Tranche 2 AML Compliance: What Australian Firms Must Do Now
On 1 July 2026, Tranche 2 AML compliance became a live legal obligation for roughly 80,000 Australian businesses that had never faced financial crime regulation before. Lawyers, accountants, conveyancers, real estate agents and dealers in precious metals now answer to AUSTRAC. Consequently, the question facing most leadership teams is no longer whether the reforms apply — it is how quickly their people can be trained to meet them.
Last updated on July 21, 2026
Australia’s Largest Compliance Expansion in Twenty Years
Why 1 July 2026 Changed Everything for Professional Services
For nearly two decades, Australia’s anti-money laundering regime covered banks, casinos, remittance providers and digital currency exchanges. Professional services sat outside it. That gap made Australia an outlier among comparable economies, and the Financial Action Task Force said so repeatedly.
The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 closed the gap. As a result, an estimated 80,000 to 90,000 newly regulated businesses joined the regime on 1 July 2026 — the single largest expansion since the framework began in 2006.
The Enrolment Deadline Sitting on Your Desk Right Now
AUSTRAC opened enrolment on 31 March 2026. Newly captured entities must complete enrolment by 29 July 2026. Furthermore, firms that begin providing a designated service after that date must apply within 28 days of doing so.
Enrolment alone does not equal compliance. Rather, it is the administrative doorway into a regime that also demands a written program, a documented risk assessment, ongoing customer due diligence, reporting capability, seven-year record-keeping, and — critically — trained staff.
Why So Many Organisations Remain Underprepared
Professional services firms are not short of intelligence. However, they are short of infrastructure. A mid-sized conveyancing practice has no compliance function, no transaction monitoring system, and no institutional memory of financial crime obligations.
Moreover, the reforms arrived during a period of dense regulatory change across privacy, psychosocial safety and modern slavery. Many principals assumed the deadline would slip again, as it had for more than a decade. It did not.
Executive Summary
- What this blog covers: How Tranche 2 AML compliance works in practice, which businesses it captures, and how organisations build the staff capability the regime demands.
- Who it’s for: Principals, partners, practice managers, compliance officers and people and culture leaders across legal, accounting, conveyancing, property and precious metals businesses.
- Key regulatory context: AUSTRAC administers the AML/CTF Act 2006 as amended by the Amendment Act 2024. Obligations commenced 1 July 2026, with enrolment closing 29 July 2026.
- The central risk: Firms treat the AML/CTF program as a document to file rather than a set of behaviours frontline staff perform under commercial pressure.
- Primary action required: Appoint a management-level AML/CTF compliance officer, complete enrolment, and roll out role-specific training that staff can actually apply at the counter.
What Tranche 2 AML Compliance Actually Requires
Which Businesses the Reforms Capture
Capture depends on activity, not job title. Specifically, the legislation defines “designated services”, and any business providing one falls inside the regime regardless of how it describes itself.
Newly regulated sectors include real estate agents and property developers, conveyancers and settlement agents, legal practitioners, accountants, trust and company service providers, and dealers in precious metals and stones. Notably, a single partner performing one designated service can pull an entire firm into scope.
Tranche 1 Compared With Tranche 2: The Practical Difference
Existing reporting entities have carried these duties since 2006 and already hold the systems. Newly regulated firms start from zero. Therefore, the comparison below matters more than the legislative text.
Consider how the two groups differ in readiness:
- Existing entities: banks, credit unions, casinos, remittance dealers and virtual asset service providers, whose amended obligations commenced 31 March 2026.
- Newly captured entities: professional services and property businesses, whose obligations commenced 1 July 2026.
- Systems: established firms run automated screening and monitoring, while most new entrants rely on manual checks and spreadsheets.
- People: banks employ dedicated financial crime teams, whereas a suburban agency may have one part-time practice manager wearing the compliance hat.
- Culture: reporting a suspicious client feels routine in banking, yet deeply uncomfortable in a referral-driven professional practice.
The Core Obligations in Plain Language
Six duties sit at the centre of the regime. Firstly, enrol with AUSTRAC. Secondly, complete a documented money laundering and terrorism financing risk assessment. Thirdly, maintain a written AML/CTF program built on that assessment.
Fourthly, conduct customer due diligence before providing a designated service, including sanctions and politically exposed person screening. Fifthly, submit suspicious matter reports and threshold transaction reports. Finally, retain records for seven years and train every worker whose role touches a designated service.
Why Professional Services Became the Regulatory Target
The Gatekeeper Problem
Criminal proceeds rarely enter the economy through a bank teller. Instead, they arrive through a property settlement, a company formation, a trust structure or a high-value asset purchase. Each of those transactions passes through a professional adviser.
Australian property has long been identified as an attractive laundering channel, because real estate stores wealth, generates income and appreciates quietly. Accordingly, the professions that facilitate those transfers became the obvious regulatory gap to close.
- Property transactions move large sums with limited scrutiny of source of funds.
- Trust and company structures obscure beneficial ownership behind layers of entities.
