Blog

Tranche 2

How AML/CTF Gaps Can Put Banking and Trust-Account Continuity at Risk

No AUSTRAC rule makes a bank freeze a trust account over enrolment. The real risk is a bank's own due diligence, and what you can evidence when it asks.

No AUSTRAC rule requires a bank to freeze a professional trust account because a firm has not enrolled. The real exposure is different and less dramatic: banks are reporting entities themselves, they assess the risk their customers present, and a weak answer to a reasonable question is what causes trouble.

Is there a rule that forces a bank to freeze the account?

There is not. A bank's decision to restrict, decline or end services is a customer-risk and commercial decision, subject to the laws that apply to the bank.

AUSTRAC's guidance on higher-risk customers says directly that a risk-based approach does not require financial institutions to disengage from risk, and that higher risk does not automatically mean a relationship must be discontinued. That is the opposite of an instruction to close accounts.

So claims that major banks are automatically freezing trust accounts because a firm cannot produce a Reporting Entity Number are too strong without bank-specific evidence. They also use terminology the regulator does not: AUSTRAC's current guidance refers to an AUSTRAC account number, or AAN, issued on enrolment. When a claim gets the name of the identifier wrong, the mechanism behind it usually has not been checked either.

So where does the real risk come from?

From the bank's own obligations. Banks are reporting entities, they need to understand the money laundering and terrorism financing risk their customers present, and they can seek information about a regulated customer's systems and controls.

That makes your AML/CTF position a commercial input as well as a regulatory one. A firm that cannot describe its own controls coherently raises uncertainty for the bank, and uncertainty is what drives enhanced due diligence, slower onboarding of new accounts and, at the far end, a decision to reduce exposure.

The distinction matters because it changes what you should prepare. Preparing for a rule that does not exist produces a certificate. Preparing for a risk assessment produces evidence.

It also changes who owns the problem. If the risk were a regulatory trigger, the compliance team could clear it by completing a step. Because the risk is a counterparty's judgement about your controls, clearing it needs the people who can actually describe how the firm operates, which usually means the compliance officer, the finance function that runs the trust account, and whoever owns the banking relationship.

What is a bank likely to want to understand?

AUSTRAC says it can be reasonable for a financial institution to ask whether a regulated business has an AML/CTF programme, how that programme was developed, and how seriously the business is implementing it. In some cases the bank may ask for a copy of the programme or other evidence to judge whether the systems and controls look reasonable for the customer's risk.

For a legal, accounting or property business, that usually resolves into a familiar set of questions.

AreaWhat the bank is testing
Enrolment and scope of regulated servicesWhether the perimeter is known and documented
ML/TF risk assessmentWhether it reflects the actual business, not a template
Compliance officer and senior oversightWhether someone accountable exists and is engaged
Customer due diligence and beneficial ownershipWhether identification actually happens, and is recorded
Sanctions, PEP and adverse media screeningWhether screening matches the stated policy
Ongoing due diligence and monitoringWhether review is triggered by change, not by a calendar
Training, reporting readiness, record keepingWhether the programme operates below partner level

A generic or defensive response against that list increases uncertainty even where it does not cause a closure.

None of those rows is unusual, and that is the point worth making internally. A bank asking them is behaving exactly as a reporting entity is expected to, so the questions are better treated as predictable than as an escalation. A firm that can answer all seven with documents rather than adjectives has removed most of the risk this article is about.

Why should trust-account continuity be a board-level dependency?

For firms that rely on trust or settlement accounts, banking access is not a treasury detail. It affects settlements, client money, contractual deadlines and the firm's ability to deliver its core service at all.

That makes it a continuity dependency rather than a compliance topic. A board or partnership should identify the critical accounts, the banking counterparties, the key contact points, and the compliance evidence that can be produced if a bank starts enhanced due diligence.

The objective is not to bury the bank in documents. It is to answer legitimate risk questions quickly, consistently, and with evidence that matches what the firm actually does.

What should a banking assurance pack contain?

