2026-04-02
Added · Updated
The Australian Transaction Reports and Analysis Centre (AUSTRAC) has directed MHITS Limited to appoint an external auditor to conduct a mandatory compliance audit under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. Triggered by suspected contraventions of sections 36 and 81 during the period from January 2024 to March 2026, the audit must comprehensively evaluate the entity’s transaction monitoring, suspicious matter reporting, enhanced customer due diligence, and governance frameworks within 180 days of auditor engagement. The appointed auditor must utilize risk-based sampling methodologies, assess the proactivity of compliance controls, and submit a detailed report containing findings and remedial recommendations directly to AUSTRAC.
Page 1 of 5 NOTICE TO APPOINT AN EXTERNAL AUDITOR TO CONDUCT COMPLIANCE AUDIT SUBSECTION 162(2) ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING ACT 2006 TO: MHITS Limited Level 1 Melbourne Building 43-45 Northbourne Avenue CITY ACT 2601 Attention: The Proper Officer
Page 3 of 5 Schedule Definitions The following definitions apply to this schedule. AML/CTF Act means the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 as in force during the Relevant Period. AML/CTF Rules 2007 means the Anti-Money Laundering and Counter-Terrorism Financing Rules Instrument 2007 (No. 1) as in force during the Relevant Period. Part A Program means Part A of: • a standard anti-money laundering and counter-terrorism program as defined in subsection 84(2) of the AML/CTF Act. Program means: • a standard anti-money laundering and counter-terrorism program as defined in subsection 84(1) of the AML/CTF Act. Relevant Period means the period 1 January 2024 to 30 March 2026. Sampling expectations:
Page 4 of 5 f. AUSTRAC recommends that the findings and insights from the audit report be actively considered as part of MHITS' preparation for the forthcoming reforms to the AML/CTF Act and Rules, scheduled to commence in 2026. The results should inform updates to compliance frameworks, risk assessments, and control measures to ensure compliance with the new AML/CTF regulatory requirements. Matters to be covered by the audit Money Laundering and Terrorism Financing Risk Assessment 4. Whether MHITS has during the Relevant Period complied with the requirements of Part 8.1 of the AML/CTF Rules 2007. Transaction Monitoring Program (TMP) 5. Assess whether MHITS’ Part A Program has during the Relevant Period complied with the requirements of paragraphs 15.4, 15.5, 15.6, and 15.7 of the AML/CTF Rules 2007. 6. Evaluate the effectiveness of its TMP, including: a. escalation procedures. b. alert review, prioritisation and typology coverage. c. change management and testing controls. 7. Evaluate the effectiveness of MHITS’ TMP to detect and escalate transactions indicative of the full array of financial crime risks the business is exposed to. The evaluation must cover specific ML/TF risk assessments, financial crime guides, and other AUSTRAC publications and associated red flags and typologies relevant to MHITS. This includes Child Sexual Exploitation risks. 8. When determining MHITS’ compliance with the matters outlined in paragraphs 3, 4 and 5 above, include the methodology for conducting the audit, in addition to sampling and data collection. Suspicious Matter Reporting (SMR) 9. Assess whether MHITS has during the Relevant Period complied with the requirements of section 41 of the AML/CTF Act. a. Evaluate whether MHITS’ processes support timely and risk-based SMR submissions, across all ML/TF risks and crime types it is exposed to. b. Include testing of alerts and case escalations c. Evaluate the timeliness of SMRs. This includes evaluating whether SMRs were initiated independently or in response to queries or notices from AUSTRAC or other Government agencies and identifying patterns that may indicate a reactive rather than proactive compliance posture. d. Review matters that were escalated for review but did not result in SMRs being submitted, including analysis of decision-making processes and documentation to determine whether suspicion should reasonably have been formed under section 41. e. Sample must include SMRs tied to high-risk customers and jurisdictions. Enhanced Customer Due Diligence (ECDD) Program 10. Whether MHITS’ Part A Program has during the Relevant Period complied with the requirements of paragraphs 15.8, 15.9, 15.10 and 15.11 of the AML/CTF Rules 2007.
Page 5 of 5 11. When determining MHITS’ compliance with the matters outlined in paragraph above: a. the methodology for conducting the audit by the external auditor must include sampling and data collection; and b. the external auditor must have regard to how MHITS met its obligations with reference to customers subject to SMRs, PEPs and high-risk corridors to which MHITS was required to apply its ECDD Program during the Relevant period. 12. The audit should assess MHITS’ policies and procedures for off boarding high-risk customers, including those subject to SMRs and must review decision making, consistency and timeliness associated with off boarding decisions. Compliance with ongoing customer due diligence (OCDD) 13. Whether MHITS has complied with section 36 of the AML/CTF Act during the Relevant Period. Governance and Oversight 14. Review the effectiveness of MHITS’ AML/CTF governance during the Relevant Period, in accordance with section 81 of the AML/CTF Act including: a. Internal audit independence and coverage of internal audits b. Board and executive oversight c. Effectiveness of quality assurance over the TMP and prevention and detective controls.