A Law Firm's Guide to Tranche 2 AML/CTF Obligations in 2026
Conveyancing and trust work put a law firm inside AUSTRAC's Tranche 2 rules from 1 July 2026. What the systems have to do, and what it costs.
Jump to section
- 01 What Tranche 2 asks of a law firm
- 02 Five systems the regime actually needs
- 03 What most firms already have
- 04 When Tranche 2 starts for law firms
- 05 Three software patterns that are working
- 06 What Tranche 2 costs a mid-size firm
- 07 The managing partner has to own this
- 08 What we handle, and what your advisor does
- 09 Primary sources
This is an IT operator’s view of the systems and software Australian law firms are using to meet Tranche 2. It isn’t legal advice or a compliance opinion. Whether any particular control satisfies your obligations is your compliance officer’s or AML advisor’s call. We implement the technical stack. They sign off on whether it clears the bar.
From 1 July 2026, the partner who signed off on the firm’s last trust-account reconciliation is also on the hook for its anti-money-laundering systems. The systems most firms have right now would not stand up to an audit by AUSTRAC, the Australian Transaction Reports and Analysis Centre. AUSTRAC has been explicit that failure to manage money-laundering and terrorism-financing risk remains a serious regulatory matter. It has been just as explicit that civil penalty proceedings and registration cancellations are possible for firms that don’t meet the obligations in 2026.
Tranche 2 is the biggest compliance shift the Australian legal profession has faced in a decade. It runs parallel to the Legal Profession rules, not inside them. The technical work underneath is largely an IT project, and the firms starting that work in early 2026 will be fine. The firms waiting until May will not.
What Tranche 2 asks of a law firm
Tranche 2 brings lawyers and conveyancers providing “designated services” into the anti-money-laundering and counter-terrorism financing (AML/CTF) regime as reporting entities. That makes AML-style obligations a matter of federal law for the firm, on top of its existing legal profession rules.
The designated services that trigger capture include real estate conveyancing, and the creation or administration of trusts. The list also covers buying and selling business entities, and handling client funds in a trust account for specific purposes.
Once captured, the firm must do all of the following.
- Enrol with AUSTRAC.
- Nominate a compliance officer.
- Write a tailored AML/CTF programme.
- Identify and verify clients.
- Monitor transactions.
- Report suspicious matters and threshold transactions.
- Retain records for seven years.
None of that is light-touch. It’s closer to the regime that banks already operate.
The firms that need to pay the closest attention are mid-size practices with a conveyancing or trust-heavy workload. A criminal-only firm with no trust work and no conveyancing is probably outside Tranche 2’s scope. A twelve-seat practice doing a hundred conveyancing settlements a year is squarely inside it.
Five systems the regime actually needs
The regime needs five technical building blocks. Most firms have one or two of them already.
- Customer due diligence. Verify who the client actually is and, for higher-risk matters, who ultimately controls the client entity. Beneficial-ownership checking belongs here, as does politically-exposed-person (PEP) and sanctions screening.
- Ongoing monitoring. Detect unusual patterns across the life of a matter, not just at onboarding.
- Reporting. Send suspicious-matter reports (SMRs) and threshold transaction reports (TTRs) into AUSTRAC’s systems.
- Record retention. Every piece of evidence has to survive seven years in a form that’s accessible and tamper-resistant.
- Control evidence. Show an auditor that each of the above actually operated, not just that it was written down.
What most firms already have
Record retention and access control are typically two-thirds solved on day one if the firm has a halfway-decent Microsoft 365 setup. The other three components are usually missing entirely.
A well-configured Microsoft 365 setup covers long-term retention, access control, and much of the audit trail. That comes from retention labels, data-loss prevention policies, conditional access, and auditing on the E5 security add-ons. Some firms are already using these features to satisfy privacy rules, cyber insurers or larger corporate clients. That investment does a lot of Tranche 2’s work.
Three things are almost always missing from the firms we assess. Identity checks against an authoritative document source, transaction monitoring tuned to the firm’s actual client base, and a reporting link into AUSTRAC’s portal. Those are the new builds.
When Tranche 2 starts for law firms
Enrolment opens on 31 March 2026. Firms must have enrolled with AUSTRAC and notified their compliance officer by 29 July 2026. The full AML/CTF programme and operational obligations start on 1 July 2026. Those three dates govern 2026 planning.
Work backwards from 1 July 2026. A firm that wants to be comfortably running on day one should be finished by mid-May 2026. By then it needs the AML/CTF programme document written, the compliance officer trained, the identity-verification workflow tested, and record-retention labels applied across Microsoft 365. That leaves a six-week buffer for the inevitable bugs, vendor delays and edge cases that appear once real clients use the new workflow.
Smaller firms get the same deadline
No meaningful staging by firm size has been announced. The obligations apply from 1 July 2026 regardless of headcount. AUSTRAC’s transitional rules provide minor technical carve-outs during the commencement window, but the core programme obligation does not wait on firm size.
That is a genuine challenge for smaller practices. A ten-seat firm with conveyancing work has the same AML/CTF programme obligation as a hundred-seat firm doing the same work. Smaller firms have narrower implementation choices: fewer options for a bespoke build, and less capacity to run a complicated stack. The regime does not grant a grace period for that.
Three software patterns that are working
Three shortlist patterns are working for mid-size Australian firms.
- An integrated AML platform (First AML, Kyckr, NameScan) that handles identity verification, PEP and sanctions screening, ongoing monitoring, and SMR filing from one interface.
