From 1 July 2026, Australia's AML/CTF Act applies to designated services provided by legal professionals, accountants, conveyancers, real estate professionals, and dealers in precious metals, stones and products. For compliance teams in these sectors, it means building the same core AML/CTF programme banks already run: risk-based customer due diligence, ongoing monitoring, record keeping, and reporting suspicious matters to AUSTRAC.
What is Tranche 2, and who does it affect?
Tranche 2 brings designated non-financial businesses and professions (DNFBPs) into Australia's AML/CTF regime for the first time, through the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Act No. 110 of 2024), which amends the AML/CTF Act 2006. The sectors most affected are legal services, accounting, real estate and conveyancing, and dealers in precious metals and stones.
Note that the obligation attaches to the designated service, not the job title. Trust and company service provider work is captured that way: AUSTRAC's professional designated services table covers selling or transferring a shelf company, creating or restructuring a body corporate or legal arrangement, and acting as a nominee shareholder or director. A firm providing any of those is in scope whether or not it thinks of itself as a TCSP.
What do compliance teams need to change first?
The first practical step is a documented, risk-based AML/CTF programme: a written policy covering how the business identifies, assesses, and manages money-laundering and terrorism-financing risk across its customers, products, and channels. AUSTRAC's own structure runs from establishing a governance framework, through risk assessment and mitigating policies, to review and independent evaluation. Without this foundation, individual controls like due diligence or monitoring have nothing to sit on.
How does customer due diligence change under Tranche 2?
Newly regulated businesses need to verify customer identity, understand the nature and purpose of the relationship, and identify beneficial ownership for corporate clients — the same customer due diligence standard already applied elsewhere, now extended to matters like property transactions, trust structures, and client-money handling that are specific to these sectors.
What ongoing monitoring is required?
Due diligence at onboarding isn't sufficient on its own. Tranche 2 also requires ongoing customer due diligence, so a change in a client's risk profile or an unusual transaction pattern gets picked up after onboarding, not just at the start of it. This is where manual, spreadsheet-based checks stop scaling and a transaction monitoring capability becomes necessary.
How should teams prepare before obligations take effect?
Moving from manual checks to repeatable compliance operations is the practical difference between a programme that holds up under audit and one that doesn't. That means screening new and existing clients against sanctions and PEP data, documenting due diligence decisions, and keeping records in a form that can be produced on request — the operational core Tranche 2 is actually asking for.
Where to go deeper
This overview covers the operational shape of Tranche 2; for the detail behind each piece, see building a risk-based AML programme for Tranche 2, how automated due diligence simplifies compliance, and the role of RegTech in supporting Tranche 2. For how the reforms play out sector by sector, see the impact on lawyers, accountants, real estate professionals, precious metals dealers, and trust and company service providers. And for what the reforms suggest about AML/CTF regulation beyond Australia, see what Tranche 2 signals about the future of global compliance.



