Compliance

Australia’s AML/CTF Tranche 2 Reforms Are Now in Force — Is Your Business Compliant?

Australia’s AML/CTF tranche 2 reforms commenced on 1 July 2026. Businesses providing certain designated services across the legal, accounting, conveyancing and real estate sectors, along with trust and company service providers and dealers in precious metals and precious stones, now operate under the country’s expanded anti-money-laundering and counter-terrorism-financing regime.

The preparation period is over. Since 1 July 2026, designated services provided by those businesses have been subject to the regime — which means AML/CTF compliance should already be part of day-to-day operations rather than a project with a future start date.

Tranche 2: the dates that matter

  • 31 March 2026 — AUSTRAC Online enrolment opened for newly regulated businesses. This is also the date reformed obligations commenced for existing reporting entities, which is a separate change and not the tranche 2 commencement date.
  • 1 July 2026 — Tranche 2 obligations commenced. The relevant schedules of the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 took effect.
  • 29 July 2026 — Initial enrolment deadline for businesses already providing designated services at commencement, reflecting the rule that a business enrols within 28 days of first providing a designated service.
  • Compliance officer notification — for newly regulated businesses the transitional deadline was the later of 29 July 2026, or 14 days after enrolment.

Confirmed against AUSTRAC guidance and the Federal Register of Legislation. Last reviewed 4 September 2026 · next review due 1 July 2027. Confirm your own position with AUSTRAC.

What Being a Reporting Entity Actually Means Now

If the regime applies to your designated services, you are required to meet the applicable obligations now — not to have a plan for meeting them. In practice that means several things running concurrently.

An AML/CTF program that exists and operates. Not a policy document produced once, but a program describing how the business identifies, mitigates and manages money-laundering and terrorism-financing risk, and which is actually followed.

A risk assessment that assesses something. The program must be grounded in the ML/TF risk the business genuinely faces given its customers, the services it provides, its delivery channels and the jurisdictions it deals with. A generic template risk assessment is a common and highly visible weakness.

Customer due diligence in operation. Identifying and verifying customers, establishing beneficial ownership where an entity is involved, applying enhanced measures to higher-risk relationships, and keeping that current rather than frozen at onboarding.

Ongoing monitoring and reporting. Monitoring proportionate to the risk, and reporting to AUSTRAC. That means suspicious matter reports (SMRs), triggered by suspicion rather than by any dollar threshold; threshold transaction reports (TTRs); and international funds transfer instructions (IFTIs) where applicable. Each has its own trigger and timeframe.

Records that can answer a question later. AML/CTF records are kept for seven years — retrievable, and capable of explaining a decision made years earlier. Seven years is long enough that the people who made a decision may no longer be at the firm, which is the practical argument for capturing the reasoning rather than only the outcome.

An AML/CTF Compliance Officer. The regime requires a named person — commonly the AMLCO — to own the program day to day. It is an accountable role, not a title added to somebody’s signature block.

Training and independent review. Staff have to be trained to recognise and report risk, and the program itself is subject to independent review at appropriate intervals. These two are the most commonly deferred, because neither produces an immediate deliverable — and both are conspicuous in their absence.

If You Are Behind

The initial 29 July 2026 enrolment deadline has passed. A business required to enrol that has not done so should address it promptly rather than letting it run, and take advice on its specific position.

For firms that have enrolled but whose implementation is incomplete, the priority has shifted from preparing for tranche 2 to closing compliance gaps — and to being able to show what has been done and what is still in progress. A partially implemented program that is documented and being worked through is a materially different position from an absence of one.

Firms Still Building Their First Program

A business discovers it needs a much more structured process than it has, often after commencement rather than before it. The temptation is a customer spreadsheet, a risk spreadsheet, a policy document, an evidence folder, a reporting calendar — and then a second spreadsheet because the first became unmanageable.

That works at ten customers. At two hundred, spread across several partners who each onboard differently, it stops working, and the failure mode is silent: nobody notices the gap until somebody asks about a specific file.

The Question You Will Eventually Be Asked

Imagine a firm onboarding a higher-risk customer. The process runs: identity verified, beneficial ownership established, source of funds considered, risk rating assigned, enhanced measures applied, decision approved.

Two years later somebody asks why that customer was accepted. The difference between a firm that can answer from records and a firm answering from memory is not a difference in integrity. It is a difference in whether the process wrote anything down at the time.

Reconstructing due diligence retrospectively is far more expensive than capturing it as it happens, and considerably less convincing. Now that the obligations are live, every customer onboarded from here is either building that record or adding to the gap.

What Compliance Software Can and Cannot Promise

Software should not claim to make a business compliant. It cannot: compliance depends on the judgements the firm makes and the obligations that apply to it specifically.

The credible promise is narrower and more useful — a structured way to manage the work, so obligations are visible, decisions are recorded, and evidence exists where somebody can find it. With the regime in force, the value of that has changed from preparatory to operational.

Disclosure: AML/CTF Compliance is built by BizziGroup, BizziKit’s parent company. This article describes a product we have a commercial interest in. It is general information about compliance practice, not legal or professional advice — verify the obligations that apply to your business with AUSTRAC and your own advisers.

BizziGroup’s AML/CTF Compliance is built for the tranche 2 businesses now captured by the reforms. It covers the obligations above in one place — building the AML/CTF program, running customer due diligence, maintaining the ML/TF risk register, managing AUSTRAC reporting, and keeping records and training current. It runs in the browser, and your data stays there.

See how AML/CTF Compliance works →

Frequently Asked Questions

When did tranche 2 commence?

Tranche 2 obligations commenced on 1 July 2026, when the relevant schedules of the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 took effect for newly regulated designated services.

Which businesses are affected?

Businesses providing newly regulated designated services in the legal, accounting, conveyancing and real estate sectors, plus trust and company service providers and dealers in precious metals and precious stones. Whether a particular service you provide is a designated service is a question for AUSTRAC and your own advisers.

What if we have not enrolled yet?

The initial enrolment deadline of 29 July 2026 has passed. A business required to enrol that has not done so should address it promptly rather than waiting, and take advice on its position.

What does an AML/CTF program have to cover?

How the business identifies, mitigates and manages money-laundering and terrorism-financing risk — grounded in a risk assessment reflecting its actual customers, services, delivery channels and jurisdictions, and supported by customer due diligence, monitoring, reporting and record-keeping.

How long must AML/CTF records be kept?

Seven years. That is long enough that the staff who made a decision may have moved on, which is why the reasoning behind a decision matters as much as the outcome.

What is an AMLCO?

The AML/CTF Compliance Officer — the named person responsible for the program day to day. Appointing one is an obligation, and for newly regulated businesses the transitional notification deadline was the later of 29 July 2026 or 14 days after enrolment.

What is a suspicious matter report?

A report to AUSTRAC made when a reporting entity forms a relevant suspicion about a customer or transaction. It is triggered by suspicion, not by any transaction value.