Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

Reporting suspicious transactions to Australia’s financial intelligence unit

Suspicious transaction reporting is a core part of an effective anti-money laundering and counter-terrorism financing program. In Australia, businesses that provide designated services must assess unusual activity, decide whether it creates a reasonable basis for suspicion, and submit a suspicious matter report (SMR) to AUSTRAC when the legal threshold is met.

A report is most useful when it gives investigators a clear account of who was involved, what happened, when it occurred, and why it appears unusual. Good reporting is not about proving that a customer has committed an offence. It is about preserving relevant information, identifying meaningful risk indicators, and passing reliable intelligence to Australia’s financial intelligence unit without alerting the customer.

Know when an SMR is required

Australian reporting entities must submit an SMR when they have reasonable grounds to suspect that a person is involved in conduct connected with an offence, money laundering, terrorism financing, or proceeds of crime. The suspicion may relate to a transaction, attempted transaction, account activity, or a broader pattern involving the customer. A completed payment is not required before a report can be made.

The suspicion should be based on facts, context, and information reasonably available to the business. A customer making several cash deposits, using multiple unrelated accounts, or sending funds to a high-risk jurisdiction may have an innocent explanation. Those indicators become more significant when they conflict with the customer’s stated business, expected turnover, source of wealth, or previous conduct.

Timing matters. A suspicious matter connected with terrorism financing must generally be reported to AUSTRAC within 24 hours after the reporting entity forms the suspicion. Other suspicious matters generally need to be reported within three business days. Internal approval processes should be designed around these deadlines rather than allowing a case to sit indefinitely with a manager or compliance committee.

Build a fact-based assessment process

Front-line staff are often the first people to notice a problem. Tellers, customer service teams, relationship managers, gaming staff, property professionals, accountants, and payments specialists may observe behaviour that does not appear in a transaction-monitoring alert. Training should help them distinguish an unusual event from a genuinely suspicious pattern and escalate concerns without making accusations.

A useful internal assessment records the customer’s identity, occupation or business activity, expected account use, relevant transactions, counterparties, jurisdictions, payment channels, and the reason the activity is inconsistent or concerning. It should also capture the source of the information, the dates reviewed, and any explanation obtained from the customer. Clear notes are particularly important when a decision is made not to submit an SMR.

Avoid relying on vague labels such as “high risk” or “looks dodgy”. A stronger analysis might state that a newly incorporated company with no visible trading history received multiple payments from unrelated overseas entities, quickly converted the funds into cryptocurrency, and could not explain the commercial purpose. Specific observations allow AUSTRAC and internal reviewers to understand the reasoning behind the suspicion.

Give AUSTRAC useful intelligence

An SMR should be written for an investigator who may know nothing about the customer. Start with a concise summary of the concern, then explain the customer’s profile, the relevant activity, the parties involved, and the indicators that led to the suspicion. Include account numbers, transaction dates, amounts, currencies, payment methods, business names, addresses, and identification details where available.

The narrative should distinguish confirmed facts from assumptions. If the customer claims that a payment is for an import contract, state that it was described in that way and explain whether supporting documents were supplied or verified. If the business has identified links to a known associate, shell company, sanctioned party, or previous internal alert, explain the connection and the source of the information.

Do not bury the central issue beneath a long export of raw transactions. Attach or retain supporting records according to the business’s procedures, but use the narrative to identify the most relevant transactions and explain their significance. A concise timeline can help show how funds moved between accounts, businesses, countries, or individuals.

Manage customer contact and tipping-off risk

Australian law restricts disclosure of information that could reveal that an SMR has been submitted or that AUSTRAC is investigating a matter. Staff should not tell a customer, supplier, agent, or unauthorised colleague that a report has been made. They should also avoid language that indirectly signals a report, such as saying that “AUSTRAC needs to know about this” or that an account is being restricted because of a suspicious transaction report.

Customer communication may still be necessary. A business can request ordinary identification, source-of-funds evidence, or an explanation of a payment when those steps are part of its normal compliance process. The wording should remain neutral and consistent with the organisation’s procedures. Staff who are unsure should escalate to the money laundering reporting officer or another authorised decision-maker before contacting the customer.

Access to SMR records should be limited to people who need the information for compliance, legal, risk, or investigative purposes. Keep a clear audit trail of who reviewed the case and why. Retention controls also matter: AML/CTF records generally need to be kept for at least seven years, subject to the applicable record category and legal requirements.

Connect reporting with wider business risks

Suspicious activity can arise outside a bank branch or payment platform. Australian businesses operating through franchisees, agents, dealers, and distributors may encounter unexplained rebates, inflated invoices, third-party payments, or cash-intensive sales. A practical approach to franchise and distributor networks can help connect anti-corruption controls with AML/CTF monitoring and escalation.

A Sydney wholesaler may see an unusual payment from a company in Southeast Asia, while a Perth resources supplier may receive funds linked to a contractor that has no apparent role in the project. In Melbourne’s property market, rapid transfers through several entities may require closer attention to beneficial ownership and the commercial purpose of a purchase. The location alone does not establish suspicion, but local industry context can make an activity more or less plausible.

Businesses should map how alerts travel through the organisation. A franchisee may notify a head office compliance team, which then needs enough information to assess the conduct and meet the reporting deadline. Contracts, training, audit rights, and escalation channels should make that path clear. Where third parties handle payments or customer onboarding, the principal should understand what information can be accessed quickly when an SMR decision is required.

Use technology without outsourcing judgement

Transaction-monitoring systems can identify unusual velocity, geographic exposure, structuring, rapid movement of funds, dormant-account activity, and links between customers. Rules should be calibrated to the organisation’s products and customer base. A threshold designed for a large bank may generate unhelpful noise in a small remittance business, while a rule that is too broad may miss activity concealed through several low-value payments.

Automated alerts still need human review. A system may flag a series of deposits below a reporting threshold, but an analyst must consider whether the customer’s occupation, location, cash exposure, and account history make the pattern credible. In Australia, a regional business may have legitimate cash flows that look unusual in a metropolitan dataset; conversely, a sophisticated laundering arrangement may be structured to appear ordinary.

Technology governance should include testing, scenario reviews, quality assurance, and documented changes to detection rules. Businesses should examine false positives, missed cases, processing delays, and the quality of information passed into an SMR. Analysts also need training on data limitations, including duplicate customer records, incomplete beneficial ownership information, transliteration differences, and outdated risk ratings.

Protect reporters and strengthen governance

Employees need a safe way to raise concerns before a formal SMR assessment begins. A confidential reporting channel can help staff report pressure to ignore unusual activity, suspected bribery, false invoices, or interference with customer due diligence. Policies should explain who receives reports, how confidentiality is protected, and when information may need to be shared for legal or regulatory reasons. Guidance on anonymous hotline design is relevant when building these safeguards.

A whistleblower process does not replace the AML/CTF escalation route. The compliance team must be able to triage a report, preserve evidence, protect the reporter from retaliation, and decide whether the underlying conduct requires an SMR or another regulatory notification. In smaller Australian businesses, the same person may perform several roles, so conflicts of interest and access controls should be addressed explicitly.

Senior management should receive useful aggregate information without being given unnecessary details about individual SMRs. Board or executive reporting might cover volumes, turnaround times, high-risk products, overdue reviews, law-enforcement requests, and recurring weaknesses. It should also show whether staff are escalating concerns consistently across branches, states, and distribution channels.

The strongest programs treat suspicious matter reporting as an intelligence discipline rather than a paperwork exercise. Clear deadlines, specific narratives, careful customer communication, reliable records, and protected escalation channels allow a business to meet its Australian obligations while contributing information that AUSTRAC can use.

The key point to remember is simple: report the facts that create the suspicion, explain the context that gives those facts meaning, meet the deadline, and never disclose the report to the person involved.

copyright © Global Advice Network