Pricing Privacy Act About Get Started Free
AUSTRAC compliance guide

AUSTRAC obligations for Australian Tranche 2 entities — what you need to do in 2026

The AML/CTF Tranche 2 reforms that came into force on 1 July 2026 imposed eight new obligations on Australian professional services firms. This guide explains each one in plain English.

The 8 AUSTRAC obligations for professional services firms

AUSTRAC requires every accounting firm providing designated services to meet eight core obligations. These aren't optional — they're legal requirements with civil penalties of up to 2 million for serious breaches.

1. Enrol with AUSTRAC

The first and most time-sensitive obligation. You must enrol your firm as a reporting entity with AUSTRAC by 29 July 2026 if you were already providing designated services on 1 July 2026. Enrolment is free and done online through AUSTRAC Online using your myID. You'll receive an AUSTRAC account number — keep it safe.

2. Appoint a Compliance Officer

Every reporting entity must appoint an AML/CTF Compliance Officer who is a 'fit and proper person.' For most small professional services firms, this is the principal or a senior partner. They're responsible for overseeing your AML/CTF program and ensuring your obligations are met.

3. Conduct a risk assessment

You must document the ML/TF risks your firm faces — considering who your clients are, what services you provide, how you deliver them, and what geographies are involved. The risk assessment underpins everything else. It must be reviewed regularly and updated when circumstances change.

4. Implement a written AML/CTF program

Your written program documents how your firm will manage the risks identified in your assessment. It must include: your risk assessment, CDD procedures, staff training arrangements, record keeping processes, and how you identify and report suspicious matters. AUSTRAC has said programs should be proportionate to your firm's size — a sole practitioner doesn't need a bank-grade document.

5. Customer due diligence (KYC)

Before providing any designated service, you must verify who your clients are. For individuals this means name, date of birth, address, and identity document. For entities it means ABN/ACN, directors, and beneficial owners. See our separate KYC checklist for full details.

6. Ongoing monitoring

AML compliance is not a one-time process. You must continuously monitor client relationships and transactions for unusual activity. This includes re-screening clients when their circumstances change and re-verifying when documents expire.

7. Report to AUSTRAC

When you suspect a client or transaction may be connected to money laundering or terrorism financing, you must lodge a Suspicious Matter Report (SMR) with AUSTRAC as soon as practicable. You must never tip off the client that you're reporting them — this is a criminal offence.

8. Keep records for 7 years

All KYC records, risk assessments, AML programs, and SMRs must be retained for at least 7 years. Records must be stored securely and be readily accessible to AUSTRAC on request.

Key insight: Meeting all 8 obligations manually across 30+ clients is extremely time-consuming. Purpose-built software like CompliDesk automates most of it — risk scoring, document management, audit trails, and review reminders happen automatically.

Manage AML compliance for all your clients from one dashboard

CompliDesk is built specifically for Australian professional services firms managing AML/CTF compliance for clients. Sign up free for free signup.

Sign up free today

AUSTRAC obligations for accountants — quick answers

Four things, continuously: verify who your clients are (KYC), assess and monitor their money-laundering risk, keep records for 7 years, and report suspicious matters or large cash transactions when they arise. Enrolment is a one-time step; these four are ongoing for as long as you provide designated services.
Both. Existing clients need to be brought into your AML/CTF Program too — you can't grandfather your existing client base out of ongoing due diligence obligations just because the relationship predates Tranche 2.
With the right software, a small practice can enrol, generate an AML/CTF Program, and start verifying clients within a single day. Working through your entire existing client base typically takes longer — plan for a few weeks to properly risk-assess everyone, prioritising higher-risk clients first.