
If you run a law firm, an accounting practice, a real estate agency or a conveyancing business, the rules changed under your feet on 1 July 2026. You have until 29 July to tell AUSTRAC you exist.
Australia’s anti-money-laundering regime, the AML/CTF Act, used to stop at banks, casinos and remittance dealers. From 1 July 2026 it reaches a second wave of businesses, the ones the reforms call “tranche 2”. If you provide one of the newly designated services, you are now a reporting entity, and around 80,000 businesses just joined you. Enrolment opened on 31 March. It closes on 29 July 2026.
Most of the coverage treats this as a form-filling exercise: enrol, appoint a compliance officer, write an AML/CTF program. That part matters. But it skips over the change that outlasts the deadline, and it is the part an auditor notices first. Overnight, tens of thousands of small firms became custodians of their clients’ most sensitive identity documents, and most of them have no system for holding that data safely.
What lands on 1 July, and what closes on 29 July
The designated services that trigger tranche 2 are the everyday work of professional firms: real estate agents helping buy or sell property, lawyers and conveyancers handling transactions, accountants and trust and company service providers, and dealers in precious metals and stones. If you provide one of these services with a connection to Australia, in the course of running a business, you are a reporting entity.
The obligations commenced on 1 July 2026. Enrolment with AUSTRAC has been open since 31 March, and the deadline to enrol is 29 July 2026. There is a second date that catches people out: you also have to notify AUSTRAC of your appointed AML/CTF compliance officer by the later of 29 July or 14 days after you enrol. The penalties for getting it wrong are not symbolic. Civil penalties for a corporation run up to A$31.3 million per contravention.
The headline obligations read like a checklist: enrol, build an AML/CTF program, carry out customer due diligence, screen against sanctions and politically exposed persons lists, report suspicious matters, and keep records for seven years. Look closely at that list and one theme runs through all of it, which is data.
Customer due diligence means you are now holding identity documents
Customer due diligence is the heart of it. To satisfy it you collect and verify who your client is: full name, date of birth, address, and usually a copy of a passport or driver licence, sometimes company records and beneficial-ownership details. The seven-year record-keeping rule then says you hold all of it, along with the evidence behind your decisions, for years after the matter closes.
Put those two obligations together and here is what a small firm actually ends up with: a growing archive of scanned passports, licences and financial details, sitting in email inboxes, shared drives and a practice-management system, kept for seven years, reachable by whoever happens to have the login. The AML rules exist to make crime harder. The awkward part is that the pile of identity documents you now have to keep is exactly what a criminal wants to steal.
The privacy exemption you used to rely on is gone
There is a second shift that a lot of small practices have not clocked. Many assumed the Privacy Act did not apply to them, because a business with annual turnover under three million dollars is generally exempt. Tranche 2 changes that. Under section 6E of the Privacy Act, once a small business becomes a reporting entity under the AML/CTF Act, the Privacy Act applies to the personal information it handles for AML/CTF purposes, as if it were a full organisation. The OAIC has published guidance for reporting entities that spells this out.
In plain terms, the exact activity AUSTRAC now requires, collecting and holding client identity data, is the activity that pulls you into the Privacy Act. You do not get to be exempt from privacy obligations for the very records the AML rules force you to keep. Both regimes now point at the same filing cabinet, and both expect you to look after it.
Why this keeps an auditor up at night
If those identity records are breached, you are squarely inside the Notifiable Data Breaches scheme, which means notifying the OAIC and telling every affected client that their passport or licence is now in the wrong hands. In 2025 the OAIC recorded its highest number of breach notifications since the scheme began. A seven-year archive of verified identity documents is close to a worst case for serious harm, because it is everything an identity thief needs, already collected and confirmed by you.
This is the gap between the two conversations firms are having right now. The compliance conversation is about enrolling and writing a program. The conversation almost nobody is having is the operational one: where does this data live, who can reach it, how is it protected, when is it destroyed, and what happens on the day it leaks. That second conversation is an information security question, and there is a well-worn standard that answers it.
What good looks like: ISO 27001 around your AML records
ISO 27001 is the international standard for an information security management system, and its Annex A controls map almost one-to-one onto the exposure tranche 2 creates. You do not have to be certified to use it as a blueprint, though certification is increasingly what larger clients and insurers ask for. The point is that it turns “we collect IDs because AUSTRAC says so” into “we hold them safely, and we can prove it.”
- Access control: only the people who need an identity file can open it, with individual logins and multi-factor authentication, rather than a shared drive the whole office can browse.
- Retention and secure disposal: a defined rule that keeps records for the seven years the law requires, then destroys them, so the archive stops growing forever.
- Encryption: identity documents protected at rest and in transit, so a lost laptop or a misdirected email is not automatically a reportable breach.
- Supplier management: the cloud tools, verification services and IT providers that touch this data get assessed, not assumed.
- Incident response: a tested plan for the day something goes wrong, so you can meet the OAIC notification clock instead of improvising.
None of this needs to be heavy. A small practice does not need a bank’s security team. It needs a right-sized set of controls that fit how the firm actually works. If you would rather your own people own it, our ISO mentoring service guides them through building a compliant system and provides the independent internal audit it needs. If you want to know where you stand first, a gap analysis shows you the holes before anyone else finds them. And if cyber and information security is new ground, our cyber and information security advisory is a sensible place to start.
A note on scope
This article is general information, written from an ISO and information-security perspective. It is not legal, financial or AML/CTF compliance advice, and we are not lawyers or registered AML advisers. Whether you provide a designated service, and exactly what your obligations are, depends on your circumstances. Check AUSTRAC’s own guidance and get qualified advice before you act. Dates and figures were correct at the time of writing and are drawn from published AUSTRAC and OAIC material.
Frequently asked questions
Do I have to be ISO 27001 certified to meet my AML obligations?
No. AUSTRAC does not require ISO 27001. It requires you to protect the information you collect. ISO 27001 is simply the most widely recognised way to do that well and to prove it, and its controls line up neatly with what tranche 2 asks of you.
We are a small firm under the turnover threshold. Are we really covered by the Privacy Act now?
For your AML/CTF activities, yes. Section 6E of the Privacy Act removes the small business exemption for the personal information you handle as a reporting entity. The OAIC has published guidance specifically for reporting entities on this point.
What is the fastest way to see where we stand?
A gap analysis. It reviews how you currently collect, store and dispose of client identity data against a recognised control set, and hands you a short list of what to fix, in priority order.
Speak with an experienced ISO auditor
If tranche 2 has turned you into a custodian of client identity data and you are not sure your controls are up to it, we can help. Email hello@streamline.business or call us. You will deal directly with an experienced ISO auditor who knows what good looks like for a small practice.
- Brisbane 07 3667 8280
- Sydney 02 8315 7780
- Melbourne 03 9034 3990
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











