Australia’s Tranche Two AML Regime Moves Into Active Supervision
Australia’s Tranche Two AML Rules Are Now in Force: AUSTRAC Sets Its 2026–27 Enforcement Priorities
Australia’s tranche-two anti-money laundering reforms have moved from implementation into active regulatory supervision. On 19 August 2026, AUSTRAC published its regulatory priorities for FY2026–27, setting out what it expects from the professional and real-estate sectors brought into the regime on 1 July 2026.
The reforms now affect designated services commonly provided by lawyers, accountants, conveyancers, trust and company service providers, real-estate businesses, and dealers in precious metals and stones. The initial 29 July 2026 enrolment deadline has also passed for businesses already providing covered services when the new regime commenced.
The compliance question has therefore changed. Businesses are no longer preparing for tranche two: they need to demonstrate that their AML/CTF framework is operating in practice.
For newly regulated professional firms, this means functioning customer due diligence, risk assessments, governance, reporting processes and record keeping rather than a compliance document prepared solely for the commencement date. For readers’ convenience, we have placed the key AUSTRAC and legislative materials at the end of this article.
Publish Date
29 Aug 2026
Reading Time
15 minutes
Category
Legal News
Jurisdiction
Australia
Australia’s tranche-two AML regime is now operational
Australia significantly expanded the perimeter of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006through the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024.
The change addressed sectors that had historically sat outside large parts of Australia’s AML/CTF framework despite their involvement in property, corporate and other transactions vulnerable to financial crime.
AUSTRAC estimated before commencement that the regulated population would grow from around 19,000 businesses to close to 100,000 nationwide once tranche two became operational.
31 March 2026 was not the tranche-two commencement date
The timetable is important because several different dates are sometimes conflated.
On 31 March 2026, enrolment opened for businesses entering the AML/CTF framework through the reforms. Important amendments also commenced for businesses already regulated under the existing regime.
However, that was not the date when the substantive tranche-two obligations began applying to newly regulated professional sectors.
1 July 2026 brought the new sectors into the regime
Schedule 7 of the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 commenced on 1 July 2026. The current consolidated AML/CTF Act reflects the amendments effective from that date.
From 1 July, covered newly regulated businesses became responsible for obligations including:
- implementing and maintaining an AML/CTF program;
- conducting customer due diligence;
- reporting suspicious matters;
- maintaining required records; and
- meeting governance and other risk-management requirements.
This is now the operative compliance position.
The initial AUSTRAC enrolment deadline has passed
Enrolment is a separate step from building an AML/CTF program.
Businesses that were already providing newly covered designated services when the regime commenced were required to enrol with AUSTRAC by 29 July 2026.
Businesses starting later have an ongoing 28-day requirement
The 29 July date was an initial transition deadline, not a permanent annual cut-off.
A business that begins providing a designated service later must generally apply to enrol with AUSTRAC no later than 28 days after it starts providing that service.
This distinction matters for new professional practices, acquisitions and firms adding regulated services after 1 July.
A business may therefore move into the AML/CTF perimeter because its service model changes even if it was outside the regime when tranche two commenced.
AML/CTF compliance officer notification has separate timing
Newly regulated businesses must also identify and notify AUSTRAC of their AML/CTF compliance officer.
Under the transitional rules, the deadline for a newly regulated entity was the later of:
- 14 days after enrolment; or
- 29 July 2026.
For example, a business that enrolled on 29 July had until 12 August 2026 to notify AUSTRAC of its compliance officer. After the transitional period, the ordinary 14-day rule applies.
Businesses should therefore not treat successful enrolment as completion of their regulatory onboarding.
AUSTRAC has now set its 2026–27 supervision priorities
The most important recent development is the regulator’s 19 August 2026 statement of priorities.
It shows how AUSTRAC intends to approach the first full year of supervision after tranche two entered into force.
AUSTRAC expects controls to be embedded in daily operations
For businesses first regulated from 1 July, AUSTRAC expects to see that they have:
- enrolled and registered where required;
- completed ML/TF risk assessments;
- appointed governance roles;
- established appropriate AML/CTF policies; and
- embedded those policies in daily operations.
That final requirement is particularly important.
An AML/CTF program should govern how the business actually onboards clients, identifies higher-risk relationships, escalates unusual activity, files reports and maintains regulatory records. A generic policy that is disconnected from day-to-day professional work creates a different compliance position from an implemented risk-based program.
