Blog

Tranche 2

How AUSTRAC's Effort Not Perfection Approach Applies After the Tranche 2 Deadline

AUSTRAC expects effort, not perfection, while controls embed. That is not a pause on baseline obligations, and it is not a defence. What to evidence instead.

AUSTRAC has said it expects effort, not perfection, while newly regulated businesses embed their controls. That is a genuine implementation signal and it is widely over-read. It is not a pause on baseline obligations, it is not a defence, and it puts the weight on evidence of trajectory.

What did AUSTRAC actually say?

Its May 2026 statement recognises that reporting entities will continue to embed practices and processes after 1 July 2026, and that it expects effort, not perfection, during FY26/27.

That sentence is usually quoted on its own, which is where the misreading starts. It sits directly beside a list of baseline expectations for newly regulated businesses, and the two are meant to be read together.

AUSTRAC expects newly regulated businesses to be enrolled, to have an AML/CTF programme and an AML/CTF compliance officer, to train staff on the programme, and to be ready to have a go at reporting when a suspicious matter arises. It has also said it will take early enforcement action against businesses that fail to enrol.

The defensible interpretation is therefore maturity with evidence, not delayed commencement. A business that has done nothing is not exercising effort; a business that has enrolled, appointed, trained and can report is inside the position AUSTRAC described even if parts of its programme are still being built.

The word doing the work in that sentence is evidence. Effort is only visible to a reviewer through a record, so the practical effect of the statement is to raise the value of documentation during the very period when a new programme is least likely to produce it. A firm that spends FY26/27 improving steadily without recording what changed, and when, and why, has done the work and cannot show it.

Why should you avoid inventing statutory categories?

Market commentary sometimes describes AUSTRAC as distinguishing wilful non-compliance from an honest effort defence. Those phrases should not be presented as if they were statutory tests unless a specific provision or regulator statement uses them that way.

The Act contains particular offences, civil penalty provisions, defences and enforcement powers. AUSTRAC separately communicates regulatory priorities and expectations. Both are real, and they do different jobs.

Collapsing them creates a specific risk for a compliance function, because it invites management to believe a defence exists that has not been enacted. A board told there is an honest effort defence may reasonably conclude that documenting good intentions is sufficient, which is the opposite of the conclusion the regulator's wording supports.

What management can control is the quality of the evidence showing what it has done, what remains incomplete, why it remains incomplete, and how the residual risk is being managed while the work continues.

What does a credible implementation plan look like?

Not a list of generic AML tasks. A plan that would survive review identifies, for each item, the control gap, the obligation or risk it relates to, the interim mitigation, the responsible owner, the target date, any dependency, and the evidence that will show completion.

FieldWhy a reviewer looks for it
Control gapStates the problem in the organisation's own terms
Obligation or riskConnects the gap to why it matters
Interim mitigationShows the risk is managed now, not only later
Responsible ownerA named person, not a function
Target dateMakes slippage visible
DependencyExplains why the date is what it is
Evidence of completionDefines what closing the item will produce

Take ongoing monitoring across a legacy customer book as an example. The plan should say how higher-risk customers are being prioritised in the interim, how changes in customer circumstances are detected while the target workflow is incomplete, who reviews those changes, and when the full workflow lands.

That demonstrates active risk management. A line item saying the organisation is working towards compliance demonstrates nothing, and it is the formulation most likely to be read as an absence of effort rather than evidence of it.

The interim mitigation column is the one most often left blank, and it is the most valuable. A gap with no interim control is an accepted risk whether or not anyone has said so, and saying so explicitly, with the reason and the approver, is a considerably stronger position than leaving it implied.

Which controls should be prioritised first?

AUSTRAC's own statement supplies a starting order, which is useful because it removes the argument about sequencing. Enrolment, then the programme and compliance officer, then staff training, then reporting readiness.

