AML/CTF Obligations for Private Lenders: What AUSTRAC Expects

Published By:

Professional man in a suit smiling, possibly for Elementor Single Post.

Gavin McInnes

Founder of GRM LAW

Key Takeaways:

  • Enrol within 28 days: If you make loans in the course of carrying on a loans business, you are a reporting entity and must apply for enrolment on the Reporting Entities Roll within 28 days of commencing that designated service, or face civil penalties.
  • Complete customer due diligence before lending: You must verify the borrower’s identity, assess their ML/TF risk, and identify beneficial owners (individuals with 25%+ ownership or control) before providing any loan — including tracing trust and corporate structures to their ultimate controllers.
  • Monitor and report suspicious matters promptly: You must conduct ongoing customer due diligence and report any suspicious matter to AUSTRAC within 24 hours for terrorism financing or three business days for money laundering and other offences.
  • Do not retain full identity documents: Under OAIC guidance, you should retain only essential data points (name, date of birth, document type and number) rather than scanned copies of identity documents, while still keeping required records for seven years after the relationship ends.
Jump to...
October 2, 2026

Introduction

Reforms to the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (‘AML/CTF Act‘), which commenced on 31 March 2026, capture private lenders who make loans in the course of carrying on a loans business, so affected lenders may need advice from private lender and non-bank finance lawyers at GRM LAW. These lenders are now reporting entities providing financial services, subject to AUSTRAC’s full suite of anti-money laundering and counter-terrorism financing obligations.

This article explains what AUSTRAC expects from private lenders as reporting entities — from enrolling on the Reporting Entities Roll to conducting customer due diligence and verifying the source of funds for borrowers.

Interactive Tool: Check If AML/CTF Rules Apply to Your Lending

AML/CTF Compliance Checker for Private Lenders

Quickly check if your private lending activities trigger AUSTRAC reporting and AML/CTF obligations under the latest reforms.

Are you making loans in the course of carrying on a loans business (not just a one-off or private arrangement)?

Have you enrolled on the AUSTRAC Reporting Entities Roll within 28 days of commencing lending activities?

Do you have a documented AML/CTF program and conduct customer due diligence (KYC) before providing loans?

✅ Not a Reporting Entity Under AML/CTF Act

Based on your answers, you are not carrying on a loans business and are unlikely to be a ‘reporting entity’ under Section 5 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). No AUSTRAC enrolment or AML/CTF program is required for one-off or private loans.

However: If your lending activities change, you should reassess your obligations.
Legal Reference:
Section 5 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Speak to a banking & finance lawyer

⚠️ AUSTRAC Enrolment Required

You are carrying on a loans business and must enrol on the AUSTRAC Reporting Entities Roll within 28 days of commencing designated lending activities. Failing to do so is a civil penalty provision under Section 51B of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).

Immediate action is required to avoid enforcement or penalties.
Legal Reference:
Section 6, Section 51B of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Get AUSTRAC compliance legal advice

⚠️ AML/CTF Program & KYC Checks Required

As a reporting entity, you must implement a documented AML/CTF program and conduct customer due diligence (KYC) before providing loans. This is required under Section 26B and Section 28 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and in the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth).

Non-compliance may result in civil penalties or AUSTRAC enforcement.
Legal Reference:
Section 26B, Section 28 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth)
Get AML/CTF program legal advice

✅ AML/CTF Compliance Confirmed

You appear to be compliant with AUSTRAC’s requirements for private lenders under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). Maintain ongoing monitoring and update your AML/CTF program as regulations evolve.

For complex lending structures or regulatory changes, seek tailored legal advice.
Legal Reference:
Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Speak to a banking & finance lawyer

Contact Us Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

When Lending Activities by Private Lenders Are Captured as Designated Services

Defining Designated Services for Non-Bank Financiers

Section 6 of the AML/CTF Act identifies financial services that are designated services. In particular, Table 1, item 6 covers making a loan where the loan is made in the course of carrying on a loans business.

The term “loan” includes:

  • an advance of money;
  • the provision of credit or other financial accommodation; and
  • a payment made where there is an obligation to repay.

The borrower is the customer of this designated service, so the provision applies to private lenders and other non-bank financiers carrying on a loans business.

The Role of Reporting Entities & Financial Services

Section 5 of the AML/CTF Act defines a reporting entity as either:

  • a person who provides a designated service; or
  • the lead entity of a reporting group.

As a result, a private lender that makes loans covered by Table 1, item 6 becomes a reporting entity when it provides that financial service.

Reporting entities need to meet the anti-money laundering and counter-terrorism financing obligation that follows from providing a designated service. This includes the compliance framework administered by AUSTRAC, which covers:

  • requirements connected with an AML/CTF program; and
  • customer due diligence.

Enrolling on the Reporting Entities Roll

A private credit fund that commences providing a designated service must apply for enrolment on the Reporting Entities Roll within 28 days under Section 51B of the AML/CTF Act. The obligation applies to reporting entities providing financial services, including the designated service of making a loan in the course of carrying on a loans business.

