You have to name an AML/CTF compliance officer, the AMLCO, and the appointment has to be real. The AMLCO is the person who runs your AML/CTF program day to day: who decides how customers are verified, when reports go to AUSTRAC, and what happens when something looks wrong.
The role exists because your firm is a reporting entity: a business that provides a designated service, a service listed in the tables to s6 of the AML/CTF Act 2006 (Cth) — Table 6 for professional services, Table 5 for real estate, Table 2 for precious metals and stones — and is therefore captured by that Act. Tranche 2 brought accountants, legal practitioners, conveyancers, real estate agents, dealers in precious metals and stones, and trust and company service providers into that position from 1 July 2026. If you provide one of those services, the obligation to appoint an AMLCO applies to you now.
Who can hold the role
The role has to be held by an individual: a real person with a name, not a committee, not a shared title, and not an outsourced function with no one answerable behind it. Four eligibility requirements sit on top of that, and they are checkable rather than a matter of judgement.
| Requirement | What it means in practice |
|---|---|
| An individual, not a position | A named person the firm and AUSTRAC can hold to account |
| Ordinarily resident in Australia | The person has to live here, not hold the role from an offshore office |
| Convictions and regulatory history considered | Whether the person has been convicted of a serious offence, is the subject of adverse regulatory findings, has been found to have engaged in serious misconduct, or is bankrupt or under a personal insolvency agreement |
| Fit and proper, and senior enough to act | Before appointing, you must determine the person is fit and proper (s26K(2), Rules s 5-14): competence, skills, knowledge, diligence, expertise and soundness of judgement; good character, honesty and integrity; and no conflict of interest creating a material risk they will not act properly. AUSTRAC expects periodic reassessment, and is explicit that this is a considered judgement, not a pass/fail checklist |
Two deadlines attach to the appointment, and both are short.
| What | When |
|---|---|
| Appoint an AMLCO after becoming a reporting entity | Within 28 days |
| Notify AUSTRAC of the appointment | Within 14 days of appointing |
| Appoint a replacement if the AMLCO leaves the role | Within 28 days |
| Notify AUSTRAC of a change of AMLCO | Within 14 days |
For a firm captured on 1 July 2026, the 28-day clock started then. If you have not made a documented appointment, that is the first thing to fix, ahead of anything else on this page.
Seniority is the practical test. An AMLCO who has to ask permission before opening records, reallocating staff time or stopping a transaction is running the program at someone else’s pace, and the obligations do not slow down to match. The role needs someone whose decisions bind the firm, or every deadline sits behind an approval chain that was never built for it.
Independence is the one people miss, and it is worth being precise about its status. It is not in the eligibility list above. It is good practice rather than a stated statutory test, and it matters because the AMLCO decides what gets checked, what gets reported and what gets stopped, and the same person should not sit on both sides of those decisions. In a small firm that is easier to want than to arrange.
Access is the fourth requirement: the systems, the records and the staff time the role depends on. An AMLCO without them has the title and nothing else, and an appointment that cannot operate is not an appointment at all.
In most Tranche 2 firms the AMLCO is a principal, a partner or a practice manager: someone already accountable for how the firm runs. In a firm of one, the sole practitioner is usually the only candidate, and holding the role yourself is workable if the record of the appointment acknowledges the conflict and says how it is managed. A firm with several offices or service lines needs the role held by someone who can see across all of them. Whether a single AMLCO can cover several entities in a group is not something we can confirm, so if your structure has more than one reporting entity in it, plan on an appointment for each until you have advice saying otherwise.
What the role is accountable for
The AMLCO is accountable for the reporting, and the deadlines are specific. A suspicious matter report (SMR), the report AUSTRAC receives when you form a suspicion about a matter, is due three business days from the moment the suspicion forms, under s41(2) of the Act. Where part of the grounds is privileged, covered by legal professional privilege, and an LPP form, the privilege claim form AUSTRAC accepts in place of the withheld information, is filed, the window extends to five business days under s 41(2)(aa); the privilege page works through those paths. A threshold transaction report (TTR), for cash of $10,000 or more, is due within ten business days under s43(2). Each of those clocks is owned by the AMLCO: the systems that make them visible, and the escalation that meets them.
