Blog > AML Tranche 2 Explained: AUSTRAC Obligations for Australian Firms

AML Tranche 2 Explained: AUSTRAC Obligations for Australian Firms

Tranche 2 AML Compliance: Train Staff | eCompliance Central
Financial Crime & Risk

Tranche 2 AML Compliance: What Australian Firms Must Do Now

On 1 July 2026, Tranche 2 AML compliance became a live legal obligation for roughly 80,000 Australian businesses that had never faced financial crime regulation before. Lawyers, accountants, conveyancers, real estate agents and dealers in precious metals now answer to AUSTRAC. Consequently, the question facing most leadership teams is no longer whether the reforms apply — it is how quickly their people can be trained to meet them.

Last updated on July 21, 2026

Australia’s Largest Compliance Expansion in Twenty Years

Why 1 July 2026 Changed Everything for Professional Services

For nearly two decades, Australia’s anti-money laundering regime covered banks, casinos, remittance providers and digital currency exchanges. Professional services sat outside it. That gap made Australia an outlier among comparable economies, and the Financial Action Task Force said so repeatedly.

The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 closed the gap. As a result, an estimated 80,000 to 90,000 newly regulated businesses joined the regime on 1 July 2026 — the single largest expansion since the framework began in 2006.

The Enrolment Deadline Sitting on Your Desk Right Now

AUSTRAC opened enrolment on 31 March 2026. Newly captured entities must complete enrolment by 29 July 2026. Furthermore, firms that begin providing a designated service after that date must apply within 28 days of doing so.

Enrolment alone does not equal compliance. Rather, it is the administrative doorway into a regime that also demands a written program, a documented risk assessment, ongoing customer due diligence, reporting capability, seven-year record-keeping, and — critically — trained staff.

Why So Many Organisations Remain Underprepared

Professional services firms are not short of intelligence. However, they are short of infrastructure. A mid-sized conveyancing practice has no compliance function, no transaction monitoring system, and no institutional memory of financial crime obligations.

Moreover, the reforms arrived during a period of dense regulatory change across privacy, psychosocial safety and modern slavery. Many principals assumed the deadline would slip again, as it had for more than a decade. It did not.

Executive Summary

  • What this blog covers: How Tranche 2 AML compliance works in practice, which businesses it captures, and how organisations build the staff capability the regime demands.
  • Who it’s for: Principals, partners, practice managers, compliance officers and people and culture leaders across legal, accounting, conveyancing, property and precious metals businesses.
  • Key regulatory context: AUSTRAC administers the AML/CTF Act 2006 as amended by the Amendment Act 2024. Obligations commenced 1 July 2026, with enrolment closing 29 July 2026.
  • The central risk: Firms treat the AML/CTF program as a document to file rather than a set of behaviours frontline staff perform under commercial pressure.
  • Primary action required: Appoint a management-level AML/CTF compliance officer, complete enrolment, and roll out role-specific training that staff can actually apply at the counter.
Australian conveyancer verifying client identification documents as part of Tranche 2 AML compliance obligations

What Tranche 2 AML Compliance Actually Requires

Which Businesses the Reforms Capture

Capture depends on activity, not job title. Specifically, the legislation defines “designated services”, and any business providing one falls inside the regime regardless of how it describes itself.

Newly regulated sectors include real estate agents and property developers, conveyancers and settlement agents, legal practitioners, accountants, trust and company service providers, and dealers in precious metals and stones. Notably, a single partner performing one designated service can pull an entire firm into scope.

Tranche 1 Compared With Tranche 2: The Practical Difference

Existing reporting entities have carried these duties since 2006 and already hold the systems. Newly regulated firms start from zero. Therefore, the comparison below matters more than the legislative text.

Consider how the two groups differ in readiness:

  • Existing entities: banks, credit unions, casinos, remittance dealers and virtual asset service providers, whose amended obligations commenced 31 March 2026.
  • Newly captured entities: professional services and property businesses, whose obligations commenced 1 July 2026.
  • Systems: established firms run automated screening and monitoring, while most new entrants rely on manual checks and spreadsheets.
  • People: banks employ dedicated financial crime teams, whereas a suburban agency may have one part-time practice manager wearing the compliance hat.
  • Culture: reporting a suspicious client feels routine in banking, yet deeply uncomfortable in a referral-driven professional practice.

The Core Obligations in Plain Language

Six duties sit at the centre of the regime. Firstly, enrol with AUSTRAC. Secondly, complete a documented money laundering and terrorism financing risk assessment. Thirdly, maintain a written AML/CTF program built on that assessment.

