Written by
Hadi Hawi, Chief Technology Officer
Reviewed by
Amos Yassa, Onboarding and Compliance Lead
Published 9 May 2026 · Last updated 9 May 2026
The deadline. Tranche 2 of Australia's Anti-Money Laundering and Counter-Terrorism Financing regime commences on 1 July 2026. AUSTRAC enrolment opens 31 March 2026. Around 90,000 Australian businesses across real estate, conveyancing, legal practice, accounting, precious metals dealing, and corporate service provision are newly captured. The penalties for non-compliance reach $33 million for a corporate breach and $6.6 million for an individual practitioner.
This guide explains what Tranche 2 is, who it captures, what the obligations look like in practice, what the cost of getting it wrong actually is, and how a Verified Once architecture changes the maths for every captured business.
Tranche 2 is the second major expansion of Australia's AML CTF regime since the original Anti-Money Laundering and Counter-Terrorism Financing Act 2006 was passed. The first tranche, in 2006, brought banks, casinos and remittance services under AUSTRAC supervision. Tranche 2 extends the same supervision to a category the regulator calls Designated Non-Financial Businesses and Professions, or DNFBPs.
The legal mechanism is the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, which received Royal Assent in late 2024. The Amendment Act re-defines "designated services" so that property transactions, conveyancing, legal trust account work, accounting client services, dealing in precious metals, and the formation of companies and trusts all become regulated activities. The moment a captured business provides one of those services, it inherits the same obligations the banks have lived with for nearly two decades.
The regulatory premise is straightforward. Money laundering does not stop at the bank. Criminal proceeds enter the legitimate economy through high-value asset purchases, professional advisory channels, and corporate structures. Real estate alone has been identified by AUSTRAC as a high-risk sector across multiple national risk assessments. Tranche 2 closes that gap by treating the gatekeepers — agents, conveyancers, lawyers, accountants — as part of the front line, not bystanders.
The headline number is the one to start with. Approximately 90,000 newly regulated reporting entities will sit under AUSTRAC supervision from 1 July 2026. For most of those businesses, this is the first time they have ever held an AML obligation. The hook stat below frames the scale.
90,000. The estimated number of Australian businesses newly captured under Tranche 2.
The Amendment Act expands the AML CTF perimeter to capture six broad professional categories. Every business inside these categories needs to assume it is captured unless its lawyer confirms otherwise.
Residential and commercial agents, buyer's agents, developers, project marketers, and advisory services. Obligations apply when the service involves buying, selling, leasing for 30 years or more, or managing real property on behalf of a client. Real estate is the largest category by entity count and the highest-risk one by laundering exposure. See Tranche 2 for real estate for the sector-specific obligations breakdown.
Any practitioner whose work involves transferring legal title to property, holding settlement monies, or facilitating property transactions outside a law firm. Captured by the same property-transaction trigger as real estate. See Tranche 2 for conveyancers .
Solicitors and barristers providing services that include holding client trust monies, managing or transferring assets, advising on or executing real estate transactions, forming companies and trusts, or acting on the buying and selling of business entities. The Law Council of Australia has been the most vocal industry body on the Tranche 2 perimeter; the perimeter is wide. See Tranche 2 for legal practices .
Public practitioners providing services that include holding client funds, executing transactions on behalf of a client, advising on or executing the buying and selling of real estate or business entities, and forming or administering trusts and companies. See Tranche 2 for accountants .
Captured when transacting above a defined threshold. The trigger is the value of the underlying transaction, not the size of the dealer.
Professional and corporate service providers. The category that captures business agents who form, register, administer, or act as nominees in the establishment of companies, trusts, partnerships and similar structures.
The legislative definition matters more than the trade label. A real estate principal whose business does sales and property management is captured for the sales work. A solicitor whose practice is purely litigation may not be captured. The way to confirm is to map every revenue line in the business against the designated-services list in the Attorney-General's Department overview of the AML CTF Amendment Act .
The transitional rules set three hard dates. None of them is negotiable.
31 March 2026, AUSTRAC enrolment opens. From this date, captured businesses can submit their enrolment to AUSTRAC. Enrolment requires the business to identify its designated AML CTF Compliance Officer, provide registration details, and confirm the designated services it provides.
1 July 2026, full enforcement commences. From this date, every captured business must have an AML CTF program in place, must be conducting Customer Due Diligence on new customers, must be monitoring transactions, and must be ready to lodge Suspicious Matter Reports and Threshold Transaction Reports as required. Civil penalties under the Act apply from this date.
29 July 2026, final enrolment cut-off. All newly captured businesses must have completed enrolment with AUSTRAC by this date. The 28-day window from 1 July to 29 July is the final compliance buffer; after that, late enrolment becomes a breach in itself.
