anti money laundering
Sep 25, 2026
13min read

Tranche 2 AML in Australia: Who Must Comply and What to Do Now

Professionals reviewing Tranche 2 AML compliance requirements in a modern Australian office

What if your business has been pulled into Australia’s AML/CTF regime without you fully realising it?

That is now a very real question for thousands of Australian businesses. Since 1 July 2026, Tranche 2 has extended AML/CTF obligations to certain services provided across real estate, legal and conveyancing practices, accounting, and precious metals and stones. AUSTRAC has confirmed that the new AML/CTF reporting regime is now in force, bringing requirements such as customer due diligence, AML/CTF programs, suspicious matter reporting and record keeping into the day-to-day operations of newly regulated businesses.

But here’s the part that causes confusion: working in a Tranche 2 profession does not automatically mean every service you provide is regulated. The real question is whether your business provides a designated service covered by the legislation.

If you are still getting familiar with the wider framework, our guide to anti-money laundering in Australia explains how AUSTRAC, reporting entities and the broader AML/CTF regime fit together.

In this guide, we’ll focus specifically on Tranche 2 AML: what changed, which businesses and services may be covered, and what you need to be doing now if the reforms apply to you.

What Is Tranche 2 AML?

Tranche 2 AML is the commonly used term for the expansion of Australia’s Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) regime to certain higher-risk services that were previously outside its full scope.

The reforms stem from changes to the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, alongside the new AML/CTF Rules. According to AUSTRAC’s overview of the AML/CTF reforms, the changes are designed to strengthen Australia’s financial crime framework, modernise existing requirements and bring the regime closer to international standards set by the Financial Action Task Force (FATF).

For newly regulated businesses, the major change arrived on 1 July 2026. From that date, certain designated services provided by real estate professionals, lawyers, conveyancers, accountants, trust and company service providers, dealers in precious metals and stones, and some virtual asset businesses became subject to the AML/CTF regime.

That distinction matters. Tranche 2 does not simply regulate entire professions by name. It regulates particular designated services provided under circumstances covered by the legislation.

So, before worrying about AML programs, customer checks or reporting requirements, there is a more immediate question to answer:

Does your business actually provide a service that Tranche 2 regulates?

Does Tranche 2 AML Apply to Your Business?

Seeing your profession on a list of Tranche 2 industries can make it sound as though every lawyer, accountant, conveyancer or real estate professional is automatically caught by the new rules.

That is not quite how it works.

The more important question is:

Does your business provide a designated service covered by the AML/CTF regime?

AUSTRAC’s current guidance on designated services for newly regulated businesses makes it clear that coverage depends on the services being provided, not simply the profession or job title of the person providing them.

For example, Tranche 2 may apply to certain services involving:

  • buying, selling or transferring real estate
  • forming or restructuring companies and other legal arrangements
  • managing money or other property in connection with particular transactions
  • providing certain trust and company services
  • dealing in precious metals, stones or related products under regulated circumstances
  • providing certain virtual asset services

Professional services are especially important here. A law firm or accounting practice may carry out a mix of work, some of which falls within the designated-service rules and some of which does not. That is why businesses need to assess what they actually do for clients, rather than assuming that an industry label gives them the answer.

Start With the Service, Not the Job Title

A useful first step is to map the services your business provides against AUSTRAC’s designated-service categories.

Ask:

  1. What service are we actually providing to the customer?
  2. Is that activity listed as a designated service?
  3. Are the conditions for that designated service met in our situation?
  4. Does an exclusion or exception apply?

That last point matters because AML/CTF legislation can include specific conditions, qualifications and exclusions. AUSTRAC itself notes that its examples are general guidance and that the circumstances of an individual business may affect how the law applies.

If your answer suggests that you are providing a covered designated service, your business may be a reporting entity and subject to Tranche 2 AML/CTF obligations.

And at that point, the question shifts from “Does Tranche 2 apply to us?” to “What do we now need to have in place?”

Which Businesses and Services Are Covered by Tranche 2?

Tranche 2 brings a much wider range of Australian businesses into the AML/CTF regime. But as we’ve already covered, the key issue is not simply which industry you work in. It is whether you provide one or more regulated designated services.

Infographic showing the main sectors and designated services covered by Tranche 2 AML in Australia

According to AUSTRAC’s guidance for newly regulated entities, the main sectors affected include:

Sector

Examples of services that may be regulated

Legal professionals and conveyancers

Certain services connected with real estate transactions, companies, trusts, legal arrangements and the management or transfer of client assets

Accountants and other professional service providers

Certain services involving companies, trusts, transactions, property and business structures

Real estate professionals

Brokering the sale, purchase or transfer of real estate

Trust and company service providers

Certain company formation, restructuring, administration and registered-office services

Dealers in precious metals, stones and related products

Certain transactions involving regulated precious metals, stones or products where the relevant conditions are met

Certain virtual asset service providers

New or expanded virtual asset designated services covered under the reformed AML/CTF framework

This is why two businesses in the same profession can end up with different AML/CTF obligations. An accounting firm focused only on routine services may have a different exposure from one helping clients create or restructure companies and trusts. 

