Skip to content

Compliance

An Accountant's Guide to Tranche 2 AML/CTF Obligations in 2026

AUSTRAC's Tranche 2 AML/CTF rules cover accounting practices doing company formation, trustee and client-money work from 1 July 2026. What your systems need.

12 min read
Jump to section
  1. 01 What Tranche 2 asks of an accounting practice
  2. 02 Which accounting practices are most exposed?
  3. 03 Six systems your practice has to run
  4. 04 What your practice probably already has
  5. 05 When Tranche 2 starts, and the four dates that matter
  6. 06 Three software patterns that work in accounting practices
  7. 07 What Tranche 2 costs a practice of 20 to 100 staff
  8. 08 Partner-level decisions the programme needs
  9. 09 What CCP builds for a Tranche 2 programme
  10. 10 Primary sources

This is an IT operator’s view of the systems and software Australian accounting practices are using to meet AUSTRAC’s Tranche 2 AML/CTF regime. AUSTRAC is the Australian Transaction Reports and Analysis Centre. AML/CTF is short for anti-money-laundering and counter-terrorism financing, and the regime covers both. It isn’t legal advice or a compliance opinion. Whether any particular control satisfies your obligations is your AML advisor’s, your compliance officer’s, or your professional body’s call. We implement the technical stack. They sign off on whether it clears the bar.

Picture a 35-seat practice doing company formations and trustee work alongside its tax and assurance lines. That is the kind of business AUSTRAC has in mind when it talks about Tranche 2. From 1 July 2026, that practice has the same kind of obligation as a remittance dealer or a bullion trader. Its current compliance machinery is almost certainly built around the Tax Practitioners Board and the firm’s professional body. It does not cover what AUSTRAC is going to ask for.

This is the largest expansion of the AML/CTF regime since the 2006 Act took effect. Accountants are inside it from day one. The firms starting their preparation in the first half of 2026 will be operational on commencement. A firm still treating it as a 2027 problem in May will not.

What Tranche 2 asks of an accounting practice

Tranche 2 captures accounting practices that provide certain “designated services”. Those practices become reporting entities, which means AUSTRAC regulates them directly. The captured services are not the firm’s whole offering. They are a defined set of activities. Acting as, or arranging for someone to act as, a director, trustee, partner, or nominee shareholder. Forming companies, partnerships, or trusts. Buying or selling business entities on behalf of a client. Receiving, holding, controlling, or transferring money or property as part of any of the above.

A pure tax-and-compliance practice is probably outside Tranche 2’s scope. That means no company-formation work, no trustee appointments, no nominee work and no client money. A practice doing two of those activities a month is squarely inside it. So are most multi-disciplinary firms of 20 to 250 staff, the size band we work in.

Once captured, the firm has to do all of the following.

  • Enrol with AUSTRAC and nominate a compliance officer. The AUSTRAC term is “AML/CTF compliance officer”.
  • Write a tailored AML/CTF programme.
  • Identify and verify clients before providing the captured service.
  • Monitor the matter as it runs.
  • Report suspicious matters and threshold transactions.
  • Retain records for seven years.

That is closer to the regime banks operate than to anything CA ANZ or CPA Australia has required before.

Which accounting practices are most exposed?

Mid-size general practices with a mix of compliance, advisory, and corporate-services work. Specialist insolvency, trustee-services and outsourced chief financial officer (virtual CFO) firms that handle client money or take board appointments as a matter of course. Boutique practices doing significant company-formation or trust-establishment volume.

A practice that only administers self-managed super funds is mostly outside Tranche 2. That work generally does not include the captured designated services. A practice doing Tax Practitioners Board work only keeps its existing obligations to that board, and Tranche 2 does not pull it in. Then there is the small advisory firm with one or two trustee appointments, taken on as a favour to long-standing clients. It is captured for those services. It has to decide whether to keep the work, refer it out, or build the programme to support it.

Capture is decided by the activity, not by the name on the door. Accountants appointed to a client’s trustee board are reporting entities for that work, even if they would call themselves advisers. So the compliance officer’s first job is to map every captured activity in the firm. Then they decide which ones are commercially worth keeping, once the cost of the AML programme is known.

Six systems your practice has to run

Six technical building blocks. Most practices have one or two of them on day one.

  • Identity verification when a client is onboarded.
  • Beneficial-ownership checks for company and trust clients, so the firm knows who really controls the entity.
  • Ongoing monitoring of transactions and matters.
  • Suspicious-matter reporting into AUSTRAC’s portal.
  • Record retention for seven years, in a form nobody can quietly alter.
  • Evidence generation for every control the firm claims, to a standard an auditor accepts.

