Skip to main content
Regulations

AUSTRAC 1 July 2026: a readiness primer

The biggest AML overhaul Australia has seen in two decades. What changes, who's in scope, what your compliance stack needs to look like by 1 July 2026, and where AI agents fit into the new requirements.

CT

Cogentic Team

20 February 2026 · 6 min read

The AML/CTF Amendment Act 2024 is the biggest AML overhaul Australia has seen in two decades. It brings tranche 2 entities under AUSTRAC supervision, expands obligations for existing DCEs, introduces ongoing customer due diligence, and tightens reporting deadlines. Enrolment runs from 31 March 2026. Full compliance is mandatory by 1 July 2026.

This primer is for AU VASPs hitting the deadline — both existing DCEs upgrading their compliance stack and tranche 2 entrants onboarding for the first time. It covers what changes, who's in scope, the operational shape of compliance under the new regime, and where AI agents fit. It is the document we hand to MLROs we work with.

What changes

Tranche 2 entities now in scope

Real-estate professionals, lawyers, accountants, trust and company service providers, and dealers in precious metals and stones move under AUSTRAC supervision. Crypto-adjacent businesses operating in these verticals — OTC desks, escrow services, custody-light operators — need to enrol with AUSTRAC and operationalise compliance from day one.

For existing crypto DCEs, this is mostly a counterparty story. Your counterparty universe widens because more entities are now obliged. Counterparty due diligence and Travel Rule data exchange now flow with a broader set of partners.

Ongoing customer due diligence

The reform shifts CDD from point-in-time to ongoing. Risk re-evaluation must trigger on material facts: sanctions list updates, adverse-media hits, transaction-pattern shifts, counterparty VASP status changes, KYC document expiry. Your compliance system needs to surface these triggers automatically. Quarterly batch reviews don't satisfy the obligation.

Tighter SMR deadlines

AUSTRAC SMR submissions move to 3 business days for money-laundering matters and 24 hours for terrorism-financing matters. The math doesn't work with manual investigations — a typical L2 case at most VASPs takes 3–6 hours of senior analyst time. Three days is feasible if your team is fully staffed and not burning weekends. Twenty-four hours is feasible only if context-gathering is compressed.

Stronger record-keeping

Seven-year evidence retention with verifiable integrity. Examiner-ready evidence packs producible on request. AUSTRAC's audit posture under the reform is more documentation-heavy than the previous regime — the immutable evidence ledger and cryptographically bound SAR signatures are not optional infrastructure if you want to defend an examiner conversation in 2027.

Who is in scope

Existing DCEs

Already enrolled with AUSTRAC. Operating under AML/CTF obligations. Need to upgrade their compliance stack to handle ongoing CDD, tighter SMR deadlines, and stronger record-keeping. Most pilot conversations we run are existing DCEs upgrading ahead of 1 July rather than scrambling on the day.

Tranche 2 entrants

New AUSTRAC supervision. Need to enrol, build out an AML/CTF programme, train MLRO and compliance staff, and operationalise reporting. Onboarding is a longer engagement than for existing DCEs — typically 8–12 weeks if no AML programme exists today.

Cross-border crypto businesses

If you serve Australian customers and are not enrolled, the reform makes enrolment more pressing. AUSTRAC's enforcement posture under the new regime tightens. Cross-border digital-asset platforms with AU customer exposure should plan for 2026 obligations even if Australia is not their primary market.

The operational shape

What your compliance operation needs to look like by 1 July.

Alert triage

L1 alerts from Chainalysis KYT, TRM Monitoring, Elliptic Navigator, and internal rules need to land in a single ranked queue with confidence scores. False positives auto-close with logged reasoning. Real alerts escalate with context. Most VASPs running point tools in 2026 have alerts spread across vendor dashboards — that's the constraint to remove first.

Investigation throughput

L2 cases need to compress from 3–6 hours to under 30 minutes including MLRO review. The compression is the only way to hit the 3-day SMR deadline at scale. AI agents that produce structured evidence packs — entity graph, flow trace, counterparty context, peer-baseline comparison, typology ranking — are the throughput multiplier.

AUSTRAC SMR drafting

SMR draft time of 30 minutes including MLRO review is the right target. Format is AUSTRAC's structured fields plus narrative section. Narrative in AUSTRAC's expected register, with page-anchored citations to source evidence. Drafted from the evidence pack, not written from scratch.

Reporter of record

MLRO is the named reporter on every SMR. Cryptographic signature binds to SMR content hash so any post-signature edit invalidates it. The reasonable-grounds judgement stays human. AI drafts; the officer decides.

Audit and record-keeping

Immutable evidence ledger with cryptographic integrity. Bit-identical case reconstruction at any time inside the 7-year retention window. Examiner-ready evidence packs in one click. SR 11-7 model risk documentation produced by default for any AI tool in scope.

Where AI agents fit

Two of the three loops AI agents perform — alert triage and investigation — directly address the throughput problem the reform creates. The third loop — reporting — directly addresses the deadline problem.

An AI agent in the investigation loop turns a 4-hour senior-analyst task into a 5-minute agent run plus a 15-minute MLRO review. An AI agent in the reporting loop turns a 4-hour SMR drafting task into a 30-second draft plus a 15-minute MLRO review. End-to-end alert-to-signed-SMR compresses from a working day to under 25 minutes. That's how you hit a 3-day deadline reliably.

For tranche 2 entrants, the question is different — you're building from zero. The AI agent shape lets you start without staffing a 5–10-person compliance team for the first quarter. Onboarding agents (extend the surface at most vendors, available now via FDE for some) handle the enrolment-to-operations transition.

What to do this quarter

If you're an existing DCE

  • Audit current compliance stack against ongoing CDD requirements (sanctions list updates, adverse media, KYC expiry, counterparty status changes)
  • Map your current investigation throughput. If average L2 case time is over an hour, plan for AI-agent augmentation
  • Run pilot conversations with two or three agentic AI vendors before end of Q2. Six-week pilots run through the reform deadline cleanly.
  • Confirm your audit ledger meets 7-year retention with cryptographic integrity. If not, prioritise this — it's the procurement-team gate

If you're a tranche 2 entrant

  • Begin AUSTRAC enrolment process now if not started. Engagement timelines tighten as the deadline approaches
  • Identify your MLRO. Their training and certification timeline often dominates the onboarding critical path
  • Scope your compliance stack ground-up. Skip the legacy AML suite — it deploys in 18 months. AI-agent-first vendors deploy in weeks
  • Build your AML/CTF programme document with vendor support. Most agentic vendors have programme templates aligned to AUSTRAC expectations

How Cogentic fits

AUSTRAC AML/CTF is. Investigation Agent and Reporting Agent are live, with AUSTRAC SMR drafting and goAML XML export. Reporter-of-record model baked in. SR 11-7 model risk documentation by default. Audit ledger with 7-year retention configured per the reform's record-keeping standards.

We work with existing DCEs upgrading their compliance stack, and with tranche 2 entrants building from zero.

AUSTRAC readiness

Walk the readiness checklist

Twenty minutes with the Cogentic team. We walk your stack against the 1 July reform and show what we'd ship for your pilot.

Book a readiness conversation
Cogentic platform

See how Cogentic fits your compliance stack

Investigation Agent and AUSTRAC SMR drafting live now. Reads your KYT vendor, runs alongside your case tool, MLRO signs every report.

See the platform
CT

Written by

Cogentic Team

The Cogentic compliance team brings together experts in crypto regulation, AML compliance, and financial technology. We share intelligence to help VASPs navigate the complex world of Travel Rule compliance.

Related articles