
Portal Terms of Use
1. Nature of the Outsourcing Arrangement
1.1 AUS AML is a technology and service provider that operates the Client Portal to facilitate the collection and processing of identification information and documentation required for KYC and CDD purposes. AUS AML is not a reporting entity under the AML/CTF Act and does not provide designated services to Customers.
1.2 AUS AML performs its functions under this Agreement as Authorised Agent for, and on behalf of, Reporting Entities with whom it has entered into Outsourcing Arrangements. Each Reporting Entity is enrolled with AUSTRAC and is independently responsible for compliance with the AML/CTF Act and AML/CTF Rules.
1.3 When an End Client accesses the Client Portal and submits KYC Information, AUS AML is acting as the agent of the applicable Reporting Entity. The Reporting Entity remains the entity that:
- Is enrolled with AUSTRAC as a reporting entity;
- Is required to adopt and maintain an AML/CTF program;
- Is responsible for ensuring compliance with the AML/CTF Act and AML/CTF Rules;
- Is responsible for conducting customer due diligence and ongoing customer due diligence;
- Is responsible for the KYC Information collected through the Portal; and
- Must report suspicious matters to AUSTRAC as required by section 41 of the AML/CTF Act.
1.4 AUS AML's role is limited to:
- Operating the Client Portal as a secure technology platform;
- Collecting KYC Information and documentation submitted by End Clients through the Portal;
- Processing, organising, and formatting the collected KYC Information;
- Verifying identification documents through electronic verification services where authorised by the Reporting Entity;
- Conducting sanctions, PEP, and adverse media screening as directed by the Reporting Entity;
- Providing the collected and processed KYC Information to the applicable Reporting Entity; and
- Storing KYC Information securely on behalf of the Reporting Entity for the retention periods required by the AML/CTF Act and AML/CTF Rules.
1.5 The End Client acknowledges that the collection of Personal Information through the Portal is undertaken by AUS AML as agent on behalf of the Reporting Entity that provides, or proposes to provide, designated services to the Customer. The Reporting Entity is the primary entity responsible for compliance with AML/CTF obligations, and AUS AML's obligations are derived from, and limited by, the terms of the relevant Outsourcing Arrangement.
1.6 Where the AML/CTF Act or AML/CTF Rules require a reporting entity to carry out initial CDD (or, during any applicable transitional period, applicable customer identification procedures), the End Client acknowledges that AUS AML performs these procedures on behalf of, and under the direction of, the Reporting Entity, and that the Reporting Entity relies on the KYC Information collected by AUS AML to satisfy its obligations under the AML/CTF Act.
2. Acceptance of Terms
2.1 By accessing, registering for, or using the AUS AML Client Portal ("Portal"), the End Client acknowledges that they have read, understood, and agree to be bound by the terms and conditions set out in this Agreement.
2.2 This Agreement constitutes a legally binding contract between the End Client and AUS AML (as agent for the applicable Reporting Entity). If the End Client does not agree to all terms of this Agreement, they must not access or use the Portal.
2.3 The End Client acknowledges that AUS AML is collecting information on behalf of a specific Reporting Entity, and that the Reporting Entity will use the collected information to comply with its obligations under the AML/CTF Act and AML/CTF Rules.
2.4 Where the End Client is accessing or using the Portal on behalf of a Customer that is an entity (including but not limited to a company, partnership, trust, association, or co-operative), the End Client represents and warrants that:
- 2.4.1 They are duly authorised by the Customer to act on its behalf in relation to the provision of designated services by the Reporting Entity;
- 2.4.2 They have the legal capacity and authority to bind the Customer to this Agreement; and
- 2.4.3 All information submitted through the Portal is true, accurate, complete, and not misleading in any material respect.
2.5 The End Client must promptly notify AUS AML in writing if their authorisation to act on behalf of the Customer is revoked, modified, or otherwise terminated.
2.6 AUS AML and the Reporting Entity reserve the right to refuse access to the Portal, or decline to provide designated services at their sole discretion, including where the End Client fails to satisfy identification and verification requirements or where AUS AML or the Reporting Entity suspects on reasonable grounds that the information provided is false, misleading, or incomplete.
2.7 This Agreement is in addition to, and does not replace or limit, any other terms and conditions that may apply between the Customer and the Reporting Entity, including any service agreement, terms of engagement, or privacy policy of the Reporting Entity.
