
Photo by Frolopiaton Palm
Building a remittance website that meets Australian regulatory standards means layering compliance obligations on top of your web design. A compliant remittance website in 2026 must display AUSTRAC-mandated disclosures, capture consent for AML/CTF customer identification, present accurate exchange rate and fee information before a transaction, and — if you carry an AFSL — publish a Financial Services Guide. Miss any of these and you expose your business to enforcement action, ASIC penalties, or the loss of your banking relationship.
The hard part is that no single regulator hands you a checklist. Your obligations sit across the AML/CTF Act 2006, the Corporations Act 2001, the ePayments Code, Australian Consumer Law, and the 2026 AML/CTF Reforms. This guide pulls those threads together so you can launch a digital channel that survives an AUSTRAC compliance assessment and an ASIC review.
Key Takeaways
- A compliant remittance website requires four disclosure layers: AUSTRAC registration status, transparent fee and FX rate display, terms of service, and — where an AFSL applies — a Financial Services Guide (FSG).
- Online onboarding must satisfy the same AML/CTF customer identification obligations as in-person channels, with additional safeguards against impersonation fraud under the 2026 reforms.
- The ePayments Code governs how you handle electronic transactions, error resolution, and unauthorised transfers if you opt in.
- Australian Consumer Law and WCAG 2.1 AA accessibility standards apply to your site's pricing accuracy and usability.
- Pre-transaction disclosure of the total cost — including the FX margin — is now a competitive and regulatory expectation aligned with World Bank pricing transparency principles.
Why Your Website Is a Regulated Channel, Not Just a Storefront
When you offer a designated service online — sending money on behalf of a customer — your website becomes the point where you collect customer data, form a business relationship, and execute reportable transactions. AUSTRAC treats your digital channel as an integrated part of your reporting entity operations, not a marketing brochure.
This matters because your AML/CTF program must describe how you deliver services through each channel. If your website onboards customers without applying the same customer identification procedures you use in a branch, your program is defective. AUSTRAC's guidance on non-face-to-face customers requires you to address the elevated impersonation risk that comes with remote onboarding.
According to AUSTRAC, more than 5,100 remittance providers are registered in Australia, and a growing share operate primarily or entirely online. The regulator has signalled that digital-only MTOs face the same scrutiny as physical operators — the delivery method changes your controls, not your obligations.
The Four Disclosure Layers Every Remittance Website Needs
A compliant remittance website carries four distinct information layers. Each serves a different regulator and a different customer-protection purpose.
1. AUSTRAC Registration Status
You must be able to demonstrate you are on the Remittance Sector Register before you accept a single customer. While there is no legal requirement to display your registration number in a specific format, publishing it builds trust and helps banking partners verify you. State clearly that you are a registered remittance provider with AUSTRAC.
Do not overstate your regulatory standing. Claiming to be "AUSTRAC licensed" is inaccurate — remittance providers are registered, not licensed, under the AML/CTF Act. Misrepresenting your status can trigger both AUSTRAC and ASIC concerns.
2. Transparent Fee and Exchange Rate Display
Australian Consumer Law prohibits misleading or deceptive conduct, and the single-price rule requires you to show the total amount a customer will pay. For remittance, this means displaying the transfer fee and the exchange rate margin in a way the customer can understand before they commit.
Best practice — aligned with the World Bank Remittance Prices Worldwide transparency framework — is to show the customer:
- The amount debited from their account (in AUD)
- The exchange rate applied
- The transfer fee
- The amount the recipient will receive (in the destination currency)
Hiding your margin inside an unfavourable rate while advertising "zero fees" invites ACCC attention. A clear breakdown protects you and converts better.
3. Terms and Conditions
Your terms of service form the contract between you and the customer. At a minimum they should cover:
- The service you provide and delivery timeframes
- Fees, exchange rate methodology, and when rates are locked
- Refund and cancellation rights
- Your right to delay or refuse a transaction for AML/CTF or sanctions reasons
- Customer obligations to provide accurate identification information
- Complaints handling and dispute resolution
- Liability limitations and force majeure
Crucially, your terms must reserve your right to freeze, delay, or refuse transactions to comply with sanctions screening and suspicious matter obligations — without breaching tipping-off rules under the AML/CTF Act.