Fourthly, conduct customer due diligence before providing a designated service, including sanctions and politically exposed person screening. Fifthly, submit suspicious matter reports and threshold transaction reports. Finally, retain records for seven years and train every worker whose role touches a designated service.

Why Professional Services Became the Regulatory Target

The Gatekeeper Problem

Criminal proceeds rarely enter the economy through a bank teller. Instead, they arrive through a property settlement, a company formation, a trust structure or a high-value asset purchase. Each of those transactions passes through a professional adviser.

Australian property has long been identified as an attractive laundering channel, because real estate stores wealth, generates income and appreciates quietly. Accordingly, the professions that facilitate those transfers became the obvious regulatory gap to close.

  • Property transactions move large sums with limited scrutiny of source of funds.
  • Trust and company structures obscure beneficial ownership behind layers of entities.
  • Legal professional privilege has historically complicated information sharing.
  • Precious metals and stones convert cash into portable, high-value assets.

The Behavioural Gap Regulators Expect You to Close

Written programs are straightforward to produce. AUSTRAC publishes starter kits, and template providers have flooded the market. However, a template does not change what a sales agent does at 4pm on a Friday when a buyer offers to settle early through an unfamiliar third party.

Behaviour is where the regime succeeds or fails. Consequently, regulators increasingly examine whether staff recognised the indicator, escalated it, and documented the decision — not merely whether a policy existed.

Compliance professionals describe this as the difference between a paper control and a lived control. A paper control satisfies an auditor’s checklist. Meanwhile, a lived control changes a decision in the moment.

Where Firms Typically Fail First

Early enforcement patterns across comparable jurisdictions point to a consistent set of weak points:

  • Customer due diligence performed after the engagement begins rather than before.
  • Beneficial ownership recorded as the named client instead of the controlling individual.
  • Suspicious matter reports delayed while partners debate commercial consequences.
  • Training delivered once at induction and never refreshed against real scenarios.

Each failure looks administrative in isolation. Together, however, they form the pattern a regulator characterises as a systemic control breakdown.

Australian firm partners reviewing their AML/CTF program and compliance officer obligations under AUSTRAC requirements

The Legal Framework Behind the Reforms

What the Legislation Requires

The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 sets the framework, while the Amendment Act 2024 extends it to the newly captured professions. AUSTRAC administers both, maintains the Reporting Entities Roll, and issues sector-specific guidance.

Australian WHS law offers a useful parallel here. Under the WHS Act 2011, a PCBU must eliminate or minimise risk so far as is reasonably practicable, and officers must exercise due diligence rather than delegate responsibility downward. Similarly, an AML/CTF compliance officer must sit at management level and cannot outsource accountability to a software vendor.

What Non-Compliance Costs

Penalties under the AML/CTF Act are calculated in penalty units and applied per contravention. Maximum civil exposure reaches 100,000 penalty units for a body corporate and 20,000 penalty units for an individual, which translates into tens of millions of dollars at current values.

  • Civil penalty proceedings brought by AUSTRAC in the Federal Court.
  • Enforceable undertakings requiring remediation at the firm’s own cost.
  • Written directions to appoint an external auditor or repeat a risk assessment.
  • Criminal exposure for serious failures, including reckless identity verification.
  • Professional consequences through state legal, conveyancing and real estate licensing bodies.

Penalties rarely arrive first, though. Typically, AUSTRAC opens with information requests and compliance assessments, which is precisely why documented evidence of training and escalation matters so much.

The Tipping-Off Prohibition

Disclosing to a customer that a suspicious matter report has been lodged is an offence in its own right. Staff must therefore understand not only when to escalate, but also what they cannot say afterwards.

This obligation creates genuine difficulty in relationship-driven professions. Indeed, an agent who has known a vendor for fifteen years needs clear scripting, not a policy clause, to navigate that conversation safely.

Leadership Accountability Under the New Regime

The Compliance Officer Is a Real Role, Not a Title

Legislation requires an AML/CTF compliance officer at management level. In smaller firms, that person is usually the principal or a senior partner. Crucially, the appointment carries expectations that go well beyond signing the program.

  • Owning the risk assessment and reviewing it as the client base changes.
  • Deciding, and documenting, whether an escalated matter becomes a report.
  • Ensuring every worker in a designated service role completes training.
  • Reporting program performance to the partnership or board on a set cycle.

