
A law firm has AML/CTF obligations only for work that is a designated service, and for most firms that means Table 6 of the AML/CTF Act 2006 (Cth): conveyancing and other real estate transactions, holding client money as part of a transaction, buying or selling companies and trusts, creating or restructuring them, acting as a director, trustee or nominee, and providing a registered office. If any of that applies, map every matter type against Table 6, have the ML/TF risk assessment in place before the first captured service (section 26E), apply to enrol with AUSTRAC no later than 28 days after starting, and carry out initial customer due diligence.
TL;DR:
- A law firm is regulated only for work listed as a designated service, such as conveyancing, holding client money in a transaction, or creating companies and trusts, not for every matter it runs.
- Firms must map each matter against Table 6 to determine if a designated service is provided, focusing on the substantive connection to transactions rather than just advice or litigation.
- After confirming a service, firms must apply to enrol with AUSTRAC no later than 28 days after starting it (section 51B), have a senior manager approve the risk assessment and policies, run customer due diligence, and keep CDD records until seven years after the client relationship ends.
- Automated platforms can streamline risk assessments, identity checks, and record-keeping, but a person should still review each result before a designated service proceeds.
- Training, governance oversight, and periodic reviews are vital for embedding AML/CTF compliance into practice management and protecting client and firm reputation.
Table of Contents
- Who Tranche 2 captures: the designated services in Table 6 that matter for law firms
- Key obligations at a glance: enrolment, program, initial CDD, reporting and records
- Practical implementation steps: mapping services, building the risk assessment and running CDD workflows
- How integrated platforms can support Tranche 2 program requirements
- Governance, training and review: embedding AML/CTF into firm oversight
- Perspective: why treat Tranche 2 as client and reputation protection
- How AML Guard supports law firms’ Tranche 2 obligations
- Sources
- FAQ
Who Tranche 2 captures: the designated services in Table 6 that matter for law firms
Tranche 2 does not capture every law firm, and it does not capture every matter within a captured firm. The trigger is the service, not the profession. AUSTRAC’s guidance on professional designated services explains that obligations depend on the services a firm provides; for law firms that usually means the services listed in Table 6.
For legal practices, the services most likely to apply are:
- Assisting a client to buy, sell or otherwise transfer real estate, including conveyancing (item 1).
- Assisting a client to buy, sell or transfer a company, trust or other legal arrangement (item 2).
- Receiving, holding and controlling or managing a client’s money or other property as part of a transaction, such as trust account money in a settlement (item 3). Some money is excluded, such as payment of the firm’s own fees.
- Assisting with equity or debt financing for a company or trust (item 4).
- Assisting a client to create or restructure a company or trust (item 6).
- Acting as, or arranging, a director, secretary, trustee or nominee shareholder, or providing a registered office or principal place of business address (items 7 to 9).
AUSTRAC’s test is whether the firm’s work directly advances the transaction or the creation of the entity; merely influencing how the client proceeds, general advice or ancillary services is not enough. The customer is the person the table names, usually the client the firm assists. For creating a company or an express trust it also includes the directors and beneficial owners, or the trustee, settlor and beneficiaries. Litigation generally falls outside Table 6, as does a transfer that results from a court or tribunal order.
Key obligations at a glance: enrolment, program, initial CDD, reporting and records
Once a firm establishes that it provides a designated service, these obligations apply, and the ML/TF risk assessment must be in place before the first designated service is provided (section 26E):
- Enrolment: apply to enrol with AUSTRAC no later than 28 days after starting to provide a designated service (section 51B).
- AML/CTF program: document a business-wide ML/TF risk assessment and a set of AML/CTF policies, with senior manager approval recorded.
- Initial CDD: identify and verify the customer, and any beneficial owners, before the designated service begins unless the Act and Rules allow it to be delayed. A firm acting for the buyer of real estate can delay it, where that is essential to avoid interrupting the ordinary course of business and the added risk is low (section 29), until the earlier of 28 days after exchange or 3 days before the initially agreed settlement day (Rules section 6-32). Enhanced CDD applies where section 32 requires it, such as a high-risk client or a foreign PEP.
- Reporting: lodge a suspicious matter report (SMR) under section 41 where suspicion arises, and a threshold transaction report where applicable.
- Record-keeping: keep CDD records until seven years after the client relationship ends (section 111), and transaction records for seven years from when they are made (section 107).
CDD records must be kept until seven years after the client relationship ends or the occasional transaction is completed, which means the retention obligation often outlasts the matter itself by a considerable margin. Section 111 requires those records to include any analysis, risk assessment or decision making about the client, so a folder of documents with no recorded reasoning is incomplete.
Practical implementation steps: mapping services, building the risk assessment and running CDD workflows
Turning these obligations into working controls is a sequencing problem more than a legal one. A workable rollout looks like this:
- Map every service line and matter type against Table 6. Go practice group by practice group and record, for each matter type, whether a designated service is provided and who the customer is.
- Draft a business-wide ML/TF risk assessment. Cover client types, jurisdictions, delivery channels and service lines, and have a senior manager formally approve it. Controls should scale with risk rather than apply uniformly.
- Adapt policies using AUSTRAC’s baseline. The legal profession program starter kit gives small practices a document library and example scenarios to customise, though it does not substitute for advice on the firm’s own risk profile.
