Calder & Vance International Sanctions & Compliance Counsel

Licensing & Authorizations · Australia

Payment authorisations under Australia: a compliance guide

A payments team at a multinational reviews its end-of-month processing queue. One beneficiary is domiciled in a jurisdiction under Australia's autonomous sanctions regime. The bank flags the instruction. The treasury function asks: is there a path to authorise this payment? Does an exemption already apply, or is a formal authorisation required from the Department of Foreign Affairs and Trade? The answer determines whether a commercial obligation is met or a relationship is severed.

Under Australia's autonomous sanctions regime (the Autonomous Sanctions Act and the associated regulations administered by DFAT – the Department of Foreign Affairs and Trade), making a payment that is a "controlled financial service" to or for the benefit of a designated person or entity is prohibited unless a relevant exemption or a ministerial authorisation applies. As of June 2026, the authorisation mechanism is narrow, the exemptions are defined in the regulations, and the compliance burden falls on the payer – not the bank alone.

This guide walks through the governing authority, the authorisation procedure, the cross-regime comparisons that matter for businesses operating across multiple jurisdictions, and the risk flags that counsel typically flags before any restricted payment is cleared.

Step 1: Identify the governing authority and legal basis

Australia's payment authorisation questions arise under DFAT's administration of the Autonomous Sanctions Act and the regime-specific regulations – the governing authority is DFAT, not a financial regulator or a customs body. DFAT maintains the Consolidated List (Australia's national designation list) and issues guidance on what constitutes a prohibited dealing with a designated person.

The Autonomous Sanctions Act provides the legislative foundation. Beneath it sit regime-specific autonomous sanctions regulations, each covering a different thematic or country programme. Payments caught by those regulations include transfers that constitute a "controlled financial service" – broadly defined to cover financial services provided to, or for the benefit of, a designated person or entity, or to a person or entity acting on their behalf.

The practical first step is therefore twofold. First, confirm whether the beneficiary – or any intermediate or ultimate party in the payment chain – appears on Australia's Consolidated List, or is owned or controlled by a listed person. Second, determine which regime-specific regulation governs the payment, because the exemptions and authorisation routes can differ between programmes. In our experience, businesses that skip this sequencing frequently conflate a general obligation with a regime-specific carve-out that may not apply to their facts.

A word on the cross-border dimension: a business subject to both Australian and US sanctions obligations faces a materially different threshold test. Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) operates mechanically and without regard to control. Australia's ownership-and-control analysis is less rigidly codified at the 50 percent line; the regulations look to whether a person is "acting on behalf of" or "controlled by" a designated person, which is a more contextual inquiry. A payment that appears clear under OFAC's arithmetic test may still be caught under the Australian regime's control analysis – and vice versa.

Step 2: Determine whether an exemption already covers the payment

Before applying for a ministerial authorisation, a payer must assess whether the payment falls within one of the existing regulatory exemptions – because if it does, no separate authorisation is required and applying for one is unnecessary delay. Exemptions in the Australian autonomous sanctions regulations typically cover categories such as humanitarian payments, certain consular dealings, and payments made in satisfaction of obligations that pre-date a designation.

Exemption analysis is not a box-tick. Each exemption has its own conditions: some require that the funds reach a specified category of recipient (a UN agency, a humanitarian organisation), others that the payment relates to a defined purpose. A business must satisfy every condition, not merely the general category. If a single condition is missed, the transaction is not covered by the exemption and the prohibition applies in full.

Where an exemption is potentially available, the evidential standard matters. Businesses should document the basis for the exemption assessment at the time of the payment, not retrospectively. In our cross-border practice, we regularly advise clients that a well-constructed contemporaneous exemption file – setting out the identification of the parties, the regulatory basis for the exemption, the conditions assessed, and the conclusion – is the most effective mitigant if the payment is later questioned by DFAT or the Australian Federal Police.

The position under comparable regimes is instructive. Under OFSI (the UK's Office of Financial Sanctions Implementation), general licences (standing authorisations that permit a defined category of transactions without a separate application) serve a similar function to the Australian regulatory exemptions: they pre-authorise defined categories of activity. Under the EU autonomous sanctions regulations, the equivalent instrument is a competent-authority licence at member-state level, which may carry different scope and duration. The Australian exemption structure is statutory rather than licence-based, which means there is no document to exhibit to a bank – the exemption either applies on the facts or it does not.

Step 3: Prepare and submit a ministerial authorisation request

Where no exemption covers the payment, the path is a ministerial authorisation under the Autonomous Sanctions Act. The decision-maker is the Minister for Foreign Affairs (in practice, the application is processed by DFAT's Sanctions and Transnational Crime Branch). Unlike OFAC's specific-licence process, which is managed by a dedicated licensing division with published processing guidance, or OFSI's specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) process with published turnaround targets, the Australian ministerial authorisation is a genuinely ministerial function. Processing timelines are not codified and can vary materially depending on the sensitivity of the programme, the completeness of the submission, and the policy context.

