Tranche 2 AML/CTF
Tranche 2 AML/CTF obligations from 1 July 2026
This guide explains Australia's Tranche 2 AML/CTF scope, 2026 timing, programs, customer due diligence, reporting and record-keeping duties.
Last reviewed
Scope, obligations and implementation priorities
Tranche 2 is the common name for the expansion of Australia's anti-money laundering and counter-terrorism financing regime to specified services in real estate, professional services, trust and company services, and dealings in precious metals, stones and related products. AUSTRAC administers the regime.
The expanded obligations commenced on 1 July 2026. As at 6 August 2026, affected businesses should have identified their designated services, addressed enrolment and put operating controls in place. This guide provides general business information based on the framework at that date. The AML/CTF Act, Rules and current AUSTRAC guidance govern each business's position.
Coverage follows the designated service
Tranche 2 coverage is service-based. A business becomes a reporting entity when it provides a service listed as a designated service and the service has the required Australian connection. Professional title, licensing status and industry membership can indicate where to examine the rules, but they do not settle coverage.
The designated-service definitions include conditions, thresholds, exclusions and geographic tests. A service-by-service assessment should record what the business does, who receives the service, how it is delivered and why the Australian connection is met. Cross-border work and work performed through related entities need particular attention.
Examples of activities that may be covered include:
- Covered real estate activities can include services involving a qualifying sale, purchase or transfer of real property.
- Specified professional services can include legal, conveyancing or accounting assistance with transactions involving real estate, businesses, client money, accounts, legal persons or legal arrangements.
- Covered trust and company services can include company formation, directorships, registered offices, trustees or nominee arrangements.
- Dealings in precious metals, precious stones or specified products can be covered when the statutory conditions and thresholds are met.
The exact statutory description controls. A firm may provide both covered and uncovered services, and its processes should distinguish between them. Existing obligations for sectors such as financial services, gambling, remittance, digital currency exchange and established bullion dealing also continue under their relevant provisions.
Timing and enrolment after commencement
AUSTRAC opened enrolment for newly regulated entities on 31 March 2026. Businesses already providing a newly regulated designated service on 1 July 2026 were generally required to enrol by 29 July 2026. A business that starts providing a designated service later generally applies for enrolment within 28 days after it starts, subject to the applicable legislation, Rules and transition settings.
A business that may have missed an applicable date should check its position promptly, contact AUSTRAC where appropriate and document the corrective steps taken. Enrolment is one part of the framework. The other obligations apply according to their own triggers and commencement provisions.
Start with a defensible implementation order
- Map services and legal entities. Identify each service, the entity that supplies it, the customer or matter type, any threshold or exclusion, and the basis for the Australian connection.
- Assign governance. Appoint an eligible AML/CTF compliance officer, establish senior management oversight and define decision, escalation and reporting responsibilities.
- Assess business-wide ML/TF risk. Consider customers, designated services, delivery channels, transaction characteristics and countries or regions connected with the work.
- Document the AML/CTF program. Convert the risk assessment into policies, controls and procedures that meet the Act and Rules and are approved through the required governance process.
- Build operational workflows. Configure CDD, beneficial ownership enquiries, risk assessment, screening, ongoing monitoring, escalation, reporting and record retention.
- Prepare people and test controls. Train relevant staff, test representative matters and exceptions, correct deficiencies and retain evidence of the work completed.
Risk assessment, program and governance
The business-wide risk assessment should explain the method used, the information considered and the reasons for each risk conclusion. It should reflect the firm's actual services and operating model. Higher exposure can arise from opaque ownership, unusual use of intermediaries, remote delivery, complex transactions, unexplained third-party funding or connections with higher-risk jurisdictions.
The AML/CTF program should state how those risks are identified, assessed, managed and kept under review. It should allocate responsibilities, set approval and escalation paths, address employee due diligence where required, and explain how the business controls CDD, monitoring, reporting, records, training and assurance. Senior management should receive enough information to oversee implementation, approve material changes and ensure that the program has suitable resources.
The AML/CTF compliance officer should have the competence, authority and access needed to perform the role. Appointment alone is insufficient evidence of governance. The program should describe the officer's responsibilities, access to decision-makers, escalation rights, reporting arrangements and coverage during absence.
CDD and beneficial ownership
Initial CDD begins with identifying the customer and verifying identity using reliable and independent information. It can also require confirmation of a representative's authority, identification and verification of beneficial owners, an understanding of the nature and purpose of the service or relationship, and a documented customer risk assessment.
Beneficial ownership analysis should consider both ownership and control. Companies, partnerships, trusts and other arrangements require methods suited to their legal form. A percentage threshold can form part of the test, while control exercised through voting, appointments, agreements or other means can also be relevant. Complex structures should be traced through to the individuals who ultimately own or control them, with gaps and inconsistencies resolved before the business proceeds where the rules require that result.
The timing and extent of CDD depend on the service, customer and risk. Any delayed verification, reliance or exemption should have a clear legal basis and documented conditions. Enhanced due diligence may require more information, closer verification, source of funds or source of wealth enquiries, senior approval and more intensive monitoring.
PEPs, sanctions and ongoing monitoring
CDD should include procedures for identifying politically exposed persons, relevant family members and close associates. The required treatment depends on the PEP category, assessed risk and current rules. PEP status carries no finding of wrongdoing; it indicates circumstances that may require additional controls.
