Australia publishes its new money laundering Bill.
"A Bill for an Act to amend the Anti‑Money Laundering and Counter‑Terrorism Financing Act 2006 and repeal the Financial Transaction Reports Act 1988, and for related purposes." This is not a small piece of legislation, then. In fact, it's more than 170 pages including 12 schedules. It does not contain explanatory notes (phew!)
It perpetuates one of the failings of the previous legislation in that it does not have a definitions section at the top but it does at least have one buried in Schedule 9 but it is limited to the 2006 Act. So that's an immediate mark against this amendment.
Commencement: there are several commencement dates some of which are fixed and some of which are longstops. Expect nothing much to happen before March 2026 with some things being scheduled for July 2026. So no brownie points for expedition, regardless of the Attorney General's comments that, inter alia, he expected Tranche II to be effective soon.
NEW:
A reporting entity is a person who provides designated services. (Designated services are listed in section 6.). Lead entities of certain business groups (known as reporting groups) are also reporting entities.
• A reporting entity must have and comply with an AML/CTF program.
What is a "lead entity"? Dunno. But a search witin the document reveals a definition in S10 (which is not a definitions section). It's "The lead entity of a reporting group means the person in the group that is specified in the AML/CTF Rules as the lead entity for the reporting group.
Note: The lead entity of a reporting group is a reporting entity, see the definition of reporting entity in section 5."
So the definition is circular, i.e. it defines itself by refering to itself. Still not helpful.
This is why a comprehensive definitions section, at the start of the Act, is such a valuable tool. It's taken ten minutes to fail to get a definition. This is unacceptable.
The Bill is unecessarily bureaucratic. It talks of "reporting groups" and has an extensive list of qualifying factors. Only an accounting/consulting company could have come up with something so complex. It should be scrapped in favour of a simple system by which each business within a corporate group has an internal MLRO team which submits its findings to single Group office in the most senior operating company in the group (with the caveat that the group may nominate that the holding company sits below the most senior operating company for this specific purpose.
"The AML/CTF program must be appropriate to the nature, size and complexity of the reporting entity’s business. For a lead entity of a reporting group, it must be appropriate to the nature, size and complexity of the business of each reporting entity in the reporting group."
Let's ignore the thing about groups for a moment and look at the first part of this provision. The Bill is saying that each business unit is to be treated as an individual unit for the purposes of designing, implementing and maintains its policies and procedures. On the face of it, this makes lots of work but in fact it's an effective recognition that there is a wide range of risks and compliance demands in complex financial groups. So it's a good thing. So is the fact that ultimate responsibility rests with "the lead entity". If we ever find out what that is.
And boards can't say "we've delegated that" because the Bill says "the governing body of the reporting entity has responsibilities relating to the AML/CTF program, including relating to overseeing and ensuring the reporting entity complies with the AML/CTF policies, this Act and instruments under this Act." OK, it would be better to say "supervising" but otherwise, this clear statement that compliance is a director-level responsibility is welcome.
But despite that, the MLRO / Compliance officer is not designated as a board function: "The reporting entity must have an AML/CTF compliance officer. The AML/CTF compliance officer has various functions, including to oversee and coordinate the effective operation of, and compliance with, the AML/CTF policies." It should be and note that this is all about compliance. What about financial crime risk?
Well, hurrah! There's a complete section about money laundering and terrorist financing risk. S26C and it's a good one. "(1) A reporting entity must undertake an assessment (an ML/TF risk assessment) that identifies and assesses the risks of money laundering, financing of terrorism and proliferation financing that the reporting entity may reasonably face in providing its designated services."
There are all sorts of twiddly bits that try to simplify things operationally but actually muddle them but the intent is clear and welcome. As is the requirement for the review and updating of risk assessments.
So, what does this mean in practice? We are already seeing across LinkedIn consultants changing their headlines to declare themselves financial crime risk specialists. Odd, that as they weren't a few weeks ago. We will see accountants setting up departments to offer this service and we will see software companies saying "we can handle your risk assessments for you" - which is presumably why AUSTRAC issued a warning notice about outsourcing within the past few days drawing specific attention to the difference between risk and compliance.
There is much, much more in the Bill and, of course, there may be many changes before it reaches Royal Assent.
You can download a copy of the Bill and follow its progress here:
https://www.aph.gov.au/Parliamentary_Business/Bills_Legislation/Bills_S…


