Nearly 80,000 Australian businesses are entering AML/CTF compliance for the first time. If you're an accountant, lawyer, real estate agent or conveyancer — this is everything you need to know, without the jargon.
Imagine you're a mid-sized accounting firm in Brisbane. You've been helping clients with their tax returns, business structures, and financial advice for fifteen years. You've built your reputation on knowing the rules and following them. You've never had a compliance problem in your life.
Then, in July 2026, a new law kicks in. Suddenly your firm is legally required to have a documented anti-money laundering program, verify the identity of your clients, monitor their transactions for suspicious behaviour, report certain activities to a government regulator, and keep records of everything for at least seven years. The penalty for getting it wrong? Up to 100,000 penalty units per contravention — $36.4 million at the current unit value.
Sound alarming? It's meant to. But here's the thing: with the right information and the right tools, it's also completely manageable. This guide exists to cut through the noise and tell you exactly what Tranche 2 means for your business — in plain English, without the compliance-speak — and what you need to do about it.
📌 Before you read on
This guide is for you if you work in:
Accounting · Bookkeeping · Tax advice · Legal services · Conveyancing · Real estate · Jewellery dealing · Trust and company services · Crypto and virtual assets
If any of those describe your work, keep reading. If they don't, Tranche 2 still might affect you — we'll explain the "designated service" test that determines whether you're caught.
AUSTRAC stands for the Australian Transaction Reports and Analysis Centre. They're the government body responsible for detecting financial crime — specifically money laundering and the financing of terrorism. Think of them as the financial intelligence agency.
Here's how money laundering actually works, in simple terms: criminals make money illegally (drug trafficking, fraud, corruption) and then they need to make that money look like it came from a legitimate source. To do that, they often route it through legitimate businesses. A criminal might buy and sell a property, run money through a legal firm's trust account, or use a complex company structure set up by an accountant. The business involved often has no idea it's happening.
AUSTRAC's job is to build a picture of suspicious financial activity by requiring certain businesses to report it. Since 2006, banks, financial institutions, and casinos have been legally required to know their customers, monitor transactions, and report anything suspicious. That's what the law calls a "reporting entity."
Tranche 2 expands that reporting entity net to include the professions that criminals also commonly exploit — and that have, until now, been a blind spot in Australia's financial crime defences.
💡 Why now?
Australia was falling behind internationally
The Financial Action Task Force (FATF) is the global standard-setter for anti-money laundering laws. In 2015, FATF evaluated Australia and found it had one of the weakest AML regimes among developed nations — specifically because professional services like legal and accounting were unregulated. Australia was one of only a handful of FATF member countries not to have addressed this. These reforms are long overdue, and international compliance is now mandatory.
The AML/CTF Act — Australia's primary anti-money laundering law — was originally passed in 2006. It covered what the government called "Tranche 1" entities: banks, remittance dealers, money changers, casinos, and other financial service providers. These businesses were required to enrol with AUSTRAC, build AML compliance programs, verify customers, and report suspicious activity.
"Tranche 2" is the second phase: extending those same obligations to a new set of industries that criminals have historically used as alternative channels when banks tighten their controls. The reforms passed into law in late 2024, with most obligations commencing on 1 July 2026.
In short: if your business was previously operating without any AML obligations, there's a real chance that's about to change.
20
Years since Australia's AML laws were last expanded
$790M
Real estate, of the $1.2B in criminal assets the AFP has restrained since 2020 (AUSTRAC)
~80k
New businesses AUSTRAC will regulate from 2026 — total rising from ~19,000 to close to 100,000
The law uses the phrase "designated service" to define what triggers your obligations. If your business provides a designated service, you are a "reporting entity" and all of the Tranche 2 rules apply to you. The designated services are surprisingly broad — and the test is based on what service you provide, not how big your firm is or how much you charge.
Here's what that looks like, profession by profession:
📊 Accountants, Bookkeepers & Tax Agents
You are caught if you: manage client money or assets, prepare or execute transactions on behalf of a client, assist with the creation or operation of a company, trust, or partnership, or provide advice on business structures for clients. General tax return work and financial statement preparation that doesn't involve managing or moving client money may sit outside the net — but the moment you touch trust accounts, manage transactions, or help structure an entity, you're in.
