AUSTRAC has said it expects effort, not perfection, while newly regulated businesses embed their controls. That is a genuine implementation signal and it is widely over-read. It is not a pause on baseline obligations, it is not a defence, and it puts the weight on evidence of trajectory.
What did AUSTRAC actually say?
Its May 2026 statement recognises that reporting entities will continue to embed practices and processes after 1 July 2026, and that it expects effort, not perfection, during FY26/27.
That sentence is usually quoted on its own, which is where the misreading starts. It sits directly beside a list of baseline expectations for newly regulated businesses, and the two are meant to be read together.
AUSTRAC expects newly regulated businesses to be enrolled, to have an AML/CTF programme and an AML/CTF compliance officer, to train staff on the programme, and to be ready to have a go at reporting when a suspicious matter arises. It has also said it will take early enforcement action against businesses that fail to enrol.
The defensible interpretation is therefore maturity with evidence, not delayed commencement. A business that has done nothing is not exercising effort; a business that has enrolled, appointed, trained and can report is inside the position AUSTRAC described even if parts of its programme are still being built.
The word doing the work in that sentence is evidence. Effort is only visible to a reviewer through a record, so the practical effect of the statement is to raise the value of documentation during the very period when a new programme is least likely to produce it. A firm that spends FY26/27 improving steadily without recording what changed, and when, and why, has done the work and cannot show it.
Why should you avoid inventing statutory categories?
Market commentary sometimes describes AUSTRAC as distinguishing wilful non-compliance from an honest effort defence. Those phrases should not be presented as if they were statutory tests unless a specific provision or regulator statement uses them that way.
The Act contains particular offences, civil penalty provisions, defences and enforcement powers. AUSTRAC separately communicates regulatory priorities and expectations. Both are real, and they do different jobs.
Collapsing them creates a specific risk for a compliance function, because it invites management to believe a defence exists that has not been enacted. A board told there is an honest effort defence may reasonably conclude that documenting good intentions is sufficient, which is the opposite of the conclusion the regulator's wording supports.
What management can control is the quality of the evidence showing what it has done, what remains incomplete, why it remains incomplete, and how the residual risk is being managed while the work continues.
What does a credible implementation plan look like?
Not a list of generic AML tasks. A plan that would survive review identifies, for each item, the control gap, the obligation or risk it relates to, the interim mitigation, the responsible owner, the target date, any dependency, and the evidence that will show completion.
| Field | Why a reviewer looks for it |
|---|---|
| Control gap | States the problem in the organisation's own terms |
| Obligation or risk | Connects the gap to why it matters |
| Interim mitigation | Shows the risk is managed now, not only later |
| Responsible owner | A named person, not a function |
| Target date | Makes slippage visible |
| Dependency | Explains why the date is what it is |
| Evidence of completion | Defines what closing the item will produce |
Take ongoing monitoring across a legacy customer book as an example. The plan should say how higher-risk customers are being prioritised in the interim, how changes in customer circumstances are detected while the target workflow is incomplete, who reviews those changes, and when the full workflow lands.
That demonstrates active risk management. A line item saying the organisation is working towards compliance demonstrates nothing, and it is the formulation most likely to be read as an absence of effort rather than evidence of it.
The interim mitigation column is the one most often left blank, and it is the most valuable. A gap with no interim control is an accepted risk whether or not anyone has said so, and saying so explicitly, with the reason and the approver, is a considerably stronger position than leaving it implied.
Which controls should be prioritised first?
AUSTRAC's own statement supplies a starting order, which is useful because it removes the argument about sequencing. Enrolment, then the programme and compliance officer, then staff training, then reporting readiness.
Those are not the only obligations, and treating them as a complete list would be its own mistake. But a business that cannot evidence those four is poorly placed to rely on a narrative of implementation maturity for anything else, because they are the items the regulator named.
The next layer connects the ML/TF risk assessment to customer due diligence, beneficial ownership, enhanced due diligence, ongoing due diligence, reporting and records. Priorities within that layer should follow the organisation's actual risk rather than the order in which tasks are easiest to close, which is the default that quietly emerges when nobody sets one. Our Tranche 2 checklist sets out that sequence with the evidence each step leaves behind.
What should board reporting show?
Trajectory, not a percentage. A single score such as 85 per cent compliant averages strong controls together with material gaps, and the averaging is what hides the gap that matters.
Report which material controls are operating, which are partially operating, which are not yet operating, and what risk is accepted or mitigated while work continues. That structure is harder to write and much harder to misread.
Useful supporting evidence includes approved programme changes, customer-file testing results, training completion, screening and match-review records, suspicious matter escalation exercises, independent evaluation planning, and closure of previously identified issues. Every item on that list is a record rather than an assertion, which is the property that makes it worth reporting.
The aim across successive reports is to show control effectiveness improving over time. A static picture repeated quarterly is itself a finding, and so is a picture that improves only in the areas that were already strong.
Keep the previous report's items visible in the next one. Being able to show that a gap identified two quarters ago was closed, and when, is the clearest available evidence of the trajectory the regulator's wording describes.
Where does technology fit while a programme matures?
Screening, monitoring, risk assessment and evidence are the parts that can be operationalised while the wider programme is still being built, and doing so early has a specific benefit: structured records make it possible to show controls were performed consistently rather than reconstructed afterwards.
That matters most for the period this article is about. The organisations that struggle to evidence effort are usually the ones whose early controls ran on individual judgement and personal files, so there is little to show for the months in question.
A platform is part of the compliance operating model, not evidence that every obligation has been met, and regulatory responsibility stays with the reporting entity. The Tranche 2 hub covers the rest of the programme this depends on.
Important information
This article provides general information about Australia's AML/CTF framework and does not constitute legal advice. Whether an obligation applies depends on the designated services provided and the circumstances of the business.
AUSTRAC's published expectations are statements of regulatory approach rather than legal defences, and they can change. Read the current versions and take your own advice on your own position. Reporting entities remain responsible for meeting their obligations under the AML/CTF Act, the Rules and applicable AUSTRAC guidance, alongside its published regulatory expectations and regulatory priorities.



