Tranche 2 AML/CTF: An Early Temperature Check for Professional Service Providers
Tranche 2 AML/CTF: An Early Temperature Check for Professional Service Providers
David Cantrick-Brooks | 02/08/2026

Why the first month is about embedding governance and workflows, not simply completing documents

On 1 July 2026, Australia’s Tranche 2 anti-money laundering and counter-terrorism financing reforms moved from preparation to live operation for newly regulated professional services, real estate and high-value goods sectors.

One month later, it is reasonable to ask how implementation is working. It is not yet reasonable to declare the reforms either a success or a failure.

The public evidence remains thin. AUSTRAC has published extensive guidance and enrolment information, professional bodies have continued to support their members, and practitioners are plainly still working through scope and implementation questions. However, I have not identified a robust, publicly available survey or dataset showing the first-month experience of professional service providers across the regulated population.

That evidentiary limitation matters. An early temperature check should identify emerging pressure points and practical priorities, without turning anecdotes or a very small poll into sector-wide conclusions.

A regime based on services, not job titles

The threshold question is still: what does the business actually do?

The reforms do not regulate every service provided by a lawyer, accountant, conveyancer, governance adviser or company secretarial practice. Table 6 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 applies to specified activities. AUSTRAC’s guidance emphasises that, for several services, merely being connected with a transaction is insufficient: the provider must take active steps that directly advance the relevant transaction, creation or restructure.

That distinction is important because many engagements contain a mixture of regulated and unregulated work. General advice may sit outside the regime, while implementing the advice may cross the line. A practice may also provide one designated service in a relatively small part of its business and thereby become a reporting entity.

The practical task is therefore not simply to classify the firm by profession. It is to map services at engagement or matter level, identify the relevant customer, determine when the designated service begins and record the reasoning applied to borderline cases.

What did 29 July mean?

For businesses that began providing newly regulated designated services on 1 July 2026, 29 July was generally the deadline to apply to enrol with AUSTRAC – 28 days after commencement.

It was not, however, a universal deadline for every related step. AUSTRAC’s transitional guidance states that newly regulated entities must notify it of their AML/CTF compliance officer by the later of 29 July 2026 or 14 days after enrolling. A business that enrolled on 29 July therefore has until 12 August to make that notification.

This distinction is worth making because enrolment, appointment of the compliance officer, notification and operational readiness are related but separate requirements.

AUSTRAC reported 38,660 enrolments across the newly regulated industry categories as at 30 July: 13,010 in accounting and professional services, 6,360 lawyers, 1,580 conveyancers, 17,460 real estate businesses and 250 jewellers and dealers in precious metals and goods.

Those figures demonstrate substantial activity. They do not, by themselves, tell us how many businesses should have enrolled, whether each enrolled business is fully operationally ready, or how effective its controls are.

What the LinkedIn poll did – and did not – show

I ran a short LinkedIn poll from 25 July to 1 August asking:

“For providers of professional designated services, how has the Tranche 2 AML/CTF workload compared with expectations (so far)?”

There were more than 200 impressions, but only two votes. One respondent selected “more than expected” and one selected “too early or hard to say”. No respondent selected “less than expected” or “about as expected”.

With a sample of two, the percentages – 50 per cent and 50 per cent – should not be treated as findings. The poll was self-selecting, unverified and not representative. A chart would risk giving visual weight to data that cannot bear it.

The more useful result is methodological: one month is too early, and a better follow-up exercise will require a larger audience, clearer sector segmentation and qualitative questions about where time and effort are actually being spent.

Where the implementation work is concentrated

Although reliable experience data is limited, the legal framework and AUSTRAC’s post-commencement guidance point to several areas that deserve immediate attention.

1. Scope mapping remains the first control

The most consequential error may occur before customer due diligence begins: failing to recognise that a designated service is being provided, or treating an entire profession as automatically in or out.

AUSTRAC updated its professional designated-services guidance on 10 July. It now states expressly that an agency or service-provider relationship, by itself, does not bring a person within Table 6 item 7, and that a person who only performs administrative or procedural steps does not fall within item 7 for that reason alone. At the same time, acting as or arranging another person to act as a director, secretary, trustee or similar officeholder may be regulated where the statutory conditions are met. Providing a registered office or principal place of business address in the course of business is separately designated.

