TrustEasy® is a registered trademark of Myna Australia Pty Ltd. Myna Australia Pty ltd complies with ISO/IEC 27001:2022

AML/CTF Tranche 2 Started July 2026: What Every Australian Accounting Firm Must Do Now

  • By TrustEasy
  • September 4, 2026
  • 2773 Views
AML/CTF Tranche 2 Started July 2026: What Every Australian Accounting Firm Must Do Now

Introduction

The AML/CTF landscape for Australian accounting firms has changed significantly.

From 1 July 2026, certain accounting services became subject to Australia’s AML/CTF regime. The new requirements form part of Australia’s broader Tranche 2 reforms covering sectors including accounting, legal, conveyancing and real estate.

But there is an important point:

Not every service provided by every accountant is automatically a designated service.

Whether an accounting firm has AML/CTF obligations depends on whether it provides a relevant designated service.

1. Identify your designated services

The first step is to determine which services your firm provides.

AUSTRAC’s professional designated services guidance covers services such as:

  • Assisting with certain real estate transactions
  • Assisting with transactions involving bodies corporate or legal arrangements
  • Receiving, holding or controlling property in certain transaction contexts
  • Certain financing transactions
  • Creating or restructuring certain legal arrangements
  • Acting in certain corporate or trust positions
  • Providing certain registered office or principal place of business services

The exact application depends on the services and circumstances.

2. Enrol with AUSTRAC

Newly regulated businesses were able to enrol from 31 March 2026, with the applicable enrolment timeframe applying to businesses providing designated services.

3. Develop your AML/CTF program

Your firm needs an AML/CTF program appropriate to its ML/TF/PF risks.

AUSTRAC has created an Accountant Program Starter Kit to help eligible small accountancy firms develop their program.

Your program should cover areas including:

  • Risk assessment
  • Governance
  • Customer due diligence
  • Enhanced CDD
  • Ongoing monitoring
  • Reporting
  • Record keeping
  • Personnel training

4. Implement customer due diligence

Initial CDD involves identifying the customer and relevant other persons and assessing the customer’s ML/TF risk.

AUSTRAC states that firms should collect and verify KYC information appropriate to the customer’s risk.

5. Manage suspicious activity

Your team needs a process for identifying and escalating suspicious matters.

From 1 July 2026, the updated SMR reporting requirements also apply to newly regulated entities.

SMRs generally need to be submitted within:

  • 24 hours where the suspicion relates to terrorism financing
  • 3 business days for other suspicions
  • 5 business days where applicable LPP rules apply

AUSTRAC confirms these current deadlines.

6. Keep your records

AML/CTF compliance needs to be demonstrable.

AUSTRAC generally requires relevant AML/CTF records to be retained for seven years, subject to the specific retention requirements.

7. Train your team

The person responsible for AML/CTF compliance cannot be expected to manage everything alone.

Personnel should understand the firm’s policies and procedures and their responsibilities.

8. Review your systems

A policy sitting in a folder is not enough.

Your firm needs processes and systems to support:

  • Client onboarding
  • KYC
  • Risk assessment
  • Screening
  • Escalations
  • Reporting
  • Record keeping
  • Staff training

How TrustEasy can help

TrustEasy is designed specifically around AML/CTF workflows for Australian accounting and tax practices.

Its AML/CTF functionality includes risk assessments, AML/CTF policy and program support, CDD/KYC, screening, training and AUSTRAC reporting tools.

Conclusion

For accounting firms, AML/CTF compliance is now an operational responsibility rather than simply a policy exercise.

The best starting point is to understand which designated services apply to your firm, assess your risks and make sure your people, policies and systems work together.

This article is general information and not legal advice.