If your compliance calendar has "AUSTRAC annual report" pencilled in for 31 March, move it. The reporting period changed with the reforms: compliance reports now run on financial years, and the next reporting period is 1 July 2026 to 30 June 2027, with the report lodged between 1 July and 30 September 2027 (AUSTRAC, annual compliance reports).
For a Tranche 2 firm, that report will be your first ever. And here is the part worth sitting with: the reporting period started seven weeks ago. Every question AUSTRAC will ask you next July is being answered right now, by the records you are keeping or not keeping this month.
The deadline moved, and most templates have not caught up
Under the old regime, compliance reports covered calendar years and were lodged by 31 March. The 2025 report, the last of that line, covered 1 January to 31 December 2025 and was submitted between 1 January and 31 March 2026, and it only applied to entities that were already regulated (AUSTRAC, 2025 compliance report preview).
The reformed Act keeps the obligation, under section 47(2) and Rules section 9-9, but resets the clock. Reporting periods are now financial years, and you must submit within 3 months of the period ending, which makes the standing window 1 July to 30 September each year (AUSTRAC, annual compliance reports).
So there is no 31 March 2027 deadline. There is a 30 September 2027 one, and it covers your entire first year in the regime. Plenty of older guides, ours included, were written before the cadence changed, so if a template or checklist you downloaded in autumn still says March, it is describing the old world. We have updated our earlier explainer on the compliance report and its enforcement history for the same reason.
Failing to lodge is not a paperwork foot-fault, either. AUSTRAC lists remedial directions and infringement notices among the consequences for not submitting by the due date (AUSTRAC, annual compliance reports), and it has taken reporting entities to the Federal Court over missing reports before.
Mostly multiple choice, and that is the trap
AUSTRAC publishes the report questions in advance so businesses can prepare. The next set will be updated for the reformed Act, a redesign AUSTRAC has since made official in its 2026-27 regulatory priorities, but the 2025 preview shows the flavour, and it has barely any free text (AUSTRAC, 2025 compliance report preview). Did you have an AML/CTF program? Was it approved by your governing body or senior management? When was it last approved? Did you conduct a documented risk assessment, and what prompted it? What training did you provide? What employee checks did you run? How did staff report unusual or potentially suspicious activity?
Tick-box questions sound easy until you notice what they quietly require. "When was your program last approved" assumes an approval record with a date on it. "What prompted these changes" assumes you wrote down why. And then there are the count questions: approximately how many customers do you have, how many are high risk, how many did you identify as politically exposed persons. Those are numbers, not vibes. You either have a register that produces them or you are guessing on a government form.
The sharpest question in the 2025 set is the one that fires when you select "staff did not identify and report any unusual or potentially suspicious activity": why not, in 500 characters (AUSTRAC, 2025 compliance report preview). We wrote about why a permanent zero looks like under-reporting, and the compliance report is exactly where that conversation with AUSTRAC starts.
None of this is trivia collection. AUSTRAC says compliance report information helps it see who needs assistance, improve guidance, and develop supervision campaigns and assessments (AUSTRAC, annual compliance reports). In plain terms: your answers help decide who gets a closer look.
Every question is a register you either keep or reconstruct
Here is the useful coincidence. AUSTRAC's record-keeping guidance publishes a table of records that "may demonstrate compliance" with each program obligation (AUSTRAC, record keeping overview). Line it up against the report questions and the two documents are nearly mirror images. The report asks the questions; the record-keeping guidance lists the paperwork that answers them.
| The report asks about | The record that answers it |
|---|---|
| Whether you have a program, who approved it, when | Program version history, senior manager approval records, notification to the governing body |
| Your ML/TF risk assessment, and what prompted it | The documented assessment with approval dates, approver details and version history |
| Whether the governing body was kept informed | Briefings, meeting minutes, and compliance officer reports at least once every 12 months |
| Training you provided, and updates to it | A training plan plus a register of attendance, results and completion |
| Personnel checks you ran | Background checks and results, reassessment records, role descriptions |
| How staff escalated unusual activity | An internal escalation log, case notes, and a reporting log with the date, type and reference of every report lodged with AUSTRAC |
| High-risk customers, PEPs, and ECDD conducted | Customer risk ratings with rationale, an ECDD register showing trigger, measures and approvals, and a high-risk customer register |
All of it from AUSTRAC's own examples (AUSTRAC, record keeping overview). If you set up your record-keeping discipline properly in July, this table is describing files you already have. If you did not, it is a shopping list, and August is a much better month to start than June 2027.
One clarification that saves storage headaches: you are not required to keep copies of ID documents. You record what you did to identify the customer and the details you relied on, not a folder of passport scans (AUSTRAC, record keeping overview).
The numbers you cannot make up in September 2027
A narrative can be reconstructed late. You can, at a pinch, write up in June 2027 the story of how your program operated. What you cannot reconstruct are counts and dates. How many clients did you risk-rate this year, and how many came out high risk? On what date did the senior partner approve the updated risk assessment, and which hat were they wearing when they did? How many staff completed training, and who missed it?
These only exist if they were written down at the time. That is the real argument for treating the compliance report as a monthly habit rather than an annual project: not fear of AUSTRAC, just the arithmetic of memory. Ten minutes a month updating four registers beats a fortnight of archaeology, and it is the same routine discipline that operating your program already demands. The report simply reads it back.
The housekeeping that takes five minutes now
Three practical details from AUSTRAC's own page (AUSTRAC, annual compliance reports):
You lodge through AUSTRAC Online, and only someone listed as an administrator on your account can submit. Log in now and check who that is. If the only administrator is a partner who retires in March, fix that before it is a September problem.
AUSTRAC sends reminders to the email addresses on file for your compliance officer and primary contacts. If those details are stale, the reminder goes to a mailbox nobody reads.
If you are part of a reporting group, only one member should lodge the report on behalf of the group, and AUSTRAC does not tell the other members it has been lodged. The lodging member has to tell everyone else, so agree now on who lodges and how they confirm it.
Fifteen minutes this month
- Fix the calendar. Reporting period ends 30 June 2027; lodgement window 1 July to 30 September 2027. Delete any 31 March entry left over from older guides.
- Check AUSTRAC Online: confirm who your administrators are and that your compliance officer and primary contact emails are current.
- Open the 2025 preview questions and read them once. Twenty minutes, and you will know exactly what your records need to produce.
- Start the registers that answer the count questions: training completions, ECDD events, high-risk customers, PEP identifications, internal escalations. A spreadsheet each is enough. If your program lives in AML Mate, these registers build themselves as you work, and the audit export produces the whole trail in one file.
- Minute what you are already doing. The independent evaluation years from now and the compliance report next July both run on the same fuel: contemporaneous records of decisions you genuinely made.
The compliance report is not an exam you can cram for. It is a mirror held up to financial year 2026-27, and the reflection is being composed now, one training entry, one risk rating, one minuted approval at a time. Firms that keep the registers will spend half an hour next July confirming what they already know. Firms that do not will spend September 2027 inventing a year they cannot quite remember, on a form that feeds AUSTRAC's supervision planning. Keep the registers.
This article is general information, not legal advice. For advice specific to your circumstances, consult a qualified AML/CTF professional.
