Australian AML/CTF · Explainer

Fraud, scams and money laundering

Fraud and scams can produce funds that are then moved or concealed through money laundering.

General information only, not legal, compliance, or other professional advice. Does not confirm compliance.

Start with: Business risk assessment and customer risk

Distinguish the harm and the movement

AUSTRAC’s 2024 national risk assessment discusses fraud, scams and the movement of their proceeds, including the role of mule accounts. Fraud concerns the underlying deception and loss; laundering concerns how criminal money or property is handled. These can appear in the same case without being identical. The assessment is historical threat evidence, not a current measure of every sector. This page helps a business separate the questions. It does not identify a customer as an offender or determine compensation for a victim.

One case can raise two different concernsSeparate evidence questions. An answer to one does not settle the others. Fraud and scams: Examine the deception, possible loss and people affected. Money laundering: Examine how criminal money or property is handled and the separate AML obligations.Fraud and scams Money laundering
  • Fraud and scams

    Examine the deception, possible loss and people affected.

  • Money laundering

    Examine how criminal money or property is handled and the separate AML obligations.

One case can raise two different concerns

The same facts may matter to both reviews. A scam email does not by itself create an SMR obligation for every recipient business.

Separate evidence questions. An answer to one does not settle the others.

Record who may be affected

An illustrative case record distinguishes the customer, possible victim, recipient and person giving instructions. A person moving money may be deceived, coerced or acting with knowledge; the business should not invent that state of mind. Record the available evidence and the immediate operational concern. If different teams handle fraud response and AML review, identify how relevant facts move between them. This proposed workflow supports a consistent case history without assuming that one team’s label answers every legal or customer-protection question.

Worked example: changed payment instructions

Imagine a business receives an email asking it to send a payment to a new account. The message appears to come from a familiar supplier, but independent contact reveals that the supplier did not request the change. In the example, the business follows its incident process and preserves the message and payment details. If money has moved through a covered service, the relevant reporting entity considers its separate AML obligations. The example does not imply that every business receiving a scam email must submit an SMR.

Avoid losing evidence between teams

For the example incident, use one factual timeline with references to the original documents. Keep conclusions clearly attributed: what the supplier confirmed, what staff observed and what remains uncertain. The fraud team may focus on stopping loss while the AML reviewer assesses another question. Their work can inform each other without collapsing into a single decision. This is a suggested coordination method, not a complete incident-response plan. Access and disclosure still need to follow the applicable rules and the organisation’s approved procedures.

Improve the process from the case

A practical review asks where the instruction changed, what independent check was available and whether staff knew the escalation route. It also asks whether the same recipient or contact details appear in other relevant records. Do not turn a single incident into an unsupported claim about all customers of a type. Use the findings to improve the actual process. This page explains how fraud and laundering can connect; it does not replace cyber security, payment verification, police reporting or the legal analysis for a specific matter.

Sources and scope

Sources checked on 2026-09-06. This page is not continuously updated. Check the linked legislation and AUSTRAC guidance for current requirements.

This page does not cover: A complete scam or cyber incident response; Compensation or liability advice.

Common AML/CTF terms