Regulatory explainer · AUSTRAC Tranche 2

AUSTRAC Tranche 2, in plain English

From 1 July 2026, certain services commonly provided by lawyers, conveyancers, accountants and real estate businesses enter Australia's AML/CTF regime. The profession is not the trigger; the designated service is.

A service test, not a job-title test

Start with what the firm does for the customer.

Tranche 2 extends AML/CTF obligations to newly regulated designated services. The same practice can perform work that is captured and work that is not. A conveyance may trigger the regime; unrelated litigation may not. Forming a trust for a customer may be captured; preparing an ordinary tax return is not captured merely because an accountant prepares it.

Map each service, the customer receiving it and the point at which the business begins to act on instructions. AUSTRAC's tools and sector guidance are the authoritative starting points. Borderline engagements need advice based on the legislation and the facts, not a generic checklist.

Who may be captured

Concrete examples by profession

These examples are orientation, not a scope determination. A service's precise features, customer and geographical connection matter.

01

Lawyers and conveyancers

May be captured: Assisting with buying, selling or transferring real estate; managing client money, securities or other assets; forming or restructuring companies and trusts; and acting in specified transactions can be designated services.

Not automatic: General advice, litigation or an in-house legal team is not captured merely because a lawyer performs it. The service and facts determine scope, not the practitioner’s title.

02

Accountants and advisers

May be captured: Setting up or restructuring companies and trusts, arranging directors or trustees, managing client assets, and providing registered-office or similar trust-and-company services can bring a practice into scope.

Not automatic: Ordinary tax return preparation, bookkeeping or advice is not automatically a designated service. Check whether the engagement crosses into a listed transaction or trust-and-company service.

03

Real estate professionals

May be captured: Brokering the sale, purchase or transfer of real estate for a customer can be captured, including relevant work by real estate agents, buyer’s agents and property developers.

Not automatic: Property management or leasing is not automatically captured by the sale-and-purchase service. Agencies should map each activity rather than assume the whole business is either in or out.

04

Mortgage and financial professionals

May be captured: Existing regulated financial services remain subject to their own AML/CTF settings. A professional practice may also be captured when it separately provides a newly designated service, such as forming a company or managing assets.

Not automatic: Professional status alone is not the trigger. The question is whether the business provides a designated service with the required Australian connection.

The obligations ladder

Five connected duties, not five isolated forms

Enrolment identifies the reporting entity. The program explains its risks and controls. CDD applies those controls to customers, monitoring keeps the assessment current, and reporting and records make the system usable and reviewable.

  1. 01

    Step

    Enrol

    A business that provides a newly regulated designated service must enrol with AUSTRAC. The July 2025 fact sheet says enrolment is due within 28 days of first providing the service, typically by 29 July 2026 for services beginning on commencement.

  2. 02

    Step

    Build an AML/CTF program

    Assess money-laundering, terrorism-financing and proliferation-financing risk, then document proportionate policies, systems and controls. Senior management approves the program, the governing body oversees it and an AML/CTF compliance officer runs day-to-day compliance.

  3. 03

    Step

    Perform initial CDD

    Before providing a designated service in most cases, establish required customer information on reasonable grounds, identify relevant beneficial owners or persons acting for the customer, assess risk and apply the verification measures your program requires.

  4. 04

    Step

    Continue due diligence

    Monitor transactions and behaviour, keep the risk profile current and review or re-verify information when triggers arise. Existing customers have transitional treatment, but specified changes or suspicious-matter reporting can activate CDD requirements.

  5. 05

    Step

    Report and retain

    Submit required suspicious-matter, threshold-transaction and cross-border reports when their tests apply, as well as the annual compliance report. Make accurate program, CDD, transaction and training records and retain most required records for seven years.

From policy to operating model

The program has to work on an ordinary Tuesday.

A compliant document that staff cannot apply is not an effective control. Translate the risk assessment into recognisable decisions, assign ownership and make the evidence path clear before a time-sensitive matter tests it.

Define the intake decision

Give the person opening an engagement a service map, not a legal label. They should know which facts determine whether the proposed work is designated, who the customer is, when the service begins and where to escalate uncertainty. Record the conclusion and revisit it if the scope changes.