4. Financial Services Guide (FSG)
If your remittance activity requires an Australian Financial Services Licence (AFSL) — for example, where you deal in foreign exchange contracts as a financial product — you must provide a Financial Services Guide under the Corporations Act. The FSG must be available before you provide a financial service and must disclose your services, fees, remuneration, and complaints process.
Many pure money-transfer businesses operate without an AFSL, but the line depends on how your product is structured. Consult the linked guide on AFSL requirements and seek legal advice on your specific model.
Online Customer Onboarding Within AML/CTF Rules
Onboarding customers through your website is where compliance and user experience collide. You need a flow that verifies identity to AUSTRAC's standard while not driving legitimate customers away.
Applying Customer Identification Remotely
Under the AML/CTF Act, you must collect and verify the identity of each customer before or at the time you provide a designated service. For online channels, verification typically uses:
- Electronic data source verification (eKYC) — matching name, date of birth, and address against reliable, independent electronic sources
- Document verification — checking a government-issued ID via the Document Verification Service (DVS)
- Biometric or liveness checks — increasingly used to counter impersonation fraud
The 2026 AML/CTF Reforms sharpen expectations around fraud-resistant onboarding. With scam losses reaching $2.18 billion in 2025, AUSTRAC expects digital MTOs to detect impersonation and synthetic identities at the point of onboarding. A simple document upload without a liveness check is no longer defensible for higher-risk profiles.
Building the Onboarding Flow
Structure your online onboarding in stages so you collect the right data at the right time:
- Registration — capture name, date of birth, residential address, and contact details.
- Identity verification — run eKYC and/or DVS checks; escalate to document plus liveness where the electronic match is weak.
- Sanctions and PEP screening — screen the customer against consolidated lists before activating the account.
- Risk rating — assign a risk level that drives ongoing monitoring and any enhanced due diligence.
- Beneficiary collection — capture recipient details, which feed your transaction monitoring and IFTI/IVTS reporting.
Each stage should log a timestamped audit trail. If AUSTRAC assesses your business, you must reproduce exactly what you collected, when, and how you verified it.
Consent and Data Handling
You must obtain informed consent to collect and use personal information under the Privacy Act 1988 and the Australian Privacy Principles. Your online privacy policy must explain what you collect, why, who you share it with (including AUSTRAC and verification providers), and how long you retain it.
Remember the AML/CTF Act requires you to retain customer identification records for seven years after the business relationship ends. Design your data architecture around that retention obligation from day one.
ePayments Code and Electronic Transaction Handling
The ePayments Code, administered by ASIC, governs electronic payment facilities including certain online remittance flows. Subscription is voluntary, but if you opt in — or if your product falls within scope — you take on obligations around:
- Terms and conditions disclosure for electronic transactions
- Receipts and transaction records
- Error and complaint resolution within defined timeframes
- Liability allocation for unauthorised transactions
Treasury's payments licensing reforms are reshaping how the ePayments Code interacts with the broader payments framework. If your website processes card or account-to-account funding, review whether the updated Code applies and document your position.
Accessibility: WCAG 2.1 AA Is the Benchmark
Accessibility is both a legal risk and a commercial opportunity. Under the Disability Discrimination Act 1992, businesses must not discriminate in the provision of goods and services — and courts have applied this to websites. The recognised standard is WCAG 2.1 Level AA.
Practical steps for a remittance website include:
- Sufficient colour contrast for rate and fee displays
- Keyboard navigation for the entire onboarding flow
- Screen-reader-compatible form labels and error messages
- Text alternatives for images and icons
- Clear, plain-language instructions at each onboarding step
Accessibility overlaps with fraud prevention: clear error messaging reduces failed onboarding and helps customers understand why a transaction is delayed.