AUSTRAC has identified its early intervention targets
The regulator has also been relatively clear about where it intends to concentrate interventions among newly regulated businesses.
For FY2026–27, AUSTRAC says it will focus on reporting entities in new sectors that:
- have not enrolled; or
- are recklessly involved in, or complicit with, criminal activity.
This does not mean other compliance deficiencies will be ignored. It does indicate where the regulator currently sees the strongest need for intervention during the transition into the new regime.
At the same time, AUSTRAC’s approach recognises that operational maturity will develop over time. The practical implication is not that businesses have a broad grace period, but that regulators may distinguish between firms making credible implementation efforts and firms that have failed to engage with the regime.
Not every lawyer, accountant or real-estate business is automatically regulated
One of the most important perimeter points is that professional title alone does not determine whether a business is a reporting entity.
AUSTRAC states expressly that a business becomes a reporting entity because it provides one or more designated services, not simply because it belongs to a particular profession.
This makes service mapping an essential part of tranche-two compliance.
Lawyers and conveyancers
Professional designated services include particular activities connected with real-estate transactions, legal entities and legal arrangements.
For example, the regime can capture a professional who assists in planning or executing:
- a sale, purchase or transfer of real estate;
- a sale, purchase or transfer of a body corporate or legal arrangement;
- creation or restructuring of certain legal entities or arrangements;
- particular financing transactions; or
- specified corporate and trust services.
The scope is not unlimited.
AUSTRAC distinguishes services that directly advance a covered transaction from general advice or ancillary services that merely influence what a client may decide to do.
A law firm should therefore classify its actual service lines rather than assuming that either all legal work or none of its legal work falls within tranche two.
Accountants and trust and company service providers
Similar analysis applies to accountants and corporate service businesses.
Services involving the creation, restructuring, ownership or operation of companies and trusts can enter the professional-services perimeter. The decisive issue remains the designated service being provided and its connection with Australia.
This is particularly important for multidisciplinary firms whose tax, audit, accounting and corporate-services teams may perform materially different activities.
Real-estate businesses
The real-estate regime covers specified activities connected with brokering the sale, purchase or transfer of real estate where the geographical-link requirements are met.
AUSTRAC indicates that this can include seller’s agents, buyer’s agents and some developers selling their own projects without using an independent agent.
The regime is therefore broader than conventional residential agency work.
Professional firms should assess services, not job titles
For compliance purposes, the useful question is:
What does the business actually do for the customer?
A group offering legal, accounting, corporate, property and advisory services may need to analyse each workflow separately. One service can be regulated while another service delivered by the same entity may fall outside the relevant designated-service definition.
AML/CTF programs must now operate in practice
For newly regulated businesses, the AML/CTF program sits at the centre of the compliance framework.
The purpose is not simply to create policies. The program must identify the business’s exposure to money laundering, terrorism financing and proliferation financing risks and establish controls appropriate to those risks.
Risk assessment comes first
A credible program should begin with an assessment of the risks created by the business’s:
- designated services;
- customers and beneficial owners;
- delivery channels;
- geographic exposure;
- transaction types;
- corporate structures; and
- other relevant risk indicators.
The assessment then needs to inform customer due diligence, escalation processes, governance and other controls.
A risk-based regime allows measures to be proportionate. It does not make the underlying risk assessment optional.
Governance needs an accountable owner
Newly regulated businesses also need a functioning governance structure.
The AML/CTF compliance officer should be more than a name supplied to AUSTRAC. The role needs sufficient authority and information to oversee implementation, escalation, reporting, training and remediation.
Senior management and governing bodies also need appropriate visibility over material AML/CTF risks.
Training should reflect the work employees actually perform
Generic AML training is unlikely to be as useful as sector-specific instruction.
Legal professionals may need to recognise unusual company, trust or property structures. Accountants may encounter opaque ownership, nominee arrangements or unexplained funding flows. Real-estate staff may see unusual purchasers, funding sources or transaction behaviour.
The program should translate those risks into situations staff can identify and escalate.
Customer due diligence is now part of professional onboarding
Customer due diligence is one of the most operationally significant changes for firms that historically relied primarily on professional onboarding or conflict-check procedures.
