Please Wait

Australia Expands AML Compliance Through Tranche 2 Reforms

Featured

Australia's anti-money laundering framework primarily targeted financial institutions for many years. This leaves numerous professional service providers outside its regulatory scope. Professionals such as lawyers, accountants, real estate agents, and trust and company service providers frequently manage high-value transactions and complex corporate structures. Still, they are not held to the same anti-money laundering standards as banks.

Therefore, Australia's Tranche 2 reforms address this long-standing weakness by extending AML and CFT obligations to designated non-financial businesses and professions (DNFBPs). The reforms require newly regulated businesses to implement customer due diligence, enterprise-wide risk assessments, ongoing monitoring, and suspicious matter reporting as part of Australia's expanded AML/CTF framework.

These updates represent one of the most significant expansions of Australia's AML regime since the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, bringing the country closer to international standards established by the FATF.

Australia Tranche 2 Reforms at a Glance: What Is Changing?

Australia's Tranche 2 reforms expand the country's AML/CTF regime by extending regulatory obligations to designated non-financial businesses and professions that were previously outside AUSTRAC's oversight. Rather than introducing a new AML framework, the reforms apply existing AML/CTF requirements to sectors that regularly facilitate higher-risk financial activities.

The key changes include:

  • New sectors become reporting entities: Lawyers, accountants, real estate professionals, trust and company service providers (TCSPs), and dealers in precious metals and precious stones are brought within the AML/CTF regime when they provide designated services.
  • Risk-based AML/CTF programs become mandatory: Newly regulated businesses must identify, assess, and manage money laundering, terrorism financing, and proliferation financing risks through documented AML/CTF programs.
  • Customer due diligence becomes compulsory: Businesses must verify customer identities, identify and verify beneficial owners where required, understand the purpose of business relationships, and apply enhanced due diligence for higher-risk customers.
  • Ongoing monitoring and reporting obligations apply: Reporting entities must monitor customer relationships, maintain compliance records, and submit suspicious matter reports to AUSTRAC where required.
  • AUSTRAC's supervisory role expands: Thousands of newly regulated businesses will be subject to registration, regulatory oversight, compliance reviews, and enforcement action where AML/CTF obligations are not met.

Importantly, the reforms regulate designated services rather than entire professions. AML/CTF obligations apply only when businesses provide specific higher-risk services defined under the legislation, ensuring that regulatory requirements remain proportionate to the financial crime risks associated with those activities.

Australia Tranche 2 Reforms at a Glance: What Is Changing?

Why Australia Introduced Tranche 2 Reforms?

Australia's decision to introduce the Australia Tranche 2 was driven by years of international scrutiny and growing evidence that financial crime risks extended well beyond the banking sector. Although financial institutions have historically been subject to anti-money laundering and counter-terrorism financing obligations, many professional service providers have remained outside the regulatory framework. This is noteworthy considering these providers frequently engage in high-value transactions, corporate structuring, and trust administration. This regulatory gap created opportunities for criminals to disguise illicit wealth through legitimate businesses.

Why Australia Introduced Tranche 2 Reforms?

FATF and APG Identified Longstanding Deficiencies

The Financial Action Task Force has consistently found that Australia's Anti-Money Laundering and Counter-Terrorism Financing regime does not fully meet the requirements of Recommendation 22. This recommendation requires designated non-financial businesses and professions to adopt customer due diligence measures, maintain proper recordkeeping, and report any suspicious transactions.

In its Mutual Evaluation, the FATF identified both technical compliance shortcomings and concerns about effectiveness. It noted that lawyers, accountants, real estate professionals, and trust and company service providers were not required to follow comprehensive AML obligations when offering higher-risk services.

The Asia/Pacific Group on Money Laundering (APG) bolstered these findings through regional assessments, highlighting that Australia's limited oversight undermines the overall effectiveness of its financial crime controls.

FATF and APG Identified Longstanding Deficiencies

How Professional Services Became Financial Crime Enablers

Criminal networks rarely move illicit funds directly into the financial system. More often, they depend on professional intermediaries to create legal distance from criminal proceeds. Real estate deals have often been leveraged to transform illegal cash into valuable assets. Meanwhile, legal professionals and accountants have played a key role in setting up companies, trusts, and financial arrangements that seem commercially legitimate.

