Australia’s Tranche 2 AML Regime Takes Effect, Bringing Property and Professional Services into Scope

Australia’s expanded anti-money laundering and counter-terrorism financing regime took effect on 1 July 2026, bringing tens of thousands of additional businesses within the supervision of the Australian Transaction Reports and Analysis Centre, or AUSTRAC.
The reforms extend AML/CTF obligations to certain services commonly provided by:
- Real estate professionals;
- Lawyers;
- Accountants;
- Conveyancers;
- Trust and company service providers; and
- Dealers in precious metals, precious stones and related products.
Certain additional virtual asset services have also entered the regulatory framework.
AUSTRAC estimates that the number of regulated businesses will increase from approximately 19,000 to close to 100,000 nationwide.
The expansion, widely referred to as Australia’s “Tranche 2” reforms, addresses sectors that can be used to purchase property, establish companies and trusts, manage client assets, and move or conceal the proceeds of crime.
For newly regulated businesses, the central compliance task is no longer preparation. From 1 July 2026, businesses providing covered services must determine whether they are reporting entities and begin meeting their obligations under the AML/CTF Act.
Regulation Applies to Services, Not Simply Professions
A lawyer, accountant or real estate agent does not automatically become regulated solely because of their professional title.
The regime applies when a business provides one or more designated services specified in the AML/CTF Act and the service has the required geographical connection to Australia.
This distinction is important because not every activity performed by a newly regulated profession falls within the regime.
For example, a lawyer providing general legal advice may not necessarily be providing a designated service. However, the position may be different where the lawyer assists a client in planning or carrying out a transaction involving property, a company, a trust or another legal arrangement.
Each business must therefore assess the services it actually provides rather than relying only on its industry classification.
Which Activities Are Now Covered?
Real Estate Services
The regime covers specified services involving the sale, purchase or transfer of real estate.
This may include real estate professionals who broker transactions on behalf of buyers or sellers, as well as property developers that directly sell certain developments without using an independent real estate agent.
Private sales and incidental disposals of property by businesses are not automatically covered. The activity must fall within the statutory definition of a designated service.
Real estate is attractive for money laundering because it can absorb substantial amounts of illicit wealth, provide an apparently legitimate investment and allow ownership to be obscured through companies, trusts or nominees.
The reforms require relevant real estate businesses to identify the customers for whom they act and assess the risks associated with the transaction.
Legal, Accounting and Conveyancing Services
Professional services may be regulated where a business assists a client in planning or executing specified transactions.
Covered activities may include assisting with:
- Buying, selling or transferring real estate;
- Buying, selling or transferring a company or other legal arrangement;
- Establishing or restructuring companies, trusts or similar arrangements;
- Receiving, holding, controlling or managing client property as part of a transaction;
- Arranging equity or debt financing for a company or legal arrangement; and
- Providing specified trust and company services.
Typical conveyancing activities may fall within scope where they directly advance a property transfer. These may include preparing transaction documents, conducting title-related work, coordinating settlement, holding funds and arranging the transfer of ownership.
The regime is intended to cover professional involvement that facilitates or carries out the relevant transaction. Services that are merely incidental or too remote from the transaction may not be designated services.
Businesses will need to map their service lines carefully, particularly where regulated and non-regulated work is performed within the same firm.
Trust and Company Services
Certain services involving the formation and administration of legal entities and arrangements are also regulated.
These may include:
- Forming a company or other legal person;
- Creating a trust or similar legal arrangement;
- Providing a registered office or business address;
- Acting, or arranging for another person to act, as a director or secretary;
- Acting, or arranging for another person to act, as a trustee; and
- Providing nominee shareholder services.
Companies and trusts can be used legitimately for commercial, investment, estate-planning and asset-management purposes. They can also be misused to conceal beneficial ownership, disguise control or separate criminal proceeds from the individuals who ultimately benefit from them.
Reporting entities providing these services must therefore understand both the legal structure and the individuals who ultimately own or control it.
Precious Metals, Stones and Related Products
Dealers may be regulated when they buy or sell precious metals, precious stones or related products involving at least A$10,000 in physical currency or virtual assets.
