If you provide a Tranche 2 designated service, real estate, legal, accounting, or trust and company work, your AML/CTF obligations commenced on 1 July 2026. Enrol with AUSTRAC by 29 July 2026 if you were already active on day one, and start building your AML/CTF program now. The first job is a scope check: confirm exactly which services you provide trigger reporting-entity status before you build anything else.
TL;DR:
- Businesses providing a designated service in the real estate, legal, accounting, trust or dealer sectors became reporting entities on 1 July 2026, and had 28 days to enrol with AUSTRAC.
- The key dates are 31 March 2026 when AUSTRAC enrolment opened, 1 July 2026 when obligations commenced, and 29 July 2026 as the enrolment deadline.
- Building a compliant AML/CTF program requires a risk assessment paired with tailored customer due diligence and staff training, integrated into workflows from the start of service.
- Embedding customer verification at engagement, including beneficial ownership checks and sanctions screening, is essential to meet AUSTRAC’s trigger points.
- Using AML Guard helps streamline compliance efforts by providing automated risk assessment, documentation, CDD workflows, and reporting, aligning with AUSTRAC’s expectations.
Table of Contents
- Who is captured by Tranche 2 AML Australia rules?
- What are the key dates for AUSTRAC enrolment?
- What are the seven core AML/CTF obligations?
- How do you embed CDD into real transaction workflows?
- What must staff know about reporting and tipping-off?
- What should your first 90 days of compliance look like?
- Where can you find AUSTRAC starter kits and legislative text?
- How does AML Guard help Tranche 2 reporting entities comply?
- Why Tranche 2 is a business-model change, not a compliance bolt-on
- Book a demo and get your AML/CTF program operational
- Sources
Who is captured by Tranche 2 AML Australia rules?
Tranche 2 AML Australia obligations extend the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 to six sectors that previously sat outside the regime entirely. If your business falls into one of these categories and provides a designated service, you are a reporting entity from 1 July 2026, regardless of firm size.
The six captured sectors are:
- Real estate agents, buyers agents and property developers
- Lawyers and conveyancers handling property or business transactions
- Accountants and bookkeepers providing designated services (not general tax return preparation)
- Trust and company service providers (TCSPs)
- Dealers in precious metals and precious stones above threshold amounts
- Settlement agents facilitating property transfers
A “designated service” is a specific, listed activity, not your whole practice. A conveyancer handling settlement is caught; the same firm running a pure litigation matter is not. An accountant establishing a company or trust structure for a client provides a designated service; one lodging a standard tax return does not. A property manager arranging a tenancy is generally outside scope, while an agent selling that same property is squarely inside it.
Run this quick check: does the service involve forming, managing or transacting through a company, trust or real property on a client’s behalf? If yes, treat it as captured and build your compliance program around it.
What are the key dates for AUSTRAC enrolment?
Three dates matter more than any others in the Tranche 2 AML Australia timeline, and missing them carries real financial consequences.
- 1 July 2026 — Tranche 2 obligations commenced. Every business providing a designated service in one of the six sectors became a reporting entity on this date.
- 31 March 2026 — AUSTRAC opened enrolment ahead of commencement, giving firms a three-month window to register before obligations took effect.
- 29 July 2026 — the hard deadline. Firms providing designated services on 1 July 2026 must be enrolled within 28 days, and this is that date.
AUSTRAC enrolment isn’t a form you fill in once and forget. At sign-up, you need your ABN, a description of your business profile and the designated services you provide, details of key personnel including your AML/CTF compliance officer, and an estimate of your reporting volumes.
Late enrolment carries civil penalty exposure that accrues daily, and AUSTRAC has signalled it will pursue enforcement action against non-compliant entities rather than treat Tranche 2 as a grace period. Firms that enrol late but otherwise comply still face scrutiny for the gap, which makes the 29 July date the single most consequential entry in your compliance calendar.
What are the seven core AML/CTF obligations?
Every Tranche 2 reporting entity must build and maintain seven interlocking obligations. Miss one, and your entire program looks incomplete to an AUSTRAC reviewer, even if the other six are solid.