How to Choose Your AML Training Approach

Training is a legislated element of the program, yet firms approach it very differently. Use the criteria below to select an approach that fits your risk profile:

  • Generic off-the-shelf module: fast and inexpensive, but rarely reflects your designated services or client types. Suitable only as a baseline awareness layer.
  • Sector-specific module: stronger fit for property or professional services, and better at teaching the red flags your people will actually encounter.
  • Customised module built on your policies: highest evidentiary value, because scenarios mirror your escalation pathway and your systems.
  • Live workshop only: valuable for partners, though difficult to evidence at scale and hard to repeat for new starters.

Whichever route you take, retain completion records. Our Anti-Money Laundering and CTF module and the specialist AML/CTF for Real Estate module both deliver SCORM-ready evidence of completion.

Tone From the Top Determines Reporting Behaviour

Workers escalate concerns when they believe leadership will back them. Where partners visibly weigh a fee against a red flag, staff learn quickly that reporting is unwelcome.

Leadership signals travel faster than policies. Therefore, the most valuable thing a principal can do in the first year is publicly support the first uncomfortable escalation, whatever it costs commercially.

Program-as-Written Versus Program-as-Practised

Defining the Gap

Every regulated firm now holds two programs. One lives in a document management system, written in legislative language and approved at a partners’ meeting. The other lives in daily habits: what staff check, what they let pass, and who they ask when unsure.

Regulators examine the second program. They interview frontline workers, review file notes, and test whether the documented process matches observed behaviour. Meanwhile, the written program serves mainly as the benchmark those observations are measured against.

A wide gap between the two is the clearest predictor of enforcement risk. Narrowing it is fundamentally a training and leadership exercise, not a drafting exercise.

Warning Signs the Gap Is Widening

Watch for these indicators across your practice:

  • Staff cannot name the escalation pathway without opening the intranet.
  • Due diligence files show identical wording copied across unrelated matters.
  • Nobody has raised a single internal concern since commencement.
  • Training completion sits below 100% for designated service roles.

Closing the Distance

Scenario-based learning closes the gap faster than policy circulation, because it rehearses judgement rather than recall. Workers practise the moment of doubt in a safe setting before meeting it commercially.

Regular refreshers matter equally. Money laundering typologies shift, and a module written in early 2026 will not describe the structuring patterns emerging by 2027.

The eCompliance Central Tranche 2 Readiness Framework

Readiness is achievable within a compressed timeframe, provided the sequence is right. The eight steps below move a firm from unregulated to defensible, and each one produces documented evidence a regulator can inspect.

An 8-Step Framework for Control

Map Your Designated Services

List every service line and test each against the legislative definitions. Scope determines everything that follows.

Appoint the Compliance Officer

Name a management-level individual and notify AUSTRAC. Give the role real authority and protected time.

Complete Enrolment

Register on the Reporting Entities Roll without delay. Late enrolment is itself a contravention.

Document the Risk Assessment

Assess customer types, delivery channels, jurisdictions and products. Show your reasoning, not just your conclusion.

Build the Written Program

Draft policies that answer the risks you identified. Generic templates fail this test quickly.

Embed Due Diligence Workflows

Wire identity and beneficial ownership checks into your existing matter-opening process. Bolt-on steps get skipped.

Train Every Frontline Role

Deliver scenario-based learning tailored to each role. Retain completion records as evidence.

Test, Review and Refresh

Sample files quarterly and update the program annually. Independent evaluation strengthens your position considerably.

Sequencing the Framework Under Time Pressure

Firms that are already past commencement should not restart at step one. Instead, complete enrolment immediately, then work backwards to scope and risk assessment while training runs in parallel. Regulators respond far better to demonstrable progress than to a perfect plan that has not begun.

What Failure Looks Like in Practice

The Chain Reaction

Enforcement seldom begins with a dramatic discovery. Usually, it begins with a routine information request that a firm cannot answer convincingly, because the underlying records were never created.

From there, consequences compound predictably:

  • A due diligence file lacks source-of-funds evidence, so the firm cannot demonstrate the check occurred.
  • AUSTRAC escalates to a formal compliance assessment, absorbing partner time and external legal spend.
  • Findings flow to professional licensing bodies, insurers and lenders, damaging commercial relationships well beyond the penalty itself.

The Reputational Dimension

Financial crime findings attach to individuals as well as entities. Named partners carry the association into future roles, and referral networks reprice risk accordingly.

Clients notice too. Increasingly, corporate purchasers ask their advisers to evidence AML capability during panel reviews, which turns readiness into a commercial advantage rather than a cost.

