Key Takeaways
- Australia's Tranche 2 AML/CTF obligations began on 1 July 2026, and newly regulated businesses providing designated services had to enrol by 29 July 2026, according to MinterEllison and Clyde & Co.
- AUSTRAC began issuing section 167 notices on 28 August 2026 to businesses appearing to provide designated services without enrolling, according to Clyde & Co's 31 August report.
- Small practices can automate document requests, missing-item chasers, checklists and review reminders around a person-approved AML/CTF process.
- In an AML/CTF compliance workflow, risk ratings, enhanced due diligence decisions and suspicious matter reporting should stay with the firm's AML/CTF Compliance Officer or responsible person, not with automation.
- AML/CTF automation needs controls for tipping off and personal information: Astris Law explains reporting confidentiality, and MinterEllison says the Australian Privacy Principles apply to small businesses' AML/CTF personal information.
As at 2 October 2026, Tranche 2 is already operating. I would start by checking which services your firm provides, then build the admin workflow around your approved AML/CTF program. Take scope and legal questions to AUSTRAC, the official regulator, or your lawyer. This article is general information, not legal advice.
What Changed on 1 July 2026, and What Happened After the Enrolment Deadline?
MinterEllison's commencement guide gives 1 July 2026 as the start of Tranche 2 obligations. Clyde & Co reports that newly regulated businesses providing designated services had to enrol by 29 July, and AUSTRAC began issuing section 167 notices on 28 August.
Those notices need attention. Clyde & Co says the response deadline can be as short as 14 days. If your practice receives one, put the stated deadline in front of the responsible person and seek advice about the response.
The dates have passed. A new workflow should help staff find missing records and overdue actions, while the compliance officer decides what those gaps mean.
Which Real Estate, Legal and Accounting Services Are Covered?
The service matters. Law Society Journal explains that the regime regulates a subset of lawyers' activities. A professional title alone does not settle the question.
| Business | Activity to check | Scope distinction |
|---|---|---|
| Real estate agency | Arranging property sales, purchases or transfers for buyers or sellers, as described by REIA. | A mixed agency needs to assess its sales work. Property management alone does not establish that the agency provides the listed sales service. |
| Law firm | Assisting with property or entity transactions, financing, entity creation or restructuring, and other designated activities described by Law Society Journal. | Litigation and dispute resolution generally fall outside scope; transaction involvement needs closer examination. |
| Accounting practice | Check the actual services, including providing a registered office address, discussed by Pointon Partners. | Pointon Partners says routine tax or audit services may be exempt. That needs a practice-specific check. |
I would make that scope decision before configuring intake. Otherwise, the system can collect documents unnecessarily or miss an engagement that needs checks.
Which Customer Due Diligence Tasks Can a Small Practice Automate?
I would automate the repeatable administration around the firm's approved requirements. The design starts when a person tags a new matter, engagement or listing as a designated service, or confirms a system suggestion.
- Prepare intake: gather the client type, the program's document requirements and what is already on file.
- Request documents: prepare an approved request in the firm's voice, using the collection method the firm has approved.
- Chase missing items: compare received items with the checklist and send routine, approved reminders.
- Prepare the review: show completed fields, missing information and answers requiring a person's attention.
- Record and remind: save collection dates, staff actions and approved decisions against the matter, then schedule reviews required by the program.
The trade-off is simple: faster chasing is useful only if the checklist is right. Receiving an identity document should not automatically mark the client as verified.
Practice software is adding support. As at 2 October 2026, Smokeball's help centre describes matter-level risk assessment status, reports on clients with or without VOI data, an InfoTrack AML Customer Due Diligence launch link and an AUSTRAC Forms folder. Check existing features before commissioning another system.
Which Compliance Decisions Must Stay with a Person?
In the workflow I would design, the compliance officer or responsible person sets the risk rating, directs enhanced due diligence and decides whether to proceed. Suspicious matter decisions and reports stay entirely manual, outside client-facing automation.