Build it before the bank asks. A concise pack can cover the entity and service scope, current enrolment evidence, the governance structure, programme approval, a risk assessment summary, compliance officer details, training status, the high-level design of customer due diligence, the independent evaluation plan, and a short description of how issues are escalated and remediated.

Two decisions should be taken in advance rather than under pressure. Where information is commercially sensitive, work out what can be shared, who authorises disclosure, and whether confidentiality protections are needed.

A controlled pack also prevents ad hoc answers from relationship managers who may not know the detail of the programme. Inconsistency between what two people at the same firm tell the same bank is its own risk signal.

Keep the pack current, and date it. An assurance pack assembled once and left alone becomes a liability, because the version a bank reads may describe a programme the firm has since changed.

What should you do when a bank raises a concern?

Four steps, in order. Establish what information or risk concern is actually driving the request, because the stated question and the underlying concern are not always the same. Provide accurate evidence rather than assurances about being compliant.

Remediate any genuine gap the request exposes, and keep a record of what changed and when. Then escalate any threatened service restriction through executive and legal channels, because the operational impact extends well beyond the compliance function.

One thing to avoid is treating the exchange as adversarial. The bank is discharging its own obligation, and a cooperative, evidenced response is both faster and less likely to escalate than a minimal one.

What not to do is claim that enrolment resolves the concern. A bank assessing residual risk is usually more interested in whether the programme is genuinely implemented than in whether a portal step has been completed. Our Tranche 2 checklist sets out the sequence that produces the evidence such a request will test.

Where does technology fit in this?

The evidence behind customer and business due diligence is the part a platform can carry: structured screening, ongoing monitoring, decision records and reporting. Those records are what let a firm show its policies operate in practice rather than existing only as documents, which is precisely the gap a bank's question is aimed at.

Banking continuity remains a wider governance matter covering risk assessment, policy, training, reporting and executive oversight. Technology supports part of that control environment. It does not guarantee that a bank will provide or continue a service, and no vendor should suggest otherwise. The Tranche 2 hub covers the rest of the programme this depends on.

Important information

This article provides general information about Australia's AML/CTF framework and does not constitute legal advice. Whether an obligation applies depends on the designated services provided and the circumstances of the business.

Decisions about banking services are made by the institution concerned under the laws and policies that apply to it, and nothing here predicts how a particular bank will act. Take your own advice on your banking arrangements and your AML/CTF position. Reporting entities remain responsible for meeting their obligations under the AML/CTF Act, the Rules and applicable AUSTRAC guidance, alongside its published regulatory expectations.

FAQ

Common questions.

Will a bank freeze our trust account if we have not enrolled with AUSTRAC?
There is no AUSTRAC rule requiring that. A bank's decision to restrict, decline or end a service is a customer-risk and commercial decision subject to the laws applying to the bank. AUSTRAC's guidance is explicit that a risk-based approach does not require institutions to disengage from risk, and that higher risk does not automatically mean a relationship must end.
Is it called a Reporting Entity Number?
No. AUSTRAC's current guidance uses an AUSTRAC account number, or AAN, which you receive on enrolment. Claims that banks are freezing accounts because a firm cannot produce a "Reporting Entity Number" use terminology the regulator does not, which is usually a sign the underlying claim has not been checked either.
What can a bank legitimately ask us for?
AUSTRAC says it can be reasonable for a financial institution to ask whether a regulated business has an AML/CTF programme, how it was developed and how seriously it is being implemented. In some cases the bank may request a copy of the programme or other evidence to assess whether the systems and controls appear reasonable for the customer's risk.
Does enrolment alone answer a bank's concerns?
Rarely. A bank assessing residual risk tends to care whether the programme is genuinely implemented rather than whether a portal step is complete. Enrolment evidence is one input into a wider assessment that covers risk assessment, governance, due diligence, monitoring, training and reporting readiness.
What should we do if a bank raises a concern?
Establish what information or risk concern is driving the request, then provide accurate evidence rather than statements about being compliant. Remediate any genuine gap and record what changed. Escalate a threatened service restriction through executive and legal channels, because the operational impact reaches beyond the compliance team.

See MemberCheck against your own risk data.

Book a walkthrough with our compliance team and screen a real case in the first session.