The threshold can be reached through:
- A single transaction; or
- Several transactions that are linked or appear to be linked.
Businesses cannot avoid the regime simply by dividing one purchase into several smaller payments.
The obligation is linked to the value and payment method specified in the legislation. It does not mean that every jewellery or precious-metal transaction is automatically a designated service.
Dealers should have procedures for identifying connected transactions and recognising attempts to structure payments below the threshold.
Enrolment Is the First Administrative Requirement
A newly regulated business that provides a designated service must enrol with AUSTRAC as a reporting entity.
Businesses providing the new services from the commencement date were required to complete enrolment by 29 July 2026 under the transitional arrangements.
A business that begins providing a designated service later must generally apply to enrol within 28 days of commencing that service.
Enrolment allows AUSTRAC to identify the reporting entity and understand matters such as:
- Its ownership and business structure;
- The designated services it provides;
- Its operating locations;
- Its contact and compliance information; and
- The scale and nature of its regulated activities.
For most lawyers, accountants, conveyancers, real estate professionals and precious-metals or stones dealers, enrolment is the relevant requirement.
Registration is a separate process that generally applies to remittance service providers and businesses providing specified virtual asset services. Newly regulated professional firms should therefore avoid using “registration” and “enrolment” interchangeably when determining their obligations.
An AML/CTF Program Must Be in Place
A reporting entity must develop and maintain an AML/CTF program appropriate to its business.
The program must contain two core components:
- A risk assessment; and
- Policies, procedures, systems and controls for managing the identified risks.
The program should reflect the nature, size and complexity of the business. A small conveyancing practice is not expected to operate the same systems as a national property group, but both must be able to demonstrate that their controls are appropriate for the risks they face.
The program should explain how the business will:
- Identify and assess ML/TF risks;
- Conduct customer due diligence;
- Identify beneficial owners;
- Apply enhanced due diligence where necessary;
- Monitor customer relationships and transactions;
- Identify and report suspicious matters;
- Manage higher-risk customers and services;
- Train relevant personnel;
- Maintain required records;
- Review and update its controls; and
- Respond to compliance failures.
An AML/CTF program should not be treated as a standard policy document adopted without reference to the business’s actual operations.
The procedures used by employees must correspond with the written program.
Businesses Must Conduct an ML/TF Risk Assessment
The risk assessment is the foundation of the AML/CTF program.
It must identify and assess the money laundering, terrorism financing and proliferation financing risks that the business may reasonably face when providing designated services.
Relevant risk factors may include:
- The types of customers served;
- The nature of the designated services;
- Countries connected with the customer or transaction;
- Delivery channels;
- Whether the customer is met in person;
- The use of companies, trusts or nominees;
- Politically exposed persons;
- The source of funds or wealth;
- Cash or virtual asset payments;
- Complex ownership structures;
- Unusual transaction instructions; and
- The involvement of third parties or intermediaries.
Different sectors will face different risks.
A real estate agency may focus on unusual purchasers, opaque funding arrangements and third-party payments. A law or accounting firm may face risks involving company formation, trusts, client accounts and transactions without a clear commercial purpose.
A dealer in precious products may need to address large cash purchases, linked transactions and customers seeking easily transferable stores of value.
The risk assessment must be kept current. It should be reviewed when the business introduces a new service, enters a new market, changes its delivery model or identifies a material change in criminal threats.
Governance Responsibility Extends Beyond the Compliance Officer
Responsibility for AML/CTF compliance does not rest solely with one employee.
The governing body has primary responsibility for overseeing compliance at the highest level. Senior management is responsible for approving the AML/CTF program and relevant compliance decisions.
The business must also appoint an AML/CTF compliance officer to oversee and coordinate day-to-day compliance.
The compliance officer must have sufficient:
- Authority;
- Independence;
- Access to information;
- Resources; and
- Knowledge or expertise.
The person must be engaged at management level and be fit and proper for the role. Where the business provides designated services through a permanent establishment in Australia, the officer must generally be an Australian resident.
Smaller businesses may appoint an owner, director or operational manager. An external person may also be engaged where the eligibility, authority and resourcing requirements are met.