Compliance Requirements at a Glance
| Requirement | Governing Framework | Applies To |
|---|---|---|
| AUSTRAC registration disclosure | AML/CTF Act 2006 | All remittance providers |
| Customer identification (eKYC/DVS) | AML/CTF Act 2006 | All designated services |
| Total cost / FX transparency | Australian Consumer Law | All online pricing |
| Financial Services Guide (FSG) | Corporations Act 2001 | AFSL holders |
| Privacy policy & consent | Privacy Act 1988 | All customer data collection |
| ePayments Code disclosures | ePayments Code (ASIC) | Opt-in / in-scope facilities |
| Accessibility (WCAG 2.1 AA) | Disability Discrimination Act 1992 | All public-facing pages |
| Sanctions screening notice | AML/CTF Act + sanctions law | All transactions |
Common Website Compliance Mistakes
Avoid these errors that regularly surface in AUSTRAC assessments and ASIC reviews:
- Advertising "no fees" while widening the FX margin — this is misleading conduct under Australian Consumer Law.
- Onboarding customers before verification completes — providing a designated service without identifying the customer breaches the AML/CTF Act.
- Copying another operator's terms of service — generic terms rarely reserve your AML/CTF refusal rights or match your actual product.
- No liveness or fraud check — document-only onboarding leaves you exposed to impersonation and synthetic identity fraud.
- Ignoring the seven-year retention rule — building a system that overwrites or deletes verification records too early.
- Overstating regulatory status — describing yourself as "licensed" when you are registered.
Preparing for the 2026 Regulatory Environment
The 2026 AML/CTF Reforms tighten the connection between your digital channel and your compliance program. Your AML/CTF program must now explicitly address the risks of non-face-to-face onboarding, the fraud vectors your website introduces, and the controls that mitigate them.
Build your website with your compliance program as the blueprint. Every disclosure, consent checkbox, and verification step should map to a documented control. When AUSTRAC assesses your business, you want to point to a website that operationalises your program — not one that contradicts it.
Start with a documented AML/CTF program and let it drive your site architecture. Use a live rate board to keep pricing accurate, and review our corridor guides to align disclosures with the markets you serve.
This information is general in nature and does not constitute legal advice. Consult AUSTRAC or a qualified legal professional for advice specific to your situation.
Frequently Asked Questions
Do I need to display my AUSTRAC registration number on my website?
There is no specific legal requirement to display your registration number, but you must be registered on the Remittance Sector Register before offering services. Publishing your registration status builds customer trust and helps banking partners verify your legitimacy. Never describe yourself as "AUSTRAC licensed" — remittance providers are registered, not licensed.
Can I onboard customers entirely online without meeting them?
Yes. Non-face-to-face onboarding is permitted, but you must apply customer identification procedures using reliable electronic verification — such as eKYC, the Document Verification Service, and liveness or biometric checks for higher-risk profiles. AUSTRAC treats remote onboarding as higher risk for impersonation, so your controls must be stronger than a simple document upload.
Do I need a Financial Services Guide for my remittance website?
Only if your activity requires an Australian Financial Services Licence — for example, where you deal in foreign exchange contracts treated as financial products. Many pure money-transfer businesses operate without an AFSL and therefore without an FSG. The distinction depends on how your product is structured, so seek legal advice on your specific model.
How do I display exchange rates and fees compliantly?
Show the customer the total cost before they commit: the amount debited in AUD, the exchange rate applied, the transfer fee, and the amount the recipient will receive. Hiding your margin inside the rate while advertising "zero fees" can constitute misleading conduct under Australian Consumer Law and attract ACCC attention.
Does the ePayments Code apply to my remittance website?
It may. The ePayments Code is voluntary to subscribe to, but if you opt in or your product processes electronic payments within scope, you take on obligations around disclosures, receipts, error resolution, and unauthorised transaction liability. Review your funding flows and document whether the Code applies to your business.
How long must I keep customer records collected online?
The AML/CTF Act requires you to retain customer identification records for seven years after the business relationship ends, and transaction records for seven years after the transaction. Design your data architecture around this retention obligation from launch so records are never overwritten or deleted prematurely.
