Skip to main content
Rules Mate

AML/CTF Tranche 2: the complete guide for real estate, accounting, legal, conveyancing, TCSPs and precious metals

Rules Mate Editorial7 min read

Plain-English guide to the 1 July 2026 AML/CTF Tranche 2 reforms. Who's captured, what designated services trigger you, the seven obligations that follow, and how to prepare.

What is Tranche 2 and when did it commence?

Australia's AML/CTF regime was extended via the AML/CTF Amendment Act 2024 (Royal Assent 10 December 2024). Since 1 July 2026, the scheme has captured six new sectors collectively referred to as "Tranche 2". These obligations are in force now. The reformed obligations for existing reporting entities took effect on 31 March 2026 (AUSTRAC).

Enrolment with AUSTRAC opened on 31 March 2026. A business must enrol within 28 days of first providing a designated service, which made 29 July 2026 the deadline for businesses providing designated services from 1 July 2026. If you missed it, enrol now.

AUSTRAC began issuing notices to apparently unenrolled real estate agents, accountants, lawyers and jewellers on 28 August 2026, saying "the time for preparation has passed" (AUSTRAC). Each day a designated service is provided while unenrolled can be a separate contravention.

Who is captured by Tranche 2?

Six sectors are newly captured when they provide a "designated service":

  1. Real estate agents — selling, buyer's agency, property development sales
  2. Accountants and bookkeepers — managing client money, company / trust formation, buying-selling business entities
  3. Lawyers and solicitors — transactional work involving property, company / trust formation, trust account management
  4. Licensed conveyancers — property transfers, settlements, PEXA transactions, managing settlement funds
  5. Trust and company service providers (TCSPs) — formation as a service, nominee director / shareholder, registered agent
  6. Precious metals and stones dealers — gold, silver, platinum or precious stones, with cash transactions of $10,000+

Common carve-outs that are NOT captured (by themselves):

  • Tax preparation only
  • Bookkeeping only (no client money)
  • Residential property management (rent collection, no sales)
  • Litigation-only legal work
  • Precious metals dealers below the $10K cash threshold

If your business is in one of the six sectors but you only do work that doesn't tick a "designated service" box, you are not captured. Our scope checker walks the decision tree.

What is a 'designated service'?

The AML/CTF Act lists discrete services that trigger capture (table 1 of section 6, as expanded by the 2024 amendments). The principle: you're captured when your services *facilitate the movement, structure, or concealment of value*. Selling a property is captured because property is a value-store. Litigation is not captured because there's no value movement.

The seven Tranche 2 obligations

Once captured, you have seven core obligations:

  1. Enrol with AUSTRAC — within 28 days of first providing a designated service.
  2. Maintain a written AML/CTF program — an ML/TF risk assessment plus AML/CTF policies (this replaced the former Part A / Part B structure).
  3. Carry out customer due diligence (CDD) — identity verification + beneficial-ownership identification before providing services.
  4. Lodge SMRs, TTRs and IFTI reports — to AUSTRAC Online.
  5. Designate an AML/CTF compliance officer — at management level, fit and proper, and notified to AUSTRAC.
  6. Train all relevant staff — initial + refresher, documented.
  7. Have your program independently evaluated — at least once every 3 years.

AUSTRAC enrolment — process and deadline

Enrolment opened on 31 March 2026 and is done via AUSTRAC Online. You need:

  • ABN + business activity profile
  • Key personnel (directors, senior managers)
  • Estimated reporting volume by service type
  • Compliance officer details

Enrolment is free. AUSTRAC may request additional information; respond promptly. You'll receive a Reporting Entity Number (REN) and access to AUSTRAC Online.

Deadline: within 28 days of first providing a designated service. For businesses providing designated services from 1 July 2026 that was 29 July 2026, which has passed. A business that starts providing a designated service later has 28 days from that first service.

Your ML/TF risk assessment

Under the reformed Act, your AML/CTF program is an ML/TF risk assessment plus AML/CTF policies. (Before the reform, programs were split into "Part A" and "Part B". That structure is now historical.) The risk assessment is a written analysis of your business's exposure to money laundering and terrorism financing risk, and it must be in place before you provide a designated service. Required content:

  • Customer types you serve (PEPs, foreign nationals, complex structures, cash-heavy)
  • Products/services you offer (which designated services from the Act)
  • Delivery channels (face-to-face, online, intermediated)
  • Jurisdictions you transact with (especially high-risk countries per AUSTRAC guidance)

Your overall risk rating drives the design of your AML/CTF policies. Higher risk means more granular CDD and more enhanced due diligence triggers.

Your governing body or senior manager must approve the program. Review the risk assessment on material change and at the intervals your policies set.

Your AML/CTF policies, including CDD

Your AML/CTF policies set out how you mitigate and manage the risks you identified, and they must be followed in practice. They cover governance and oversight, personnel due diligence and training, and the operational controls:

  • Customer identification — name, address, DOB for individuals; ABN, registered office, beneficial owners (≥25%) for non-individuals
  • Verification — government ID + electronic-database verification, or biometric
  • Beneficial owner identification — natural persons who ultimately own or control ≥25%
  • Enhanced due diligence (EDD) — triggered by PEPs, high-risk countries, complex structures, adverse media
  • Ongoing CDD — monitor for changes in customer profile, behaviour, risk
  • Transaction monitoring — automated or manual review for suspicious patterns
  • Record-keeping — 7 years minimum

Reporting: SMRs, TTRs, IFTIs

Three core report types lodged via AUSTRAC Online:

  • Suspicious Matter Report (SMR) — within 3 business days of forming a suspicion (24 hours for terrorism financing). Tipping-off offence prohibits telling the customer.
  • Threshold Transaction Report (TTR) — within 10 business days for cash transactions ≥$10,000 AUD.
  • International Funds Transfer Instruction (IFTI) report — within 10 business days for international funds movement you instruct or receive.