For governance and company secretarial providers, the sensible conclusion is neither “all company secretarial work is caught” nor “administrative work is exempt”. Formal appointments, appointment arrangements, registered-office services, corporate formations and direct implementation of restructures require careful analysis. Pure advice, meeting support and filing activity may produce a different answer depending on the facts.

The position of a person serving only as an external member of the compliance committee of a registered managed investment scheme is not squarely addressed in the public AUSTRAC guidance I located. That role should not be categorically treated as either captured or exempt by title alone. The actual services, authority, customer relationship and any associated trust or company service activities need to be examined.

2. A program is an operating framework, not a document set

Under the reformed regime, the AML/CTF program comprises the business’s money laundering, terrorism financing and proliferation financing risk assessment and the policies, procedures, systems and controls used to manage those risks. The program must be tailored, documented, approved and followed.

This is where implementation becomes a governance and operating-model exercise. The governing body has oversight responsibilities. A senior manager approves the program. The compliance officer needs suitable authority, resources and access. Personnel performing relevant functions require role-appropriate initial and ongoing training.

A downloaded template or starter kit can be a useful foundation. It does not prove that the business has correctly identified its services and risks, integrated controls into its workflow, trained its people or created evidence that the program is being followed.

3. The real test is the live engagement

The best early diagnostic is to run actual or simulated engagements through the end-to-end process.

Can personnel identify the designated service and customer? Is due diligence completed at the right time? Can beneficial owners be identified and verified? Are risk ratings supported by recorded reasons? Do high-risk matters escalate to the right person? Can the business deal consistently with incomplete information, client resistance, delayed due diligence and pre-commencement customers?

The process should be integrated into client and matter opening, not operated as a parallel compliance exercise that can be bypassed under time pressure.

4. Recordkeeping and privacy must be designed together

The reforms require evidence of due diligence, risk assessment, decisions and compliance. They do not require businesses to retain full copies of identity documents merely for AML/CTF recordkeeping.

The Office of the Australian Information Commissioner has stressed data minimisation and says Tranche 2 entities should not retain full copies of passports or driver licences for AML/CTF purposes unless another law requires this. That makes system design important: businesses need sufficient records to demonstrate what was checked and how, without unnecessarily accumulating sensitive identity documents.

5. Guidance monitoring is now a control

The body of guidance did not freeze on 1 July. AUSTRAC updated material on pre-commencement customers, suspicious matter reporting and legal professional privilege on commencement day; updated insolvency guidance on 8 July; and updated the professional designated-services page on 10 July. Program starter-kit materials had also been revised shortly before commencement.

A business should assign responsibility for monitoring changes, assessing their implications and documenting any program updates. Where AUSTRAC materials do not resolve a question, AUSTRAC expects the business to form and document a reasonable position, supported by advice where appropriate.

What should governing bodies and senior managers ask now?

The next phase should move from commencement readiness to operational effectiveness. Five questions provide a useful starting point:

1) Are we identifying designated services consistently at the correct point in each engagement?

2) Has our written program been tested against real files, exceptions and higher-risk scenarios?

3) Do decision records show why customers, matters and controls were assessed as they were?

4) Is management information revealing delays, overrides, high-risk customers, escalations, training gaps and possible suspicious matters?

5) Are we preserving the evidence needed for internal review and independent evaluation?

The risk assessment and AML/CTF policies must be reviewed at least every three years and earlier when relevant triggers arise. Independent evaluation is also required at least every three years, with transitional timing for the first evaluation. Waiting until the final deadline would miss the opportunity to identify design or implementation weaknesses early.

Alertness, not alarm

AUSTRAC has said it expects “effort, not perfection” during 2026–27 and recognises that practices and processes will continue to be embedded after commencement. It has also made clear that this is not a compliance holiday: early enforcement will focus on businesses that wilfully fail to enrol and those suspected of complicity or wilful blindness to money laundering.

The balanced message is therefore straightforward. Tranche 2 implementation is not finished because a program has been approved or an enrolment submitted. The next test is whether scope decisions, due diligence, escalation, reporting, privacy, recordkeeping and oversight work reliably in live practice.

The first month does not provide enough evidence for a verdict. It does provide a useful agenda for the next six months – and a stronger basis for a follow-up survey once providers have processed enough real matters to distinguish temporary implementation effort from enduring regulatory burden.

