What a trust and company service provider must do under Australia's AML/CTF Act from 1 July 2026: designated services, enrolment, CDD, ECDD and reporting.
Table of contents
- A trust and company service provider became a reporting entity on 1 July 2026 if it provides any of the professional designated services in table 6 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006: forming or restructuring companies and trusts, selling shelf companies, acting or arranging for someone to act as director, trustee, partner or nominee shareholder, and providing a registered office or principal place of business address.
- Enrolment with AUSTRAC is due no later than 28 days after the first designated service is provided, and the business then sits on the Reporting Entities Roll. As of 17 September 2026 AUSTRAC recorded 13,780 enrolments from accounting and professional services and 6,580 from lawyers.
- Enrolment is the smallest duty. The substantive obligations are an AML/CTF programme built on a money laundering and terrorism financing risk assessment, initial and ongoing customer due diligence, enhanced customer due diligence in defined circumstances, suspicious matter and threshold transaction reporting, and record keeping.
- For a firm that forms companies and trusts for a living, the hard part is beneficial ownership: every trustee, settlor, appointor, guardian, protector and controlling individual behind a trust, and every individual owning 25 percent or more of a company or controlling it, must be identified on reasonable grounds before the service starts.
- Suspicious matter reports are due within 3 business days of forming a suspicion, or 24 hours where terrorism financing is suspected. Records must show how each matter was established, and AUSTRAC states that copies of identity documents do not have to be kept, only their details.
- The price lists in this market mark complex structures as bespoke. A trust and company service provider whose clients are complex structures by definition needs a verification model that resolves ownership to natural persons and shows what it could not resolve, without warehousing every director's passport.
A trust and company service provider is a business that forms or restructures companies and trusts for clients, arranges for someone to act as director, trustee or nominee shareholder, or provides a registered office address. In Australia these are designated services under table 6 of the AML/CTF Act from 1 July 2026, making the provider an AUSTRAC reporting entity.
TL;DR
From 1 July 2026 a trust and company service provider in Australia is a reporting entity if it provides any table 6 designated service with a geographical link to Australia. It must enrol with AUSTRAC within 28 days of starting, adopt an AML/CTF programme built on its own ML/TF risk assessment, complete initial customer due diligence on every client, its beneficial owners and the people acting for it before the service begins, apply enhanced customer due diligence where the law requires it, report suspicious matters within 3 business days, and keep records for seven years. Beneficial ownership of trusts and layered companies is where the workload sits, and it is the part worth automating first.
What is a trust and company service provider under the AML/CTF Act?
The Act does not regulate professions. It regulates services, and it uses the term reporting entity for any business that provides one of them. That is why AUSTRAC's own guidance is titled professional designated services rather than lawyers or accountants: the same service is caught whether a law firm, an accounting practice, a corporate services company or a specialist trust administrator provides it.
A trust and company service provider, in the sense the Financial Action Task Force (FATF) uses, is a business that forms companies and trusts for clients, provides people to sit in their governing positions, or gives them an address. Australia had left these services outside the anti-money laundering regime since the original 2006 Act. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, assented to on 10 December 2024, closed that gap in Schedule 3, with obligations commencing on 1 July 2026. The wider reform, and the dates, are covered in our AUSTRAC tranche 2 guide; this article is about the obligations as they land on such a firm specifically.
The test is functional. A firm that provides one designated service, once, in the course of carrying on a business, is a reporting entity for that service, whatever else it does. A firm that provides none is not, whatever its professional title.
Which services make the provider a reporting entity?