- Build CDD workflows into intake. This means identity verification for individuals, beneficial ownership checks run on a company’s ACN, and for trust or SMSF clients, the trust’s own details (the trustee, the beneficiaries or classes of beneficiary, and anyone who controls the trust), with a corporate trustee resolved on its own ACN. Set clear triggers for enhanced CDD as section 32 has them, such as a high ML/TF risk rating, a foreign PEP, or a jurisdiction the FATF has called for enhanced due diligence on.
- Tighten trust account controls. Document who authorises receipts and disbursements from trust money, and keep that reasoning alongside the CDD file for the matter.
Pro Tip: Build the Table 6 mapping into your matter-opening checklist so fee earners answer the designated-service question before a file is opened, not after.
How integrated platforms can support Tranche 2 program requirements
A firm can meet every obligation above manually, but doing so consistently across practice groups is where most programs break down. Purpose-built platforms address that consistency problem directly, rather than replacing legal judgement.
- Generating the risk assessment, policies, action plan and training manual as one linked set, so a change in the risk assessment flows through to policy wording.
- Running identity verification, document checks and biometric liveness checks alongside sanctions and PEP screening.
- Resolving beneficial ownership on a company’s ACN, with trusts and SMSFs reached through their corporate trustee’s own determination.
- Recording each decision and its reasoning in a tamper-evident audit trail.
- Keeping identity documents and CDD evidence out of email and shared drives, in a system with its own access record.
Pro Tip: Whatever tool a firm uses, an AML/CTF compliance officer should approve each determination before the designated service proceeds; automation can run the lookups, but it cannot substitute for that sign-off.
Governance, training and review: embedding AML/CTF into firm oversight
A program is only as strong as the people running it. Every reporting entity must designate an AML/CTF compliance officer at management level (section 26J), and its governing body must oversee the program (section 26H), not just its existence on paper.
- Training should be role-specific: fee earners need to recognise red flags at intake, while trust accounting staff need to understand payment authorisation controls.
- Completion records for that training should be kept alongside the rest of the compliance file, so a supervisor can see who was trained and when.
- The risk assessment must be reviewed at least every three years and when the firm’s services, clients or jurisdictions change materially (section 26D), and the program needs an independent evaluation at least every three years (section 26F).
Treating the program as a living document, rather than a one-off compliance exercise, is what keeps it defensible under scrutiny.
Perspective: why treat Tranche 2 as client and reputation protection
Firms that bolt AML/CTF checks onto intake as an afterthought tend to create friction exactly where clients notice it most: at the start of the relationship. Embedding these checks into existing onboarding, and documenting the reasoning behind each judgement call, protects both the client relationship and the firm’s standing with its regulator. Proportionate, well-recorded controls beat perfect ones that arrive too late. Some firms also use a phone answering service, such as Callspace’s AI phone answering for lawyers, to keep first contact with new clients consistent; the identity checks still happen in the CDD workflow.
How AML Guard supports law firms’ Tranche 2 obligations
Firms that want a purpose-built system rather than a stitched-together set of templates and spreadsheets have another option. AML Guard produces a firm’s risk assessment, AML/CTF policies, action plan and training manual as one linked set, runs identity and beneficial ownership checks (company determinations on the ACN, with trusts reached through their corporate trustee’s own determination), and keeps an 8-year tamper-evident audit trail, above the Act’s seven-year minimum. An officer approves each determination before customer due diligence proceeds. If you’re weighing this against a manual build, see pricing on the AML Guard site or book a demo through the AML Guard homepage to see how a tenant would be configured to your designated services.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Professional designated services | AUSTRAC
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Legal profession program starter kit | AUSTRAC
FAQ
Does legal professional privilege exempt a firm from AML/CTF obligations?
No. Section 242 of the AML/CTF Act preserves the right to refuse to give information or produce a document on the ground of legal professional privilege, and the privilege belongs to the client. It does not excuse a firm from enrolling with AUSTRAC, maintaining an AML/CTF program, or conducting customer due diligence on captured matters, and how privilege applies to a specific matter is a question for legal advice rather than general guidance.
Which legal services count as designated services under Tranche 2?
Conveyancing and other assistance buying or selling real estate, holding or managing client money as part of a transaction, and creating or restructuring companies and trusts are designated services under Table 6. Ordinary litigation and advisory work, where the firm is not handling the underlying transaction, generally are not.
Why do trust accounts create particular AML/CTF exposure for law firms?
A law firm that receives, holds and controls or manages client money in its trust account as part of a transaction is generally providing a designated service in its own right (Table 6, item 3), unless an exclusion in section 6(5C) applies, such as payment of the firm’s own fees. That is why documenting who authorises receipts and disbursements matters as much as the customer due diligence itself. Holding funds while acting on a client’s instructions is a point where money laundering risk concentrates.
How long must a firm keep AML/CTF compliance records?
CDD records must be kept until seven years after the client relationship ends or the occasional transaction is completed (section 111), and transaction records for seven years from when they are made (section 107). Records need to show what verification was done, what risk conclusion was reached, and who approved it.
What should a firm do first to start Tranche 2 compliance?
Start by confirming whether the firm provides a Table 6 designated service, then map matter types against that list, have the ML/TF risk assessment in place before the first captured service (section 26E), and apply to enrol with AUSTRAC no later than 28 days after starting a designated service. From there, build the business-wide ML/TF risk assessment and begin initial customer due diligence before any captured service is provided.
Recommended
- Tranche 2 AML Australia: your compliance obligations explained
- Tranche 2 customer due diligence in Australia
- AML/CTF Program Documents for Tranche 2
- AML/CTF policy template for Tranche 2 firms
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.