Reports are XML-formatted; most software automates the generation and lodgement.

Independent evaluation

Under the reformed Act, the former independent review of a Part A program has been replaced by an independent evaluation of your whole AML/CTF program, at least once every 3 years, at a frequency set in your AML/CTF policies. The evaluator can be internal or external, but must be independent (for example, not involved in developing your program); AUSTRAC sets no mandatory qualifications. The evaluation tests whether you appropriately identified, assessed, mitigated and managed your ML/TF risks and complied with your policies (AUSTRAC Step 5).

For newly regulated Tranche 2 entities, the first evaluation is due between 30 June 2029 and 31 December 2030, depending on the last two digits of your AUSTRAC account number. Separately, AUSTRAC can require an external audit by written notice where it suspects non-compliance.

Compliance officer designation

You must designate an AML/CTF compliance officer. Requirements:

  • Employed or engaged at management level, with sufficient authority, independence and resources
  • Fit and proper person
  • Australian resident where services are provided through an Australian permanent establishment
  • Notified to AUSTRAC — newly regulated entities by the later of 29 July 2026 or 14 days after enrolling

For sole-practitioner businesses, the principal practitioner can be the compliance officer. If you use outside help, check AUSTRAC's compliance officer guidance first — outsourcing does not transfer your liability.

Penalties for non-compliance

The penalty regime is deliberately severe. For contraventions on or after 1 July 2026 (penalty unit $364):

  • Civil penalties of up to $36.4M for a body corporate (100,000 penalty units) or $7.28M for an individual (20,000 penalty units) — maximum per contravention
  • Failure to enrol: each day you provide a designated service unenrolled can be a separate contravention. AUSTRAC can issue an infringement notice of $21,840 (company) or $4,368 (individual) per contravention, or seek a civil penalty up to the maximum in court
  • Criminal offences, including tipping off (up to 2 years imprisonment and/or 120 penalty units) and other offences under the Act
  • Loss of registration in many sector-specific regimes (e.g. real estate licence implications)

Recent enforcement scale: Westpac $1.3B (2020), Crown $450M (2023), SkyCity Adelaide $67M (2024). The penalty curve runs from infringement notices to civil penalty proceedings; AUSTRAC chooses based on cooperation, scale, and harm (AUSTRAC — consequences of not complying).

Privacy Act coverage. Tranche 2 small businesses are covered by the Privacy Act for their AML/CTF activities, even under the $3M turnover threshold: section 6E(1A) of the Privacy Act 1988 treats a small business operator that is an AML/CTF reporting entity as an organisation for those activities. The customer identification records you collect for CDD fall under the Australian Privacy Principles.

What AUSTRAC expects in FY26/27

AUSTRAC's May 2026 statement of expectations says it expects "effort, not perfection" from newly regulated businesses during FY26/27 — but it "will take early enforcement action against businesses who fail to enrol" and against businesses suspected of complicity in money laundering (AUSTRAC). Since 28 August 2026 it has been issuing information notices to apparently unenrolled businesses.

What AUSTRAC expects a newly regulated business to have in place now:

  1. Enrolment — enrol immediately if you have not. Run our scope checker to confirm capture.
  2. An AML/CTF program — an ML/TF risk assessment and AML/CTF policies, approved and actually applied in daily operations. AUSTRAC publishes free program starter kits for each Tranche 2 sector.
  3. An AML/CTF compliance officer — designated and notified to AUSTRAC.
  4. Trained staff — initial training, documented.
  5. Readiness to report — an SMR process (3 business days, or 24 hours for terrorism financing) and TTRs where relevant. AUSTRAC asks businesses to "be ready to have a go at reporting".

Then keep your program current and plan for your first independent evaluation (due 30 June 2029 – 31 December 2030).

Frequently asked

When did Tranche 2 commence?

1 July 2026 — the obligations are in force now. Enrolment with AUSTRAC opened 31 March 2026. Businesses must enrol within 28 days of first providing a designated service, which was 29 July 2026 for businesses providing designated services from 1 July 2026.

Is tax-return-only work captured?

No. Tax preparation alone is not a designated service. You're only captured if you also provide a designated service such as managing client money, company/trust formation, or buying/selling business entities.

Do residential property managers need to enrol?

Not on the basis of property management alone. Rent collection and tenant management are not designated services. If the same business also sells property or acts as a buyer's agent, those activities trigger capture.

Can I outsource the Compliance Officer role?

The compliance officer must be employed or engaged at management level and be fit and proper. External consultants can support the function; check AUSTRAC's compliance officer guidance before relying on an outsourced arrangement, because outsourcing does not transfer your liability.

What's the penalty if I'm not enrolled or not compliant?

Each day you provide a designated service unenrolled can be a separate contravention: AUSTRAC can issue an infringement notice of $21,840 (company) or $4,368 (individual) per contravention, or seek a civil penalty. Civil penalties for failing to maintain a program, conduct CDD or lodge required reports are up to $36.4M (body corporate) or $7.28M (individual), maximum per contravention.

Does the Privacy Act apply to a small Tranche 2 business?

Yes, for its AML/CTF activities. Privacy Act s6E(1A) treats a small business operator that is an AML/CTF reporting entity as an organisation for those activities, so the APPs apply to the personal information you handle for AML/CTF purposes, even under $3M turnover. Source: legislation.gov.au/C2004A03712/latest/text.

Related

Related reading