Where the Act reaches into fund management
The AML/CTF Act 2006 (Cth) does not organise its obligations around industries or licence types. It organises them around designated services, defined in section 6 of the Act through tables that list specific activities rather than professions. An AFSL holder, a responsible entity or a trustee becomes a reporting entity under the Act the moment it provides one of those designated services, regardless of how the entity describes its own business or how it is licensed. For an investment manager the relevant services typically include issuing an interest in a registered or unregistered managed investment scheme, accepting an investment or subscription into a fund, and, in many structures, acting as trustee for pooled capital. Arranging for a client to receive one of these services can itself be a designated service, which means a corporate advisory practice introducing capital into a fund it does not operate can also fall inside the perimeter. The practical consequence is that the question an investment manager has to ask is not whether it holds an AFSL or resembles a bank, but whether any part of its business, examined service by service, matches an item on the table. Some functions inside a single manager may sit inside the perimeter while others, custody arranged through a third party administrator for instance, sit outside it, so the analysis has to be done at the level of the specific service rather than assumed for the entity as a whole.
Enrolment with AUSTRAC, and when registration adds a further layer
Once an entity provides a designated service, enrolment with AUSTRAC, the Australian Transaction Reports and Analysis Centre, is not optional and is not something that can wait until a fund has raised its first dollar. Enrolment is the baseline obligation attaching to every reporting entity providing a designated service listed in the Act, and it has to happen before, not after, that service is first provided. Enrolment places the entity on AUSTRAC's register and is the gateway through which the entity later lodges compliance reports and submits suspicious matter reports. A narrower group of reporting entities, generally those offering the higher risk designated services identified in the Act, must also register on AUSTRAC's separate register for those business types, a further step carrying its own eligibility requirements on top of enrolment. For an investment manager standing up a new fund, the sequencing question is straightforward in principle and frequently mishandled in practice: enrolment needs to be assessed and, where required, completed as part of the structuring work that precedes launch, not treated as a compliance item to circle back to once the fund is trading. A fund that accepts its first subscription before enrolment is complete has already contravened the Act, and that contravention exists independently of how well the fund's broader compliance program is eventually built.
The AML/CTF program, the compliance architecture behind enrolment
Enrolment establishes that the Act applies. The AML/CTF program is what the Act then requires the reporting entity to build and maintain, and reform has changed what that program has to look like. Where the program was once commonly built and described as two separate parts, a Part A addressing risk based systems and controls and a Part B addressing customer identification procedures, the Act now calls for a single, integrated program that brings both functions together rather than treating them as separate documents governed by separate logic. That program still has to set out how the entity identifies and assesses the money laundering and terrorism financing risk in its business, what governance and oversight sits over the program, how staff are trained, how the program is independently reviewed and kept current, and the practical rules for verifying who a customer is before a designated service is provided, but the Act now expects those elements to sit together as one risk based framework rather than as parallel compliance streams that can drift apart from each other. A program is not a static compliance manual produced once and filed away. The Act expects it to be risk based, meaning the depth of a manager's controls should track the actual risk profile of its investor base, its distribution channels and the jurisdictions its capital moves through, and expects the program to be reviewed and updated as that risk profile changes. A fund manager that copies a program template from another entity without tailoring it to its own investor base, distribution model and product set has a document that satisfies the letter of the requirement without doing the work the requirement exists to do, and that gap tends to surface at the least convenient moment, during an AUSTRAC compliance assessment or in the aftermath of a transaction the untailored program was never built to catch.
Customer due diligence on investors
Customer due diligence is the point at which the AML/CTF program meets the investor sitting in front of the manager. Before providing a designated service, a reporting entity has to collect and verify identifying information sufficient to be reasonably satisfied that the customer is who it claims to be, using reliable and independent documentation or electronic verification. The standard obligation applies to every investor, individual or entity, but the Act calibrates the depth of diligence to the risk the customer presents, which means a manager's program has to build in a genuine risk assessment rather than a single fixed checklist applied uniformly to every applicant.
- Standard due diligence: verifying an individual investor's identity against government issued documentation, or an entity investor's existence, ownership structure and controlling persons against constitutional and register documents.
- Enhanced due diligence: additional verification, closer ongoing scrutiny and, in some programs, senior management sign off, applied where an investor presents as higher risk, including politically exposed persons, complex ownership structures, or connections to higher risk jurisdictions.
- Simplified due diligence: a reduced level of verification available only in the narrow circumstances the Act and its rules define, not a default a manager can apply simply because an investor appears low risk on its face.