The role also owns the secrecy side. Under s123 of the Act, tipping-off is an offence: telling a customer, or anyone else, something that would, or could reasonably be expected to, prejudice an investigation, whether or not one has started. The maximum penalty is two years imprisonment, 120 penalty units, or both. The AMLCO is the person who makes sure staff can raise a suspicion without the subject of it finding out, and the tipping-off page covers the shape of that offence.
The day-to-day work is the due diligence the firm performs before a service is provided: who the customer is, who ultimately owns them, and whether the transaction matches what they have said. Higher-risk customers get deeper checks, on where the money comes from and what the transaction is for. The AMLCO sets how all of this happens, checks that it happens, and decides where the line sits between a standard check and a deeper one. The AML/CTF program is the document the role runs, and the independent evaluation is the check on it: the evaluator has to be independent of the program’s design and operation, which is why the AMLCO usually cannot be the evaluator.
Records sit with the role as well. The program, the due diligence files, the reports and the reasoning behind decisions are retained for seven years, and the AMLCO is the person who can produce them when asked.
The role does not absorb the firm’s obligations. Naming an AMLCO does not make the firm compliant, does not move liability, and does not reduce what you must do. It creates a person who owns the program, which is why the appointment matters and why a name on paper with nothing behind it changes nothing.
What catches people out
Three things undo otherwise-sensible appointments.
The obvious candidate can be the one with the conflict. In a small firm, the person with the time and the knowledge is often the practitioner whose own work the program exists to check. Name that person, and the decision-maker is deciding on their own matters: whether their own client’s transaction is suspicious, whether their own file gets the closer look. The consequence is a program whose checks are applied by the person they exist to catch, and an independent evaluation that flags the appointment rather than passing it.
The role carries personal accountability. When a report is late or a customer was never verified, the questions run to the person who owned the program, not only to the firm. The consequence is that the named AMLCO answers for the program by name, which is a reason to give the role what it needs and to record the appointment and its scope rather than leave it informal.
A nominal appointment is a failure in its own right. Name someone and give them no access to the systems they must oversee, and the firm has the appearance of a program with none of the operation: the AMLCO cannot see the flags, the files or the deadlines, so reports go out late and transactions go unchecked. The consequence is a program that is treated as not operating, because the person accountable for it never had the means.
What is still unsettled
The eligibility requirements and the two deadlines above are settled. What sits around them is less so.
The AML/CTF Rules (2025) were remade with new numbering, so any rule reference you find in older guidance needs re-checking before it goes into your own procedure. Whether a smaller firm can satisfy the obligation with a lighter arrangement, such as a contact officer rather than a full AMLCO, is not something we can confirm, so plan for a full appointment. The same goes for whether the AMLCO has to be named as part of enrolment: assume you will be asked for the name and have it ready.
Write the appointment and its reasoning now, and expect to revise both as the detail firms up.
Where to start
Three steps do most of the work:
- Name the person: choose the AMLCO and write down the reasoning: seniority, independence, access. If the only candidate has a conflict, record how it will be managed rather than leaving it unspoken.
- Give the role working access: the systems, the records, the staff time, and a private route for staff to raise concerns without the subject of a suspicion finding out.
- Write the appointment into the program: the appointment, its scope and its limits belong in the AML/CTF program, approved and recorded, so the independent evaluation checks a real role rather than a name on paper.
How duely handles this
The AMLCO is a single role, not a permission that several people can hold, and it comes with a console only that person can open. Appointment details and the cadence dates sit on the firm record, and the escalations that need AMLCO attention (risk, sanctions, review outcomes) land in one queue rather than being spread across the product. Approving an AML/CTF program is blocked while no AMLCO is appointed, so the appointment cannot be quietly deferred.