The Australian Transaction Reports and Analysis Centre (AUSTRAC) runs a risk-based Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) regime, which puts the burden on each reporting entity to decide what its own risks are. That is why compliance officers at Australian iGaming and fintech firms keep hitting the same wall: they want a list of transactions AUSTRAC expects them to flag, and no such list exists.
This guide explains what that means in practice for operators moving high volumes of money.
quick summary
What AML Compliance Means for iGaming and Fintech in Australia
AUSTRAC regulates any business providing a designated service, which captures online gambling operators and most fintech models: payments, remittance, digital currency exchange and lending. Meeting that definition makes a company a reporting entity with obligations from the first transaction.
Both sectors move money quickly and at scale, which is exactly the environment money launderers look for. Gambling accounts and payment rails let illicit funds enter, mix and exit fast, so AUSTRAC holds these operators to a demanding monitoring standard.
Austrac Uses a Risk-Based Approach, Not a Checklist
The most common misunderstanding among newer reporting entities is that the regulator will hand them a set of rules to run. But in reality, AUSTRAC expects each business to assess its own exposure and build controls that answer the risks it actually faces.
That reframes the whole task. Instead of asking “what does AUSTRAC want me to monitor,” an operator has to ask “where is my business most exposed to laundering, and can I show controls that match.” An ATM-heavy cash business worries most about laundering typologies, while a card-present retailer worries more about chargeback and fraud, so their monitoring rules should look different.
“AUSTRAC doesn’t tell you what to look for. It tells you to do your own risk assessment and make sure your transaction monitoring is mapped to it. Whatever inherent risks you find, that is what you monitor.”
Nauman Abuzar, VP of AML Compliance and Risk
Core Austrac Obligations for Reporting Entities
Compliance starts with enrollment on the AUSTRAC Reporting Entities Roll and a written AML/CTF program built on a documented risk assessment. The program has to reflect the specific business, because AUSTRAC judges whether controls match real exposure rather than whether a template was filled in.
From there, several duties run continuously. Operators verify identity through customer due diligence (CDD), screen against sanctions and PEP lists, monitor transactions, report to AUSTRAC and keep relevant records for seven years.
Transaction Monitoring: What Austrac Actually Expects
Monitoring is where the regime gets heaviest, and where audit findings most often surface. A frequent trigger for change is an external audit that flags manual or batch-based reconciliation as inadequate, with a recommendation to automate monitoring and map it directly to the risk assessment.
Effective programs have rules in place that trace back to named risks. Alerts feed a case with an audit trail and confirmed suspicion produces a suspicious matter report (SMR), with a threshold transaction report (TTR) for cash movements at or above AUD 10,000.
Catch the typologies that match your risk
Structuring, velocity spikes, high-risk geographies and pass-through activity are the patterns most operators need to catch, but the specific rules depend on the business. A cash-heavy operator might flag repeated withdrawals on one card across several devices in a short window, while a payments firm watches for rapid in-and-out movement that suggests layering.
Keep false positives from burying the team
Static thresholds cannot tell a legitimate high roller from a launderer, so rules-only monitoring buries analysts in noise. Layering behavioral and device signals onto transaction data adds the context that lets a team clear alerts faster and escalate the ones that matter, which is the difference between a program that scales and one that stalls.
Source of Funds and Source of Wealth: The Australian Data Gap
iGaming operators carry a specific burden that catches many teams out. Verifying a customer’s source of wealth or income is a regulatory expectation for higher-risk gambling relationships, yet Australia lacks the public wealth and property databases that make this straightforward in other markets.
The practical answer is to combine electronic identity checks with evidence gathered directly from the customer, then risk-rate the relationship so scrutiny scales with exposure. Trying to source wealth data that simply is not available leads teams to over-collect and slow down onboarding for everyone.
Reduce Onboarding Friction With Pre-Kyc Screening
Full identity verification is costly and slows down legitimate customers, so screening high-risk applicants out before that stage saves money and friction. Checking an applicant’s email, phone, IP and device against their digital footprint flags synthetic identities and manipulation before a formal Know Your Customer (KYC) check begins.
This matters most for high-volume operators, where even a small share of fraudulent onboarding attempts adds up fast. Filtering early keeps expensive checks focused on genuine prospects and keeps the funnel smooth for real customers.
Preparing for Austrac’s Risk-Based Framework by March 2029
AUSTRAC has reformed its AML/CTF framework, moving Tranche 1 businesses further toward risk-based customer due diligence and away from prescriptive processes. The reform reinforces the same principle that already trips up newer entities: controls must follow from a documented assessment of risk.
Tranche 1 businesses have until March 2029 to complete the move from legacy programs to the new standard. The runway is long, but operators who transition early avoid a deadline scramble and get tighter, risk-based controls in the meantime.
FAQ
Does AUSTRAC tell you which transactions to monitor?
No. AUSTRAC uses a risk-based approach. Each reporting entity runs its own money laundering and terrorism financing risk assessment and maps its transaction monitoring rules to the inherent risks it identifies.
What does an AUSTRAC transaction monitoring program need?
Monitoring rules tied to a documented risk assessment, real-time or timely detection, alerts that feed a case with an audit trail, and a path to file suspicious matter reports and threshold transaction reports.
Do iGaming and fintech companies need AML compliance in Australia?
Yes. Both are Tranche 1 reporting entities regulated by AUSTRAC and must maintain an AML/CTF program, perform customer due diligence, screen for sanctions and PEPs, monitor transactions and report.
How do Australian iGaming operators verify source of wealth?
Australia lacks public wealth and landlord databases, so operators combine electronic identity verification with evidence supplied directly by the customer, applying enhanced due diligence to higher-risk relationships.
When do Tranche 1 businesses have to meet AUSTRAC’s new framework?
Tranche 1 businesses have until March 2029 to move from legacy programs to AUSTRAC’s reformed risk-based customer due diligence framework.
