Not every accounting engagement triggers AML/CTF obligations. Tranche 2 captures specific designated services only: assisting with real estate or company sale transactions, managing client money or accounts, and organising contributions to create or run a company or trust. If your firm provides none of these, ordinary tax agent work, audit, and general bookkeeping stay outside the regime. If you provide even one, you must enrol with AUSTRAC and build a tailored AML/CTF program before delivering that service. Run a designation audit now and diarise your enrolment.
TL;DR:
- Only services assisting with real estate or company transactions, managing client funds, or organising company or trust contributions trigger AML/CTF obligations; routine tax and audit work do not.
- Enrolment with AUSTRAC is mandatory before providing a designated service, requiring an online account, business profile, and a risk-based policies and controls framework.
- Firms must conduct a thorough designation audit, matching each service against the captured categories, and document ambiguous cases for officer review to stay compliant.
- Ongoing customer due diligence, including periodic reviews and enhanced checks for high-risk clients, must be documented and retained for seven years in tamper-evident form.
- Implementing a compliance platform can streamline risk management, policies, training, and record-keeping, but final judgment on flagged cases remains with the designated officer.
Table of Contents
- Do you need to comply? Testing whether your service is designated
- Enrolling with AUSTRAC: process and timing
- Building your AML/CTF program: risk assessment, policies, and CDD
- Governance and training: the compliance officer’s role
- Ongoing monitoring, reporting, and record keeping
- Using AUSTRAC’s starter kit without over-relying on it
- How a compliance platform fits into the program in practice
- What Tranche 2 onboarding keeps teaching us
- Getting your AML/CTF program running without building it from scratch
- Where to check the primary sources
- Sources
Do you need to comply? Testing whether your service is designated
The AML/CTF Act applies to services, not industries. A firm can hold itself out as an “accounting practice” while running a mix of captured and uncaptured work, and the AML/CTF Act 2006 (Cth) tests each engagement on its own facts, not the letterhead it sits under. Professional bodies including CPA Australia make the same point when advising members to audit their own revenue streams line by line rather than assume the whole practice is either in or out.
Services that typically trigger obligations include:
- Assisting a client to plan or execute buying or selling real estate or a body corporate
- Managing client money, accounts, or securities on a client’s behalf
- Organising contributions for creating, operating, or managing a company, trust, or other legal arrangement
Services that typically do not include ordinary tax return preparation, statutory audit work, and standard bookkeeping are those where the accountant never plans or executes the underlying transaction or handles the funds.
Run this designation audit and keep a written record of it in your AML/CTF policies:
- List every service line the practice bills for.
- Test each against the three captured categories above.
- Flag ambiguous engagements (trust establishment work, SMSF administration) for a documented officer decision.
- Record the outcome, the reasoning, and the review date in your policy document.
Enrolling with AUSTRAC: process and timing
Enrolment is not optional once a designated service is on your books. AUSTRAC treats it as a legal requirement that sits ahead of, not alongside, actually delivering that service to a client. The process runs through AUSTRAC’s online systems and asks for detail on your business structure and the designated services you provide.
The practical steps look like this:
- Confirm at least one designated service applies, using the audit above.
- Create your AUSTRAC online account and complete the business profile.
- Nominate your AML/CTF compliance officer as part of that profile.
- Build the risk assessment and policies before, not after, you take on the first captured engagement.
Enrolments for Tranche 2 opened in March 2026, and the Institute of Public Accountants’ guidance urges firms to check applicability and enrol promptly rather than wait. Do not rely on older AUSTRAC pages written for the pre-reform regime; the current program structure sits under the AML/CTF Rules 2025.
Building your AML/CTF program: risk assessment, policies, and CDD
Your program has two legal components: a business-wide ML/TF and proliferation financing risk assessment, and the AML/CTF policies that respond to it. The Act requires reporting entities to undertake this risk assessment and maintain matching policies, and the assessment has to cover proliferation financing risk alongside money laundering and terrorism financing, not just the latter two.
The risk assessment should be scoped to what your practice actually does. A firm that only assists small business owners with company incorporations faces a different risk profile to one that regularly manages settlement funds for property transactions. Review it at least annually, and sooner if you add a new service line or a client base with materially different risk (offshore beneficial owners, cash-intensive businesses).
Your policies need to visibly respond to that risk assessment. Supervisors look for a direct line between a risk you identified and a control you documented.
Customer due diligence follows from there:
- Verify the client’s identity using reliable, independent documents or data
- Identify beneficial owners for companies, and trace through to the underlying individuals for trusts and SMSFs via the corporate trustee
- Apply enhanced CDD where the risk assessment flags a trigger: politically exposed persons, complex ownership structures, or higher risk jurisdictions
Keep the operational paper trail alongside the substantive checks: the forms you used, who authorised each CDD decision, and the retained evidence.
Pro Tip: Map each policy clause back to the specific risk it mitigates before you finalise the document. A policy that cannot point to a risk assessment line is the single most common gap AUSTRAC starter kit guidance warns against, because a mismatch between the two is a common finding on supervision review.
Records supporting these determinations need to survive seven years in tamper-evident form, not just filed away and forgotten.
Governance and training: the compliance officer’s role
Every reporting entity must designate and notify AUSTRAC of an AML/CTF compliance officer. This isn’t a title you assign quietly. The AML/CTF Rules 2025 set out the officer’s functions and the notification steps required when that person changes.