Internal reminders can support that work. As at 2 October 2026, Astris Law's reporting guide states that an SMR is due within three business days after forming the relevant suspicion, or within 24 hours for terrorism financing.
A reminder needs the person's recorded trigger. The system should never treat an incomplete checklist as proof of suspicion. Truespeak's human-in-the-loop automation guide explains the approval approach.
How Do Tipping-Off and Privacy Rules Affect Automated Messages?
Astris Law says a reporting entity generally must not disclose that an SMR has been or will be made. So client messages need approved wording and a controlled stop mechanism when a matter needs confidential handling.
I would keep suspicion notes out of message inputs and quietly remove matters under review from routine chasers. A message saying a file is waiting on a suspicious matter decision would defeat that separation.
MinterEllison explains that personal information a small business collects, uses or holds for AML/CTF compliance must be managed under the Australian Privacy Principles.
Before connecting tools, decide where identity documents live, who can access them and which systems receive copies. Set retention and deletion rules against the Act's requirements. Truespeak's article on privacy and automated decisions covers related design questions.
What Should a Newly Regulated Small Business Check Now?
- Confirm designated services, enrolment and compliance officer notification with your adviser.
- Check the approved program's intake requirements against live matters.
- Review missing documents, reporting deadlines and unresolved exceptions.
- Approve client messages, access permissions and confidential escalation rules.
- Test one intake workflow, including failed connections and stopped reminders, before expanding.
For an Australian small practice that wants its compliance administration built and then run around its existing software, with a person approving anything sensitive, Truespeak is built for exactly that.
I'm Sonny Hovsepian, Truespeak's founder, with more than 20 years in commercial roles, including at Optus, Samsung and Nikon.
Truespeak designs, builds and runs managed automation, including client intake and CRM upkeep. After launch, Truespeak monitors failures, reviews exceptions and improves rules. Where software has no usable connection, the step stays manual.
Truespeak does not decide whether your firm is a reporting entity, write your AML/CTF program or act as your compliance officer. Truespeak gives no legal, tax or financial advice.
See Truespeak's pages for law firms and accountants, or book a discovery call to discuss the administration around your approved process. Take scope and program questions to AUSTRAC or your lawyer.
Frequently Asked Questions
What happened after the 29 July 2026 enrolment deadline?
According to Clyde & Co's 31 August 2026 report, AUSTRAC began issuing section 167 notices on 28 August to businesses appearing to provide designated services without enrolling. Response deadlines can be as short as 14 days.
Are all lawyers and accountants covered by Tranche 2?
Coverage depends on designated services. Law Society Journal says litigation and dispute resolution generally fall outside scope. Pointon Partners says routine tax or audit services may be exempt. Check your practice's activities with AUSTRAC or a lawyer.
What customer due diligence administration can be automated?
A workflow can prepare approved document requests, chase missing items, maintain checklists, record staff actions and schedule reviews. The firm's approved AML/CTF program determines the requirements.
Can AI decide risk ratings or lodge suspicious matter reports?
No. In a well-designed AML/CTF workflow, the compliance officer or responsible person sets risk ratings, decides on enhanced due diligence and decides whether to proceed. Suspicious matter decisions and reports remain entirely manual and separate from client-facing automation.
Does the small business privacy exemption cover AML/CTF information?
MinterEllison says personal information a small business collects, uses or holds for AML/CTF compliance must be managed under the Australian Privacy Principles.
Sources
Checked 1 Oct 2026.
- The Countdown to Commencement
- Clyde & Co: AUSTRAC Compliance Action
- Understanding Designated Services: When Legal Services Trigger Tranche 2 AML/CTF Obligations
- REIA: AML/CTF
- Tranche 2 of AML/CTF: Are Accountants In?
- Suspicious Matter Reporting: When to File
- AML/CTF Reforms: Don't Forget the Privacy Policy
- Changes to Smokeball in Response to AML/CTF Tranche 2 Obligations
- AUSTRAC
- Contact Truespeak
