Where this now stands
Tranche 2 extended Australia's AML/CTF regime to professions that had never been reporting entities. The dates have passed:
| Date | What happened |
|---|---|
| 31 March 2026 | Enrolment with AUSTRAC opened |
| 1 July 2026 | Obligations commenced for the newly regulated sectors |
| 29 July 2026 | Enrolment deadline |
That changes the question. Until 1 July the work was preparation, and being mid-build was a reasonable position. It is not one now. A firm providing a designated service is a reporting entity whether or not it has enrolled, and whether or not it has a programme.
If you are still outside the regime
Being late is recoverable. Being late and undocumented is harder, because the first thing you will be asked is when you established your scope and what you did about it.
- Work through your services one at a time against AUSTRAC's designated services, and write down the reasoning, including for the services you conclude are not caught
- If any are caught, enrol with AUSTRAC
- Appoint an AML/CTF compliance officer at management level
- Complete the risk assessment before designing controls, because it is what justifies them
- Start customer due diligence on new customers immediately, then plan the existing book
The readiness workflow sets out that sequence in full, and the checklist is the version you can work through and tick off.
Two dates follow from enrolling rather than from the commencement calendar, so they are easy to miss. Your compliance officer must be notified to AUSTRAC by the later of 14 days after you enrol or 29 July 2026. Your first independent evaluation is due between 30 June 2029 and 31 December 2030 depending on the last two digits of the AUSTRAC account number you are issued on enrolment, and the checklist sets out which pairing gives which date.
What ongoing compliance looks like
Setup had deadlines and an end. The two obligations that replaced it have neither, and between them they carry almost all of the standing cost.
Ongoing customer due diligence. Not a periodic refresh cycle. The obligation is to keep customer information current and to review when something changes, which makes the trigger an event rather than a date. A customer who becomes a politically exposed person, an entity whose beneficial ownership changes, a counterparty added to a sanctions list overnight: each of those is a review, and none of them arrives on schedule. That is why perpetual KYC replaces the annual review as the operating model.
Suspicious matter reporting. Within the statutory timeframes, every time, with the tipping-off prohibition attached. For a firm that has never reported, this is an entirely new muscle, and the failure mode is not refusing to report but not recognising what needed reporting.
Screening is the part that changes most often, because what moves is the data rather than the rule. Sanctions lists change without notice, so a check that was clean at onboarding is not evidence of anything a month later. Ongoing monitoring against current data is what keeps the position defensible.
What AUSTRAC has said it will enforce
AUSTRAC has published its position, and it is more specific than a general warning. Its regulatory expectations state that it does not expect newly regulated businesses "to be perfect at identifying and controlling for money laundering risks from day one", but that it does expect "honest efforts to meet your obligations and report suspicions to AUSTRAC".
⚠️ It then names what it will pursue. After 1 July 2026 AUSTRAC said it would focus enforcement in the newly regulated sectors on entities "who wilfully ignore the obligation to enrol" and those it suspects are "complicit with, or wilfully blind to, money laundering in their business". Its 2026 to 2027 priorities keep the same shape: effort rather than perfection, with enforcement aimed at non-enrolment and complicity.
Read together, those two statements are the practical guide. An imperfect programme that is enrolled, staffed and honestly operated is not the target. Not enrolling is. So is a programme that exists on paper while the business declines to look at what it is being told.
That is also why the record matters more than the intention. The exposure for a newly regulated firm is rarely a deliberate breach, it is having accepted a customer for good reasons and having no record of what those reasons were. In practice:
- Every screening decision needs a retained result, not just an outcome
- Every alert needs a named reviewer and a dated rationale
- Every risk rating needs the methodology that produced it
- Every exception needs whoever authorised it
⚠️ Two published deadlines do not apply to you, and mistaking them is easy. AUSTRAC's transitional rules set a compliance officer notification date of 30 May 2026 and allow initial customer due diligence to continue under the old procedures until 31 March 2029. Both are conditional on having been enrolled as a reporting entity on 30 March 2026, so both belong to businesses that were already regulated. A newly regulated firm has no such transition: new customers get the new initial CDD framework from the start, and its officer notification runs from its own enrolment date.
Guidance by sector
The newly regulated categories concentrate in five sectors, and each has its own version of the problem:
- Legal and conveyancing. What Tranche 2 means for lawyers, and AML compliance for law firms
- Accounting. The impact on the accounting profession, and AML compliance for accounting firms
- Real estate. The impact on real estate professionals, and AML compliance for real estate
- Trust and company service providers. The impact on TCSPs, and AML compliance for TCSPs
- Precious metals and stones. The impact on dealers, and AML compliance for precious metals dealers
The four pages, and what each answers
| If you are... | Start here |
|---|---|
| Working out what the reforms were | What is Tranche 2? |
| Working out whether you are caught, and what to build | Readiness workflow |
| Working through it step by step | Tranche 2 AML checklist |
| Choosing tooling | Software buyer's guide |
Where MemberCheck fits
MemberCheck screens customers, entities and beneficial owners against global sanctions, PEP, watchlist and adverse-media data, verifies identities, and monitors continuously, with an audit trail behind each decision. Bringing an existing client book up to a standard it was never opened against is a remediation programme rather than an intake process, and it is the piece most firms underestimated.
If you would rather talk it through, get in touch and say which sector you are in and whether you have enrolled.