- Reliance and outsourcing: a manager can in some circumstances rely on due diligence already performed by another regulated entity, but legal responsibility for the customer's identity stays with the manager regardless of who performed the underlying checks.
Trusts and self managed superannuation funds
Pooled investment vehicles are themselves common investors into other funds, and trust structures, including self managed superannuation funds, present a due diligence problem that a simple individual verification checklist does not solve. A trust is not itself a natural person, so verifying a trust as an investor means verifying the trustee, individual or corporate, verifying the trust itself against its trust deed and any register record, and then looking through the structure to identify the beneficial owners, the individuals who ultimately own or control the trust or stand to benefit from it, rather than stopping at the trustee's own identity. An SMSF investing into a fund raises the same layered question in a common and recurring form: the trustee, whether an individual trustee or a corporate trustee established for the fund, has to be identified and verified in its own right, the trust deed establishing the fund has to be sighted, and the members of the fund, who are typically also its beneficiaries, need to be considered as part of the beneficial ownership analysis even though they may not be signing the application themselves. A common failure point is treating the individuals behind an SMSF as adequately identified because they are well known to the adviser introducing the investment. Familiarity is not verification, and the due diligence obligation runs to the manager receiving the designated service, not to the introducing adviser's own comfort with the client. Discretionary trusts add a further layer again, because the class of potential beneficiaries is often defined broadly in the deed, and a manager's program needs a documented, defensible approach to who within that class is treated as a beneficial owner for due diligence purposes, applied consistently rather than decided ad hoc on each application.
Ongoing monitoring and suspicious matter reporting
Due diligence performed once at onboarding is not where the obligation ends. The Act requires ongoing customer due diligence, meaning a manager has to monitor an investor's transactions and behaviour against the profile built at onboarding, and to update that profile when circumstances change, an investor's structure is altered, a new controlling person appears, or a pattern of activity develops that does not fit the original assessment. Monitoring has to be proportionate to risk, so a program's monitoring intensity should mirror the same calibration that shapes its due diligence, closer for higher risk investors and lighter, though never absent, for lower risk ones.
- Suspicious matter reports: an obligation to report to AUSTRAC where a reporting entity forms a suspicion, on reasonable grounds, that a matter may be relevant to money laundering, terrorism financing or certain other offences, reported within the short statutory timeframe the Act sets, which shortens further where terrorism financing is suspected.
- Other prescribed reports: additional reporting obligations attach to certain transaction types and thresholds set out in the Act and its rules, separate from and additional to the suspicion based reporting obligation.
- Tipping off: a separate offence under the Act to disclose that a suspicious matter report has been made or is being considered, which shapes how a manager can communicate internally and with the investor concerned once a suspicion has been raised.
- Record keeping: due diligence records, transaction records and the reports themselves have to be retained for the period the Act requires, in a form that can be produced to AUSTRAC on request.
The 2024 reform direction, and the practical takeaway
The AML/CTF Act was substantially amended by reforms enacted in 2024, and those reforms move the regime in a consistent direction rather than delivering a single isolated change. The amendments broaden the range of businesses and services the Act reaches, extend elements of the regime toward professions and services that had previously sat outside it, and revise aspects of how customer due diligence, the definition of designated services, and the treatment of digital and virtual assets operate under the Act. The detail of implementation is being staged and refined through AUSTRAC guidance over an extended period, and a manager building or reviewing its program now should treat the 2024 reforms as a signal that the compliance perimeter is widening and the standard of documented, risk based practice AUSTRAC expects is rising, rather than waiting for every implementation detail to settle before beginning that work.
For an investment manager, the practical position is straightforward to state and genuinely demanding to execute. The designated service test decides whether the Act applies at all, and that test has to be checked service by service rather than assumed from the manager's licence type. Enrolment, and registration where it applies, has to be complete before the first designated service is provided, not treated as a parallel workstream to launch. The AML/CTF program has to be built around the manager's actual investor base and risk profile, not adopted as a template, and has to be reviewed as that base and the regulatory perimeter around it both change. Due diligence on trusts and superannuation funds needs a documented approach to beneficial ownership that survives scrutiny, not an assumption that familiarity with the introducing adviser is enough. None of this sits comfortably as a task to finish once and file away. It is a standing discipline that has to keep pace with a regime that is, by design, becoming broader rather than narrower.
This article is general information only and does not constitute investment, legal, tax or financial product advice.
Related work