Those are not the only obligations, and treating them as a complete list would be its own mistake. But a business that cannot evidence those four is poorly placed to rely on a narrative of implementation maturity for anything else, because they are the items the regulator named.

The next layer connects the ML/TF risk assessment to customer due diligence, beneficial ownership, enhanced due diligence, ongoing due diligence, reporting and records. Priorities within that layer should follow the organisation's actual risk rather than the order in which tasks are easiest to close, which is the default that quietly emerges when nobody sets one. Our Tranche 2 checklist sets out that sequence with the evidence each step leaves behind.

What should board reporting show?

Trajectory, not a percentage. A single score such as 85 per cent compliant averages strong controls together with material gaps, and the averaging is what hides the gap that matters.

Report which material controls are operating, which are partially operating, which are not yet operating, and what risk is accepted or mitigated while work continues. That structure is harder to write and much harder to misread.

Useful supporting evidence includes approved programme changes, customer-file testing results, training completion, screening and match-review records, suspicious matter escalation exercises, independent evaluation planning, and closure of previously identified issues. Every item on that list is a record rather than an assertion, which is the property that makes it worth reporting.

The aim across successive reports is to show control effectiveness improving over time. A static picture repeated quarterly is itself a finding, and so is a picture that improves only in the areas that were already strong.

Keep the previous report's items visible in the next one. Being able to show that a gap identified two quarters ago was closed, and when, is the clearest available evidence of the trajectory the regulator's wording describes.

Where does technology fit while a programme matures?

Screening, monitoring, risk assessment and evidence are the parts that can be operationalised while the wider programme is still being built, and doing so early has a specific benefit: structured records make it possible to show controls were performed consistently rather than reconstructed afterwards.

That matters most for the period this article is about. The organisations that struggle to evidence effort are usually the ones whose early controls ran on individual judgement and personal files, so there is little to show for the months in question.

A platform is part of the compliance operating model, not evidence that every obligation has been met, and regulatory responsibility stays with the reporting entity. The Tranche 2 hub covers the rest of the programme this depends on.

Important information

This article provides general information about Australia's AML/CTF framework and does not constitute legal advice. Whether an obligation applies depends on the designated services provided and the circumstances of the business.

AUSTRAC's published expectations are statements of regulatory approach rather than legal defences, and they can change. Read the current versions and take your own advice on your own position. Reporting entities remain responsible for meeting their obligations under the AML/CTF Act, the Rules and applicable AUSTRAC guidance, alongside its published regulatory expectations and regulatory priorities.

FAQ

Common questions.

What did AUSTRAC actually say about effort and perfection?
Its May 2026 statement recognises that reporting entities will keep embedding practices and processes after 1 July 2026, and says it expects effort, not perfection, during FY26/27. That sits beside a clear list of baseline expectations, so it is an implementation signal rather than a deferral of obligations.
Which baseline obligations does AUSTRAC expect regardless?
That newly regulated businesses are enrolled, hold an AML/CTF programme and have an AML/CTF compliance officer, have trained staff on the programme, and are ready to have a go at reporting when a suspicious matter arises. It has also said it will take early enforcement action against businesses that fail to enrol.
Is there an honest effort defence in the Act?
Not as a statutory test. Commentary sometimes presents phrases like honest effort defence or wilful avoidance as though they were legal categories. The Act contains specific offences, civil penalty provisions, defences and enforcement powers, and AUSTRAC separately publishes priorities and expectations. Keep the two apart.
What can management actually control here?
The quality of the evidence showing what has been done, what remains incomplete, why it remains incomplete, and how the residual risk is being managed in the meantime. That record is what turns a claim of implementation maturity into something a reviewer can test.
Should we report a percentage complete to the board?
Avoid it. A single completeness score averages a well-run control together with a material gap and hides the second one. Report which material controls are operating, which are partially operating, which are not yet operating, and what risk is accepted or mitigated while work continues.

See MemberCheck against your own risk data.

Book a walkthrough with our compliance team and screen a real case in the first session.