AML/CTF Compliance for fund managers: What the 2026 reforms mean for you
- Thomas Worden
- 13-Aug-2026
- 8 min read
Fund managers were already subject to AML/CTF requirements, but the 2026 reforms extended and sharpened them. Here, we break this down to help you understand these obligations.

Changes to Australia's anti-money laundering and counter-terrorism financing (AML/CTF) regime took effect in March and July 2026. In this article, we cover how the reforms affect fund managers in Australia.
If you already run a fund, most of this will be familiar in outline but perhaps new in detail – you were a reporting entity before, and you still are, but the framework underneath has been rebuilt. If you're weighing up your first fund, this is the compliance backdrop you're stepping into. Either way, we hope you find this article helpful.
Why did the AML/CTF laws change in 2026?
The reforms aim to close avenues to organised crime by closing regulatory gaps, tightening obligations and expanding the regime's scope.
For nearly two decades, Australia's AML/CTF regime covered banks, financial institutions, casinos and a handful of other sectors, but left large parts of the economy, including lawyers, accountants and real estate, outside it.
The reforms (contained in the 2024 Amendment Act) aim to close those gaps, and also simplify and modernise the regime, and align it with international standards set by the Financial Action Task Force – the global financial crime watchdog and standard-setter.
Much of the operative detail sits not in the Act but in the AML/CTF Rules 2025, finalised in August 2025, and in AUSTRAC's guidance, which continues to develop. Transitional rules soften the landing in one specific respect, covered in the customer due diligence section below. They do not defer the program obligations.
What have the AML/CTF reforms changed for fund managers?
Fund managers were already subject to AML/CTF requirements. Overall, the 2026 reforms have extended and sharpened your requirements.
At a glance, the reforms affect fund managers by:
- Affecting service providers that many fund managers work with
- Replacing the old two-part program with a single risk-based AML/CTF program, and setting out who must own it
- Changing the substance and legal force of initial and ongoing investor due diligence
Each of these is covered in more detail below.
What you need to know about service providers
From 1 July 2026, the AML/CTF regime has extended to include service providers and others not previously covered. This includes lawyers, conveyancers, accountants, real estate agents, property developers, trust and company service providers, and dealers in precious metals and stones.
As a fund manager, you’re likely working with at least some of these service providers so it’s important to be aware of this and consider:
- Asking them about their AML/CTF policy to understand their compliance approach
- Including AML/CTF clauses in contracts with suppliers if you don’t already
- In general, asking questions if you’re not sure, rather than assuming compliance is covered
Why you need a risk-based AML/CTF program and someone overseeing it
The reforms aim to simplify AML/CTF obligations by shifting from the old Part A/Part B structure to a risk-based approach. They require you to develop an AML/CTF program, built around your actual risk, and maintain and comply with it.
The program needs to include:
- A risk assessment covering money laundering, terrorism financing and proliferation financing (PF) risk – the reforms treat the three together. You can only skip a dedicated PF policy if you have assessed the risk as immaterial and recorded that assessment in the program.
- AML/CTF policies – the procedures, systems and controls you’ll use to manage and mitigate the risks identified in step 1.
The program must be documented in writing and in place before you provide designated services. If you were already operating, it needed to be updated to meet the new requirements by 31 March 2026.
Who owns it is where the reforms are most demanding, and it is not one person. The regime sets out three distinct roles:
- The governing body – your board, or the equivalent for your structure – approves the program and oversees its implementation. This is a real accountability shift. For a fund with a corporate trustee, that responsibility sits with the trustee's directors, not with whoever administers compliance day to day.
- A senior manager, with defined responsibilities for the program.
- An AML/CTF compliance officer, appointed to oversee the program in practice.
You also need to review and update the program as your fund changes, and arrange a regular independent evaluation of it. The independent evaluation is a standing obligation, not a one-off implementation exercise.
The reforms are designed to prevent generic risk templates, token actions or policies, and vague accountability.
How has customer due diligence (CDD) changed?
The requirement to identify and verify an investor before you provide a service is not new. Under the previous regime, you already had to complete the applicable customer identification procedure before providing a designated service.
What has changed is the substance of that obligation, and its legal force.
The old prescriptive procedure has been replaced with an outcomes-based initial customer due diligence (CDD) obligation. Before you issue an interest to an investor, you need to establish on reasonable grounds who the investor is, who any beneficial owners are, whether anyone involved is a politically exposed person (PEP) or subject to sanctions, and the nature and purpose of the relationship, and you need to assess the ML/TF (money laundering/terrorism financing) risk that serving them presents.
The other change is enforcement. These requirements have moved out of the Rules and into the Act itself, and they now carry direct civil penalty provisions. Failing to verify before providing a service, failing to screen for PEP and sanctions risk, failing to assess customer risk, and failing to keep records of what you did are each independently exposed.
In practice, that means understanding each investor's risk before they're in, not after. This reform also leans on a risk-based approach with an expectation that checks should be adapted to investor risk profiles.
In addition, fund managers have an ongoing CDD obligation to keep customer information current and to monitor the relationship over its life. That means reviewing and refreshing information, watching for changes in circumstances or risk, and acting when something shifts, whether that's an investor becoming a PEP, a change in their structure, or activity that doesn't fit the picture held at onboarding. A fund with no scheduled review process is very likely operating outside the rules, however clean its original onboarding was.
Ongoing CDD obligations are applied to all customers from 31 March 2026. There is no grace period here. Initial CDD on pre-existing customers has a three-year transitional window running to 30 March 2029.
