Introduction
Australia’s anti-money laundering and counter-terrorism financing (AML/CTF) regime was significantly expanded through the Tranche 2 reforms. The reforms were enacted principally through the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) (AML/CTF Amendment Act), with the obligations applying to newly regulated designated services from 1 July 2026.
Businesses providing these newly ‘designated services‘ are now considered reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act). This article outlines what these Tranche 2 entities need to know, covering key compliance requirements such as enrolling with the Australian Transaction Reports and Analysis Centre (AUSTRAC), conducting risk assessments, performing customer due diligence, and meeting new reporting obligations.
Interactive Tool: See If Your Business Must Comply With Tranche 2 Reforms
AML/CTF Tranche 2 Compliance Readiness Checker
Quickly check if your business is caught by the new AML/CTF Tranche 2 reforms and what you must do next.
What type of services does your business provide?
Have you started providing these services on or after 1 July 2026?
Are any of your transactions (for precious dealers) $10,000 or more and paid in cash or virtual assets?
✅ You Are a Tranche 2 Reporting Entity
Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Section 106 of the Strata Schemes Management Act 2015 (NSW)
⚖️ Limited AML/CTF Obligations Apply
Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
❌ Not a Designated Service Under Tranche 2
Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
⚠️ Special Rules for Existing Clients
Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
What Are the AML/CTF Tranche 2 Reforms for AUSTRAC Regulated Entities?
Why Australia Expanded the AML/CTF Regime
The Tranche 2 reforms expand Australia’s AML/CTF laws to address vulnerabilities in the national framework. These changes aim to close regulatory gaps that could be exploited for ML/TF.
A key driver for this expansion is to align Australia’s regime with international standards established by the Financial Action Task Force (FATF). Bringing sectors like real estate professionals, lawyers, and accountants under the AML/CTF framework brings Australia more in line with these global expectations.
What Commenced on 1 July 2026
The substantive AML/CTF obligations applying to the newly regulated designated services commenced on 1 July 2026. However, the legislation does not mandate full compliance by that date — different obligations have different transitional timelines, statutory triggers and deadlines.
Affected businesses are expected to have several key measures in place, including:
- a risk-based and appropriately tailored AML/CTF program under Sections 26B, 26C and 26F of the AML/CTF Act;
- the designation of an AML/CTF compliance officer under Sections 26J and 26K;
- initial and ongoing training for personnel who perform functions relevant to the entity’s obligations, as required by Section 26F(4)(e); and
- processes for initial and ongoing customer due diligence (CDD) under Sections 28 and 30, enhanced CDD under Section 32, suspicious matter reporting under Section 41 and threshold transaction reporting under Section 43, where those provisions apply.
Tranche 2 Entities: Which Businesses Are Regulated From 1 July 2026?
Legal Professionals Conveyancers & Settlement Service Providers
Legal and conveyancing professionals are subject to AML/CTF obligations when they provide certain designated services. Regulation is based on the specific activities performed for a client, not simply the professional’s title.
Relevant professional services under Table 6 in Section 6 of the AML/CTF Act include assisting a client with, or acting for a client in, specified transactions involving:
- buying, selling or transferring real estate;
- buying, selling or transferring a body corporate or legal arrangement;
- receiving, holding, controlling, disbursing or managing money, accounts, securities, virtual assets or other property as part of a transaction;
- arranging equity or debt financing connected with a body corporate or legal arrangement;
- transferring a shelf company;
- creating or restructuring a body corporate or legal arrangement;
- acting, or arranging for another person to act, in specified positions such as director, secretary, partner, trustee, or attorney; and
- acting, or arranging for another person to act, as a nominee shareholder.
Accountants & Trust and Company Service Providers
Accountants and trust and company service providers are captured by the Tranche 2 reforms when they provide one or more of the professional services listed in Table 6 in Section 6 of the AML/CTF Act.
Relevant services may include:
- establishing, administering, or restructuring companies, trusts, or other legal arrangements;
- acting, or arranging for another person to act, as a director, company secretary, partner, trustee, or holder of a power of attorney;
- acting, or arranging for another person to act, as a nominee shareholder;
- providing a registered office, principal place of business, correspondence address or administrative address;
- managing client money or other property as part of a specified transaction.
Ordinary accounting, tax-return preparation, bookkeeping or advisory work is not automatically a designated service.
Real Estate Professionals & Property Transaction Services
Real estate professionals are regulated when they provide either of the real estate designated services in Table 5 in Section 6 of the AML/CTF Act.
Designated services in this sector include:
- brokering the sale, purchase, or transfer of real estate on behalf of a seller, buyer, transferor, or transferee in the course of carrying on a business; and
- selling or transferring real estate in the course of carrying on a business of selling real estate, where the transaction is not brokered by an independent real estate agent.
Certain activities, standing alone, generally do not satisfy Table 5, including:
- property management;
- residential tenancy agreements; and
- the leasing of commercial real estate.
