You are liable for a counter-party you never checked.
TL;DR
- The obligation is continuous, not a one-off at onboarding. A file that was correct in March is not evidence of anything in August.
- The events that create the exposure are on the public record the day they happen. Nobody notifies you.
- Manual rescreening of 30 to 60 active counter-parties every week is not a discipline problem. It is arithmetic that does not work.
- Closing the gap is a $0.49 check, or $29 a month to watch the list continuously. Ironbark is the verification layer inside your program, not the program.
The question you cannot answer from the file
A conveyancing practice settles somewhere between thirty and sixty matters a month. A small accounting practice carries fifty to two hundred business clients. Each of those is a counter-party you verified once, at the point you took them on, using whatever was true that day.
Now picture the question asked twelve months later, in a review, about one specific matter: what did you know about this party, and when did you know it? The file answers the first half. It has an identity record, a date, a signature. It does not answer the second half at all, because nothing in it was ever updated.
That gap is the entire exposure. It is not a failure to check. It is a failure to keep checking, and the two are treated very differently.
Why the obligation does not end at onboarding
The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) requires ongoing customer due diligence, not a single identification event. The risk profile of a customer has to be kept current for the life of the business relationship, calibrated to the assessed risk. That is the risk-based approach, and it is a duty rather than a discretion.
For accountants, lawyers, conveyancers and real estate agents, those obligations commenced on 1 July 2026 under the AML/CTF Amendment Act 2024 (Cth) and have been running for 53 days. Every designated service provided since then is inside the regime, whether or not the program was written when it was provided. AUSTRAC has estimated that more than 100,000 businesses become reporting entities under the reforms. Confirm the commencement position for your own profession against AUSTRAC directly rather than against a date quoted on a vendor page, including this one.
The exposure is not only the entity's
In a sole practice the separation between the business and the person is largely notional. You are the reporting entity. You are, in most small practices, also the AML compliance officer. You are the person who formed the view that the counter-party was acceptable. The civil penalty provisions reach individuals as well as bodies corporate, and beyond penalty there is professional-body exposure, insurer exposure, and the question of whether the matter should have proceeded at all.
We are not going to quote you a headline penalty number. Vendors do that because a large figure sells, and the figure moves with the penalty unit value. The exposure worth planning around is not the theoretical maximum. It is having no defensible answer to a question about a specific file.
What the public record would have told you
Here is the uncomfortable part. In nearly every case where a counter-party turns out to have been a problem, the fact was public before the settlement, and free to look up. It was simply not looked up, because looking it up for every active party every week is not something a person does.
- A sanctions listing on the Australian Sanctions Consolidated List, maintained by the Department of Foreign Affairs and Trade, published the day it takes effect.
- An external administration appointment on the ASIC insolvency register, usually within days of appointment.
- A personal insolvency on the AFSA register, from the date of the sequestration order or debt agreement.
- A director disqualification on the ASIC banned and disqualified persons register.
- A Federal Court proceeding, on the public cause list.
- An ABN cancellation or a change in entity status on the Australian Business Register.
Each of those is a five-minute lookup. That is the trap: individually trivial, collectively impossible. Forty active counter-parties across six registers, weekly, is 240 lookups a week. Nobody does that, and the practices that say they do are describing an intention.
What actually closes the gap
Two things, in order, and only the second is a product.
First, a written program. The Part A risk assessment and the Part B customer identification procedures are the obligation. No tool substitutes for them. If yours is not written, that is the first job, and the free readiness check below will tell you where you stand across twelve obligation domains in about two minutes.
Second, a monitoring layer that runs without you. This is what Ironbark is: a Trust Score per ABN built from six published sub-scores against Australian registers, refreshed continuously, with a timestamped citation on every field. Add the counter-parties you are exposed to and the change comes to you the day it appears on the public record, rather than the day somebody asks about it in a review.
The evidence trail matters as much as the alert. A score with a source and a date behind every component is something you can put in a working paper. A recollection that you checked is not.
What it is not
Ironbark is not an AML/CTF program, not a substitute for an AML compliance officer, not legal advice, and not an AUSTRAC determination. It is one layer. The weights, sources and refresh cadence of every sub-score are published at /methodology, including the change log, so the methodology can be assessed rather than taken on trust.
What it costs
A single check is $0.49 and the credit never expires. The free tier is ten checks a month and needs no card. Watching an active counter-party list continuously starts at $29 a month.
Every figure on this page is in Australian dollars and is the amount billed. IRONBARKTECH holds an ABN but is not registered for GST, so no GST is added at checkout and there is none to claim back.
Set against it: one loaded hour of casual administrative time costs more than the entry subscription, and it does not buy you a defensible record. The full cost comparison is at the pricing breakdown.
Find out where you actually stand.
Twelve questions, about two minutes, no login. You get a 0 to 100 readiness score, a breakdown by obligation, and your gaps in priority order. If verification is not your biggest gap, it will tell you that.
Frequently asked
Can an individual be penalised personally under the AML/CTF Act, or only the business?
Both are exposed. The civil penalty provisions in the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) apply to reporting entities, and the maximum penalty available against an individual is lower than the maximum against a body corporate but is not nominal. Officers can also be exposed where they were involved in the contravention. In a sole practice the distinction is thin in practice: you are the reporting entity, the AML compliance officer, and the person who signed off the file. Check the current penalty unit value and the applicable provisions with your own adviser rather than relying on a figure quoted on a vendor site.
I checked the counter-party when I onboarded them. Is that enough?
Onboarding is the start of the obligation, not the end of it. The Act requires ongoing customer due diligence: the risk profile has to be kept current for the life of the relationship, and a matter you opened in March can involve a counter-party whose circumstances changed in July. A single point-in-time check produces a file that was correct once. That is the gap continuous monitoring exists to close.
How would I even know a counter-party had been sanctioned or become insolvent?
The events are public the day they happen: a listing on the Australian Sanctions Consolidated List maintained by the Department of Foreign Affairs and Trade, an external administration appointment on the ASIC insolvency register, a personal insolvency on the AFSA register, a director disqualification on the ASIC banned and disqualified persons register, a Federal Court matter. None of them sends you a letter. Somebody has to look, on a cadence, at every active counter-party.
Is Ironbark an AML/CTF program?
No, and it does not claim to be. Ironbark is the verification and ongoing monitoring layer that sits inside a program. The written Part A risk assessment, the Part B customer identification procedures, the AML compliance officer, the reporting, the independent review and the training all remain your responsibility. What Ironbark removes is the manual rescreening work and the absence of a timestamped evidence trail. Full scope is published at /methodology.
What does it cost to close this gap?
A single check is $0.49 and credits never expire. The free tier is 10 checks a month with no card. Continuous monitoring of an active counter-party list sits on the $29 a month tier. Prices are in Australian dollars and are the amount billed: IRONBARKTECH holds an ABN but is not registered for GST, so no GST is added at checkout. Full pricing is at /pricing.
What if I have not written my AML/CTF program yet?
Then the verification layer is not your first problem, and it would be dishonest to sell it to you as one. Start with the free readiness check at /aml-readiness-check, which scores 12 obligation domains and returns the gaps in order. Verification is one of them, not all of them.