← Back to blog

Are you a Tranche 2 entity? A plain-English checklist

Australia's AML/CTF regime is expanding to cover professions that have never had to think about AUSTRAC before. Here's how to work out, in five minutes, whether that includes you.

Key takeaways

From 1 July 2026, AML/CTF obligations extend to lawyers, accountants, conveyancers, real estate agents, trust and company service providers, and dealers in precious metals and stones — including jewellers.

The obligation attaches to the specific "designated service" you provide — not your job title — and there's a required order of work: risk assessment first, then a program built around it.

A named Compliance Officer and staff training are separate, mandatory requirements — not optional extras layered on top of the written program.

If your business is a law firm, an accounting practice, a real estate agency, a conveyancing practice, a trust and company service provider, or a jeweller or precious metals dealer, you've probably heard the phrase "Tranche 2" somewhere in the last year. Here's what it actually means for you, without the legislative jargon.

What's changing

Australia's Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) Act has, until now, mainly applied to banks, casinos, and remittance and digital currency exchange providers — often called "Tranche 1" entities. From 1 July 2026, that regime extends to a second group of professions, referred to as Tranche 2.

Regulatory note

The obligation doesn't attach to your job title — it attaches to the specific service you provide. Two firms in the same profession can land on opposite sides of the line depending on what they actually do for clients.

Who's typically captured

Based on the services listed in the AML/CTF Act, the sectors affected include:

  • Lawyers and conveyancers handling client money, property settlements, or company/trust formation
  • Accountants providing services like managing client funds or structuring entities
  • Real estate agents and property managers involved in the buying and selling of real property
  • Trust and company service providers (formation agents, nominee directors, registered office providers)
  • Dealers in precious metals, stones and products — including jewellers and bullion dealers — once a cash or virtual-asset transaction reaches $10,000 or more

That last category catches businesses that don't tend to think of themselves as "financial" at all. A jeweller who has never dealt with AUSTRAC in their life is a reporting entity the moment they take a $12,000 cash payment for a piece of jewellery — the obligation is triggered by the transaction, not by the type of business.

What "designated service" means in practice

A quick way to think about it: if part of your work involves handling client funds, forming or managing companies and trusts on someone's behalf, facilitating property transactions, or accepting large cash or virtual-asset payments for high-value goods, there's a reasonable chance you're providing a designated service under the Act. If your work is purely advisory — for example, tax advice with no funds handling or entity formation — you may sit outside scope, but it's worth confirming rather than assuming.

What it means if you're captured — in the right order

This is where a lot of the informal advice circulating online gets it backwards. AUSTRAC doesn't let you write a program first and figure out your risks later — each step below depends on the one before it, and skipping ahead usually means redoing the work.

1. Enrol with AUSTRAC

Newly regulated businesses must enrol as a reporting entity within 28 days of starting to provide a designated service. For anyone captured from day one of the reform, that means enrolling by 29 July 2026 at the latest.

2. Complete a documented risk assessment

Before you can write a compliance program, the Act requires you to first assess your business's exposure to money laundering and terrorism financing — across your customer types, the services you offer, how you deliver them, and the jurisdictions you deal with. This has to be a genuine, documented assessment specific to your business, not a generic template, and it needs to be kept up to date and reviewed periodically (independently audited at least every three years for most entities).

Regulatory note

Your AML/CTF program is only as good as the risk assessment underneath it. AUSTRAC's guidance is explicit that the program must respond to your specific, documented risks — not a generic industry template.

3. Build your written AML/CTF program

With the risk assessment done, you develop a written program with two parts: Part A covers your business-wide policies — how you assess customer risk, apply customer due diligence, monitor transactions, and escalate concerns — and Part B covers employee due diligence, including screening staff who are exposed to ML/TF risk. Part A needs to be approved by your board or equivalent senior decision-maker before it takes effect.

4. Appoint — and notify AUSTRAC of — a Compliance Officer

Every reporting entity must name a specific AML/CTF Compliance Officer: a fit-and-proper person, senior enough in the business, who owns the program's implementation and AUSTRAC reporting obligations day to day. For a sole practitioner this may well be you — but it still has to be formally documented and notified to AUSTRAC (by 29 July 2026, or within 14 days of enrolling, whichever is later).

5. Train your staff — properly, not once

This is the step most commonly skipped, and it's a standalone legal requirement, not a nice-to-have that comes bundled with the written program. Everyone involved in providing your designated services — including directors and contractors, not just front-line staff — needs regular AML/CTF risk awareness training: what your obligations are, what suspicious activity looks like in your specific business, and how to escalate it internally. The depth and frequency of training should match each person's role and the risks identified in your assessment, and it needs to be repeated on an ongoing basis, not delivered once and filed away.

6. Carry out customer due diligence and ongoing monitoring

Identify and verify who you're dealing with before providing a designated service, and keep monitoring the relationship afterwards — higher-risk customers require closer scrutiny than lower-risk ones.

7. Report and keep records

Report suspicious matters and relevant threshold transactions to AUSTRAC as they arise, and retain your records — customer identification, transaction records, and your program documentation — generally for seven years.

These obligations apply even to sole practitioners and small partnerships — size doesn't exempt a business from the Act if it's providing a designated service. What changes with size is usually the complexity of the program, not whether you need one.

What to do next

Given how new this is for most Tranche 2 sectors, the practical first step is simply confirming whether — and where — your specific services fall under the Act, rather than jumping straight to writing a program before you know what it needs to cover. AUSTRAC's own guidance is the authoritative source for enrolment timing and requirements; a short conversation with someone who works across both the compliance and operational side can usually save weeks of uncertainty, and stop you building a program in the wrong order.

Not sure where you stand?

A 20-minute call is usually enough to tell you exactly what you need.

Book a free call