A closer look at PEPs, beneficial owners and entity investors
A few investor types deserve specific attention, because they’re often where due diligence and onboarding can go wrong.
Politically exposed persons (PEPs). A PEP is someone who holds, or is close to someone who holds, a prominent public position, and their involvement calls for extra scrutiny. Where an investor, a beneficial owner or someone acting on their behalf is a foreign PEP, or a higher-risk domestic one, you need senior sign-off to proceed and you need to establish their source of funds and source of wealth before providing the service. PEP status can also arise after onboarding so it's something to keep monitoring, not a one-off check.
Beneficial owners. For any investor that isn't an individual, you need to look through to the people who ultimately own or control it, generally those holding 25% or more. However, someone who has the power to direct the entity's decisions or replace decision makers is also seen as a beneficial owner. A company owned by another company owned by a trust has to be traced through each layer.
Trusts and entity investors. Trusts are the most involved for investor due diligence because the trustee’s identity needs to be verified, along with the appointor, and details of beneficiaries or classes of beneficiaries. Where an investment manager subscribes on behalf of an underlying fund, both the manager and the fund may need to be identified.
Where an investor is low risk, simplified CDD may be available – for instance where the investor is controlled by a licensed or regulated entity such as an AFSL holder or an APRA-regulated body, you might not need to trace beneficial ownership. However, simplified is not the same as skipped: you still need to have assessed and documented the low-risk conclusion, and to follow your own policies.
What technology and outsourcing can and can't do
Most fund managers don't run this themselves, end to end. They use a platform, an administrator or a combination of service providers, and the reforms explicitly allow you to rely on a third party's customer due diligence under a written agreement.
This is worth highlighting because it outsources the work but not the liability which is why the arrangement must be in writing, the third party needs to be assessed as having appropriate measures to meet AML/CTF obligations, the provider and the arrangement needs to be assessed at least every two years and you must be able to obtain the underlying information when requested. If an assessment leaves you unsatisfied that the arrangement complies, you must conduct your own initial CDD.
Generally, the fund manager will remain legally liable for any breach of your fund’s AML/CTF obligations, even under outsourcing arrangements, so you want to make sure you’re working with trusted providers experienced in AML/CTF compliance and can verify they are doing what the agreement says.
A note on the wider reforms
The 2026 reforms also require fund managers to keep AML/CTF records for seven years after they cease to be relevant, in a form you can produce if audited. They also grant AUSTRAC more authority to enforce compliance. This could involve more frequent assessments and investigations, making it clear that being audit-ready, and working with providers who are, is crucial.
There are other changes too, though they’re less relevant for a typical venture or private capital fund. This includes the introduction of a "travel rule" requiring certain information to accompany transfers of money, virtual assets or property, aimed mainly at banks, remitters and virtual asset service providers.
Where to start
If you're already operating a fund, a useful question is whether your current setup adheres to the AML/CTF reforms. If you’re launching, it’s good to understand that AML/CTF compliance isn’t just an essential cost of running a fund in Australia, it also signals that you’re serious.
Regardless, AUSTRAC has made its expectations clear, including that it expects essentials to be in place and ongoing efforts to be clear. That includes being able to show your workings and produce a file on request without a due diligence scramble, which coincidentally is also the impression you want to provide an LP.
This article is general information about Australia's AML/CTF reforms, current as at 13 August 2026. AUSTRAC guidance and the transitional rules continue to develop, so please check the current position before relying on anything here. It isn't legal advice, and your obligations depend on the designated services you provide and your ML/TF risk assessment.
Frequently asked questions
Do I need an AFSL to run a fund in Australia?
Not necessarily your own. Issuing interests in a fund is a regulated activity, but you can operate under a licensed trustee and an authorised representative arrangement instead. Ventari appoints a professional trustee under an AFSL, so fund managers and syndicate leads aren't taking on the licensed role themselves.
Do my investors need to be wholesale or sophisticated investors?
Yes. Investors must hold a current sophisticated or professional investor certificate issued within the last two years. This is usually from a qualified accountant confirming gross income of $250,000 or more in each of the previous two years, or net assets of at least $2.5 million. Investors on our platform meet these requirements.
Does wholesale investor status replace AML/KYC?
No. Wholesale status is a Corporations Act question about who can receive the offer. AML/CTF verification establishes investor identity, beneficial ownership and sanctions and PEP status before you provide the service. It’s possible for an investor to meet wholesale or sophisticated investor requirements but still fail your customer due diligence.
Can I accept a subscription while KYC is still outstanding?
No. Initial customer due diligence has to be complete before you issue an interest. A narrow delayed pathway exists in limited circumstances, but even then you can't make funds available to the investor until verification is done.
Who handles investor KYC and verification on Ventari?
We do. Identity verification, entity checks and wholesale status are handled by the platform rather than left with fund managers or syndicate leads. The legal obligation still sits with the reporting entity though, which is why the process is documented and auditable.
Does using a fund administration platform remove my AML/CTF liability?
No. Using a platform means you’re outsourcing the work but not the liability. Fund managers remain legally liable for any breach of a fund’s AML/CTF obligations, even under outsourcing arrangements, so you want to make sure you’re working with trusted providers experienced in AML/CTF compliance who make it easy for you to be audit ready.
Come see what we’re about
Thinking about launching or moving a fund or syndicate? Book a demo and we'll show you what running one on Ventari actually looks like, including the parts most platforms gloss over.