3. Regulatory Framework
3.1 The collection, use, disclosure, and handling of Personal Information through the Portal is governed by the following legislative and regulatory framework:
- The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act);
- The Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (F2025L01026) (AML/CTF Rules), as amended from time to time, which commenced on 31 March 2026 and give effect to the Tranche 2 Reforms, with AML/CTF obligations commencing for tranche 2 entities on 1 July 2026;
- The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs);
- The Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cth) (NDB Scheme);
- The Australian Securities and Investments Commission Act 2001 (Cth);
- The Corporations Act 2001 (Cth); and
- All other applicable Commonwealth, State, and Territory legislation and regulatory guidance.
3.2 The Reporting Entity is enrolled with AUSTRAC and is required to comply with its obligations under the AML/CTF Act and AML/CTF Rules, including but not limited to:
- Enrolling and maintaining enrolment with AUSTRAC;
- Adopting and maintaining an AML/CTF program that includes appropriate risk-based systems and controls;
- Conducting customer due diligence (CDD) before providing designated services;
- Identifying and verifying the identity of customers and beneficial owners;
- Monitoring transactions on an ongoing basis;
- Reporting suspicious matters to AUSTRAC where required;
- Complying with record-keeping obligations; and
- Providing reports and information to AUSTRAC upon request.
3.3 AUS AML assists the Reporting Entity to comply with its AML/CTF obligations through the Outsourcing Arrangement by:
- Collecting KYC Information from End Clients through the Portal;
- Verifying identification information using electronic and documentary methods;
- Screening against sanctions lists, PEP databases, and adverse media sources;
- Organising and presenting KYC Information in a format suitable for the Reporting Entity's assessment;
- Securely storing KYC Information for the required retention periods; and
- Notifying the Reporting Entity of any matters that may require further attention or suspicious matter reporting.
3.4 The End Client acknowledges that AUS AML is not a reporting entity and does not itself provide designated services or have direct AML/CTF compliance obligations to AUSTRAC. AUS AML's collection and processing of Personal Information is performed as agent for, and on behalf of, the Reporting Entity under an Outsourcing Arrangement.
3.5 The End Client further acknowledges that failure to provide the information requested through the Portal may result in the Reporting Entity being unable to provide the designated service, as the Reporting Entity is prohibited by law from providing designated services to a customer in respect of whom it has not carried out initial CDD (or, during any applicable transitional period, applicable customer identification procedures).
4. Collection of Personal Information
4.1 AUS AML collects Personal Information through the Portal on behalf of the Reporting Entity for the purposes of enabling the Reporting Entity to comply with its customer identification and due diligence obligations under the AML/CTF Act and AML/CTF Rules. The nature and extent of information collected depends on the type of Customer being onboarded.
4.2 The End Client acknowledges that the collection of all Personal Information submitted through the Portal, including any information uploaded as documentation, is required or authorised by the AML/CTF Act and the AML/CTF Rules and is reasonably necessary for the Reporting Entity's functions and activities as a reporting entity. To the extent that consent is required for the collection of any Personal Information or Sensitive Information, the End Client provides that consent on behalf of the Reporting Entity.
5. Purpose of Collection
5.1 AUS AML collects Personal Information through the Portal on behalf of the Reporting Entity for the following primary purposes:
- To enable the Reporting Entity to comply with its obligations under the AML/CTF Act and AML/CTF Rules, including initial and ongoing customer due diligence (and, during any applicable transitional period, applicable customer identification procedures);
- To enable the Reporting Entity to verify the identity of Customers and beneficial owners;
- To enable the Reporting Entity to assess and manage ML/TF risk associated with the provision of designated services;
- To enable the Reporting Entity to conduct enhanced due diligence where required;
- To enable the Reporting Entity to monitor transactions and customer activity on an ongoing basis;
- To enable the Reporting Entity to identify and report suspicious matters to AUSTRAC as required by law;
- To enable the Reporting Entity to comply with its obligations under the Privacy Act and the APPs;
- To enable the Reporting Entity to fulfil record-keeping requirements under the AML/CTF Act and AML/CTF Rules;
- To enable the Reporting Entity to comply with any request, direction, or requirement of AUSTRAC, the OAIC, or any other regulatory authority;
- To enable the Reporting Entity to provide designated services to the Customer; and
- For any other purpose required or authorised by law.