An effective authorisation request contains, at minimum: a clear identification of all parties to the proposed payment, a description of the payment's purpose and commercial or humanitarian basis, identification of the specific prohibition engaged and the reason no exemption applies, supporting documentation for each factual assertion, and the proposed conditions under which the authorised payment would be made. Thin applications – those that merely identify the parties and state the amount – are routinely returned for supplementation, which extends the timeline.

What conditions might DFAT attach to an authorisation? In practice, conditions have included requirements that funds be paid into a designated account, that evidence of end-use be provided within a specified period, and that the authorisation not be used for a broader purpose than stated. We have acted for clients in preparing authorisation requests across several programme categories. The pattern we observe is consistent: the more precisely the request is tailored to the specific facts and the more proactively the business identifies potential DFAT concerns, the more efficiently the process moves.

The position for a business also subject to US rules deserves a paragraph of its own. OFAC's specific-licence process is managed through an online portal with published categories of general licences that may already cover the transaction. BIS licensing under the EAR follows a similar structured process. If the payment has a US nexus – a US-person participant, a USD clearing leg, a US-origin good or technology embedded in the underlying transaction – the business may need a parallel OFAC or BIS authorisation. A ministerial authorisation from DFAT does not shield US-nexus exposure under OFAC, and an OFAC general licence does not satisfy the Australian prohibition. Both must be cleared independently. This is a point that frequently catches in-house teams who treat one clearance as global cover.

How does Australia's ownership-and-control test compare with other regimes?

The ownership-and-control question is often the threshold issue for payment authorisations: is the beneficiary itself caught, even if it is not on the Consolidated List? Australia's autonomous sanctions regulations address this through the concept of a person "acting on behalf of" or "controlled by" a designated person. The test is fact-intensive and contextual; it does not resolve to a single numerical threshold in the way that OFAC's 50 percent rule does.

Under OFSI and the EU regime, the ownership-and-control test is similarly broader than a simple arithmetic threshold. OFSI guidance makes clear that a non-designated entity can be caught if a designated person holds it directly or indirectly, or exercises control over it – and control is assessed by reference to a range of factors including the ability to give binding instructions to the board, to appoint or remove a majority of directors, or to direct the use of financial resources. The EU's approach is materially similar, with the EU General Court having confirmed that control is assessed by reference to all relevant circumstances and not solely ownership percentage.

For a business making payment decisions under multiple regimes simultaneously, the practical implication is that the entity screening step cannot stop at the Consolidated List check. The business must trace the ownership and control chain and apply the specific test of each relevant regime. A counterparty that clears the Australian Consolidated List and sits below the 50 percent OFAC line may still be caught by the OFSI control test, or vice versa. Where the regimes conflict – one prohibits, another permits – the stricter prohibition governs the business's exposure under that regime.

Step 4: Manage banking intermediaries and document the chain

A payment authorisation clears the payer's exposure. It does not automatically clear the correspondent bank's exposure. This is one of the most practically significant gaps in cross-border payment authorisation advice, and it is a risk flag we raise routinely with treasury and payments clients.

A correspondent bank processing an international payment cleared by an Australian ministerial authorisation is not itself acting under that authorisation unless its own exposure – under its own applicable regime – is separately addressed. A US correspondent bank clearing a USD payment has its own OFAC exposure. A European bank has its own EU sanctions exposure. Each institution must conduct its own assessment. The payer's authorisation is not portable across clearing chains.

The practical consequence is that a business with a DFAT ministerial authorisation in hand may still find that its correspondent bank declines to process the payment. Addressing this requires either pre-clearing the payment chain – sharing the authorisation and the underlying analysis with correspondent banks before initiating the transaction – or structuring the payment to avoid the legs that raise independent concerns for the correspondents. Neither is a trivial exercise, and neither should be left until settlement day.

Documentation of the entire chain is equally important. Record-keeping obligations under the Autonomous Sanctions Act are supported by DFAT guidance, and DFAT can require production of documentation in the course of an investigation. A complete payment file should include: the initial screening result and the date it was run, the exemption analysis or the ministerial authorisation, correspondence with correspondent banks, the payment instruction and the confirmation of execution, and any end-use evidence required by the authorisation conditions. In our experience, a well-ordered payment file resolves DFAT inquiries quickly; a poorly documented one extends them.

Step 5: Recognise the risk flags that warrant early counsel involvement

Not every payment question requires outside counsel. But several patterns in the Australian payment authorisation space reliably indicate that a matter has moved beyond what an in-house team should handle alone. Identifying those patterns early preserves options.

