AUSTRAC Enforcement and the Tranche 2 Due Diligence Defence
Advisory

AUSTRAC Enforcement and the Tranche 2 Due Diligence Defence

AUSTRAC took two entities to the Federal Court over an unlodged report. What its enforcement record means for Tranche 2 firms and the section 236 defence.

Category
Advisory
Read time
6 min.
Published
August 20, 2026
AUSTRAC Enforcement and the Tranche 2 Due Diligence Defence

AUSTRAC Went to the Federal Court Over an Unlodged Report

In December 2025, AUSTRAC commenced civil penalty proceedings in the Federal Court against two reporting entities, Castra Licensee Pty Ltd and Princeton Securities (NSW) Pty Ltd. The proceedings were not for money laundering or failing to report a suspicious matter, but for failing to lodge an annual compliance report.

Each organisation had previously been issued an infringement notice. It is easy to assume that failing to pay an infringement notice on time does not trigger an escalation where the regulator takes the matter to court. In this case, the organisations did not pay and AUSTRAC went to court. Both matters have since been resolved. Castra and Princeton each admitted the contravention, and in May 2026 the Federal Court ordered Castra to pay a $50,000 penalty plus $15,000 in costs, and Princeton a $45,000 penalty plus $5,000 in costs.

Our advice is that organisations should read this as a clear signal from the regulator that AML compliance should be taken seriously. This is not an isolated case; in July 2025, AUSTRAC commenced civil penalty proceedings against a suburban community club over alleged serious and systemic non-compliance. AUSTRAC's record of enforcement actions shows that organisations of all sizes, not just banks and casinos, should be implementing AML Compliance processes diligently.

Being New to the Regime Is Not a Defence; Only Documented Diligence Is

The civil penalty provisions of the AML/CTF Act do not require AUSTRAC to show that an organisation meant to fail, or that the organisation was aware that it had failed to implement AML Compliance. AUSTRAC simply has to prove that a breach or contravention of regulations occurred.

Organisations may get a false sense of security, assuming that they can rely on section 236 of the AML/CTF Act. This section provides a defence where the organisation can argue that it has taken reasonable precautions and exercised due diligence to avoid a contravention. A careful review of section 236 shows that the defendant carries the legal burden of demonstrating that proper due diligence and precautions were actively in place.

You cannot build a section 236 defence after AUSTRAC writes to you. Either the evidence already exists, or it does not.

For a business that enrolled ahead of 1 July, put an employee’s name in the compliance officer field, and has not returned to the subject since, that evidence of diligence does not exist.

The Penalty Lands on Your Entity but it Can Also Impact You.

AUSTRAC's civil penalty orders run against the reporting entity, not against the compliance officer personally. This could give the impression that individuals cannot be adversely impacted. However, the real impact could be personal.

Sole traders. There is no separation to rely on, because the individual sole trader is the reporting entity. The maximum civil penalty for a person other than a body corporate is 20,000 penalty units. Based on the penalty unit value applying from 1 July 2026, this amounts to $7.28 million.

Partnerships. Section 237 governs how the Act treats a partnership, and general law does the rest.  Since partners are jointly liable for the obligations of the firm, a penalty against the firm directly impacts the partners.

Companies. The company carries the penalty. But where a failure is serious and someone senior was aware and did not take corrective action, a second regulator has a separate route which is covered below.

The Consequence That Outlasts the Penalty

For regulated professionals, an AUSTRAC outcome can directly affect their ability to continue their professional practice.

Under the Legal Profession Uniform Law, each principal of a law practice is responsible for ensuring that reasonable steps are taken so that practitioners comply with their professional obligations. Where the practice contravenes a provision, a principal is taken to have contravened the same provision if they were, or ought reasonably to have been, in a position to influence the conduct and failed to take reasonable steps to prevent it. Failure can constitute unsatisfactory professional conduct or professional misconduct.

Accountants face the equivalent through APES 110 and their professional bodies. Licensed agents and conveyancers face fit-and-proper-person assessment and licence conditions.

The consequences of an AUSTRAC investigation can affect how these professionals are assessed by their professional bodies.

When Compliance Failures Become Personal

On 17 June 2026, the Federal Court penalised two former Star Entertainment executives for breaching their duty of care and diligence under section 180(1) of the Corporations Act. Former CEO Mathias Bekier was fined $700,000 and disqualified for six years. Former Chief Legal and Risk Officer Paula Martin was fined $400,000 and disqualified for seven years.

ASIC's case against all seven former non-executive directors was dismissed. The liability was attached to the two people who held the information and failed to escalate it and did not inform the board. This was a Corporations Act case, not an AML/CTF Act case. The AML/CTF Act does not impose personal liability on directors and officers directly. However, this does not stop personal consequences arriving through other routes.

What Independence and Expertise Look Like in Writing

Section 236 of the AML/CTF Act asks what precautions were taken and what diligence was exercised. The decision about who holds the compliance officer role is one of those precautions, which is made in advance and can be documented.

The Rules require the AML/CTF compliance officer to be a fit and proper person, engaged at the management level, resident in Australia, and to have sufficient authority, independence, access to resources and expertise to perform the role.

What we commonly observe is that most small and medium sized newly regulated businesses have appointed a partner or office manager who already has a full-time job, has a close relationship with the sales part of the business, and has limited expertise in AML compliance. Two key limbs of the test, independence and expertise, are where we see many organisations risk missing the mark.