There is one more date to watch. The AML CTF Transitional Rules 2026 set the operational detail behind the Amendment Act. Captured businesses should monitor AUSTRAC's guidance updates between now and 1 July 2026 because the practical interpretation of the Rules continues to evolve.
The pre-enrolment runway is the period to act in. Procuring a verification platform, drafting the AML CTF program, briefing the board, training the staff and running the pre-July dry-run all take time. By 31 March 2026, the captured business should already know which platform it is using.
The Amendment Act creates five distinct statutory obligations. All five apply to every captured business from 1 July 2026. Failure on any one of them is a breach.
Every captured business must enrol with AUSTRAC. Enrolment is the act of telling the regulator that the business is providing designated services and is therefore a reporting entity. Enrolment opens 31 March 2026 and closes 29 July 2026. The enrolment record names the business, its registered details, the designated services it provides, and the management-level AML CTF Compliance Officer who carries internal responsibility for the program. Enrolment is free; the work sits in identifying the right Compliance Officer and getting the registration details right the first time. Late enrolment, or enrolment with incorrect data, is itself a civil penalty matter under the Act.
A captured business must adopt and maintain a written AML CTF program tailored to its own money-laundering and terrorism-financing risk. The program is not a generic template. It is a documented, board-approved framework that maps the specific risks of the business — the customer types, the transaction types, the geographies, the structures it deals with — and sets out how the business will identify, mitigate and monitor those risks.
The program covers governance, customer onboarding, ongoing customer review, transaction monitoring, suspicious-matter escalation, record-keeping and staff training. The risk-based approach means a small residential agency will not need the same program as a multi-office franchise; the program must be proportionate to the risk profile, not a one-size-fits-all document.
Every new customer must be subjected to Customer Due Diligence (CDD) before the designated service is provided. CDD has four core components. First, identify the customer using reliable, independent identification documents. Second, identify any beneficial owners — the natural persons who ultimately own or control the customer entity. Third, screen the customer and its beneficial owners against AUSTRAC's sanctions lists and against Politically Exposed Person registers. Fourth, understand the purpose and intended nature of the business relationship.
Where the risk is higher — non-resident customers, complex corporate structures, PEP matches, transactions inconsistent with the customer's profile — the business must escalate to Enhanced Due Diligence (EDD), which requires deeper verification, source-of-funds enquiry, and senior-management approval. Existing customers do not need an immediate CDD redo unless a suspicious matter arises or the risk profile changes; new customers do, from 1 July 2026.
The captured business must actively monitor transactions for activity that does not fit the customer's known profile. When activity raises a reasonable suspicion of money laundering, terrorism financing, or other proceeds-of-crime offences, the business must lodge a Suspicious Matter Report (SMR) with AUSTRAC.
When a transaction crosses the threshold transaction value (currently $10,000 in physical currency or equivalent), a Threshold Transaction Report (TTR) must be lodged. Both reports operate under strict timeframes and the no-tipping-off rule, which prohibits the business from disclosing to the customer that a report has been made or is being made.
Every staff member whose role involves customer interaction, file handling, or transaction processing must receive ongoing AML CTF training. The training must cover the obligations under the program, the red flags relevant to the business, the escalation procedure, and the no-tipping-off rule.
Training is not a one-off induction. It is a recurring program, evidenced through training logs that the AML CTF Compliance Officer can produce on demand during an AUSTRAC review.
For the deeper version of all five obligations with worked examples per industry, download the Tranche 2 whitepaper .
There are two costs to non-compliance. The first is the regulatory penalty if AUSTRAC finds a breach. The second is the operational cost of trying to do the job manually.
AUSTRAC enforces compliance through civil penalty orders adjudicated by the Federal Court of Australia. Penalties are quantified in penalty units, not dollars, so the figures index automatically. Under Section 4AA of the Crimes Act 1914 , a single Commonwealth penalty unit was set to $330 from 7 November 2024, up from $313.
The maximum civil penalty for a corporate entity that systemically breaches the AML CTF Act is 100,000 penalty units, equating to $33 million per breach (or up to 10 percent of annual turnover, capped at 2.5 million penalty units, whichever is lower). The maximum civil penalty for an individual practitioner is 20,000 penalty units, or $6.6 million.
These are not theoretical. AUSTRAC has settled multi-hundred-million-dollar penalties against Tranche 1 entities in the last decade and has signalled the same posture toward Tranche 2.
The penalty stack. $33 million for a corporate breach. $6.6 million for an individual practitioner. $330 per penalty unit, indexed.
Self-managed compliance is the other expensive option. The Australian Government's Regulatory Impact Statement estimates the average ongoing cost of manual AML CTF compliance at $23,250 per business per year. For businesses with annual turnover above $200,000, the upfront cost of establishing a compliant framework is estimated at $28,650.
