On 1 July 2026, roughly eighty thousand Australian businesses that had never answered to a financial regulator were pulled into one. The coverage has focused on what that means for money-laundering compliance. Almost none of it has costed the cyber consequence — and for law and accounting firms, that consequence is the part that gets you breached.
What Actually Changed on 1 July 2026
The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 — the reform known as “Tranche 2” — extends AUSTRAC’s regime to a set of “gatekeeper” professions for the first time since the framework began in 2006. From 1 July 2026, lawyers, conveyancers, accountants, real estate professionals, trust and company service providers, and dealers in precious metals and stones become reporting entities when they provide a designated service with a link to Australia.
The obligation attaches to the activity, not the job title. Under guidance from the Law Society of NSW, a firm is captured when it provides one or more designated services — such as receiving, holding or managing client property in a transaction, or assisting with equity or debt financing — in the course of carrying on a business. AUSTRAC opened enrolment on 31 March 2026, and newly regulated firms providing a designated service from 1 July must enrol by 29 July 2026. The new duties are familiar to any bank and entirely new to most practices: enrol with AUSTRAC, stand up an AML/CTF programme, run customer due diligence before you act, screen against sanctions and politically exposed persons, file suspicious matter reports, and keep the records for seven years.
The Part No One Is Costing In
Read that last duty again: seven-year record-keeping, on customers you must now identify to a standard you never had to before. To meet Tranche 2, your firm now collects and retains identity documents, proof of address, beneficial-ownership detail and source-of-funds evidence — a concentrated store of exactly the personal information attackers want and regulators scrutinise. You have, overnight, become a data custodian on a scale you were not built for.
Two consequences follow that most firms haven’t connected. First, if your practice is already covered by the Privacy Act 1988 (Cth) — and most established firms are — Australian Privacy Principle 11 requires reasonable steps to protect that information, and “reasonable” is now read against a far larger, more sensitive holding. Second, the downside is no longer only regulatory: since 10 June 2025, a statutory tort for serious invasions of privacy lets individuals sue directly where their information is exposed. A KYC file lost in a breach is precisely the harm that tort was written for.
What Your Public Presence Already Reveals
Here is the uncomfortable part. Before a single client file is stolen, an attacker can already see how ready you are to hold it — using nothing but public information.
The same passive view a threat actor takes of a newly regulated firm routinely surfaces staff credentials already exposed in third-party breach datasets; a client portal or document-exchange platform running a version with known, actively exploited vulnerabilities; email that can be spoofed because SPF, DKIM and DMARC were never finished; and forgotten subdomains and legacy systems no one has owned for years. None of it requires touching your systems. It is the outside view — the one a regulator, an insurer at renewal, or an attacker choosing a target already has. A firm that has just become custodian of seven years of KYC data cannot afford to be discoverable as the soft option.
Who Is Most Exposed Right Now
The firms most at risk are the ones least resourced for it: small and mid-sized practices with no security function, now holding regulated data for the first time, often relying on an outsourced IT provider whose remit was never governance, privacy or breach readiness. They have the obligation without the capability — and the enrolment deadline arrived faster than the security uplift. It is not a hypothetical exposure, either: legal, accounting and management services already sit among the most-breached sectors in the country, with 81 notifications to the OAIC in 2025.
What to Do Before the Exposure Becomes an Incident
Map what you now hold. The KYC data, where it lives, who can reach it, how long it sits and under what control. You cannot protect a store you haven’t inventoried.
Baseline your external exposure. See your firm the way an attacker does, so credential leaks, exposed interfaces and spoofable email are found and closed before they are used, not after.
Set your obligations against reality. Line your APP 11 posture and your new AML data-handling up against the controls you actually have, and fix the gaps that carry real regulatory, insurer and litigation weight.
Tranche 2 made your firm a reporting entity. It also made you a target. The firms that treat the cyber exposure as seriously as the AML enrolment are the ones that won’t be explaining a breach of client identity data to a board, an insurer and a regulator at the same time.
Sources
Key facts are drawn from primary and authoritative sources. Confirm current dates and scope against AUSTRAC directly before relying on them.
- Department of Home Affairs — Overview of the AML/CTF Amendment Act
- Law Society of NSW — When legal services trigger Tranche 2 AML/CTF obligations
- OAIC — Data breach notifications increase to all-time high in 2025 (NDB statistics)
- OAIC — About the Notifiable Data Breaches scheme
Frequently asked questions
When does Tranche 2 start for lawyers and accountants?
AML/CTF obligations commence on 1 July 2026 for newly regulated Tranche 2 entities. AUSTRAC enrolment opened on 31 March 2026, and affected firms providing a designated service from 1 July must enrol with AUSTRAC by 29 July 2026.
Which firms are covered by Tranche 2?
Lawyers, conveyancers, accountants, real estate professionals, trust and company service providers, and dealers in precious metals and stones — when they provide a designated service with a link to Australia in the course of carrying on a business. The activity, not the job title, decides whether a firm is in scope.
What does Tranche 2 mean for my firm’s cyber security?
To meet the obligations, firms now collect and retain sensitive customer identity and source-of-funds information and keep it for seven years. That enlarges data-security obligations under Australian Privacy Principle 11 and makes the firm a more attractive target. A breach of that data can also expose the firm to the statutory tort for serious invasions of privacy, in force since June 2025.
How do we check our cyber exposure?
A passive external (OSINT) assessment shows what an attacker or regulator can already see — leaked credentials, exposed portals, weak email authentication and forgotten assets — without touching your systems, so the gaps can be closed before they are exploited.