By Greta Menzies, Founder & Chief Executive Officer, My Databoss
When the reforms came in on 1 July, most of the conversation was about the deadline. But the conversation has moved on. AUSTRAC has started writing to businesses it believes should be enrolled, and we now have business owners sitting at home, stressed that they’ve received one of these notices and wondering how to fix it. And on the 30th September, AUSTRAC began issuing infringement notices to businesses that still haven't enrolled.
If that is you, the important thing is to get a plan in place, get advice on your response and get support. It is serious, but it is manageable, and you are not the only one.
It is a compulsory formal notice under section 167 of the AML/CTF Act that requires you to give AUSTRAC specific information or documents by a set date. It applies whether or not you are enrolled (Clyde & Co).
So it is not a reminder to enrol. It is a request for records, which means it is really asking one question: can you show what you have done?
It is a penalty. Where a section 167 notice asks you for information, an infringement notice is issued when AUSTRAC believes a breach has already happened. In this case, the breach is providing designated services without being enrolled.
AUSTRAC began issuing them on 1 October 2026. The penalty is $21,840 for a company and $4,368 for an individual, and it can keep accruing for each day the business remains unenrolled
Obligations started on 1 July and the deadline to enrol was 29 July. By mid-August, fewer than half of the businesses expected to enrol had done so. As at 13 August 2026, 39,520 of an expected 89,557 Tranche 2 businesses had enrolled, or 44 per cent (AUSTRAC figures published by Hall & Wilcox, 18 August 2026).
I understand why the number is low. These sectors are dominated by small businesses, and many of them are managing a lot of change at once. Most have also never been regulated in this way before, so the weight of the obligation may not have landed yet.
So the notices are AUSTRAC's way of making sure the obligation lands. Before 1 July, the message was about awareness and getting ready. Now the deadline has passed, and a business that provides designated services but hasn't enrolled is out of step with the law. The notices make that clear, and in my view they are a signal that this isn't going away.
This is the part I want people to hear. AUSTRAC has said it does not expect newly regulated businesses to be perfect from day one. It expects honest efforts to meet your obligations and to report suspicions. Its enforcement focus is on businesses that wilfully ignore the obligation to enrol, or that are complicit in or wilfully blind to money laundering (AUSTRAC).
So the question isn’t whether your program is perfect. It’s whether you can show a genuine effort that is actually working. That effort only counts if you can evidence it.
Unfortunately, this is here to stay, and I think we will see more of the regulator from here, not less.
Australia is being assessed on how well its AML/CTF regime works. The Financial Action Task Force, the global body that sets anti-money laundering standards, is running Australia's next evaluation across 2026 and 2027 (Department of Home Affairs). Many comparable countries brought real estate, accounting and legal services into their regimes years ago. Australia was one of the few that hadn't, leaving these sectors open to criminals to exploit. Now that the gap has closed, Australia needs to show the evaluators that the new framework is actually working.
That means demonstrating more than enrolment numbers. In my view, it means showing that the regulator is monitoring these sectors and acting where businesses aren’t meeting their obligations. The notices are the first visible step.
AUSTRAC has a long track record of enforcement in the sectors it already regulates. Businesses in real estate, accounting and legal haven’t seen that yet, because until 1 July they sat outside the regime. The firms that act now, while AUSTRAC is still focused on honest effort, will be in a far better position than the ones that wait.
When I explain the obligation to firms, I break it into five pillars: an AML/CTF program, a compliance officer, customer risk assessments, an audit trail and staff training. A notice can reach into any of them.
In practice, that could mean being asked for your assessment of which services are designated, your risk assessment, your customer due diligence files, how you verified the beneficial owners of your business clients, and what monitoring you have done since onboarding.
AUSTRAC judges compliance by evidence, not effort or intent. You can understand the law and apply it well, but if you can’t show months later what you did, you are exposed.
That last step matters more than people think. A documented plan that you are working through is what honest effort looks like on paper.
Try this. Pick five recent clients and ask your team to pull the full record for each one. The verified ID, the beneficial owners if it’s a company or trust, the risk rating and why, and anything that has happened since onboarding.
If someone says, “give me a minute, I think it’s in an email somewhere,” that is your gap.
It is the most common one we see. In the past, compliance lived in policies that were filed away and never really tested. Most firms had their policies written by 1 July. The harder part is making them living and breathing documents that show up in how the team actually works, so you are audit ready at any point in time.
They treated it as a change to how the business runs, not a document to file.
DiJones is a good example. It has offices across Sydney, Wollongong, the Southern Highlands and the Central Coast, and each office had its own way of doing things. Brent May, their COO, put it well: “We weren’t looking for software. We were looking for an operating model.” Now every office follows the same workflow and every decision is recorded as it happens.
Owen Hodge Lawyers moved early too. Rolf Howard, their CEO, says the platform “gives us confidence that obligations are being applied consistently, without disrupting how we work.”
That's the difference a working system makes. When the regulator asks, the answer is a report, not a fortnight of digging.
I think it can. I know that is a hard thing to hear when you are holding a letter from the regulator, but I have watched it happen with our clients.
When compliance runs through documents and inboxes, it is pure cost. Your team spends time searching for files and asking clients for the same ID twice, and none of it is billable. It also gets worse as you grow, because every new client adds to the pile.
When it is built into how the business runs, it starts paying back. Onboarding becomes faster and more consistent, so a buyer or a new client isn’t held up waiting on paperwork. Clients can see their information is being handled properly, and that is trust you can point to. The firm can then take on more work without the compliance load growing at the same rate.
Owen Hodge reduced the amount of sensitive identity information held on its own systems, which lowered its cyber exposure at the same time as meeting its obligations. DiJones can now run one process across every office, which is exactly what a network needs to grow. That isn’t a compliance cost. It’s a better-run business.
We started My Databoss because the tools we needed didn’t exist, so we built them. My Databoss is the Australian platform for identity verification, AML/CTF compliance, secure data sharing and privacy. AML/CTF is where most firms start with us, and the same platform helps you meet the privacy and security obligations that come with the client data you now hold.
Here is what that looks like in practice.
The platform is built on Microsoft Azure, hosted in Australia and ISO 27001 certified. That matters to us, because we are asking you to trust us with the same sensitive information your clients trust you with.
If you’ve received a notice, or you want to know your records would hold up if you did, our team will walk you through what a working program looks like for a firm like yours.
This article is general information only and is not legal advice.
Sources: AUSTRAC; Hall & Wilcox, 18 August 2026; Clyde & Co; Department of Home Affairs; My Databoss case studies, DiJones and Owen Hodge Lawyers.