Very likely caught
⚖️ Lawyers & Solicitors
You are caught if you: handle client funds through a trust account, buy or sell property on behalf of a client, assist with company or trust formation, manage a client's assets or money, or represent clients in transactions involving large sums. Note: legal professional privilege is preserved — you are not required to disclose privileged communications. Court representation is also excluded. But conveyancing, settlements, and business transactions almost certainly catch you.
Very likely caught
🏠 Real Estate Agents & Buyers Agents
You are caught if you assist in buying, selling, or leasing real estate on behalf of a client. This includes residential and commercial property, and buyers' agents acting on behalf of purchasers. Property management where you also handle rent collections and disbursements is also likely included. The rationale is that real estate is one of the most common vehicles for money laundering in Australia.
Caught
📝 Conveyancers & Settlement Agents
Almost certainly caught in full. You sit at the exact point in a property transaction where money changes hands — exactly where laundering occurs. Your obligations will be substantial, particularly around verifying all parties to a transaction and monitoring the source of funds.
Caught
💎 Jewellers & Precious Metal Dealers
Caught if you deal in physical cash or crypto transactions of $10,000 or more. This includes buying or selling jewellery, gold, silver, diamonds, or other precious metals. Note the threshold: if you only sell by credit card and small transactions you may have limited exposure, but cash or crypto dealings at scale catch you immediately.
Caught if $10k+ cash/crypto
🏛️ Trust & Company Service Providers
Caught if you form companies, trusts, or partnerships on behalf of clients; act as a registered agent or nominee director; provide a registered office address; or manage a legal entity on behalf of a client. This is a broad category that catches ASIC agents, registered office providers, and many business advisory firms.
Caught
₿ Virtual Asset Service Providers (VASPs)
If you operate a crypto exchange, provide crypto custody, facilitate crypto-to-crypto transfers, or issue tokens — you are caught, and you are caught earlier. VASP obligations under Tranche 2 commence on 31 March 2026, three months before everyone else. If you're in crypto, your deadline has already passed or is imminent.
⚠️ Earlier deadline: 31 March 2026
🤔 "I'm not sure if I'm caught..."
The honest answer is: if you're asking the question, you probably are. The test is not about your job title — it's about what services you actually provide. A tax agent who sticks to returns is less exposed than a tax agent who helps structure business transactions. When in doubt, the safest approach is to assume you're caught and build accordingly.
Seek advice to confirm
⚠️ Important note on size
Small practices are NOT exempt
There is no small business exemption in the AML/CTF Act. If you provide a designated service — whether you're a sole trader or a 200-person firm — the obligations apply in full. The size of your practice affects the complexity of your AML program, but not whether you need one.
Before we go through your obligations, here's a plain-English glossary of the terms you'll encounter constantly. Bookmark this section.
AML/CTF
Anti-Money Laundering and Counter-Terrorism Financing. The name of the legal framework you're now operating under.
AUSTRAC
The government regulator who oversees AML/CTF compliance. Think of them as the ATO, but for financial crime. They can audit you, fine you, and prosecute you.
Reporting Entity
What you become when Tranche 2 applies to you. A reporting entity has legal obligations to enrol, have a program, verify customers, report, and keep records.
Designated Service
The specific activity that triggers your AML obligations. If you provide a designated service, you're a reporting entity. If you don't, you're not.
AML/CTF Program
A documented set of policies and procedures your business must have, explaining how you identify and manage the risk of being used for money laundering. Think of it as your compliance manual.
CDD (Customer Due Diligence)
Knowing and verifying who your clients actually are. At minimum: name, date of birth, address, and identity document. For higher-risk clients, more is required.
SMR (Suspicious Matter Report)
A report you file with AUSTRAC when you suspect a client is involved in financial crime. You don't need to be certain — just reasonably suspicious. You must file within 24 hours of forming that suspicion.
