Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

AUSTRAC Tranche 2: You’re Now Holding Clients’ ID Documents. Where Are Your Controls?

Security operations desk with data monitoring screens, representing information-security controls over client identity records
From 1 July 2026 around 80,000 newly regulated firms must collect and keep client identity records. AUSTRAC enrolment closes 29 July 2026.

If you run a law firm, an accounting practice, a real estate agency or a conveyancing business, the rules changed under your feet on 1 July 2026. You have until 29 July to tell AUSTRAC you exist.

Australia’s anti-money-laundering regime, the AML/CTF Act, used to stop at banks, casinos and remittance dealers. From 1 July 2026 it reaches a second wave of businesses, the ones the reforms call “tranche 2”. If you provide one of the newly designated services, you are now a reporting entity, and around 80,000 businesses just joined you. Enrolment opened on 31 March. It closes on 29 July 2026.

Most of the coverage treats this as a form-filling exercise: enrol, appoint a compliance officer, write an AML/CTF program. That part matters. But it skips over the change that outlasts the deadline, and it is the part an auditor notices first. Overnight, tens of thousands of small firms became custodians of their clients’ most sensitive identity documents, and most of them have no system for holding that data safely.

What lands on 1 July, and what closes on 29 July

The designated services that trigger tranche 2 are the everyday work of professional firms: real estate agents helping buy or sell property, lawyers and conveyancers handling transactions, accountants and trust and company service providers, and dealers in precious metals and stones. If you provide one of these services with a connection to Australia, in the course of running a business, you are a reporting entity.

The obligations commenced on 1 July 2026. Enrolment with AUSTRAC has been open since 31 March, and the deadline to enrol is 29 July 2026. There is a second date that catches people out: you also have to notify AUSTRAC of your appointed AML/CTF compliance officer by the later of 29 July or 14 days after you enrol. The penalties for getting it wrong are not symbolic. Civil penalties for a corporation run up to A$31.3 million per contravention.

The headline obligations read like a checklist: enrol, build an AML/CTF program, carry out customer due diligence, screen against sanctions and politically exposed persons lists, report suspicious matters, and keep records for seven years. Look closely at that list and one theme runs through all of it, which is data.

Customer due diligence means you are now holding identity documents

Customer due diligence is the heart of it. To satisfy it you collect and verify who your client is: full name, date of birth, address, and usually a copy of a passport or driver licence, sometimes company records and beneficial-ownership details. The seven-year record-keeping rule then says you hold all of it, along with the evidence behind your decisions, for years after the matter closes.

Put those two obligations together and here is what a small firm actually ends up with: a growing archive of scanned passports, licences and financial details, sitting in email inboxes, shared drives and a practice-management system, kept for seven years, reachable by whoever happens to have the login. The AML rules exist to make crime harder. The awkward part is that the pile of identity documents you now have to keep is exactly what a criminal wants to steal.

The privacy exemption you used to rely on is gone

There is a second shift that a lot of small practices have not clocked. Many assumed the Privacy Act did not apply to them, because a business with annual turnover under three million dollars is generally exempt. Tranche 2 changes that. Under section 6E of the Privacy Act, once a small business becomes a reporting entity under the AML/CTF Act, the Privacy Act applies to the personal information it handles for AML/CTF purposes, as if it were a full organisation. The OAIC has published guidance for reporting entities that spells this out.

In plain terms, the exact activity AUSTRAC now requires, collecting and holding client identity data, is the activity that pulls you into the Privacy Act. You do not get to be exempt from privacy obligations for the very records the AML rules force you to keep. Both regimes now point at the same filing cabinet, and both expect you to look after it.

Why this keeps an auditor up at night

If those identity records are breached, you are squarely inside the Notifiable Data Breaches scheme, which means notifying the OAIC and telling every affected client that their passport or licence is now in the wrong hands. In 2025 the OAIC recorded its highest number of breach notifications since the scheme began. A seven-year archive of verified identity documents is close to a worst case for serious harm, because it is everything an identity thief needs, already collected and confirmed by you.

