Episode 11

full
Published on:

30th Jun 2026

Inside FATF: Australia’s role in the global taskforce fighting financial crime

Episode Summary:

The Financial Action Task Force, or FATF, may be the most important organisation Australian lawyers have never heard of. Its global standards underpin Australia’s AML/CTF Tranche 2 reforms, shaping how legal practices onboard clients, assess risk and help prevent financial crime. This episode explains why the regime exists, how Australia fell behind its global counterparts and the practical steps lawyers need to be taking as the reforms come into effect from 1 July 2026.

Guest:

Host:

Episode Overview:

The Financial Action Task Force, or FATF, is the global standard-setter behind anti-money laundering and counter-terrorism financing laws, but its influence is often invisible to legal practitioners. This episode explains how FATF reshaped the global financial crime system, why Australia’s Tranche 2 reforms now extend AML/CTF obligations to designated services provided by lawyers, and what this means for everyday practice. Tim Goodrick outlines the practical impact of risk-based AML/CTF compliance on customer due diligence, beneficial ownership checks, suspicious matter reporting and legal professional privilege. The discussion is designed for practitioners who need to understand why the regime exists, whether they provide designated services, how to identify risk in routine work and practical steps to implementation.

Topics & Timestamps:

  • [00:04] Welcome to Cross-Examined
  • [00:12] Episode introduction and AML/CTF Tranche 2 overview
  • [00:54] Why lawyers need to understand FATF
  • [01:14] FATF – the most important body you’ve never heard of
  • [03:24] How Australia moved from model jurisdiction to compliance gaps
  • [07:05] Real-world harms the AML/CTF regime is designed to prevent
  • [09:06] What Tranche 2 means in practice for lawyers
  • [12:24] Professional resistance and lessons from New Zealand
  • [15:22] Legal professional privilege and confidential instructions
  • [18:10] What the regime means for sole practitioners and smaller firms
  • [20:35] First steps for lawyers who have not started yet
  • [22:50] Closing remarks
  • [22:57] Resources, show notes and AML/CTF mini-series reminder

Key Takeaways:

  • FATF is not a domestic regulator. It is an inter-governmental standard-setter that assesses how countries combat money laundering, terrorism financing and proliferation financing
  • Australia helped build the global AML system but has fallen behind FATF standards in areas involving lawyers, accountants, real estate agents and other professional services
  • AML/CTF compliance is not only about paperwork. The regime is designed to protect communities by helping law enforcement follow the money behind serious and organised crime
  • Lawyers may be exposed to money laundering risk through ordinary work involving property, trusts, companies, client money and beneficial ownership structures
  • Tranche 2 introduces practical obligations including AUSTRAC enrolment, risk assessments, AML programs, customer due diligence, ongoing monitoring and suspicious matter reporting
  • Legal professional privilege remains important, but practitioners need to understand the distinction between privileged legal advice and transactional services
  • The first practical step is to identify whether the services provided fall under designated services, then map the regulated parts of the business and build the AML/CTF program into daily operations

Resources & Links:

About This Podcast:

Cross-Examined is a new podcast from the Law Institute of Victoria. Tune in to hear experts discuss hot topics in the law and the changes shaping the legal profession. Regular episodes will cover everything from AI and cyber threats to ethical dilemmas, workplace taboos and practice management insights.

This podcast is recorded on the traditional lands of the Wurundjeri people of the Kulin Nation. The Law Institute of Victoria acknowledges the Traditional Custodians of Country across Australia. We pay our respects to Elders past and present.

Disclaimer:

This podcast is for informational purposes only and is not intended to replace professional legal advice. The views expressed in this podcast do not necessarily reflect the views of the Law Institute of Victoria (LIV). The LIV is not responsible for any losses, damages or liabilities that may arise from the use of this podcast. Listeners should seek independent legal advice for their matters.

Production Information:

  • Produced by: The Law Institute of Victoria
  • Producer and audio editor: Garreth Hanley
  • Music: Garreth Hanley
  • Copy and show notes: Louise Surette

Connect With Us:

Transcript
Garreth Hanley:

Welcome to Cross-Examined a podcast by the Law Institute of Victoria

Artemis Evangelidis:

The latest reforms to Australia’s anti-money laundering and counter-terrorism financing regime, or the AML/CTF Tranche 2, come into force on the first of July.

Today on Cross-Examined, we delve into why the global anti-money laundering system was created, the role that Australia, one of its founding architects, has to play, and what every lawyer needs to understand about the regulatory changes.

I’m Artemis Evangelidis and my guest today is Tim Goodrick, a partner in KPMG’s financial crime practice, who spent five years inside the Financial Action Task Force, or FATF for short, and assessed countries against its standards, and led Australia’s financial crime policy at the Attorney-General’s Department.

Tim, welcome to Cross-Examined.

Tim Goodrick:

Thank you, Artemis.

Artemis Evangelidis:

Tim, you spent five years inside FATF, including running its training and research institute. Most lawyers know the acronym, but perhaps not the institution. Can you tell us – what problem was FATF built to solve, and what does its day-to-day work look like on the ground now, several decades later?

Tim Goodrick:

Thanks, Artemis. It’s a good question, because the Financial Action Task Force, or the FATF, has often been referred to as the most important body you’ve never heard of. And it’s referred to [as] that because it’s fundamentally changed the way we engage with the financial sector and other sectors beyond that as well.

ially, the FATF was set up in:

What the FATF does is four things. It sets the global standards of what countries have to do to combat money laundering and terrorism financing. It then assesses implementation against those standards – and I’m sure we’ll touch on that throughout this conversation, given that Australia is in the middle of one of those assessments at the moment. It monitors trends and methods, looking at the way that criminals are evolving and the way that terrorists move their funds over time, to make sure we are monitoring changes. And lastly, it identifies high-risk countries that might be a threat to the international financial sector.

But what the FATF has done over the last 30 to 40 years has significantly changed the scope and breadth of the international standards. It started with quite a narrow set, where we had to criminalise money laundering, focus on prosecutions and make sure we had financial intelligence units, and law enforcement had the powers to conduct financial investigations. At the same time, there were some obligations on the banking sector as well, to prevent and detect dirty money going through their organisations.

ader financial sector. And in:

Artemis Evangelidis:

Tim, Australia was one of FATF’s founding members in 1989. What has happened in the intervening years to see us go from a model jurisdiction to one with significant compliance gaps – and why?

Tim Goodrick:

I think the first important point here is that Australia, in a number of respects, in a number of aspects, remains a model jurisdiction. We have been identified by the FATF in previous assessments, including 10 years ago, that we have great powers – law enforcement bodies – for asset confiscation. We have great powers on the books to ensure that we can prosecute money laundering and follow the money, in terms of those financial investigations, across any profit-motivated crime. And that has been used effectively to combat terrorism financing and to combat money laundering. So, I think that’s the first point.

ly. We established AUSTRAC in:

So, in 2003, the government in place at the time decided, fine, we need to update this legislative regime, we need to put stronger obligations onto the private sector. In fact, we are going to start first with the financial sector and casinos, because those are the entities that throughout the 90s were already used to some level of regulation – that’s what we are going to call Tranche 1. We are going to split out a second tranche, which is going to cover lawyers, accountants, real estate agents, and trust and company service providers – and that will be Tranche 2.

hat decision was taken around:

Because if we fast forward to today, we are one of five countries globally – out of those 205 that have signed up to FATF – we are one of five countries to be found non-compliant with the FATF standards in respect to these professional businesses and professions. That’s big, because it’s us, it’s Haiti, it’s Madagascar, as well as China and the United States in company – five out of 205 jurisdictions have been found to be non-compliant.

When we talk about the FATF, the Financial Action Task Force, and the assessments that they undertake of countries around the world – what’s critical here is, at the end of that process, which takes about 15 months, at the end of this process they give a public report card on a country.