Table 6 of subsection 6(5B) of the Act lists the professional designated services. AUSTRAC's professional designated services guidance summarises them as follows.
| Item | Designated service | Where the service typically arises |
|---|---|---|
| 1 | Assisting in the planning or execution of a transaction to sell, buy or transfer real estate | Property holding structures set up around a purchase |
| 2 | Assisting in the planning or execution of a transaction to sell, buy or transfer a body corporate or legal arrangement | Share sales, transfers of trusts and partnerships |
| 3 | Receiving, holding, controlling or managing a person's property to help in the planning or execution of a transaction | Client money and escrow arrangements |
| 4 | Assisting in organising, planning or executing a transaction for equity or debt financing of a body corporate or legal arrangement | Capital raises and shareholder loans for client entities |
| 5 | Selling or transferring a shelf company | The classic corporate services product |
| 6 | Assisting in the planning or execution of the creation or restructuring of a body corporate or legal arrangement | Company incorporations, trust deeds, restructures |
| 7 and 8 | Acting, or arranging for someone to act, on behalf of a person in particular positions in a body corporate or legal arrangement | Nominee directors, company secretaries, trustees, partners and nominee shareholders |
| 9 | Providing a registered office address or principal place of business address for a body corporate or legal arrangement | Registered office and virtual office services |
Two interpretive points from the guidance matter for scoping. First, assisting means active steps that directly advance the outcome; general advice that merely influences how a client proceeds is not caught. AUSTRAC's example is a financial adviser who recommends a trust and introduces a solicitor: the solicitor who drafts the deed provides the item 6 service, the adviser does not. Second, a service is only designated if it is provided to an external customer in the course of carrying on a business. A one-off service still counts, and a free service still counts if it furthers the business. Items 1 and 2 carve out transactions made pursuant to a court or tribunal order.
When did the obligations start, and how does a firm enrol?
Obligations for table 6 services commenced on 1 July 2026. Under AUSTRAC's enrolment overview, a business must apply to enrol no later than 28 days after the day it starts providing a designated service, through an AUSTRAC Online account, and is then placed on the Reporting Entities Roll. These firms enrol but do not register; registration is the additional step reserved for remitters and virtual asset service providers. Enrolment details must be updated within 14 days of a change, and an enrolled business must submit an annual compliance report for as long as it stays on the Roll.
The scale of the transition is now visible in AUSTRAC's own figures. Its enrolment table, updated to 17 September 2026, records the following new reporting entities by industry.
| Industry | Enrolments recorded by AUSTRAC |
|---|---|
| Real estate | 18,350 |
| Accounting and professional services | 13,780 |
| Lawyer | 6,580 |
| Conveyancer | 1,600 |
| Jewellers and dealers in precious metals and goods | 320 |
Trust and company services are spread across the accounting, professional services and legal rows rather than counted separately, which is itself a reminder that the regime attaches to the service, not the sign on the door. AUSTRAC has also begun issuing notices to businesses it believes should have enrolled and have not, so a firm that provides a table 6 service and is not on the Roll is already late rather than early.
What must the AML/CTF programme contain?
Schedule 1 of the 2024 Act rewrote the programme obligations for every reporting entity, not only the newly regulated. The firm must have an AML/CTF programme in two parts: a money laundering and terrorism financing (ML/TF) risk assessment that describes the risks the business actually faces, across its customer types, services, delivery channels and jurisdictions, and AML/CTF policies that set out how those risks are managed. AUSTRAC's guidance on initial and enhanced due diligence repeatedly points back to these policies: they must state which know your customer information the firm collects and verifies for each customer type, when it collects source of funds and wealth, when and how it applies enhanced measures, who is responsible, and how it handles tipping off.
The programme also needs a person accountable for it and oversight from the firm's governing body, and it has to be kept current as the business changes. The practical failure mode AUSTRAC describes across its guidance is the template: a risk assessment that could describe any firm in the country reads, to a supervisor, as evidence that no assessment was done. For a firm in this sector the assessment has to say something specific about complex structures, offshore clients, nominee arrangements and trusts, because those are the features that make the sector high risk in AUSTRAC's National Money Laundering Risk Assessment.
What does initial customer due diligence require for companies and trusts?