- Legal professional privilege has historically complicated information sharing.
- Precious metals and stones convert cash into portable, high-value assets.
The Behavioural Gap Regulators Expect You to Close
Written programs are straightforward to produce. AUSTRAC publishes starter kits, and template providers have flooded the market. However, a template does not change what a sales agent does at 4pm on a Friday when a buyer offers to settle early through an unfamiliar third party.
Behaviour is where the regime succeeds or fails. Consequently, regulators increasingly examine whether staff recognised the indicator, escalated it, and documented the decision — not merely whether a policy existed.
Compliance professionals describe this as the difference between a paper control and a lived control. A paper control satisfies an auditor’s checklist. Meanwhile, a lived control changes a decision in the moment.
Where Firms Typically Fail First
Early enforcement patterns across comparable jurisdictions point to a consistent set of weak points:
- Customer due diligence performed after the engagement begins rather than before.
- Beneficial ownership recorded as the named client instead of the controlling individual.
- Suspicious matter reports delayed while partners debate commercial consequences.
- Training delivered once at induction and never refreshed against real scenarios.
Each failure looks administrative in isolation. Together, however, they form the pattern a regulator characterises as a systemic control breakdown.
The Legal Framework Behind the Reforms
What the Legislation Requires
The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 sets the framework, while the Amendment Act 2024 extends it to the newly captured professions. AUSTRAC administers both, maintains the Reporting Entities Roll, and issues sector-specific guidance.
Australian WHS law offers a useful parallel here. Under the WHS Act 2011, a PCBU must eliminate or minimise risk so far as is reasonably practicable, and officers must exercise due diligence rather than delegate responsibility downward. Similarly, an AML/CTF compliance officer must sit at management level and cannot outsource accountability to a software vendor.
What Non-Compliance Costs
Penalties under the AML/CTF Act are calculated in penalty units and applied per contravention. Maximum civil exposure reaches 100,000 penalty units for a body corporate and 20,000 penalty units for an individual, which translates into tens of millions of dollars at current values.
- Civil penalty proceedings brought by AUSTRAC in the Federal Court.
- Enforceable undertakings requiring remediation at the firm’s own cost.
- Written directions to appoint an external auditor or repeat a risk assessment.
- Criminal exposure for serious failures, including reckless identity verification.
- Professional consequences through state legal, conveyancing and real estate licensing bodies.
Penalties rarely arrive first, though. Typically, AUSTRAC opens with information requests and compliance assessments, which is precisely why documented evidence of training and escalation matters so much.
The Tipping-Off Prohibition
Disclosing to a customer that a suspicious matter report has been lodged is an offence in its own right. Staff must therefore understand not only when to escalate, but also what they cannot say afterwards.
This obligation creates genuine difficulty in relationship-driven professions. Indeed, an agent who has known a vendor for fifteen years needs clear scripting, not a policy clause, to navigate that conversation safely.
Leadership Accountability Under the New Regime
The Compliance Officer Is a Real Role, Not a Title
Legislation requires an AML/CTF compliance officer at management level. In smaller firms, that person is usually the principal or a senior partner. Crucially, the appointment carries expectations that go well beyond signing the program.
- Owning the risk assessment and reviewing it as the client base changes.
- Deciding, and documenting, whether an escalated matter becomes a report.
- Ensuring every worker in a designated service role completes training.
- Reporting program performance to the partnership or board on a set cycle.
How to Choose Your AML Training Approach
Training is a legislated element of the program, yet firms approach it very differently. Use the criteria below to select an approach that fits your risk profile:
- Generic off-the-shelf module: fast and inexpensive, but rarely reflects your designated services or client types. Suitable only as a baseline awareness layer.
- Sector-specific module: stronger fit for property or professional services, and better at teaching the red flags your people will actually encounter.
- Customised module built on your policies: highest evidentiary value, because scenarios mirror your escalation pathway and your systems.
- Live workshop only: valuable for partners, though difficult to evidence at scale and hard to repeat for new starters.
Whichever route you take, retain completion records. Our Anti-Money Laundering and CTF module and the specialist AML/CTF for Real Estate module both deliver SCORM-ready evidence of completion.
Tone From the Top Determines Reporting Behaviour
Workers escalate concerns when they believe leadership will back them. Where partners visibly weigh a fee against a red flag, staff learn quickly that reporting is unwelcome.
Leadership signals travel faster than policies. Therefore, the most valuable thing a principal can do in the first year is publicly support the first uncomfortable escalation, whatever it costs commercially.
Program-as-Written Versus Program-as-Practised
Defining the Gap
Every regulated firm now holds two programs. One lives in a document management system, written in legislative language and approved at a partners’ meeting. The other lives in daily habits: what staff check, what they let pass, and who they ask when unsure.
Regulators examine the second program. They interview frontline workers, review file notes, and test whether the documented process matches observed behaviour. Meanwhile, the written program serves mainly as the benchmark those observations are measured against.
A wide gap between the two is the clearest predictor of enforcement risk. Narrowing it is fundamentally a training and leadership exercise, not a drafting exercise.