Customer due diligence comes first. The firm needs a reliable way to verify who the client actually is, with the documentary evidence stored against the client record. For company and trust clients, you also have to establish who ultimately controls the entity, and document that ownership chain to AUSTRAC’s standard. Screening for sanctions and for politically exposed persons happens at onboarding and then continues.

Ongoing monitoring comes next. The firm has to detect unusual patterns across the life of an engagement, not just at the start of it.

Reporting is third. You need a working route to file suspicious matter reports and threshold transaction reports into AUSTRAC’s portal, inside the reporting windows the regime sets.

Retention and evidence come last. Every document used in a client check, every file note and every transaction record is kept for seven years and produced on request. And the firm has to show an auditor not only that a control exists, but that it actually operated.

What your practice probably already has

Document storage and access control are partly covered already, if the firm runs Microsoft 365 properly, with retention labels and conditional access. Conditional access is Microsoft’s rule set for who can sign in, from where, and on what device. Practice-management systems handle some workflow tracking. Almost nothing else is in place.

The technical baseline AUSTRAC implies is much tighter than anything a tax-only or assurance-only firm has needed before. Take a practice on Microsoft 365 Business Standard, with its practice-management system left on the default settings and client documents in shared folders. It will be missing the access controls, the retention discipline and the evidence the regime expects. Client documents in open folder shares are the weak spot we see most often.

Retention, access and audit logging are the easy part. Microsoft 365 does all three, and both the licence step-up and the configuration work are predictable. Identity verification, ongoing monitoring and AUSTRAC reporting are the three blocks that have to be built or bought from scratch.

When Tranche 2 starts, and the four dates that matter

Enrolment opens on 31 March 2026. The firm’s AML/CTF programme has to be in place by 30 June 2026. Operational obligations commence 1 July 2026. Enrolment with AUSTRAC and registration of the compliance officer must be completed by 29 July 2026. Those four dates govern 2026 planning.

Work backwards from 1 July 2026. A practice that wants to commence operationally on day one should have five things done by mid-May 2026.

  • Programme document drafted.
  • Compliance officer trained.
  • Identity-verification workflow tested with real clients.
  • Retention labels applied across the document store.
  • Threshold-transaction monitoring switched on.

The gap between mid-May and 1 July absorbs the bugs and the vendor delays. It also absorbs the client-acceptance edge cases that always appear once real engagements start running through the new workflow.

One mistake comes up in almost every early conversation. Firms assume they have until 29 July 2026 to be operational, because that is the date enrolment closes. It isn’t. The programme has to be operational on 1 July, and 29 July is the back-end administrative deadline. Confusing the two costs a month of preparation.

Staged rollout for smaller practices?

No meaningful staging by firm size has been announced. The obligations apply from 1 July 2026 regardless of firm headcount. AUSTRAC’s transitional rules contain narrow technical accommodations during the commencement window but no carve-out from the core programme obligation.

That is a real burden for smaller practices. A 15-seat firm doing a handful of company formations a year has the same programme obligation as a 200-seat firm doing a hundred. A smaller practice also has fewer options, because it has less appetite for a six-figure platform and less capacity to run sophisticated tooling. The regime still grants no relief based on size. So smaller practices are increasingly asking whether the captured work is worth keeping at all, once the programme cost is in the budget.

Three software patterns that work in accounting practices

Three patterns are working for mid-size Australian accounting firms preparing for Tranche 2.

  • One platform for everything. An integrated AML platform built for professional services, such as First AML, Kyckr or NameScan. It handles identity verification, beneficial-ownership and politically-exposed-person screening, ongoing monitoring, and suspicious-matter filing through a single interface.
  • Several tools, layered. Existing identity tooling integrates with a dedicated identity-verification service. Monitoring rules run inside the practice-management system, and suspicious-matter reports go out through a specialised filing tool.
  • A bolt-on to what you already run. Some practice-management software already includes an AML module. Integrations exist around Xero Practice Manager, MYOB and CCH iFirm, with varying maturity.

Which one fits depends on how much captured work the firm actually does. A steady company-formation and trustee book justifies the integrated platform. Sporadic captured work does not, and a six-figure platform licence will not earn its keep. Layer the point tools instead.

Two warnings about the platform market. First, the Tranche 2 AML market in Australia is genuinely young. Some vendors have done excellent work for banks and Australian financial services licensees. That does not mean they have a track record with accounting workflows. Their screens and field structures may not match how an accountant verifies a corporate client. Second, practice-management AML modules vary widely in depth. Run a real captured engagement through any module before you sign.