TTR (Threshold Transaction Report)
A mandatory report for cash transactions of $10,000 or more. Must be filed within 10 business days of the transaction.
ML / TF / PF
Money Laundering / Terrorism Financing / Proliferation Financing. The three categories of financial crime your program must address.
Risk Assessment
A documented analysis of how likely your business is to be exploited for financial crime, based on your clients, services, geographies, and delivery channels. Forms the foundation of your AML program.
Compliance Officer
A person you designate to be responsible for your AML program. Doesn't have to be a compliance specialist — could be a senior partner or manager. But you must formally appoint someone and notify AUSTRAC.
IFTI (International Funds Transfer Instruction)
A report required when money moves internationally on behalf of a client. Must be filed within 10 business days.
Once Tranche 2 applies to your business, you have six core obligations. Here they are, one by one, in plain language.
1
Enrol with AUSTRAC
Deadline: within 28 days of providing a designated service · Enrolment opens 31 March 2026
This is the starting line. Before anything else, your business needs to formally register with AUSTRAC as a reporting entity. You do this through AUSTRAC Online — their web portal.
The enrolment process requires you to provide your business details, the designated services you offer, the name of your compliance officer, and contact information. It's not complicated, but it is mandatory, and the clock starts ticking from the moment you provide a designated service — not from when the law commences.
What this means practically: If you're already providing services that will be designated on July 1, 2026, you need to enrol within 28 days of that date — so your enrolment deadline is effectively around 29 July 2026. But AUSTRAC strongly recommends doing it as soon as enrolment opens (31 March 2026) to avoid the rush.
⚠️ Failing to enrol is itself a breach of the AML/CTF Act and can attract civil penalties.
2
Write and maintain an AML/CTF Program
The big one — this is your compliance manual, tailored to your business
This is the most substantial requirement and the one that most businesses find most daunting. Your AML/CTF program is a documented set of policies, procedures, and controls that explains how your business identifies and manages the risk of being used for money laundering or terrorism financing.
Think of it less like a government form and more like a business operations manual — but specifically for financial crime risk. It needs to cover how you assess the risk level of your clients, how you verify their identity, how you monitor their transactions, how you train your staff, and how you report suspicious activity.
The program has two parts:
What this means practically: Your program must be tailored to your business. A conveyancing firm's program will look different from an accounting firm's. AUSTRAC doesn't accept generic templates as compliance. You also need to have the program independently evaluated at least once every three years.
💰 The cost of doing this yourself
Hiring a compliance consultant to write an AML/CTF program from scratch typically costs between $15,000 and $40,000 and takes 2–4 months. Those figures are our estimate of the market, not a surveyed rate. This is where most businesses experience sticker shock — and it's one of the problems Detekta was built to solve. More on that below.
3
Know and verify your customers (Customer Due Diligence)
CDD — the ongoing process of understanding who your clients are
You probably already know your long-standing clients well. But under Tranche 2, "knowing your client" has a specific legal meaning — and a process attached to it.
Customer Due Diligence (CDD) means you must verify the identity of each client before (or as soon as practicable after) you provide them with a designated service. For individuals, this means confirming their name, date of birth, and address using a reliable, independent source — typically a government-issued document. For companies and trusts, it extends to understanding the ownership structure and identifying the people who actually control the entity.
There are three levels of CDD:
CDD is not a one-off: You must also monitor existing client relationships on an ongoing basis. If a client's circumstances change, or you notice unusual activity, you may need to re-verify or escalate to enhanced CDD.
⚠️ Tipping off: it is an offence under the AML/CTF Act to tell a client you've filed a Suspicious Matter Report about them, or that they're under investigation. If you become suspicious, report — don't warn.
4
Report certain transactions and suspicious activity to AUSTRAC
The reports you must file — and the strict deadlines that apply
This is the part that feels most uncomfortable to many professionals: filing reports about your clients with a government regulator. It's worth remembering why it exists — AUSTRAC uses this information to build intelligence about financial crime. You are not accusing your client of a crime; you are providing the regulator with information that, combined with thousands of other data points, may help identify criminal networks.