The application must be made in writing under Section 51E of the AML/CTF Act and contain information required by the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth) (‘AML/CTF Rules‘), including:

  • details about the fund;
  • its designated services;
  • business activities;
  • ownership;
  • management;
  • reporting group status; and
  • approximate turnover.

Failing to apply within the required period is a civil penalty provision under Section 51B of the AML/CTF Act.

Structuring an Effective AML/CTF Program

Under Section 26B of the AML/CTF Act, an AML/CTF program comprises the reporting entity’s ML/TF risk assessment and AML/CTF policies. The risk assessment must identify and assess the money laundering, terrorism financing and proliferation financing risks the fund may reasonably face through its designated services.

Section 26F of the AML/CTF Act requires AML/CTF policies, procedures, systems and controls that manage and mitigate those risks and suit the nature, size and complexity of the business, so private lenders can seek advice from private lender AML/CTF regulatory compliance lawyers. The AML/CTF Rules, Section 5‑2, requires those policies to state when the fund will collect and verify KYC information, including information about a customer’s source of funds where relevant to the customer’s risk.

Executing Initial Customer Due Diligence

Before providing a loan or other financial accommodation, a reporting entity must complete initial customer due diligence under Section 28 of the AML/CTF Act. The fund must:

  • establish the customer’s identity;
  • identify anyone acting on the customer’s behalf;
  • understand the nature and purpose of the relationship;
  • assess the customer’s ML/TF risk; and
  • collect and verify KYC information using reliable and independent data.

The AML/CTF Rules set minimum information requirements for different customers:

  • Under Section 6‑2 of the AML/CTF Rules, a corporate borrower requires information about its name, existence, registered office, business operations, governing individuals, and ownership and control structure.
  • Under Section 6‑3 of the AML/CTF Rules, a trust borrower requires information about the trust type, existence, trustees, beneficiaries or beneficiary classes, and relevant control information.

A fund must not commence providing the designated service until it has established the required matters on reasonable grounds.

Request Free Consultation

Not sure which matter or service is right for you? Request free consultation from our senior lawyers.

Verifying Beneficial Ownership Behind Corporate & Trust Borrowers for Syndicate Lenders

Identifying Beneficial Owners of a Company

A beneficial owner is an individual who ultimately owns, directly or indirectly, 25% or more of a customer, or controls the customer. Under Section 5 of the AML/CTF Act, control may exist even where the individual does not own the company.

Syndicate lenders should trace each ownership layer until the relevant individuals are identified. The following documents may assist with this due diligence:

  • ASIC registers;
  • annual statements;
  • current and historical company extracts;
  • company constitutions; and
  • shareholder distribution statements.

As noted above, Section 6‑2 of the AML/CTF Rules also requires information about the borrower’s ownership and control structure.

Where ownership cannot be established after all reasonable steps, Section 6‑8 of the AML/CTF Rules requires the reporting entity to record those steps and verify the identity of the company’s chief executive officer or equivalent.

Unpacking Trust Structures & Control

As set out earlier, Section 6‑3 of the AML/CTF Rules requires customer due diligence to collect the trust’s name, kind, existence, governing powers and the individuals responsible for its governance and executive decisions.

The lender must also identify each beneficiary or, where the trust’s terms do not allow each beneficiary to be identified, each beneficiary class. In addition, the identity of the trustees must be collected, together with information about the trust’s control structure and any:

  • settlor;
  • appointor;
  • guardian; or
  • protector.

Section 11(2) of the AML/CTF Act treats control of a person other than a body corporate as including the capacity to control a governing body or determine financial and operating policy through practical influence.

Contact Us Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Ongoing Monitoring & Suspicious Matter Reporting Triggers for Mortgage Funds

Implementing Ongoing Customer Due Diligence

Under Section 30 of the AML/CTF Act, mortgage funds must monitor customers to identify, assess, manage and mitigate money laundering, terrorism financing and proliferation financing risks connected with their financial services.

Monitoring must include unusual transactions and behaviour that may create a suspicious matter reporting obligation. A fund must review and, where appropriate, update customer risk assessments when there is a significant change or unusual activity. It must also review, update and reverify KYC information at a frequency suited to the customer’s risk.

Under Section 6‑21 of the AML/CTF Rules, the fund must hold information about a customer’s source of wealth and source of funds when enhanced customer due diligence applies and that information is relevant to the customer’s risk.

Identifying Suspicious Matter Reporting Triggers

Under Section 41 of the AML/CTF Act, a suspicious matter reporting obligation arises when a mortgage fund has reasonable grounds to suspect that a customer or agent is not who they claim to be, or that information connected with a financial service may relate to:

  • tax evasion or another offence;
  • money laundering or proceeds of crime; or
  • terrorism financing.

