All insights
Compliance10 min read

AML/CTF Tranche 2: What Australian Professional Firms Must Do Now

From 1 July 2026, AML/CTF obligations apply to designated services commonly provided by legal professionals, accountants, conveyancers, real estate professionals and dealers in precious metals and stones. The obligation is activity-based: being an accountant or lawyer does not make every service a designated service.

At a glance

Key takeaways

  • Map actual services against AUSTRAC’s designated-service definitions.
  • Enrol promptly if the business provides covered services.
  • Build the risk assessment before writing generic policies.
  • Integrate customer due diligence, reporting, records, privacy and governance.

1. Determine whether your services are covered

Start with a service inventory. Review what the firm actually does, for whom, through which entities and at what stage of a transaction. Then compare those activities with AUSTRAC’s professional designated-service guidance.

Do not rely on the firm’s industry label. Some work may be covered while other work is not. Document the basis for the assessment and review it when the service mix changes.

The regime attaches to designated services, not simply to professional titles. Scope must be assessed service by service.

2. Complete enrolment and governance

Businesses providing covered services need to enrol with AUSTRAC and establish accountable governance. Senior management should understand the firm’s exposure, approve the AML/CTF program and receive meaningful compliance reporting.

Responsibility cannot sit only with a template or an external consultant. The program needs an internal owner with authority, access to information and a clear escalation path.

3. Build a business-specific risk assessment

The risk assessment should consider customer types, services, delivery channels and geographic exposure. It should explain how the firm identifies and assesses money-laundering, terrorism-financing and proliferation-financing risks.

A generic document that does not match client onboarding, transactions or systems will not create an effective control environment.

  • Customer and beneficial-owner profiles
  • Nature, size and complexity of transactions
  • Countries and jurisdictions involved
  • Non-face-to-face and technology-enabled delivery
  • Use of trusts, companies and other legal structures
  • Higher-risk services or unusual transaction patterns

4. Translate risk into an AML/CTF program

AUSTRAC states that an AML/CTF program must contain a risk assessment and policies, procedures, systems and controls to manage the identified risks and meet the firm’s obligations.

The program should connect to real workflows: matter opening, customer acceptance, identity checks, beneficial ownership, ongoing monitoring, escalation and reporting.

5. Operationalise customer due diligence

Define what information is collected, how identity is verified, when beneficial ownership is established and what triggers enhanced due diligence. Staff need practical decision paths for incomplete, inconsistent or higher-risk information.

Customer due diligence is not a one-time document collection exercise. Ongoing monitoring and risk changes need to be reflected in the customer profile and the firm’s response.

6. Prepare reporting, records and assurance

The firm needs processes for identifying reportable matters, meeting timeframes, keeping required records and protecting sensitive information. Testing should examine whether controls operate in practice, not just whether a policy exists.

Training should be tailored to the employee’s role. A receptionist, adviser, finance employee and compliance lead will face different decisions and warning signs.

7. Treat privacy as part of implementation

AML/CTF compliance involves collecting and handling sensitive identity and transaction information. AUSTRAC and OAIC guidance should be considered together so that collection, access, retention, security and disclosure controls are aligned.

Firms should review privacy notices, access permissions, storage locations, service-provider arrangements and secure destruction. Collecting more information is not a substitute for controlling it properly.

A focused 30-day action plan

If preparation is incomplete, prioritise the decisions that determine the rest of the program.

  • Week 1: map services, entities and current onboarding
  • Week 2: confirm scope, enrolment and governance ownership
  • Week 3: complete the risk assessment and identify control gaps
  • Week 4: implement priority due-diligence, escalation, reporting and training controls
  • Ongoing: test operation, remediate gaps and update the program
This article is general information, not legal advice. Firms should use current AUSTRAC guidance and obtain advice for their specific services and circumstances.

Sources & further reading

Primary guidance

This publication provides general information only. It does not replace accounting, tax, legal, workplace-relations or other professional advice tailored to your circumstances.

Turn insight into action

Where is your business carrying avoidable risk or pressure?

We can help you assess the process, controls and capability needed before recommending a practical starting point.

Book a free consultation