AML/CTF Tranche 2: A Legal Roadmap for Newly Regulated Firms (Copy)

Pexels wei chong teng

AML/CTF Tranche 2 is the extension of Australia’s anti-money laundering and counter-terrorism financing regime to professional services. From 1 July 2026, law firms and other professions will become AUSTRAC reporting entities when they provide a designated service. Becoming a reporting entity is not only a security and certification exercise. It brings a full legal architecture that no certification can build for you.

Key takeaway. Becoming an AML/CTF reporting entity brings scoping, enrolment, a risk assessment, customer due diligence, privilege handling, and Privacy Act compliance. This article sets out the architecture and the order in which to build it.

 

Cybercert’s update makes the case for securing the data: cybercert.substack.com/p/the-amlctf-reforms-were-about-money. This companion covers the legal work that sits around it: whether you are captured at all, what AUSTRAC expects you to build, the privilege questions unique to legal practice, and the Privacy Act obligations no certification can satisfy.

The Cybercert article explains what changed on 1 July and why securing client data is the move you can make immediately. This add-on starts with the obligations that cannot be certified into existence, the judgment calls the regime demands, and the sequence in which to make them.

It is written for the same audience: law firms, conveyancers, accountants, real estate professionals, dealers in precious metals and stones, and trust and company service providers. It assumes the first article’s central point, that the security baseline is the fast half. This is the rest.

Are you captured, and where?

The regime does not capture businesses by label. It captures them by activity. You become a reporting entity only where you provide a designated service, the higher-risk activities the legislation lists, such as receiving or holding client money or property in the course of a transaction, buying or selling real estate, or establishing companies and trusts. A litigation practice that never touches a settlement may be outside the regime entirely. A suburban firm that does one conveyance a month is inside it for that work.

That makes scoping the first genuine legal task, and it is worth doing rigorously rather than defensively. Map your service lines against the designated services, matter type by matter type, and record the reasoning, including for the services you conclude are not captured. If AUSTRAC ever asks why you did not enrol earlier, or did not apply customer due diligence to a class of work, a contemporaneous documented analysis is worth far more than a conclusion reached in hindsight.

Edge cases, such as mixed retainers, occasional trust work, and informal handling of deposits, are precisely where a legal as a service arrangement earns its fee.

What must you build, and in what order?

For services that are captured, the obligations arrive in a logical order, and building them in that order saves rework.

Enrolment comes first. An organisation must enrol with AUSTRAC within 28 days of first providing a designated service. Alongside it, appoint an AML/CTF compliance officer at the management level. This is someone with enough seniority to change how the organisation takes on work, because that is what the role requires. For smaller practices, a fractional general counsel can carry this responsibility without a full-time hire.

The money laundering and terrorism financing risk assessment is the document from which everything else hangs. It is not a template exercise. It must reflect your actual clients, services, delivery channels and geographies, and it determines how demanding your program and due diligence need to be. A two-partner conveyancing practice and a firm structuring cross-border trusts should not produce similar documents.

The written AML/CTF program then operationalises the risk assessment. It sets out the policies, procedures and controls, approved at principal or board level. Customer due diligence includes: identifying clients and beneficial owners before providing a designated service, with enhanced measures for higher-risk situations and ongoing monitoring after onboarding.

Then come the continuing obligations: suspicious matter reports within short statutory timeframes (days, and in some cases 24 hours), records kept for seven years, and staff trained well enough that the program describes what the firm actually does.

The consistent theme in AUSTRAC’s guidance is proportionality. The regulator expects the architecture to fit the firm, not a bank’s compliance manual photocopied onto a five-person practice. For a small practice, sensible legal support for small business means building only what the assessed risk requires, and no more.

How do privilege and tipping off change the picture?

Two features of the regime land differently for legal practices than for anyone else.

The first is legal professional privilege. The amending legislation includes express protection. The regime does not require a lawyer to disclose communications that are privileged, and there is a mechanism for asserting privilege where information is sought, including in AUSTRAC’s online forms. The protection only works if the firm can operate it. That means being able to identify, at the point at which a reporting obligation or an AUSTRAC notice arises, which parts of a file are privileged and which are not, and having a partner-level process for making and documenting the claim. Privilege asserted sloppily, or over-claimed, is at risk.

The second is the tipping-off offence. The reforms recast it to focus on disclosures that could reasonably prejudice an investigation, which is a welcome narrowing, but it still sits awkwardly against a lawyer’s instinct to be frank with a client. If your firm lodges a suspicious matter report, what you may say to the client about it, and when, is a question that should be answered by procedure in advance, not improvised in the moment.