The fund must report the matter to the AUSTRAC CEO within 24 hours after forming the suspicion where it relates to terrorism financing. Other matters, including money laundering or tax evasion, must be reported within three business days under Section 41.

The report must include the information required by Section 9‑2, Section 9‑3 and Section 9‑4 of the AML/CTF Rules, including the grounds for suspicion and relevant customer, account and transaction details.

Request Free Consultation

Not sure which matter or service is right for you? Request free consultation from our senior lawyers.

Privacy Act Requirements & Data Minimisation for High-Net-Worth Individuals

Aligning AML/CTF Records with the Privacy Act

Section 105 of the AML/CTF Act provides that Part 10 does not override Part IIIA of the Privacy Act 1988 (Cth) (‘Privacy Act‘). The Office of the Australian Information Commissioner privacy guidance issued in April 2026 explains that privacy obligations apply alongside anti-money laundering and counter-terrorism financing obligations.

Reporting entities and their authorised agents must comply with the Australian Privacy Principles when handling personal information for AML/CTF purposes, regardless of business size. This includes high-net-worth individuals acting as private lenders, where their activities make them reporting entities or involve handling information for a reporting entity.

Data Minimisation & Identity Document Retention

The OAIC guidance states that reporting entities should not retain scanned or photocopied identity documents for AML/CTF record-keeping unless a specific legal requirement applies. Reporting entities should retain only information reasonably necessary to meet their obligations, such as:

  • the individual’s name, date of birth and residential address;
  • the document type, number and expiry date;
  • verification steps taken and their outcome; and
  • customer due diligence and money laundering or terrorism financing risk assessment records.

Reporting entities must take reasonable steps to secure personal information and destroy or de-identify it when it is no longer needed, subject to an applicable exception. However, records required by Section 111 of the AML/CTF Act must still be retained for seven years after the business relationship ends or the occasional transaction is completed.

Contact Us Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Enforcement Actions & Penalties for Non-Compliant Property Development Financiers

Civil Penalty Orders & Financial Fines

Under Section 175 of the AML/CTF Act, AUSTRAC may apply to the Federal Court of Australia for a civil penalty order where a reporting entity has contravened a civil penalty provision. The Federal Court may order payment to the Commonwealth after considering matters such as:

  • the nature and extent of the contravention;
  • any resulting loss or damage;
  • the surrounding circumstances; and
  • similar previous conduct.

The maximum penalty is 100,000 penalty units for a body corporate and 20,000 penalty units for another person. For contraventions occurring on or after 1 July 2026, one penalty unit is $364, meaning the maximum amounts are $36.4 million and $7.28 million respectively. The maximum is not an automatic fine.

Remedial Directions & Enforceable Undertakings

Under Section 191 of the AML/CTF Act, the AUSTRAC CEO may give a reporting entity a written remedial direction after a civil penalty provision has been contravened. The direction may require steps to prevent a further breach, such as:

  • implementing compliance monitoring systems;
  • improving staff understanding; or
  • submitting a report that was not lodged.

Under Section 197 of the AML/CTF Act, the AUSTRAC CEO may accept a written enforceable undertaking requiring a person to take specified action, refrain from specified action or reduce the risk of future non-compliance. If the undertaking is breached, Section 198 of the AML/CTF Act allows an application to the Federal Court for orders requiring:

  • compliance;
  • payment of a financial benefit obtained from the breach; or
  • compensation for resulting loss.

Request Free Consultation

Not sure which matter or service is right for you? Request free consultation from our senior lawyers.

Conclusion

Private lenders providing loans in the course of a loans business may be reporting entities with obligations covering enrolment, AML/CTF programs, customer due diligence, beneficial ownership checks, ongoing monitoring, source of funds information, reporting, record keeping and privacy. The AML/CTF Act also gives AUSTRAC enforcement options where those obligations are not met.

With these requirements in place, contact GRM Law’s private lenders and non-bank finance lawyers in Queensland to review your lending model, enrolment position and compliance processes. Contact AML/CTF regulatory compliance lawyers for private lenders at GRM LAW for clear legal guidance on customer due diligence, reporting entities’ obligations and the application of the AML/CTF Act to your financial services.

Frequently Asked Questions

Disclaimer: This is general information only and is not legal advice. For advice on your circumstances, contact GRM LAW.

JUMP TO...
Table of Contents

Published By:

Professional man in a suit smiling, possibly for Elementor Single Post.

Gavin McInnes

Founder of GRM LAW

Contact us today.

Our senior lawyers will contact you to discuss your situation & outline next steps.

Legal & Compliance Insights

What Our Clients Say

Request Free Consultation

Not sure which matter or service is right for you? Leave your details & our lawyers will contact you to discuss your situation & outline next steps.

Enquire Now

Tell us briefly what you need help with & we’ll reply within 1 business day.

    ICT managed & secured by Black Shard  ·  SMB1001:2026 Gold certified