There are three main report types you need to know:
Annual Compliance Reports: You must also submit an annual compliance report to AUSTRAC each calendar year, confirming that your program is in place, your training is current, and you have met your obligations. This is separate from the transaction reports above.
⚠️ Failing to file an SMR within 24 hours is a serious breach. AUSTRAC has a strong track record of enforcement — fines in this area have run into the millions for financial institutions that failed to report adequately.
5
Keep records for at least seven years
Everything you do for compliance must be documented and kept
Seven years. That's how long you must retain records related to your AML/CTF obligations. This includes: all customer identification records, transaction records, copies of reports filed with AUSTRAC, risk assessment documentation, staff training records, audit results, and any changes to your AML/CTF program.
These records must be held in a way that allows them to be retrieved promptly if AUSTRAC requests them. If you're audited or investigated, these records are your primary evidence of compliance.
What this means practically: If you're still keeping compliance records in a shared drive, a spreadsheet, or paper files, you'll need to significantly upgrade your record management. The records must be complete, accurate, and accessible. AUSTRAC can request them at any time.
6
Train your staff
Everyone in your firm who might encounter a designated service must be trained
Your AML/CTF obligations only work if the people in your firm actually know about them. AUSTRAC requires you to have a training program in place — and to ensure that all relevant staff complete it and understand it.
Training must be role-specific (a receptionist who never handles client money needs different training from a partner who manages transactions), and must be repeated regularly — not just once at onboarding. New employees must also be trained before they start handling designated services.
You need to keep records of who completed what training and when. AUSTRAC will ask for these records in an audit, and "we trained people informally" will not be an acceptable answer.
Note for legal professionals: The new laws include provisions that ensure legal professional privilege remains unchanged. You will not be required to disclose privileged communications or documents to AUSTRAC — the privilege applies and AUSTRAC has confirmed this in their guidance.
Take the 2-minute AI-powered check — we'll ask three quick questions and tell you exactly where you stand and what to do next.
Let's be direct. AUSTRAC is not a toothless regulator. They have a strong track record of pursuing enforcement action — and the penalties are substantial.
⚠️ The penalties are real
Civil penalties for AML/CTF breaches
For companies: Up to 100,000 penalty units per contravention. With the Commonwealth penalty unit at $364 — the value in force from 1 July 2026 — that is $36.4 million. The unit value is indexed, so the dollar figure changes.
For individuals: Up to 20,000 penalty units per contravention — $7.28 million at the same unit value.
For criminal offences (such as tipping off a client about an SMR): up to 2 years imprisonment, or 120 penalty units, or both.
These aren't theoretical. AUSTRAC successfully pursued Westpac for $1.3 billion in 2020 and CBA for $700 million in 2018 — both for systemic AML failures. While small businesses are unlikely to face those figures, the principle applies at every scale.
Beyond the financial penalties, non-compliance can result in: loss of your professional licence, reputational damage, personal liability for firm principals, being named in public enforcement actions, and — in serious cases — criminal prosecution.
❌"My clients are all reputable. I don't deal with criminals — this doesn't really apply to me."
✅Reality: Money laundering doesn't announce itself. Criminals specifically target businesses with legitimate-looking clients, because that provides cover. The financial adviser who unwittingly structured a fraudster's assets, the conveyancer who settled a property bought with proceeds of crime, the accountant who incorporated a shelf company used as a shell — none of them knew. Your compliance obligations exist precisely because criminal activity is designed to look legitimate.
❌"I'll wait until closer to July 2026 and see what other firms in my sector do."
✅Reality: Building an AML/CTF program takes time — 4–12 weeks if you're using a platform, months if you're doing it from scratch with a consultant. Enrolment with AUSTRAC opened in March 2026, and a newly regulated business must notify AUSTRAC of its compliance officer appointment within 14 days of enrolling. If you start in June, you will be scrambling, under-prepared, and technically non-compliant from day one. AUSTRAC has made clear that enforcement will not wait for businesses that chose to delay.
❌"My industry association will send me a template — I'll just fill that in."