An existing “know your client” process is not automatically equivalent to the statutory AML/CTF framework.
Initial CDD requires more than collecting identification
Covered businesses need processes for identifying and verifying customers and, where required, relevant beneficial owners and persons acting on their behalf.
The depth of the process depends on the customer and applicable risk.
Higher-risk situations can require enhanced measures, while changes in information or conduct may trigger further review after onboarding.
Ongoing CDD continues after the file is opened
AML/CTF compliance does not end when identity documents have been collected.
Businesses must monitor relevant information and respond appropriately to changes in customer risk, unusual activity or inconsistencies with what is known about the customer.
For professional firms, this means the engagement team may become an important source of AML information after formal onboarding.
Delayed CDD rules require careful handling
Recent updates to AUSTRAC’s professional-sector materials reflect changes to delayed CDD timing in relevant property transactions.
For specified circumstances, updated materials refer to a period of 28 days after exchange of contracts or three days before the initially agreed settlement date, depending on how the applicable rule operates.
This is not a general permission to postpone verification.
Firms relying on delayed CDD need to confirm that the legal conditions are satisfied and that the process is reflected accurately in their AML/CTF policies.
Suspicious matter reporting is now a professional-services compliance issue
From 1 July, newly regulated reporting entities also became responsible for identifying and reporting suspicious matters.
This is one of the areas where operational implementation matters most because the relevant information often arises within the professional engagement rather than through a dedicated compliance system.
Suspicion needs an escalation route
Employees should know:
- what indicators may require escalation;
- who receives an internal escalation;
- how the compliance function assesses the matter;
- when an SMR may be required; and
- what records need to be maintained.
AUSTRAC has made improvement in the quality of suspicious matter reports a specific FY2026–27 regulatory priority. It emphasises accurate, timely and useful reporting rather than reporting volume alone.
Lawyers need to consider legal professional privilege separately
For legal practices, AML/CTF reporting also interacts with legal professional privilege.
That issue should not be reduced to a simple proposition that privilege either overrides all AML/CTF obligations or has no relevance.
AUSTRAC maintains separate guidance on privilege claims and states that the Minister for Home Affairs will issue guidelines addressing how claims are handled.
Legal practices should therefore build processes that identify potential privilege issues early and distinguish them from ordinary confidentiality obligations.
AUSTRAC’s starter kits are useful, but they are not safe harbours
To support the large number of businesses entering AML/CTF regulation for the first time, AUSTRAC released sector-specific program starter kits.
They cover areas including legal practice, accounting, conveyancing, real estate and dealers in precious metals and stones.
The kits are designed for eligible, less complex businesses
For example, the legal-profession starter kit is intended to help suitable small practices customise, implement and maintain their own AML/CTF program.
AUSTRAC makes clear that a legal practice providing covered professional designated services must have an AML/CTF program in place before providing those services.
However, the starter kits are not intended to provide a universal compliance solution.
The regulator expressly states that they reflect its interpretation and application of the law for eligible reporting entities and are not a substitute for legal advice. Australian courts remain responsible for interpreting the legislation.
Version control now matters
The starter materials have already changed since their original release.
AUSTRAC’s current update pages reflect version 1.1, with substantive changes relating to:
- beneficial ownership processes;
- annual compliance reporting;
- risk assessments;
- onboarding;
- first independent evaluations; and
- updated national risk information.
The pages themselves were updated again on 20 August 2026, immediately after publication of AUSTRAC’s new regulatory priorities.
Businesses that used an earlier starter kit should therefore check their program against the current materials rather than assuming that a downloaded template remains current indefinitely.
Independent evaluation should already be on the compliance calendar
The reformed framework also requires independent evaluation of the AML/CTF program.
A reporting entity’s policies must specify an appropriate evaluation frequency, with an evaluation occurring at least once every three years under the general framework.
For newly regulated businesses, transitional rules stagger the first evaluation deadlines according to the last two digits of the entity’s AUSTRAC account number.
Depending on those digits, the first deadline falls between 30 June 2029 and 31 December 2030.
That transition reduces immediate pressure on the independent-evaluation market. It should not, however, encourage firms to wait several years before testing whether a newly implemented program works.
Where major gaps appear during initial implementation, an earlier independent assessment may be commercially sensible.