Calibrate CDD to risk

Set the information and verification steps for ordinary risk, then specify triggers for enhanced measures. Ownership complexity, an unexpected representative, unusual transaction behaviour or a material change in the relationship should lead staff to the procedure the program requires—not an improvised response.

Join monitoring to the matter

Ongoing CDD needs information from the people doing the work. Define how a new party, changed purpose, inconsistent source of funds or unusual instruction reaches the risk owner. The file should show what changed, who reviewed it and whether the customer profile, controls or reporting decision changed too.

Practise the exception path

Train with realistic scenarios: a customer cannot complete verification, a caller insists on a new account, a beneficial owner is unclear or staff form a suspicion. Make pause, escalation, approval and reporting responsibilities explicit. A failed check is useful risk information; it is not permission to bypass the control.

Timing

1 July is commencement. 29 July is typically enrolment.

AUSTRAC's July 2025 fact sheet distinguishes the two dates. Build the program and operating procedures before commencement; do not treat the later enrolment deadline as a four-week grace period for the substantive obligations.

01

Before 1 July 2026

Identify every service line that may be designated, confirm the customer for each service, complete a risk assessment, establish governance and train the people who will operate the program.

02

1 July 2026

The new Tranche 2 obligations commence for designated services. This is the compliance start date in AUSTRAC’s fact sheet—not 29 July.

03

Typically by 29 July 2026

A newly regulated business that starts providing a designated service on commencement generally reaches the fact sheet’s 28-day enrolment deadline. A different first-service date can change the calculation.

04

Throughout the relationship

Operate ongoing CDD, reporting, record-keeping, training, governance and review. Treat changes in behaviour, authority, contact details or payment instructions as potential risk triggers under the firm’s program.

Enforcement posture: the cited fact sheet sets obligations and timing but does not promise an enforcement grace period. Plan for compliance from commencement and check AUSTRAC's current reform guidance for later regulatory updates.
The evidence-trail thread

A reviewer needs to reconstruct the control and the decision.

Program evidence

Keep the approved risk assessment, policies, roles, training, internal reviews and independent evaluations. The record should show that the written program reflects the services the business actually provides.

Customer and transaction evidence

Preserve CDD information, risk decisions, beneficial-owner and representative checks, transaction records, monitoring outcomes, reporting decisions and the basis for any escalation.

Interaction evidence

For a high-risk call or changed instruction, record who performed the check, the trusted contact point used, the method, time, outcome and what the firm decided before acting.

Each authorised-contact check creates a timestamped, hash-chained record: who requested it, the masked target, method and outcome. Compliance-authorised users can export the record as PDF or CSV. This is evidence of that interaction, not evidence that the firm's entire CDD or AML/CTF program is complete.

Verification evidence, not client files. Vericode stores verification metadata and does not require a firm to upload client matter documents. Customer and verification data — recipient details, messages and verification records — is hosted in Australia. Staff sign-in is handled by our identity provider, WorkOS, in the United States; see the subprocessor information.

Ongoing CDD meets the live channel

Onboarding identity does not authenticate every later instruction.

Ongoing CDD asks whether the customer's risk, behaviour and information remain consistent. A changed payment destination, unexpected representative, new contact point or urgent instruction can be both an operational fraud signal and a reason to apply the firm's risk-based procedures.

Vericode uses possession-based verification. A code goes to the verified phone number held for the real person, not to the contact details supplied in the suspicious request. Delivery uses Australian SMS providers MobileMessage or ClickSend using the ACMA-registered sender ID VERICODE.

The check confirms possession of the trusted phone at that moment. It does not verify an identity document, screen a person or prove the payment details are correct. Staff still need to read the full instruction out and back, follow approvals, consider escalation and preserve the surrounding matter record.

Apply the framework to the workflow

Continue with profession-specific guidance

The legal and conveyancing industry page is not linked because it is not present on the current main branch. The live VOI guide above provides the relevant workflow detail.

Frequently asked questions

Tranche 2, without the shorthand

Make the program operable

Connect the policy to the interaction in front of staff.

Build the AML/CTF program with qualified advice. Then give staff a repeatable way to verify an authorised contact at a high-risk moment and preserve evidence of the check.

General information only. This explainer is not legal, financial, AML/CTF compliance or incident-response advice. Confirm obligations with current AUSTRAC guidance and seek professional advice for your circumstances.