
Photo by stockedhousestudio
Outsourcing your AML/CTF compliance function can cut costs and give a small remittance business access to expertise it could never afford to hire in-house — but it never transfers your legal accountability. Under the AML/CTF Act 2006, you remain the reporting entity, and AUSTRAC will hold you responsible for every breach, even one caused by a contractor you paid to get it right.
That single principle should shape every outsourcing decision you make. Many small MTOs outsource transaction monitoring, sanctions screening, or the AML/CTF Compliance Officer role because they lack the volume to justify a full-time specialist. Done well, this is legitimate and AUSTRAC-recognised. Done poorly — with no oversight, a vague contract, and blind trust in the vendor — it becomes a fast route to enforcement action. This guide shows you where outsourcing makes sense, what a compliant arrangement looks like, and where the accountability traps sit.
Key Takeaways
- You cannot outsource accountability. As the reporting entity, you remain liable for AML/CTF compliance under the Act — regardless of who performs the work.
- Outsourcing is legitimate and common for transaction monitoring, sanctions screening, independent reviews, and even the AML/CTF Compliance Officer function, provided you retain oversight.
- A compliant arrangement needs a written contract, defined SLAs, access to records, audit rights, and documented oversight — not a handshake and an invoice.
- AUSTRAC expects board and senior management to remain engaged. "The vendor missed it" is not a defence in an enforcement matter.
- The 2026 AML/CTF reforms reinforce that governance and oversight obligations sit with the reporting entity, sharpening scrutiny of outsourced functions.
Why Small MTOs Consider Outsourcing Compliance
Compliance is expensive, and it does not scale down neatly. A remittance business processing 200 transactions a month faces the same core obligations as one processing 200,000 — you still need transaction monitoring, sanctions screening, suspicious matter reporting, an AML/CTF program, and an independent review.
The fixed cost of building this in-house is brutal for a small operator. A qualified AML/CTF Compliance Officer commands a salary well above AUD 120,000, transaction monitoring platforms carry licensing fees, and staying current with regulatory change demands hours you would rather spend on the business.
Outsourcing spreads these costs across a vendor's client base. You pay for the slice of expertise and technology you actually use, which is why the model appeals to sole operators, family-run MTOs, and businesses in their first two years of trading.
The functions MTOs most commonly outsource
Not every compliance task is equally suited to outsourcing. In practice, small MTOs outsource these functions most often:
| Function | Commonly outsourced? | Why |
|---|---|---|
| Transaction monitoring | Yes | Requires software and analyst time small MTOs lack |
| Sanctions screening | Yes | Screening providers maintain live DFAT and global lists |
| Independent AML/CTF review | Yes (required) | Must be performed by someone independent of the program |
| AML/CTF Compliance Officer role | Sometimes | Permitted, but oversight expectations are high |
| SMR/TTR/IFTI drafting and lodgement | Sometimes | Vendor prepares; you approve and authorise |
| KYC/customer onboarding decisions | Rarely fully | Retaining control reduces accountability risk |
| Board and senior management oversight | Never | Cannot be delegated under the Act |
The pattern is clear: technical, resource-intensive tasks are good outsourcing candidates. Governance and final decision-making are not.
What AUSTRAC Says About Accountability
Here is the rule that governs everything else: outsourcing a function does not outsource the obligation. AUSTRAC has stated repeatedly that a reporting entity retains full legal responsibility for meeting its AML/CTF obligations even when a third party performs the work.
This is reinforced by the AML/CTF Act 2006 and the AML/CTF Rules. Your Part A program must still identify and manage money laundering and terrorism financing risk. If an outsourced provider fails to monitor a transaction and a suspicious matter goes unreported, you committed the breach — not the vendor.
AUSTRAC's enforcement history makes this concrete. In its dealings with major reporting entities, the regulator has consistently held boards and senior management responsible for compliance failures, including those involving systems and processes managed by external parties. "The vendor was supposed to handle it" has never succeeded as a defence.
The 2026 reforms sharpen the focus on governance
The 2026 AML/CTF reforms, which reshaped obligations from 31 March 2026, place heavier emphasis on governance, senior management accountability, and risk-based oversight. Reporting entities must demonstrate that their governing body understands and actively oversees the AML/CTF program.
For an MTO that outsources compliance, this raises the bar. You must be able to show AUSTRAC how you supervise the vendor, review their output, and satisfy yourself that obligations are being met — not merely that you signed a contract and paid the invoices.