The use of trust structures, corporate entities, shell companies, and nominee directors or shareholders has complicated investigations by obscuring the identities of those who truly own or control the assets. These layered ownership arrangements frequently span several jurisdictions, making beneficial ownership identification significantly more difficult for investigators and reporting entities.

A significant instance arose during the Panama Papers investigation, revealing how offshore service providers established intricate corporate structures and shell companies for clients worldwide. The investigation found that although many arrangements had valid intentions, they were also misused to obscure beneficial ownership. This included the use of anonymous companies, nominee setups, and trusts, which facilitated tax evasion and helped launder illicit proceeds. The case demonstrated that professional services can unintentionally become essential to financial crime when transparency and customer due diligence requirements are absent.

Australia's Tranche 2 reforms effectively tackle these risks by broadening AML obligations to include sectors that are vital in establishing, managing, and transferring assets on behalf of clients. This expanded regulatory framework enhances transparency into beneficial ownership and reduces the risk that criminals will use professional services as conduits for money laundering.

Which Businesses Are Covered by Australia's Tranche 2 Reforms?

The Tranche 2 reforms in Australia broaden AML/CTF requirements from financial institutions to non-financial businesses and professions. The sectors are often used to register companies, sell or buy real estate, and manage assets. They are therefore appealing for purposes of hiding beneficial ownership and laundering of illegal funds. These reforms enhance the supervision of these higher-risk activities.

Lawyers

The legal profession is often involved with trusts, company registration, holding of client funds, and property transactions, which can be manipulated to hide illegal assets.

Law firms that provide designated services are required to perform customer due diligence, verify beneficial ownership, keep records, and report suspicious activity to AUSTRAC where required. The principle of legal professional privilege remains applicable so long as it is so protected by law.

Accountants

Accounting firms help companies set up, structure, and arrange financing transactions that could be used to conceal ownership.

Accounting services would involve customer due diligence, risk assessment, AML/CTF programs, and continuous documentation for designated services.

Real Estate Professionals

Property transactions enable large sums of money to be converted into legitimate assets, creating money laundering risks.

Reporting entities are required to verify customers, identify beneficial owners, evaluate transaction risks, maintain records, and report any suspicious activity.

Trust and Company Service Providers

The TCSPs create and manage companies and trusts that can be designed to hide the beneficial interests of their owners.

Businesses are required to verify customers and beneficial owners, track business relationships, keep records, and report issues to AUSTRAC.

Dealers in Precious Metals and Precious Stones

Money laundering or sanctions evasion can be carried out through high-value, portable assets such as precious metals and gemstones.

The organizations are required to conduct customer due diligence, monitor specific transactions, keep records, screen for sanctions-related risks if applicable, and report suspicious activities.

Newly regulated sectors

AML Compliance Requirements Under Australia's Tranche 2 Reforms

Compliance extends well beyond customer identification. Reporting entities must establish governance, assess financial crime risks, perform customer due diligence, monitor business relationships, and maintain effective internal controls throughout the customer lifecycle.

Conducting an Enterprise Risk Assessment

A comprehensive enterprise-wide risk assessment provides the basis for an effective AML program. This helps organizations identify vulnerabilities before deciding on controls.

Four important areas should be assessed:

  • Money laundering, terrorism financing, and proliferation financing risks are associated with the business and its services.
  • Customer risks, including ownership complexity, customer profiles, and business relationships.
  • Geographic risks, especially in customer and transaction areas involving higher-risk jurisdictions.
  • Product and service risks, focusing on activities that could facilitate financial crime.
  • Delivery channel risks, such as onboarding that is not done face-to-face, intermediaries, or digital service delivery.

Risk assessments need to be updated regularly to account for changes in customers, services, regulatory requirements, and new financial crime risks.

Developing an AML/CTF Program

The risk assessment should guide the development of the organization's AML/CTF program. Policies and procedures must reflect the business's actual exposure rather than adopting off-the-shelf compliance templates.