Australian sanctions are a separate legal regime. Risk-based screening against the DFAT Consolidated List can support compliance, provided possible matches are resolved and escalated under a documented process. Foreign sanctions lists may also matter where the business has a legal, contractual or operational exposure to those regimes. Sanctions screening complements customer and beneficial ownership enquiries.
Ongoing customer due diligence should keep information current and test whether activity remains consistent with the customer's profile, purpose and risk. Monitoring should cover the designated services and relevant transactions, with triggers for changes in ownership, unusual payment methods, unexplained third parties, rapid movement of value, inconsistent instructions and other material departures from expected activity. Alerts need documented review, disposition and escalation.
SMR, TTR and IFTI reporting
A suspicious matter report may be required when the statutory suspicion test is met in connection with a customer, service or transaction. SMR deadlines are short and depend on the nature of the suspicion, with terrorism financing suspicions subject to the shortest period. Procedures should support immediate internal escalation, authorised decision-making, secure submission and compliance with tipping-off restrictions.
A threshold transaction report generally concerns a transfer of physical currency of A$10,000 or more, or the foreign currency equivalent, where the statutory reporting conditions are met. It is usually due within 10 business days. The threshold applies to each transfer under the Act. A series of lower-value transfers can indicate structuring and should be considered for SMR purposes, even where no individual transfer triggers a TTR.
An international funds transfer instruction report applies when a reporting entity sends or receives a reportable instruction to transfer money or property into or out of Australia. A client's overseas connection or an international payment somewhere in a transaction does not by itself establish that the professional firm has an IFTI duty. The firm's role and the statutory sender or recipient test need to be checked.
Each report type has its own trigger. A transaction can require more than one report, and submitting one report does not discharge another applicable duty. Businesses should also confirm whether annual compliance reporting or other AUSTRAC reporting applies to them.
Records, training and independent review
Record-keeping should cover customer and beneficial ownership information, verification evidence, risk assessments, designated services and transactions, program versions, approvals, monitoring and escalation decisions, reports, training, reviews and remediation. Many records are generally retained for seven years, with the relevant starting point and retention rule determined by record type. Records should remain secure, retrievable and protected according to their confidentiality and privacy requirements.
Training should be matched to each role. Staff who identify scope, conduct CDD, review alerts, make reporting decisions or manage records need instruction and practical exercises relevant to those duties. Training should occur before a person performs the function and whenever changes, incidents or testing show that further instruction is needed. The program should explain how competence is assessed and evidenced.
Independent review or evaluation should test the design, implementation and effectiveness of the program. Its scope and timing should follow the applicable requirements and the business's risk profile. The reviewer should have suitable skill and independence from the work being assessed. Findings should be reported through governance channels, assigned to accountable owners and tracked to completion.
Maintaining the program
Implementation continues after enrolment. The business should revisit service mapping and risk assessment when services, customers, delivery methods, ownership, systems or geographic exposure change. Management information should show whether CDD is completed on time, alerts are resolved, reports meet deadlines, records are accessible and remediation remains on track.
This article is general information as at 6 August 2026 and is not legal advice. Businesses should check the current AML/CTF Act, Rules and AUSTRAC guidance and obtain advice on their specific services and circumstances.
Core implementation areas
-
Check service coverage
Coverage depends on providing a designated service with the required Australian connection.
-
Assess ML/TF risk
The assessment should address customers, services, delivery methods, transactions and geographic exposure.
-
Establish governance
Senior management should oversee the program and give the compliance officer suitable authority and resources.
-
Apply customer due diligence
CDD should identify and verify customers and beneficial owners in accordance with the applicable requirements.
-
Monitor and report
Ongoing controls should detect material changes and support each reporting duty that is triggered.
-
Keep evidence current
Records, training and independent review should demonstrate how the program operates in practice.
Tranche 2 questions
Does every lawyer, accountant or real estate agent fall within Tranche 2?
Coverage depends on whether the business provides a designated service with the required Australian connection. A professional title, licence or industry category alone does not determine whether the AML/CTF obligations apply.
When did the Tranche 2 obligations commence?
The expanded obligations commenced on 1 July 2026. Businesses already providing newly regulated designated services at commencement were generally required to enrol by 29 July 2026. A business starting later generally applies within 28 days after it begins providing a designated service, subject to the legislation, rules and any applicable transition arrangements.
What does customer due diligence cover?
CDD can include identifying and verifying the customer, confirming anyone acting for the customer, identifying and verifying beneficial owners, understanding the purpose of the service or relationship, screening for relevant risk factors and assigning a documented risk rating. The required steps and timing depend on the designated service, customer type, risk and current rules.
Does PEP status prevent a business relationship?
PEP status identifies a category that can require additional risk assessment, approval and due diligence. It carries no finding of wrongdoing. The response depends on the type of PEP, the assessed risk and the requirements in force.
Which AUSTRAC reports can apply?
A suspicious matter report can be required when the statutory suspicion test is met. Threshold transaction reports and international funds transfer instruction reports apply only when their separate transaction and service triggers are satisfied. One report does not replace another when several duties apply.
How long must AML/CTF records be retained?
Many customer identification, transaction and program records are generally retained for seven years, although the starting point and period depend on the record type. Businesses should map each category to the current legislation and rules and protect confidential reporting information.