AML/CTF
Your Engagement Letter Is a Compliance Control Most Accounting Firms MissÂ
Â
Pull out your standard engagement letter template.
Read it carefully.
Not the fee schedule. Not the scope of services section. The terms and conditions, the clauses that govern the relationship between your firm and your client.
Now ask yourself an honest question.
Does that document give your firm the legal foundation it needs to operate as a regulated reporting entity under Australia's AML/CTF laws, now in effect since 1 July 2026?
For the overwhelming majority of Australian accounting firms, the answer is no.
Not because the engagement letter was poorly drafted. Because it was drafted for a different regulatory world, one in which accounting firms had no formal AML/CTF obligations, no customer due diligence requirements, and no statutory reporting obligations that could override their duty of confidentiality to clients.
That world ended on 1 July 2026.
The three frameworks your engagement letter must now serveÂ
Since 1 July 2026, every engagement letter issued by a firm providing designated services must operate across three regulatory frameworks simultaneously.
- The first is TASA, the Tax Agent Services Act 2009, and the Tax Practitioners Board Code of Professional Conduct. This is the framework most accounting firms are already familiar with. It governs professional conduct, competence, confidentiality, and client obligations.
- The second is the AML/CTF Act, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. This is the new framework. It imposes customer due diligence obligations, ongoing monitoring requirements, suspicious matter reporting obligations, and record-keeping requirements on accounting firms that provide designated services.
- The third is the Privacy Act 1988. This governs how the personal information collected during customer due diligence is handled, stored, used, and disclosed.
Your engagement letter must support all three simultaneously. If it does not, the firm lacks the contractual foundation to do what the law now requires it to do.
What is missing from most engagement lettersÂ
Most accounting firm engagement letters contain strong language around scope, fees, liability limitation, and professional obligations under TASA.
They contain almost nothing that supports AML/CTF compliance.
Specifically, they do not require clients to provide identity and beneficial ownership documents as a condition of the engagement. They do not give the firm the contractual right to conduct PEP, sanctions, or adverse media screening. They do not require clients to notify the firm when ownership, control, or structure changes. They do not establish the firm's right to pause or cease services if CDD requirements are not met.
And critically, they do not address the most important and most sensitive clause of all.
They do not disclose to the client that the firm's confidentiality obligations are subject to statutory override, that the firm may be required to report information to AUSTRAC without the client's knowledge or consent, and that the firm may be legally prohibited from telling the client that such a report has been made.
That clause is not optional. It is the clause that manages the direct tension between the firm's TASA obligation to maintain client confidentiality and its AML/CTF obligation to report suspicious matters. Without it, the firm is operating with an unresolved conflict at the heart of its client relationships.
Â
The eight clause categories every engagement letter needs
The AML/CTF framework requires accounting firms to address eight specific areas in their engagement letter terms.
- Identity verification and customer due diligence. The engagement letter must establish clearly that the firm is a reporting entity with AML/CTF verification obligations, that clients must cooperate with those obligations, and that designated service work does not commence until minimum CDD is satisfactorily completed.
- Ongoing notification of material changes. Clients must be contractually obligated to notify the firm when ownership, control, or structure changes, when directors change, when new shareholders are introduced, when trustees or appointors change, or when a significant change to business activity occurs. Without this clause, the firm has no contractual basis for expecting to be informed of the very changes that trigger its monitoring obligations.
- Screening consent. The Privacy Act requires informed consent for the collection and use of personal information. A screening consent clause obtains that consent explicitly, covering PEP screening, sanctions screening, and adverse media screening, both at onboarding and on an ongoing basis.
- The right to pause or cease services. This clause gives the firm the contractual protection it needs when it must stop acting. Without it, a client who is disengaged for failing to provide CDD documents has a potential breach of contract claim. With it, the firm's right to disengage is established as a condition of the relationship from the outset.
