WealthWorks WealthWorks

AUSTRAC Tranche 2 Is Now in Force: Australia's 2026 AML/CTF Compliance Guide

WealthWorks Team
13 min read

Australia’s long-awaited expansion of anti-money laundering and counter-terrorism financing regulation is no longer a future project. From 1 July 2026, thousands of businesses in real estate, conveyancing, legal services, accounting and the precious stones and metals sector entered the AML/CTF regime.

AUSTRAC says newly regulated businesses must enrol by 29 July 2026. Covered businesses must do much more than collect a driver licence. They need a risk-based AML/CTF program, customer due diligence, suspicious-matter reporting, record keeping, staff training and ongoing monitoring.

The reforms affect the transaction advisers and gatekeepers involved when money moves into Australian property, companies, trusts and valuable goods. This guide explains what business owners, buyers and professional firms need to understand now.

Why Australia expanded the AML/CTF regime

Criminal proceeds rarely arrive with an obvious label. Illicit money can be layered through companies and trusts, converted into real estate or high-value goods, and moved through transactions that appear legitimate.

Australia’s earlier framework regulated banks, remitters, casinos and other established reporting entities but left several professional “gatekeeper” sectors outside the full regime. International reviews had repeatedly criticised that gap.

The July 2026 changes bring designated services in the following areas into scope:

  • real estate;
  • conveyancing;
  • legal services;
  • accounting;
  • trust and company services; and
  • dealing in precious stones and precious metals.

Coverage is based on the service provided. Not every employee or every task performed by a firm is automatically a designated service.

The immediate dates businesses need to know

DateRequirement or event
1 July 2026Expanded reporting regime came into force
29 July 2026AUSTRAC enrolment deadline stated for newly regulated businesses
From commencementCovered businesses must operate compliant controls and reporting processes
OngoingUpdate risk assessments, monitor customers, train staff and retain records

Enrolment is generally the entry into AUSTRAC’s regulated population. Remittance and virtual-asset designated service providers face registration as well as enrolment requirements.

A firm that missed the 29 July deadline should not hide the issue or delay further. It should stop, determine whether covered services are being provided, seek advice, contact AUSTRAC where appropriate and document its remediation.

Is your Australian business covered?

The correct question is not “Am I an accountant?” or “Am I an estate agent?” It is “Do I provide a designated service?”

Real estate businesses

Real estate can convert and store large amounts of value. Covered activities may arise around transactions in real property, depending on the statutory service definition and the firm’s role.

Agencies should map:

  • listing and sale processes;
  • buyer identification;
  • deposits and trust money;
  • agency authorities;
  • auctions and private sales;
  • corporate and trust purchasers;
  • overseas customers; and
  • referrals to conveyancers, lawyers and finance providers.

Property managers should not assume all leasing work is covered in the same way as sales. The designated-service analysis must be performed against current AUSTRAC guidance.

Lawyers and conveyancers

Legal professionals may facilitate property transfers, create companies or trusts, manage client money or act in transactions. Professional privilege and confidentiality remain important, but they do not justify ignoring AML/CTF obligations.

Firms need protocols that identify what can be disclosed, who makes a report and how to avoid “tipping off” a customer. These issues require legal and sector-specific guidance.

Accountants and business advisers

An accounting firm may provide routine tax-return work, entity formation, registered-office services, transaction assistance, trust administration or management functions. Different services can have different AML status.

The engagement letter, workflow and billing description should accurately state what the firm does. A practice cannot rely on calling work “tax advice” if the actual service is a covered company or trust activity.

Precious metals and stones

High-value, portable goods can be purchased, transferred and resold across borders. Dealers need to understand when a sale or related service becomes designated and whether cash or structured payments create heightened risk.

Enrolment is only the beginning

AUSTRAC enrolment does not certify a business as compliant. It tells the regulator who provides designated services. The operational obligations sit behind it.

A workable implementation has at least seven elements:

  1. governance and accountability;
  2. money-laundering and terrorism-financing risk assessment;
  3. documented AML/CTF policies and controls;
  4. customer due diligence;
  5. ongoing monitoring;
  6. regulatory reporting; and
  7. records, assurance and training.

Building a risk-based AML/CTF program

A generic policy purchased online is unlikely to reflect the firm’s customers, services, delivery channels and geography. The program should respond to the business’s actual risk.

Assess customer risk

Risk factors can include:

  • complex ownership;
  • unexplained use of nominees;
  • politically exposed persons;
  • customers connected to higher-risk jurisdictions;
  • reluctance to provide identity or source information;
  • unusual urgency;
  • a transaction inconsistent with known income or business;
  • frequent changes in purchaser or settlement instructions; and
  • third-party payments without a clear reason.

No single factor necessarily proves criminality. The purpose of a risk model is to decide what checks and escalation are proportionate.

Assess service risk

Company formation, trust arrangements, handling client money and rapid high-value property transactions may present different risks from a routine, low-value service. Firms should score each designated service rather than applying one rating to the entire practice.

Assess delivery-channel risk

Remote onboarding can increase impersonation and document-fraud risk. Face-to-face contact is not automatically safe, but it offers different verification opportunities.

