Understand the disclosure question
AUSTRAC describes tipping off by reference to protected information and the risk of prejudicing an investigation. It is not helpful to turn that into a rule that all customer communication must stop. Equally, an ordinary service message can disclose something sensitive if it explains an internal suspicion or reporting action. Read the current guidance and its conditions before making a disclosure decision. This page explains a practical communication boundary; it does not list every lawful disclosure route or decide a particular privilege question.
- Proposed message
Identify the recipient and the routine information they need.
- Restricted material
Check attachments, file names, comments and message history.
- Authorised review
Escalate uncertainty and apply the current disclosure test and exceptions.
Review the whole disclosure
Suggested communication check. It neither bans all customer contact nor supplies a universally lawful script.
Follow the process from top to bottom.
Separate service work from restricted material
A suggested operating design keeps routine customer information requests separate from restricted review notes. Staff can use approved explanations for normal verification work without being shown every internal conclusion. Access should follow the person’s role in the process. Before sharing a document externally, consider attachments, comments and message history as well as the visible sentence. This is an illustrative control design, not a prescribed software permission model. Its purpose is to make accidental disclosure less likely while allowing necessary business work to continue.
Worked example: a customer asks about delay
Imagine a customer asks why a transaction is taking longer than expected. A staff member can see a restricted review note and is tempted to copy it into a reply. In the example workflow, the staff member instead refers the communication to the authorised reviewer. That person considers the applicable disclosure rules and the facts. The answer should not reveal a report merely to justify the delay. The example does not supply a universal script because the lawful response depends on the circumstances.
Review more than email
The same example business checks shared folders, customer portals, meeting notes and support tickets. A restricted report reference could appear in a file name or an exported case summary even if the main message is careful. A useful review asks what the recipient can infer from the full material being released. It also checks whether an automated notification can expose an internal status. These examples show how restricted information can be disclosed. They are not evidence that a particular platform has a defect or that every disclosure is prohibited.
Give staff a clear escalation path
A practical instruction tells staff whom to contact when they are unsure about a proposed disclosure. It includes a backup so that uncertainty does not produce an improvised answer. Training can use fictional messages and ask staff to identify what should be escalated. Record the final decision and the basis for it in the restricted case record. Where the law is unclear on the facts, obtain appropriate advice. This process supports careful communication but does not replace the current statutory test or its exceptions.