✅Reality: Industry association templates may be a useful starting point, but AUSTRAC requires your AML/CTF program to be tailored to your specific business. A generic template that hasn't been customised to your client types, service lines, and risk profile will not satisfy AUSTRAC in an audit. This is explicitly stated in AUSTRAC's guidance. Your program must reflect YOUR risk assessment — not a hypothetical firm of your type.
❌"The requirements are too complex for a small practice like mine."
✅Reality: AUSTRAC has confirmed that the complexity of your AML program should be proportionate to the complexity and size of your business. A small sole-trader conveyancer does not need the same program as a national law firm. But they do still need a program. "It was too complex" is not a legal defence. The good news is that for most small-to-medium practices, a well-structured platform or guided process makes this genuinely achievable without specialised compliance expertise.
❌"This is just about reporting cash transactions over $10,000 — I never deal in cash, so I'm fine."
✅Reality: Threshold Transaction Reports (for $10,000+ cash) are one of six obligations — and arguably the smallest one. The bigger obligations are your AML/CTF program, customer due diligence on every client, Suspicious Matter Reports (which apply regardless of transaction size), 7-year record keeping, staff training, and annual reporting. The $10,000 cash rule is the tip of the iceberg.
The good news is that AUSTRAC has been clear about what they expect and when. Here's a realistic timeline for getting compliant:
Now
Start understanding your obligations
Confirm whether your business provides a designated service. Read AUSTRAC's guidance for your sector (available on AUSTRAC's website). Brief your senior leadership. Make the decision on whether to use a platform, hire a consultant, or build internally.
Do this now
At enrolment
Appoint your Compliance Officer · within 14 days of enrolling
Designate a person who will be responsible for your AML/CTF program. This doesn't require a compliance qualification — but the person must understand the obligations and have the authority to act on them. You must formally notify AUSTRAC of this appointment within 14 days of enrolling. (AUSTRAC’s own example: enrol on 29 July 2026, notify by 12 August 2026.) The 30 May 2026 date you may have seen applies to businesses that were already reporting entities before 31 March 2026 — not to you.
Deadline approaching
Mar–Jun 2026
Build and approve your AML/CTF Program
Complete your risk assessment and write your program (Parts A and B). Get it approved by your board or senior management. This is the most time-intensive step — start early. AUSTRAC enrolment opens 31 March 2026: enrol as soon as it opens to give yourself maximum time.
Allow 4–8 weeks minimum
Jun 2026
Train your team
Deliver AML/CTF training to all relevant staff before July 1. Training must be role-specific and documented. Set up your record-keeping systems so they're ready to capture all compliance activity from day one.
Complete before July 1
1 Jul 2026
Go live — all obligations commence
Your AML/CTF program must be active. Customer due diligence must start for all new clients. Transaction monitoring must be running. Your reporting processes must be operational. From this date, AUSTRAC expects full compliance.
Hard deadline — no extensions
Ongoing
Ongoing compliance — this is a permanent operational requirement
File SMRs within 24 hours of forming a suspicion. File TTRs within 10 days of qualifying cash transactions. Review and update your risk assessment when your business changes. Annual compliance report to AUSTRAC each year. Independent program evaluation every three years.
Permanent obligation
This is the question most business owners want answered. The honest truth is: it depends on how you approach it, and the options range from free (and risky) to very expensive (and unnecessary for most businesses).
AUSTRAC provides guidance materials and templates. In theory, a knowledgeable person in your organisation could write your program, build your processes, and set up your reporting systems from scratch. In practice, this takes 80–200 hours of staff time, requires someone with a solid understanding of the legal requirements, and risks producing a program that looks plausible but doesn't pass an AUSTRAC audit. For most professional services firms, the cost in partner time alone far exceeds what a platform or consultant would charge.
A good compliance consultant will assess your business, write a tailored AML/CTF program, set up your processes, and train your team. The output is high quality and genuinely tailored. The cost is typically $15,000–$40,000 for initial setup, plus ongoing fees for annual reviews, regulatory updates, and program maintenance. This makes sense for larger firms or those with genuinely complex risk profiles. For a small accounting practice or sole-trader conveyancer, it's often disproportionate.
