Tranche 2 Commenced on 1 July.
Roughly 80,000 businesses were not told properly.

You now hold seven years of client identity documents. Who has assessed how you protect them? A passive external assessment is where the honest answers begin: what you expose to the outside world, and who owns that risk.

Assess Your Exposure →

On 1 July 2026, Australia’s AML/CTF regime expanded to cover lawyers, accountants, conveyancers, real estate agents, property developers, trust and company service providers, and dealers in precious metals and stones. Estimates of the number of newly regulated businesses range from around 80,000 to 90,000 — one of the largest expansions of the regime since it began in 2006.

AUSTRAC enrolment opened 31 March 2026 and closed on 29 July 2026. Both dates have now passed.

Ask a suburban conveyancer, a three-partner accounting practice or a regional real estate agency what changed on 1 July, and a great many will not be able to tell you.

Tranche 2 — commenced 1 July 2026
0
businesses newly regulated from 1 July 2026
0
A$ maximum civil penalty per contravention
0
mandatory retention of client identity records
0
practical preparation window from enrolment opening
Sources: Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth); AUSTRAC enrolment guidance; industry estimates range from roughly 80,000 to 90,000 affected businesses.
The point of this articleNot to restate the obligations — the professional bodies have done that. It is to make two arguments almost nobody is making: that the communication of this reform to the affected businesses has been inadequate, and that the cyber consequence of what those businesses now hold has been discussed by essentially no one.
Twelve years late, then three months to comply
For more than a decade
Australia named as an outlier

The Financial Action Task Force identified the gap in Australia’s regime for well over a decade. Australia was repeatedly noted among comparable jurisdictions for excluding gatekeeper professions entirely.

Click any point to read what happened
Sources: AUSTRAC enrolment guidance; Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth); FATF mutual evaluation record.

Australia was more than a decade late, and then rushed the landing

Tranche 2 is not new policy. The Financial Action Task Force has identified the gap in Australia’s regime for well over a decade, and Australia has repeatedly been noted as an outlier among comparable jurisdictions for excluding gatekeeper professions.

The legislation finally passed in late 2024. Commencement was set for 1 July 2026, and enrolment opened 31 March 2026 — a three-month practical preparation window for businesses that had never held a compliance obligation of this kind.

The pattern is familiar. A long delay, then a compressed implementation, then an expectation that tens of thousands of small businesses will independently discover, interpret and implement a framework built for banks. Larger firms had counsel and consultants. A two-person conveyancing practice in a regional town had a website update it never saw.

What actually applies now

Eight core obligations, all live:

  • Enrolment with AUSTRAC on the Reporting Entities Roll — outer deadline 29 July 2026, within 28 days of commencing a designated service
  • A money laundering and terrorism financing risk assessment specific to your business
  • An AML/CTF program, with an AML/CTF compliance officer appointed at management level
  • Customer due diligence performed before providing a designated service
  • Sanctions and politically exposed person screening
  • Suspicious matter reports and threshold transaction reports
  • Record keeping for seven years
  • Staff training

Two points that are consistently misunderstood. First, obligations commenced on 1 July regardless of whether you enrolled — enrolment is not a precondition for the duties to apply. Second, scope is determined by the designated service, not the profession. A solicitor who never touches client funds may be out of scope; one who assists with planning or executing a transaction involving property, or with equity or debt financing, is in.

Civil penalties reach up to approximately A$31.3 million per contravention for a corporation. Failing to lodge a suspicious matter report, or tipping off a customer that one was lodged, carries serious penalties of its own.

The part nobody is discussing

Here is the consequence that has received almost no attention.

Tens of thousands of small Australian professional services businesses have just been compelled, by law, to begin collecting and retaining for seven years:

  • Verified identity documents — passports, driver licences, birth certificates
  • Residential addresses and dates of birth
  • Beneficial ownership information for corporate and trust clients
  • Source of funds and source of wealth evidence — bank statements, tax returns, sale contracts, gift and loan documentation
  • Politically exposed person determinations
  • Records of suspicious matter assessments, which are themselves highly sensitive

That is a near-perfect identity theft package, per client, held for seven years, in businesses that in most cases have no security function, no monitoring, no incident response plan and no budget line for any of it.

The compliance conversation has been almost entirely about collection: what to verify, how to verify it, what to record. The security conversation — how a four-person practice protects a seven-year archive of identity documents on a shared drive behind a single-factor login — has barely started.

The obligation nobody mentionedTranche 2 does not impose a cyber security obligation. It does not need to. APP 11 already requires reasonable steps to protect personal information, and much of what Tranche 2 mandates you collect is sensitive information attracting a higher standard. The AML reform created the data concentration. The Privacy Act governs what happens when you lose it. Those are two different regulators, and only one of them wrote to you.
Who is in scope, and what each now holds
Legal practices
In scope by designated service, not by profession
Item 3receiving or managing property in a transaction
Item 4equity or debt financing assistance

A solicitor who never touches client funds may be out of scope entirely. One who assists with planning or executing a property transaction, or with equity or debt financing, is in.

Firms now hold verified identity documents, beneficial ownership for trusts and corporate clients, and records of suspicious matter assessments — which are themselves among the most sensitive documents a practice will ever hold.

