IronSights
All insights

compliance

AML/CTF Tranche 2: what legal practices need to do before 1 July 2026

From 1 July 2026, the AML/CTF regime extends to conveyancing, company and trust formation, estate administration and related services. Affected practices become reporting entities with AUSTRAC. Here are the obligations, the Privacy Act duties that come with them, and why the data-security work should start now.

By IronSights Editorial, Practitioner team11 June 20264 min read
ByIronSights Editorial11 June 20264 min read

From 1 July 2026, the anti-money laundering and counter-terrorism financing regime reaches a large group of legal practices for the first time. The AML/CTF Amendment Act 2024 extends the regime to additional designated services, and several of those sit squarely inside everyday legal and conveyancing work. If your firm provides them, you have real obligations and a fixed date to meet them by.

Which services are now in scope

The new designated services include conveyancing, company and trust formation, estate administration, and certain trust account management activities. These are routine offerings for many small and mid sized firms, which is why Tranche 2 affects far more of the profession than the earlier rules ever did.

A practice that provides any of these services becomes a reporting entity and must enrol with AUSTRAC, the federal agency that oversees the regime. Being a reporting entity is not a one-off form. It brings ongoing duties that have to be built into how the firm operates.

The obligations you take on

Once in scope, a practice carries a defined set of responsibilities.

  • A written AML/CTF program: a documented program that sets out how your firm identifies and manages money laundering and terrorism financing risk.
  • Customer due diligence and identity verification: confirming who your clients are, and in some cases who stands behind them, before and during the work.
  • Ongoing transaction monitoring: watching matters and transactions for activity that does not fit what you would expect.
  • Suspicious matter reporting: reporting to AUSTRAC when something gives you reasonable grounds to suspect a problem.
  • Record-keeping: retaining the records behind all of the above for the periods the law requires.

The Privacy Act duty many firms miss

Customer due diligence means collecting and storing identity documents and for every client in scope. That information is governed by the Privacy Act 1988, including the , regardless of the practice's turnover. Many smaller firms have sat under the usual small-business turnover threshold and have not had to think hard about the Act before. Collecting this data for AML/CTF purposes brings them into the Act's reach, often for the first time.

In plain terms, the moment you start holding verified identity records to satisfy AUSTRAC, you also have to handle that information the way the Privacy Act requires, and you have to be able to notify if it is breached. Two separate obligations land together, and the second one is easy to overlook while you are focused on the first.

Why the work should start now

Building a compliant program takes longer than most practices expect. You have to decide who in the firm owns the program, write and adopt the documentation, set up identity verification that works without slowing client onboarding to a crawl, and train staff so the process is actually followed. The supporting data handling, where this information is stored, who can see it, how long it is kept and how it is destroyed, takes its own planning.

None of that is sensible to start in June 2026. A firm that leaves it late ends up with a rushed program and weak data handling, which is the worst of both worlds. Starting well before the date lets you build something that holds up and does not disrupt the practice.

The cyber security overlap

AML/CTF compliance is not only a legal exercise. The data it requires you to collect, identity documents, addresses and verification records, is exactly the sensitive information attackers want. Concentrating it in your systems makes your firm a more attractive target, and a breach of it is both a privacy incident and a problem for your standing with AUSTRAC and your clients.

So the program and the data security have to be designed together. Where the records sit, who can reach them, how access is controlled and how a breach would be detected and contained are questions to answer as you build the program, not after.

IronSights helps Australian legal practices get the data-security side of AML/CTF readiness right, so the identity information you collect for AUSTRAC is held and protected properly. If you want to make sure the security work is in place before 1 July 2026, a security review is a practical first step.

Keep reading

More from the IronSights team.