Preparing AUSTRAC Online for the New TTR & SMR Forms: A Practical Checklist
On 1 July 2026, AUSTRAC releases redesigned Threshold Transaction Report (TTR) and Suspicious Matter Report (SMR) forms. They are not a cosmetic refresh. The new AML/CTF Rules expand the details you must report in both form types, and the change lands at the same moment the "Tranche 2" reforms pull whole new industries into the regime. If you lodge reports through AUSTRAC Online, the practical question is simple: is your team, your data, and your system ready to produce accurate reports against the new fields? This checklist walks a compliance team through getting there.
The short version
- From 1 July 2026, new TTR and SMR forms go live in AUSTRAC Online, with expanded reportable details in both.
- Entities enrolled on or before 30 March 2026 can transition anytime between 1 July 2026 and 30 March 2029; those enrolling after 30 March 2026 must use the new forms from day one.
- Core deadlines are unchanged: TTRs within 10 business days, SMRs within 3 business days (24 hours for terrorism financing).
- The work is mostly data readiness: mapping current fields to the new ones and closing gaps in what you collect and verify.
- Strong KYC/KYB, sanctions and PEP screening, and transaction monitoring feed the accurate identity and activity data these reports depend on.
A note on sources. This guide is current as of July 2026 and draws on AUSTRAC's published guidance, including its page on changes to transaction reporting from 1 July 2026. AUSTRAC may update forms and Rules; always confirm the exact field lists at austrac.gov.au. Spotted something out of date? Flag it via didit.me/contact.
What is actually changing
Two things are moving at once, and it helps to keep them separate.
First, the forms themselves. AUSTRAC is rolling out new TTR and SMR forms designed to improve data quality and give a more streamlined experience inside AUSTRAC Online. The redesign comes with expanded reportable details, so the same underlying transaction now requires more (and more structured) information than the old form captured.
Second, the scope of who reports. The changes sit within the broader Tranche 2 reforms amending the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. From 1 July 2026, "Designated Non-Financial Businesses and Professions" (DNFBPs) enter the regime for specified designated services. That includes lawyers, accountants, conveyancers, real estate professionals, dealers in precious metals and stones, and trust and company service providers (TCSPs).
The two headline report types remain:
| Report | Trigger | Deadline |
|---|---|---|
| TTR | A cash transaction of AUD 10,000 or more (or foreign-currency equivalent) | Within 10 business days |
| SMR | Forming a suspicion about a matter (money laundering, fraud, other offences) | Within 3 business days |
| SMR (terrorism financing) | Suspicion relating to terrorism financing | Within 24 hours |
The deadlines have not changed. What changes is the volume and structure of the detail you provide inside each report.
Step 1: Map your current reporting
Before touching the new forms, document how reporting works today. You cannot close gaps you have not measured.
- List every scenario that triggers a TTR or SMR in your business, and who owns each one.
- Note where the data for each field currently comes from — core system, CRM, onboarding record, or manual entry.
- Record your current lodgement path: direct keying in AUSTRAC Online, file upload, or system-to-system reporting via the AUSTRAC Online channel.
- Capture your average and peak monthly report volumes, so you can size the testing and training effort realistically.
Step 2: Run a data-field gap analysis
This is the heart of the work. Because the new forms expand reportable details, treat readiness as a field-mapping exercise.
- Obtain the new form's field list from austrac.gov.au and lay it beside the data you capture today.
- Flag each new or expanded field as: already captured, captured but not structured, or not captured at all.
- For every "not captured" field, trace it back to the point in your process where that data should have been collected — usually customer onboarding or transaction capture.
- Pay attention to identity and party details. Expanded reporting typically wants cleaner, more complete information about the persons and entities involved in a transaction — exactly the data a robust identity-verification process produces at onboarding.
Where Didit helps: Many gaps trace back to thin or unverified customer data. Didit's KYC and KYB flows capture verified identity attributes for individuals and businesses at onboarding, so the party details behind a TTR or SMR are complete and consistent rather than reconstructed under a deadline. Didit does not lodge reports for you — it helps you hold accurate, verified data ready to populate them.
