AML for accountants: which services are captured

AML for accountants: which services are captured

Only some accounting services are designated services. Which ones trigger AML/CTF obligations, which stay outside the regime, and how to run the test.

AML/CTF Compliance 7 September 2026 10 min read AML Guard

Not every accounting engagement triggers AML/CTF obligations. Tranche 2 captures specific designated services only: assisting with real estate or company sale transactions, managing client money or accounts, and organising contributions to create or run a company or trust. If your firm provides none of these, ordinary tax agent work, audit, and general bookkeeping stay outside the regime. If you provide even one, you must enrol with AUSTRAC and build a tailored AML/CTF program before delivering that service. Run a designation audit now and diarise your enrolment.


TL;DR:


AML Guard
Build Your Australian AML/CTF Program
AML Guard helps accounting practices manage risk assessment, policies, customer due diligence, training and records in one platform.

Table of Contents

Do you need to comply? Testing whether your service is designated

The AML/CTF Act applies to services, not industries. A firm can hold itself out as an “accounting practice” while running a mix of captured and uncaptured work, and the AML/CTF Act 2006 (Cth) tests each engagement on its own facts, not the letterhead it sits under. Professional bodies including CPA Australia make the same point when advising members to audit their own revenue streams line by line rather than assume the whole practice is either in or out.

Services that typically trigger obligations include:

Services that typically do not include ordinary tax return preparation, statutory audit work, and standard bookkeeping are those where the accountant never plans or executes the underlying transaction or handles the funds.

Run this designation audit and keep a written record of it in your AML/CTF policies:

  1. List every service line the practice bills for.
  2. Test each against the three captured categories above.
  3. Flag ambiguous engagements (trust establishment work, SMSF administration) for a documented officer decision.
  4. Record the outcome, the reasoning, and the review date in your policy document.

Enrolling with AUSTRAC: process and timing

Enrolment is not optional once a designated service is on your books. AUSTRAC treats it as a legal requirement that sits ahead of, not alongside, actually delivering that service to a client. The process runs through AUSTRAC’s online systems and asks for detail on your business structure and the designated services you provide.

The practical steps look like this:

  1. Confirm at least one designated service applies, using the audit above.
  2. Create your AUSTRAC online account and complete the business profile.
  3. Nominate your AML/CTF compliance officer as part of that profile.
  4. Build the risk assessment and policies before, not after, you take on the first captured engagement.

Enrolments for Tranche 2 opened in March 2026, and the Institute of Public Accountants’ guidance urges firms to check applicability and enrol promptly rather than wait. Do not rely on older AUSTRAC pages written for the pre-reform regime; the current program structure sits under the AML/CTF Rules 2025.

Building your AML/CTF program: risk assessment, policies, and CDD

Your program has two legal components: a business-wide ML/TF and proliferation financing risk assessment, and the AML/CTF policies that respond to it. The Act requires reporting entities to undertake this risk assessment and maintain matching policies, and the assessment has to cover proliferation financing risk alongside money laundering and terrorism financing, not just the latter two.

The risk assessment should be scoped to what your practice actually does. A firm that only assists small business owners with company incorporations faces a different risk profile to one that regularly manages settlement funds for property transactions. Review it at least annually, and sooner if you add a new service line or a client base with materially different risk (offshore beneficial owners, cash-intensive businesses).

Your policies need to visibly respond to that risk assessment. Supervisors look for a direct line between a risk you identified and a control you documented.

Customer due diligence follows from there:

Keep the operational paper trail alongside the substantive checks: the forms you used, who authorised each CDD decision, and the retained evidence.

Pro Tip: Map each policy clause back to the specific risk it mitigates before you finalise the document. A policy that cannot point to a risk assessment line is the single most common gap AUSTRAC starter kit guidance warns against, because a mismatch between the two is a common finding on supervision review.

Records supporting these determinations need to survive seven years in tamper-evident form, not just filed away and forgotten.

Governance and training: the compliance officer’s role

Every reporting entity must designate and notify AUSTRAC of an AML/CTF compliance officer. This isn’t a title you assign quietly. The AML/CTF Rules 2025 set out the officer’s functions and the notification steps required when that person changes.