So, I mentioned earlier, Australia is going through that process right now. It’s called a peer evaluation, or mutual evaluation, because it’s not done by bureaucrats sitting in Paris – well, they are part of it, and I used to be one of those bureaucrats, but it’s not just done by them. It’s done by experts from other FATF countries as well, who come in and assess two things.

Firstly, they assess whether Australia has the laws on the books – so, are they technically compliant with the international obligations. But then secondly, just as importantly, they’ll tell us if we are actually effective at doing so.

And so, as Australia goes through this process over the next 12 months, at the end we’ll get that report card – not just do we have laws on the books, but, Australia as a country, from private sector to public sector entities, are we actually doing any good at combating money laundering and terrorism financing.

h is why we find ourselves in:

Artemis Evangelidis:

What are the real-world harms the AML/CTF regime is trying to prevent? And can you give us some examples of how a lawyer may have unwittingly contributed to laundering money or supporting terrorism without even realising?

Tim Goodrick:

There’s a risk, when we start to think about the anti-money laundering and counter-terrorism financing regime – there’s a risk that we view this in one of two ways. We look at it as a compliance problem – that we look at it, we need to comply with the laws, we need to make sure we’ve got all our paperwork in line. That’s not the purpose of this regime.

The second risk, which we often hear talked about, is that the intention of the regime is to protect the integrity of the financial system. Again, that’s a small sliver of what we are trying to achieve here.

What we are trying to achieve is much broader than that, through the AML/CTF regime. It’s about protecting communities and it’s about using the tools and powers across government and within the private sector to combat all forms of money laundering and terrorism financing.

What that means in practice is that the powers and information that we have and gather – the private sector, the activities that they take to gather information – is then used to be able to help law enforcement undertake their investigations, help them to follow the money. And that cuts across all types of serious and organised crime.

It could be tax evasion, where potentially lawyers are unwittingly used to help set up a complex web of trusts, companies and other types of corporate vehicles to disguise the origin of the profit or revenue, to avoid paying taxes in Australia, or to funnel the money offshore. It could be large-scale movements of money on behalf of organised crime syndicates – again, setting up different structures and companies, or putting those funds into real estate, again, unwittingly involved as well. But these are real-life harms that we are trying to combat by putting in place an anti-money laundering system.

On the back end, you’ve then got law enforcement, AUSTRAC and other law enforcement bodies coming back to help follow the money. And this is where lawyers play a key role – by having that information trail around who, on whose behalf those services were provided, to follow the thread of who was actually pulling the strings behind the scenes.

Artemis Evangelidis:

Tim, we know that the Tranche 2 reforms are a key next step in AML/CTF implementation in Australia. Can you explain what this means in practice for the professions covered by these reforms, and particularly for lawyers?

Tim Goodrick:

In short, it’s big. It’s a significant change in the way that lawyers and other covered sectors engage with their customers, both upfront and on an ongoing basis. It’s a complex set of regulatory obligations, which cover everything from establishing an anti-money laundering program – which includes a risk assessment – and then having policies, procedures, systems and controls to essentially do that. That’s a mouthful. What it means in practice is, maybe I’ll break it down into a couple of practical areas that lawyers have to follow.

The first is they need to enrol with AUSTRAC if they are regulated – they need to enrol with AUSTRAC to ensure it’s visible – and then they need to establish that program that I mentioned.

The reason we start with a risk assessment is because the legislative regime, the regulatory regime, is not a prescriptive regime. It sets the minimum requirements, and then organisations that are regulated have some flexibility to implement those requirements based on the risk of money laundering, the risk of terrorism financing, that their organisation faces. There’s some flexibility in there. So, the starting point is always a risk assessment.

That’s not a regulatory risk assessment, that’s not a risk of things going wrong – that’s actually a risk of how criminals might come into our organisation and put money through. So, that’s always the starting point.