- The confidentiality limitation and AML/CTF reporting obligations clause. This clause discloses upfront that the firm's confidentiality obligations are subject to statutory override, that AUSTRAC reports may be made without client knowledge or consent, and that the firm may be prohibited by law from disclosing that such a report has been made. This is the clause that manages the tipping-off risk at the contractual level.
- Record keeping and data handling. Clients should understand that AML/CTF-related identity and compliance records will be retained for a minimum of seven years, stored securely, and accessed only by authorised personnel for compliance purposes.
- Source of funds and source of wealth for higher-risk engagements. For structuring, outsourced CFO, business advisory, and SMSF matters involving significant transactions, the firm needs the contractual basis to request detailed source of funds and source of wealth information, including supporting documentation, not just verbal explanation.
- Client acknowledgement and cooperation obligation. This is the clause that ties everything together, a standalone acknowledgement confirming the client has read and understood the firm's AML/CTF obligations, agrees to cooperate with CDD and monitoring requirements, and understands that failure to cooperate may result in the cessation of services.
Â
The existing client problem
Most accounting firms are focused on their new client engagement letters. The existing client problem is the one they are avoiding.
If a client is receiving designated services and the current engagement letter predates the AML/CTF framework, the prudent position is that the engagement terms should be updated.
The firm should not be relying on an engagement letter from three years ago to support obligations that did not exist when that letter was signed. The contractual foundation for requesting identity documents, conducting screening, pausing services, and managing reporting obligations must be current.
- For high-risk clients providing designated services, the update should happen before or at the commencement of the next designated service matter.
- For medium-risk clients, the update should be completed at the next natural renewal point.
- For lower-risk clients, a rolling program is appropriate.
The conversation with existing clients is not as difficult as most partners fear. The script is straightforward: this is a firm-wide update driven by new legislative requirements, and it applies to every client without exception.
The minimum viable clause
For firms that have not yet completed a full engagement letter update, there is an interim position.
A single paragraph that establishes the firm's AML/CTF obligations, its right to request information, its right to pause or cease services, and the statutory limitation on confidentiality, inserted into existing templates as a matter of urgency, is significantly better than nothing.
It is not a substitute for the full eight-clause framework. But it establishes the firm's legal position in writing and demonstrates a genuine effort to implement its obligations.
The full clause set update should follow as quickly as possible after that.
Version control and rollout
Once the engagement letter has been updated, version control becomes critical.
Every template must carry an effective date. Every partner and manager must be using the current version, not a saved personal copy of an older template. Previous versions must be retained and not deleted, because they are evidence of what terms were in place at the time each prior engagement letter was signed.
And a process must exist to update engagement letter templates whenever the firm's AML/CTF program is materially revised.
The engagement letter is not a set-and-forget document. It is a live compliance control that must keep pace with the firm's obligations.
The bottom lineÂ
The engagement letter is the document that defines the terms of every client relationship your firm holds.
Since 1 July 2026, those terms must support your AML/CTF obligations, not conflict with them, not ignore them, and not leave the firm without the contractual foundation it needs to do what the law requires.
The firms that update their engagement letters properly will have a clear, written basis for every CDD request, every screening process, every monitoring review, and every difficult conversation about pausing or ceasing services.
The firms that do not will be making up the rules as they go, without a contractual leg to stand on.
Best Practice Group delivers a turnkey AML/CTF Tranche 2 Training and Certification Program designed specifically for public accounting firms. It includes a complete compliance playbook, two live implementation sessions, 16 operational templates, mandatory compliance assessments, and two certificates per participant issued by Best Practice Group.
Your AML/CTF obligations are live now. If your firm still needs to get operational, the time to enrol is now.
👉 Register for the AML/CTF Tranche 2 Training Program
👉 Get the Free AML Playbook
Or contact us directly:
đź“§Â team@bestpracticegroup.com.au
📞 1300 274 636
This article is general guidance only and does not constitute legal advice. Firms should confirm their specific obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and seek independent legal advice where required.
Partner Override: How Fee Pressure Weakens AML/CTF Compliance
Coming Soon