Tranche 2 Is Live.
So Is Your New Data Exposure.

Newly a reporting entity — but are you newly a target? Tranche 2 makes your firm a custodian of sensitive client data. A passive external assessment shows what that now exposes — before it becomes an incident.

Assess Your Exposure →

On 1 July 2026, roughly eighty thousand Australian businesses that had never answered to a financial regulator were pulled into one. The coverage has focused on what that means for money-laundering compliance. Almost none of it has costed the cyber consequence — and for law and accounting firms, that consequence is the part that gets you breached.

What Actually Changed on 1 July 2026

The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 — the reform known as “Tranche 2” — extends AUSTRAC’s regime to a set of “gatekeeper” professions for the first time since the framework began in 2006. From 1 July 2026, lawyers, conveyancers, accountants, real estate professionals, trust and company service providers, and dealers in precious metals and stones become reporting entities when they provide a designated service with a link to Australia.

The obligation attaches to the activity, not the job title. Under guidance from the Law Society of NSW, a firm is captured when it provides one or more designated services — such as receiving, holding or managing client property in a transaction, or assisting with equity or debt financing — in the course of carrying on a business. AUSTRAC opened enrolment on 31 March 2026, and newly regulated firms providing a designated service from 1 July must enrol by 29 July 2026. The new duties are familiar to any bank and entirely new to most practices: enrol with AUSTRAC, stand up an AML/CTF programme, run customer due diligence before you act, screen against sanctions and politically exposed persons, file suspicious matter reports, and keep the records for seven years.

The Tranche 2 clock From reporting entity to data custodian — the dates that decide your exposure 31 MAR 2026AUSTRAC enrolment opens 1 JUL 2026Obligations commence 29 JUL 2026Enrolment deadline THEN — SEVEN YEARS OF KYC & SOURCE-OF-FUNDS RECORDS TO HOLD AND PROTECT

The Part No One Is Costing In

Read that last duty again: seven-year record-keeping, on customers you must now identify to a standard you never had to before. To meet Tranche 2, your firm now collects and retains identity documents, proof of address, beneficial-ownership detail and source-of-funds evidence — a concentrated store of exactly the personal information attackers want and regulators scrutinise. You have, overnight, become a data custodian on a scale you were not built for.

Two consequences follow that most firms haven’t connected. First, if your practice is already covered by the Privacy Act 1988 (Cth) — and most established firms are — Australian Privacy Principle 11 requires reasonable steps to protect that information, and “reasonable” is now read against a far larger, more sensitive holding. Second, the downside is no longer only regulatory: since 10 June 2025, a statutory tort for serious invasions of privacy lets individuals sue directly where their information is exposed. A KYC file lost in a breach is precisely the harm that tort was written for.

The exposure, in one lineTranche 2 didn’t just make your firm a reporting entity — it made you a custodian of breach-grade data, under a security obligation you may never have measured.

What Your Public Presence Already Reveals

Here is the uncomfortable part. Before a single client file is stolen, an attacker can already see how ready you are to hold it — using nothing but public information.

The same passive view a threat actor takes of a newly regulated firm routinely surfaces staff credentials already exposed in third-party breach datasets; a client portal or document-exchange platform running a version with known, actively exploited vulnerabilities; email that can be spoofed because SPF, DKIM and DMARC were never finished; and forgotten subdomains and legacy systems no one has owned for years. None of it requires touching your systems. It is the outside view — the one a regulator, an insurer at renewal, or an attacker choosing a target already has. A firm that has just become custodian of seven years of KYC data cannot afford to be discoverable as the soft option.

Who Is Most Exposed Right Now

The firms most at risk are the ones least resourced for it: small and mid-sized practices with no security function, now holding regulated data for the first time, often relying on an outsourced IT provider whose remit was never governance, privacy or breach readiness. They have the obligation without the capability — and the enrolment deadline arrived faster than the security uplift. It is not a hypothetical exposure, either: legal, accounting and management services already sit among the most-breached sectors in the country, with 81 notifications to the OAIC in 2025.

What to Do Before the Exposure Becomes an Incident

Map what you now hold. The KYC data, where it lives, who can reach it, how long it sits and under what control. You cannot protect a store you haven’t inventoried.

Baseline your external exposure. See your firm the way an attacker does, so credential leaks, exposed interfaces and spoofable email are found and closed before they are used, not after.

Set your obligations against reality. Line your APP 11 posture and your new AML data-handling up against the controls you actually have, and fix the gaps that carry real regulatory, insurer and litigation weight.

Tranche 2 made your firm a reporting entity. It also made you a target. The firms that treat the cyber exposure as seriously as the AML enrolment are the ones that won’t be explaining a breach of client identity data to a board, an insurer and a regulator at the same time.

Sources

Key facts are drawn from primary and authoritative sources. Confirm current dates and scope against AUSTRAC directly before relying on them.

Frequently asked questions

When does Tranche 2 start for lawyers and accountants?

AML/CTF obligations commence on 1 July 2026 for newly regulated Tranche 2 entities. AUSTRAC enrolment opened on 31 March 2026, and affected firms providing a designated service from 1 July must enrol with AUSTRAC by 29 July 2026.

Which firms are covered by Tranche 2?

Lawyers, conveyancers, accountants, real estate professionals, trust and company service providers, and dealers in precious metals and stones — when they provide a designated service with a link to Australia in the course of carrying on a business. The activity, not the job title, decides whether a firm is in scope.

What does Tranche 2 mean for my firm’s cyber security?

To meet the obligations, firms now collect and retain sensitive customer identity and source-of-funds information and keep it for seven years. That enlarges data-security obligations under Australian Privacy Principle 11 and makes the firm a more attractive target. A breach of that data can also expose the firm to the statutory tort for serious invasions of privacy, in force since June 2025.

How do we check our cyber exposure?

A passive external (OSINT) assessment shows what an attacker or regulator can already see — leaked credentials, exposed portals, weak email authentication and forgotten assets — without touching your systems, so the gaps can be closed before they are exploited.

See Your Exposure
Before a Regulator Does.

Tranche 2 made your firm a custodian of sensitive client data. A BlackFlag passive OSINT assessment shows what that now exposes — from the outside, publicly available sources only, mapped to the obligation it touches and the owner accountable for it. Board-ready within days.

Passive Only — No Systems Accessed · Confidential by Design
Request an Assessment
Please complete all fields with a valid email and phone.
✓ Thank you — we will be in touch within 24 hours.

Confidential — no obligation. We respond within 24 hours.