Then, in terms of those minimum areas organisations have to follow – a key cornerstone of the anti-money laundering regime is ‘Know Your Customer’, or customer due diligence. This starts with onboarding. So, identifying the person who you’re providing the services to – that could be an individual or a legal person. If it is a legal person or legal arrangement – so a company, trust or other form of corporate vehicle – you then need to take another step further and identify the beneficial owner who’s actually controlling that corporate vehicle. So, the natural person at the end of the chain who’s pulling the strings.

That’s really important, because if you look at any large-scale money laundering operation or money laundering set up around the world, they are using corporate vehicles to disguise their ownership. I think any money launderer worth their salt would not be setting up accounts in their own name – they keep their name out of it.

So that’s customer due diligence. That starts at onboarding of a client, but also throughout the life of that customer relationship – what’s called ongoing due diligence. That might be when customers change – it could be a change in ownership of a company, it could be a new director being onboarded – understanding what those changes are. Or it could be on a periodic basis as well, re-evaluating some of the information that you have about that client, understanding who they are, the nature of their business. So, customer due diligence is a key point.

Another cornerstone of the anti-money laundering regime is monitoring the activity of customers – monitoring their transactions, their behaviour – and determining if anything is suspicious. And, in your view, if it is suspicious, the requirement is then to report any suspicious matter to AUSTRAC, who is the financial intelligence unit, and then they can help analyse and use that as part of their intelligence work, or potentially feed that into law enforcement bodies as part of their investigation. Reporting suspicious matters is key as well.

So, as I said, quite a complex regulatory framework that’s being set up, with a series of obligations to sit behind that.

Artemis Evangelidis:

Tim, I want to ask – you were seconded to the New Zealand Ministry of Justice when they went through the same transition. Did you encounter resistance from the profession there? And if you did, what did that look like and how was it overcome?

Tim Goodrick:

I think I’ll talk to my experience not just in New Zealand, but working with different legal sectors, real estate and accounting sectors around the world as part of my work at the FATF. And I think it’s fair to say there’s always some element of challenge around that. The common frame globally is that it’s a complex regulatory regime that’s disproportionately hitting small business that doesn’t necessarily have the tools set up.

I think a common concern globally has been, you’re applying a banking regulatory framework to the legal sector and small businesses in particular. That’s often the criticism we’ve heard.

I think that’s often a criticism without necessarily understanding how the anti-money laundering framework works in practice. As I said, there’s a fair bit of flexibility in the regulatory framework, because it does apply a risk-based approach. And while the thematics might be the same – the thematic expectations on a small law firm providing certain services might be the same as what there is on a bank – the way that these organisations actually implement controls, implement their obligations, is fundamentally different on how it’s done in practice. And I think that’s a really important point.

What we often find in talking to smaller law firms, or other sectors that are being captured, is they do understand their clients. They do understand the nature of their business dealings with them. They do understand where they are coming from.

I worked with one entity, for example, in New Zealand – it’s a small entity, it was already regulated – and I said to them, what would you consider to be a suspicious matter? And they said to me, someone that walks in the door that I’ve never heard of before, that’s not from my community. So, I think what we often find in practice is the organisations do know who they deal with. So, then it comes back to, how do you document that in a considered way?

They are often seeing things that they may consider to be suspicious – they may consider it to be not quite in line with what they would expect from all of their other clients. The question is whether they have taken action in the past. Some have – they might off-board them. Some might keep them on and say, well, that’s not my business. The shift in mindset going forward will be, actually, if you do see that something is suspicious, or you do think that something isn’t quite right, what steps do you take?

The risk is that some of these practical steps are overcomplicated and built out in such a way that the smaller businesses are drowning under documentation. That is a risk. But if it’s set up in a structured, ordered way, there’s a way to comply with this obligation that doesn’t necessarily provide a disproportionate burden.

