Tranche 2 AML Australia: your compliance obligations explained

Tranche 2 AML Australia: your compliance obligations explained

Understand your compliance obligations under Tranche 2 AML Australia and learn how to prepare your business for the upcoming changes.

AML/CTF Compliance 25 August 2026 11 min read AML Guard

If you provide a Tranche 2 designated service, real estate, legal, accounting, or trust and company work, your AML/CTF obligations commenced on 1 July 2026. Enrol with AUSTRAC by 29 July 2026 if you were already active on day one, and start building your AML/CTF program now. The first job is a scope check: confirm exactly which services you provide trigger reporting-entity status before you build anything else.


TL;DR:


Table of Contents

Who is captured by Tranche 2 AML Australia rules?

Tranche 2 AML Australia obligations extend the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 to six sectors that previously sat outside the regime entirely. If your business falls into one of these categories and provides a designated service, you are a reporting entity from 1 July 2026, regardless of firm size.

The six captured sectors are:

A “designated service” is a specific, listed activity, not your whole practice. A conveyancer handling settlement is caught; the same firm running a pure litigation matter is not. An accountant establishing a company or trust structure for a client provides a designated service; one lodging a standard tax return does not. A property manager arranging a tenancy is generally outside scope, while an agent selling that same property is squarely inside it.

Run this quick check: does the service involve forming, managing or transacting through a company, trust or real property on a client’s behalf? If yes, treat it as captured and build your compliance program around it.

What are the key dates for AUSTRAC enrolment?

Three dates matter more than any others in the Tranche 2 AML Australia timeline, and missing them carries real financial consequences.

  1. 1 July 2026 — Tranche 2 obligations commenced. Every business providing a designated service in one of the six sectors became a reporting entity on this date.
  2. 31 March 2026 — AUSTRAC opened enrolment ahead of commencement, giving firms a three-month window to register before obligations took effect.
  3. 29 July 2026 — the hard deadline. Firms providing designated services on 1 July 2026 must be enrolled within 28 days, and this is that date.

AUSTRAC enrolment isn’t a form you fill in once and forget. At sign-up, you need your ABN, a description of your business profile and the designated services you provide, details of key personnel including your AML/CTF compliance officer, and an estimate of your reporting volumes.

Late enrolment carries civil penalty exposure that accrues daily, and AUSTRAC has signalled it will pursue enforcement action against non-compliant entities rather than treat Tranche 2 as a grace period. Firms that enrol late but otherwise comply still face scrutiny for the gap, which makes the 29 July date the single most consequential entry in your compliance calendar.

What are the seven core AML/CTF obligations?

Every Tranche 2 reporting entity must build and maintain seven interlocking obligations. Miss one, and your entire program looks incomplete to an AUSTRAC reviewer, even if the other six are solid.

Your AML/CTF program has two limbs. The first is a business-wide ML/TF risk assessment: it identifies how your specific services, customer types, delivery channels and jurisdictional exposure could be misused for money laundering or terrorism financing. The second is your AML/CTF policies, which translate that risk assessment into concrete customer due diligence (CDD) procedures, staff training and reporting systems. AUSTRAC expects the policies to flow logically from the risk assessment, not sit as a generic template bolted on top. If you have seen the older Part A and Part B split referenced elsewhere, that structure was replaced by the 2024 amendments.

The seven obligations are:

AUSTRAC’s obligations guidance sets out the full detail on verification standards and enhanced due diligence triggers.

Pro Tip: Build your training content around real scenarios from your own transaction types, not generic examples. A conveyancer training staff on precious metals red flags wastes time; train on the settlement scenarios your team actually sees.

How do you embed CDD into real transaction workflows?

Compliance obligations attach the moment you begin providing a designated service, not when a deal settles. That distinction trips up more firms than any other Tranche 2 requirement, because many practices only run identity checks near completion, well after the point AUSTRAC expects due diligence to have started.

For property sales, the practical sequence looks like this:

  1. Verify the identity of the buyer or seller at the point of engagement, before contracts are exchanged.
  2. Identify and verify beneficial owners where the buyer is a company, trust or SMSF, tracing ownership through each layer of the structure.
  3. Screen all parties against sanctions and politically exposed persons lists, and re-screen if the transaction timeline extends significantly.
  4. Assess risk factors, cash-heavy deals, offshore buyers, unusual settlement structures, and apply enhanced due diligence where warranted.
  5. Document every check and store evidence in a format that survives an audit, not just a folder of scanned IDs.

Company and trust formation work follows the same logic: verify the individuals behind the structure before you lodge anything, not after. For SMSFs, trace beneficial ownership through the trustee and members, since AUSTRAC treats these structures with the same scrutiny as discretionary trusts.