Choose the officer against a short list of practical tests:
- Do they have real operational authority to direct changes to client engagement processes, not just a compliance job description?
- Do they understand the firm’s designated services well enough to spot when a new engagement needs a fresh look?
- Do they have access to client files, CDD records, and engagement letters when a review is needed?
Outsourcing the administrative workload is fine. Final accountability rests with the named officer, and that responsibility cannot be delegated away entirely.
Staff training needs to cover how to spot a designated service at intake, how CDD steps apply to that service, and when to escalate to the compliance officer. Keep dated completion records for every staff member. An officer who cannot produce training records for a supervision visit has, in practice, no training program at all.
Ongoing monitoring, reporting, and record keeping
Customer due diligence does not end at onboarding. The obligation is ongoing: periodic reviews scaled to risk, and a defined trigger for escalating a client to enhanced review when their circumstances or transaction pattern shift.
Reporting sits on top of that monitoring. Section 41 of the Act requires a suspicious matter report where reasonable grounds exist, regardless of whether a transaction actually proceeds. Threshold transaction reports apply to large cash transactions crossing the regulatory threshold, and annual compliance reporting rounds out the reporting calendar. AUSTRAC and Home Affairs frame these alongside enrolment and CDD as six connected obligations that make up the regime rather than isolated boxes to tick.
Build these habits into your practice calendar:
- Set review dates for higher-risk clients rather than waiting for a red flag to force the issue
- Brief staff on what “reasonable grounds to suspect” looks like in practice, using real (anonymised) scenarios
- Log every SMR consideration, including the ones you decided not to lodge, with your reasoning
Records supporting all of this, from the original CDD through to reporting decisions, need to be kept for seven years in a tamper-evident format under the AML/CTF Act. A supervisor reconstructing a file years later should be able to follow your reasoning without a phone call to ask what you meant.
Using AUSTRAC’s starter kit without over-relying on it
AUSTRAC’s document library for accountants includes a customisable program guide, role appointment forms, risk assessment templates, and annual report templates. It is a genuinely useful starting point. It is also, by AUSTRAC’s own warning, not a finished product.
Work through it in this order:
- Complete your designation audit and draft risk assessment first, before opening any template.
- Adapt the starter kit’s risk assessment structure to the specific services your audit identified as captured.
- Rewrite policy clauses so each one references the risk item it addresses, rather than copying generic language.
- Circulate the draft to your compliance officer and key client-facing staff for a workflow sanity check before sign-off.
- Set a twelve-month review date in the practice calendar.
A small practice with one or two designated service lines can realistically work through this in a few weeks, provided the designation audit is done properly first. Rushing the adaptation step is where most gaps creep in.
How a compliance platform fits into the program in practice
A platform can link your risk assessment, policies, training records, and CDD outcomes so they stay consistent with each other, which is exactly where manually adapted templates tend to drift apart over time. When checking any platform, look for beneficial ownership resolution run against a company’s ACN, biometric liveness checks alongside document verification, PEP and sanctions screening with ongoing re-screening, and an officer approval step before CDD proceeds rather than a black box decision.
- Confirm beneficial ownership tracing reaches trusts and SMSFs through their corporate trustee’s own ACN, not just company lookups
- Check that records are stored tamper-evidently, not just backed up
- Verify the platform logs the reasoning behind each risk determination, not only the outcome
Pro Tip: No platform makes the judgement call for you. It automates the lookups and the record keeping; your compliance officer still has to decide what a flagged result means for that specific client.
What Tranche 2 onboarding keeps teaching us
The recurring mistake isn’t ignorance of the law. It’s copying a starter kit template wholesale, assigning a compliance officer title without giving them real authority, or skipping beneficial ownership tracing for trusts because it looked complicated. Fix those three things early. If you want a practical walkthrough of how the pieces fit together for your practice, a demo conversation costs you an hour and saves considerably more than that in rework.
**
Getting your AML/CTF program running without building it from scratch
Some compliance platforms give accounting practices a faster path to a defensible AML/CTF program than assembling one manually from separate templates, spreadsheets, and a compliance officer’s personal notes. Instead of maintaining a risk assessment in one document and policies in another that quietly drift out of sync, guided wizards produce the risk assessment, policies, compliance action plan, and staff training manual as one linked set, built from the same answers.

For the customer due diligence side, the platform runs identity verification with document and biometric checks, sanctions and PEP screening with ongoing re-screening, and beneficial ownership determination through a company’s ACN, reaching trusts and SMSFs through their corporate trustee. Every determination sits behind an officer approval step, and the seven-year tamper-evident audit trail means a supervision request doesn’t turn into a scramble through old email threads. AML Guard is not self-service software you sign up for on a whim. Firms start by booking a demo, after which the platform is configured to their actual designated services and risk profile.
Where to check the primary sources
Work from primary sources, not secondhand summaries:
- The AML/CTF Act 2006 (Cth) for statutory obligations, including section 41 reporting duties
- AUSTRAC’s accounting program starter kit and its document library for templates to adapt, not adopt unchanged
- CPA Australia and CA ANZ member guidance, alongside DFAT’s sanctions lists, for screening obligations that intersect with your CDD process
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
Sources
- Accounting program starter kit: Getting started | AUSTRAC
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 - Federal Register of Legislation
Recommended
- Tranche 2 AML Australia: your compliance obligations explained
- Tranche 2 customer due diligence in Australia
- AML/CTF Program Documents for Tranche 2
- Acceptable ID documents for Tranche 2 firms
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.