AUSTRAC Annual Compliance Reports: A Guide for TCSPs

TCSPs enrolled with AUSTRAC must lodge an annual AML/CTF compliance report confirming their programme is current. Here's what it covers and when it's due.
Trust and company service providers enrolled with AUSTRAC must lodge an annual AML/CTF compliance report confirming their programme is in place and operating -- the first report is due within the window AUSTRAC specifies, and missing it is a standalone breach separate from having a weak programme.
What Is an AML/CTF Compliance Report?
The annual compliance report is a formal declaration lodged through AUSTRAC Online, confirming a TCSP's AML/CTF programme was in place and operating throughout the reporting period. It isn't a full audit -- it's an attestation, usually completed by the AML/CTF Compliance Officer (AMLCO) or a principal, covering enrolment status, risk assessment currency, training completion, and whether any suspicious matters were reported.
When Does a TCSP Lodge Its First Report?
AUSTRAC sets the reporting period and lodgement window for each entity and notifies enrolled TCSPs directly through AUSTRAC Online -- don't assume a fixed calendar date without checking your own portal notice. For most TCSPs enrolled around the 1 July 2026 deadline, the first period runs to the following 30 June, with lodgement due shortly after. Treat the AUSTRAC Online notification as authoritative and calendar it the moment it appears.
What Does the Report Actually Cover?
- Confirmation of enrolment details -- entity name, ABN, and designated services (formation, registered office, nominee director or shareholder services) remain accurate.
- Risk assessment status -- whether the ML/TF risk assessment has been reviewed or updated in the period.
- Programme currency -- confirmation the AML/CTF programme reflects how the TCSP actually operates, including nominee and beneficial ownership arrangements.
- Training completion -- whether relevant staff completed AML/CTF training in the period.
- Reporting activity -- a summary of whether suspicious matter reports were lodged, without disclosing the substance of any individual report.
What Happens If a TCSP Misses the Deadline or Lodges Inaccurately?
A missed or false compliance report is a discrete civil penalty exposure under the AML/CTF Act 2006, independent of whatever AUSTRAC later finds during a supervisory review. A genuinely good programme isn't enough protection if the report itself is late or the declarations don't match reality -- particularly where nominee arrangements or layered ownership make the underlying programme harder to evidence. Treat the lodgement date like a tax deadline: fixed, calendared, and owned by a named person.
How Can TCSPs Prepare Before the Report Is Due?
Preparation is mostly about keeping evidence current rather than compiling it retrospectively. A TCSP that updates its risk assessment only when a report is due is already behind -- it should be a living document reviewed whenever the client base or structure mix changes materially. AMLify for trust and company service providers keeps risk assessments, beneficial ownership records, training logs, and SMR history in one place, so the evidence an annual report requires is already assembled.
Key Takeaways
- The annual compliance report is a formal attestation lodged through AUSTRAC Online, not a full audit submission
- AUSTRAC notifies each TCSP of its specific reporting period and lodgement window -- confirm this directly rather than assuming a fixed date
- The report covers enrolment accuracy, risk assessment currency, training completion, and reporting activity
- A late or inaccurate report is a standalone breach under the AML/CTF Act 2006, regardless of the underlying programme's quality
- AMLify keeps the evidence an annual report requires up to date year-round
Frequently Asked Questions
Q: Is the annual compliance report the same as the independent review for TCSPs?
No. The compliance report is an annual attestation confirming the programme is in place and operating. The independent review is a separate, periodic assessment (roughly every one to three years, calibrated to risk) of the programme's design and effectiveness, usually done by someone outside its day-to-day operation.
Q: Who is responsible for lodging the report at a TCSP?
Typically the AML/CTF Compliance Officer or a principal, since they're best placed to confirm the programme's operational status. The obligation ultimately sits with the reporting entity itself.
Q: What happens if our TCSP has had no suspicious matters to report?
That's recorded as a genuine outcome, not a red flag. AUSTRAC doesn't expect every TCSP to have lodged an SMR -- it expects an accurate account of what did or didn't occur during the period.
Q: Can a TCSP request an extension if it needs more time to prepare?
TCSPs should contact AUSTRAC directly through AUSTRAC Online well before the due date if they anticipate difficulty meeting it -- raising a timing issue proactively is treated far more favourably than lodging late without explanation.
This is general information only and not a substitute for legal advice.