When Outsourcing Compliance Makes Sense
Outsourcing is the right call when the numbers and the risk profile line up. It makes sense when:
- Your transaction volume is too low to justify full-time in-house compliance staff but too high to manage manually.
- You lack access to transaction monitoring or sanctions screening technology that a vendor already operates at scale.
- You need specialist expertise — for example, an independent AML/CTF review, which must be conducted by someone independent of the program's design and operation.
- You are launching a new corridor or product and need experienced hands to build the risk assessment before hiring permanently.
- You want continuity. A vendor with a team does not go on leave or resign the way a single in-house officer might.
When outsourcing is the wrong choice
Equally, some situations argue against it. Think twice if:
- You cannot commit the internal time to oversee the vendor. Outsourcing without supervision is worse than no arrangement at all, because it creates the illusion of coverage.
- Your business model carries high inherent risk — high-risk corridors, cash-intensive operations, or a large agent network — where hands-on control matters more.
- The vendor cannot demonstrate remittance-specific experience. Generic AML consultants who have never worked with an MTO will miss corridor-specific typologies and IFTI/IVTS reporting nuances.
- The cost saving is marginal. If outsourcing barely undercuts an in-house hire, the added accountability risk may not be worth it.
What a Compliant Outsourcing Arrangement Looks Like
A compliant arrangement is defined by documentation and oversight, not by the vendor's reputation alone. AUSTRAC expects you to manage the relationship as a controlled, monitored dependency. Build it around these elements.
1. A written outsourcing agreement
Never rely on an informal understanding. Your contract should specify:
- The exact scope of services (which functions, which reports, which screening lists).
- Service level agreements (SLAs) with measurable timeframes — for example, alerts reviewed within 24 hours, sanctions matches escalated within 2 hours.
- Data handling, privacy, and security obligations consistent with the Privacy Act 1988 and Australian Privacy Principles.
- Your right to audit the vendor and access all underlying records.
- Breach notification obligations — the vendor must tell you immediately if something goes wrong.
- Termination and transition provisions so you can retrieve your data and records if the relationship ends.
2. Retained access to your records
Under the AML/CTF Act, you must keep records for seven years. If your monitoring or reporting is outsourced, ensure the contract guarantees you access to — and ownership of — those records at all times. If the vendor holds them and disappears, you are the one who cannot produce them for AUSTRAC.
3. Documented oversight and review
This is where most small MTOs fall short. You must actively supervise the vendor and keep evidence of it. Practical oversight includes:
- Monthly or quarterly review meetings with minutes recorded.
- Sampling the vendor's work — pull a set of monitoring alerts or screening results and check the quality of the decisions.
- Reviewing key metrics: number of alerts, false positive rates, SMRs raised, screening hits cleared.
- Approving reports yourself. Even if the vendor drafts an SMR or TTR, the authorised officer within your business should review and lodge it.
4. A named AML/CTF Compliance Officer accountable inside your business
Even if you outsource day-to-day compliance operations, AUSTRAC expects an accountable person connected to your business. Where the Compliance Officer role itself is outsourced, ensure that person has genuine authority, sufficient seniority, and direct reporting lines to your governing body — not a name on paper who never engages with your risk profile.
5. Due diligence on the vendor before you sign
Vet the provider as carefully as you would a high-risk customer. Confirm their remittance experience, references from other MTO clients, professional indemnity insurance, data security controls, and continuity arrangements. Ask what happens to your data if they are acquired or cease trading.
The Accountability Traps to Watch Out For
Outsourcing goes wrong in predictable ways. Watch for these traps.
Set-and-forget syndrome. You sign the contract, breathe a sigh of relief, and never look at the vendor's work again. Twelve months later an AUSTRAC assessment finds unreviewed alerts and missed SMRs — and you cannot show a single oversight record. This is the single most common failure.
Assuming the vendor understands your risk. A generic provider applies generic thresholds. If your business runs a high-remittance corridor with specific structuring typologies, an off-the-shelf monitoring ruleset will miss the patterns that matter. Your risk assessment must drive the vendor's configuration, not the other way around.
Losing control of reporting timeframes. SMRs must be lodged within 3 business days of forming a suspicion (24 hours for terrorism financing). TTRs are due within 10 business days. If the vendor sits on a matter, you breach the deadline — and the clock does not pause because you outsourced the function.
No visibility into IFTI/IVTS obligations. International funds transfer reporting is highly specific to remittance. A vendor unfamiliar with IVTS reporting obligations under the current framework can leave you exposed. Confirm they understand the reporting regime that applies to your rails.