And one call-out that I’d like to make here is the work of AUSTRAC and the government is to support small businesses. What they have produced is something called Starter Kits, where if you fit the fact pattern, if you’re a business in the legal sector which suits the criteria and circumstances that they have documented, you can adopt what’s called this Starter Kit, which is essentially a risk assessment and a program, and you fill that in. And then the key step is to implement – not just have the documentation in place, but implementation as well.

Artemis Evangelidis:

Tim, one key concern we hear from practitioners is, does this regime require me to report what my client told me in a confidential instruction? How does legal professional privilege fit with the AML/CTF regime? And what are some of the challenges you have seen with lawyers navigating this conflict?

Tim Goodrick:

It’s a really complex area, to balance the obligations of legal professional privilege with this new set of obligations coming in July – to report suspicious matters and to conduct enhanced due diligence on certain numbers of your customers. It’s really complex and challenging. And, to be fair, long dissertations and publications have been produced over time in countries that already have this regime in place, like the UK, which has had it since 2007.

A couple of things I’d like to call out, though, is – one, AML obligations do not take over legal professional privilege obligations. That’s still there, and that’s still enshrined in legislation. Where it gets challenging is probably, Artemis – the first part of your question is, what is legal professional privilege versus what is client confidentiality, and the obligation to maintain client confidentiality? That’s not covered in the obligation.

As I say, it’s complex, and this is where it’s important to look at the guidance being produced by organisations like the Law Institute of Victoria, other law societies around Australia as well, even the UK has some good guidance on how lawyers navigate this.

The fear, and the call-out from law enforcement globally over the last 20 years, is that legal professional privilege, in their view, in a number of instances, has been used to such an extent to disrupt and prevent law enforcement to be able to do their jobs – and, in their view, it’s been claimed over and above what should be claimed. That’s been the risk globally. So, while there’s a clear obligation that AML obligations don’t overtake LPP, there is a view from some parts of law enforcement and research that has shown that there’s a potential that it has been overreached.

When I come back to the regime in Australia, that balance is really important. AUSTRAC has put out guidance – and in fact the Minister for Home Affairs just put out draft guidelines around what that looks like in practice, to balance the role of legal professional privilege and the importance that takes in society, versus the new obligations coming in.

When I’ve worked with regulators globally, I think what we find is there’s three areas that you look at, those circumstances which are clearly out of scope of legal professional privilege – it’s not with respect to litigation, it’s not with respect to legal proceedings coming up. They might be establishing trust companies, they might be providing conveyancing services – typically, those type of activities might not have been seen within the scope of legal professional privilege.

On the other hand, there’s activities which clearly are in the scope and in the realm of legal professional privilege as well. But there is grey in the middle, and that’s where these guidelines being produced, and guidance by other bodies as well, has been so important to help lawyers navigate that balance.

Artemis Evangelidis:

A sole practitioner doing conveyancing or succession work in the suburbs or a small regional town may think that they have smaller issues to face than a big city firm, but that isn’t always the case. How will this regime matter in their day-to-day practice?

Tim Goodrick:

I’d probably call that in two ways. In some ways, if you look at a small practitioner with a book of customers that come from the local community, there is a potential that they do face a lower level of money laundering risk, a lower level of terrorism financing risk, than organisations in a larger city that have a different book of customers. And I think that’s the first point.

Because when I think about the obligations – actually setting up your risk assessment, setting up your program – it’s really important to get that right, and taking the time up front to document what your risks are and why, if you consider yourself to be low risk – documenting why that is the case, leveraging the government’s guidance and the government’s resources – and if you fit the circumstances of a Starter Kit, please, I’d recommend you use that as well, and documenting that in a clean, structured way in your risk assessment. Then, potentially you have to do less than what a law firm in the city may have to do that faces greater risks – because it’s a risk-based approach. It’s around putting in controls that are proportional to the risks that you face.

When I think of a small suburban practice, either involved in conveyancing or trust and succession work, the clear shift is going to be around how you onboard customers in the first place. So today, most law firms have some level of onboarding procedures in place to ensure that you are comfortable dealing with that person who’s seeking the services. That can be quite streamlined. Some large organisations might have a complex, robust system already. But a smaller firm needs to revisit that and say, “actually, how do I identify my customers?”

