AML/CTF compliance

Choosing AML/CTF Software? What AUSTRAC Says You Should Expect, and Watch Out For

26 September 2026 · 4 min read

Legal team evaluating AML compliance software

In brief

Good AML/CTF software should support risk-based compliance, mandatory reporting data, restricted access, human approval and audit evidence without claiming to replace the firm’s legal responsibility or to be AUSTRAC endorsed.

Tranche 2 has brought many new compliance software providers. At its September 2026 RegTech session, AUSTRAC set out its expectations of those providers. Those expectations are also a useful buying checklist.

What AUSTRAC made clear

  • Your firm stays responsible. Reporting entities are responsible for meeting their AML/CTF obligations, including customer due diligence. Software supports compliance; it doesn't take on your obligations.
  • AUSTRAC doesn't endorse products. Be wary of any vendor that claims to be "AUSTRAC approved".
  • Marketing must be clear and accurate. Vendors should explain what their solution can and can't do, including its limitations.
  • Solutions must be kept current as the rules change. For example, IFTI reporting is due to change in 2029.
  • Test before you go live. Reporting solutions should be tested in AUSTRAC's training environment, and your firm controls access to AUSTRAC Online and that environment.

Questions to ask any vendor

1. Which of my obligations does your product support, and which doesn't it cover? 2. How do you make sure reports meet AUSTRAC's mandatory fields and data-quality expectations? 3. How do you prevent tipping off? Who can see suspicion-related records? 4. Is every decision attributed and timestamped for audit? 5. Where is my data stored? Is it in Australia? 6. How do you keep up with changes to the Rules and report formats? 7. Does a human approve every lodgement and every risk decision?

Where Comply.LM stands

Comply.LM is built for Australian legal and conveyancing firms:

- automated identity, address and sanctions checks - exception-based review, so staff look only at the cases that need attention - traffic-light risk scoring - role-based access - a document repository - guided AUSTRAC enrolment - decisions that are audit-ready by default

Your firm stays in control of every decision. Comply.LM handles the paperwork around it, so your lawyers can keep practising law.

General information only, not legal advice.

  • Today:
  • Available now: guided AUSTRAC reporting for SMR, TTR, IFTI-E and CBM. - Coming next: the Risk Assessment Agent.

Authoritative sources

This article draws on current AUSTRAC guidance. Always check the source guidance for updates that apply to your circumstances.

Common questions

Does AUSTRAC approve AML/CTF software?

No. AUSTRAC does not endorse individual RegTech products, and the reporting entity remains responsible for compliance.

What should a law firm ask a software vendor?

Ask about supported obligations, data validation, tipping-off controls, audit trails, data location, regulatory updates, human approval and known limitations.