Annual compliance reporting has moved to a financial-year cycle
The next annual compliance reporting period runs from 1 July 2026 to 30 June 2027.
Reporting entities generally need to submit the relevant compliance report during the following three-month submission period, ending 30 September 2027.
This creates an important evidence-management issue now.
Businesses should maintain records of implementation, governance, training, risk assessment updates, customer controls and other relevant compliance activity throughout the financial year. Trying to reconstruct that evidence shortly before the reporting deadline is substantially harder.
Australia tranche-two AML timeline
| Date | Development | Practical significance |
|---|---|---|
| 31 March 2026 | Enrolment opened for newly regulated sectors | Entry point for tranche-two businesses to enrol; reforms for existing reporting entities also commenced |
| 1 July 2026 | Tranche-two substantive obligations commenced | Covered professional and real-estate businesses became subject to the AML/CTF framework |
| 29 July 2026 | Initial enrolment deadline | Applied to relevant businesses already providing covered designated services |
| 12 August 2026 | Example latest compliance-officer notification date | Applied where a newly regulated business enrolled on 29 July |
| 19 August 2026 | AUSTRAC published FY2026–27 regulatory priorities | Supervision moves towards implementation quality and targeted intervention |
| 30 June 2027 | Current annual compliance reporting period ends | Firms should preserve evidence throughout the first full reporting year |
| 30 September 2027 | General compliance-report submission deadline | First post-reform financial-year reporting cycle closes |
What newly regulated firms should do now
For businesses already inside the regime, the priority should be implementation quality.
Firms that have not enrolled
A business providing covered designated services that has not enrolled should treat the issue as an immediate regulatory remediation matter.
AUSTRAC has specifically identified unenrolled businesses in newly regulated sectors as an intervention priority for FY2026–27.
Firms that enrolled but have not operationalised their program
Businesses should test whether they can demonstrate that:
- the regulatory perimeter has been mapped;
- the ML/TF risk assessment reflects actual services;
- the AML/CTF compliance officer is functioning in practice;
- staff have received role-specific training;
- customer and beneficial-owner checks are operational;
- unusual activity can be escalated;
- suspicious matter reporting procedures are usable;
- records are retained appropriately; and
- the program is updated when regulatory guidance or risk information changes.
A signed policy without these operational elements is unlikely to provide the same regulatory assurance as a working compliance system.
Firms using AUSTRAC starter kits
Businesses should confirm that they satisfy the suitability criteria for the relevant kit and check whether they are using the latest version.
The program also needs to be customised to the firm rather than adopted unchanged.
Multidisciplinary professional groups
Law, accounting, corporate-services and advisory groups should map their services at entity and business-line level.
Different teams may enter the AML/CTF perimeter through different designated services, while other activities may remain outside it.
This analysis is particularly important for groups involved in company formation, trust services, transactions, real estate or cross-border structures.
Legasset assists professional-services, financial and corporate groups with AML/CFT perimeter analysis, regulatory gap assessments, compliance-program design and cross-border market-entry planning. Our work may include designated-service mapping, governance reviews, customer due diligence frameworks and remediation planning where implementation deadlines have already passed.
Australia Tranche Two AML FAQ
When did Australia’s tranche-two AML reforms take effect?
The core tranche-two obligations for newly regulated professional and real-estate sectors commenced on 1 July 2026.
That date brought covered designated services provided by businesses such as lawyers, accountants, conveyancers and real-estate professionals within the AML/CTF regime.
Was 31 March 2026 the AML deadline for lawyers and accountants?
No.
31 March 2026 was the date on which enrolment opened for newly regulated businesses. It was also an important commencement date for reforms affecting existing reporting entities.
The substantive tranche-two obligations for newly regulated sectors commenced on 1 July 2026.
Who had to enrol with AUSTRAC by 29 July 2026?
Businesses already providing newly regulated designated services when tranche two commenced generally needed to enrol by 29 July 2026.
A business starting a designated service later must generally apply to enrol within 28 days after it begins providing that service.
Do all Australian lawyers and accountants now have AML/CTF obligations?
No.
Regulation depends on whether the person or business provides a covered designated service, not simply whether it is a law firm, accounting practice or other professional business.
Each service line should therefore be assessed against the statutory definitions and relevant AUSTRAC guidance.
What should a newly regulated business have in place now?
