Received a notice from AUSTRAC? What it means and what to do next

Oct 6, 2026

BANNER BLOG 1 (1)-1

By Greta Menzies, Founder & Chief Executive Officer, My Databoss

When the reforms came in on 1 July, most of the conversation was about the deadline. But the conversation has moved on. AUSTRAC has started writing to businesses it believes should be enrolled, and we now have business owners sitting at home, stressed that they’ve received one of these notices and wondering how to fix it. And on the 30th September, AUSTRAC began issuing infringement notices to businesses that still haven't enrolled.

If that is you, the important thing is to get a plan in place, get advice on your response and get support. It is serious, but it is manageable, and you are not the only one.

What is a section 167 notice?

It is a compulsory formal notice under section 167 of the AML/CTF Act that requires you to give AUSTRAC specific information or documents by a set date. It applies whether or not you are enrolled (Clyde & Co).

So it is not a reminder to enrol. It is a request for records, which means it is really asking one question: can you show what you have done?

What is an Infringement notice?

It is a penalty. Where a section 167 notice asks you for information, an infringement notice is issued when AUSTRAC believes a breach has already happened. In this case, the breach is providing designated services without being enrolled.

AUSTRAC began issuing them on 1 October 2026. The penalty is $21,840 for a company and $4,368 for an individual, and it can keep accruing for each day the business remains unenrolled

Why is this happening now?

Obligations started on 1 July and the deadline to enrol was 29 July. By mid-August, fewer than half of the businesses expected to enrol had done so. As at 13 August 2026, 39,520 of an expected 89,557 Tranche 2 businesses had enrolled, or 44 per cent (AUSTRAC figures published by Hall & Wilcox, 18 August 2026).

I understand why the number is low. These sectors are dominated by small businesses, and many of them are managing a lot of change at once. Most have also never been regulated in this way before, so the weight of the obligation may not have landed yet.

So the notices are AUSTRAC's way of making sure the obligation lands. Before 1 July, the message was about awareness and getting ready. Now the deadline has passed, and a business that provides designated services but hasn't enrolled is out of step with the law. The notices make that clear, and in my view they are a signal that this isn't going away.

What does AUSTRAC actually expect?

This is the part I want people to hear. AUSTRAC has said it does not expect newly regulated businesses to be perfect from day one. It expects honest efforts to meet your obligations and to report suspicions. Its enforcement focus is on businesses that wilfully ignore the obligation to enrol, or that are complicit in or wilfully blind to money laundering (AUSTRAC).

So the question isn’t whether your program is perfect. It’s whether you can show a genuine effort that is actually working. That effort only counts if you can evidence it.

Why I expect enforcement to increase

Unfortunately, this is here to stay, and I think we will see more of the regulator from here, not less.

Australia is being assessed on how well its AML/CTF regime works. The Financial Action Task Force, the global body that sets anti-money laundering standards, is running Australia's next evaluation across 2026 and 2027 (Department of Home Affairs). Many comparable countries brought real estate, accounting and legal services into their regimes years ago. Australia was one of the few that hadn't, leaving these sectors open to criminals to exploit. Now that the gap has closed, Australia needs to show the evaluators that the new framework is actually working.

That means demonstrating more than enrolment numbers. In my view, it means showing that the regulator is monitoring these sectors and acting where businesses aren’t meeting their obligations. The notices are the first visible step.

AUSTRAC has a long track record of enforcement in the sectors it already regulates. Businesses in real estate, accounting and legal haven’t seen that yet, because until 1 July they sat outside the regime. The firms that act now, while AUSTRAC is still focused on honest effort, will be in a far better position than the ones that wait.

What could AUSTRAC ask you to produce?

When I explain the obligation to firms, I break it into five pillars: an AML/CTF program, a compliance officer, customer risk assessments, an audit trail and staff training. A notice can reach into any of them.

In practice, that could mean being asked for your assessment of which services are designated, your risk assessment, your customer due diligence files, how you verified the beneficial owners of your business clients, and what monitoring you have done since onboarding.

AUSTRAC judges compliance by evidence, not effort or intent. You can understand the law and apply it well, but if you can’t show months later what you did, you are exposed.

I haven’t enrolled. Where do I start?