Off-the-shelf beats a custom build

There is essentially no case for a custom-built AML system in an accounting practice of any size. The regulatory bar is high, the cost of getting it wrong is high, and the off-the-shelf market has competent options. Bespoke is justified only where extreme volume meets a workflow no vendor supports, which is vanishingly rare in Australian accounting.

The realistic option is an off-the-shelf platform, integrated properly into the firm’s practice-management, document-management and identity systems. Most of the real implementation budget goes on that integration.

Which Microsoft 365 licence you need

Most AML/CTF programmes depend on Microsoft 365 for record retention, audit logging and data-loss prevention. If yours does, the licence tier matters. Microsoft 365 Business Premium covers retention labels and basic data-loss prevention. Microsoft 365 E3 with the E5 Security add-on, or full E5, goes further. That tier covers advanced auditing and the sign-in controls auditors increasingly ask about. It also covers eDiscovery, which is Microsoft’s tool for finding and holding records for a legal matter. Practices on Business Standard will struggle to produce the evidence Tranche 2 implies.

The licence step-up is not trivial. Moving from Business Premium to E3 plus E5 Security roughly doubles the per-seat cost. Model that cost before you settle on the rest of the programme.

What Tranche 2 costs a practice of 20 to 100 staff

For a 20-to-100-seat Australian practice, our current view is a one-off implementation spend of 25,000 to 75,000 Australian dollars, depending on platform choice. On top of that, expect ongoing licensing and operating costs of 12,000 to 35,000 dollars a year. These are estimates that move with vendor pricing, not formal quotes.

The one-off spend covers six things.

  • Programme document.
  • Compliance-officer training.
  • Platform selection and procurement.
  • Integration with the practice-management and document-management systems.
  • Workflow design for client onboarding under the new rules.
  • Staff training.

Where Microsoft 365 is well run and the practice-management configuration is clean, expect the lower end. A practice that has to fix baseline IT hygiene at the same time is at the higher end. In that case Tranche 2 is what finally forces a long-overdue cleanup.

Ongoing cost, after the project ends

The ongoing cost is the one practices under-estimate. A captured firm has taken on a permanent compliance function, not a one-off project. It runs every month for the life of the firm. Expect to pay for compliance-officer time, quarterly programme review and software licensing. In some configurations there is also an annual independent review. Then the small recurring items: training every new starter, and the incidents that come with each new office.

Budget for the second year to cost more than the first. That is when the annual-review cycle and the steady-state training schedule are both in operation.

Partner-level decisions the programme needs

The programme needs a senior owner, and that owner needs time to actually own it. The compliance officer is a regulatory requirement. But a compliance officer without partner-level backing cannot get decisions made when they need to be. Three choices belong to the partners. Which captured services the firm will continue to offer. What risk the firm is willing to accept on an individual client. How much technology the firm is willing to fund to operate the programme well.

Partner backing means three things in practice. A standing partnership agenda item on AML/CTF status, through the first year after commencement. Authority for the compliance officer to refuse or escalate client onboarding when the risk warrants it. The classic case is the unfamiliar overseas client who wants a company formed immediately. And funding the technology properly, rather than stretching a practice-management bolt-on past what it can credibly do.

What CCP builds for a Tranche 2 programme

We do not write AML/CTF programme documents. We set up the systems the programme runs on, and we keep them running.

For an accounting practice preparing for Tranche 2, the work usually splits into three streams.

Microsoft 365 and identity

Retention labels, sign-in rules, audit logging, and the licence uplift where the existing tier cannot meet the regime’s expectations. This stream moves fastest, because the configuration is well understood and the vendor supports it.

The AML platform

We shortlist the two or three platforms that suit the firm’s captured work, then run proofs of concept on real client data. We integrate the chosen platform into the practice-management environment, so onboarding does not make staff jump between five interfaces.

Evidence for the auditor

Every control the firm claims has to produce the audit-grade evidence AUSTRAC will look for. This is the part most firms under-invest in, and then scramble for at audit time.

Three things stay with the firm’s AML advisor and the compliance officer. The AML/CTF programme document. The legal interpretation of which services fall inside Tranche 2’s scope. And the risk-assessment methodology the programme is built on. Our boundary is explicit. We handle the machinery. They handle the interpretation.

The practices we see starting this work in March and April 2026 will be comfortable on 1 July. Start in June and you will ship something that functions. Wait until July and you will be apologising to AUSTRAC inside six months.

Primary sources

Tags complianceaustracaml-ctftranche-2financeaccountants
Share LinkedIn Email
See if we're a fit