An effective program should implement well-defined governance arrangements, including oversight by the board or senior management, the appointment of a suitably empowered AML/CTF compliance officer, and the establishment of documented policies and internal controls. Independent reviews are essential to determine whether the program remains effective and consistent with regulatory requirements.

Applying Customer Due Diligence

Informed risk management starts with customer due diligence (CDD). Reporting entities are required to verify who their customers are and, if relevant, verify beneficial owners, and determine the nature and purpose of the business relationship before rendering services.

Strengthening Controls Through Enhanced Due Diligence

Higher-risk relationships will require more than routine checks for verification. Politically exposed persons, individuals listed on sanctions, individuals linked to high-risk jurisdictions, and individuals with complex ownership structures that may be difficult to trace should be subject to enhanced due diligence. Companies need to consider whether to implement additional measures when customer activity or transaction behavior suggests a higher financial crime risk.

Monitoring Transactions and Maintaining Records

AML compliance continues after onboarding. Reporting entities should monitor customer activities to identify any unusual or abnormal activity. They are required to research any potential issues that may arise and, if necessary, report them to the designated person through appropriate documentation and internal procedures. A risk-based monitoring plan enables organizations to allocate investigative resources to high-risk activities and ensure adequate monitoring of the broader customer base.

Companies are also required to keep detailed customer records, transaction records, and audit trails to demonstrate how compliance decisions have been made and to make them available for regulatory examination if necessary.

Building a Culture of Compliance

Financial crime can only be prevented if employees understand and apply policies consistently. Regular, role-specific training is provided to ensure staff are aware of their AML responsibilities, know which suspicious indicators are relevant to their role, and follow appropriate reporting and internal escalation procedures. Continuous education also enables organizations to adapt to evolving regulatory requirements and boost compliance throughout the customer lifecycle.

The Role of AUSTRAC's Supervisory and Enforcement

The Australia Tranche 2 reforms markedly expand AUSTRAC's supervisory duties by bringing thousands of newly regulated businesses into the national AML/CTF regime. It will be a first for many organizations to implement compliance programs. But regulatory oversight will go beyond registration to assess whether companies have effective, risk-based controls in place that actually work – and not just on paper.

The process starts with registration and enrolment, which enables AUSTRAC to identify the reporting entities and what services they are authorized to provide. In addition to its administrative duties, AUSTRAC has a statutory responsibility to assist regulated sectors in their transition to regulation and provide a series of guidance materials. As it interacts with the industry, the organization provides practical compliance resources to help organizations manage changes effectively.

Supervision will be risk-based, meaning AUSTRAC will concentrate on businesses, sectors, and activities that pose greater financial crime risks. This process can involve compliance assessments, thematic reviews, requests for information, and site inspections. The measures aim to assess whether AML/CTF programs, customer due diligence procedures, governance, and record-keeping are adequate for proper supervision.

If it becomes apparent that there are significant deficiencies, AUSTRAC has several enforcement powers at its disposal. The regulator has various options to address non-compliance, depending on its severity. They could issue infringement notices, negotiate enforceable undertakings that require remedies, or pursue civil penalties for serious or repeated breaches of AML/CTF obligations. The measures are designed to promote sustainable compliance while maintaining the integrity of Australia's financial system.

As businesses transition into the expanded regime, regulatory expectations are likely to mature alongside industry implementation. Early action by firms improves governance, establishes risk-based control documentation, and shows continuous improvement. As time goes on, it will be better equipped to respond as AUSTRAC matures its supervisory approach and compliance priorities.

The Implementation Timeline

Australia's Tranche 2 reforms have been rolled out in phases, allowing newly regulated businesses ample time to understand their obligations, establish compliance frameworks, and prepare for regulatory oversight. These reforms encompass more than just legislative changes, including support for AML/CTF Rules, AUSTRAC guidance, and meaningful industry consultations to enable effective implementation. As rulemaking and operational guidance continue to develop, firms should check key dates and compliance deadlines against the most recent legislative updates and AUSTRAC publications before finalizing their implementation plans.

