Tranche 2, explained without the jargon.
The questions we're asked most often by people who've never had an AML/CTF obligation before. If yours isn't here, it's a genuinely good reason to just ask us directly.
What is Tranche 2, in one sentence?
It's the extension of Australia's existing AML/CTF laws — previously aimed mainly at banks, casinos, and remittance providers — to also cover lawyers, conveyancers, accountants, real estate agents, and trust and company service providers when they provide certain specific services, effective 1 July 2026.
How do I know if I'm actually captured?
It depends on the specific service, not your job title. A conveyancer handling a property settlement is generally captured; the same conveyancer giving general advice with no transaction involved may not be, for that particular piece of work. This is the single most common source of confusion, and the safest approach is a short conversation about what you actually do day to day, rather than guessing from a checklist.
What happens if I don't enrol with AUSTRAC?
Enrolment is a legal obligation, not optional paperwork, for entities providing a designated service. Penalties for non-compliance with the AML/CTF Act can be severe — both civil penalties for the business and, in some circumstances, personal liability for people in management. Beyond the legal exposure, an unenrolled reporting entity is also operating outside the law for every transaction it handles in the meantime.
Do I need a lawyer, an accountant, or a consultant for this?
None of those exclusively — AML/CTF compliance is its own specialism, distinct from legal advice or tax and accounting work, even though it commonly sits inside law and accounting firms. A consultant who works in AML/CTF specifically will typically be faster and more cost-effective than asking your existing lawyer or accountant to build this from scratch, unless they already have that specific expertise in-house.
What actually goes into an AML/CTF program?
One integrated, outcomes-focused AML/CTF program — built around your actual risk, not a generic template. (Note: the AML/CTF reforms that commenced in 2026 removed the old two-part "Part A / Part B" structure that used to define this; it's now a single program rather than two prescribed documents.) In practice, it still covers the same ground: your risk assessment methodology, governance and compliance officer arrangements, initial and ongoing customer due diligence procedures, transaction monitoring, staff training, and your process for reporting to AUSTRAC.
What's an "independent review" and why can't I just do it myself?
Your AML/CTF program is required to be periodically evaluated by someone independent of the people who designed and run it — the same logic as a financial audit needing an external auditor. The point is an outside, objective check on whether the program actually works in practice, not just whether it reads well on paper.
How much does this typically cost?
It depends heavily on your size and complexity — a sole practitioner's program is a very different scope to a firm with multiple offices and staff. We quote a fixed fee after an initial call, once we understand your actual services and client base, rather than pricing off a generic package.
How long does it take to become compliant?
A straightforward program for a small business is typically achievable within a few weeks from the first call. More complex businesses with multiple service lines or higher-risk client bases take longer, mainly because the risk assessment itself needs more depth.
Didn't find your answer here?
Send us your specific situation and we'll tell you plainly where you stand.