  1. Read the notice carefully and seek advice on your response. Note what it asks for and when it is due.
  2. If you provide designated services, enrol now.
  3. Appoint your compliance officer and notify AUSTRAC. They need to be at management level, resident in Australia and a fit and proper person.
  4. Get your risk assessment and program in place, and write down your plan for the gaps.

That last step matters more than people think. A documented plan that you are working through is what honest effort looks like on paper.

I’ve enrolled. Would my records hold up?

Try this. Pick five recent clients and ask your team to pull the full record for each one. The verified ID, the beneficial owners if it’s a company or trust, the risk rating and why, and anything that has happened since onboarding.

If someone says, “give me a minute, I think it’s in an email somewhere,” that is your gap.

It is the most common one we see. In the past, compliance lived in policies that were filed away and never really tested. Most firms had their policies written by 1 July. The harder part is making them living and breathing documents that show up in how the team actually works, so you are audit ready at any point in time.

What are the firms doing this well doing differently?

They treated it as a change to how the business runs, not a document to file.

DiJones is a good example. It has offices across Sydney, Wollongong, the Southern Highlands and the Central Coast, and each office had its own way of doing things. Brent May, their COO, put it well: “We weren’t looking for software. We were looking for an operating model.” Now every office follows the same workflow and every decision is recorded as it happens.

Owen Hodge Lawyers moved early too. Rolf Howard, their CEO, says the platform “gives us confidence that obligations are being applied consistently, without disrupting how we work.”

That's the difference a working system makes. When the regulator asks, the answer is a report, not a fortnight of digging.

Can compliance actually be good for your business?

I think it can. I know that is a hard thing to hear when you are holding a letter from the regulator, but I have watched it happen with our clients.

When compliance runs through documents and inboxes, it is pure cost. Your team spends time searching for files and asking clients for the same ID twice, and none of it is billable. It also gets worse as you grow, because every new client adds to the pile.

When it is built into how the business runs, it starts paying back. Onboarding becomes faster and more consistent, so a buyer or a new client isn’t held up waiting on paperwork. Clients can see their information is being handled properly, and that is trust you can point to. The firm can then take on more work without the compliance load growing at the same rate.

Owen Hodge reduced the amount of sensitive identity information held on its own systems, which lowered its cyber exposure at the same time as meeting its obligations. DiJones can now run one process across every office, which is exactly what a network needs to grow. That isn’t a compliance cost. It’s a better-run business.

You don’t have to work this out alone

We started My Databoss because the tools we needed didn’t exist, so we built them. My Databoss is the Australian platform for identity verification, AML/CTF compliance, secure data sharing and privacy. AML/CTF is where most firms start with us, and the same platform helps you meet the privacy and security obligations that come with the client data you now hold.

Here is what that looks like in practice.

  • One system of record. Identity verification, AML screening, client risk assessments, ongoing monitoring, suspicious matter escalation and staff training all happen in one place, and every verification, screening result, decision and training record is time-stamped as it happens. Your evidence is ready whenever you need it..
  • Start where you are. Bring your own program, build on AUSTRAC's starter kit, or leverage ours, written for legal, accounting and real estate and tailored to your business. Every option links to the workflows your team uses every day.
  • A path for every client. Fast, low-friction digital onboarding is the default, with a secure assisted option for clients who need it. Either way, you get the same complete, consistent record. And if someone stalls, our support team follows up, so your team isn't chasing.
  • Business clients handled properly. Enter an ABN or ACN and the platform builds the beneficial ownership tree and invites each beneficial owner to verify themselves directly.
  • Privacy by design. Clients see why their data is collected, who holds it and how long it is kept. They upload once and can share many times across businesses in our secure network.
  • People behind the platform. Our Australian AML specialists run live sessions every week, including an open floor for shared learnings and assistance navigating complex cases.

The platform is built on Microsoft Azure, hosted in Australia and ISO 27001 certified. That matters to us, because we are asking you to trust us with the same sensitive information your clients trust you with.

If you’ve received a notice, or you want to know your records would hold up if you did, our team will walk you through what a working program looks like for a firm like yours.

Book a demo

This article is general information only and is not legal advice.

Sources: AUSTRAC; Hall & Wilcox, 18 August 2026; Clyde & Co; Department of Home Affairs; My Databoss case studies, DiJones and Owen Hodge Lawyers.