Engaging specialist AML consultants to build a bespoke program typically runs $10,000 to $50,000 upfront, plus $3,000 to $10,000 in ongoing annual review fees.
The hidden cost is the time. A captured small-to-medium business carrying its own AML workload internally typically spends 40 to 60 hours per month on enrolment maintenance, customer due diligence, transaction monitoring, suspicious-matter assessment, training, audit prep, and program upkeep.
At $60 per hour staff cost, that is $2,400 to $3,600 per month in pure time, before software, legal review or consultant fees. Across a year, the time burden alone runs to $28,800 to $43,200. Add the documented $23,250 baseline, and a self-managed posture lands at $50,000 to $66,000 per year for a small agency.
The platform-managed alternative compresses that burden. A managed verification and CDD platform absorbs identity verification, CDD orchestration, audit trail, training records and SMR drafting into one workflow.
See Ratified pricing for the comparison against the self-managed baseline.
Most captured businesses, faced with the obligations above, look for a software vendor and assume the problem is solved. It is not. The competitive landscape in Australian AML software has three structural failures that the captured business carries the cost of.
Every fragmented vendor builds the same model. The customer is forced through identity verification, biometric scanning and document upload at the first touchpoint with a regulated business, then again at the second, then again at the third.
A property buyer onboarded by their real estate agent goes through it. The same buyer goes through it again with the conveyancer. Then again with the bank. Then again with the accountant.
The data on this is brutal. Complex digital onboarding workflows show abandonment rates of 70 to 80 percent. Encompass Corporation's annual corporate-treasury survey found that 97 percent of corporate clients have actively considered switching service providers due to repetitive KYC friction.
A 2025 global financial-institutions survey found 70 percent of institutions had lost clients in the previous twelve months specifically because of slow, frictional onboarding. Every fragmented platform passes that abandonment risk straight to the captured business.
The friction problem. Customers repeatedly uploading identity documents across multiple regulated businesses creates abandonment, onboarding delays, and trust erosion.
Most Tranche 2 software is sized for sole practitioners and small SMEs. Franchise networks, multi-office groups, and corporate practices need granular role-based access control, hierarchical branch oversight, network-wide audit consolidation, and a single Compliance Officer Dashboard that spans every office.
The fragmented vendors do not build for this. A 50,000-agent national franchise cannot run AML CTF compliance on a tool designed for a five-agent agency, and the gap shows up the first time AUSTRAC asks for evidence of program execution across the network.
The most dangerous content gap in the competitive market is the privacy paradox. The AML CTF Act requires identity verification. The Privacy Act 1988, through Australian Privacy Principle 11 , requires reporting entities to take active steps to destroy or de-identify personal information once it is no longer needed for the purpose it was collected.
The Office of the Australian Information Commissioner (OAIC) has issued explicit privacy guidance for reporting entities under the AML CTF Act confirming that the AML CTF Act does not authorise the indefinite retention of raw identity documents.
A vendor that promises "secure document storage" of passports and driver licences is not solving the problem. It is creating a centralised honeypot of personally identifiable information that exposes the captured business to privacy breach liability under APP 11, on top of the cyber-liability exposure of holding the data at all.
The average Australian corporate data breach now costs $4.26 million, up 27 percent since 2020. The only legally defensible architecture is one that verifies the customer against the government register, retains the verification record, and destroys the underlying document data — not one that stockpiles documents on a server.
For the deeper architectural treatment of this, read APP 11 and the IVS Act .
Ratified was built specifically for the Tranche 2 problem. The architecture starts from the privacy paradox and works backwards.
The customer is verified to AUSTRAC standards once, against the Commonwealth's Document Verification Service, with express informed consent under the Identity Verification Services Act 2023 .
The result of that verification is cryptographically transformed into a single Ratified QR code — a digital identity passport that the customer carries. When the same customer engages the conveyancer, the legal practitioner, and the accountant, they present the QR code. The downstream regulated business consumes the verification result without ever touching the underlying documents.
That is what the brand line Verified Once, Trusted Everywhere means in practice. The mechanism is detailed at the Ratified Network .
Verified Once, Trusted Everywhere. One verified identity, reusable across regulated businesses without repeatedly handling raw identity documents.
The product is also Australian-built and Australian-hosted, on Australian sovereign infrastructure. The verification result is stored as a tokenised audit record. The raw documents are not retained. APP 11 obligations are satisfied at the architectural level, not at the policy level.
The full architecture is at Australian-built and APP 11 compliant .
The pedigree behind this matters for a regulated audience. The platform is built by Tritorian, an Australian fintech with more than 10 years operating identity verification and onboarding for regulated financial services.