5.2 AUS AML does not use Personal Information collected through the Portal for its own purposes, including direct marketing. Personal Information is collected solely on behalf of the Reporting Entity for the Reporting Entity's AML/CTF compliance purposes.
5.3 The Reporting Entity will not disclose Personal Information to third parties except as required or authorised by law, as necessary for the provision of designated services, or with the consent of the End Client. AUS AML will disclose Personal Information only to the Reporting Entity or as directed by the Reporting Entity, except as required by law.
6. Consent and Notification
6.1 In accordance with Australian Privacy Principle 5 (APP 5) and the requirements of the AML/CTF Act, AUS AML provides this notification on behalf of the Reporting Entity at or before the time of collection of Personal Information.
6.2 By accessing and using the Portal, the End Client acknowledges that the following collection, use and disclosure of Personal Information is required or authorised by the AML/CTF Act, the AML/CTF Rules and the Privacy Act, and, to the extent that consent is required, consents to:
- The collection of their Personal Information (and the Personal Information of beneficial owners, directors, partners, trustees, beneficiaries, and other relevant individuals) by AUS AML as agent for the Reporting Entity, as described in this Agreement and as required under the AML/CTF Act and AML/CTF Rules;
- The collection of Sensitive Information where such collection is required or authorised by the AML/CTF Act or other applicable law;
- The use of Personal Information by the Reporting Entity for the purposes specified in Section 5 of this Agreement;
- The disclosure of Personal Information by the Reporting Entity to AUSTRAC, the OAIC, and other regulatory authorities where required or authorised by law;
- The verification of identity documents by AUS AML through the Document Verification Service (DVS) or other electronic verification services on behalf of the Reporting Entity;
- The retention of Personal Information by AUS AML on behalf of the Reporting Entity for the periods required by the AML/CTF Act and AML/CTF Rules (being a minimum of seven (7) years from the date of the transaction or the termination of the business relationship, whichever is later);
- The disclosure of Personal Information by AUS AML to the Reporting Entity and to third-party service providers engaged by AUS AML or the Reporting Entity for the purposes of identity verification, sanctions screening, PEP screening, adverse media screening, transaction monitoring, and secure data storage; and
- The cross-border disclosure of Personal Information to overseas recipients, where applicable, in accordance with Section 11 of this Agreement.
6.3 The End Client acknowledges that the provision of designated services by the Reporting Entity is conditional upon the collection and verification of the required Personal Information. If the End Client does not provide the requested information, the Reporting Entity may be unable to provide the designated service.
6.4 The End Client must ensure that all beneficial owners, directors, partners, trustees, beneficiaries, office holders, and other individuals whose Personal Information is provided through the Portal are made aware of this Agreement and consent to the collection, use, and disclosure of their Personal Information in accordance with its terms.
6.5 The End Client acknowledges that this Agreement serves as the collection notice required under APP 5 of the Privacy Act on behalf of the Reporting Entity, and that by proceeding to use the Portal, they are deemed to have received this notice.
6.6 The End Client acknowledges that AUS AML is not the entity providing the designated service to the Customer. AUS AML's role is limited to collecting and processing KYC Information on behalf of the Reporting Entity. All decisions regarding the provision or refusal of designated services are made by the Reporting Entity.
7. Verification of Identity
7.1 The Reporting Entity is required by the AML/CTF Act and AML/CTF Rules to verify the identity of customers and beneficial owners from reliable and independent documentation or electronic data, or a combination of both. AUS AML undertakes verification procedures on behalf of the Reporting Entity under the Outsourcing Arrangement.
7.2 For individuals, AUS AML may verify identity on behalf of the Reporting Entity using reliable and independent data or documentation appropriate to the customer's ML/TF risk, as determined by the Reporting Entity's risk-based customer due diligence procedures, which may include one or more of the following methods:
- Primary photographic identification documents (e.g., Australian passport, foreign passport, Australian driver's licence);
- Primary non-photographic identification documents (e.g., birth certificate, citizenship certificate);
- Secondary identification documents (e.g., government benefit notice, ATO assessment notice);
- Electronic verification using the Document Verification Service (DVS) or other reliable and independent electronic data sources;
- Biometric verification, where available and with consent; or
- A disclosure certificate, where applicable.