Likewise, a legal practice needs to look at the specific transactions and services it handles rather than assuming that every legal matter falls within Tranche 2.

There can also be important thresholds, exclusions and conditions attached to individual designated services. AUSTRAC therefore recommends checking the exact service your business provides against the relevant category instead of relying on a broad industry description.

If your activities fall within these designated services, the next issue becomes much more practical: what does being a Tranche 2 reporting entity actually require you to do?

If Tranche 2 Applies, What Must Your Business Do Now?

Once you confirm that your business provides a designated service, the focus shifts from whether Tranche 2 applies to how you are meeting the obligations that come with it.

Infographic showing the main steps businesses must take if Tranche 2 AML applies to them

For newly regulated businesses, AUSTRAC now expects more than a policy sitting in a folder. Your AML/CTF framework needs to operate as part of the way you assess customers, manage risk, train staff and respond to suspicious activity.

At a practical level, that means several things need to be in place.

Enrol with AUSTRAC. Most newly regulated businesses must be enrolled with AUSTRAC before providing designated services. Some businesses providing remittance or certain virtual asset services may also have separate registration requirements. You can check the current requirements through AUSTRAC’s guidance on the new reporting regime.

Assess your money laundering, terrorism financing and proliferation financing risks. Your risk assessment should reflect the customers you deal with, the services you provide, how those services are delivered and any geographic or transaction-related risks relevant to your business.

Develop and maintain an AML/CTF program. The program should translate those risks into actual policies, procedures, systems and controls. It should explain how your business conducts customer due diligence, manages higher-risk situations, escalates concerns and meets its reporting and record-keeping responsibilities.

For smaller or lower-complexity businesses, AUSTRAC has created sector-specific resources to make this process easier. Our guide to AUSTRAC AML Starter Kits explains how these templates can be used as a starting point and why they still need to be adapted to your actual business risks.

Appoint an AML/CTF compliance officer. This person is responsible for helping oversee the program and needs enough authority, independence and access to resources to perform the role effectively. AUSTRAC provides specific guidance on appointing and notifying an AML/CTF compliance officer.

Carry out customer due diligence. Depending on the customer and risk involved, this can include identifying and verifying customers, understanding beneficial ownership, assessing customer risk and applying ongoing or enhanced due diligence where required.

Monitor and report suspicious activity. Reporting entities need processes that help staff recognise when something does not make sense and escalate it appropriately. Where the legal requirements are met, this may lead to reports such as suspicious matter reports or threshold transaction reports.

Keep the required records and train relevant staff. Records should demonstrate what your business actually did, not simply what its written policy says it should do. Staff also need enough AML/CTF training to understand the procedures relevant to their roles.

The bigger point is that an AML/CTF program is not a one-off compliance document. AUSTRAC’s current regulatory expectations focus on businesses making a genuine effort to embed their controls into day-to-day operations.

So, if Tranche 2 applies to your business, the real benchmark is not whether you have written a program. It is whether that program is actually being used.

What About Clients You Already Had Before 1 July 2026?

If you were already working with clients before Tranche 2 commenced, you may be wondering whether every one of them now needs to go through a completely new customer due diligence process.

Not necessarily.

AUSTRAC uses the term pre-commencement customer for certain customers connected to designated-service relationships that existed on or before 1 July 2026. Its guidance on transitioning existing customers recognises that these established relationships can be treated differently from entirely new customers.

In many cases, a reporting entity can continue providing designated services to a pre-commencement customer without immediately completing full initial customer due diligence.

Infographic explaining how Tranche 2 affects existing clients and what to do if a business missed AUSTRAC enrolment

However, that does not mean existing clients can simply be ignored.

You still need to carry out ongoing customer due diligence and monitor for changes or activity that could alter the customer's risk profile. Initial CDD can become necessary later if, for example:

  • a suspicious matter reporting obligation arises
  • there is a significant change in the nature or purpose of the business relationship
  • that change results in the customer's money laundering, terrorism financing or proliferation financing risk becoming medium or high

For example, a long-standing client asking you to perform a substantially different or higher-risk designated service may require a fresh look at the relationship before you proceed.

So the practical takeaway is simple: do not automatically treat every pre-July 2026 client as either fully cleared or completely new. Review the relationship, understand whether the customer meets the pre-commencement rules, and apply the appropriate level of due diligence based on the circumstances and risk.

Missed the Tranche 2 Enrolment Deadline? Don’t Ignore It

For most newly regulated Tranche 2 businesses, the initial deadline to enrol with AUSTRAC was 29 July 2026. That deadline has now passed.

If your business provides a designated service and has not enrolled, the worst move is to assume the issue can wait.

On 28 August 2026, AUSTRAC confirmed that it had begun issuing section 167 notices to businesses that appeared to be providing designated services without being enrolled. These notices can require businesses to provide information so AUSTRAC can determine whether they are regulated and whether they are meeting their obligations under the AML/CTF Act.

That does not mean every late or unenrolled business will face the same regulatory response. It does mean AUSTRAC is actively looking at whether newly regulated businesses have identified their obligations and taken action.