This is the most practical route for most small-to-medium businesses entering compliance for the first time. A good compliance platform guides you through your risk assessment, generates your AML/CTF program tailored to your business type, handles your customer verification, manages your reporting obligations, and keeps your records — all in one place, for a fixed monthly fee.
📊 A rough cost comparison
What does it actually cost?
DIY: $0 in direct costs, 100–200 hours of staff time, high risk of non-compliance
Compliance consultant (market estimate): $15,000–$40,000 setup, $5,000–$15,000/year ongoing
Compliance platform (e.g. Detekta): $299–$799/month — program generated in minutes, all ongoing obligations managed automatically
Detekta was built for exactly this problem. We saw nearly 80,000 businesses about to face obligations they'd never dealt with before, being quoted tens of thousands by consultants, and feeling overwhelmed by regulation that — while genuinely important — shouldn't require a specialist to navigate.
Detekta · AI Compliance Platform
Get fully Tranche 2 compliant in 48 hours.
Answer a guided questionnaire about your business. Detekta generates your complete AML/CTF program — Parts A and B — in minutes. Then it runs your customer due diligence, manages your compliance obligations, and handles your reporting. Automatically.
Full AML/CTF program generated in 8 minutes — AUSTRAC-compliant, tailored to your business type
Customer identity verification (KYC) built in — no separate tool needed
Compliance Hub shows every obligation you carry, what's done and what's due
Staff training modules — role-specific, completion tracked, evidence ready for AUSTRAC
Living documents — when AUSTRAC updates a rule, your program updates automatically
7-year record keeping — all compliance records stored, instantly retrievable for audits
Annual compliance report preparation — guided, pre-filled from your data
Consultant setup typically runs $15,000–$40,000; Detekta is $299–$799 per month
Book a 20-min call →Use this as your practical action plan. Everything on this list needs to be in place before 1 July 2026.
Confirm whether your business provides a "designated service" under the AML/CTF ActUrgent
Decide on your compliance approach: platform, consultant, or internal buildUrgent
Appoint a Compliance Officer (can be an existing senior staff member)Within 14 days of enrolling
Notify AUSTRAC of your Compliance Officer appointment via AUSTRAC OnlineWithin 14 days of enrolling
Enrol your business with AUSTRAC (enrolment opens 31 March 2026)By Jul 29
Complete your ML/TF/PF risk assessment for your businessBefore Jul 1
Write and formally approve your AML/CTF program (Parts A and B)Before Jul 1
Set up your customer due diligence (CDD) process for all new clientsBefore Jul 1
Train all relevant staff on their AML/CTF obligations (role-specific)Before Jul 1
Set up your record-keeping system (7-year retention required)Before Jul 1
Establish your reporting process — how will you file SMRs, TTRs, and IFTIs?Before Jul 1
Ensure new employee onboarding includes AML training before they handle designated servicesOngoing from Jul 1
File Suspicious Matter Reports (SMRs) within 24 hours of forming a suspicionOngoing
File Threshold Transaction Reports (TTRs) within 10 days of $10,000+ cash transactionsOngoing
Review and update your risk assessment when your business changes significantlyOngoing
Submit your annual compliance report to AUSTRAC each calendar yearAnnual
Have your AML/CTF program independently evaluated at least every three yearsEvery 3 years
Conduct annual refresher training for all relevant staffAnnual
Tranche 2 is the most significant expansion of Australia's financial crime laws in twenty years. For the nearly 80,000 businesses it captures, the obligations are real, the deadlines are firm, and the penalties for non-compliance are substantial.
But here's the thing: compliance isn't complicated if you approach it systematically. The businesses that will struggle in 2026 are the ones who delay, assume it doesn't apply to them, or wait for someone else to solve it. The businesses that will be fine are the ones who start now, use the tools available to them, and treat this as what it actually is — a permanent operational requirement, not a one-off project.
You're not being asked to be a financial crime detective. You're being asked to know who your clients are, have a documented process for managing risk, and report when something looks wrong. That's it. Done well, it takes a few hours a month and protects your business, your clients, and your professional reputation.
