News and Insights

Australia’s AML/CTF Tranche 2 Reforms

Rollout and immediate compliance implications of Australia’s expanded anti-money laundering and counter-terrorism financing regime.

Key takeaway for clients

The Tranche 2 reforms[1] which came into effect on 1 July 2026 present a fundamental expansion of Australia’s AML/CTF regime into professional services, property and other sectors previously outside AML/CFTC obligations.

The regime is now operational.

Designated service providers must now be complying with Tranche 2 obligations.

A compliant framework should be capable of demonstrating four things:

  1. We know where our AML/CTF risks are.
  2. We have controls proportionate to those risks.
  3. Our staff understand and apply those controls.
  4. We can demonstrate the effectiveness of those controls through records, reporting and governance.

The precise obligations should be assessed against your business model, designated services and corporate structure.

[1] Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) and the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025.

1. Expanded professional and commercial services

The newly regulated businesses are commonly described as “Tranche 2” entities:

  • legal professionals and law practices;
  • accountants and accounting practices;
  • conveyancers;
  • real estate professionals, including certain real estate agents, buyer’s agents and property developers;
  • trust and company service providers; and
  • dealers in precious metals, precious stones and related products.
29 July 2026 General deadline for newly regulated businesses to enrol with AUSTRAC, being 28 days after commencement.
From 1 July 2026 Tranche 2 entities must comply with applicable AML/CTF program, customer due diligence, reporting and record-keeping obligations.

AUSTRAC has emphasised that the reforms are directed at services and activities considered vulnerable to exploitation for money laundering, terrorism financing and proliferation financing.

Practical implication: the first compliance question should be “Which designated services do we provide?”, rather than simply “Are we in a Tranche 2 industry?”

2. Core obligations 

A Tranche 2 reporting entity will generally need to establish and maintain an AML/CTF framework proportionate to its ML/TF/PF risks. 

  • ML (Money Laundering) 
  • Hiding the illegal source of money to make it look clean. 
  • TF (Terrorist Financing): 
  • Raising or moving money to support terrorist acts or groups.PF  
  • PF (Proliferation Financing):  
  • Providing funds or financial services to help build or transport weapons of mass destruction.

a. AML/CTF program

The business must develop and maintain an AML/CTF program designed to identify, assess, manage and mitigate relevant risks. 

The program should be tailored to the nature, size and complexity of the business and should address matters including: 

  • the business’s ML/TF/PF risk profile; 
  • customer risk; 
  • service and transaction risk; 
  • geographic risk; 
  • delivery-channel risk; 
  • customer due diligence; 
  • ongoing customer monitoring; 
  • suspicious matter reporting; 
  • record keeping; 
  • governance and oversight; and 
  • staff training. 

Compliance is often not straightforward.  AUSTRAC has made starter AML/CTF programs available for certain lower-complexity businesses, but businesses remain responsible for ensuring that the program actually addresses their own risk profile.

b. AML/CTF compliance officer

A reporting entity must have appropriate governance arrangements, including responsibility for AML/CTF compliance. 

c. Customer due diligence (CDD)

Depending on the circumstances, businesses may need to establish and verify: 

  • the customer’s identity; 
  • beneficial ownership; 
  • persons acting on behalf of or controlling the customer; 
  • the purpose and intended nature of the business relationship; and 
  • source of funds or source of wealth where required by the risk assessment; 

The Rules expressly contemplate policies addressing when information about a customer’s source of wealth and source of funds should be collected and verified. 

d. Ongoing customer due diligence

CDD is not necessarily a one-off exercise. 

Businesses must have processes to identify changes in customer circumstances and identify transactions or behaviour that may be inconsistent with the customer’s known risk profile. This is particularly relevant to businesses dealing with: 

  • complex ownership structures; 
  • trusts; 
  • companies; 
  • politically exposed persons (PEPS); 
  • high-value transactions; 
  • cross-border transactions; and 
  • customers or transactions presenting elevated geographic or financial-crime risks. 

e. Suspicious matter reporting

Tranche 2 entities must understand the reporting obligations and have a documented escalation process for identifyingassessing and reporting suspicious matters.

f. Threshold transaction reporting

Where applicable, businesses must also comply with threshold transaction reporting requirements. 

The updated reporting regime commenced on 1 July 2026 for newly regulated businesses, with new TTR and SMR forms available through AUSTRAC Online. 

g. Record keeping

Businesses must maintain appropriate records demonstrating compliance with their AML/CTF obligations. 