Step 3: Update systems and integrations
Once you know the field deltas, plan the technical changes.
- If you lodge via file upload or a reporting integration, confirm whether your file schema or API mapping must change to match the new form structure, and schedule that work well before your chosen transition date.
- Add capture points for any newly required fields in your onboarding and transaction systems, so staff are not forced into free-text workarounds.
- Check validation rules: the new forms are meant to improve data quality, so expect stricter formatting expectations on identifiers, dates, and amounts.
- Version-control the change and keep a record of what you altered and when — useful evidence of a diligent transition.
Step 4: Train your staff
A better form only produces better data if the people filling it in understand it.
- Brief report preparers on the new fields, what each one means, and where to source it.
- Refresh the suspicion-formation process for SMRs — the trigger and the 3-business-day (or 24-hour) clock are unchanged, but the detail expected has grown.
- Run a short worked example end to end, from trigger to lodged report, on the new layout.
- Make sure new DNFBP-sector staff, if that applies to you, understand these are legal obligations, not optional paperwork.
Step 5: Test in AUSTRAC Online
Do not let go-live be the first time your team sees the new form in production.
- Have preparers walk the new form inside AUSTRAC Online before you commit real reports to it, so navigation and field placement are familiar.
- If you use system-to-system lodgement, validate a full test cycle against the new schema and confirm acknowledgements come back clean.
- Reconcile a sample of test reports field by field against your source data to catch mapping errors early.
- Confirm every preparer has correct AUSTRAC Online access and permissions.
Step 6: Choose your transition date
Timing depends on when you enrolled with AUSTRAC.
| Your situation | When you use the new forms |
|---|---|
| Enrolled on or before 30 March 2026 | Transition any time between 1 July 2026 and 30 March 2029 |
| Enrol after 30 March 2026 | Must use the new forms from 1 July 2026 |
If you have the flexibility of the transition window, pick a date deliberately. Move once your gap analysis is closed, systems are updated, staff are trained, and testing is clean — but do not drift toward 30 March 2029 without a plan. An earlier, well-prepared switch reduces the risk of running two processes in parallel for years.
Step 7: Strengthen the data that underpins accurate reports
Accurate reports start long before the form. The quality of a TTR or SMR is only as good as the identity and activity data behind it.
- Verify identity at onboarding (KYC). Confirmed identity documents and biometric checks give you reliable party details for every future report.
- Verify businesses (KYB). For entity customers — and for the TCSP and real-estate services now in scope — knowing the business and its beneficial owners underpins both onboarding and reporting.
- Screen against sanctions and PEP lists. Screening surfaces the risk indicators that often sit behind a suspicious matter.
- Monitor transactions. Ongoing monitoring is what actually detects the unusual activity that leads to an SMR, and flags cash movements relevant to TTRs.
Where Didit helps: Didit brings KYC, KYB, sanctions and PEP screening, age verification, and transaction monitoring together behind one API, with public per-check pricing and 500 free verifications a month. It helps you collect and verify the identity data and detect the activity that make accurate TTRs and SMRs possible. It does not lodge reports with AUSTRAC on your behalf — that step stays with you inside AUSTRAC Online.
Your readiness at a glance
- [ ] Current reporting mapped and owners assigned
- [ ] Gap analysis complete against the new field list
- [ ] Systems and integrations updated for new/expanded fields
- [ ] Staff trained on the new forms and unchanged deadlines
- [ ] Tested in AUSTRAC Online end to end
- [ ] Transition date chosen and documented
- [ ] Identity, screening, and monitoring data quality strengthened
Get the data right and the new forms become a formatting change rather than a scramble. Start with the gap analysis, close it at the source, and choose your transition date on your own terms.
---
Building the identity and monitoring foundation behind accurate reporting? Didit offers KYC, KYB, AML sanctions and PEP screening, age verification, and transaction monitoring through a single API — so the verified data behind your TTRs and SMRs is ready when you need it.
This article is general information, not legal advice. Reporting obligations depend on your specific circumstances — confirm yours with AUSTRAC or your professional adviser before acting.