A digital process may use document verification, biometric or liveness checks, bank-account verification and independent database checks. The firm must understand vendor limitations and remain responsible for the outcome.

Assess geographic risk

Consider customer residence, source and destination of funds, business activities and transaction links. Do not substitute nationality-based assumptions for evidence. Risk controls must also comply with Australian discrimination and privacy law.

Customer due diligence in practice

Customer due diligence, or CDD, is the process of knowing who the customer is, who ultimately owns or controls them, why the relationship exists and whether activity remains consistent with that understanding.

Individuals

For an individual, the business may need to collect and verify:

  • full legal name;
  • date of birth;
  • residential address;
  • identity-document details;
  • beneficial or representative capacity;
  • purpose of the transaction; and
  • risk-relevant source information.

Verification should use reliable and independent documents or electronic data. A photocopy stored in a folder is not necessarily sufficient.

Companies

For a company, obtain the registered name, ACN or ABN, registered office, principal business address, directors and ownership information. Identify the natural persons who ultimately own or control the entity under the applicable rules.

An ASIC extract is useful but may not answer every beneficial-ownership question, especially where shares are held by trusts, nominees or overseas entities.

Trusts

Trust onboarding can require the trust name and type, trustee, settlor information where relevant, beneficiaries or beneficiary classes, appointor or controller, and the individuals who ultimately control the arrangement.

Read the trust deed and later amendments. Do not rely entirely on a customer-completed form where documents contradict it.

Acting through an agent

If a person acts for someone else, verify both the representative’s identity and authority. Obtain the power of attorney, agency authority, board resolution or other evidence and check its scope.

Beneficial ownership is a central challenge

Money-laundering controls fail if a firm verifies only the entity at the front of a structure. The key question is which human beings ultimately own or control it.

Consider this simplified chain:

LayerEntity
PurchaserHarbour Property Pty Ltd
ShareholderCoastal Holdings Unit Trust
TrusteeCoastal Nominees Pty Ltd
Ultimate controllersTwo individuals

The purchaser’s company extract is only the first step. The firm must follow the chain through the trust and trustee to the relevant natural persons, applying the statutory thresholds and control tests.

Where ownership cannot be resolved, the matter should be escalated. Proceeding because settlement is close is not a risk control.

Politically exposed persons and sanctions

A politically exposed person, or PEP, is someone entrusted with a prominent public function, along with relevant family members and close associates as defined by the framework. PEP status does not mean a person is corrupt. It signals that enhanced controls may be required because of position and access.

Firms should also screen relevant customers and beneficial owners against Australian sanctions. Screening must be refreshed because positions, relationships and sanctions lists change.

Potential enhanced due diligence may include:

  • senior approval;
  • deeper source-of-funds and source-of-wealth enquiries;
  • independent adverse-media checks;
  • closer transaction monitoring; and
  • more frequent customer reviews.

Suspicious matter reporting

A suspicious matter can arise where a reporting entity suspects on reasonable grounds that activity relates to crime, tax evasion, identity fraud, money laundering, terrorism financing or another reportable concern under the law.

Red flags in a property or professional-services context may include:

  • repeated changes to ownership shortly before settlement;
  • a customer unwilling to identify controllers;
  • funds arriving from unrelated third parties;
  • an implausible explanation for wealth;
  • instructions to overpay and refund to another account;
  • rapid purchase and resale without commercial rationale;
  • forged or inconsistent identity documents; or
  • pressure to omit information from records.

Staff should report internally to the nominated AML function immediately. The authorised person determines whether and when an AUSTRAC suspicious matter report is required.

Avoid tipping off

Businesses need scripts for handling customer questions. Telling a customer that an AUSTRAC report has been made, or revealing information that compromises an investigation, can create legal risk.

Staff can request further documents or state that compliance checks are incomplete without disclosing internal suspicions. Escalate difficult conversations rather than improvising.

Threshold transaction and other reports

AUSTRAC released updated threshold transaction report and suspicious matter report forms with the new regime. A threshold transaction generally involves physical currency of $10,000 or more, or the foreign-currency equivalent, where the reporting conditions are met.

Businesses should not assume that accepting payments of $9,900 avoids scrutiny. Deliberately splitting a larger cash amount can itself be suspicious.

International funds transfer reporting and other obligations depend on the services and transaction. Map every report type applicable to the business and build calendar controls around statutory timeframes.

Record keeping and privacy

AML/CTF compliance requires records, while Australian Privacy Principles require personal information to be handled appropriately. The goals are compatible when the business collects what law and risk justify, restricts access and disposes of information when permitted.

Records to maintain

Depending on the obligation, retain:

  • customer identification and verification evidence;
  • beneficial-ownership analysis;
  • risk ratings and reasons;
  • enhanced due diligence;
  • transaction and service records;
  • internal escalations;
  • reports submitted to AUSTRAC;
  • training completion;
  • program approvals and reviews; and
  • vendor assurance.

Cybersecurity controls

Identity documents and trust deeds are valuable to criminals. Use role-based access, multi-factor authentication, encryption, secure portals, audit logs, tested backups and incident-response procedures.

