No AUSTRAC rule requires a bank to freeze a professional trust account because a firm has not enrolled. The real exposure is different and less dramatic: banks are reporting entities themselves, they assess the risk their customers present, and a weak answer to a reasonable question is what causes trouble.
Is there a rule that forces a bank to freeze the account?
There is not. A bank's decision to restrict, decline or end services is a customer-risk and commercial decision, subject to the laws that apply to the bank.
AUSTRAC's guidance on higher-risk customers says directly that a risk-based approach does not require financial institutions to disengage from risk, and that higher risk does not automatically mean a relationship must be discontinued. That is the opposite of an instruction to close accounts.
So claims that major banks are automatically freezing trust accounts because a firm cannot produce a Reporting Entity Number are too strong without bank-specific evidence. They also use terminology the regulator does not: AUSTRAC's current guidance refers to an AUSTRAC account number, or AAN, issued on enrolment. When a claim gets the name of the identifier wrong, the mechanism behind it usually has not been checked either.
So where does the real risk come from?
From the bank's own obligations. Banks are reporting entities, they need to understand the money laundering and terrorism financing risk their customers present, and they can seek information about a regulated customer's systems and controls.
That makes your AML/CTF position a commercial input as well as a regulatory one. A firm that cannot describe its own controls coherently raises uncertainty for the bank, and uncertainty is what drives enhanced due diligence, slower onboarding of new accounts and, at the far end, a decision to reduce exposure.
The distinction matters because it changes what you should prepare. Preparing for a rule that does not exist produces a certificate. Preparing for a risk assessment produces evidence.
It also changes who owns the problem. If the risk were a regulatory trigger, the compliance team could clear it by completing a step. Because the risk is a counterparty's judgement about your controls, clearing it needs the people who can actually describe how the firm operates, which usually means the compliance officer, the finance function that runs the trust account, and whoever owns the banking relationship.
What is a bank likely to want to understand?
AUSTRAC says it can be reasonable for a financial institution to ask whether a regulated business has an AML/CTF programme, how that programme was developed, and how seriously the business is implementing it. In some cases the bank may ask for a copy of the programme or other evidence to judge whether the systems and controls look reasonable for the customer's risk.
For a legal, accounting or property business, that usually resolves into a familiar set of questions.
| Area | What the bank is testing |
|---|---|
| Enrolment and scope of regulated services | Whether the perimeter is known and documented |
| ML/TF risk assessment | Whether it reflects the actual business, not a template |
| Compliance officer and senior oversight | Whether someone accountable exists and is engaged |
| Customer due diligence and beneficial ownership | Whether identification actually happens, and is recorded |
| Sanctions, PEP and adverse media screening | Whether screening matches the stated policy |
| Ongoing due diligence and monitoring | Whether review is triggered by change, not by a calendar |
| Training, reporting readiness, record keeping | Whether the programme operates below partner level |
A generic or defensive response against that list increases uncertainty even where it does not cause a closure.
None of those rows is unusual, and that is the point worth making internally. A bank asking them is behaving exactly as a reporting entity is expected to, so the questions are better treated as predictable than as an escalation. A firm that can answer all seven with documents rather than adjectives has removed most of the risk this article is about.
Why should trust-account continuity be a board-level dependency?
For firms that rely on trust or settlement accounts, banking access is not a treasury detail. It affects settlements, client money, contractual deadlines and the firm's ability to deliver its core service at all.
That makes it a continuity dependency rather than a compliance topic. A board or partnership should identify the critical accounts, the banking counterparties, the key contact points, and the compliance evidence that can be produced if a bank starts enhanced due diligence.
The objective is not to bury the bank in documents. It is to answer legitimate risk questions quickly, consistently, and with evidence that matches what the firm actually does.
What should a banking assurance pack contain?
Build it before the bank asks. A concise pack can cover the entity and service scope, current enrolment evidence, the governance structure, programme approval, a risk assessment summary, compliance officer details, training status, the high-level design of customer due diligence, the independent evaluation plan, and a short description of how issues are escalated and remediated.
Two decisions should be taken in advance rather than under pressure. Where information is commercially sensitive, work out what can be shared, who authorises disclosure, and whether confidentiality protections are needed.
A controlled pack also prevents ad hoc answers from relationship managers who may not know the detail of the programme. Inconsistency between what two people at the same firm tell the same bank is its own risk signal.
Keep the pack current, and date it. An assurance pack assembled once and left alone becomes a liability, because the version a bank reads may describe a programme the firm has since changed.
What should you do when a bank raises a concern?
Four steps, in order. Establish what information or risk concern is actually driving the request, because the stated question and the underlying concern are not always the same. Provide accurate evidence rather than assurances about being compliant.
Remediate any genuine gap the request exposes, and keep a record of what changed and when. Then escalate any threatened service restriction through executive and legal channels, because the operational impact extends well beyond the compliance function.
One thing to avoid is treating the exchange as adversarial. The bank is discharging its own obligation, and a cooperative, evidenced response is both faster and less likely to escalate than a minimal one.
What not to do is claim that enrolment resolves the concern. A bank assessing residual risk is usually more interested in whether the programme is genuinely implemented than in whether a portal step has been completed. Our Tranche 2 checklist sets out the sequence that produces the evidence such a request will test.
Where does technology fit in this?
The evidence behind customer and business due diligence is the part a platform can carry: structured screening, ongoing monitoring, decision records and reporting. Those records are what let a firm show its policies operate in practice rather than existing only as documents, which is precisely the gap a bank's question is aimed at.
Banking continuity remains a wider governance matter covering risk assessment, policy, training, reporting and executive oversight. Technology supports part of that control environment. It does not guarantee that a bank will provide or continue a service, and no vendor should suggest otherwise. The Tranche 2 hub covers the rest of the programme this depends on.
Important information
This article provides general information about Australia's AML/CTF framework and does not constitute legal advice. Whether an obligation applies depends on the designated services provided and the circumstances of the business.
Decisions about banking services are made by the institution concerned under the laws and policies that apply to it, and nothing here predicts how a particular bank will act. Take your own advice on your banking arrangements and your AML/CTF position. Reporting entities remain responsible for meeting their obligations under the AML/CTF Act, the Rules and applicable AUSTRAC guidance, alongside its published regulatory expectations.