7.3 For companies and other corporate entities, AUS AML may verify existence and identity on behalf of the Reporting Entity using methods appropriate to the customer's ML/TF risk, as determined by the Reporting Entity's risk-based customer due diligence procedures, which may include:
- Searching the relevant ASIC database;
- Reviewing certificates of registration or incorporation;
- Reviewing public documents issued by the company;
- Searching relevant domestic or foreign stock exchanges;
- Searching the licence or other records of the relevant regulator;
- Reviewing reliable and independent documentation or electronic data; or
- Obtaining a disclosure certificate.
7.4 The End Client consents to AUS AML verifying identity information on behalf of the Reporting Entity through the Document Verification Service (DVS), which involves checking identity documents against records held by the issuing Commonwealth, State, or Territory government agencies.
7.5 Where AUS AML suspects, on reasonable grounds, that a customer is not the person they claim to be, AUS AML will notify the Reporting Entity, which may take additional verification steps as required by the AML/CTF Act and the AML/CTF Rules.
8. Beneficial Ownership
8.1 The Reporting Entity is required by the AML/CTF Act and AML/CTF Rules to identify and take reasonable measures to verify the beneficial owners of certain customers. AUS AML collects beneficial ownership information on behalf of the Reporting Entity through the Portal.
8.2 The End Client acknowledges that the Reporting Entity must collect the name and address of each beneficial owner (if any) of:
- A proprietary or private company;
- A trust (including details of beneficiaries and classes of beneficiaries);
- A partnership;
- Any other legal arrangement; and
- Any Customer where the Reporting Entity determines, in accordance with its risk-based systems and controls, that beneficial ownership information should be collected and verified.
8.3 A beneficial owner is an individual who ultimately owns or controls (directly or indirectly) the Customer, or on whose behalf a transaction is conducted. This includes individuals who:
- Hold a beneficial interest of 25% or more in a company, partnership, or trust;
- Exercise control (directly or indirectly) over the Customer, including through voting rights, veto rights, or veto power over decisions;
- Have the power to appoint or remove directors, trustees, or partners; or
- Are beneficiaries of a trust or equivalent legal arrangement.
8.4 The End Client consents to the collection and verification of beneficial ownership information by AUS AML on behalf of the Reporting Entity and warrants that all beneficial ownership information provided through the Portal is true, accurate, and complete.
8.5 The End Client undertakes to notify AUS AML and the Reporting Entity promptly in writing of any changes to beneficial ownership, including changes to the identity of beneficial owners, changes in shareholdings, or changes in the nature or extent of beneficial interests.
8.6 The Reporting Entity may, in its discretion and having regard to ML/TF risk, apply simplified beneficial ownership verification procedures to certain customers, including domestic listed public companies, majority-owned subsidiaries of domestic listed public companies, and entities licensed and subject to the regulatory oversight of a Commonwealth, State, or Territory statutory regulator. AUS AML will implement such determinations as directed by the Reporting Entity.
9. Ongoing Customer Due Diligence
9.1 The Reporting Entity is required by the AML/CTF Act and AML/CTF Rules to apply ongoing customer due diligence (OCDD) procedures in respect of all applicable customers. AUS AML may assist the Reporting Entity with OCDD activities as specified in the Outsourcing Arrangement.
9.2 As part of OCDD, the End Client acknowledges and consents to:
- The periodic review and updating of KYC Information held by the Reporting Entity (and stored by AUS AML on its behalf);
- The re-verification of identification information where required by the Reporting Entity's risk-based systems and controls;
- Transaction monitoring by the Reporting Entity for the purpose of identifying suspicious transactions;
- Enhanced monitoring by the Reporting Entity in respect of higher-risk customers, including PEPs, customers from high-risk jurisdictions, and customers with complex ownership structures;
- The provision of updated information and documentation upon request by the Reporting Entity or AUS AML on its behalf; and
- The reporting by the Reporting Entity of suspicious matters to AUSTRAC where required by section 41 of the AML/CTF Act.