✅ Final thought
The businesses that get this right will have a competitive advantage
In a world where sophisticated clients — particularly in property, corporate advisory, and financial services — are increasingly asking their professional advisers about AML compliance, having a robust, demonstrable compliance program is a trust signal. The firms that treat this as an opportunity to professionalise their client onboarding and risk management will be better positioned for the decade ahead than those who treat it as a checkbox.
This article is for general information only and does not constitute legal advice. AML/CTF obligations are complex and depend on your specific business circumstances. If you are unsure whether Tranche 2 applies to your business, seek advice from a qualified compliance professional or legal adviser. AUSTRAC guidance continues to evolve — check the AUSTRAC website for the most current information.
If you're an accountant, lawyer, real estate agent, or conveyancer in Australia — July 1, 2026 is a date you need to have circled.
That's when AUSTRAC Tranche 2 kicks in.
And if you haven't heard of it yet, here's the plain-English version of what it means for your business:
---
🔵 WHAT IS TRANCHE 2?
Australia's anti-money laundering laws (the AML/CTF Act) have applied to banks and financial institutions since 2006. Tranche 2 extends those same obligations to professional services — accounting, legal, real estate, conveyancing, jewellery, and crypto — for the first time.
Nearly 80,000 Australian businesses become regulated by AUSTRAC from July 2026, taking the total regulated population from around 19,000 to close to 100,000. Most of them have never had a compliance obligation in their professional lives.
---
🔵 WHAT DOES IT ACTUALLY REQUIRE?
Six things. Here's the summary:
1️⃣ Enrol with AUSTRAC (enrolment opens 31 March 2026)
2️⃣ Write an AML/CTF program — a documented set of policies tailored to your business
3️⃣ Verify your clients' identity before providing regulated services
4️⃣ Report suspicious transactions to AUSTRAC (within 24 hours)
5️⃣ Keep records of everything for 7 years
6️⃣ Train your staff — documented, role-specific, ongoing
---
🔵 WHO IS CAUGHT?
In short: if you assist clients with buying or selling property, manage their money or assets, help structure their businesses, handle trust accounts, or deal in large cash transactions — you're almost certainly caught.
Size doesn't matter. A sole-trader bookkeeper has the same obligations as a national law firm. The complexity of your program scales — but not whether you need one.
---
🔵 THE DEADLINES
⚠️ 31 March 2026 — Enrolment opens (don't wait)
⚠️ Compliance Officer must be notified to AUSTRAC within 14 days of enrolling
⚠️ 1 July 2026 — All obligations commence. Enforcement begins.
If you're in crypto/VASPs — your deadline was 31 March 2026. You may already be behind.
---
🔵 WHAT HAPPENS IF YOU IGNORE IT?
Civil penalties up to 100,000 penalty units per contravention for companies ($36.4 million at the current unit value), and 20,000 units for individuals ($7.28 million).
And that's before reputational damage, licence implications, or criminal prosecution for specific offences.
AUSTRAC is not a theoretical regulator. They pursued Westpac for $1.3B and CBA for $700M. They will pursue professional services firms that don't comply.
---
🔵 THE GOOD NEWS
This is manageable. Especially if you start now.
The businesses that are going to struggle in July 2026 are the ones who waited, assumed it didn't apply to them, or hoped their industry association would sort it out.
The ones who are fine will be the ones who got informed early, made a plan, and used tools that were built for exactly this problem.
---
If you're not sure where to start, I've put together a detailed guide covering every obligation, all the deadlines, and exactly what compliance looks like in practice — in plain English, no jargon.
Link in comments 👇
#AUSTRAC #Tranche2 #AML #Compliance #AccountingAustralia #LegalAustralia #RealEstateAustralia #FinancialCrime #SmallBusiness #AMLCompliance
A 20-minute call. We'll map exactly what applies to your firm and how we take it off your desk.
This guide is general information to help you understand the reform — it isn't legal advice, and your exact obligations depend on your specific services. We'll confirm them with you directly.