Store your UBO evidence, verification records and risk scores centrally rather than scattered across email threads and physical files. When compliance actually starts in your specific workflow is worth mapping out before you finalise your AML/CTF policies, because getting the trigger point wrong undermines everything downstream. Real estate professionals face particular pressure here given the volume and speed of typical property transactions, where settlement timelines leave little room for late-stage compliance scrambling.

Open filing cabinet with compliance folders

What must staff know about reporting and tipping-off?

Reporting obligations run on strict timeframes, and getting them wrong, or discussing them with the wrong person, carries criminal exposure.

Hand sealing envelope for suspicious matter report

Suspicious matter reports (SMRs) must be filed as soon as practicable, generally within days of forming a suspicion, never batched up for convenience. Threshold transaction reports (TTRs) apply to cash transactions of $10,000 or more and must be lodged within ten business days. International funds transfer instructions (IFTIs) have their own reporting rules tied to the transfer, not the underlying transaction.

Tipping-off is a separate criminal offence: telling a client, or anyone else, that a suspicious matter report has been filed or is being considered. AUSTRAC’s tipping-off guidance is unambiguous on this point.

Train client-facing staff on this short list:

Retain all CDD records, risk assessments and reporting evidence for seven years from the date the relationship ends or the transaction completes.

What should your first 90 days of compliance look like?

A structured rollout beats a scramble. Break the work into three phases.

Days 1 to 30: Run your designated-service scope check, appoint your AML/CTF compliance officer, begin AUSTRAC enrolment, and adopt a program starter kit as your drafting baseline rather than your finished product.

Days 30 to 60: Build out CDD workflows for each transaction type you handle, establish your beneficial ownership tracing procedure, and deliver initial staff training with completion records.

Days 60 to 90: Stand up transaction monitoring and reporting workflows, schedule your independent program review, and operationalise ongoing re-screening for existing clients against sanctions and PEP lists.

Phase Core focus Key output
Days 1 to 30 Scope and enrolment AUSTRAC enrolment submitted, compliance officer named
Days 30 to 60 CDD build-out Working CDD and UBO tracing procedures, trained staff
Days 60 to 90 Operational readiness Reporting workflows live, independent review booked

Where can you find AUSTRAC starter kits and legislative text?

Don’t build your program from memory or a colleague’s summary of the law. Go to the primary sources.

Treat starter kits as a first draft, not a finished document. AUSTRAC reviewers can tell the difference between a tailored program and a template with your business name inserted.

How does AML Guard help Tranche 2 reporting entities comply?

Building all seven obligations from scratch, in-house, while running a legal, real estate or accounting practice is a significant undertaking. AML Guard was built specifically for Tranche 2 entities to close that gap without replacing the systems you already run.

The platform covers:

AML Guard integrates with REX CRM, pushing only compliance status flags against a listing, never sensitive CDD data, so your existing systems stay intact. A client-pays option lets a transaction party fund their own verification, with the fee credited back against your subscription.

Pro Tip: If your risk assessment and your CDD procedures are built in separate documents by separate people, check them against each other before your first AUSTRAC interaction, mismatches here are the most common trigger for regulator follow-up questions.

Why Tranche 2 is a business-model change, not a compliance bolt-on

Most firms treat AML/CTF as a checklist added at the end of a transaction: verify identity, tick a box, move on. That mindset fails under Tranche 2, because AUSTRAC expects due diligence woven into onboarding and sales workflows from the first client contact, not retrofitted before settlement.

The firms that pass scrutiny are the ones whose risk assessment and AML/CTF policies were built together, so a change in a client’s risk rating automatically changes what verification steps apply. Structural mismatches between the two are the most common failure point regulators flag. Treat Tranche 2 as a rebuild of how you onboard clients, not an extra form.

Book a demo and get your AML/CTF program operational

If you’re a principal, compliance officer or practice manager working through Tranche 2 for the first time, a demo with AML Guard walks through your specific designated services, current CDD process and where the gaps sit against AUSTRAC’s requirements. There’s no free trial or self-service sign-up: firms start by booking a demo, after which your tenant gets configured to your risk profile and workflow.

AML Guard

Most firms move from initial demo to operationally live within a few weeks, covering risk assessment sign-off, CDD workflow setup and staff training rollout in that order. AML Guard is the alternative to building your program in-house from a starter kit and spreadsheets: your risk assessment, policies, action plan and training manual come out linked and consistent, and your CDD, UBO tracing and reporting workflows run in one platform with a seven-year audit trail already built in, rather than assembled from four separate documents that drift apart over time.

Visit AML Guard to see how the platform maps to your sector’s designated services, and book a demo to get your compliance officer and team working from a single, audit-ready system before your next transaction.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 25 August 2026.