Your AML/CTF program has two limbs. The first is a business-wide ML/TF risk assessment: it identifies how your specific services, customer types, delivery channels and jurisdictional exposure could be misused for money laundering or terrorism financing. The second is your AML/CTF policies, which translate that risk assessment into concrete customer due diligence (CDD) procedures, staff training and reporting systems. AUSTRAC expects the policies to flow logically from the risk assessment, not sit as a generic template bolted on top. If you have seen the older Part A and Part B split referenced elsewhere, that structure was replaced by the 2024 amendments.
The seven obligations are:
- A documented, risk-based AML/CTF program: a business-wide ML/TF risk assessment plus AML/CTF policies
- Customer due diligence, including identity verification and beneficial ownership checks
- Enhanced due diligence for higher-risk customers, PEPs and sanctioned parties
- Suspicious matter, threshold transaction and international funds transfer reporting
- An appointed AML/CTF compliance officer
- Ongoing staff training relevant to each employee’s role
- Seven-year record-keeping and a periodic independent review
AUSTRAC’s obligations guidance sets out the full detail on verification standards and enhanced due diligence triggers.
Pro Tip: Build your training content around real scenarios from your own transaction types, not generic examples. A conveyancer training staff on precious metals red flags wastes time; train on the settlement scenarios your team actually sees.
How do you embed CDD into real transaction workflows?
Compliance obligations attach the moment you begin providing a designated service, not when a deal settles. That distinction trips up more firms than any other Tranche 2 requirement, because many practices only run identity checks near completion, well after the point AUSTRAC expects due diligence to have started.
For property sales, the practical sequence looks like this:
- Verify the identity of the buyer or seller at the point of engagement, before contracts are exchanged.
- Identify and verify beneficial owners where the buyer is a company, trust or SMSF, tracing ownership through each layer of the structure.
- Screen all parties against sanctions and politically exposed persons lists, and re-screen if the transaction timeline extends significantly.
- Assess risk factors, cash-heavy deals, offshore buyers, unusual settlement structures, and apply enhanced due diligence where warranted.
- Document every check and store evidence in a format that survives an audit, not just a folder of scanned IDs.
Company and trust formation work follows the same logic: verify the individuals behind the structure before you lodge anything, not after. For SMSFs, trace beneficial ownership through the trustee and members, since AUSTRAC treats these structures with the same scrutiny as discretionary trusts.
Store your UBO evidence, verification records and risk scores centrally rather than scattered across email threads and physical files. When compliance actually starts in your specific workflow is worth mapping out before you finalise your AML/CTF policies, because getting the trigger point wrong undermines everything downstream. Real estate professionals face particular pressure here given the volume and speed of typical property transactions, where settlement timelines leave little room for late-stage compliance scrambling.

What must staff know about reporting and tipping-off?
Reporting obligations run on strict timeframes, and getting them wrong, or discussing them with the wrong person, carries criminal exposure.

Suspicious matter reports (SMRs) must be filed as soon as practicable, generally within days of forming a suspicion, never batched up for convenience. Threshold transaction reports (TTRs) apply to cash transactions of $10,000 or more and must be lodged within ten business days. International funds transfer instructions (IFTIs) have their own reporting rules tied to the transfer, not the underlying transaction.
Tipping-off is a separate criminal offence: telling a client, or anyone else, that a suspicious matter report has been filed or is being considered. AUSTRAC’s tipping-off guidance is unambiguous on this point.
Train client-facing staff on this short list:
- Don’t say “we’ve reported this” or “our compliance officer flagged your file.”
- Don’t delay a transaction visibly because of a pending report.
- Do use a standard, pre-approved script for any client who asks why something is taking longer than usual.
- Do escalate internally to your compliance officer immediately, never to the client first.
Retain all CDD records, risk assessments and reporting evidence for seven years from the date the relationship ends or the transaction completes.
What should your first 90 days of compliance look like?
A structured rollout beats a scramble. Break the work into three phases.
Days 1 to 30: Run your designated-service scope check, appoint your AML/CTF compliance officer, begin AUSTRAC enrolment, and adopt a program starter kit as your drafting baseline rather than your finished product.
Days 30 to 60: Build out CDD workflows for each transaction type you handle, establish your beneficial ownership tracing procedure, and deliver initial staff training with completion records.