This is the gap between the two conversations firms are having right now. The compliance conversation is about enrolling and writing a program. The conversation almost nobody is having is the operational one: where does this data live, who can reach it, how is it protected, when is it destroyed, and what happens on the day it leaks. That second conversation is an information security question, and there is a well-worn standard that answers it.

What good looks like: ISO 27001 around your AML records

ISO 27001 is the international standard for an information security management system, and its Annex A controls map almost one-to-one onto the exposure tranche 2 creates. You do not have to be certified to use it as a blueprint, though certification is increasingly what larger clients and insurers ask for. The point is that it turns “we collect IDs because AUSTRAC says so” into “we hold them safely, and we can prove it.”

  • Access control: only the people who need an identity file can open it, with individual logins and multi-factor authentication, rather than a shared drive the whole office can browse.
  • Retention and secure disposal: a defined rule that keeps records for the seven years the law requires, then destroys them, so the archive stops growing forever.
  • Encryption: identity documents protected at rest and in transit, so a lost laptop or a misdirected email is not automatically a reportable breach.
  • Supplier management: the cloud tools, verification services and IT providers that touch this data get assessed, not assumed.
  • Incident response: a tested plan for the day something goes wrong, so you can meet the OAIC notification clock instead of improvising.

None of this needs to be heavy. A small practice does not need a bank’s security team. It needs a right-sized set of controls that fit how the firm actually works. If you would rather your own people own it, our ISO mentoring service guides them through building a compliant system and provides the independent internal audit it needs. If you want to know where you stand first, a gap analysis shows you the holes before anyone else finds them. And if cyber and information security is new ground, our cyber and information security advisory is a sensible place to start.

A note on scope

This article is general information, written from an ISO and information-security perspective. It is not legal, financial or AML/CTF compliance advice, and we are not lawyers or registered AML advisers. Whether you provide a designated service, and exactly what your obligations are, depends on your circumstances. Check AUSTRAC’s own guidance and get qualified advice before you act. Dates and figures were correct at the time of writing and are drawn from published AUSTRAC and OAIC material.

Frequently asked questions

Do I have to be ISO 27001 certified to meet my AML obligations?

No. AUSTRAC does not require ISO 27001. It requires you to protect the information you collect. ISO 27001 is simply the most widely recognised way to do that well and to prove it, and its controls line up neatly with what tranche 2 asks of you.

We are a small firm under the turnover threshold. Are we really covered by the Privacy Act now?

For your AML/CTF activities, yes. Section 6E of the Privacy Act removes the small business exemption for the personal information you handle as a reporting entity. The OAIC has published guidance specifically for reporting entities on this point.

What is the fastest way to see where we stand?

A gap analysis. It reviews how you currently collect, store and dispose of client identity data against a recognised control set, and hands you a short list of what to fix, in priority order.

Speak with an experienced ISO auditor

If tranche 2 has turned you into a custodian of client identity data and you are not sure your controls are up to it, we can help. Email hello@streamline.business or call us. You will deal directly with an experienced ISO auditor who knows what good looks like for a small practice.

  • Brisbane 07 3667 8280
  • Sydney 02 8315 7780
  • Melbourne 03 9034 3990

Related reading

  • ISO 27001 certification cost and timeline in Australia
  • Australia’s 2025 data breach numbers, and what an auditor reads into them
  • ISO 27001 vs SOC 2: which does your business need?
General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Manager reviewing a budget spreadsheet
    ISO 27001 Certification Cost & Timeline in Australia…
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Tilt-shift miniature of a submarine periscope casting a narrow cone of light onto one small island of activity in a vast dark ocean
    ISO Clause 4.3: Determining Your Scope (Inside Your…
  • Tilt-shift miniature of a collapsed bridge with engineers at a drawing board tracing the failure back to the design
    ISO 9001 Clause 8.3: Design Inputs, Outputs, Review,…

Filed Under: Articles Tagged With: #informationsecurity, #iso27001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire