AUSTRAC's Biggest Enforcement Actions: The Cases Every Business Should Know
Money laundering networks are getting more complicated as technology moves forward, and with Tranche 2 now in effect, tens of thousands of Australian businesses now carry AML/CTF obligations.
Over the past decade, a run of high-profile enforcement cases has exposed how significant the gaps in Australia's AML defences have been. Each has pushed the regulator to sharpen the rules, close specific loopholes, and set a higher bar for the businesses that come next.
In this blog, we'll look at some of the biggest money laundering scandals that have shaped AUSTRAC enforcement action against financial crime in Australia, and what each teaches us.
Key Takeaways
- Some of AUSTRAC's civil penalties are now among the largest ever handed down by an Australian court.
- Size hasn't been a shield. The largest penalties have been handed down to the biggest names in Australian banking and gaming.
- The failure pattern is remarkably consistent: a risk is identified but never acted on, or a policy sits on paper that doesn't match how the business actually operates.
- Financial penalties are no longer the only exposure. AUSTRAC has pursued individual directors and officers personally, and the reputational damage tends to outlast the fine itself.
Who is AUSTRAC, and what powers do they have?
AUSTRAC (the Australian Transaction Reports and Analysis Centre) is Australia's financial intelligence and AML/CTF regulator.
Their job is to detect, deter and disrupt the criminal abuse of the financial system. AUSTRAC has very clear expectations when it comes to regulated businesses.
What penalties can AUSTRAC impose?
AUSTRAC can:
- Apply for civil penalty orders through the Federal Court
- Issue infringement notices for specific breaches
- Accept (or compel) enforceable undertakings
- Issue remedial directions requiring specific corrective action
- Direct a business to appoint an external auditor
- Suspend or cancel a business's registration
- Refer serious matters for criminal investigation
What are other implications from AUSTRAC enforcement?
AUSTRAC fines are only part of the cost. A business named in AUSTRAC enforcement action can also face:
- Reputational damage
- Lost customer and investor trust
- Scrutiny that lasts years
- Executive departures and leadership shakeups
For smaller businesses, the reputational fallout and operational disruption often outweigh the fine.
Five Cases That Redefined Compliance Risk in Australia (and What They Mean for You)
See what happens when they flex these powers and see the amounts that make it clear that AUSTRAC does not treat non-compliance as a minor administrative issue.
Westpac's $1.3 Billion Penalty
The outcome
In 2020, the Federal Court ordered Westpac to pay a $1.3 billion penalty for breaches of the AML/CTF Act, the highest of any AUSTRAC fine in Australian history at the time.
AUSTRAC's then-CEO said the outcome sent a clear message that financial institutions are legally obliged to take their compliance obligations seriously.
The background
Westpac admitted to over 23 million breaches, including failing to report more than 19.5 million international funds transfer instructions worth over $11 billion, and failing to carry out appropriate customer due diligence on transactions linked to possible child exploitation.
The takeaway
Scale doesn't protect you. Westpac had enormous compliance resources, and the failures still happened because monitoring and reporting systems weren't properly maintained.
Commonwealth Bank's $700 Million Settlement
The outcome
In 2018, CBA agreed to a $700 million penalty after admitting to 53,750 contraventions of the AML/CTF Act, largely tied to its Intelligent Deposit Machines (IDMs).
The background
The bank failed to assess money laundering risks before rolling the machines out, failed to lodge over 53,000 threshold transaction reports on time, and failed to properly monitor transactions on more than 778,000 accounts for a period of three years.
AUSTRAC's investigation, run alongside the AFP and state police, found the IDMs had been used to launder proceeds connected to drug importation and distribution.
The takeaway
A single technology rollout, introduced without a proper risk assessment, was enough to trigger one of the largest AUSTRAC fines in Australian corporate history. This shows us that new technology and payment channels need AML/CTF risk assessment built in from day one, not one created after a problem is discovered.