Dealers in Precious Metals Stones & Products
Dealers who transact in precious metals, stones, or related products face new obligations based on transaction value and the method of payment. These rules are designed to prevent high-value goods from being used to launder illicit funds.
Under Table 2, item 1 in Section 6 of the AML/CTF Act, buying or selling bullion in the course of carrying on a bullion business is a designated service.
Separately, Table 2, item 2 applies when a person buys or sells other precious metal, precious stones or precious products in the course of carrying on a business and:
- the transaction, or a series of apparently linked transactions, has a total value of AUD 10,000 or more; and
- the transaction involves payment in physical currency or virtual assets.
This may include:
- precious metals such as gold, silver, platinum, and palladium;
- precious stones such as diamonds, sapphires, rubies, emeralds, opals, and pearls; and
- precious products such as jewellery or watches containing precious metals or stones
Transactions below this threshold, or those paid for with other methods like credit cards or BPAY, do not trigger these specific compliance requirements.
General AML/CTF Obligations of Tranche 2 Entities
Enrolling With AUSTRAC
Under Section 51B(1) of the AML/CTF Act, businesses providing designated services under the Tranche 2 reforms must enrol with AUSTRAC. The enrolment period began on 31 March 2026, and organisations have 28 days to complete this process after they commenced offering a designated service.
Accordingly, a newly regulated entity that first commenced providing a designated service on 1 July 2026 ordinarily had until 29 July 2026 to apply for enrolment.
This enrolment is a foundational step that is separate from the substantive compliance obligations. During enrolment, businesses must provide AUSTRAC with key details, including:
- their business structure;
- the types of designated services offered;
- relevant earnings information; and
- contact information for key personnel.
Conducting an ML/TF Risk Assessment
As per Sections 26B and 26C of the AML/CTF Act, a primary obligation for newly regulated entities is to conduct a thorough ML/TF/PF risk assessment, and the steps taken to identify and assess those risks must be appropriate to the nature, size, and complexity of the entity’s business.
This involves a detailed analysis of several factors, including:
- the designated services provided or proposed to be provided;
- the kinds of customers to whom those services are or will be provided;
- the delivery channels used, including new and emerging technologies;
- the countries with which the business deals;
- relevant risk information communicated by AUSTRAC; and
- any matters specified in the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth) (AML/CTF Rules).
Preparing & Maintaining an AML/CTF Program
Following the risk assessment, every reporting entity must develop, implement, and maintain an AML/CTF Program. Under Section 26B of the AML/CTF Act, this program must document the policies, procedures, and controls the business has in place to mitigate the ML/TF risks identified in its assessment.
Under Section 26F(8) of the AML/CTF Act, the entity cannot provide a designated service without compliant AML/CTF policies. Further, as per Section 26N of the AML/CTF Act and Rule 5-15 of the AML/CTF Rules, the initial program must be documented before the entity provides its first designated service.
The AML/CTF Program is a living document that needs to be kept up-to-date to reflect any significant changes to the business or its risk profile.
Appointing an AML/CTF Compliance Officer
Organisations must appoint an AML/CTF Compliance Officer to oversee their compliance obligations, and this individual plays a central role in the day-to-day operation of the AML/CTF Program, in terms of Section 26J of the AML/CTF Act.
The appointed officer must be at a management level and have sufficient authority and resources to perform their duties effectively. The officer must also be a fit and proper person. Key responsibilities include:
- overseeing the organisation’s compliance with its AML/CTF Program;
- managing communication with AUSTRAC; and
- ensuring the program remains effective and up-to-date.
Under Section 26K(1), if an officer has not already been designated when the entity commences providing a designated service, the entity must designate one within 28 days. Further, as per Section 26M(1), AUSTRAC must be notified within 14 days after the officer is designated.
New Customer Due Diligence Requirements
Identifying & Verifying Customers
Under Section 28(1) of the AML/CTF Act, reporting entities must perform initial CDD before providing a designated service. This process requires collecting and verifying a customer’s identity based on reasonable grounds. The objective is to establish a clear understanding of who the customer is from the outset of the business relationship.
The information collected and verified at this step usually includes:
- the customer’s identity;
- the identity of any person on whose behalf the customer is receiving the service;
- the identity and authority of anyone acting for the customer;
- the identity of the customer’s beneficial owners, where the customer is not an individual;
- whether relevant persons are politically exposed persons (PEP) or persons designated for targeted financial sanctions;
- the nature and purpose of the business relationship or occasional transaction; and
- any additional matters prescribed by the Rules.
Understanding Beneficial Ownership & Control
CDD extends beyond identifying the immediate client. For many Tranche 2 entities, a key obligation is to understand the beneficial ownership and control of their customers. As per Section 5 of the AML/CTF Act, a beneficial owner of an entity is an individual who:
- ultimately owns, directly or indirectly, 25% or more of the entity; or
- directly or indirectly controls the entity.
This is particularly relevant when dealing with partnerships, companies, trusts, or other complex legal structures. Businesses must look through the corporate veil to identify the individuals who ultimately own or control the entity. Simply collecting an ABN or ACN is not sufficient.