9.3 The End Client must promptly notify AUS AML (who will notify the Reporting Entity) of any material changes to:
- The Customer's name, address, or contact details;
- The Customer's business activities or ownership structure;
- The identity of directors, partners, trustees, beneficial owners, or authorised representatives;
- The beneficial ownership of the Customer;
- Whether any individual connected with the Customer becomes a PEP or is subject to sanctions; or
- Any other matter that may affect the Reporting Entity's assessment of ML/TF risk.
9.4 The Reporting Entity may, at any time and having regard to ML/TF risk, request additional information or documentation from the End Client for the purposes of updating or re-verifying KYC Information. AUS AML will facilitate such requests on behalf of the Reporting Entity.
10. Data Security and Retention
10.1 AUS AML takes the security of Personal Information seriously and implements appropriate technical and organisational measures to protect Personal Information from misuse, interference, loss, and from unauthorised access, modification, or disclosure. These measures are applied to Personal Information collected and stored by AUS AML on behalf of the Reporting Entity.
10.2 These measures include, but are not limited to:
- Encryption of data in transit and at rest using industry-standard encryption protocols;
- Secure access controls and authentication mechanisms for the Portal;
- Regular security assessments and penetration testing;
- Employee training on data security and privacy obligations;
- Incident response procedures for data security incidents;
- Secure data storage infrastructure with appropriate backup and disaster recovery arrangements; and
- Compliance with Australian information security standards and guidelines.
10.3 AUS AML will retain Personal Information on behalf of the Reporting Entity for the period required by the AML/CTF Act and AML/CTF Rules, being a minimum of seven (7) years from the date of the relevant transaction or the termination of the business relationship, whichever is later.
10.4 Following the expiration of the required retention period, AUS AML will, at the direction of the Reporting Entity, take reasonable steps to destroy or de-identify Personal Information, unless the information is required to be retained by or under an Australian law or court/tribunal order.
10.5 The End Client acknowledges that while AUS AML takes reasonable steps to protect Personal Information, no security measure is completely infallible, and AUS AML cannot guarantee the absolute security of information transmitted through the Portal or stored by AUS AML.
10.6 The End Client is responsible for maintaining the confidentiality of their Portal login credentials and must immediately notify AUS AML of any unauthorised access to or use of their account.
11. Cross-Border Disclosure
11.1 The Reporting Entity (through AUS AML acting on its behalf) may disclose Personal Information to overseas recipients in the following circumstances:
- Where required or authorised by the AML/CTF Act or other applicable Australian law;
- Where necessary for the provision of designated services, including for identity verification services, sanctions screening, PEP screening, and transaction monitoring services that operate internationally;
- Where the End Client has consented to the disclosure; or
- Where the disclosure is to an overseas recipient that is subject to a comparable privacy scheme or where the Reporting Entity has taken reasonable steps to ensure the overseas recipient will not breach the APPs.
11.2 Before disclosing Personal Information to an overseas recipient, AUS AML (on behalf of the Reporting Entity) will take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to the information, unless an exception under APP 8.2 applies.
11.3 The Reporting Entity remains accountable for any breach of the APPs by an overseas recipient to whom Personal Information is disclosed in accordance with APP 8.
11.4 The End Client consents to the cross-border disclosure of Personal Information by AUS AML on behalf of the Reporting Entity as described in this Section 11.
12. Notifiable Data Breaches
12.1 The Reporting Entity (and AUS AML as its service provider) is subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act.
12.2 In the event of an eligible data breach involving Personal Information collected through the Portal, AUS AML will:
- Take reasonable steps to contain the breach and prevent further unauthorised access or disclosure;
- Promptly notify the Reporting Entity of the breach;
- Assist the Reporting Entity to assess the breach to determine whether it is an eligible data breach that is likely to result in serious harm to affected individuals; and
- Assist the Reporting Entity to notify affected individuals and the OAIC as required by the NDB scheme.
12.3 For the purposes of the NDB scheme, "serious harm" may include physical, psychological, emotional, financial, or reputational harm.
12.4 AUS AML will conduct a reasonable and expeditious assessment of any suspected eligible data breach, taking all reasonable steps to ensure that such assessment is completed within 30 calendar days of becoming aware of the suspected breach, and will notify the Reporting Entity accordingly.
12.5 The End Client agrees to promptly notify AUS AML of any actual or suspected data breach, unauthorised access, or security incident relating to the Portal or Personal Information accessed through the Portal.