Why is the Privacy Act half bigger than APP 11?

Cybercert explains how becoming a reporting entity removes the small business exemption and puts firms inside the Privacy Act, and why a security baseline addresses APP 11. From a legal standpoint, the exposure is wider than security controls.

The Australian Privacy Principles run from collection through to destruction. Firms newly covered by the Act need a compliant privacy policy and collection notices that describe what identity information is gathered and why. These are custom legal documents built around your actual client intake, not templates pulled off a shelf. The identity data collected for customer due diligence is collected for that purpose, not as a general asset of the practice.

Retention is where the two regimes have to be read together. The seven-year record-keeping obligation covers what the AML/CTF regime requires you to keep, and the OAIC’s guidance is blunt that full copies of identity documents are generally not among it. Keep the record of verification. Do not warehouse passports.

And the Notifiable Data Breaches scheme is not just a duty to notify but a duty to assess, quickly, whether a breach is likely to result in serious harm. An organisation with no data breach response plan will make that assessment badly and late. Preparing one is a half-day of work now, against a very bad week later. This is the practical point where cyber security for lawyers meets privacy law: the controls protect the data, and the legal framework decides what must happen when they fail.

How will AUSTRAC enforce the new regime?

AUSTRAC has signalled a pragmatic approach to the new population, with an early emphasis on education and support rather than immediate enforcement. That patience is real, but it is conditional. It assumes an organisation has enrolled, has started its risk assessment, and can show genuine effort.

The penalties in the Act are civil and substantial; they can attach to individuals as well as firms, and for legal practitioners, there is a second layer: conduct that falls short of the regime is unlikely to remain solely AUSTRAC’s concern once professional regulators take an interest.

The realistic risk for most small law firms in the first year is not a headline penalty. It is failing to demonstrate, when asked, that the firm took the obligations seriously from the start.

The order of operations

Sequenced sensibly, the work is demanding but manageable:

  1.   Scope your services and document the analysis.
  2.   Enrol, and appoint your compliance officer.
  3.   Build the risk assessment before the program, and the program before the procedures.
  4.   Stand up customer due diligence for new matters, then work back through existing clients as the rules require.
  5.   In parallel, because it does not depend on any of the above, map the personal information you hold, cut what you should not be keeping, write the breach response plan, and take the security baseline Cybercert describes.

The certification is the first half. This is the rest. Neither substitutes for the other, and a firm that does both will be in better shape than most of its peers by Christmas.

Frequently asked questions

What is AML/CTF Tranche 2?

AML/CTF Tranche 2 is the extension of Australia’s anti-money laundering and counter-terrorism financing regime to professional services. From 1 July 2026, law firms, conveyancers, accountants, real estate professionals, dealers in precious metals and stones, and trust and company service providers become reporting entities when they provide a designated service.

When must a law firm enrol with AUSTRAC?

A firm must enrol with AUSTRAC within 28 days of first providing a designated service. Enrolment opened on 31 March 2026, and for most new Tranche 2 services the practical deadline falls in late July 2026. Enrolment is free and completed through AUSTRAC Online.

Does the AML/CTF regime override legal professional privilege?

No. The amending legislation preserves legal professional privilege. A firm is not required to disclose privileged communications, and there is a mechanism for asserting privilege when information is sought. The protection only works if the firm can identify privileged material and document the claim at the partner level.

What counts as a designated service for a law firm?

A designated service is one of the higher-risk activities the legislation lists, such as receiving or holding client money or property in a transaction, buying or selling real estate, or establishing companies and trusts. A firm becomes a reporting entity only for the work that is a designated service, not for everything it does.

 

Disclaimer. This article is general information only and is not legal advice. Whether and how the AML/CTF regime and the Privacy Act apply to your firm depends on the specific services you provide and your circumstances, and the obligations described here are summarised, not exhaustive. Obtain advice specific to your practice before acting.

< Previous PostI am a button
Share :

Crunchy

Kirsten Dilena is the founder and principal lawyer at DLC Legal, a boutique commercial and regulatory practice advising on governance, compliance, cybersecurity and data privacy law, and government procurement. With 20+ years of legal experience across government, defence, and commercial and emerging technology sectors, Kirsten helps regulated businesses build compliance architecture that is proportionate, defensible, and workable.