Business Strategy

AML Tranche 2: AI for Accounting Firms

AML Tranche 2: AI for Accounting Firms

Abstract visualisation of customer due diligence, screening and record-keeping flowing through an accounting practice

A Bank-Grade Obligation Lands on Professional Services

For most accounting firms, anti-money laundering was something other industries worried about. Banks, remitters and casinos carried the load under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. That changed on 1 July 2026, when the long-anticipated Tranche 2 reforms extended AML/CTF obligations to a new set of professions, accountants and bookkeepers among them, alongside lawyers, conveyancers, real estate agents, dealers in precious metals and stones, and trust and company service providers. The reforms flow from the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, and for the firms newly in scope they represent the most significant regulatory addition to practice management in a generation.

The timing is not gentle. AUSTRAC opened enrolment on 31 March 2026, and a firm that provides a designated service must enrol before 29 July 2026. It must also appoint an AML/CTF compliance officer and notify AUSTRAC of that appointment by the later of 29 July 2026 or 14 days after enrolment. Those dates are not aspirational milestones. They are statutory deadlines that have either just passed or are passing as many firms are still working out whether they are captured at all. This guide is for the practice principal, compliance lead or operations manager who now has to stand up a working AML/CTF program across a book of clients without hiring a compliance department to do it.

The reframing that makes this manageable is to recognise what the obligation actually is underneath the acronyms. Tranche 2 is a data-collection, verification, screening and record-keeping regime, repeated for every client who receives a designated service, sustained continuously, and provable to a regulator on demand. That is a workflow and data problem far more than it is a legal one, and it is precisely the kind of high-volume, repeatable, easy-to-neglect discipline that disciplined automation handles well.

What Actually Triggers an Obligation

The single most important thing for an accounting firm to get right is scope, because Tranche 2 does not capture everything an accountant does. The obligations attach to specific designated services, not to the profession as a whole. General tax return preparation, standard bookkeeping and routine advisory work are not, on their own, designated services and do not by themselves bring a firm into the regime. What brings a firm in is providing services of a kind the legislation designates as higher risk for money laundering, such as assisting a client to plan or execute the buying or selling of a body corporate or real estate, managing a client's money, accounts or assets, or helping to create, operate or manage a company or trust or acting as a formation agent.

Getting this boundary right is the whole ballgame, because it determines both whether a firm must enrol and which clients trigger obligations. A firm that assumes it is entirely out of scope when it provides even one designated service exposes itself to serious regulatory risk. A firm that assumes every engagement is captured buries itself in compliance work it does not owe. The correct answer is specific to the mix of services a firm actually provides, and it should be confirmed against AUSTRAC's guidance and, where needed, legal advice rather than assumed.

Are You Likely Captured by Tranche 2

Does your firm provide any of these services to clients?
Managing client money, accounts or assets
→ Likely a designated service, confirm and enrol
Assisting with buying or selling a business or real estate
→ Likely a designated service, confirm and enrol
Creating or managing companies or trusts
→ Likely a designated service, confirm and enrol
Only tax returns, bookkeeping and general advice
→ Generally not captured on those services alone

Once a firm is in scope, the core obligations are recognisable to anyone who has dealt with a bank's onboarding: know your customer through customer due diligence, understand the nature and purpose of the relationship, conduct ongoing due diligence on the relationship, screen customers against sanctions and politically exposed person lists, report suspicious matters to AUSTRAC, and keep records for seven years. Wrapping all of it is the requirement to maintain a documented, risk-based AML/CTF program and to have an accountable compliance officer overseeing it. The obligations are not conceptually complex. What makes them heavy is the volume, the repetition and the standard of evidence, all sustained across an entire client book without lapse.

Why This Breaks Manual Processes

The instinct in many firms will be to handle Tranche 2 the way small firms handle most new compliance: a template, a checklist, a diligent staff member and good intentions. That approach fails here, and it fails predictably, because the regime is built on volume and consistency rather than one-off effort. Customer due diligence has to be collected and verified for every client receiving a designated service, screening has to be repeated as sanctions and politically exposed person lists change, ongoing monitoring has to actually be ongoing, and every step has to be recorded to a standard that survives regulatory scrutiny years later. A manual system holds for a handful of clients and quietly collapses at scale, usually invisibly, until an audit or an incident exposes the gaps.

Where Manual AML Compliance Falls Over

Metric
Manual and Ad Hoc
Structured and Automated
Improvement
Identity verificationEmailed documents, retypedStructured capture and verification workflowConsistent
Sanctions and PEP screeningDone once, rarely repeatedScreened and re-screened automaticallyOngoing
Ongoing due diligenceForgotten after onboardingScheduled and promptedSustained
Record-keepingScattered across systemsCentralised, seven-year retentionProvable
Suspicious activityDepends on who noticesFlagged for human assessmentSystematic

There is a sharper edge to getting this wrong than mere inefficiency. AUSTRAC is an active enforcement regulator with a record of very large penalties against major institutions for AML/CTF program failures. The reforms extend that enforcement reach to professional services, and while a small accounting firm is not a major bank, the obligation to have a genuine, working, risk-based program is real and the consequences of a hollow one are serious. Equally serious is the tipping-off risk: a firm must not alert a client that a suspicious matter report has been or may be made about them. That constraint shapes how any workflow must be built, because the system has to route a concern to the compliance officer discreetly rather than surfacing it in a way a client could see. Compliance here is not a form-filling exercise. It is an operational capability that has to work quietly and hold up under examination.

