AML/CTF Ongoing Monitoring for Accounting Firms

Australian accounting firms must monitor existing clients on an ongoing basis under Tranche 2. Here's what the obligation requires and how to meet it.
Australian accounting firms covered by the Tranche 2 reforms to the AML/CTF Act 2006 must monitor existing client relationships on an ongoing basis — not just verify identity at intake. Ongoing monitoring is a mandatory obligation, and AUSTRAC has signalled it will assess compliance with it as part of Tranche 2 supervision from 1 July 2026.
What does ongoing monitoring mean under the AML/CTF Act 2006?
Ongoing monitoring covers two distinct obligations. First, transaction monitoring: scrutinising the transactions clients conduct through your designated services to detect activity inconsistent with your understanding of them. Second, CDD currency: periodically reviewing and updating the customer due diligence information you hold — particularly beneficial ownership records, business profile, and risk rating. Both obligations run for the life of the client relationship, not just at onboarding.
Which accounting services does ongoing monitoring apply to?
The obligation applies to clients receiving a designated accounting service under Tranche 2: - Managing client funds — receiving, holding, or disbursing money on a client's behalf - Company and trust formation — acting as registered agent, nominee, or company secretary - Real property transactions — participating in the financial aspects of a purchase or sale - Business acquisitions — acting in the transfer of assets or funds Tax return preparation and general business advice are not designated services, so those clients do not require ongoing monitoring.
How often do you need to update client CDD records?
There is no fixed re-verification timetable — the obligation is risk-based. Your AML/CTF programme (Part B) must set the schedule and define the trigger events, which typically include: - A risk-rated review cycle — for example, high-risk clients reviewed annually, medium-risk every two years - Trigger events: a change in ownership or control, a request to start a new designated service, or the client appearing on a PEP or sanctions list - Unexpected transactions inconsistent with the client's known business profile For Australian SME clients structured through discretionary trusts with corporate trustees, beneficial ownership records should be re-confirmed whenever the trustee or beneficiary structure changes.
What activity should accountants monitor for?
Red flags relevant to accounting relationships include: - Irregular or unexplained flows through managed client accounts - Requests to manage transactions with no clear business purpose or legitimate rationale - Frequent entity formation or restructuring without a clear commercial explanation - Source of funds inconsistent with the client's known income or business profile - Reluctance to provide updated CDD documentation when a periodic review falls due If monitoring identifies activity giving rise to a reasonable suspicion of money laundering or terrorism financing, you must lodge a Suspicious Matter Report (SMR) with AUSTRAC as soon as practicable. See the SMR guide for accountants for the filing process.
How does AMLify support ongoing monitoring for accountants?
AMLify automates the obligations that are hardest to maintain manually. The platform schedules periodic CDD review reminders based on each client's risk rating, flags trigger events that require an out-of-cycle review, and stores review history and updated records against each client to give you an auditable trail for AUSTRAC. Now that Tranche 2 has commenced, ongoing monitoring is one of the easiest obligations to overlook in the push to complete enrolment. See AMLify for accountants or start a free trial.
Key Takeaways
- Ongoing monitoring is mandatory — it applies throughout the client relationship, not just at onboarding
- Two obligations: transaction monitoring for unusual activity, and periodic CDD review to keep identification and beneficial ownership records current
- Risk-based frequency: your programme sets the review schedule; higher-risk clients are reviewed more often
- Trigger events — ownership changes, new designated services, or unexpected activity — require an immediate CDD review regardless of schedule
- SMRs are required when monitoring identifies a reasonable suspicion of money laundering or terrorism financing
Frequently Asked Questions
Q: Does ongoing monitoring apply to all accounting clients?
No. Only clients for whom your firm provides a designated service under Tranche 2 — such as managing client funds, company or trust formation, or real property transactions — require ongoing monitoring. Tax advice and general advisory services are not designated services and do not trigger the obligation.
Q: What triggers a mid-cycle CDD review?
A change in the client's ownership or control structure, a request to engage in a new designated service, the client appearing on a PEP or sanctions list, or any transaction that is inconsistent with your understanding of their business. Your Part B programme should specify these triggers so your team knows when to act.
Q: What are the penalties for failing to monitor ongoing client relationships?
AUSTRAC can impose civil penalties on reporting entities that fail to meet ongoing monitoring obligations. Penalties can be significant and accrue per contravention. Evidence of a functioning monitoring process — documented review records, updated CDD files, and any SMRs lodged — is your best protection if your firm is subject to AUSTRAC supervision.
This is general information only and not a substitute for legal advice.