13. Access, Correction and Complaints
13.1 In accordance with APP 12 and APP 13 of the Privacy Act, the End Client has the right to:
- Request access to Personal Information held by the Reporting Entity (and stored by AUS AML on its behalf) about them or (where authorised) about the Customer they represent;
- Request correction of Personal Information that is inaccurate, out-of-date, incomplete, irrelevant, or misleading; and
- Make a complaint about a breach of the APPs or this Agreement.
13.2 Requests for access to, or correction of, Personal Information should be directed to the Reporting Entity. AUS AML will assist the Reporting Entity to respond to such requests as required. The Reporting Entity will respond to access and correction requests within a reasonable timeframe and in accordance with its obligations under the Privacy Act. In certain circumstances, the Reporting Entity may refuse to provide access to Personal Information, including where:
- Providing access would have an unreasonable impact on the privacy of other individuals;
- The request is frivolous or vexatious;
- The information relates to existing or anticipated legal proceedings;
- Providing access would be unlawful; or
- Denying access is required or authorised by or under an Australian law.
13.3 Where the Reporting Entity refuses to provide access to or correct Personal Information, it will provide written reasons for the refusal and information about the mechanisms available to complain about the refusal.
13.4 The End Client may make a complaint about the handling of Personal Information by contacting the Reporting Entity or AUS AML using the contact details in Section 20. AUS AML will acknowledge receipt of any complaint and will liaise with the Reporting Entity as appropriate. The Reporting Entity is responsible for investigating and responding to complaints in accordance with its complaints handling procedures.
13.5 If the End Client is not satisfied with the response to a complaint, they may refer the complaint to the OAIC.
14. Third-Party Service Providers
14.1 AUS AML may engage third-party service providers to assist in the performance of its obligations under the Outsourcing Arrangement, including but not limited to:
- Identity verification service providers (including providers of electronic identity verification and the Document Verification Service);
- Sanctions, PEP, and adverse media screening providers;
- Secure cloud storage and data processing providers;
- Customer relationship management and workflow management providers;
- IT support and cybersecurity providers; and
- Professional advisers including legal advisers, accountants, and auditors.
14.2 Third-party service providers engaged by AUS AML are required to comply with applicable privacy and data protection obligations, including obligations equivalent to those under the APPs, and to process Personal Information only for the purposes of performing services for AUS AML on behalf of the Reporting Entity.
14.3 AUS AML takes reasonable steps to ensure that third-party service providers implement appropriate technical and organisational measures to protect Personal Information and to use and disclose Personal Information only for the purposes for which it was provided by the End Client on behalf of the Reporting Entity.
14.4 The End Client consents to the disclosure of Personal Information to third-party service providers engaged by AUS AML in its capacity as agent for the Reporting Entity, as described in this Section 14.
15. Limitation of Liability
15.1 To the maximum extent permitted by law, AUS AML's liability to the End Client in connection with this Agreement and the use of the Portal is limited to re-supplying the relevant collection and processing service.
15.2 AUS AML will not be liable for any indirect, consequential, special, or punitive damages, including loss of profits, revenue, data, or business opportunities, arising out of or in connection with this Agreement or the use of the Portal.
15.3 AUS AML acts solely as agent for the Reporting Entity in collecting KYC Information and does not make any decision regarding the provision or refusal of designated services. AUS AML is not liable for any decision made by the Reporting Entity to decline or terminate the provision of designated services to the Customer.
15.4 AUS AML will not be liable for any failure or delay in performing its obligations under this Agreement where such failure or delay is due to circumstances beyond its reasonable control, including but not limited to acts of God, natural disasters, war, terrorism, riots, embargoes, acts of civil or military authorities, fire, floods, accidents, strikes, or shortages of transportation, facilities, fuel, energy, labour, or materials.
15.5 Nothing in this Agreement excludes, restricts, or modifies any guarantee, term, condition, warranty, or right under the Competition and Consumer Act 2010 (Cth) or any other applicable consumer protection legislation that cannot be lawfully excluded.
