the right answer for twenty years, it is what most of the internet still says, and it is now wrong.
The report did not go away. It moved.
What the report is, and what changed
The compliance report is the one thing every reporting entity submits to AUSTRAC on a fixed annual schedule. It is a set of questions about how you have met your AML/CTF obligations, required under section 47(2) of the Act and section 9-9 of the Rules (AUSTRAC, annual compliance reports). It is not a financial return and it costs nothing to lodge. It is a structured account of your own year.
Under the old arrangement the period was the calendar year and the report was due by 31 March. The Anti-Money Laundering and Counter-Terrorism Financing (2025 Rules) Amendment Rules 2026 realigned the reporting period and the lodgement date to the Commonwealth Performance Framework set out in the Public Governance, Performance and Accountability Act 2013, and AUSTRAC rewrote its guidance on 31 March 2026 to match (AUSTRAC, latest guidance updates).
The new shape is simple. The reporting period is the financial year. You submit within 3 months of a reporting period ending, so the submission window runs between 1 July and 30 September each year, and the report covers your business activities for the previous 1 July to 30 June. AUSTRAC states the next reporting period plainly: 1 July 2026 to 30 June 2027 (AUSTRAC, annual compliance reports, last updated 1 April 2026).
So when is yours due
If your obligations commenced on 1 July 2026, the arithmetic falls out of that in one step.
| What | When |
|---|---|
| Your AML/CTF obligations commence | 1 July 2026 |
| Your first reporting period | 1 July 2026 to 30 June 2027 |
| Your first compliance report lodged | between 1 July and 30 September 2027 |
| Every year after that | the same window, covering the previous financial year |
Two things follow, and firms tend to hear only one of them.
The first: nothing is due from you this September. There was no reporting period ending 30 June 2026 that you could have been part of, because you were not yet carrying obligations. September 2026 is somebody else's deadline.
The second is the one that matters. Your first reporting period is not in the future. It opened on 1 July 2026 and it is running right now. The report you lodge in 2027 asks about your business activities during that period, which means the year being graded is the one you are currently living in, roughly six weeks deep.
The distance between the deadline and the work
That gap is where firms get caught, and it is the same trap as the deadlines that are not deadlines. A due date eleven months away reads as "later". The thing the due date measures is happening today.
You cannot retro-fit training that nobody attended. You cannot reconstruct a sanctions screening you never ran. You cannot backdate a risk rating decision to a file that was closed in August. Come July 2027 the form is either a transcription job, copying across what your records already say, or it is an archaeology project with an honesty problem attached.
The honesty problem is not hypothetical. This is a self-report, and every answer is a statement to the regulator about your own conduct. The comfortable moment to discover a gap is now, while the year is still open and the gap can be closed before it becomes something you have to describe.
What AUSTRAC does with your answers
Firms treat the compliance report as a filing formality because it looks like one. AUSTRAC is unusually direct about what it is for. The information helps AUSTRAC to see if you need any extra assistance to meet your obligations, to improve its education and guidance for businesses, and to develop supervision campaigns and assessments (AUSTRAC, annual compliance reports).
Read that third one again. Your own answers are an input to how the regulator decides where to look. It is not the only input, but it is the one you write yourself, once a year, in your own words. That is worth knowing before you fill it in, and it is worth knowing now, while you still have eleven months to change what the answers will say. AUSTRAC has tens of thousands of new entities to triage, and self-reported data is the cheapest triage there is.
The plumbing to sort out this year, not next
Four details cost nothing to fix today and are irritating to discover in September 2027.
Who is allowed to press submit. To lodge a compliance report you must be listed as an administrator in your AUSTRAC Online account, and there is no limit to how many administrators an account can have (AUSTRAC, annual compliance reports). If your firm has exactly one administrator and that person is on leave, has left, or is the partner who set up the account and then forgot the login, you have a single point of failure with a statutory deadline attached. Add a second administrator while nobody is under pressure.
Whether AUSTRAC can reach you. AUSTRAC sends reminders by email and as messages in your AUSTRAC Online account, which is why it asks you to keep contact details current, including the addresses for your compliance officer and primary contacts (AUSTRAC, annual compliance reports). A reminder delivered to a departed employee's mailbox is not a reminder. If your compliance officer has changed since enrolment, that update belongs in AUSTRAC Online, not just in your program document.
Who lodges if you are in a reporting group. Only one member should lodge the annual compliance report on behalf of all members, and the member who lodged it should tell everyone else, because AUSTRAC does not notify the other members that a report has been received (AUSTRAC, annual compliance reports). Any group member whose circumstances are substantially different can still submit its own report using the override link against the group report in AUSTRAC Online. Two members each assuming the other lodged is a very ordinary way to miss a deadline, so decide now who owns it and how the rest find out. More on the structure in our piece on reporting groups and lead entities.
What if you provided no designated services at all. You still lodge. If you did not provide any designated services during the reporting period, or you sold, closed or merged the business, you are only required to complete the first question of the report to tell AUSTRAC your circumstances (AUSTRAC, annual compliance reports). And if you have stopped providing designated services altogether, that is a separate step: you must request removal from AUSTRAC's roll or registers, or the correspondence keeps arriving.
Exemptions from the report exist and they are narrow. None of them is "small firm". They cover small gaming venues licensed for no more than 15 gaming machines with no other designated services, entities solely registered as an affiliate of a remittance network provider, AFSL holders whose only designated service is making arrangements for a customer to receive a designated service rather than providing it themselves, and businesses granted a specific exemption (AUSTRAC, annual compliance reports). If you are an accountant, lawyer, conveyancer, real estate agent or dealer in precious metals and stones providing designated services, you are lodging.
What missing it costs
If you are required to submit a report and you do not submit by the due date, you may face enforcement action, which can include a remedial direction and an infringement notice (AUSTRAC, annual compliance reports).
That is the guidance's own language, and it understates the tail. AUSTRAC has taken firms to the Federal Court over nothing more than missing compliance reports, and two of them ended up paying more than double the original infringement amount by ignoring the notice that followed. A single missing form is, on its own, enough to start that sequence, which is the point of our earlier piece on the Castra and Princeton proceedings.
The August version of this job
You cannot fill in the 2027 form in 2026. You can make it a five-minute form instead of a five-day one, and the way to do that is to keep the record as the year happens rather than assembling it afterwards. The report asks how you met your obligations, so the record that answers it is simply the record of your obligations being met:
- CDD you completed, including what you did when a client would not cooperate and where you declined the service.
- Screening runs and their outcomes, especially the hits you cleared and why.
- Training delivered, with who attended and when, not just the fact that a course exists. Our training and audit export walkthrough covers what a defensible record looks like.
- Reports lodged, with dates, for both SMRs and TTRs, including the nil periods.
- Your risk assessment and every review of it, with what triggered the review and who approved the result. A rating nobody decided is not a risk assessment.
- Governance changes, meaning who held the compliance officer role, when that changed, and what the governing body was told.
That list is not a compliance calendar so much as a habit. If your program lives in AML Mate, most of it accumulates on its own, and the audit export pulls the year into one file when you need it. If it does not, a shared folder and a monthly fifteen minutes will still beat a scramble in the third quarter of 2027.
The deadline moved and it moved in your favour: you have a full financial year of runway and a lodgement window instead of a single date. That generosity has a catch, which is that the runway is the thing being measured. Diarise 1 July 2027. Then go and do the monthly version of the work, because that is the part the form is actually asking about.
This article is general information, not legal advice. For advice specific to your circumstances, consult a qualified AML/CTF professional.
