The commencement of AUSTRAC's Tranche 2 reforms represents a significant operational shift for professional service firms. Now that the transitional phase has ended, businesses providing designated services must operate under a fully functional, documented AML/CTF compliance framework.

Whether you are a lawyer, accountant, conveyancer, real estate agent, trust and company service provider (TCSP), precious metals dealer, or virtual asset service provider (VASP), you must ensure your business meets its compliance obligations. This guide provides a practical, step-by-step checklist to help you establish your framework.

Step 1: Determine If Your Services Are Captured

Not all services provided by professional firms are regulated under the Act. You must review your business model against the list of "designated services" in Schedule 1 of the AML/CTF Act 2006. For example:

Step 2: Enrol with AUSTRAC

If you provide any designated services, you must enrol as a reporting entity with AUSTRAC. This is completed online via the AUSTRAC Online portal. You will need to provide your business details, ABN/ACN, contact information, and a list of the designated services you provide. Enrolment is a mandatory requirement; failing to enrol is a direct breach of the law.

Step 3: Appoint a Compliance Officer

You must formally appoint an AML/CTF Compliance Officer. This person is responsible for maintaining your compliance program, training staff, and acting as the primary contact for AUSTRAC. The appointment must be documented in writing and approved by senior management.

Tip: In small firms, the Compliance Officer is often one of the partners or directors. In larger firms, it may be a dedicated risk manager. Regardless of firm size, this person must have the authority and resources to manage the compliance framework.

Step 4: Conduct a Risk Assessment

Before you can write your compliance program, you must conduct and document a Money Laundering/Terrorism Financing (ML/TF) risk assessment. You must evaluate your risk exposure across four key areas:

  1. Customer Risk: Do you act for PEPs, foreign nationals, or complex corporate structures?
  2. Service Risk: Which of your services are most vulnerable to exploitation?
  3. Delivery Channel Risk: Do you onboard clients online or face-to-face?
  4. Geographic Risk: Are your clients or their funds linked to high-risk jurisdictions?

Important: Your risk assessment must be committed to writing and reviewed at least once every 12 months. It forms the basis of your entire risk-based compliance framework.

Step 5: Develop Your AML/CTF Program

Your written AML/CTF Program must be divided into two parts:

Establish Your Compliance Framework Today

CompliDesk provides complete, industry-specific AML/CTF program templates, risk assessment wizards, and automated KYC workflows to get your business compliant quickly.

Get Started Free

Frequently Asked Questions

What is the difference between AUSTRAC enrolment and registration?
Enrolment is a general requirement for all reporting entities providing designated services. Registration is an additional, stricter requirement that applies specifically to digital currency exchanges (VASPs) and remittance service providers, who must be listed on specific AUSTRAC registers before they can operate.
How long does it take to set up an AML/CTF program from scratch?
If managed manually, designing a program, conducting a risk assessment, and establishing KYC procedures can take several weeks of administrative work. Using a platform like CompliDesk allows you to set up your program and start running compliant KYC checks in a single day.
Is AUSTRAC auditing businesses for Tranche 2 compliance in 2026?
Yes. While AUSTRAC is focusing on education and support during the initial phase, they are actively conducting compliance reviews and audits, particularly in sectors identified as high-risk (such as legal trust accounts and real estate transactions).

Related reading: AUSTRAC Tranche 2 complete guide · Choosing AML compliance software · 15 common AML compliance mistakes · Frequently asked questions