Missing the AUSTRAC enrolment deadline is a civil penalty matter, not a criminal one. Criminal exposure is real but it arrives by a different route, usually through how a business handles the investigation rather than through the original failure. Keeping those pathways distinct changes what you do first.
What kind of breach is failure to enrol?
Section 51B of the AML/CTF Act requires reporting entities to apply for enrolment within the statutory timeframe. The Act expressly makes subsection 51B(1) a civil penalty provision, and it treats continued lateness as a separate contravention on each relevant day until the obligation ends.
So it is inaccurate to say that missing the enrolment deadline automatically becomes a strict-liability criminal offence. That framing appears in commentary and it changes behaviour in an unhelpful direction, because a business that believes it is already exposed to criminal liability tends to become defensive at exactly the point where prompt, accurate cooperation is the better course.
The enrolment breach itself sits in the civil penalty framework. Criminal exposure can arise through separate conduct under separate offence provisions, and governance teams need to keep those pathways apart when they brief a board or instruct counsel.
How can ignoring a notice create an offence?
Section 167 allows an authorised officer to require information or documents relevant to compliance or enforcement. A person who has been given a notice and omits to do an act required by it can commit an offence, and the penalty stated in section 167 is imprisonment for six months or 30 penalty units, or both.
The same failure can also engage a civil penalty provision under section 167(3A) and (3B). One act, two routes, which is unusual enough to be worth stating plainly to whoever ends up owning the response.
That is why investigation conduct needs its own legal and governance response even when the underlying issue began as a civil enrolment question. Treating the notice as administrative correspondence to be handled alongside other work is how a manageable civil matter acquires a second, more serious dimension.
The organisational failure mode here is rarely defiance. It is a notice that arrives during a busy period, gets assigned to whoever has capacity, and is answered from what that person can find rather than from a controlled search. Nobody decides to ignore it, and the outcome is the same as if somebody had.
Why does an inaccurate response create its own risk?
The Act contains offences dealing with knowingly false or misleading information and documents in relevant AML/CTF contexts, and a section 167 notice is required to draw attention to those provisions. The notice itself tells you this.
An organisation responding should therefore validate every statement against source records, avoid speculation, and control document versions so that what was supplied and when is unambiguous. Where a fact cannot be established from records, say so rather than estimating, and record why the record does not exist.
Correcting an enrolment gap is important. Supplying inaccurate information during an investigation can create a different and potentially more serious problem, and it is a problem entirely within the organisation's own control. This is the practical reason a response should be slower and checked rather than fast and approximate.
| Pathway | Provision area | What it turns on |
|---|---|---|
| Failure to enrol | Section 51B(1), civil penalty | The dates and the designated service |
| Continuing failure | Section 51B(2C) | Each day until the obligation ends |
| Not complying with a notice | Section 167, offence and civil penalty | Omitting a required act |
| False or misleading material | Separate offence provisions | Knowingly giving false information or documents |
How do civil and criminal proceedings interact?
The Act contains rules governing the relationship between civil penalty proceedings and criminal proceedings. It can allow criminal proceedings to be started for conduct substantially the same as conduct constituting a civil penalty contravention, subject to safeguards about parallel proceedings, prior conviction and the use of evidence.
The detail of those safeguards is genuinely a matter for counsel, and this is not a subject where a general summary is a safe substitute for advice on the facts. What a board should take from it is that the two tracks are related rather than independent, so a decision made for civil-side reasons can have consequences on the criminal side.
The governance point is narrower and still useful. It is another reason not to reduce the risk analysis to a headline fine. Once formal enforcement begins, the questions become which provisions are engaged, what conduct is alleged and what the evidence shows, and those are not answerable from a penalty table.
What should leaders do when the issue is discovered?
Five steps, in order, and the order matters because the first two reduce exposure while the rest establish position.
Establish whether the business is a reporting entity and whether section 51B has been contravened. Stop any continuing enrolment failure by making the required application where appropriate, since the contravention count runs until you do.
Preserve documents and create a privileged legal workstream where advice is needed. Assess whether any regulator notice, prior representation or internal instruction creates separate legal issues, because those are the facts most likely to move the matter beyond the civil framework.
Then remediate the wider programme. A business that focuses only on the enrolment form may remain exposed through customer due diligence, programme, reporting, training or record-keeping gaps, and those are the areas a supervisor examines once enrolment is resolved. Our Tranche 2 checklist sets out that sequence.
What does good documentation look like here?
Contemporaneous, dated and attributable. The organisation should be able to show when the gap was identified, who identified it, what advice was sought, what decision was taken, who took it and what was done.
What it should not do is reconstruct history. Do not backdate documents or create records implying that controls existed when they did not, which is both ineffective and capable of creating exposure of its own.
Remediation is consistently stronger when an organisation can show it found a problem and fixed it than when it presents a tidy file that raises questions about when the file was assembled.
A useful habit is to keep the discovery record separate from the remediation record. The first explains how the gap came to light and what was known at that point. The second shows what changed and when. Merged into a single document written afterwards, both become harder to rely on.
Where does technology fit?
The operational evidence behind customer and business screening, risk assessment, ongoing monitoring and review decisions is what reduces ambiguity about what checks were performed and how a potential match or risk issue was handled. In a remediation context that matters because the alternative is reconstructing months of decisions from memory and inboxes.
No platform is a legal-enforcement tool, and none determines whether conduct is civil or criminal. Formal investigation and offence questions require legal analysis of the Act and the facts. The Tranche 2 hub covers the surrounding programme.
Important information
This article provides general information about Australia's AML/CTF framework and does not constitute legal advice. Whether an obligation applies depends on the designated services provided and the circumstances of the business.
Questions about offences, civil penalty provisions and the interaction between proceedings turn on specific provisions and specific conduct. If your business may have missed an enrolment obligation or has received a notice, take your own legal advice. Reporting entities remain responsible for meeting their obligations under the AML/CTF Act, the Rules and applicable AUSTRAC guidance.