Governance in Action Pty Ltd can assist clients with AML/CTF-related policies and processes. David Cantrick-Brooks FGIA FCG, Principal & Director of Governance in Action Pty Ltd, would be pleased to assist with enquiries. Please feel free to reach out via LinkedIn or via gia.net.au.

AI-assisted tools and techniques were used here to support the research, drafting and editing of this publication. Responsibility for the final content rests with David Cantrick-Brooks.

Whilst accounting and legal terms and references may be contained in this publication, it does not constitute or purport to be or represent accounting or legal advice of any kind – whatsoever. Readers should seek their own professional advice.

Sources of Information

1. AUSTRAC – About the AML/CTF reforms – Commencement and newly regulated sectors.

2. AUSTRAC – Professional designated services (updated 10 July 2026) – Activity-based scope, direct advancement, item 7, administrative/procedural steps and registered-office services.

3. AUSTRAC – Enrol with us overview – Enrolment requirements and industry enrolment counts as at 30 July 2026.

4. AUSTRAC – AML/CTF compliance officer – Appointment and transitional notification timing.

5. AUSTRAC – Your AML/CTF program overview – Program structure, approval and tailoring.

6. AUSTRAC – Latest guidance updates – Post-commencement updates and starter-kit revisions.

7. OAIC – Updated privacy guidance for AML/CTF reporting entities – Data minimisation and non-retention of full identity-document copies for AML/CTF purposes.

8. AUSTRAC – Update to regulator statement of expectations (21 May 2026) – “Effort, not perfection”, unresolved questions and enforcement focus.

9. Governance Institute of Australia – Clarification letter to AUSTRAC (11 May 2026) – Company-secretarial service models and unresolved scope questions before commencement.

10. User-supplied drafting prompt and poll results – Poll wording, dates, impressions and two-response result.

11. AUSTRAC – Review and update your AML/CTF program – Minimum three-year review cycle and trigger-based reviews.

12. AUSTRAC – Conduct an independent evaluation – Minimum three-year independent evaluation cycle and transitional timing.

PreviousNext

Related Articles

APRA’s proposed recast CPS 510: What changes, what matters and how boards should prepare

APRA’s proposed recast CPS 510 Governance is more than a technical consolidation. It would combine five prudential standards into one cross-industry framework and impose clearer, more evidence-based expectations for board accountability, delegation, management information, skills, performance, renewal, conflicts and fitness and propriety. The most consequential proposals include a mandatory measurable board skills matrix, an independent external board review every three years for significant financial institutions, and a 12-year maximum tenure for non-executive directors. The draft also creates sharper requirements for group-board independence and board information, while reducing routine fit-and-proper reporting through alignment with the Financial Accountability Regime. This article explains the key changes, contrasts them with the draft 5th edition of the ASX Corporate Governance Principles and Recommendations, and sets out a practical implementation agenda for boards, company secretaries and governance advisers. Although commencement is expected in early 2028, long-lead matters such as director succession, committee composition, constitutions, charters and systems should be identified well before the final standard takes effect.

08/01/2026

Forty Years of Director and Officer Penalties in Australia: What the Evidence Really Shows

Australia’s corporate-enforcement system has changed substantially over the four financial decades to 30 June 2026. Civil-enforcement activity and statutory penalty ceilings have increased, and recent cases demonstrate that directors and senior officers can face substantial personal penalties, lengthy disqualification and costs exposure. Yet the available public data does not prove that the underlying rate of serious misconduct has risen—or that higher financial penalties alone deter it. Headline ASIC totals are dominated by penalties imposed on companies, while director-specific research shows that disqualification and imprisonment have historically been central to individual accountability. This article separates what the evidence establishes from what remains uncertain, examines the impact of the 2019 penalty reforms, and identifies the practical lessons for boards, governance professionals and regulators.

07/29/2026

ASX governance principles, take two: a better balance – but important questions remain

ASX’s revised draft fifth edition of the Corporate Governance Principles and Recommendations is a significant improvement on the abandoned 2024 proposal. It preserves the eight-Principle, “if not, why not” framework while reducing prescription and legal duplication. Important questions nevertheless remain about disclosure gaps, proportionality for smaller issuers, assurance expectations, diversity reporting, Appendix 4G and the treatment of artificial intelligence. This article examines the proposed changes and their practical implications for listed-company directors and company secretaries.

07/24/2026