The first flag is complexity in the ownership chain. Where the beneficiary is held through multiple intermediate layers, where a listed person's ownership sits near but below the threshold, or where the business cannot obtain reliable corporate records for intermediate entities, the risk of misclassification is high. An incorrect determination – that a payment is not caught – exposes the business to enforcement under the Autonomous Sanctions Act.

The second flag is a multi-regime payment. Where the same transaction engages Australian sanctions, OFAC, OFSI, and EU rules simultaneously, the legal analysis is not additive – it is multiplicative. Each regime has its own prohibitions, its own exemptions, and its own authorisation route. Missing one is sufficient for an apparent violation under that regime.

The third flag is a time-sensitive commercial deadline. Payment authorisation processes – particularly ministerial authorisations – cannot be shortened by urgency. A business that arrives at a Friday afternoon with a Monday payment deadline and no authorisation in place is in a materially worse position than one that identified the issue two weeks earlier. The time to involve counsel is when the transaction is first flagged, not when the window has closed.

A fourth flag is a prior history of apparent violations. Where a business has previously made a payment that may not have been properly authorised, any new authorisation request is assessed in a context where DFAT may already be aware of, or may inquire into, prior conduct. A VSD (voluntary self-disclosure to a regulator) in relation to the prior payment may be the appropriate step before seeking fresh authorisation. The two questions – the past exposure and the future authorisation – interact, and they should be managed together.

The position above covers the standard path. Your facts – the counterparty structure, the payment chain, the regime in play, and the commercial timeline – change the analysis. If a payment has already been flagged, or a prior transaction may not have been properly authorised, an early review preserves options that narrow over time. Contact Calder & Vance at info@caldervance.com.

Common mistakes and misconceptions in Australian payment authorisations

One persistent misconception is that Australia's autonomous sanctions regime is less strict than the US or EU equivalents, and that the compliance burden is correspondingly lighter. This is not accurate. The Autonomous Sanctions Act carries criminal penalties for individuals and significant civil exposure for corporate entities. The fact that DFAT enforcement actions are less publicly profiled than OFAC penalty notices does not mean the risk is lower – it means the enforcement posture differs.

A second common error is treating the bank's screening as the compliance function. Banks screen for their own exposure. A bank declining to flag a payment does not mean the payment is authorised; it means the bank did not identify a concern on its own systems at that moment. The legal obligation to determine whether a payment is prohibited, and whether an authorisation is needed, rests with the payer.

A third error is applying the exemption analysis once and treating it as permanent. Designations change. A person who was not on the Consolidated List when the business last screened may have been added. DFAT updates the Consolidated List without advance notice, and a payment made the day after a new designation is added is caught by the prohibition even if the counterparty was clean on the previous screen. Ongoing monitoring – not point-in-time screening – is the appropriate standard for recurring payment relationships with elevated-risk counterparties.

If you are approaching an Australian payment authorisation with the assumption that the regime is a lighter-touch version of OFAC or OFSI, that assumption should be tested against the actual regulatory text and DFAT's published guidance before any payment is cleared on that basis. We regularly advise clients on exactly this comparison and the gaps it reveals.

Related practices

Frequently asked questions

What are the steps to authorise a restricted payment under Australia?
The steps are: first, identify whether the beneficiary or any party in the payment chain is on Australia's Consolidated List or is owned or controlled by a designated person; second, assess whether a regulatory exemption under the applicable autonomous sanctions regulations already covers the payment; third, if no exemption applies, prepare and submit a ministerial authorisation request to DFAT; fourth, address the independent sanctions exposure of any correspondent bank in the payment chain; and fifth, document the entire assessment and the authorisation before executing the payment. Each step requires contemporaneous evidence, and the sequence cannot be short-circuited by commercial urgency.
What is the most common mistake in payment authorisations?
The most common mistake is treating the bank's decision to process the payment as the compliance determination. Banks screen for their own exposure and may process a payment without having conducted the full analysis that the payer is independently required to carry out. A payment that clears a bank's systems is not thereby authorised under the Autonomous Sanctions Act. The legal obligation to identify a potential prohibition and to obtain an authorisation rests with the payer, not with its financial institution. A secondary common error is conducting the ownership-and-control analysis only at the first layer of the beneficiary's corporate structure and missing an indirect holding that triggers the prohibition.
How does Australia differ from other regimes here?
Australia's ministerial authorisation is a genuinely government-level decision, unlike OFAC's specific-licence process (handled by a dedicated licensing division with published procedural guidance) or OFSI's specific-licence route (with published turnaround targets). Processing timelines under the Australian regime are not codified. Australia's Consolidated List also updates independently of the UN Consolidated List, OFAC's SDN List, and OFSI's designations, meaning a party can be listed under one regime and not under another. A business subject to multiple regimes must screen against each list separately and cannot treat clearance under one as global authority.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.