Accounting practices
Source of funds and source of wealth
Tax returnsheld as SoF evidence
Bank stmtsheld as SoF evidence
7 yrsretention

Source-of-funds and source-of-wealth evidence means bank statements, tax returns, sale contracts, and gift and loan documentation — retained for seven years.

That is a materially richer dataset than anything taken in the large Australian breaches of 2022 and 2023, held by organisations several orders of magnitude smaller.

Agents, conveyancers and developers
Why property was the driver
Propertya primary laundering vehicle
ID docspassports and licences
Volumehigh transaction count

Property is one of the most common vehicles for money laundering in Australia, which is why these professions were the centre of the reform.

It also means high transaction volume: an agency processes far more customer due diligence checks per year than a boutique law firm, and accumulates the archive proportionally faster.

Dealers in precious stones, metals and products
Including jewellers
Cashhistorically cash-intensive
Smalltypical business size

Frequently the smallest businesses in scope, with the least compliance infrastructure and the highest proportion of walk-in customers requiring identification at the point of sale.

Select a profession
Sources: AUSTRAC designated services guidance; Law Society of NSW guidance on legal designated services.

Why this becomes a live problem quickly

Attackers follow data concentration. The 2026 record is unambiguous that the target selection logic is where sensitive data pools, particularly where it pools in organisations with limited defensive capability. Tranche 2 has, in a single day, created tens of thousands of new pools.

These firms are already being compromised. ASD’s 2026 advisories repeatedly named Australian small and medium businesses as impacted — by the CMS exploitation campaign, by ClickFix credential harvesting through compromised WordPress sites, and by MSP-managed control panels leading to customer compromise. The professions now in Tranche 2 sit squarely in that population.

The retention period works against you. Seven years is a long time to hold a passport scan. Latitude Financial’s breach drew scrutiny in part because it held records dating back to 2005. A Tranche 2 entity does not have the option of minimising retention — the law requires it. That makes the security of the archive the only variable you control.

Client scrutiny is coming. Corporate clients performing their own third-party risk assessments will begin asking their law firm, accountant and conveyancer how identity data is protected. Firms that cannot answer will lose work to firms that can.

What a Tranche 2 entity should do this quarter

  • Confirm your enrolment status. If you provide a designated service and did not enrol by 29 July, address it now. Obligations applied from 1 July either way.
  • Locate the data. Where do verified identity documents actually live — practice management system, shared drive, email attachments, a partner’s laptop? Most firms find at least three locations, and email is nearly always one.
  • Fix access control before anything else. Multi-factor authentication on everything that reaches client data. This is the single highest-value control and the cheapest.
  • Assess your external exposure. What does an attacker see? Exposed remote access, forgotten subdomains, an unpatched website, staff credentials in published infostealer corpora. All of it is visible from outside and none of it requires touching your systems.
  • Write down your reasonable steps. APP 11 requires reasonable steps. Reasonable is judged against your circumstances — but an undocumented assessment is very difficult to characterise as reasonable after an incident.
  • Ask your suppliers. Your practice management vendor, document platform and IT provider now hold or reach this data. The obligation does not transfer with the outsourcing.

The compliance deadline has passed. The security question has not been asked yet. It will be — by a client, an insurer, a regulator, or an attacker, and the order is not up to you.

Are you exposed? Eight questions.
Tick every statement that is true of your firm today.
We provide at least one designated service with a geographical link to Australia.
We enrolled with AUSTRAC on or before 29 July 2026.
We have appointed an AML/CTF compliance officer at management level.
We know every location where verified identity documents are stored — including email.
Multi-factor authentication is enforced on everything that reaches client identity data.
We have documented our “reasonable steps” under APP 11 in writing.
We have asked our practice management and IT providers how they protect this data.
We have assessed what our firm exposes externally — remote access, subdomains, staff credentials in breach corpora.
Tick every statement that is true of your organisation
Passive only — no systems accessedBlackFlag Advisory assesses what a Tranche 2 reporting entity exposes to the outside world using exclusively passive OSINT techniques and publicly available data. No systems, networks or accounts are accessed, probed or tested. Findings are mapped to the Privacy Act and the Australian Privacy Principles, and delivered in a form suitable for a partners’ meeting.
SourcesAnti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth); AUSTRAC enrolment guidance and Reporting Entities Roll; Law Society of NSW guidance on designated services and legal practice; professional and legal commentary on Tranche 2 commencement including Norton Rose Fulbright, Kennedys and Grant Thornton; Financial Action Task Force standards; OAIC Australian Privacy Principles Guidelines. This article is general information and is not legal advice. Analysis by BlackFlag Advisory.

New Obligations. New Data.
Same Unassessed Perimeter.

A BlackFlag Advisory passive assessment shows a Tranche 2 reporting entity exactly what an attacker sees — before AUSTRAC, the OAIC or a client asks how seven years of identity documents are being protected.

Request an Assessment →
Passive Only — No Systems Accessed

All BlackFlag Advisory assessments use exclusively passive OSINT techniques and publicly available data sources. No systems, networks, or accounts are accessed, probed, or tested at any time. Board-ready output delivered within three to seven business days.