AML/CTF Tranche 2 Reporting Entities

You Now Hold Seven Yearsof client identity documents.

Tranche 2 commenced 1 July 2026. Roughly 80,000 Australian businesses must now collect and retain identity and source-of-funds records — most without a security function.

LawyersAccountants, conveyancers, agents, dealers
PassportsLicences, bank statements, tax returns
7 yearsYou must retain every document
$31.3MMaximum penalty per contravention

Passive only — no systems, networks or accounts are accessed at any point.

1 July 2026: The Data Arrived Before the Security Did

Tranche 2 obligations commenced on 1 July 2026. AUSTRAC enrolment opened 31 March and closed 29 July. Roughly 80,000 to 90,000 Australian businesses are now reporting entities.

The compliance conversation has been almost entirely about collection — what to verify, how to verify it, what to record. The security conversation has barely started, and it is the one that determines what happens next.

Because of Tranche 2, tens of thousands of small Australian professional services businesses are now legally required to collect and retain, for seven years:

  • Verified identity documents — passports, driver licences, birth certificates
  • Residential addresses and dates of birth
  • Beneficial ownership information for corporate and trust clients
  • Source of funds and source of wealth evidence — bank statements, tax returns, sale contracts, gift and loan documentation
  • Politically exposed person determinations
  • Records of suspicious matter assessments, which are themselves highly sensitive
Two regulators, one datasetTranche 2 does not impose a cyber security obligation. It does not need to. APP 11 already requires reasonable steps to protect personal information, and much of what Tranche 2 mandates you collect is sensitive information attracting a higher standard. The AML reform created the data concentration. The Privacy Act governs what happens when you lose it. Only one of those regulators wrote to you.

Why This Becomes a Live Problem Quickly

Attackers follow data concentration. The target selection logic through 2026 has been consistent: where sensitive data pools, particularly where it pools in organisations with limited defensive capability. Tranche 2 created tens of thousands of new pools in a single day.

These firms are already being compromised. ASD’s 2026 advisories repeatedly named Australian small and medium businesses — through a large-scale content management system exploitation campaign, through credential harvesting distributed via compromised Australian business websites, and through managed service provider control panels leading to customer compromise. The professions now in Tranche 2 sit squarely in that population.

The retention period works against you. Seven years is a long time to hold a passport scan, and the law removes your option to minimise retention. That makes the security of the archive the only variable you actually control.

What a Tranche 2 Assessment Covers

  • Your firm’s full external footprint — every domain, subdomain and internet-facing service attributable to the practice, including legacy and forgotten sites
  • Exposed remote access — portals, VPN endpoints and practice management access reachable from the public internet
  • Staff credential exposure in published breach and infostealer corpora. In our scan of twenty Australian law firms, this was the most consistently present finding
  • Website and CMS exposure, matched against the vulnerability classes ASD named in its 2026 campaign advisories
  • Email authentication posture — whether your firm’s domain can be spoofed in a trust-account or settlement fraud attempt
  • Third-party surface — your practice management platform, document automation and outsourced IT provider, which hold or reach the same data
  • APP 11 mapping with a documented, dated record of the reasonable steps considered

The report is written to be read in a partners’ meeting, not by a security team you do not have.

Passive Only — No Systems AccessedEvery BlackFlag Advisory assessment uses exclusively passive OSINT techniques against publicly available sources. No systems, networks or accounts are accessed, probed or tested at any point. No authorisation to test is required, and nothing we do can disrupt your operations.

Who This Is For

Law firms

In scope by designated service rather than by profession. A practice assisting with property transactions or with equity or debt financing is captured.

Accounting practices

Now holding source-of-funds and source-of-wealth evidence — bank statements, tax returns, sale contracts — for seven years.

Conveyancers, real estate agencies and property developers

High transaction volume means the identity archive accumulates faster than in any other Tranche 2 profession.

Trust and company service providers, and precious metals dealers

Frequently the smallest businesses in scope, with the least compliance infrastructure and the most walk-in identification.

How the Engagement Runs

Five steps. The only one that requires your time is the first and the last.

1. Scope

We agree the domains, entities or suppliers in scope and the frameworks the findings should be mapped to. Nothing else is required from you — no access, no credentials, no questionnaire to complete.

2. Passive collection

We observe what your organisation exposes using publicly available sources: certificate transparency logs, passive DNS, published vulnerability data, and public breach and infostealer corpora. No systems, networks or accounts are accessed, probed or tested at any point.

3. Analysis and triage

Findings are validated, deduplicated and prioritised against confirmed exploitation status, exploitation probability and asset exposure — not by severity score alone. Every finding carries the evidence that produced it.

4. Regulatory mapping

Each finding is mapped to the obligation it engages, so the report speaks in the language your Board, auditor, insurer or regulator already uses.

5. Delivery and walkthrough

A dual-audience report: a Board section stating the position in plain terms, and a technical section carrying reproducible evidence. We walk you through it, and we are available for the remediation questions that follow.

Frequently Asked Questions

The questions we are asked most often by partners and practice managers in newly regulated firms.

Who is covered by Tranche 2?

Lawyers, accountants, conveyancers, real estate agents and property developers, trust and company service providers, and dealers in precious metals and stones. The obligation attaches when a business provides a designated service with a geographical link to Australia, so the activity rather than the profession determines scope.

Does Tranche 2 create a cyber security obligation?

Not directly, but the data it requires you to collect and retain does. Seven years of identity documents, source-of-funds evidence and transaction records is personal and in places sensitive information, engaging APP 11 reasonable steps obligations and the Notifiable Data Breaches scheme. The AML obligation creates the data concentration; the Privacy Act governs how you protect it.

We are a small practice. Is this relevant?

Particularly so. ASD named Australian small and medium businesses as impacted in multiple 2026 advisories, including a large-scale content management system exploitation campaign and a credential-harvesting campaign using compromised Australian business websites. Small professional services firms now hold a concentration of identity data with, in most cases, no security function.

Will our clients ask about this?

Corporate clients performing their own third-party risk assessments are increasingly asking their law firm, accountant and conveyancer how identity data is protected. Firms that can answer with independent evidence are better placed than firms relying on assurances.

Packages are set out on the assessment packages page. To discuss scope for your practice, book a short call.

New Obligations. New Data.
Same Unassessed Perimeter.

A BlackFlag Advisory assessment shows your firm exactly what an attacker sees — before a client, an insurer or a regulator asks how seven years of client identity documents are being protected.

Request an Assessment →
Assessments
AI Governance CPS 234 Essential Eight Privacy Act & APP 11 Third-Party Risk Tranche 2 Cyber Which one do I need? →
Intelligence
All briefings Romania land registry Tranche 2 commenced ASD advisories, 2026
Practice
GRC Partnerships Pricing Privacy
Start
Threat Scan Enquire Sample report