Tranche 2 AML/CTF for Australian law firms

Tranche 2 AML/CTF for Australian law firms

Which legal work is a designated service under Table 6, what enrolment and customer due diligence involve, and why privilege is not an exemption.

AML/CTF Compliance 29 September 2026 8 min read AML Guard

Solicitor reviewing AUSTRAC enrolment documents

A law firm has AML/CTF obligations only for work that is a designated service, and for most firms that means Table 6 of the AML/CTF Act 2006 (Cth): conveyancing and other real estate transactions, holding client money as part of a transaction, buying or selling companies and trusts, creating or restructuring them, acting as a director, trustee or nominee, and providing a registered office. If any of that applies, map every matter type against Table 6, have the ML/TF risk assessment in place before the first captured service (section 26E), apply to enrol with AUSTRAC no later than 28 days after starting, and carry out initial customer due diligence.


TL;DR:


AML Guard
Bring Tranche 2 Compliance Together
AML Guard connects the risk assessment, AML/CTF policies, customer due diligence, screening and audit records for Australian law firms.

Table of Contents

Who Tranche 2 captures: the designated services in Table 6 that matter for law firms

Tranche 2 does not capture every law firm, and it does not capture every matter within a captured firm. The trigger is the service, not the profession. AUSTRAC’s guidance on professional designated services explains that obligations depend on the services a firm provides; for law firms that usually means the services listed in Table 6.

For legal practices, the services most likely to apply are:

AUSTRAC’s test is whether the firm’s work directly advances the transaction or the creation of the entity; merely influencing how the client proceeds, general advice or ancillary services is not enough. The customer is the person the table names, usually the client the firm assists. For creating a company or an express trust it also includes the directors and beneficial owners, or the trustee, settlor and beneficiaries. Litigation generally falls outside Table 6, as does a transfer that results from a court or tribunal order.

Key obligations at a glance: enrolment, program, initial CDD, reporting and records

Once a firm establishes that it provides a designated service, these obligations apply, and the ML/TF risk assessment must be in place before the first designated service is provided (section 26E):

CDD records must be kept until seven years after the client relationship ends or the occasional transaction is completed, which means the retention obligation often outlasts the matter itself by a considerable margin. Section 111 requires those records to include any analysis, risk assessment or decision making about the client, so a folder of documents with no recorded reasoning is incomplete.

Practical implementation steps: mapping services, building the risk assessment and running CDD workflows

Turning these obligations into working controls is a sequencing problem more than a legal one. A workable rollout looks like this:

  1. Map every service line and matter type against Table 6. Go practice group by practice group and record, for each matter type, whether a designated service is provided and who the customer is.
  2. Draft a business-wide ML/TF risk assessment. Cover client types, jurisdictions, delivery channels and service lines, and have a senior manager formally approve it. Controls should scale with risk rather than apply uniformly.
  3. Adapt policies using AUSTRAC’s baseline. The legal profession program starter kit gives small practices a document library and example scenarios to customise, though it does not substitute for advice on the firm’s own risk profile.
  4. Build CDD workflows into intake. This means identity verification for individuals, beneficial ownership checks run on a company’s ACN, and for trust or SMSF clients, the trust’s own details (the trustee, the beneficiaries or classes of beneficiary, and anyone who controls the trust), with a corporate trustee resolved on its own ACN. Set clear triggers for enhanced CDD as section 32 has them, such as a high ML/TF risk rating, a foreign PEP, or a jurisdiction the FATF has called for enhanced due diligence on.
  5. Tighten trust account controls. Document who authorises receipts and disbursements from trust money, and keep that reasoning alongside the CDD file for the matter.

Pro Tip: Build the Table 6 mapping into your matter-opening checklist so fee earners answer the designated-service question before a file is opened, not after.

How integrated platforms can support Tranche 2 program requirements

A firm can meet every obligation above manually, but doing so consistently across practice groups is where most programs break down. Purpose-built platforms address that consistency problem directly, rather than replacing legal judgement.

Pro Tip: Whatever tool a firm uses, an AML/CTF compliance officer should approve each determination before the designated service proceeds; automation can run the lookups, but it cannot substitute for that sign-off.

Governance, training and review: embedding AML/CTF into firm oversight

A program is only as strong as the people running it. Every reporting entity must designate an AML/CTF compliance officer at management level (section 26J), and its governing body must oversee the program (section 26H), not just its existence on paper.

Treating the program as a living document, rather than a one-off compliance exercise, is what keeps it defensible under scrutiny.

Perspective: why treat Tranche 2 as client and reputation protection

Firms that bolt AML/CTF checks onto intake as an afterthought tend to create friction exactly where clients notice it most: at the start of the relationship. Embedding these checks into existing onboarding, and documenting the reasoning behind each judgement call, protects both the client relationship and the firm’s standing with its regulator. Proportionate, well-recorded controls beat perfect ones that arrive too late. Some firms also use a phone answering service, such as Callspace’s AI phone answering for lawyers, to keep first contact with new clients consistent; the identity checks still happen in the CDD workflow.

How AML Guard supports law firms’ Tranche 2 obligations

Firms that want a purpose-built system rather than a stitched-together set of templates and spreadsheets have another option. AML Guard produces a firm’s risk assessment, AML/CTF policies, action plan and training manual as one linked set, runs identity and beneficial ownership checks (company determinations on the ACN, with trusts reached through their corporate trustee’s own determination), and keeps an 8-year tamper-evident audit trail, above the Act’s seven-year minimum. An officer approves each determination before customer due diligence proceeds. If you’re weighing this against a manual build, see pricing on the AML Guard site or book a demo through the AML Guard homepage to see how a tenant would be configured to your designated services.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources

FAQ

No. Section 242 of the AML/CTF Act preserves the right to refuse to give information or produce a document on the ground of legal professional privilege, and the privilege belongs to the client. It does not excuse a firm from enrolling with AUSTRAC, maintaining an AML/CTF program, or conducting customer due diligence on captured matters, and how privilege applies to a specific matter is a question for legal advice rather than general guidance.

Conveyancing and other assistance buying or selling real estate, holding or managing client money as part of a transaction, and creating or restructuring companies and trusts are designated services under Table 6. Ordinary litigation and advisory work, where the firm is not handling the underlying transaction, generally are not.

Why do trust accounts create particular AML/CTF exposure for law firms?

A law firm that receives, holds and controls or manages client money in its trust account as part of a transaction is generally providing a designated service in its own right (Table 6, item 3), unless an exclusion in section 6(5C) applies, such as payment of the firm’s own fees. That is why documenting who authorises receipts and disbursements matters as much as the customer due diligence itself. Holding funds while acting on a client’s instructions is a point where money laundering risk concentrates.

How long must a firm keep AML/CTF compliance records?

CDD records must be kept until seven years after the client relationship ends or the occasional transaction is completed (section 111), and transaction records for seven years from when they are made (section 107). Records need to show what verification was done, what risk conclusion was reached, and who approved it.

What should a firm do first to start Tranche 2 compliance?

Start by confirming whether the firm provides a Table 6 designated service, then map matter types against that list, have the ML/TF risk assessment in place before the first captured service (section 26E), and apply to enrol with AUSTRAC no later than 28 days after starting a designated service. From there, build the business-wide ML/TF risk assessment and begin initial customer due diligence before any captured service is provided.

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 29 September 2026.