The records should allow the business to demonstrate, among other things: 

  • how customers were identified; 
  • how risk was assessed; 
  • what CDD was undertaken; 
  • what decisions were made regarding higher-risk customers; 
  • how suspicious activity was assessed; 
  • what reports were submitted; and 
  • how the AML/CTF program is maintained and reviewed. 

3. Completed tasks

Tranche 2 entities should have already done the following: 

a. Confirm regulatory scope

Prepare an inventory of all services provided by the business and map those services against the statutory designated services. This should include services provided through related entities, different business units and group structures. 

b. Confirm AUSTRAC enrolment

Confirm that the relevant entity has enrolled with AUSTRAC and that its enrolment information is accurate and current.

c. Complete the ML/TF/PF risk assessment

The business should document its assessment of the risks arising from: 

  • customers; 
  • services; 
  • transactions; 
  • geographic exposure; 
  • delivery channels; and 
  • relevant ownership or control structures. 

d. Implement the AML/CTF program

The program should be approved and operational rather than merely existing as a document. Policies should translate into practical procedures for staff dealing with customers and transactions.

e. Review onboarding and CDD

Existing client onboarding processes should be tested against the new requirements. 

Particular attention should be given to: 

  • beneficial ownership; 
  • trusts; 
  • companies; 
  • complex structures; 
  • politically exposed persons; 
  • source of funds/source of wealth; 
  • higher-risk customers; and 
  • circumstances requiring enhanced due diligence. 

f. Establish suspicious activity escalation procedures

Staff should know: 

  • what constitutes a potential red flag; 
  • who receives internal escalations; 
  • who determines whether an SMR is required; 
  • applicable reporting timeframes; 
  • how confidentiality is maintained; and 
  • the restrictions imposed by the tipping-off provisions. 

h. Train relevant staff

Training should be role-specific. 

For example, front-line property, legal or accounting staff may need practical training on identifying suspicious activity, whereas senior management may require training concerning governance, risk appetite and oversight.

i. Test systems and controls

Businesses should conduct sample testing of customer files and transactions to establish whether the controls actually work. 

A useful initial exercise is to select a representative sample of new and existing matters and ask: 

Could we demonstrate to AUSTRAC, from our records, why we accepted this customer, what risk we identified, what CDD we performed and how we continue to manage that risk?

Any inability to answer those questions should be treated as a remediation priority. 

4. Particular areas of risk for professional services

a. Legal practices

Law firms should carefully assess transactions involving: 

  • property; 
  • trusts and companies; 
  • client money; 
  • complex corporate structures; 
  • high-value transactions; and 
  • clients whose source of funds or wealth is difficult to establish. 

The distinction between legal work that is regulated and legal work outside the designated-service provisions will need to be assessed carefully.

b. Accountants

Accounting firms should consider whether their services involve regulated professional or trust/company services and assess the AML/CTF implications of: 

  • company formation; 
  • trust structures; 
  • transaction assistance; 
  • financial arrangements; 
  • management of client funds or assets; and 
  • advice or services involving higher-risk customers. 

c. Conveyancers

Conveyancers should focus particularly on property transactions, customer identity and beneficial ownership, source of funds and suspicious transaction escalation. 

d. Real estate businesses

Real estate businesses face particular exposure because property transactions can involve significant sums and complex ownership structures. 

Controls should address: 

  • buyer and seller identification; 
  • beneficial ownership; 
  • source of funds; 
  • unusual transaction structures; 
  • third-party payments; 
  • high-risk jurisdictions; 
  • cash or cash-like transactions; and 
  • unexplained changes in transaction arrangements. 

AUSTRAC has specifically identified real estate and complex company structures as areas vulnerable to exploitation by organised crime.

e. Precious metals and stones

Dealers should assess customer, transaction and payment risks, particularly where transactions are high value, involve unusual payment arrangements or lack an apparent commercial rationale. 

5. Regulatory approach and enforcement risk

AUSTRAC has indicated that it expects newly regulated businesses to have meaningful systems and controls in place and has identified failure to enrol, failure to implement an AML/CTF program and failure to meaningfully address ML/TF/PF risks as matters likely to attract regulatory attention. 

The salient question is: is whether the service or  business can demonstrate that its AML/CTF framework is effective, risk-based and embedded in its operations.

 

To find out more or seek legal advice contact colin.miller@arch.law

 

Get the latest News & Insights.

Sign up to receive the latest news, legal insights and updates by email. Unsubscribe at any time.

    I agree to receive email updates from arch.law and have read the Privacy Policy.

    Explore our solutions

    Contact us today.

      I agree to the Privacy Policy.