Blog

Tranche 2

How to Build a Risk-Based AML/CTF Programme After the Tranche 2 Deadline

Obligations commenced on 1 July 2026. The sequence for building a compliant programme now, including how to stop continuing exposure if enrolment was missed.

Tranche 2 obligations commenced on 1 July 2026, which changes how this work is sequenced. A business starting now is not preparing for a deadline; it is building a programme while already inside the regime, and if enrolment was missed the first task is to stop that exposure growing.

What comes first if enrolment was missed?

Stopping any continuing failure. If a business is providing a designated service and should have applied for enrolment but has not, the first priority is to establish the facts and act on them.

Section 51B makes late enrolment a continuing obligation and treats each relevant day as a separate civil contravention until the obligation ends. So confirm the legal entity, the designated service, the start date and the enrolment status, then make the required application where appropriate. Preserve evidence of the original dates and involve legal counsel if there is potential historical exposure or any regulator contact.

Do not backdate documents or create records that imply controls existed when they did not. Remediation is consistently stronger when an organisation can show when a gap was identified and what it did to correct it, and a tidy reconstructed file raises the question of when the file was assembled.

Which programme structure applies now?

The unified one. The reformed regime does not require newly regulated businesses to build the old Part A and Part B programme structure, and material still describing that split is out of date.

AUSTRAC's current framework is a single AML/CTF programme built around governance, the ML/TF risk assessment, AML/CTF policies, review and update, independent evaluation and record keeping. The programme has to reflect the actual nature, size and complexity of the business, and it needs approval from the appropriate senior manager.

That last requirement is worth reading as a design constraint rather than a formality. A programme copied from a larger organisation will not reflect the business, and the senior manager approving it is approving a description of how the business actually operates.

It also sets a floor for how short the programme can be. Governance, risk assessment, policies, review, evaluation and records all have to be addressed, so a two-page document will not cover the framework however small the business is. The proportionality applies to the depth of each element rather than to whether it appears at all.

How do you build the risk assessment?

From the services the business actually provides, not from a template. Map the designated services, customer types, delivery channels, jurisdictions and any other risk factors relevant to the business. Identify where each service could be misused for money laundering, terrorism financing or proliferation financing, and assess the inherent risk.

Then map existing controls against those risks. That step is what makes the exercise useful rather than academic, because it usually shows the business already has several effective processes and a small number of material gaps.

The risk assessment then becomes the basis for prioritising customer due diligence, enhanced due diligence, ongoing due diligence, reporting and record-keeping controls. Priorities set any other way tend to follow whichever task is easiest to close.

What governance does remediation need?

Enough to make decisions and record them. Confirm the AML/CTF compliance officer, the senior manager approval route and the governing body's oversight role, and give the compliance officer access to the systems, customer information and decision-makers the work requires.

For each material gap, record six things.

FieldPurpose
GapStates the problem in the organisation's own terms
OwnerA named person rather than a function
Interim controlShows the risk is managed now, not only later
Target stateDefines what closing the gap means
DeadlineMakes slippage visible
Evidence for closureSays what closing it will produce

Management should receive regular reporting on open higher-risk gaps rather than a single percentage-complete score, which averages a strong control together with a material gap and hides the second one.

Keep the previous report's items visible in the next one. Being able to show that a gap identified two quarters ago was closed, and when, is the clearest evidence available that the programme is improving rather than merely being worked on.

How do you get from policy to operating evidence?

By testing real files. A programme becomes defensible when customer records show the control working, so prioritise live workflows for identity and beneficial ownership, customer risk assessment, screening where policy requires it, enhanced due diligence, ongoing due diligence, suspicious matter escalation, training and records.

Then take a sample of real matters or customers and ask whether the team can reconstruct the decision trail from the file alone. Who the customer was, what was collected, how ownership was established, what screening ran, how a potential match was resolved, what rating was assigned and who approved any exception.

If that reconstruction needs a conversation with the original reviewer, the control is not yet embedded, however complete the policy document looks. Our Tranche 2 checklist sets out the evidence each step should leave behind.

When should independent evaluation happen?

Earlier than the deadline, in most cases. AML/CTF policies must provide for independent evaluations of the programme, policies must set an appropriate frequency, and the minimum is at least once every three years. Transitional rules stagger the first evaluation deadlines for newly regulated businesses according to their AUSTRAC account number.

A late adopter should not treat the outer transitional deadline as a reason to defer assurance. An earlier evaluation can identify material design or implementation weaknesses once enough of the programme is operating to be tested, which is considerably cheaper than finding them later.

Record the findings, the remediation decisions and the closure evidence, so the governing body can see whether the programme is becoming more effective over time rather than simply remaining in progress.

What does a risk-based approach deliver beyond compliance?

Concentration of effort. A flat process applies the same scrutiny to a long-standing local customer and a layered foreign structure, which means most of the work happens where the risk is lowest.

A risk-based programme also produces better management information, because the ratings and escalations tell the business something about its own customer base. And it is easier to defend, since the reasoning behind each level of scrutiny is recorded rather than implied.

There is a commercial dimension too. Banking counterparties assessing a regulated customer tend to ask how a programme was developed and how seriously it is being implemented, and a risk assessment tied to the firm's actual services answers that question in a way a template cannot.

Where does technology fit?

In the screening, customer and business risk, monitoring and audit-record components. For a business moving away from manual or inconsistent controls, structured workflows turn policy requirements into repeatable steps that leave evidence as a by-product rather than as a separate task.

That should be positioned as part of the control environment, not as a substitute for enrolment, programme governance, reporting obligations, legal advice or independent evaluation. The Tranche 2 hub routes to the sector guidance and the rest of the sequence.

Important information

This article provides general information about Australia's AML/CTF framework and does not constitute legal advice. Whether an obligation applies depends on the designated services provided and the circumstances of the business.

If an enrolment obligation may have been missed, take your own legal advice on your own dates and services before acting. Reporting entities remain responsible for meeting their obligations under the AML/CTF Act, the Rules and applicable AUSTRAC guidance, alongside its published regulatory expectations.

FAQ

Common questions.

Do we still build a Part A and Part B programme?
No. The reformed regime does not require newly regulated businesses to build the old Part A and Part B structure. The current framework is a unified AML/CTF programme built around governance, ML/TF risk assessment, AML/CTF policies, review and update, independent evaluation and record keeping.
What is the first thing to do if we missed the enrolment deadline?
Establish the facts and stop the continuing failure. Section 51B makes late enrolment a continuing obligation and treats each relevant day as a separate civil contravention until it ends, so confirm the legal entity, designated service, start date and enrolment status, then make the required application where appropriate.
Should we backdate documents to show controls were in place?
No. Do not backdate documents or create records implying controls existed when they did not. Remediation is stronger when the organisation can show when a gap was identified and what was done to correct it, and a reconstructed file invites questions about when it was assembled.
What does a risk-based approach actually mean here?
Assessing money laundering and terrorism financing risk against the services the business actually provides, its customer types, delivery channels and jurisdictions, then applying proportionate controls. The alternative, applying identical scrutiny to every relationship, spends most of the effort where the risk is lowest.
Can we wait for the outer independent evaluation deadline?
You can, and it is usually the wrong call. Transitional rules stagger the first evaluation deadlines by AUSTRAC account number, but an earlier independent evaluation can identify material design or implementation weaknesses once enough of the programme is operating to be tested.

See MemberCheck against your own risk data.

Book a walkthrough with our compliance team and screen a real case in the first session.