Compliance Intelligence: Key Insights

Capture under Tranche 2 depends on the services a business provides, not the industry label it uses.
Enrolment with AUSTRAC is an administrative step, whereas compliance is a continuing operational discipline.
Staff training sits inside the legislated program, so untrained frontline workers create direct regulatory exposure.
Beneficial ownership, not the named client, is the detail most commonly recorded incorrectly.
Tipping off a customer about a suspicious matter report is a separate offence with its own consequences.
Officer accountability under the AML/CTF regime mirrors officer due diligence duties under the WHS Act 2011.
Zero internal escalations after commencement signals a silent culture rather than a clean client book.

Key Takeaways

  • Map every service line against the designated services definitions before assuming you fall outside scope.
  • Appoint a management-level AML/CTF compliance officer and give the role genuine authority.
  • Complete AUSTRAC enrolment immediately if you have not already done so.
  • Document your risk assessment so the reasoning, not merely the rating, is visible.
  • Wire customer due diligence into matter opening rather than adding it as a separate step.
  • Train every frontline role with scenarios drawn from your actual transactions.
  • Review the program annually and retain seven years of records as the legislation requires.

Frequently Asked Questions

Scope and Deadlines

Does Tranche 2 apply to my accounting practice if I only do tax returns?
Preparing tax returns alone generally does not constitute a designated service. However, capture depends on the full range of work your practice performs. Assisting with company or trust formation, managing client money, or acting in property transactions will bring you into scope. Consequently, most practices need a documented scoping exercise rather than an assumption. Because the definitions are technical, many firms obtain legal advice on scope before finalising their position.
What is the deadline to enrol with AUSTRAC for Tranche 2 AML compliance?
AUSTRAC opened enrolment on 31 March 2026, and newly regulated entities were required to enrol by 29 July 2026. Businesses that start providing a designated service after commencement must apply within 28 days. Failing to enrol is itself a civil penalty contravention. Therefore, firms that have missed the date should enrol without delay and document when and why the delay occurred.
Do sole traders and small firms have the same obligations as large ones?
Yes, although the regime is risk-based, which means the depth of your controls should reflect the scale and risk of your business. A sole practitioner still needs enrolment, a risk assessment, a written program, due diligence processes and training. Nevertheless, the documentation can be proportionate. AUSTRAC has published starter kits specifically to help smaller newly regulated entities build a defensible baseline.

Obligations and Accountability

Is staff training actually mandatory, or just recommended?
Training forms part of the AML/CTF program required under the legislation, so it is an obligation rather than a suggestion. Workers involved in designated services must understand their responsibilities, recognise indicators of money laundering, and know the escalation pathway. Moreover, you must retain evidence that training occurred. Completion records become important documentation during any AUSTRAC compliance assessment.
How does officer accountability compare to WHS obligations in Australia?
The structures rhyme closely. Under the WHS Act 2011, a PCBU must manage risk so far as is reasonably practicable, while officers exercise proactive due diligence rather than passive oversight. Similarly, an AML/CTF compliance officer sits at management level and carries personal expectations around program effectiveness. In both regimes, regulators look for evidence of active inquiry. Delegating the function to a vendor or a template will not satisfy either standard.
What should we do if a long-standing client triggers a red flag?
Follow your documented escalation pathway and refer the matter to your compliance officer promptly. Do not raise the concern with the client, because tipping off is a separate offence under the AML/CTF Act. Record what you observed, when, and what you did next. Ultimately, clear internal scripting helps staff manage these conversations without damaging the relationship or breaching the prohibition.

About the Author

This comprehensive article was actively developed by the expert content team at eCompliance Central, under the highly skilled direction of Dr. Denise Meyerson. Dr. Meyerson is the successful founder, a PhD-qualified educator, and a leading learning innovation specialist boasting over 35 years of deep, practical experience in learning and development, strict compliance, and vocational education. She has consulted extensively for leading global organisations and currently remains a highly recognised authority on behaviour-based compliance training within the complex Australian context. We firmly help ambitious organisations meet their strict compliance obligations through highly customised, deeply engaging, SCORM-ready training modules. We proudly build these robust tools precisely around your specific policies, your unique people, and your actual, daily operational realities. Note: We are professional educators, absolutely not legal advisors. For specific legal advice tailored precisely to your exact situation, please consult a fully qualified legal professional.

Get Your People Ready Before the Next Compliance Assessment

Programs pass audits only when people apply them. Our SCORM-ready AML/CTF modules are built around your designated services, your escalation pathway and your client base, so frontline staff recognise the red flags that matter in your business.

Explore Custom Compliance Solutions
0
    0
    Your Cart
    Your cart is emptyReturn to Shop