What is AML/CTF Tranche 2?
AML/CTF Tranche 2 is the second stage of Australia's Anti-Money Laundering and Counter-Terrorism Financing reform program. It extends the obligations that banks and financial institutions have operated under since 2006 to a new group of "gatekeeper" professions — including accountants, lawyers, real estate agents, and conveyancers.
The reforms were passed by Parliament in late 2024 and came into force on 1 July 2026. The regulator is AUSTRAC (the Australian Transaction Reports and Analysis Centre).
In plain English: From 1 July 2026, certain accounting services now have the same anti-money laundering obligations as banks. You must verify who your clients are, assess their risk, and report suspicious activity to AUSTRAC.
Am I in scope?
Not every accounting service triggers Tranche 2 obligations. The law applies based on what services you provide — not simply because you're an accountant. You are in scope if you provide any of the following "designated services":
- Forming or managing companies, trusts, or other legal arrangements
- Acting as or arranging a nominee director, trustee, or shareholder for a client
- Managing client funds, bank accounts, securities, or assets
- Buying or selling businesses on behalf of clients
- Acting on behalf of clients in property transactions
Practices that only provide tax returns, BAS preparation, and general bookkeeping are likely not in scope. However, most professional services firms that also help clients set up companies, manage trusts, or handle transactions will be captured.
Important: If you are unsure whether your services are in scope, seek independent legal advice. AUSTRAC has also published a self-assessment tool on their website. Do not assume you are out of scope without checking.
Key dates
Legislation passed
AML/CTF Amendment Act 2024 passed by Parliament.
Enrolment opens
AUSTRAC opens enrolment for Tranche 2 entities.
Obligations begin
AML/CTF obligations are live. All designated services must comply from this date.
Enrolment deadline
Final date to enrol with AUSTRAC if you were providing designated services on 1 July 2026.
Your 8 AUSTRAC obligations
If your firm is in scope, AUSTRAC requires you to meet eight core obligations:
1. Enrol with AUSTRAC
Register your firm as a reporting entity through AUSTRAC Online. Enrolment is free. You must enrol by 29 July 2026 if you were already providing designated services on 1 July 2026.
2. Appoint an AML/CTF Compliance Officer
Your firm must appoint a compliance officer who meets AUSTRAC's "fit and proper person" requirements. For small firms, this is typically the principal or a senior partner. The role can be internal or outsourced.
3. Conduct a risk assessment
Prepare a written assessment of the money laundering and terrorism financing risks your firm faces — considering your client types, services, delivery channels, and geographies. This must be reviewed regularly.
4. Implement a written AML/CTF program
Develop a documented program outlining how your firm will manage ML/TF risks. It must include your risk assessment, policies and procedures, customer due diligence processes, training requirements, and review schedule.
5. Customer due diligence (KYC)
Verify the identity of every client before providing designated services. This includes individuals (name, date of birth, address, identity document) and entities (ABN/ACN, beneficial owners, directors). See the KYC section below for detail.
6. Ongoing monitoring
Continuously monitor your client relationships and transactions for unusual activity. Re-screen clients periodically and when circumstances change.
7. Report to AUSTRAC
Lodge Suspicious Matter Reports (SMRs) when you suspect a client or transaction may be connected to money laundering or terrorism financing. Threshold Transaction Reports (TTRs) are also required for cash transactions over $10,000.
8. Keep records for 7 years
Retain all KYC records, risk assessments, AML program documents, and suspicious matter reports for at least 7 years. Records must be accessible to AUSTRAC on request.
KYC requirements in detail
Customer Due Diligence (CDD) — also called Know Your Customer (KYC) — is the process of verifying who your clients are. AUSTRAC requires this before you provide any designated service.
For individual clients, you must collect and verify:
- Full name
- Date of birth
- Residential address
- Identity document (Australian driver's licence, passport, or Medicare card)
For company clients, you must collect and verify:
- Company name and ACN/ABN
- Registered address
- Directors and beneficial owners (anyone owning 25%+)
- Nature and purpose of the business relationship
For trust clients, you must collect and verify:
- Trust name and type
- Trustee identity (individual or corporate)
- Settlor details
- Beneficiaries (if ascertainable)
Electronic verification: AUSTRAC accepts electronic identity verification (eIDV) using the Biometric identity verification (Didit). This is faster and more defensible than manual photocopies — and it's what CompliDesk uses.
What your AML/CTF program must include
Your written AML/CTF program is the cornerstone of your compliance. It doesn't need to be hundreds of pages — AUSTRAC has said smaller firms can have simpler programs. But it must genuinely reflect how your firm manages risk. It must include:
- Your ML/TF risk assessment
- Your customer due diligence procedures
- How you identify and report suspicious matters
- Your record-keeping procedures
- Your staff training program
- How and when the program will be reviewed
- Who is responsible for compliance
Penalties for non-compliance
AUSTRAC has been clear: they will enforce Tranche 2 compliance. Penalties for breaching the AML/CTF Act can be severe:
- Civil penalties up to $33 million for serious breaches
- Criminal penalties including imprisonment for deliberate non-compliance
- Reputational damage — AUSTRAC publishes enforcement actions
- Personal liability for directors and officers
AUSTRAC has stated: "Australia is catching up to jurisdictions like the UK, where accountants and real estate agents have been subject to AML obligations for years. AUSTRAC has made it clear that businesses ignoring these changes will face consequences."
Your compliance checklist
Before 29 July 2026
Determine if you're in scope — map your services against AUSTRAC's designated services list
Enrol with AUSTRAC — through AUSTRAC Online using your myID
Appoint a compliance officer — document this appointment in writing
Complete your risk assessment — document your client types, services, and risk exposure
Write your AML/CTF program — tailored to your firm's size and risk profile
Start KYC on existing clients — verify identity of all clients receiving designated services
Train your staff — document who was trained and when
Set up record keeping — 7 years, secure and accessible
How CompliDesk helps
CompliDesk is built specifically for Tranche 2 reporting entities managing AML/CTF compliance for their clients — not just their own firm. From one dashboard you can:
- Run KYC identity checks on clients electronically via Didit biometrics
- Generate tailored AML/CTF risk assessments for each client
- Create compliant AML/CTF programs from guided templates
- Monitor ongoing risk and receive alerts when action is needed
- Maintain a 7-year audit trail for every action
- Lodge suspicious matter reports through a guided workflow
- Track staff training completion
- AUSTRAC reporting built in services
Ready to get compliant?
Create your CompliDesk account and start managing your AML/CTF compliance in minutes.
Sign up free today