At a minimum, a covered business should be able to demonstrate an appropriate risk assessment, AML/CTF program, governance framework, customer due diligence processes, reporting capability, record keeping and relevant staff training.
AUSTRAC’s 2026–27 priorities specifically expect newly regulated businesses to have established these controls and embedded their policies in daily operations.
Does using an AUSTRAC starter kit guarantee compliance?
No.
AUSTRAC describes the starter kits as practical support for eligible businesses. They reflect the regulator’s interpretation and are not a substitute for legal advice or a universal program appropriate to every reporting entity.
The kit must also be customised and kept current.
Can customer verification be delayed in a property transaction?
Only where the applicable delayed CDD requirements are satisfied.
Current sector materials reflect revised timing in certain situations, including 28 days after exchange of contracts or three days before the initially agreed settlement date. This is not a general exemption from customer due diligence.
Are newly regulated businesses required to report suspicious matters?
Yes, where the statutory reporting conditions are met.
Suspicious matter reporting is now part of the AML/CTF obligations applying to newly regulated reporting entities, and AUSTRAC has made higher-quality SMRs a specific supervisory priority for FY2026–27.
What happens if a business failed to enrol?
Failure to enrol can expose the business to regulatory intervention.
It is particularly significant because AUSTRAC has expressly identified newly regulated entities that have not enrolled as a focus for its FY2026–27 interventions.
A firm in this position should address its enrolment and wider compliance position promptly rather than treating 29 July as a missed opportunity that can simply be ignored.
When is the next annual AML/CTF compliance report due?
The next reporting period runs from 1 July 2026 to 30 June 2027.
The general submission period runs from 1 July to 30 September 2027.
Australia AML Tranche Two: Core AUSTRAC and Legislative Resources
The regulator’s 19 August 2026 priorities explain what newly regulated sectors are expected to have implemented and identify unenrolled entities and businesses linked to criminal activity as early intervention priorities.
II. AUSTRAC — New Reporting Regime Now in Force
This official commencement update confirms the 1 July 2026 start of tranche-two obligations, the core compliance requirements and the initial 29 July 2026 enrolment deadline.
III. AUSTRAC — Key Steps and Support for Your AML/CTF Journey
The post-commencement guidance explains what newly regulated businesses should now have in place and confirms the ongoing requirement to enrol within 28 days after starting to provide a designated service.
IV. AUSTRAC — AML/CTF Transitional Rules 2026
This guidance covers transitional arrangements including AML/CTF compliance officer notification, customer due diligence transitions and staggered deadlines for first independent evaluations.
V. Federal Register of Legislation — Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024
The amending legislation provides the statutory basis for the AML/CTF reforms and confirms the staged commencement structure, including 1 July 2026 for Schedule 7.
VI. Federal Register of Legislation — Anti-Money Laundering and Counter-Terrorism Financing Act 2006
The current consolidated Act reflects the tranche-two amendments in force from 1 July 2026 and provides the primary statutory framework for reporting-entity obligations.
VII. AUSTRAC — Professional Designated Services
This guidance explains which professional activities can bring lawyers, accountants, conveyancers, corporate-service providers and other advisers within the AML/CTF perimeter.
VIII. AUSTRAC — Legal Profession AML/CTF Program Starter Kit
The starter kit provides practical materials for eligible legal practices building and maintaining an AML/CTF program, while making clear that the material must be customised and is not a substitute for legal advice.
IX. AUSTRAC — Annual Compliance Reports
This resource confirms the new financial-year reporting cycle from 1 July 2026 to 30 June 2027 and the general submission period ending 30 September 2027.
How do I get other licenses?
White-Label vs Proprietary Casino: Platform Risk in iGaming Acquisitions
Gaming Licence Value and Change of Control in iGaming Acquisitions
Singapore’s Agentic AI Framework and the Next Phase of Stablecoin Regulation
Hong Kong Stablecoin Regulation Moves From Licensing to Live Market Deployment
Curaçao B2B Supplier Licensing and Registration Before December 2026
How Crypto and Payment Firms Should Prepare for the EU AML Regulation
Which Financial and Crypto Groups Could Face Direct AMLA Supervision?
European Commission Reviews MiCA Rules for Stablecoins and Crypto Services
FCA Crypto Authorisation: Preparing for the September 2026 Gateway