16. Termination and Suspension
16.1 AUS AML may suspend or terminate the End Client's access to the Portal where:
- The End Client breaches any term of this Agreement;
- AUS AML suspects, on reasonable grounds, fraudulent, unlawful, or suspicious activity;
- AUS AML or the Reporting Entity is required to do so by law, regulatory direction, or court order;
- AUS AML or the Reporting Entity suspects, on reasonable grounds, that the Customer is not the person they claim to be;
- The Reporting Entity determines, in accordance with its risk-based systems and controls, that the ML/TF risk associated with the Customer is unacceptable;
- The End Client's authorisation to act on behalf of the Customer has been revoked or terminated; or
- The Outsourcing Arrangement between AUS AML and the Reporting Entity has been terminated.
AUS AML will give the End Client reasonable prior notice before suspending or terminating access under this clause 16, except where paragraph (b), (c), (d) or (e) applies, or where giving prior notice is not practicable, would be unlawful, or would be contrary to a regulatory direction or court order, in which case AUS AML may act immediately and will notify the End Client as soon as reasonably practicable afterwards. Where access is suspended or terminated for a breach under paragraph (a) that is capable of remedy, AUS AML will, where practicable, first give the End Client a reasonable opportunity to remedy the breach.
16.2 The End Client may terminate this Agreement at any time by ceasing to use the Portal and notifying AUS AML in writing.
16.3 Termination of this Agreement does not affect any rights or obligations that accrued prior to termination, including the Reporting Entity's obligations to retain records under the AML/CTF Act and AML/CTF Rules and AUS AML's corresponding obligations to store KYC Information on behalf of the Reporting Entity.
16.4 Sections 10 (Data Security and Retention), 15 (Limitation of Liability), 18 (Governing Law), and any other provisions that by their nature should survive termination, will survive termination of this Agreement.
17. Amendments
17.1 AUS AML may amend this Agreement at any time to reflect changes in applicable law, regulatory requirements, industry best practice, the terms of Outsourcing Arrangements, or the operation of the Portal.
17.2 AUS AML will provide notice of material amendments to the End Client by posting the updated Agreement on the Portal and/or by email to the address provided by the End Client.
17.3 For material amendments, AUS AML will present the updated terms to the End Client at the next login after the amendment takes effect and will ask the End Client to confirm acceptance before continuing to use the Portal. For non-material amendments, the End Client's continued use of the Portal following notice of the amended terms constitutes acceptance. Amendments apply prospectively only. If the End Client does not agree to the amended terms, they may cease using the Portal at any time without penalty, and this Agreement will end without further liability to the End Client, subject to the record-keeping and retention obligations that survive termination under clause 16.3.
17.4 Material amendments will take effect no less than 14 days after notice is provided, unless a shorter period is required to comply with applicable law or regulatory requirements.
18. Governing Law
18.1 This Agreement is governed by and construed in accordance with the laws of New South Wales, Australia.
18.2 The parties submit to the exclusive jurisdiction of the courts of New South Wales and the Federal Court of Australia.
18.3 If any provision of this Agreement is found to be invalid, unenforceable, or illegal, that provision will be severed, and the remaining provisions will continue in full force and effect.
19. Contact Information
AUS AML (Portal Operator)
For technical support, Portal access issues, or general enquiries relating to the Client Portal:
Email: contact@ausaml.com
Reporting Entity
For enquiries relating to the provision of designated services, AML/CTF compliance matters, or decisions regarding the Customer's onboarding contact your RE
Privacy and Data Protection
For enquiries, access requests, correction requests, or complaints relating to the handling of Personal Information:
Email: contact@ausaml.com
Note: AUS AML will liaise with the Reporting Entity as appropriate in respect of privacy-related enquiries and complaints.
Office of the Australian Information Commissioner (OAIC)
For complaints about privacy that are not resolved to the End Client's satisfaction:
Website: www.oaic.gov.au
Telephone: 1300 363 992
Postal Address: GPO Box 5218, Sydney NSW 2001
AUSTRAC
For matters relating to AML/CTF compliance by reporting entities:
Website: www.austrac.gov.au
Telephone: 1300 021 037
Postal Address: PO Box 5515, West Chatswood NSW 1515
20. Definitions and Interpretation
In this Portal Terms of Use ("Agreement"), unless the context otherwise requires:
"ACN" means Australian Company Number as issued by the Australian Securities and Investments Commission (ASIC).
"ABN" means Australian Business Number as issued by the Australian Business Register.
"AML/CTF Act" means the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), as amended from time to time.
"AML/CTF Rules" means the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (F2025L01026), as amended from time to time.
