Introduction
Now layer on AUSTRAC’s reforms to the AML/CTF Act, which commence on 31 March 2026 for existing reporting entities and 1 July 2026 for Tranche 2 entities including legal, accounting, real estate, and jeweler industries. The compliance bar isn’t just rising; it’s expanding tens of thousands of additional businesses being captured into the regulatory net. For both existing reporting entities and newly regulated sectors, AUSTRAC compliance is moving from “good enough” to “empirically justifiable.”
Sign 1: More Customers = More Manual Checks and More Room for Error
Customer due diligence (CDD) scales linearly with growth. Every new customer is another identity to verify, another sanctions check to run, another risk rating to assign, another set of records to file. In a spreadsheet world, every one of those steps is a human action (copy, paste, screenshot, save, name the file, link it back to the row).
- Inconsistent data formats (DOB entered six different ways)
- PEP and sanctions screening done weeks apart, or skipped entirely
- Risk ratings that drift because two people scored “medium” differently
- Identity documents stored in someone’s inbox rather than against the customer record
- Re-verification dates that quietly pass with no alert
Under AUSTRAC Tranche 2, the new AML/CTF Rules tighten what counts as adequate CDD – including lowering the initial CDD threshold for certain gambling services from $10,000 to $5,000. If your verification process is held together by manual diligence and good intentions, the volume will eventually break it.AUSTRAC
Key takeaway: Manual CDD is sustainable until it isn’t. The moment you can’t confidently say every customer was checked to the same standard, automated customer due diligence stops being a luxury.
Sign 2: Compliance Information Lives in Too Many Places
Ask a growing compliance team where a specific customer’s KYC file is, and the answer often involves a chain: “The ID is in the CRM, the sanctions screenshot is in Slack, the risk assessment is in the master sheet, the SMR draft is in someone’s drafts folder, and the source-of-funds evidence is in an email thread from March.”
That’s not a process – it’s an archaeological dig.
- Single points of failure. When that person is on leave, knowledge walks out the door with them.
- Inconsistent records. The CRM says the customer is low risk; the spreadsheet says medium.
- Slow incident response. A regulator query that should take an hour, takes a week.
- Data security gaps. Sensitive identity documents sitting in inboxes and shared drives are an obvious exposure under the Privacy Act and APP 11.
Sign 3: It’s Hard to Prove What Was Checked and When
Here’s a useful thought experiment: if AUSTRAC asked you tomorrow to produce the complete CDD record for a specific customer including who verified them, what documents were sighted, what screening was run on what date, every risk rating change, every review, and every monitoring alert – how long would it take?
If the answer is more than a few minutes, you have an audit trail problem.
- Cell histories aren’t real audit logs
- “Last modified by” doesn’t capture what was changed
- Files get renamed, moved, or accidentally overwritten
- Screenshots prove a check happened, not when it happened or what the underlying data was
- There’s no tamper-evidence
Sign 4: Monitoring and Reviews Become Inconsistent
Onboarding is the easy part of AML compliance. Ongoing customer due diligence is where most manual programs quietly fail.
- A column for “next review date”
- A calendar reminder that fires for the compliance officer
- A scramble to find the file and redo the assessment
- A note added back to the row
Sign 5: The Team Spends Too Much Time on Administration Instead of Risk Management
This is the sign most founders miss until it’s already costing them.
Watch what a manual-process compliance team does day-to-day: copying IDs between systems, formatting evidence into PDF packs, chasing customers for missing documents over email, manually re-running sanctions checks before a review, tagging spreadsheet rows, exporting data for the monthly report. Most of it is the administration. Very little of it is risk management.
- Real risk gets missed. The unusual transaction, the subtle structuring pattern, the customer whose stated source of wealth doesn’t quite add up; these need a human looking at them carefully. They don’t get that attention when the same human is reformatting a spreadsheet.
- Good people leave. Senior compliance hires don’t stay long in roles that have quietly become data-entry jobs. Replacing them is expensive, and the institutional knowledge that leaves your business with them is hard to rebuild.A compliance platform inverts the ratio where routine work is automated, and humans focus on judgement calls. That is exactly the work AUSTRAC, in an outcomes-focused regime, increasingly wants to see being done.
- Key takeaway: If your compliance team is too busy to think, your compliance program isn’t working, regardless of what the spreadsheet says.
Conclusion: What to Look for in a Compliance Platform as the Business Scales
Moving from spreadsheets to a compliance platform isn’t about chasing software as that seems to be your best solution. It’s about reaching the point where your manual processes can no longer defensibly support the obligations you’ve taken on, and the obligations of Tranche 2 are about to add.
When you evaluate platforms, look for a tool that genuinely fits a growing business rather than a global bank. Strong candidates share a few characteristics:
- End-to-end CDD and EDD automation: identity verification, sanctions and PEP screening, beneficial ownership, and risk scoring in one workflow
- A centralised, immutable audit trail: every action timestamped, attributable, and reproducible on demand
- Real-time ongoing monitoring: continuous rescreening and transaction monitoring rather than scheduled batch checks
- AUSTRAC reporting readiness: SMRs, TTRs, and IFTI reporting built into the workflow, aligned to the AML/CTF Rules 2025
- Scalability without enterprise bloat: the configurability of a serious tool without a 12-month implementation
- Integration capabilities: clean APIs into your CRM, core banking, payments, or onboarding stack
- Strong data security and Australian data residency: encryption, access controls, and infrastructure choices that align with the Privacy Act and your customers’ expectations
The honest truth is that spreadsheets were never designed for AML compliance; they were tolerated as long as the volume was small, and the obligations were simple. With 31 March 2026 and 1 July 2026 in the calendar, neither of those conditions holds anymore.



