On Friday 29 August 2025, the final Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Final Rules) were tabled in Parliament following 9 months of consultation.
The Final Rules differ in some material respects from the draft version mostly recently consulted on (the Draft Rules) and reporting entities should carefully consider the impact of the changes to the Final Rules, especially if plans to uplift AML/CTF Program documentation, policies, systems or procedures have been prepared based on the Draft Rules.
There remain a number of concerns that have not been fully addressed in the Final Rules (for example, the application of the value transfer services to gift card issuers and potential inconsistencies between travel rule requirements and foreign law). Reporting entities may wish to consider advocating for these matters to be addressed in either sector-specific guidance or, if greater certainty is required, engaging with AUSTRAC directly to obtain a formal exemption under section 248 of the amended AML/CTF Act.
In terms of next steps:
- AUSTRAC intends to release core guidance in October 2025 and sector-specific guidance in December 2025.
- Most changes for existing reporting entities will commence on 31 March 2026 and changes for entities that only provide “tranche 2” designated services will commence on 1 July 2026.
We set out in the table below our key takeaways based on the differences between the Draft Rules and the Final Rules.
|
Key takeaways
|
INDIVIDUAL
|
Example
uses 2
|
|
1. Rules that deem certain initial CDD matters to have been established are a helpful starting point but meeting conditions may create practical challenges
The initial CDD requirements in the Final Rules remain prescriptive, with limited relief provided. There are various rules (primarily rules 6-17 and 6-19) that “deem” certain initial CDD matters to have been established. However, these deeming rules do not apply to every matter in section 28(2) that must be established and the conditions that must be met to rely on these rules create some practical challenges. There has also been some confusion introduced in relation to initial CDD for trusts. The initial CDD requirements no longer apply in respect of “trustees of a trust” but rather to “trusts”. This arguably creates confusion regarding the legal person that is the “customer” of the designated service, with the Explanatory Statement suggesting that the “trust estate should be treated as the customer”. Initial CDD requirements are also imposed for trustees (as persons acting on behalf of the customer) and beneficiaries (as persons on whose behalf the customer receives the service). It is easiest to illustrate the operation of the “deeming” provisions with an example: a reporting entity carrying out initial CDD in relation to a trust. If the reporting entity treats the “trust” as the “customer” of the designated service (ie the legal relationship between the trustee and beneficiaries), key initial CDD requirements include establishing on reasonable grounds the identify of beneficiaries (as persons on whose behalf the trust is receiving the designated service), the identity of trustees and their authority to act (as persons acting on behalf of the trust), and the identity of any beneficial owners of the trust. The new rule 6-17 deems the reporting entity to have established these matters subject to certain conditions, including that:
Even if rule 6-17 applies, certain prescriptive requirements will still apply, including to:
If rule 6-17 does not apply, there are other provisions that deem specific matters to have been established. However, the conditions to rely on these provisions again create practical challenges. For example, rule 6-19 deems a reporting entity to have established the identity of persons acting on behalf of the trust (eg trustees) and their authority to act. Unusually, one of the conditions to rely on this is that the reporting entity establishes on reasonable grounds the trustee’s authority to act on behalf of the trust (ie it is circular). |
|
|
|
2. The delayed verification provisions have been expanded
Where a designated service is provided at or through a permanent establishment in Australia, a reporting entity may defer establishing certain matters (Permitted Matters) until after providing the designated service, provided certain requirements are met. Although the Final Rules reduce the timeframe in which a reporting entity must establish the Permitted Matters from 30 to 20 days after providing the designated service, they also allow a wider range of matters to be deferred, including the establishment of the identity of any person on whose behalf the customer is receiving the designated service, the identity of beneficial owners, and the nature and purpose of the business relationship or occasional transaction. Further, certain conditions to rely on the delayed verification relief when opening an account and allowing a deposit have been removed. For example, the Final Rules replace the requirement to identify the ML/TF risk of the customer and take reasonable steps to establish individual customers are the person they claim to be with a requirement not to make transfers on behalf of the customer or make money available to the customer (otherwise than by holding the money in the opened account). |
|
|
|
3. Limited relief from travel rule obligations for offshore permanent establishments has been included
Under the Draft Rules, the travel rule applied where an item 29, 30 or 31 designated service (Value Transfer Service) was provided irrespective of whether the transfer occurred entirely offshore. The Final Rules provide that the travel rule does not apply to a person providing a Value Transfer Service at or through a foreign permanent establishment provided that:
However, this means that the travel rule must still be applied even if the value is transferred completely offshore where:
No relief has been provided in the Final Rules where compliance with the travel rule would not be permitted under local laws. Further, there was a concern with the Draft Rules that foreign permanent establishments accepting transfer instructions from existing customers would need to verify information about their customer to comply with the travel rule (even if they were relying on grandfathering relief from initial CDD obligations). The Final Rules now address this concern and provide that an ordering institution is not required to verify certain information about a payer in relation to instructions accepted before 1 July 2030 provided that:
|
|
|
|
4. Clear relief has now been provided from initial CDD for existing customers of foreign permanent establishments in FATF countries
The Draft Rules only provided limited relief from initial CDD for existing customers of foreign permanent establishments of reporting entities. A new rule has been included providing that a reporting entity is deemed to comply with initial CDD obligations in respect of a customer if:
|
|
|
|
5. If all members of a business group do not agree in writing on a lead entity, no “business reporting group” is automatically formed
Under the Draft Rules, each entity in a “business group” automatically became a member of a “reporting group” if at least one person in the business group provided a designated service (Business Reporting Group). Under the Final Rules, a Business Reporting Group won’t be formed unless each member of the “business group” agrees in writing as to which member is the lead entity of the reporting group (being a member that satisfies certain requirements in Rule 2-1(2)). One consequence of this may be that if one or more members of the business group do not agree in writing on a lead entity, or if the agreed lead entity does not meet the requirements in rule 2-1(2), none of the members may be part of the reporting entity’s “reporting group”. This means that the reporting entity may be unable to rely on section 236B(5) of the amended AML/CTF Act where other members of that business group discharge its obligations (although common law principles of agency may still apply). |
|
|
|
6. The definition of “security” includes interests in managed investments schemes
As part of the amendments to the AML/CTF Act, the definition of “security” was changed to have the same meaning as “security” in Chapter 7 of the Corporations Act 2001 (Cth) (Corporations Act) (rather than prior to the amendments where the definition was based on section 92(1) of the Corporations Act). However, the definition of “security” in Chapter 7 of the Corporations Act does not include interests in a managed investment scheme because they are treated as a separate financial product under Chapter 7. The Final Rules have resolved this issue by clarifying that the definition of “security” includes interests in a managed investment scheme. It remains important to remember that the new definition has significantly expanded the definition of “security” beyond share, debentures and now interests in a managed investment scheme to include, for example, a legal or equitable right in a share, debenture or interest in a managed investment scheme or a right to acquire such a product. |
|
|
|
7. Transitional relief is provided for SMR and TTR obligations (but not for the travel rule)
The Final Rules provide transitional relief for SMRs and TTRs which differs according to when the obligation to submit the report to AUSTRAC arises:
Although the application of the travel rule has been modified (particularly for offshore transfers), no transitional relief has been provided in the Final Rules. |
|
|



