Section 51B turns an overdue enrolment into a growing problem rather than a fixed one: each day the obligation remains unmet is treated as a separate contravention. That mechanic is widely misread, usually by multiplying a Federal Court maximum by a day count. Here is how to model the exposure defensibly instead.
What does section 51B actually require?
Section 51B of the AML/CTF Act requires a person who starts providing a designated service while not entered on the Reporting Entities Roll to apply for enrolment no later than 28 days after starting that service, subject to the exceptions in the Act.
If that deadline passes, the obligation does not lapse. It continues until the person applies for enrolment or ceases to be a reporting entity. Subsection 51B(1) is a civil penalty provision, so the failure is enforceable rather than merely administrative.
For directors and compliance teams the implication is simple to state and easy to miss: delay increases the number of contraventions in issue. This is not one historical failure sitting static in the past.
Why is late enrolment a separate breach each day?
Subsection 51B(2C) treats the failure as a separate contravention on each day from the enrolment deadline through to the day the continuing obligation ends. The period in issue is therefore defined by two dates you control, the date the designated service began and the date you applied.
That is why the first management action on discovering a late enrolment is to apply, not to commission an analysis. Every day spent deciding what to do adds to the count that will later have to be explained.
Both of those dates need evidence behind them, and only one is usually easy. The application date is a matter of record. The commencement date has to be established from engagement letters, matter descriptions, invoices and ledger activity, and it is the date most often argued about, because the day a service was first provided is rarely the day anyone wrote it down.
How should you not calculate the exposure?
The Act provides several enforcement mechanisms and they should not be collapsed into one formula. A Federal Court civil penalty maximum is a statutory ceiling, not an automatic fine imposed for each day. The Court determines a penalty after considering relevant matters including the nature and extent of the contravention, the circumstances in which it occurred, any loss or damage, and relevant prior findings.
Multiplying a headline maximum by a number of days produces a figure with no legal basis. It also tends to paralyse decision-making at exactly the point where prompt application would reduce the period in issue.
There is a governance cost to circulating that kind of number internally. A figure large enough to alarm a board tends to move the conversation towards whether the obligation really applies, when the useful question is how quickly the continuing failure can be stopped and evidenced.
What are the actual statutory figures?
As at 1 July 2026 one Commonwealth penalty unit is 364 dollars. The mechanisms sit at different scales and are triggered differently.
| Mechanism | Who applies it | Statutory amount | What it is |
|---|---|---|---|
| Civil penalty order, body corporate | Federal Court | Up to 100,000 penalty units (s175) | A ceiling the Court may impose, not a starting point |
| Civil penalty order, other person | Federal Court | Up to 20,000 penalty units (s175) | Same basis, applied to a person |
| Infringement notice, body corporate | AUSTRAC | 60 penalty units (s186A) | Administrative, unless the Rules set a different permitted amount |
| Infringement notice, other person | AUSTRAC | 12 penalty units (s186A) | May specify more than one alleged contravention |
Reading those rows together is the point. An infringement notice and a civil penalty order are alternative routes at very different scales, and neither is a per-day tariff.
One further feature of infringement notices is worth noting, because it is where the daily contravention mechanic and the administrative route meet: a notice can specify more than one alleged contravention. That does not turn the per-day count into a multiplier, but it does mean the length of the period is capable of being reflected in an administrative outcome as well as a judicial one.
What should an internal exposure schedule contain?
A useful schedule starts with facts, not a penalty estimate. Compliance and legal teams should establish the legal entity that provided the service, the designated service relied on, the date that service first commenced, the statutory enrolment deadline, the date an enrolment application was made or the entity ceased to be a reporting entity, and the resulting number of potential contravention days under section 51B(2C).
It should also record whether multiple entities in a partnership, corporate group or reporting group need separate analysis, because one line in a schedule can conceal several different answers.
Only once that factual schedule is settled should legal advisers model possible enforcement outcomes. The purpose of the model is to give management a controlled view of the period in issue, not to claim certainty about what AUSTRAC or a court will do.
How does enterprise structure complicate this?
Large professional networks should not assume that one central enrolment resolves every entity-level question. Partnerships, controlled groups, franchise arrangements and elective reporting groups can allocate or extend obligations in different ways.
Map the entity providing the designated service, the reporting-group structure and any applicable attribution provisions before management signs off on an exposure calculation. That matters most where customers contract with different legal entities across offices or service lines, which is common in accounting and real estate networks and is exactly where a single central answer tends to be wrong. Our Tranche 2 checklist sets out the scope mapping this depends on.
What should remediation look like?
Once a genuine late-enrolment issue is identified, the operational priority is to stop the continuing failure by completing the application, then address the wider control environment. Preserve the original dates and records rather than rewriting the history, because the dates are what the schedule above depends on.
A remediation file should document how the issue was identified, who authorised corrective action, when enrolment was submitted, what other programme gaps were found and how they were closed. AUSTRAC's published regulatory expectations say it expects newly regulated businesses to be enrolled, and that its enforcement focus falls on those who wilfully ignore that obligation.
What has AUSTRAC said about non-enrolment specifically?
AUSTRAC's published position separates imperfection from avoidance. Its expectations state that it does not expect newly regulated businesses to be perfect at identifying and controlling money laundering risk from day one, but that it does expect honest efforts to meet obligations and report suspicions.
Against that, the obligation to enrol is treated differently from the rest of the programme. AUSTRAC has said its enforcement focus in the newly regulated sectors falls on entities that wilfully ignore the obligation to enrol, and on those it suspects are complicit with, or wilfully blind to, money laundering. In late August 2026 it also began issuing information-gathering notices to businesses that appeared to be providing designated services without being enrolled.
The practical reading for a late enroller is that an imperfect but enrolled and honestly operated programme is not the stated target, and that the way to move out of the stated target is to apply.
Where does technology fit?
The controls that sit beyond enrolment are where an operating model is demonstrated: structured screening, customer and business risk workflows, ongoing monitoring and retrievable audit records. Those can help show that remediation has moved into day-to-day operations rather than remaining a policy exercise.
No platform calculates legal liability, and none should be treated as a substitute for advice on penalty exposure. The defensible position combines legal analysis of the contravention period with evidence that the compliance operating model is genuinely under control. The Tranche 2 hub sets out the rest of that sequence.
Important information
This article provides general information about Australia's AML/CTF framework and does not constitute legal advice. Whether an obligation applies depends on the designated services provided and the circumstances of the business, and penalty exposure depends on facts that are specific to each case.
If you believe an enrolment obligation may have been missed, take your own legal advice on your own dates and services. Reporting entities remain responsible for meeting their obligations under the AML/CTF Act, the Rules and applicable AUSTRAC guidance.