Choose the officer against a short list of practical tests:

Outsourcing the administrative workload is fine. Final accountability rests with the named officer, and that responsibility cannot be delegated away entirely.

Staff training needs to cover how to spot a designated service at intake, how CDD steps apply to that service, and when to escalate to the compliance officer. Keep dated completion records for every staff member. An officer who cannot produce training records for a supervision visit has, in practice, no training program at all.

Ongoing monitoring, reporting, and record keeping

Customer due diligence does not end at onboarding. The obligation is ongoing: periodic reviews scaled to risk, and a defined trigger for escalating a client to enhanced review when their circumstances or transaction pattern shift.

Reporting sits on top of that monitoring. Section 41 of the Act requires a suspicious matter report where reasonable grounds exist, regardless of whether a transaction actually proceeds. Threshold transaction reports apply to large cash transactions crossing the regulatory threshold, and annual compliance reporting rounds out the reporting calendar. AUSTRAC and Home Affairs frame these alongside enrolment and CDD as six connected obligations that make up the regime rather than isolated boxes to tick.

Build these habits into your practice calendar:

Records supporting all of this, from the original CDD through to reporting decisions, need to be kept for seven years in a tamper-evident format under the AML/CTF Act. A supervisor reconstructing a file years later should be able to follow your reasoning without a phone call to ask what you meant.

Using AUSTRAC’s starter kit without over-relying on it

AUSTRAC’s document library for accountants includes a customisable program guide, role appointment forms, risk assessment templates, and annual report templates. It is a genuinely useful starting point. It is also, by AUSTRAC’s own warning, not a finished product.

Work through it in this order:

  1. Complete your designation audit and draft risk assessment first, before opening any template.
  2. Adapt the starter kit’s risk assessment structure to the specific services your audit identified as captured.
  3. Rewrite policy clauses so each one references the risk item it addresses, rather than copying generic language.
  4. Circulate the draft to your compliance officer and key client-facing staff for a workflow sanity check before sign-off.
  5. Set a twelve-month review date in the practice calendar.

A small practice with one or two designated service lines can realistically work through this in a few weeks, provided the designation audit is done properly first. Rushing the adaptation step is where most gaps creep in.

How a compliance platform fits into the program in practice

A platform can link your risk assessment, policies, training records, and CDD outcomes so they stay consistent with each other, which is exactly where manually adapted templates tend to drift apart over time. When checking any platform, look for beneficial ownership resolution run against a company’s ACN, biometric liveness checks alongside document verification, PEP and sanctions screening with ongoing re-screening, and an officer approval step before CDD proceeds rather than a black box decision.

Pro Tip: No platform makes the judgement call for you. It automates the lookups and the record keeping; your compliance officer still has to decide what a flagged result means for that specific client.

What Tranche 2 onboarding keeps teaching us

The recurring mistake isn’t ignorance of the law. It’s copying a starter kit template wholesale, assigning a compliance officer title without giving them real authority, or skipping beneficial ownership tracing for trusts because it looked complicated. Fix those three things early. If you want a practical walkthrough of how the pieces fit together for your practice, a demo conversation costs you an hour and saves considerably more than that in rework.

**

Getting your AML/CTF program running without building it from scratch

Some compliance platforms give accounting practices a faster path to a defensible AML/CTF program than assembling one manually from separate templates, spreadsheets, and a compliance officer’s personal notes. Instead of maintaining a risk assessment in one document and policies in another that quietly drift out of sync, guided wizards produce the risk assessment, policies, compliance action plan, and staff training manual as one linked set, built from the same answers.

AML Guard program documents generated as one linked set

For the customer due diligence side, the platform runs identity verification with document and biometric checks, sanctions and PEP screening with ongoing re-screening, and beneficial ownership determination through a company’s ACN, reaching trusts and SMSFs through their corporate trustee. Every determination sits behind an officer approval step, and the seven-year tamper-evident audit trail means a supervision request doesn’t turn into a scramble through old email threads. AML Guard is not self-service software you sign up for on a whim. Firms start by booking a demo, after which the platform is configured to their actual designated services and risk profile.

Where to check the primary sources

Work from primary sources, not secondhand summaries:

This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.

Sources

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 7 September 2026.