Emailing passport scans to a shared inbox and retaining them indefinitely creates avoidable exposure. Vendors should be assessed for hosting location, subcontractors, breach notification and deletion processes.

Staff training must match the role

An annual generic video is insufficient if employees cannot recognise risks in their workflow.

Role-based examples should cover:

TeamTraining focus
Reception and onboardingIdentity mismatch, document handling, escalation
Sales agentsThird-party buyers, unusual urgency, deposit red flags
Conveyancers and lawyersTrust money, beneficial owners, privilege, tipping off
AccountantsEntity structures, source information, designated services
Finance and trust accountingCash, refunds, third-party payments
Directors and partnersRisk appetite, accountability, resourcing and breach response

Test understanding with realistic scenarios. Record attendance, assessment results and remediation.

Governance and independent review

Senior management remains accountable even if a consultant writes the program or a platform performs identity checks.

The board or partners should approve the risk framework, assign an AML compliance role, receive regular reporting and fund necessary controls.

Useful management metrics include:

  • customers by risk level;
  • overdue CDD reviews;
  • unresolved beneficial-owner cases;
  • enhanced due diligence volume;
  • internal suspicious-matter escalations;
  • reports lodged;
  • training completion;
  • vendor exceptions; and
  • control-testing findings.

Independent review should test design and operation. Sampling files often reveals whether staff follow the written process and whether evidence supports risk ratings.

A 30-day remediation plan

Days 1-3: determine scope

List every service, customer type and transaction flow. Map designated services and stop relying on broad industry assumptions.

Days 4-7: enrol and assign ownership

Complete AUSTRAC enrolment where required. Nominate accountable senior personnel and an operational lead.

Days 8-14: assess risk

Document customer, service, channel and geographic risks. Decide escalation and enhanced-due-diligence triggers.

Days 15-21: deploy controls

Finalise onboarding forms, verification pathways, beneficial-owner checks, reporting procedures, secure storage and staff scripts.

Days 22-30: train, test and review

Train every relevant role. Run sample individuals, companies, trusts, remote customers and high-risk scenarios through the process. Then sample completed matters, fix gaps and report results to partners or the board.

Common implementation mistakes

Avoid these early failures:

  • treating enrolment as full compliance;
  • copying a generic program without a business risk assessment;
  • verifying a company but not its beneficial owners;
  • collecting documents without checking them;
  • failing to distinguish source of funds from source of wealth;
  • letting commercial deadlines override escalation;
  • giving all staff access to identity records;
  • overlooking sanctions and PEP updates;
  • failing to train casual or contract staff; and
  • telling a customer that a suspicious matter report was made.

The regime is risk based, but “risk based” does not mean optional. It means the firm must understand its exposure, apply proportionate controls and retain evidence of its reasoning.

Prepare for Australia’s new gatekeeper regime

Tranche 2 changes how Australian property and professional-service transactions are onboarded and monitored. Firms that build the process into ordinary workflows can protect clients and meet deadlines without making every matter feel adversarial.

Find an Australian accountant on WealthWorks to review entity structures, beneficial ownership and the financial records needed for AML/CTF implementation. For legal interpretation and reporting obligations, obtain advice from an appropriately qualified Australian lawyer or AML specialist.

Frequently Asked Questions

When did Australia's Tranche 2 AML/CTF laws start in 2026?

The expanded Australian AML/CTF reporting regime came into force on 1 July 2026. AUSTRAC says newly regulated businesses must enrol by 29 July 2026. Covered sectors include real estate, conveyancing, legal services, accounting and dealers in precious stones and metals.

Which Australian businesses are covered by Tranche 2 AML/CTF laws?

Coverage depends on whether an Australian business provides a designated service, not merely its industry label. Newly regulated sectors include certain real estate, legal, conveyancing, accounting and precious-metals or precious-stones services. Businesses should map each service against AUSTRAC guidance and obtain legal advice where classification is uncertain.

What must an Australian Tranche 2 business do under AML/CTF rules?

Core Australian obligations include enrolling with AUSTRAC, maintaining a risk-based AML/CTF program, conducting customer due diligence, reporting suspicious matters and applicable threshold transactions, keeping required records, training staff and conducting ongoing monitoring.

Do Australian accountants need to enrol with AUSTRAC in 2026?

An Australian accounting practice needs to enrol if it provides one or more designated services covered by the amended AML/CTF Act. Ordinary service labels are not enough to decide. The practice should assess activities such as forming or managing entities, handling transactions and other specified services against AUSTRAC's sector guidance.

Does Australian AML customer due diligence replace normal identity checks?

No. AML/CTF customer due diligence is a statutory, risk-based process that may require identity verification, beneficial-owner identification, purpose and nature checks, politically exposed person screening and ongoing monitoring. It can sit alongside professional, land-title, trust-account and fraud-prevention checks.

What is the AUSTRAC enrolment deadline in Australia for newly regulated businesses?

AUSTRAC states that newly regulated businesses under the regime commencing 1 July 2026 must enrol by 29 July 2026. Providers of remittance or virtual-asset designated services must also apply for registration. Businesses starting a covered service later should check the applicable pre-commencement enrolment requirement.

Related Articles