On 1 July 2026, Australia’s AML/CTF regime expanded to cover lawyers, accountants, conveyancers, real estate agents, property developers, trust and company service providers, and dealers in precious metals and stones. Estimates of the number of newly regulated businesses range from around 80,000 to 90,000 — one of the largest expansions of the regime since it began in 2006.
AUSTRAC enrolment opened 31 March 2026 and closed on 29 July 2026. Both dates have now passed.
Ask a suburban conveyancer, a three-partner accounting practice or a regional real estate agency what changed on 1 July, and a great many will not be able to tell you.
The Financial Action Task Force identified the gap in Australia’s regime for well over a decade. Australia was repeatedly noted among comparable jurisdictions for excluding gatekeeper professions entirely.
Australia was more than a decade late, and then rushed the landing
Tranche 2 is not new policy. The Financial Action Task Force has identified the gap in Australia’s regime for well over a decade, and Australia has repeatedly been noted as an outlier among comparable jurisdictions for excluding gatekeeper professions.
The legislation finally passed in late 2024. Commencement was set for 1 July 2026, and enrolment opened 31 March 2026 — a three-month practical preparation window for businesses that had never held a compliance obligation of this kind.
The pattern is familiar. A long delay, then a compressed implementation, then an expectation that tens of thousands of small businesses will independently discover, interpret and implement a framework built for banks. Larger firms had counsel and consultants. A two-person conveyancing practice in a regional town had a website update it never saw.
What actually applies now
Eight core obligations, all live:
- Enrolment with AUSTRAC on the Reporting Entities Roll — outer deadline 29 July 2026, within 28 days of commencing a designated service
- A money laundering and terrorism financing risk assessment specific to your business
- An AML/CTF program, with an AML/CTF compliance officer appointed at management level
- Customer due diligence performed before providing a designated service
- Sanctions and politically exposed person screening
- Suspicious matter reports and threshold transaction reports
- Record keeping for seven years
- Staff training
Two points that are consistently misunderstood. First, obligations commenced on 1 July regardless of whether you enrolled — enrolment is not a precondition for the duties to apply. Second, scope is determined by the designated service, not the profession. A solicitor who never touches client funds may be out of scope; one who assists with planning or executing a transaction involving property, or with equity or debt financing, is in.
Civil penalties reach up to approximately A$31.3 million per contravention for a corporation. Failing to lodge a suspicious matter report, or tipping off a customer that one was lodged, carries serious penalties of its own.
The part nobody is discussing
Here is the consequence that has received almost no attention.
Tens of thousands of small Australian professional services businesses have just been compelled, by law, to begin collecting and retaining for seven years:
- Verified identity documents — passports, driver licences, birth certificates
- Residential addresses and dates of birth
- Beneficial ownership information for corporate and trust clients
- Source of funds and source of wealth evidence — bank statements, tax returns, sale contracts, gift and loan documentation
- Politically exposed person determinations
- Records of suspicious matter assessments, which are themselves highly sensitive
That is a near-perfect identity theft package, per client, held for seven years, in businesses that in most cases have no security function, no monitoring, no incident response plan and no budget line for any of it.
The compliance conversation has been almost entirely about collection: what to verify, how to verify it, what to record. The security conversation — how a four-person practice protects a seven-year archive of identity documents on a shared drive behind a single-factor login — has barely started.
A solicitor who never touches client funds may be out of scope entirely. One who assists with planning or executing a property transaction, or with equity or debt financing, is in.
Firms now hold verified identity documents, beneficial ownership for trusts and corporate clients, and records of suspicious matter assessments — which are themselves among the most sensitive documents a practice will ever hold.
Source-of-funds and source-of-wealth evidence means bank statements, tax returns, sale contracts, and gift and loan documentation — retained for seven years.
That is a materially richer dataset than anything taken in the large Australian breaches of 2022 and 2023, held by organisations several orders of magnitude smaller.
Property is one of the most common vehicles for money laundering in Australia, which is why these professions were the centre of the reform.
It also means high transaction volume: an agency processes far more customer due diligence checks per year than a boutique law firm, and accumulates the archive proportionally faster.
Frequently the smallest businesses in scope, with the least compliance infrastructure and the highest proportion of walk-in customers requiring identification at the point of sale.
Why this becomes a live problem quickly
Attackers follow data concentration. The 2026 record is unambiguous that the target selection logic is where sensitive data pools, particularly where it pools in organisations with limited defensive capability. Tranche 2 has, in a single day, created tens of thousands of new pools.
These firms are already being compromised. ASD’s 2026 advisories repeatedly named Australian small and medium businesses as impacted — by the CMS exploitation campaign, by ClickFix credential harvesting through compromised WordPress sites, and by MSP-managed control panels leading to customer compromise. The professions now in Tranche 2 sit squarely in that population.
The retention period works against you. Seven years is a long time to hold a passport scan. Latitude Financial’s breach drew scrutiny in part because it held records dating back to 2005. A Tranche 2 entity does not have the option of minimising retention — the law requires it. That makes the security of the archive the only variable you control.
Client scrutiny is coming. Corporate clients performing their own third-party risk assessments will begin asking their law firm, accountant and conveyancer how identity data is protected. Firms that cannot answer will lose work to firms that can.
What a Tranche 2 entity should do this quarter
- Confirm your enrolment status. If you provide a designated service and did not enrol by 29 July, address it now. Obligations applied from 1 July either way.
- Locate the data. Where do verified identity documents actually live — practice management system, shared drive, email attachments, a partner’s laptop? Most firms find at least three locations, and email is nearly always one.
- Fix access control before anything else. Multi-factor authentication on everything that reaches client data. This is the single highest-value control and the cheapest.
- Assess your external exposure. What does an attacker see? Exposed remote access, forgotten subdomains, an unpatched website, staff credentials in published infostealer corpora. All of it is visible from outside and none of it requires touching your systems.
- Write down your reasonable steps. APP 11 requires reasonable steps. Reasonable is judged against your circumstances — but an undocumented assessment is very difficult to characterise as reasonable after an incident.
- Ask your suppliers. Your practice management vendor, document platform and IT provider now hold or reach this data. The obligation does not transfer with the outsourcing.
The compliance deadline has passed. The security question has not been asked yet. It will be — by a client, an insurer, a regulator, or an attacker, and the order is not up to you.