"APPs" means the Australian Privacy Principles set out in Schedule 1 of the Privacy Act 1988 (Cth).
"ARBN" means Australian Registered Body Number as issued by ASIC.
"AUS AML" means AUS AML Pty Ltd (ABN 70 690 857 277), the operator of the Client Portal and a service provider that collects and processes identification information and documentation on behalf of Reporting Entities. AUS AML is not itself a reporting entity under the AML/CTF Act.
"AUSTRAC" means the Australian Transaction Reports and Analysis Centre.
"Authorised Agent" means AUS AML acting under an outsourcing arrangement as agent for a Reporting Entity for the purposes of collecting KYC Information and undertaking initial CDD (or, during any applicable transitional period, applicable customer identification procedures).
"Beneficial Owner" means an individual who ultimately owns or controls (directly or indirectly) a customer, or on whose behalf a transaction is conducted, including beneficiaries of trusts and holders of dominant positions in companies and other legal arrangements, as defined in the AML/CTF Rules.
"CDD" means Customer Due Diligence, being the process of identifying and verifying the identity of customers and beneficial owners in accordance with the AML/CTF Act and AML/CTF Rules.
"Client Portal" means the secure online platform operated by AUS AML through which End Clients submit identification information and documentation on behalf of a Customer for KYC/CDD purposes on behalf of a Reporting Entity.
"Customer" means the person or entity (including individuals, sole traders, companies, partnerships, trusts, associations, co-operatives, and government bodies) to whom a Reporting Entity provides, or proposes to provide, a designated service as defined in the AML/CTF Act.
"Designated Service" has the meaning given in section 6 of the AML/CTF Act.
"Document Verification Service (DVS)" means the Australian Government service that allows authorised entities to electronically verify evidence of identity documents issued by Australian government agencies.
"EDD" means Enhanced Due Diligence, being additional verification and monitoring measures applied to higher-risk customers or transactions as required under the AML/CTF Act and AML/CTF Rules.
"Eligible Data Breach" has the meaning given in Part IIIC of the Privacy Act 1988 (Cth).
"End Client" means the individual, entity, or authorised representative who accesses and uses the Client Portal to submit identification information and documentation on behalf of a Customer to a Reporting Entity.
"KYC" means Know Your Customer, being the process by which a Reporting Entity verifies the identity of its customers and assesses potential risks of illegal intentions.
"KYC Information" has the meaning given in the AML/CTF Rules and includes all information collected to identify and verify a customer and beneficial owners.
"ML/TF Risk" means Money Laundering and Terrorism Financing risk.
"NDB Scheme" means the Notifiable Data Breaches scheme established under Part IIIC of the Privacy Act 1988 (Cth).
"OAIC" means the Office of the Australian Information Commissioner.
"Outsourcing Arrangement" means the contractual arrangement between AUS AML and a Reporting Entity under which AUS AML is engaged to collect KYC Information and undertake customer identification procedures on behalf of the Reporting Entity in accordance with the AML/CTF Act and AML/CTF Rules.
"PEP" means Politically Exposed Person, being an individual who holds or has held a prominent public function, including foreign PEPs, domestic PEPs, and international organisation PEPs as defined in the AML/CTF Rules.
"Personal Information" has the meaning given in section 6 of the Privacy Act 1988 (Cth) and includes information or an opinion about an identified individual, or an individual who is reasonably identifiable.
"PII" means Personally Identifiable Information, being any data that could potentially identify a specific individual.
"Privacy Act" means the Privacy Act 1988 (Cth), as amended from time to time.
"Reporting Entity" has the meaning given in section 5 of the AML/CTF Act and means the AUS AML client that is enrolled with AUSTRAC and provides designated services to the Customer. The Reporting Entity is the entity responsible for compliance with the AML/CTF Act and AML/CTF Rules.
"Sensitive Information" has the meaning given in section 6 of the Privacy Act 1988 (Cth).
"Service Provider" means AUS AML in its capacity as a provider of KYC/CDD collection services to Reporting Entities under Outsourcing Arrangements.
"Tranche 2 Reforms" means the amendments to the AML/CTF Act and AML/CTF Rules that commenced on 1 July 2026, extending AML/CTF obligations to additional designated services including legal practitioners, accountants, and real estate professionals.