Warning Signs the Gap Is Widening
Watch for these indicators across your practice:
- Staff cannot name the escalation pathway without opening the intranet.
- Due diligence files show identical wording copied across unrelated matters.
- Nobody has raised a single internal concern since commencement.
- Training completion sits below 100% for designated service roles.
Closing the Distance
Scenario-based learning closes the gap faster than policy circulation, because it rehearses judgement rather than recall. Workers practise the moment of doubt in a safe setting before meeting it commercially.
Regular refreshers matter equally. Money laundering typologies shift, and a module written in early 2026 will not describe the structuring patterns emerging by 2027.
The eCompliance Central Tranche 2 Readiness Framework
Readiness is achievable within a compressed timeframe, provided the sequence is right. The eight steps below move a firm from unregulated to defensible, and each one produces documented evidence a regulator can inspect.
An 8-Step Framework for Control
Map Your Designated Services
List every service line and test each against the legislative definitions. Scope determines everything that follows.
Appoint the Compliance Officer
Name a management-level individual and notify AUSTRAC. Give the role real authority and protected time.
Complete Enrolment
Register on the Reporting Entities Roll without delay. Late enrolment is itself a contravention.
Document the Risk Assessment
Assess customer types, delivery channels, jurisdictions and products. Show your reasoning, not just your conclusion.
Build the Written Program
Draft policies that answer the risks you identified. Generic templates fail this test quickly.
Embed Due Diligence Workflows
Wire identity and beneficial ownership checks into your existing matter-opening process. Bolt-on steps get skipped.
Train Every Frontline Role
Deliver scenario-based learning tailored to each role. Retain completion records as evidence.
Test, Review and Refresh
Sample files quarterly and update the program annually. Independent evaluation strengthens your position considerably.
Sequencing the Framework Under Time Pressure
Firms that are already past commencement should not restart at step one. Instead, complete enrolment immediately, then work backwards to scope and risk assessment while training runs in parallel. Regulators respond far better to demonstrable progress than to a perfect plan that has not begun.
What Failure Looks Like in Practice
The Chain Reaction
Enforcement seldom begins with a dramatic discovery. Usually, it begins with a routine information request that a firm cannot answer convincingly, because the underlying records were never created.
From there, consequences compound predictably:
- A due diligence file lacks source-of-funds evidence, so the firm cannot demonstrate the check occurred.
- AUSTRAC escalates to a formal compliance assessment, absorbing partner time and external legal spend.
- Findings flow to professional licensing bodies, insurers and lenders, damaging commercial relationships well beyond the penalty itself.
The Reputational Dimension
Financial crime findings attach to individuals as well as entities. Named partners carry the association into future roles, and referral networks reprice risk accordingly.
Clients notice too. Increasingly, corporate purchasers ask their advisers to evidence AML capability during panel reviews, which turns readiness into a commercial advantage rather than a cost.
Compliance Intelligence: Key Insights
Key Takeaways
- Map every service line against the designated services definitions before assuming you fall outside scope.
- Appoint a management-level AML/CTF compliance officer and give the role genuine authority.
- Complete AUSTRAC enrolment immediately if you have not already done so.
- Document your risk assessment so the reasoning, not merely the rating, is visible.
- Wire customer due diligence into matter opening rather than adding it as a separate step.
- Train every frontline role with scenarios drawn from your actual transactions.
- Review the program annually and retain seven years of records as the legislation requires.
Frequently Asked Questions
Scope and Deadlines
Does Tranche 2 apply to my accounting practice if I only do tax returns?
What is the deadline to enrol with AUSTRAC for Tranche 2 AML compliance?
Do sole traders and small firms have the same obligations as large ones?
Obligations and Accountability
Is staff training actually mandatory, or just recommended?
How does officer accountability compare to WHS obligations in Australia?
What should we do if a long-standing client triggers a red flag?
About the Author
This comprehensive article was actively developed by the expert content team at eCompliance Central, under the highly skilled direction of Dr. Denise Meyerson. Dr. Meyerson is the successful founder, a PhD-qualified educator, and a leading learning innovation specialist boasting over 35 years of deep, practical experience in learning and development, strict compliance, and vocational education. She has consulted extensively for leading global organisations and currently remains a highly recognised authority on behaviour-based compliance training within the complex Australian context. We firmly help ambitious organisations meet their strict compliance obligations through highly customised, deeply engaging, SCORM-ready training modules. We proudly build these robust tools precisely around your specific policies, your unique people, and your actual, daily operational realities. Note: We are professional educators, absolutely not legal advisors. For specific legal advice tailored precisely to your exact situation, please consult a fully qualified legal professional.
Get Your People Ready Before the Next Compliance Assessment
Programs pass audits only when people apply them. Our SCORM-ready AML/CTF modules are built around your designated services, your escalation pathway and your client base, so frontline staff recognise the red flags that matter in your business.
Explore Custom Compliance Solutions
Looking for a broader overview?
Read our definitive Australian Workplace Compliance Guide.