Who this checklist is for
Tranche 2 extended Australia's AML/CTF regime to businesses that had never been reporting entities. Obligations commenced on 1 July 2026, so this is a compliance checklist rather than a preparation one. If you are in one of these sectors, work through it now:
- Legal and conveyancing professionals
- Accountants and bookkeepers
- Real estate agencies
- Trust and company service providers
- Dealers in precious metals and stones
⚠️ Sector membership is not the test. The obligation attaches to providing a designated service, not to being in a listed industry. Two firms on the same street can reach different answers. Start with step 1 rather than assuming you are in or out.
1. Establish whether you are caught
- List every service you provide to clients, including ones you rarely sell
- Check each against AUSTRAC's designated services, service by service
- Record the ones that are caught, and the reasoning for the ones that are not
- Note where a service is provided through an intermediary or a referrer
- Have someone accountable sign the conclusion
Evidence to leave: a dated document stating which of your services are designated services and why. If you conclude you are out of scope, this is the document that defends that position.
2. Enrol and appoint, before the deadlines
- Enrol the entity with AUSTRAC as a reporting entity
- Appoint an AML/CTF compliance officer at management level
- Notify AUSTRAC of the appointment, and of any change to it
- Confirm who deputises when that person is unavailable
⚠️ The notification deadline is not the enrolment deadline. Under AUSTRAC's transitional rules, a newly regulated business must notify AUSTRAC of its compliance officer by the later of 14 days after enrolling, or 29 July 2026. Enrol on 29 July 2026 and you have until 12 August 2026. Once the transitional period ends the standard 14 day rule applies to every change of officer after that.
3. Write the risk assessment first
- Rate customer, product, channel and jurisdiction risk separately
- State the methodology, including what makes something high rather than medium
- Name the typologies your sector is actually exposed to, not a generic list
- Record where you deliberately accept risk, and who accepted it
Evidence to leave: a risk assessment that predates your controls. Building controls first and writing the assessment afterwards produces a programme that works and cannot explain itself.
4. Build the AML/CTF programme
- Write policies proportionate to the services you actually provide
- Set out your customer due diligence procedures, including when EDD applies
- Define how suspicious activity is escalated, and to whom
- Set a record-keeping standard and a retention period
- Schedule staff training, and record who completed it
- Work out your independent evaluation deadline from your AUSTRAC account number
You do not have to start from a blank page. AUSTRAC publishes a starter AML/CTF programme for newly regulated businesses, and adopting it is an accepted way to meet the programme obligation. Its own stated expectation for 1 July 2026 was that a business be enrolled, hold a programme (its starter one or your own), have a compliance officer, have trained staff, and be ready to ask clients questions and report suspicious activity.
Your first independent evaluation deadline depends on your AUSTRAC account number (AAN), which you receive when you enrol. The transitional rules stagger it by the last two digits:
| Last two digits of your AAN | First independent evaluation by |
|---|---|
| Both odd | 30 June 2029 |
| Second-last odd, last even | 31 December 2029 |
| Both even | 30 June 2030 |
| Second-last even, last odd | 31 December 2030 |
Check yours and put the date in your programme now, because the evaluation has to be scheduled against it rather than discovered late.
5. Customer due diligence
- Apply initial CDD to every new customer, from commencement onwards
- Identify beneficial owners for entity customers
- Screen customers and beneficial owners against sanctions, PEP and adverse-media data
- Plan the existing book as a remediation programme, in risk order
- Decide what triggers a review, rather than defaulting to a periodic cycle
6. The two obligations that never end
Everything above has a completion date. These two do not, and they are what a supervisor tests once the regime has bedded in:
- Ongoing customer due diligence, driven by what changed rather than by the calendar
- Suspicious matter reporting, within the statutory timeframes, every time
What to do next
The setup work gets the attention because it has deadlines. The ongoing obligations absorb the standing cost. The Tranche 2 readiness workflow sets out the same sequence as a workflow, and what Tranche 2 is covers the reforms themselves. If you are choosing tooling, the software buyer's guide sets out the criteria before it names any platform. The Tranche 2 hub routes to all of it, and to the guidance for each newly regulated sector.