Where AI Genuinely Helps, and Where a Human Must Decide

The productive way to apply AI to Tranche 2 is to let it carry the volume and the vigilance while keeping every consequential decision with an accountable human. The regime is full of work that is repetitive, continuous and unforgiving of inconsistency, which is exactly what automation is good at, and it is also full of judgements that carry legal weight and personal accountability, which automation must never make on its own.

The AML Compliance Workflow, Automated Where It Should Be

Collect
Customer due diligence data captured in a structured, consistent form
Screen
Sanctions and PEP checks run and repeated as lists change
Monitor
Ongoing due diligence and unusual patterns flagged for review
Record
Every step retained to the seven-year evidentiary standard

Consider each step. Collection is where AI removes the most friction, turning the scramble of emailed documents and retyped details into a structured intake that captures customer due diligence data consistently and completely, with nothing missing because a field was skipped. Screening is a natural fit for automation, because checking a client against sanctions and politically exposed person lists, and then re-checking as those lists change, is precisely the kind of tireless, repetitive vigilance that software sustains and humans do not. Ongoing monitoring benefits from automation for the same reason, because the obligation is continuous and a system that watches every relationship in the background will surface an unusual pattern that a busy accountant would miss. Record-keeping is where automation quietly earns its place, assembling a complete, retrievable, seven-year audit trail as a by-product of the work rather than a separate chore.

The line that must not be crossed is decision-making. AI can flag a transaction as unusual, but the decision that a matter is genuinely suspicious and reportable is a human judgement that belongs to the compliance officer, because that decision carries legal weight and personal accountability under the Act. AI can assemble the information behind a risk rating, but the rating that shapes how a firm treats a client is a professional decision, not an algorithmic output. AI can draft and maintain the documentation of the AML/CTF program, but the program itself must reflect the firm's real, considered assessment of its risks. The design principle is the same one that governs any responsible automation: the machine handles the collection, the screening, the monitoring and the record, and the accountable human makes every call that matters. We set out how to draw that boundary deliberately in our guide to AI agent governance, data access and human override, and nowhere is it more important than here.

Building It Into the Practice, Not Bolting It On

The firms that handle Tranche 2 well will be the ones that treat it as part of client onboarding and ongoing service rather than a separate compliance silo. An accounting practice already collects a great deal about its clients, already onboards them, and already maintains records. The efficient path is to extend those existing workflows so that customer due diligence, screening and monitoring happen inside the systems the firm already runs, rather than standing up a parallel process that staff have to remember to feed. That integration is where the practical gains come from, because compliance that lives inside the natural flow of work gets done, and compliance that sits in a separate system gets skipped under pressure.

This is the same discipline that makes any firm-wide automation pay off. The reconciliation, data-hygiene and consolidation work that underpins reliable AI automation for accounting firms and tax compliance is the same foundation that makes AML monitoring practical, because a firm with clean, connected client data can screen and monitor that data far more easily than one whose records are scattered across disconnected tools. A practice that has already modernised how it handles Xero and MYOB automation is well placed to absorb Tranche 2, because much of the underlying data plumbing already exists.

Where the Effort Goes, Manual vs Automated

Manual: onboarding due diligence per clientHours, every engagement
Manual: periodic re-screening across the bookRarely done at all
Automated: structured intake and screeningMinutes, consistent
Automated: continuous monitoring and audit trailRuns in the background

It is worth being clear-eyed about what automation does and does not do. It does not make a firm compliant by itself, it does not replace the compliance officer, and it does not remove the need for the firm to genuinely understand its money-laundering risk. A tool that produces a tidy AML report while the underlying program is hollow is a liability, not an asset, because a regulator will look straight through the report to whether the firm actually assessed and managed its risk. The purpose of the technology is to make the real obligation sustainable at the scale of a whole client book, so that the accountable humans spend their time on judgement rather than on data collection and manual screening. This is the same reason financial-crime detection increasingly leans on automation across banking and telecommunications, a shift we examine in our look at the Scams Prevention Framework and AI detection.

What to Do Now

Given where the deadlines sit, the immediate priority is certainty about scope and enrolment. A firm that has not yet determined whether it provides a designated service should do so urgently, because enrolment, compliance officer appointment and notification obligations are already live. From there, the work is to stand up a program that is genuine and a workflow that is sustainable.

Standing Up a Working AML/CTF Capability

1
Immediately
Confirm scope and enrol
Determine designated services, enrol with AUSTRAC, appoint and notify the compliance officer
2
First weeks
Document the program
Build a genuine risk-based AML/CTF program reflecting the firm's real risk
3
Next quarter
Automate the workflow
Structured due diligence intake, automated screening, continuous monitoring, central records
4
Ongoing
Monitor and prove
Re-screen as lists change, keep seven-year records, review the program regularly

The strategic read for a practice principal is that Tranche 2 is a capability the firm now has to own, and the choice is only whether to build it as a manual burden or an automated one. Handled manually, it is a permanent drag on chargeable time and a standing source of risk, because the volume and continuity it demands exceed what checklists and goodwill can sustain. Handled with disciplined automation, it becomes a quiet background capability that collects, screens, monitors and records reliably, freeing the firm's accountable people to make the judgements the law actually reserves for them. The obligation is not optional and the deadlines have arrived. The firms that come through it well will be the ones that built the workflow properly the first time, and treated AML not as paperwork bolted onto the practice but as a data discipline woven into how the practice already works. That same discipline is what underpins the firm's readiness for every other 2026 change bearing down on the profession, from AML to the Division 296 super tax.

Related Reading

This article is general information, not legal or compliance advice. AML/CTF obligations depend on the specific services your firm provides and your assessment of risk. Confirm your obligations with AUSTRAC guidance and qualified advice.