Crown Resorts and the Casino Sector Crackdown
The outcome
In 2023, the Federal Court ordered Crown Melbourne and Crown Perth to pay a $450 million penalty after Crown admitted it failed to appropriately assess money laundering and terrorism financing risks at its casinos.
The background
Crown lacked a transaction monitoring program suited to the size and complexity of its business, and failed to conduct appropriate ongoing due diligence on higher-risk customers.
The takeaway
Crown's CEO acknowledged the failings and pointed to significant investment in rebuilding the company's compliance framework as part of the settlement.
Having a policy isn't the same as having the right policy. Crown's AML/CTF program existed… it just wasn't proportionate to the actual risks the business faced.
SkyCity Adelaide's AML/CTF Failures
The outcome
In 2024, the Federal Court ordered SkyCity Adelaide to pay a $67 million penalty, plus $3 million in AUSTRAC's costs, after the casino's AML/CTF programs were found not to meet legal requirements.
The background
SkyCity failed to carry out required checks on 121 customers, including several where the casino knew customers were of interest to law enforcement, and failed to establish adequate board and senior management oversight of its compliance program.
The takeaway
Governance failures compound technical ones. Senior leadership wasn't overseeing these controls, which made their AML/CTF programs weak by AUSTRAC's standards.
Star Entertainment Group Under Fire
The outcome
In March 2026, the Federal Court found that Star's former CEO, Matthias Bekier, and former Chief Legal & Risk Officer, Paula Martin, personally breached their duties under the Corporations Act, in relation to their handling of money laundering risk at the casino.
The background
The Court found Bekier failed to properly deal with a report identifying deficiencies in Star's AML/CTF processes, and failed to properly manage and escalate concerns about the misuse of foreign payment cards by customers.
Martin was found to have failed to properly inform the board about money laundering risks and was involved in misleading Star's bank about how those cards were being used.
The takeaway
Unlike the other cases here, this is one of the few AUSTRAC enforcement actions to target an individual directly, not just the company.
The common thread that caused these cases to happen…
Across many of the cases, here are the common patterns:
- Risks were identified, internally or externally, but weren't acted on quickly or seriously enough.
- Monitoring systems existed on paper but didn't match how the business operated.
- Reporting obligations were missed, delayed, or treated as low priority.
- Senior leadership wasn't told about the risk, or was told and didn't escalate it further.
Why Tranche 2 entities are exposed to the same risk
Every case above involved a business operating under AML/CTF obligations for years. But now, Tranche 2 brings other businesses into the fold.
Since 1 July 2026, real estate agents, conveyancers, lawyers and accountants are now subject to the same AUSTRAC enforcement powers, often with far less compliance infrastructure.
The risks don't disappear because a business is smaller. They just look different, with less experience spotting red flags.
Don't become a case study. Here's how.
- Enrol with AUSTRAC immediately (if you haven't already)
- Build an AML/CTF program not a template - your AML/CTF obligations are specific to how you actually do business
- Know who you're working with - Verify your customers properly before they're in the system
- Risk doesn't stay the same - review and reassess continuously, not as an annual tick-box
- Your team needs to know what they're looking for - train staff to spot red flags and escalate without delay
For Tranche 2 businesses building a program for the first time, make sure policies reflect real operations, risk assessments should be tailored, and escalation actually happens when something looks wrong.
Compliance isn't optional…
Tranche 2 is now in effect, and AUSTRAC enforcement actions show that it will act when AML/CTF obligations aren't met. In fact, they've already started handing out issue notices to businesses that have failed to comply. If you're unsure where your business stands, now's the time to find out, not after AUSTRAC comes knocking.
easyAML helps lawyers, accountants, real estate agents and conveyancers close that gap, with step-by-step guidance, an AUSTRAC-aligned program built specifically for your business and support whenever you need it.
The difference between compliance and non-compliance isn't effort - it's whether you're ready now. AUSTRAC isn't waiting. Your firm shouldn't be either.