Initial customer due diligence (CDD) must be complete before a designated service starts, subject to narrow delayed-CDD exceptions. Under AUSTRAC's initial CDD overview, the firm must establish the following matters on reasonable grounds:
- the identity of the customer
- the identity of any person on whose behalf the customer receives the service, such as the beneficiaries of a trust
- the identity of any person acting on behalf of the customer, and their authority to act
- where the customer is not an individual, the identity of its beneficial owners
- whether any of those people is a politically exposed person or designated for targeted financial sanctions
- the nature and purpose of the business relationship
- source of funds and source of wealth for foreign PEPs and, where enhanced CDD applies, for the customer.
Reasonable grounds is an objective standard: a reasonable person with the same material would reach the same conclusion, and the firm must record how each matter was established. The information collected must be appropriate to the customer's ML/TF risk, and at least one piece of KYC information for each matter must be verified against reliable and independent data.
For a company customer that means the entity's identity, its directors and its beneficial owners. For a trust, AUSTRAC's initial CDD guide for trusts sets out the fuller list: the trust's name, kind, business names and identifier, its principal place of operation, evidence of its existence (the deed, will or letters of administration), the powers that govern it, and the individuals responsible for its governance, which for most trusts means all trustees, appointors, guardians and protectors, and for a corporate trustee, the individuals on its board. Beneficiaries, or each class of beneficiaries where they cannot be named, must be identified as the people on whose behalf the trust receives the service.
The trust deed and its variations are the primary verification source, with the Australian Business Register for the ABN and letters from an independent professional adviser as alternatives. AUSTRAC also notes that trusts rated high risk nationally are not automatically high-risk customers; the firm still has to rate each one on its own circumstances.
When must the firm apply enhanced customer due diligence?
Enhanced customer due diligence (ECDD) is mandatory, not discretionary, in the circumstances AUSTRAC's enhanced CDD guidance lists:
- the customer's ML/TF risk is high, whether identified at onboarding or later
- the firm is required to submit a suspicious matter report about the customer and intends to keep providing the service
- the requested service involves transactions that are unusually complex or large, have no apparent economic or legal purpose, or form an unusual pattern
- the service is part of a nested services relationship
- the customer, a beneficial owner, a person acting for the customer or a person on whose behalf the service is received is a foreign politically exposed person
- any of those people is located or formed in a jurisdiction the FATF has called for enhanced CDD to be applied to.
The measures have to be targeted to the reason the risk is high: more KYC information, source of funds and wealth for the customer or beneficial owner, the reason for particular transactions, closer monitoring, more frequent reviews, and escalation to senior management. AUSTRAC is explicit that enhanced CDD means active steps to manage the risk, including declining the service, not only extra monitoring. For such a firm, a layered structure with an offshore owner in a listed jurisdiction hits two of these triggers at once, and the file has to show that the firm noticed.
How do you identify the beneficial owners of a trust or a company?
A beneficial owner is an individual who directly or indirectly owns 25 percent or more of the customer, or who otherwise controls it. A customer may have several, and AUSTRAC accepts that some customers have none, in which case the file must say why and identify who does control the entity.
The work is in the chain. AUSTRAC's own example is a trust controlled by a company: if the company's owner is an individual, identify them; if it is another entity, keep following the chain until the individuals who ultimately own or control the customer are reached. Indirect holdings multiply along each link, so a person holding half of a company that owns 60 percent of the customer holds 30 percent and is a beneficial owner. Nominee shareholders are looked through, corporate trustees are unwrapped to their own beneficial owners, and settlors, appointors, guardians and protectors are identified because they control the trust without owning it. A customer-supplied ownership chart is a starting point, never the evidence.
This is the seam the whole sector prices as bespoke. Standard verification products stop at the first corporate shareholder; the clients of firms in this sector rarely do. Our guides on what a KYB check involves and ultimate beneficial owners cover the mechanics, and the companion piece on beneficial ownership through multi-layer trusts with offshore owners works a four-layer example step by step.
What must be reported to AUSTRAC, and by when?
