Australia’s financial intelligence regulator, the Australian Transaction Reports and Analysis Center (AUSTRAC), announced on 1 September 2026 the opening of an enforcement investigation into Western Union Financial Services Australia and its US parent, the Western Union Company.
For compliance officers, this is more than just another enforcement headline. The research paints a useful picture of what regulators consider when assessing whether an Anti-Money Laundering (AML) framework works in practice, not just whether policies exist.
The AUSTRAC Western Union Investigation Backstory
Western Union runs the world’s biggest international money-transfer networks. While, the scale of that is commercially valuable, it can equally pose as a major financial crime challenge.
Cross-border payment providers operate where large cash sums, international transfers, customers, and varied jurisdictions meet. This mix yields diverse risk profiles. Notably, AUSTRAC says clearly that international payment providers are vulnerable to criminal exploitation. However, its worries about Western Union didn’t come overnight.

In July 2025, AUSTRAC identified several concerns in the effectiveness of the company’s Customer Due Diligence (CDD), suspicious matter reporting, and AML and Counter-Terrorism Financing (CTF) program. The regulator then ordered Western Union Financial Services Australia to appoint an external compliance auditor. Subsequently, the audit findings escalated into an enforcement investigation.
We launched this investigation because we have serious concerns that Western Union has failed to adequately manage risks.
Although the company has not faced enforcement action, AUSTRAC underscores the significance of the investigation. Its CEO, Brendan Thomas, notes, “The risks facing this sector include terrorism financing, human trafficking, fraud and child sexual exploitation. We launched this investigation because we have serious concerns that Western Union has failed to adequately manage those risks.”
What is AUSTRAC Investigating?
AUSTRAC is pushing for one statement: that having a global AML control framework cannot excuse a company from being able to explain why its controls are appropriate to its own risks. Multinational firms often centralize technology, risk models, alert thresholds, and compliance decisions. However, businesses must remain accountable for meeting their jurisdiction-specific obligations.
AUSTRAC Identified Three Focus Areas in This Case:
- First, the adequacy of Western Union’s AML and CTF program in supporting its ability to identify, assess, and mitigate financial crime risks.
- Second is its transaction monitoring effectiveness. Notably, AUSTRAC wants to know if Western Union’s systems can identify known money-laundering typologies. This is especially true where activity pertains to terrorism financing and child sexual exploitation.
- Third is governance, including the influence of Western Union’s global headquarters on decisions affecting its Australian operation.
This is Not Western Union’s First AML Reckoning
In 2017, Western Union settled with the US Department of Justice (DOJ) and Federal Trade Commission (FTC) for $586 million. The company admitted criminal violations as part of its plea deal with the DOJ. This included failing to maintain an effective AML program and abetting wire fraud.
The conduct at issue relates to the failures of agents involved in suspicious transactions and consumer fraud. US authorities said Western Union had information pertaining to these suspicious activities but, in some cases, failed to take sufficient corrective action.
The lesson remains very relevant: having risk information is not the same as acting on it. Modern compliance programs generate large volume of alerts, customer risk scores, and management information. Regulators are increasingly looking for evidence that those signals result in decisions.
The Warning Hidden Inside Transaction Monitoring
During a broader supervisory campaign involving payment platforms, AUSTRAC found low levels of reporting of suspicious matters, weak transaction monitoring, and failures to identify high-risk customers.
There is no single indicator that can immediately point to criminal activity.
Some relevant transactions can also appear deceptively ordinary. AUSTRAC has identified common low-value transactions, often below AUD500, paired with factors such as sending funds to higher-risk jurisdictions and benign payment descriptions.
However, there is no single indicator that proves criminal activity. The point is that monitoring should combine transactional, behavioral and customer information rather than simplistic value thresholds. That is an important distinction for compliance teams, that a transaction-monitoring system should detect risk, not merely process rules.
How to Avoid Becoming AUSTRAC’s Next Investigation
To avoid regulatory scrutiny, there are several practical lessons from the Western Union case worth taking on board. These takeaways are especially critical as regulation intensifies, scrutiny of payment providers heightens, and there is greater emphasis on high-quality controls capable of identifying real-world criminal typologies.
AUSTRAC Western Union Investigation Practical Insights:
- Make sure controls are relevant to current risks: Risk assessments should take into account how customers use a specific product, the jurisdictions in which they are based, or where your highest-risk channels are located. Assess if risk assessment is directly incorporated into customer risk scoring, Enhanced Due Diligence (EDD) triggers, and transaction monitoring scenarios.
- Test transaction monitoring against known typologies: Monitoring controls should not outdated or copied from industry norms. Instead, it has to clearly show that it can detect suspicious activity specific to your business. Thus, it is crucial to test them against different scenarios, track the trends of false positives and false negatives, and make sure that each rule is fed with the right data.
- Treat suspicious matter reporting as an intelligence function: Regulators not only demand timely submission of reports, but also whether firms are identifying meaningful suspicious activity. Very low reporting volumes can be a warning sign if they are inconsistent with the firm’s risk profile. Businesses should benchmark reporting volumes against customer activity and risk exposure, and also do a quality-check on suspicious activity reporting narratives.
- Test remediation for effectiveness, not completion: Closing an audit finding because a policy was updated or a control was added does not prove that the underlying weakness has been fixed. Instead, implement post-remediation testing, assign clear control owners, track measurable outcomes, and independently verify that the risk has genuinely reduced before closing the issue.

Find out more AML news in ComplyCube’s Trust Edition newsletter. We explore the latest in developments across identity verification and AML globally.