There’s usually a shift in the way that law firms around the world, in circumstances like you just mentioned, would actually onboard a customer. Then, it’s around how you maintain ongoing customer due diligence as well.

That might be providing training to your staff to identify if something is suspicious, making sure they have a person to escalate to. As I talked about some of the obligations before – what I should have mentioned is there’s a clear obligation to identify and appoint an anti-money laundering compliance officer as well that’s then responsible for oversight and monitoring implementation of the AML program as well.

So, in some ways, it’s actually setting up the program, setting up the controls, making sure people are across it, and then following that on a day-to-day basis as well.

Artemis Evangelidis:

Tranche 2 obligations formally commence on 1 July 2026, and I know that you’ve already shared a lot around what our lawyers should be doing to get ready. But for those who haven’t started yet, what should they actually do this week, and where should they go first?

Tim Goodrick:

If you’re just looking at it now, step one would be, figure out if the services and products that you provide to your clients are actually captured. The way the government structured this – and this has been to ensure there’s a level playing field and fair competition – is they are not regulating all of the legal sector, as I touched on.

They are setting out what’s called a series of designated services. And no matter what your business is called – if you’re a trust and company service provider, if you’re a lawyer, if you’re helping clients set up companies, set up and manage trusts, if you’re helping engage with financial institutions on their behalf to move money, or engaging in property and real estate transactions on their behalf, if you’re providing conveyancing services – again, it doesn’t matter what your business is called or how you are structured. It’s about the service you are providing.

So, step one is, look at the designated services and map out what part of your business is regulated, if any. That’s the first thing I’d be doing this week.

Then we'll be saying, which part of my business? You might find that 5 per cent, 10 per cent, 50 per cent, 100 per cent could be regulated. And then it’s around drafting your risk assessment and program following the guidance from the government – like I said, there’s quite a lot of information out there – documenting how it applies to your business and then figuring out implementation.

I say that in a bit of a throwaway line, but that’s often where we find things go wrong – where we walk into organisations that we help to either set this up or we come back and look at it later. They have great documents on file. Someone took the time – they took a few weeks out when it was being set up and they drafted these really great documents, they followed the legal requirements. When you come back in two years, you can almost blow the dust off those documents, because no one’s picked them up. No one’s thought about them. No one’s tried to implement them into your business-as-usual activities. It’s almost been an add-on.

So, I’d say, once you’ve gone through that step one – figuring out the services – once you’ve documented your risk assessment and program, then really think about how you are going to implement that in practice as well. So, building in those steps and controls into BAU activity is actually really important as well.

Artemis Evangelidis:

It’s a fascinating topic, but sadly that’s all we have time for today. Thank you, Tim, for joining us.

Tim Goodrick:

Thank you for having me.

Artemis Evangelidis:

And thank you to everyone listening to Cross-Examined. Please check the show notes for links to FATF’s Australia country assessment page, the APG typologies reports, AUSTRAC’s Tranche 2 resources and the Law Institute of Victoria’s AML/CTF Hub. If you found this episode insightful, please share it with colleagues, and don’t forget to hit subscribe so you don’t miss the next two episodes in our AML/CTF mini-series. Until next time, thanks for listening.

Show artwork for Cross-Examined

About the Podcast

Cross-Examined
A Law Institute of Victoria podcast
The law never stops evolving. Now, Victorian lawyers have a new way to stay informed.

Cross-Examined is a new podcast from the Law Institute of Victoria. Tune in to hear experts on hot topics in the law and the changes shaping the legal profession.

Regular episodes will cover everything from AI and cyber threats to ethical dilemmas, workplace taboos and practice management insights. To make sure you don’t miss our first episodes, landing in early 2026.

Find and subscribe to Cross-Examined on your favourite podcast app today.