The commencement of AUSTRAC's Tranche 2 reforms represents a significant operational shift for professional service firms. Now that the transitional phase has ended, businesses providing designated services must operate under a fully functional, documented AML/CTF compliance framework.
Whether you are a lawyer, accountant, conveyancer, real estate agent, trust and company service provider (TCSP), precious metals dealer, or virtual asset service provider (VASP), you must ensure your business meets its compliance obligations. This guide provides a practical, step-by-step checklist to help you establish your framework.
Step 1: Determine If Your Services Are Captured
Not all services provided by professional firms are regulated under the Act. You must review your business model against the list of "designated services" in Schedule 1 of the AML/CTF Act 2006. For example:
- Captured: Managing client trust accounts, facilitating property transactions, setting up corporate structures, or acting as a nominee trustee.
- Exempt: General tax advice, basic bookkeeping, representing a client in litigation, or providing general commercial legal advice.
Step 2: Enrol with AUSTRAC
If you provide any designated services, you must enrol as a reporting entity with AUSTRAC. This is completed online via the AUSTRAC Online portal. You will need to provide your business details, ABN/ACN, contact information, and a list of the designated services you provide. Enrolment is a mandatory requirement; failing to enrol is a direct breach of the law.
Step 3: Appoint a Compliance Officer
You must formally appoint an AML/CTF Compliance Officer. This person is responsible for maintaining your compliance program, training staff, and acting as the primary contact for AUSTRAC. The appointment must be documented in writing and approved by senior management.
Tip: In small firms, the Compliance Officer is often one of the partners or directors. In larger firms, it may be a dedicated risk manager. Regardless of firm size, this person must have the authority and resources to manage the compliance framework.
Step 4: Conduct a Risk Assessment
Before you can write your compliance program, you must conduct and document a Money Laundering/Terrorism Financing (ML/TF) risk assessment. You must evaluate your risk exposure across four key areas:
- Customer Risk: Do you act for PEPs, foreign nationals, or complex corporate structures?
- Service Risk: Which of your services are most vulnerable to exploitation?
- Delivery Channel Risk: Do you onboard clients online or face-to-face?
- Geographic Risk: Are your clients or their funds linked to high-risk jurisdictions?
Important: Your risk assessment must be committed to writing and reviewed at least once every 12 months. It forms the basis of your entire risk-based compliance framework.
Step 5: Develop Your AML/CTF Program
Your written AML/CTF Program must be divided into two parts:
- Part A (General): Outlines your policies, procedures, and systems for identifying, mitigating, and managing ML/TF risks. It must cover your risk assessment, customer due diligence (CDD) policies, ongoing customer monitoring, staff training, and independent review procedures.
- Part B (Customer Identification): Details your specific KYC verification procedures, outlining exactly how you verify the identity of individuals, companies, and trusts.
Establish Your Compliance Framework Today
CompliDesk provides complete, industry-specific AML/CTF program templates, risk assessment wizards, and automated KYC workflows to get your business compliant quickly.
Get Started FreeFrequently Asked Questions
Related reading: AUSTRAC Tranche 2 complete guide · Choosing AML compliance software · 15 common AML compliance mistakes · Frequently asked questions