The Ratified product itself represents a $2 million-plus engineering investment over a three-year build period before launch. This is not a feature on top of a generic SaaS. It is a purpose-built compliance infrastructure for the Australian regulatory market.
For the captured business, the practical outcome is one platform that handles AUSTRAC enrolment posture, AML CTF program scaffolding, Customer Due Diligence, ongoing monitoring, audit-trail generation, training records, and SMR/TTR drafting.
One Compliance Officer Dashboard for the whole business, or one dashboard per office across a franchise network, with reusable identity verification running underneath.
Source draft reference available here. :contentReference[oaicite:0]{index=0}
The runway between now and 1 July 2026 is short. The practical sequence for a captured business is straightforward.
First, confirm whether the business is captured. Map every designated-service revenue line against the AML CTF Act perimeter. If unsure, the AUSTRAC overview and the Attorney-General's Department overview are the canonical reference.
Where the perimeter is genuinely ambiguous, get a written legal opinion before 31 March 2026.
Second, choose the platform. The platform decision compresses everything else. A purpose-built verification and CDD platform absorbs the bulk of the program and dictates the operational shape of the AML CTF program document.
The right choice is the one that resolves the APP 11 paradox at the architecture level and that scales from a single office to a multi-office network without rework.
See Ratified pricing for the comparison.
Third, build the program, train the staff, enrol with AUSTRAC, and run a pre-July dry-run on five real customer files.
The dry-run is the difference between a program that survives an AUSTRAC review and a program that does not.
The implementation window is short. Businesses should already be selecting platforms, preparing AML/CTF programs, and operationalising onboarding workflows before 31 March 2026.
The Ratified team is taking new agencies, conveyancing firms, legal practices and accounting practices through this sequence right now.
To see the Ratified workflow and the Compliance Officer Dashboard in action, register now .
To go deeper on the regulatory detail, download the Tranche 2 whitepaper , the full long-form regulatory primer.
For more on the broader reform context, read our blog post on the Tranche 2 reforms in 2026 .
Ratified is built by Tritorian, an Australian fintech operating identity verification and onboarding for regulated financial services since 2015. A Caprock product. ABN [TBC for Ratified Pty Limited]. Australian-built, Australian-hosted, APP 11 compliant.
Tranche 2 AML/CTF obligations commence on 1 July 2026. AUSTRAC enrolment opens on 31 March 2026, with final enrolment cut-off on 29 July 2026. From 1 July 2026, newly captured businesses must have an AML/CTF program in place, conduct Customer Due Diligence, monitor transactions, and be capable of lodging Suspicious Matter Reports and Threshold Transaction Reports.
Tranche 2 captures real estate professionals, conveyancers, settlement-service providers, legal practitioners, accountants, dealers in precious metals and stones, and professional or corporate service providers. The determining factor is whether the business provides designated services defined under the AML/CTF Amendment Act, not the business label itself.
The maximum civil penalty for a corporate breach of the AML/CTF Act is 100,000 penalty units, currently equivalent to $33 million. Individual practitioners can face penalties up to $6.6 million. AUSTRAC has historically enforced significant penalties against reporting entities and has signalled the same posture toward Tranche 2 industries.
Captured businesses must enrol with AUSTRAC, maintain a written AML/CTF program, conduct Customer Due Diligence and Enhanced Due Diligence, monitor transactions and report suspicious matters, and provide ongoing AML/CTF training to staff. All five obligations apply from 1 July 2026 and failure on any one obligation may constitute a breach.
Yes. Every captured business providing designated services under Tranche 2 must enrol with AUSTRAC. Enrolment opens on 31 March 2026 and requires the business to nominate its AML/CTF Compliance Officer, identify the designated services provided, and submit the required registration details to the regulator.
Customer Due Diligence (CDD) is the standard identity verification and customer-risk assessment process required before providing a designated service. Enhanced Due Diligence (EDD) applies where higher-risk factors exist, including foreign ownership structures, politically exposed persons, unusual transaction behaviour, or complex beneficial ownership arrangements requiring deeper review.
No. The AML/CTF Act requires businesses to verify identity and retain appropriate records, but Australian Privacy Principle 11 also requires businesses to destroy or de-identify personal information when it is no longer required. A compliant architecture focuses on retaining the verification result and audit trail, rather than indefinitely storing raw identity documents.
A platform like Ratified can automate and operationalise major parts of the AML/CTF workflow, including identity verification, Customer Due Diligence orchestration, audit trails, monitoring workflows, training records, and reporting support. However, the reporting entity itself remains legally responsible for compliance under the AML/CTF Act.
Written by Hadi Hawi, Chief Technology Officer · Reviewed by Amos Yassa, Onboarding and Compliance Lead · Built by the team behind Ratified .
Ratified, AML made simple. See Ratified pricing or register now.