AUSTRAC Tranche 2: What Australian accountants need to know
The expanded AML/CTF regime has been in force since 1 July 2026. For accounting practices, it applies when they provide covered professional designated services with an Australian geographic link. This guide explains the conditional scope, current timing rules and practical next steps.
1. What is Tranche 2?
Australia's Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) regime has historically applied to financial institutions, gambling operators, and bullion dealers ("Tranche 1"). Tranche 2 extends these obligations to "gated professions" -- also known as Designated Non-Financial Businesses and Professions (DNFBPs).
The AML/CTF Amendment Act 2024 was passed by Parliament in late 2024 and introduces requirements for accountants, tax agents, real estate agents, lawyers, and trust and company service providers to identify, assess, and mitigate money laundering and terrorism financing risks.
An accounting practice comes within the regime when it provides a covered professional designated service with an Australian geographic link. Where the Act applies, the resulting obligations can include an AML/CTF program, customer due diligence and reporting. Ordinary accounting work is not automatically covered merely because an accountant performs it.
2. Who does it affect?
Tranche 2 applies where a person or entity provides a covered professional designated service with an Australian geographic link. For accountants and tax agents, examples can include:
- Managing client money or securities
- Creating, operating, or managing companies, trusts, or other legal structures
- Buying or selling business entities
- Acting as or arranging for another person to act as a nominee director or secretary
- Providing a registered office or business address for a company
- Real property transactions above threshold amounts
3. Current timing rules
Expanded regime in force
- Coverage depends on providing a professional designated service
- The service must have the required Australian geographic link
- Reporting entities must follow the obligations that apply to their services
Initial CDD timing is circumstance-specific
- Apply initial CDD before providing a covered service unless a rule permits different timing
- Use enhanced measures where the customer risk and the Act require them
Conditional transition rules apply
- Transition rules for existing customers are conditional
- Risk and specified trigger events can affect when initial CDD is required
- Check AUSTRAC's current guidance before setting a practice-wide timetable
4. CDD requirements by entity type
Customer due diligence depends on the covered service, customer type, risk and circumstances. The examples below are planning prompts, not a complete statement of what you must collect or verify.
Individuals
- Full legal name and any aliases
- Date of birth
- Residential address (not PO Box)
- Government-issued photo ID (passport, driver licence)
- Source of wealth (for high-risk clients)
- PEP and sanctions screening
Companies
- Full company name, ACN/ABN, registered address
- ASIC company extract
- Identification of all directors
- Identification of beneficial owners (25%+ ownership)
- Identification of any person with effective control
- Company structure chart (for complex structures)
- PEP and sanctions screening on all identified persons
Trusts
- Full name of trust and ABN/TFN
- Trust deed (or certified extract)
- Identification of all trustees (individual or corporate)
- Identification of settlor
- Identification of beneficiaries (or class of beneficiaries)
- Identification of appointor/guardian (if applicable)
- PEP and sanctions screening on all identified persons
SMSFs
- Fund name, ABN, and registration details
- Trust deed
- Identification of all individual trustees or corporate trustee directors
- Identification of all members
- PEP and sanctions screening on all identified persons
- Verification that fund is regulated by ATO
5. Your AML/CTF program
A reporting entity must develop and maintain an AML/CTF program that is appropriate to its risks, nature, size and complexity. Use AUSTRAC's current guidance and your own advice to determine the required content. At a practical level, organise the work around these two connected areas:
Risk assessment and governance
- ML/TF risk assessment tailored to the covered services you provide
- Roles, oversight and accountability
- Staff suitability and training controls
- Independent evaluation where required
- Record-keeping and reporting controls that fit your obligations
Customer due diligence controls
- Initial CDD procedures for the services and customer types you cover
- Beneficial-owner and control checks where required
- Enhanced measures for higher-risk circumstances
- Escalation when required information cannot be obtained
- Ongoing CDD and transaction-monitoring procedures where applicable
6. Penalties for non-compliance
Tranche 2 extends AML/CTF obligations to accountants and other DNFBPs. What your practice must do depends on which designated services you provide. This page is general information, not legal advice.
Civil penalties under the AML/CTF Act are set in penalty units, are indexed, and scale with the size of the entity and the seriousness of the contravention. These are maximums for the largest reporting entities, not a forecast for your practice. This is general information, not legal advice - get your own advice.
7. How to review your practice now
Assess your exposure
Review which of your services qualify as "designated services" under the Act. Map your client base by entity type and risk level.
Develop your AML/CTF program
Document a program suited to the covered services you provide and the ML/TF risks you face. Use AUSTRAC's current guidance and obtain specialist advice where needed.
Appoint a compliance officer
Designate a person within your practice who is responsible for AML/CTF compliance. This person must have sufficient authority and resources.
Train your team
All staff who provide designated services must receive AML/CTF training. Training must be ongoing, not just a one-time event.
Choose your tooling
The Act does not require software - a small practice can meet its obligations on paper. But whatever you use must let you evidence every check and retrieve it for seven years.
Apply your current onboarding rules
For each new customer, identify whether you will provide a covered designated service and apply the initial CDD timing rule that fits the circumstances. Review existing customers under AUSTRAC's conditional transition guidance rather than assuming one universal date.
Let Fedix streamline your compliance workflow -- you remain the reporting entity
Fedix drafts your CDD paperwork, runs DFAT sanctions screening, surfaces political-exposure indicators for your review, and keeps the records. You make every compliance decision and lodge every report -- the obligation stays yours.