An externally engaged professional compliance officer addresses both directly. Independence is structurally implemented because the officer sits at arm's length from the transactions they are assessing. The officer has no stake in a matter settling, no fee riding on the outcome, and no reporting line to the person who brought the transaction. Expertise is delivered through an AML specialist whose sole focus is AML compliance, and who is supported by a wider group of similar specialists constantly solving AML problems for peer organisations.

Engaging an external AML/CTF Compliance Officer or outsourcing AML compliance services does not transfer the obligation. The reporting entity remains responsible for ensuring the individual it designates meets the eligibility criteria and has the authority and resources to do the job.

What this arrangement can provide is evidence supporting a section 236 defence:

  • why we judged them as independent and qualified,
  • how the organisation provided them the resources and authority,
  • and what the person reported and when.

The Same Evidence Every Time

The evidence entities produce for AUSTRAC under section 236, may also have to be produced for professional bodies, licensing regulators, and insurers.  A documented AML/CTF program, approved at the appropriate level, should be further supported by:

  • a risk assessment that reflects the size and complexity of the business,
  • reporting that reaches decision-makers, and
  • records showing that appropriate analysis and decisions occurred within escalation pathways that have been used at least once.

These are not different compliance stories, but a single coherent evidentiary record that can withstand different forms of scrutiny.

Get ready for Tranche 2 with AusAML

ausaml.com provides Compliance-as-a-Service solutions for Australian businesses of all sizes. Our AML solutions and consulting services cover your risk assessment, AML/CTF Program, CDD procedures, AUSTRAC enrolment support, staff training, and ongoing compliance monitoring, managed by experienced AML professionals. Contact us to find out how we can get your business compliant.

Related Articles

Articles
AUSTRAC Enforcement and the Tranche 2 Due Diligence Defence

AUSTRAC Enforcement and the Tranche 2 Due Diligence Defence

AUSTRAC took two entities to the Federal Court over an unlodged report. What its enforcement record means for Tranche 2 firms and the section 236 defence.

Button icon
Read
Button icon
6 min.
AUSTRAC Enforcement and the Tranche 2 Due Diligence Defence
Advisory
Advisory

AUSTRAC Enforcement and the Tranche 2 Due Diligence Defence

AUSTRAC took two entities to the Federal Court over an unlodged report. What its enforcement record means for Tranche 2 firms and the section 236 defence.

AML Regulatory Requirements in Australia: Tranche 2, AUSTRAC and What Changes for Your Business

AML Regulatory Requirements in Australia: Tranche 2, AUSTRAC and What Changes for Your Business

From 1 July 2026, around 90,000 professional services businesses fall under Australia's AML/CTF regime for the first time. Here is what Tranche 2, AUSTRAC enrolment, reporting and the new penalties mean for your business.

Button icon
Read
Button icon
10 min.
AML Regulatory Requirements in Australia: Tranche 2, AUSTRAC and What Changes for Your Business
Guidance
Guidance

AML Regulatory Requirements in Australia: Tranche 2, AUSTRAC and What Changes for Your Business

From 1 July 2026, around 90,000 professional services businesses fall under Australia's AML/CTF regime for the first time. Here is what Tranche 2, AUSTRAC enrolment, reporting and the new penalties mean for your business.

Why KYC Costs More Than You Think: The Tranche 2 Scaling Trap

Why KYC Costs More Than You Think: The Tranche 2 Scaling Trap

The inclusion of real estate in the regulatory net from July this year will capture somewhere in the order of five hundred thousand or more transactions per year and it is not widely appreciated that each transaction will require multiple KYCs.

Button icon
Read
Button icon
5 min.
Why KYC Costs More Than You Think: The Tranche 2 Scaling Trap
Best Practice
Best Practice

Why KYC Costs More Than You Think: The Tranche 2 Scaling Trap

The inclusion of real estate in the regulatory net from July this year will capture somewhere in the order of five hundred thousand or more transactions per year and it is not widely appreciated that each transaction will require multiple KYCs.

Tranche 2 Compliance: The Lessons the Big Banks Never Learned

Tranche 2 Compliance: The Lessons the Big Banks Never Learned

The conversation around Australia's Tranche 2 AML/CTF reforms has tended to miss something crucial: hindsight.

Button icon
Read
Button icon
7 min.
Tranche 2 Compliance: The Lessons the Big Banks Never Learned
Strategy
Strategy

Tranche 2 Compliance: The Lessons the Big Banks Never Learned

The conversation around Australia's Tranche 2 AML/CTF reforms has tended to miss something crucial: hindsight.

Better Data, Better Decisions: Making Risk Easier to Understand and Defend

Better Data, Better Decisions: Making Risk Easier to Understand and Defend

With Tranche 2 AML compliance deadlines fast approaching this July, businesses must strengthen their financial crime risk management frameworks.

Button icon
Read
Button icon
3 min.
Better Data, Better Decisions: Making Risk Easier to Understand and Defend
Best Practice
Best Practice

Better Data, Better Decisions: Making Risk Easier to Understand and Defend

With Tranche 2 AML compliance deadlines fast approaching this July, businesses must strengthen their financial crime risk management frameworks.