On 1 July 2026, Australia’s anti-money laundering laws expanded. Thousands of businesses that previously had no AML/CTF obligations now do — specifically accountants, lawyers, conveyancers, real estate agents, and dealers in precious metals and stones.
If your business falls into one of those categories, you’ve likely already started thinking about your AML/CTF program: the policies, the risk assessments, the enrolment with AUSTRAC. What most businesses haven’t thought through yet is the technology that program actually requires to work.
That’s what this post covers.
What the Reforms Actually Require (From an IT Perspective)
Under the new laws, newly regulated businesses need to:
- Maintain a written AML/CTF program
- Conduct and document customer due diligence (CDD) — collecting and verifying client identity information
- Keep records of CDD and transactions for a minimum of 7 years
- Report suspicious matters and threshold transactions to AUSTRAC
- Conduct and document ongoing customer due diligence
- Train staff and document that training
Each of these has an IT component that people don’t initially think about. Let’s go through them.
The IT Problems Hidden in Your AML/CTF Obligations
1. Record-keeping for 7 years
You need to retain client identity records, CDD documents, and transaction records for a minimum of seven years. That means:
- A documented, reliable place to store those records
- Backups that are tested and proven to work
- A system that doesn’t rely on one person’s hard drive or local PC
- Retention policies that prevent accidental deletion
If your document storage is a mix of shared network drives, email attachments, and individual desktops, you have a compliance gap right now.
2. Access controls on sensitive client data
Your CDD records contain highly sensitive information — identity documents, financial records, beneficial ownership details. The AML/CTF framework assumes this data is protected. In practice, that means:
- Only authorised staff can access relevant client records
- There’s an audit trail showing who accessed what and when
- Former employees no longer have access after they leave
- Your systems don’t leave sensitive data exposed via shared logins or uncontrolled file sharing
Microsoft 365 with properly configured SharePoint and access controls handles most of this — but “properly configured” is the key phrase. Default M365 setups often have overly permissive sharing settings and no meaningful audit logging turned on.
3. Cybersecurity for compliance data
AUSTRAC’s program requirements specifically mention protecting client information. A breach of your CDD records isn’t just a privacy incident — it’s a compliance failure. This means your cybersecurity posture matters more now than it did six months ago:
- Multi-factor authentication on all accounts that can access client records
- Email security to prevent phishing attacks that could expose client data
- Endpoint protection on every device used to access compliance systems
- A documented incident response plan (what happens if you’re breached?)
Most small professional services firms have basic antivirus. Few have the full stack.
4. Disaster recovery for compliance records
If your records are destroyed — through ransomware, hardware failure, or flood — and you can’t produce them when AUSTRAC asks, that’s a problem that goes beyond lost data. You need:
- Offsite backups that aren’t connected to the same systems as your primary data
- A tested recovery process (not just “we have backups” — but “we’ve verified we can restore them”)
- A recovery time that keeps you operational during an AUSTRAC review
5. Staff training records
You need to document AML/CTF training for your staff and keep those records. This is simple to do if you have a centralised system — and a pain if you don’t. At minimum, you need a reliable place to store training completion records that won’t disappear when someone leaves.
What “Compliant IT” Actually Looks Like
You don’t need a purpose-built compliance platform. For most small professional services firms, the right IT stack for AML/CTF support looks like this:
- Microsoft 365 Business Premium — includes SharePoint for document management, proper retention policies, audit logging, and Azure AD for access control
- Properly configured SharePoint — with site-level permissions, not “share with everyone” defaults
- MFA on all accounts — non-negotiable for any system touching client data
- Tested, offsite backup — separate from M365, recoverable, with a documented RTO
- Email security — Microsoft Defender or equivalent, configured (not just licensed)
- Documented offboarding process — so former staff are removed from all systems promptly
None of this is exotic. But most small firms either don’t have it fully configured, or have it partially set up with gaps that an AML/CTF review would surface.
Is Your IT Ready?
Here’s a quick self-check. If you answer no to any of these, you have a gap worth addressing:
- Do all staff use MFA on every account that touches client data?
- Are your client identity records stored in a centralised, access-controlled location?
- Do you have a tested backup that could restore 7 years of records if your primary system failed?
- Do you have an audit log showing who accessed sensitive client records?
- When a staff member leaves, is there a documented process to remove their access within 24 hours?
Not Sure Where Your IT Stands?
We do IT assessments for Brisbane businesses as part of our managed IT onboarding. It’s a straightforward review of your environment against a practical standard — including the kind of security and record-keeping setup that AML/CTF compliance assumes you have.
Book a CallThe Bigger Picture
The AUSTRAC reforms are getting a lot of attention for the compliance obligations they create. Less discussed is that they’re also quietly raising the IT baseline for an entire sector of Australian small businesses.
If you’re an accountant, lawyer, or conveyancer in Brisbane who’s been putting off a proper IT review — the new compliance environment is a reasonable prompt to do it now. Not because AUSTRAC will audit your IT directly, but because the record-keeping, security, and access control requirements assume a level of IT hygiene that a lot of small professional firms don’t currently have.
Getting that sorted is good compliance practice. It’s also just good IT.
Questions about your specific IT setup? See what managed IT from Connected Platforms covers, or book a call to talk through your situation.