Three reporting duties apply. Under AUSTRAC's suspicious matter report guidance, a suspicious matter report (SMR) is due within 3 business days after the day a suspicion is formed on reasonable grounds, or within 24 hours where the suspicion relates to terrorism financing, and within 5 business days where legal professional privilege is claimed over part of the information. The obligation applies even where the firm declines to provide the service, and a new SMR is due each time a new suspicion forms. A threshold transaction report is due within 10 business days where a designated service involves physical currency of 10,000 dollars or more. And every enrolled business files an annual compliance report.
The tipping off offence, rewritten in Schedule 5 of the 2024 Act, governs what may be said to a client once a report is made or contemplated. It is the rule firms new to the regime break most naturally, by explaining to a client why a matter has stalled. Staff who talk to clients need to know it before they need it.
What records must be kept, and for how long?
Records must show how each initial CDD matter was established on reasonable grounds, what enhanced measures were applied and why, what was reported, and the programme itself, and they must be retained for seven years. AUSTRAC's trust guidance makes a point that matters for the operating model: a firm is not required to keep copies of identity documents and can instead record their details. That is the difference between a compliance file and a database of clients' passports, and it is worth designing for from the start rather than discovering after a breach notification.
How does a small firm run this without a compliance team?
The obligations above are the same for a two-partner practice and a national firm, and the fixed costs of verification, screening and record keeping do not scale down. The way a small firm carries them is to automate the parts that are mechanical and keep judgment for the decisions the Act reserves to the firm.
Zyphe's KYB software runs the entity and ownership layers: when a client submits, the authoritative register record is purchased live from the relevant register and the submission is graded against it, across more than 240 registries in three published latency tiers. Ownership discovery then follows corporate shareholders through every available tier until it reaches natural persons, bounded by a credit budget the firm sets. Branches the budget cuts stay visible as truncated; a branch that reaches a jurisdiction with no register coverage stays visible as unresolved and is held as a proxy, never reported as a person; where discovery cannot complete, the client is asked to declare the owners and the declaration is marked as declared. That is the evidence trail AUSTRAC's reasonable grounds standard asks for, including for the cases where the answer is that a person could not be found.
Each beneficial owner, trustee and director then receives a linked KYC flow, and the business verification cannot be approved until it completes; sanctions, PEP and adverse media screening runs on the entity and on every person found. Where the file needs a human decision on enhanced due diligence, the UBO and EDD review desk assembles the ownership trace, the screening results and a draft rationale, and the firm's own responsible person approves it, which is where the Act puts the decision.
On the question Australian buyers ask first, where the documents go, the position is in writing on the security and data handling page: identity documents and biometrics are processed transiently and stored encrypted in the individual's own vault, and Zyphe retains the verification results, audit logs and proofs. For a firm whose regulator has just told it that copies of documents need not be kept, that is the model that matches the rule.
The bottom line
Tranche 2 turned the corporate services firm from an unregulated professional into a reporting entity with the same categories of obligation as a bank: enrol, assess, programme, verify, escalate, report, retain. Enrolment was the visible deadline and the small part. The work that decides whether a supervisory review goes well is beneficial ownership on layered structures, evidenced on reasonable grounds and documented where it could not be finished, and that is precisely the work that automation with an honest edge does better than a spreadsheet and a shared drive of passport scans.
This article is general information, not legal advice. Obligations depend on the services a business provides, and firms should take advice on their own circumstances.
Related resources
- AUSTRAC tranche 2: enrolment, obligations and deadlines
- Beneficial ownership verification for multi-layer trusts with offshore owners
- What is KYB (Know Your Business)?
- Ultimate beneficial owner (UBO)
- Enhanced due diligence: when and how to apply it
- KYB software
- KYC software
- UBO and EDD review desk
- Security and data handling
Cited sources
- Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (No. 110, 2024), Federal Register of Legislation
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006, Federal Register of Legislation
- AUSTRAC, Professional designated services
- AUSTRAC, Enrol with us overview
- AUSTRAC, Overview of initial customer due diligence
- AUSTRAC, Initial CDD for trust
- AUSTRAC, Enhanced customer due diligence
- AUSTRAC, Suspicious matter reports
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.