Australia trenche

The phased approach enables businesses to move smoothly from awareness to operational compliance. This method gives them the flexibility to adapt internal processes, governance structures, and technology to align with regulatory expectations effectively.

Key Compliance Challenges for Newly Regulated Businesses

The most difficult aspect of business for many newly regulated companies is not so much understanding the legislation as successfully integrating compliance into the business's daily operations without impacting client services. Entering AML for the first time comes with expectations from regulators, limited resources, unclear guidance, and increasing operational needs.

  • Law firms: Many practices lack dedicated compliance teams, making implementation resource-intensive. They must also be mindful of the requirement to balance AML obligations with legal professional privilege obligations where there is no legal professional privilege and legal obligations are met.
  • Small accounting firms: Generally have limited AML experience and limited budgets. Developing a risk management framework, recording policies, and delegating compliance duties can be stressful for existing staff.
  • Real estate agencies: High transaction volume and short settlement periods make it difficult to verify customers. Agencies are required to conduct due diligence without delaying legitimate property transactions or affecting the customer experience.
  • Trust and company service providers frequently establish and administer legal entities with complex ownership structures. Identifying beneficial owners, assessing nominee arrangements, and understanding cross-border corporate structures can significantly increase compliance complexity.
  • Technology challenges: Manual sanctions screening, disparate onboarding procedures, disjointed recordkeeping systems, and inconsistent monitoring are all technology hurdles that add risk to operations and complexity to regulatory audits.
  • Cost considerations: Compliance is a continuous investment, not a one-time project. Businesses must budget for AML software, customer screening solutions, staff training, independent program reviews, ongoing governance, and periodic system enhancements as regulatory expectations continue to mature.

Addressing these challenges requires proportionate governance, well-defined compliance procedures, appropriate technology, and ongoing monitoring rather than relying solely on manual processes.

How Tranche 2 Changes Customer Due Diligence

Australia's Tranche 2 reforms transform customer due diligence from a one-time onboarding activity into a continuous risk management process. Reporting entities are expected to reassess customer risk periodically, update due diligence where circumstances change, and investigate unusual activity throughout the business relationship.

As compliance obligations expand across newly regulated sectors, automated sanctions screening, PEP screening, adverse media monitoring, beneficial ownership verification, and ongoing monitoring help organizations maintain consistent compliance while reducing manual investigation workloads.

Expected Impact on Financial Crime Prevention

Expanding Australia's AML regime to designated non-financial businesses and professions significantly expands Australia's AML/CTF coverage across higher-risk professional services. Bringing lawyers, accountants, real estate agents, trust and company service providers, and dealers in precious metals and stones under AUSTRAC’s supervision will improve the visibility of financial activity across sectors that have historically received limited AML oversight. This change is expected to increase the suspicious transaction reporting and make it harder for criminals to exploit these professional services. The success of the reforms will hinge on how consistently businesses adopt risk-based controls and how effectively AUSTRAC oversees compliance in the newly regulated sectors.

How Businesses Can Prepare for Australia's Tranche 2 Reforms

Successfully implementing the Australia Tranche 2 reforms requires more than meeting minimum regulatory obligations. Organizations should begin by identifying whether they provide designated services, conducting an enterprise-wide risk assessment, developing an AML/CTF program, assigning governance responsibilities, and implementing customer due diligence and monitoring processes before the compliance deadlines take effect.

Prepare for Australia's Tranche 2 Reforms with Confidence

Australia's Tranche 2 reforms introduce ongoing AML obligations for thousands of newly regulated businesses. Manual processes for customer screening, ongoing monitoring, and regulatory reporting can drive up compliance costs, slow client onboarding, and complicate regulatory examinations.

AML Watcher empowers organizations to enhance their AML compliance with tools for automated sanctions screening, PEP screening, adverse media checks, ongoing monitoring, and risk-based customer due diligence. The platform supports businesses as regulatory requirements evolve while improving operational efficiency.

Request a demo to learn how AML Watcher can support compliance with Australia's Tranche 2 reforms.

Access Premium Content

Register once. Get unlimited access to exclusive AML insights and expert industry analysis, all in one place.

Your information is secure and will not be shared.
Scroll to Top