The appointment of an external adviser does not transfer the reporting entity’s legal responsibility for compliance.
Newly regulated businesses must notify AUSTRAC of their compliance officer by the later of:
- 29 July 2026; or
- 14 days after enrolling with AUSTRAC.
The compliance officer must report to the governing body at least annually on the effectiveness of the business’s AML/CTF policies, its compliance status and any significant deficiencies.
Customer Due Diligence Becomes Part of Client Onboarding
Before providing a designated service, a reporting entity generally needs to conduct customer due diligence appropriate to the circumstances.
This includes establishing and verifying the customer’s identity.
Where the customer is a company, trust, partnership or other organisation, the business may also need to identify:
- The legal existence of the customer;
- Directors, trustees or other controllers;
- Persons authorised to act;
- The ownership structure; and
- The individuals who ultimately own or control the customer.
The reporting entity must assess the customer’s ML/TF risk and obtain enough information to understand the nature and purpose of the relationship.
Higher-risk relationships may require enhanced due diligence. This may include obtaining additional information about:
- Beneficial ownership;
- Source of funds;
- Source of wealth;
- The purpose of a transaction;
- The customer’s business activities;
- Connected jurisdictions; and
- The reason for using a particular structure.
For professional firms, customer due diligence must be integrated into the engagement process.
It should occur early enough to prevent the business from providing a designated service before the required checks have been completed.
Existing Clients Cannot Simply Be Ignored
Businesses entering the regime may already have long-standing customers.
The reforms include arrangements for pre-commencement customers, but existing relationships are not permanently outside the AML/CTF framework.
A business may need to conduct or update customer due diligence where:
- A triggering event occurs;
- The customer’s circumstances change;
- The business identifies a higher level of risk;
- Existing identification information is unreliable or insufficient;
- Suspicious activity is detected; or
- The AML/CTF program requires a review.
Businesses should therefore identify existing customers receiving designated services and determine how those relationships will be managed under the new framework.
Relevant Personnel Must Receive AML/CTF Training
Employees and other personnel performing AML/CTF-related functions must understand the risks relevant to their roles.
Training should cover matters such as:
- The business’s AML/CTF program;
- Customer identification procedures;
- Beneficial ownership;
- Risk indicators;
- Enhanced due diligence;
- Suspicious matter escalation;
- Recordkeeping;
- Privacy and confidentiality; and
- The consequences of non-compliance.
Training should be tailored to the employee’s responsibilities.
A receptionist who collects customer information does not need the same training as a compliance officer. However, the receptionist may still need to recognise when information is missing or when a customer resists identification requirements.
Employees involved in onboarding, trust accounts, settlement, company formation and transaction review will generally require more detailed and regular training.
A business should maintain records showing:
- Who received training;
- When it was delivered;
- What subjects were covered;
- Whether understanding was assessed; and
- When refresher training is required.
Generic awareness training alone may not be sufficient for staff performing higher-risk functions.
Suspicious Matters Must Be Reported to AUSTRAC
A reporting entity must submit a suspicious matter report when it has reasonable grounds to suspect that a matter may relate to specified criminal activity or that a person may not be who they claim to be.
A suspicion may arise before, during or after a designated service is provided.
Examples relevant to the newly regulated sectors may include:
- A buyer using an unexplained third party to fund a property purchase;
- A customer using multiple companies without a clear commercial reason;
- Instructions to conceal the identity of the beneficial owner;
- Funds received from a jurisdiction unrelated to the transaction;
- A client showing unusual concern about reporting or identification requirements;
- Attempts to divide a large cash purchase into smaller transactions;
- Sudden changes in transaction instructions;
- Documents that appear false or inconsistent;
- A customer seeking to use a trust account without a genuine legal purpose; or
- A transaction that appears inconsistent with the customer’s financial profile.
Suspicious matter reports must generally be submitted:
- Within 24 hours where the suspicion relates to terrorism financing; or
- Within three business days for other suspicions.
Employees should have a clear internal escalation process for referring concerns to the compliance officer.
A business does not need to prove that a crime has occurred before submitting a report. The reporting obligation is based on reasonable grounds for suspicion, not a completed investigation or criminal finding.
