AML/CTF Reforms: A Sales Opportunity for MSPs

Australia’s AML/CTF reforms have created a new compliance headache for many small and medium businesses. For MSPs this is a practical opening to talk about privacy, cyber risk and SMB security controls.

From 1 July 2026, Australia’s anti-money laundering and counter-terrorism financing rules expanded to cover certain designated services provided by:

  1. Lawyers,
  2. Conveyancers,
  3. Accountants,
  4. Real estate professionals,
  5. Dealers in precious metals and stones, and
  6. Trust and company service providers.

Affected businesses may need to enrol with AUSTRAC, assess money laundering and terrorism financing risk, conduct customer due diligence, report suspicious matters, keep records and train staff.

But there is another issue sitting directly alongside it. When a business becomes an AML/CTF reporting entity, the Privacy Act applies to its handling of personal information for AML/CTF purposes, even if the business is small enough to otherwise be exempt.

What changed within Australia’s AML/CTF regime?

For years, most small businesses have been exempt from the Privacy Act where annual turnover is $3 million or less. 

So a small firm that was previously outside the Privacy Act can now find itself subject to the Australian Privacy Principles, including APP 11, which requires reasonable steps to protect the personal information you hold, and the Notifiable Data Breaches scheme, which requires you to notify the regulator and affected individuals of eligible breaches.

anti money laundering impacts

The reforms expand Australia’s AML/CTF regime to many professional services firms for the first time, requiring them to capture more information, and therefore protect it. AUSTRAC expects tens of thousands of new reporting entities, many of them SMBs, which starts conversations about how these small firms manage identity data, access, retention and cyber risk.

For those involved, obligations can include enrolment, risk assessment, customer due diligence, sanctions screening, reporting, record-keeping and staff training. While it would be a mistake to try to own those obligations, we can support the related privacy and security uplift.

Why should you care about the AML/CTF reforms?

These reforms give MSPs a legitimate reason to speak with both prospects and existing clients in affected sectors, including accounting, legal, conveyancing and real estate firms. Many will be trying to understand whether their current systems are good enough for new compliance, privacy or insurance expectations.

For new clients, the reforms create a clear opening for a practical security review. For current ones, they provide a natural upsell path into stronger account protection, device management, backup, retention, documentation and baseline certification support.

An estimated 100,000 SMBs have an annoying new problem. You can help them.

The commercial opportunity is helping affected SMBs turn a new compliance burden into practical, documented improvements to their security baseline.

Meanwhile, attacks are becoming more frequent

This arrives just as the threat environment gets worse. In June, the Five Eyes cyber security agencies issued a joint warning that artificial intelligence is accelerating attacks, and that the window between a weakness being found and exploited is shrinking to months rather than years. Automated tools now scan continuously for the least-protected business connected to a target, and smaller professional firms, holding freshly expanded piles of client identity data, are an attractive target.

Packaging the security opportunity: SMB1001

The reforms create several practical ways to start commercial conversations without positioning ourselves as compliance advisers. The most obvious pathway is SMB1001, offering a practical, tiered pathway that demonstrates reasonable efforts to secure data. 

You might consider packaging SMB1001 – or the controls it requires – in different ways:

How to package the security opportunity

We are not promising compliance; we are helping clients show they are taking practical steps to protect the extra information they now hold.

Turn compliance pressure into revenue

The AML/CTF reforms will push many SMBs to collect, store and protect more sensitive client information than before. For MSPs, this is a timely opportunity to connect compliance pressure with practical security improvements that clients can understand, budget for and evidence.

Now is the time to identify affected clients and prospects, start the conversation, and package a clear security uplift that helps them protect the information they are now expected to manage.

 

Learn more from Cybercert including a white paper download on the AML/CTF Privacy Act.

 

NOTE: Not every business in the aforementioned sectors will be captured. The obligations generally apply when a firm provides a “designated service”, such as handling client money or property, transferring real estate, or setting up companies and trusts. Clients should get specialist advice to confirm whether the regime applies.

Related Articles

You may also be interested in...