- A layered stack built on your existing identity and document-management systems, with identity verification bolted in as a dedicated service.
- A tight bolt-on for firms whose practice-management software already includes an AML module. Some Affinity, LEAP and Smokeball plugins now exist, with varying maturity.
The choice depends on how much conveyancing and trust work the firm actually does. A firm with hundreds of high-risk matters a year will stretch the bolt-ons quickly and benefit from the integrated platform. Thirty matters a year won’t return the cost of a six-figure platform licence. That firm should add a single identity-verification service to the environment it already has.
Two caveats on the platform market. First, it’s a young market in Australia for Tranche 2 specifically. Vendors are still stabilising their offerings, and a track record with banks or AFS licensees doesn’t automatically translate to legal practice workflows. Second, practice-management AML modules vary widely in quality. Run a real matter through any module you’re considering before signing.
Off-the-shelf versus custom build
Custom-built AML systems have essentially no case for a law firm of any size. The regulatory bar is high, the compliance risk of getting it wrong is high, and the market already has competent off-the-shelf options. The only reason to consider bespoke is extreme volume plus a workflow no vendor supports. That combination is vanishingly rare in Australian legal practice.
The realistic option is to pick an off-the-shelf platform and integrate it properly into the firm’s practice-management, document-management and identity systems. That integration work is where we spend most of our time on an AML engagement.
Microsoft 365 licensing, and the step-up cost
Most AML/CTF programmes rely on Microsoft 365 for record retention, audit logging and data-loss prevention. That means the firm needs the right licence tier. Microsoft 365 Business Premium covers retention labels and basic data-loss prevention. Microsoft 365 E3 plus the E5 Security add-on, or full E5, covers the advanced auditing, eDiscovery and conditional-access features auditors increasingly ask about. Firms on Business Standard will struggle to produce the evidence Tranche 2 implies.
The licence step-up is not trivial. Business Premium to E3 plus E5 Security is roughly double the per-seat cost. It’s a real input into the Tranche 2 budget and should be modelled before committing to the overall programme.
What Tranche 2 costs a mid-size firm
For a 20-to-100-seat Australian firm, our current view is a one-off implementation spend of 25,000 to 80,000 Australian dollars, depending on platform choice. On top of that, expect 12,000 to 40,000 dollars a year for the AML platform and any licence step-ups. These numbers are estimates that move with vendor pricing, not formal quotes.
The one-off spend covers the following.
- The AML/CTF programme document.
- Compliance-officer training.
- Platform selection and procurement.
- Integration into the existing identity and document-management systems.
- Workflow design for client onboarding.
- Staff training.
A firm with a well-managed Microsoft 365 setup and a sensible practice-management configuration is at the lower end of that range. Where baseline IT hygiene has to be fixed at the same time, the number is at the higher end. Tranche 2 then becomes the reason long-overdue work finally gets done.
Ongoing versus one-off
The ongoing cost is the one firms under-estimate. A captured firm is not buying a project. It is acquiring a compliance function that runs monthly for the life of the firm.
Ongoing effort comes from compliance-officer time, quarterly programme review, and software licensing. Some configurations also require an annual independent review. Then there are the small things, like training a new hire or opening a new office.
Budget for the programme to cost more in year two than in year one, once the annual-review and training cycles are running.
The managing partner has to own this
The programme needs an owner inside the firm’s leadership, and that owner needs time to own it. A designated compliance officer is a legal requirement. But without managing-partner backing, that officer can’t get decisions made when they need to be. What the programme looks like depends on partner-level choices: risk appetite, client acceptance policy, and how much the firm will spend on technology.
The practical version of that backing is three things. First, a recurring partnership agenda item on AML/CTF status for the first twelve months after commencement. Second, authority for the compliance officer to refuse or escalate client onboarding when the risk warrants it. That is the conveyancing referral that’s too good to be true. Third, a willingness to pay for the technology properly rather than trying to stretch practice-management modules beyond their real capability.
What we handle, and what your advisor does
We don’t write AML/CTF programme documents. We build the systems the programme depends on, and we keep them working.
For a law firm preparing for Tranche 2, our work has three parts. The first is the Microsoft 365 and identity work: retention labels, conditional access, audit logging, and the licensing uplift where needed. This is often the fastest-moving part, because most of the configuration is vendor-supported and well understood.
The second is platform selection and integration. We shortlist the two or three platforms that fit the firm’s workload and run proofs of concept against real matter data. Then we integrate the chosen platform into the practice-management system, so staff aren’t switching between five screens for every onboarding.
The third is evidence. Every control the programme claims to have has to produce evidence AUSTRAC can see if they ask. Firms under-invest in this and then scramble for it at audit time.
Three things stay with the firm’s legal and compliance advisors. The AML/CTF programme document itself, the legal interpretation of which matters fall under Tranche 2’s scope, and the risk-assessment methodology behind the programme. Our boundary is explicit. We handle the machinery. They handle the interpretation.
The firms we’re seeing start this work in April and May 2026 are going to be comfortable by 1 July. The firms starting in June will ship something that functions. The firms starting in July will be apologising to AUSTRAC inside six months.
Primary sources
- AML/CTF transitional rules update, AUSTRAC’s rolling guidance page for Tranche 2 reforms. Accessed 21 April 2026.
- AML/CTF transitional rules 2026, the formal transitional rules registered for 2026 commencement. Accessed 21 April 2026.
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), as amended, available via Federal Register of Legislation.