Reporting entities must also observe restrictions on disclosing information that could reveal that an SMR has been or may be submitted.
For legal professionals, the relationship between reporting obligations and legal professional privilege requires particular care. Privilege may affect the disclosure of protected information, but it does not provide a general exemption from the AML/CTF regime.
Other Reporting Obligations May Also Apply
Depending on the services and transactions involved, a reporting entity may also need to submit other reports to AUSTRAC.
These may include threshold transaction reports where a designated service involves physical currency of A$10,000 or more.
International value transfer reporting may also apply in relevant circumstances.
Businesses should determine which reporting requirements apply to their specific designated services rather than assuming that suspicious matter reporting is their only reporting obligation.
Records Must Demonstrate What the Business Actually Did
Reporting entities must retain records supporting their compliance.
These may include:
- Customer identification and verification records;
- Beneficial ownership information;
- Customer risk assessments;
- Enhanced due diligence records;
- Transaction information;
- Suspicious matter assessments;
- AML/CTF program versions;
- Staff training records;
- Compliance officer appointments;
- Governing-body reports;
- Monitoring results; and
- Independent evaluation findings.
Good recordkeeping allows the business to demonstrate not only that policies existed, but also that they were applied in practice.
This will be particularly important for professional firms that have historically relied on informal knowledge of their clients rather than documented customer and transaction risk assessments.
Programs Must Be Independently Evaluated
The AML/CTF framework also requires periodic independent evaluation of the reporting entity’s program.
The evaluation should assess whether the business:
- Has appropriately identified its risks;
- Has suitable policies and controls;
- Is following those policies;
- Is meeting its legal obligations; and
- Is correcting identified weaknesses.
The evaluator must be sufficiently independent from the activities being reviewed.
The frequency and scope of evaluations should reflect the size, complexity and risk profile of the business, as well as the applicable statutory and transitional requirements.
An independent evaluation is not merely a review of whether the program document contains the expected sections. It should examine how effectively the controls operate.
What Newly Regulated Businesses Should Prioritise
Businesses that have entered the regime should be able to demonstrate that they have addressed the following core requirements:
- Determine whether they provide a designated service.
- Enrol with AUSTRAC as a reporting entity.
- Document an ML/TF risk assessment.
- Develop and implement an AML/CTF program.
- Appoint and notify an eligible compliance officer.
- Establish customer and beneficial-owner identification procedures.
- Introduce customer risk classification and enhanced due diligence.
- Train relevant personnel.
- Create an internal suspicious matter escalation process.
- Prepare to submit reports through AUSTRAC Online.
- Maintain appropriate compliance records.
- Plan for independent evaluation and ongoing program updates.
Businesses should also review engagement letters, onboarding forms, transaction workflows, customer communications and internal responsibilities.
The objective is to integrate AML/CTF controls into ordinary business processes rather than add them as a separate administrative exercise after a transaction has begun.
A Significant Change for Australia’s AML Framework
Australia’s Tranche 2 reforms close a long-standing gap in the country’s AML/CTF regime.
Banks and other financial institutions have been subject to AML obligations for many years, but criminals do not rely only on financial institutions.
They may use:
- Real estate to store illicit wealth;
- Lawyers and conveyancers to carry out transactions;
- Accountants and corporate service providers to create structures;
- Trusts and companies to conceal ownership; and
- Precious assets to move or preserve value.
Bringing these services within the AML/CTF regime does not mean that every customer or transaction should be treated as suspicious.
It requires businesses to understand the risks they face, identify their customers, recognise warning signs and report matters that give rise to reasonable suspicion.
For newly regulated professions, the principal change is therefore not simply the requirement to enrol with AUSTRAC.
It is the introduction of a documented, risk-based compliance framework into services that can play a central role in the movement and concealment of criminal proceeds.
Main Sources
AUSTRAC — Anti-Money Laundering and Counter-Terrorism Laws Cover Thousands More Businesses
AUSTRAC — About the AML/CTF Reforms
AUSTRAC — Designated Services for Newly Regulated Entities
AUSTRAC — Your AML/CTF Obligations
AUSTRAC — Enrol With Us