Days 60 to 90: Stand up transaction monitoring and reporting workflows, schedule your independent program review, and operationalise ongoing re-screening for existing clients against sanctions and PEP lists.
| Phase | Core focus | Key output |
|---|---|---|
| Days 1 to 30 | Scope and enrolment | AUSTRAC enrolment submitted, compliance officer named |
| Days 30 to 60 | CDD build-out | Working CDD and UBO tracing procedures, trained staff |
| Days 60 to 90 | Operational readiness | Reporting workflows live, independent review booked |
Where can you find AUSTRAC starter kits and legislative text?
Don’t build your program from memory or a colleague’s summary of the law. Go to the primary sources.
- AUSTRAC’s newly regulated businesses page sets out the enrolment pathway and reform timeline in full.
- The program starter kits give you a co-designed baseline template, but AUSTRAC is explicit that these need customisation to your firm’s actual risk profile, not a straight copy-paste.
- The AML/CTF Rules text on legislation.gov.au is the authoritative statutory source when you need to settle an interpretation question.
- REIA’s AML/CTF guidance translates the obligations specifically for real estate professionals, including CDD and beneficial ownership verification expectations.
Treat starter kits as a first draft, not a finished document. AUSTRAC reviewers can tell the difference between a tailored program and a template with your business name inserted.
How does AML Guard help Tranche 2 reporting entities comply?
Building all seven obligations from scratch, in-house, while running a legal, real estate or accounting practice is a significant undertaking. AML Guard was built specifically for Tranche 2 entities to close that gap without replacing the systems you already run.
The platform covers:
- Guided risk assessment, AML/CTF policies, compliance action plan and training manual, generated as one linked set so your policies always match your risk assessment
- End-to-end CDD and enhanced due diligence, including identity verification, biometric liveness checks, sanctions and PEP screening with ongoing re-screening
- Beneficial ownership tracing across companies, trusts and SMSFs
- Suspicious matter and threshold transaction reporting workflows with a seven-year tamper-evident audit trail
AML Guard integrates with REX CRM, pushing only compliance status flags against a listing, never sensitive CDD data, so your existing systems stay intact. A client-pays option lets a transaction party fund their own verification, with the fee credited back against your subscription.
Pro Tip: If your risk assessment and your CDD procedures are built in separate documents by separate people, check them against each other before your first AUSTRAC interaction, mismatches here are the most common trigger for regulator follow-up questions.
Why Tranche 2 is a business-model change, not a compliance bolt-on
Most firms treat AML/CTF as a checklist added at the end of a transaction: verify identity, tick a box, move on. That mindset fails under Tranche 2, because AUSTRAC expects due diligence woven into onboarding and sales workflows from the first client contact, not retrofitted before settlement.
The firms that pass scrutiny are the ones whose risk assessment and AML/CTF policies were built together, so a change in a client’s risk rating automatically changes what verification steps apply. Structural mismatches between the two are the most common failure point regulators flag. Treat Tranche 2 as a rebuild of how you onboard clients, not an extra form.
Book a demo and get your AML/CTF program operational
If you’re a principal, compliance officer or practice manager working through Tranche 2 for the first time, a demo with AML Guard walks through your specific designated services, current CDD process and where the gaps sit against AUSTRAC’s requirements. There’s no free trial or self-service sign-up: firms start by booking a demo, after which your tenant gets configured to your risk profile and workflow.

Most firms move from initial demo to operationally live within a few weeks, covering risk assessment sign-off, CDD workflow setup and staff training rollout in that order. AML Guard is the alternative to building your program in-house from a starter kit and spreadsheets: your risk assessment, policies, action plan and training manual come out linked and consistent, and your CDD, UBO tracing and reporting workflows run in one platform with a seven-year audit trail already built in, rather than assembled from four separate documents that drift apart over time.
Visit AML Guard to see how the platform maps to your sector’s designated services, and book a demo to get your compliance officer and team working from a single, audit-ready system before your next transaction.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Newly regulated businesses: get ready for the reforms | AUSTRAC
- Legislation
- AML/CTF | REIA
- Overview of the AML/CTF Amendment Act | Home Affairs
Recommended
- AML Guard — AML/CTF Compliance for Australian Real Estate
- AML/CTF Compliance Checklist for Real Estate Agents: What You Need Before 1 July 2026 | AML Guard
- AML Compliance Pricing in Australia: 2026 Comparison | AML Guard
- Tranche 2 AML/CTF Guide for Australian Real Estate Agents | 1 July 2026
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.