Applying Enhanced Due Diligence to Higher-Risk Customers or Transactions
Where a customer or transaction presents a higher risk of ML/TF, standard due diligence is not enough. In these situations, reporting entities must apply enhanced CDD measures, as stated in Section 32 of the AML/CTF Act.
Enhanced due diligence involves taking additional steps to verify information and understand the nature of the business relationship. Examples of such measures, among other things, include:
- Conducting inquiries into the customer’s source of wealth and funds.
- Applying more rigorous verification procedures for PEPs.
- Increasing the monitoring of transactions for unusual activity.
Keeping Customer Due Diligence Records
A crucial part of the CDD process is maintaining accurate and complete records. Under Section 111 of the AML/CTF Act, this is essential for compliance with the applicable CDD obligations.
All records related to CDD, including identity verification documents and risk assessments, must be retained for a period of seven years. Further, the records should be protected against unauthorised access and maintained in a form that can be produced when lawfully required.
Applicable Reporting & Record-Keeping Obligations
Suspicious Matter Reporting
Reporting entities are mandated by Section 41 of the AML/CTF Act to submit Suspicious Matter Reports (SMRs) to AUSTRAC. This duty is triggered when there are reasonable grounds to suspect that a matter is connected to criminal activity or that a person is not who they claim to be. The timelines for these reporting obligations are strict.
A report must be filed with AUSTRAC:
- within 24 hours of forming a suspicion related to TF; or
- within three business days for suspicions related to all other matters, such as ML.
The obligation is triggered by reasonable grounds for the statutory suspicion, not merely by a general sense that a customer or transaction is unusual. However, unusual activity should be assessed promptly because it may provide the grounds for a report.
Threshold Transaction Reporting
Another key reporting obligation involves large cash transactions. Under Section 43 of the AML/CTF Act, businesses must submit Threshold Transaction Reports (TTRs) to AUSTRAC for any individual transaction that involves AUD 10,000 or more in physical currency, or the foreign currency equivalent.
This report must be completed and submitted within 10 business days from the date of the transaction. This requirement helps law enforcement to detect and monitor significant cash movements that could be linked to illicit activities.
International Value Transfer Reporting
The Tranche 2 reforms also introduce reporting requirements for international value transfers. This mandate, contained in Sections 45 and 46 of the AML/CTF Act, applies only to entities that offer “international value transfer service” (IVTS) covered by Table 1, items 29 or 30.
These additional reporting mandates generally do not apply before the reporting entity’s IVTS transition date. The default transition date is 31 March 2029. Until then, the former international funds transfer instruction reporting regime continues to apply to entities already subject to that regime, subject to the transitional provisions.
Record-Keeping for AML/CTF Compliance
Maintaining accurate and complete records is a foundational component of AML/CTF compliance. Reporting entities must securely store all documentation related to their compliance activities.
For most obligations, records must be retained for a period of seven years. This includes keeping detailed records of:
- the organisation’s AML/CTF program;
- all CDD checks and decisions;
- transaction records; and
- records of staff training sessions.
Practical Next Steps for AUSTRAC-Regulated Entities
Newly regulated businesses should prioritise the following practical steps:
- Confirm which services are regulated: Map each service against the designated services in Section 6 of the AML/CTF Act 2006. A business is regulated only when it provides a designated service, not merely because it belongs to a particular profession.
- Update client onboarding: Build initial CDD into matter intake and onboarding processes, including customer identification, beneficial ownership checks and customer-risk assessment. Procedures should also address ongoing and enhanced CDD.
- Establish governance and oversight: A senior manager must approve the risk assessment and AML/CTF policies, while the governing body must exercise ongoing oversight and take reasonable steps to support compliance.
- Train relevant personnel: Provide initial and ongoing training to personnel whose roles relate to AML/CTF compliance, as required by Section 26F(4)(e) of the AML/CTF Act and Rule 5-9 of the AML/CTF Rules. Staff should understand relevant risks, red flags and internal escalation procedures.
- Keep the program current: Review the risk assessment and AML/CTF policies when services, customers, delivery channels or jurisdictions change, and at least once every three years, in accordance with Sections 26D and 26F.
- Arrange independent evaluation: The AML/CTF program must be independently evaluated at a frequency appropriate to the business and at least once every three years under Section 26F(4)(f) and Rule 5-10.
- Maintain evidence of compliance: Retain appropriate records of risk assessments, CDD, transactions, training, and program implementation for the specified periods.
Conclusion
The Tranche 2 reforms significantly expand Australia’s AML/CTF obligations to a new sector of businesses. Reporting entities providing designated services must now implement a compliant AML/CTF program, conduct CDD, and meet strict reporting requirements to manage financial crime risk.
Meeting these new compliance obligations requires careful planning and implementation. If your organisation needs assistance developing a tailored AML program or requires an independent evaluation, contact the AML/CTF experts at Click Legal.