If you think Tranche 2 may apply to your business, check your status rather than relying on assumptions. You can review AUSTRAC’s enrolment requirements and complete the process through AUSTRAC Online.

Also remember that enrolment and registration are not the same thing. Most newly regulated lawyers, accountants, real estate professionals, conveyancers and dealers in precious metals and stones generally need to enrol. Remittance and certain virtual asset service providers must both enrol and register with AUSTRAC.

If you have already missed the deadline, the practical priority is straightforward: confirm whether your services are covered, address any outstanding enrolment requirements and start fixing the underlying compliance gaps now.

Don’t Forget Privacy When Conducting Customer Due Diligence

Tranche 2 compliance may require your business to collect more information about customers, beneficial owners and the purpose of certain transactions. But AML/CTF obligations do not give businesses a free pass to collect and retain personal information without limits.

The Office of the Australian Information Commissioner’s guidance on AML/CTF and privacy obligations makes it clear that reporting entities still need to consider their obligations under the Privacy Act 1988 and the Australian Privacy Principles where those laws apply.

In practice, that means your customer due diligence processes should consider:

  • what personal information you genuinely need to collect
  • how customers are informed about that collection
  • how identity and verification information is stored and protected
  • who within the organisation can access it
  • how long information should be retained
  • when information should be securely destroyed or de-identified where permitted

A common mistake is assuming that AML/CTF record-keeping requirements mean businesses should simply keep complete copies of every identity document they receive. The OAIC has specifically warned businesses to think carefully about data minimisation and whether retaining full copies of identification documents is actually necessary.

This matters because poor privacy practices can create a second compliance problem while you are trying to solve the first one.

The better approach is to design your customer due diligence and privacy processes together. Collect what the law requires, keep the evidence you need, protect it properly and avoid holding sensitive information simply because “more data feels safer”.

That way, your AML/CTF controls strengthen your compliance framework instead of creating unnecessary privacy and cybersecurity risk.

Does Your Team Need AML/CTF Training?

If Tranche 2 applies to your business, having the right policies is only part of the job. The people carrying out those policies also need to understand what they are expected to do.

Compliance team receiving AML and customer due diligence training in a modern office setting

That means relevant staff should know how AML/CTF requirements affect their day-to-day work, including:

  • recognising when a designated service is being provided
  • carrying out customer due diligence correctly
  • identifying unusual behaviour or potential financial crime red flags
  • escalating concerns through the right internal channels
  • understanding record-keeping and reporting responsibilities
  • following the business’s AML/CTF program in practice

AUSTRAC’s current expectations for newly regulated businesses include ensuring staff are trained on the organisation’s AML/CTF program and understand their responsibilities under it. Training should therefore be relevant to the employee’s role rather than treated as a one-size-fits-all compliance exercise.

For example, a customer-facing employee may need to understand identity checks and escalation procedures, while managers and compliance personnel may need deeper knowledge of risk assessments, suspicious matter reporting, governance and ongoing monitoring.

The goal is not to turn every employee into an AML specialist. It is to make sure that the people who encounter AML/CTF risks can recognise them and respond appropriately.

If your organisation is building that capability, the Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) course provides structured training on the core obligations, customer due diligence, reporting, record keeping and the Tranche 2 reforms.

Training works best when it supports the controls your business already has in place. If your written program says one thing but staff do something different in practice, the program is not really operating as intended.

Frequently Asked Questions

The new obligations for most newly regulated Tranche 2 sectors commenced on 1 July 2026. Businesses providing covered designated services are now expected to comply with the applicable AML/CTF requirements, rather than simply prepare for them.

If your business only recently started providing a designated service, AUSTRAC generally requires you to apply for enrolment no later than 28 days after you begin providing that service. You can check the current requirements through AUSTRAC’s AML/CTF guidance for newly regulated businesses.

No. Tranche 2 does not automatically make every lawyer, accountant or other professional a reporting entity.

Coverage depends on whether the business provides a designated service under the AML/CTF legislation and whether the conditions applying to that service are met. That is why businesses should assess their actual client services rather than relying solely on their profession or industry classification.

Potentially, yes.

Being a small business or sole practitioner does not automatically place you outside the AML/CTF regime. The central issue is still whether you provide a covered designated service.

However, the nature, size and complexity of a business can affect how its AML/CTF program and controls are designed. A small conveyancing practice, for example, may not need the same systems as a large national firm, but any applicable legal obligations still need to be met.

Not automatically.

Some customers with an existing designated-service relationship before or on 1 July 2026 can qualify as pre-commencement customers. In certain circumstances, businesses can continue providing designated services without immediately conducting full initial CDD.

However, ongoing customer due diligence still applies, and particular changes or risk triggers may require further checks. AUSTRAC’s guidance on transitioning existing customers explains when those requirements can arise.

If your business is a reporting entity providing designated services, you must appoint an AML/CTF compliance officer.

AUSTRAC states that the appointment must generally be made within 28 days of starting to provide designated services, with AUSTRAC then notified within the required timeframe. The person also needs sufficient authority, independence, resources and expertise to perform the role effectively.

You can review the full requirements in AUSTRAC’s guidance on appointing an AML/CTF compliance officer.