Weak breach notification. If the vendor's contract does not require immediate notification of failures, you may only learn of a problem when AUSTRAC does. Insist on rapid escalation and document every notification you receive.
Data offshoring without controls. Some vendors process data offshore. This raises privacy, security, and jurisdictional concerns. Understand where your customer data goes and confirm the safeguards meet Australian standards.
Cost Comparison: In-House vs Outsourced Compliance
The economics vary with volume, but the table below illustrates typical trade-offs for a small MTO. Figures are indicative and depend on transaction volume and risk profile.
| Element | In-house | Outsourced |
|---|---|---|
| AML/CTF Compliance Officer | AUD 120,000+ salary | Bundled or AUD 2,000–6,000/month |
| Transaction monitoring software | AUD 10,000–40,000/year | Included in service fee |
| Sanctions screening tool | AUD 5,000–20,000/year | Included in service fee |
| Independent review | AUD 8,000–20,000 per review | Often separate engagement |
| Oversight time (your cost) | Lower — you run it | Ongoing — you must supervise |
| Accountability | Yours | Still yours |
| Best suited to | Higher-volume / complex MTOs | Low-to-mid volume MTOs |
The headline saving is real for low-volume operators, but note the two constants at the bottom: you still spend time on oversight, and you still carry accountability.
A Practical Decision Framework
Use this sequence to decide whether to outsource:
- Quantify your volume and risk. Complete a current AML/CTF risk assessment first — it tells you how much compliance capacity you actually need.
- Cost the in-house option honestly, including software and the independent review.
- Compare against vendor quotes for the same scope, and factor in your oversight time.
- Test vendor expertise with remittance-specific questions — IFTI/IVTS reporting, corridor typologies, threshold structuring.
- If you proceed, build the contract, SLAs, and oversight routine before go-live — not after.
- Schedule your first review within 30 days of the arrangement starting, and quarterly thereafter.
Bringing It Together
Outsourcing compliance is a legitimate, cost-effective strategy for small MTOs — but only when paired with active oversight and a solid contract. The vendor performs the work; you own the outcome. AUSTRAC's position has not softened, and the 2026 reforms have made governance and senior management accountability more explicit than ever.
Treat your compliance vendor the way you treat a critical supplier in any regulated industry: contract tightly, monitor continuously, and keep evidence of your supervision. Get that balance right and outsourcing frees you to grow the business while staying inside the rules.
To get your foundations in order before engaging a vendor, build or review your program with our AML/CTF program tool, and explore corridor guides to understand the specific risks your vendor must be configured to catch.
This information is general in nature and does not constitute legal advice. Consult AUSTRAC or a qualified legal professional for advice specific to your situation.
Frequently Asked Questions
Can I outsource my AML/CTF Compliance Officer role?
Yes. AUSTRAC permits the AML/CTF Compliance Officer function to be performed by an external party, and many small MTOs do this. However, the outsourced officer must have genuine authority, remittance-relevant expertise, and direct reporting lines to your governing body. Your board and senior management retain accountability for the program regardless of who fills the role.
Does outsourcing transfer my legal liability to the vendor?
No. Under the AML/CTF Act 2006, you remain the reporting entity and retain full legal responsibility for compliance. If an outsourced provider fails to monitor a transaction or lodge a report, AUSTRAC will treat it as your breach. You can pursue the vendor contractually, but the regulatory liability stays with you.
What oversight of an outsourced compliance vendor does AUSTRAC expect?
AUSTRAC expects documented, active supervision — not a set-and-forget arrangement. This includes regular review meetings with minutes, sampling the vendor's alerts and decisions, tracking key metrics such as SMRs raised and false positive rates, and personally approving reports before lodgement. You must be able to produce evidence of this oversight during a compliance assessment.
How much does outsourced compliance cost for a small MTO?
Costs vary with transaction volume and risk, but outsourced compliance packages typically run from around AUD 2,000 to AUD 6,000 per month, often bundling monitoring software and sanctions screening. Independent AML/CTF reviews are usually a separate engagement of AUD 8,000 to AUD 20,000. Compare this against the AUD 120,000-plus cost of a full-time in-house officer plus software.
What should be in an outsourcing contract with a compliance provider?
At minimum: defined scope of services, measurable SLAs with response timeframes, data handling and privacy obligations, your right to audit and access all records, immediate breach notification requirements, seven-year record retention arrangements, and termination and data-transition provisions. Without these, you cannot demonstrate control of the outsourced function to AUSTRAC.

