Business Strategy

AML/CTF Tranche 2: AI for Gatekeeper Firms

AML/CTF Tranche 2: AI for Gatekeeper Firms

Abstract visualisation of identity verification and financial transaction monitoring data flows

On 1 July 2026, the largest expansion of Australia's anti-money laundering regime in two decades takes effect. Under the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, the "Tranche 2" reforms bring real estate agents, conveyancers, legal practitioners, accountants, trust and company service providers, and dealers in precious metals and stones into the regime regulated by AUSTRAC. Government estimates put the number of newly captured businesses at roughly 80,000 to 90,000.

For most of these firms, this is the first time they have ever faced a financial-crime regulator. Enrolment opened on 31 March 2026, obligations commence on 1 July 2026, and the final enrolment and registration window closes on 29 July 2026, 28 days after commencement. If you run a midsize professional services firm, the question is no longer whether you are in scope. It is whether your customer due diligence, transaction monitoring, and reporting processes can carry the new load without burying your fee earners in administrative work.

This guide maps the obligations to a practical operating model, then shows where AI genuinely reduces effort and risk, and where it quietly adds audit exposure if you let it run unsupervised.

Why Tranche 2 is different from anything your firm has done before

Australia introduced its AML/CTF regime in 2006, but it deliberately deferred coverage of the so-called "gatekeeper" professions. Tranche 2 closes that gap because lawyers, accountants, and real estate agents sit at the exact points where illicit funds enter the legitimate economy: property settlements, company formations, trust structures, and the handling of client monies.

The practical consequence is that providing a "designated service" now triggers obligations regardless of how small the matter is. A conveyancing file, an SMSF setup, a company incorporation, or a real estate sale can each be a designated service. Once you provide one, you are a reporting entity.

The core obligations fall into five buckets:

  • Enrolment and registration with AUSTRAC before you provide designated services.
  • An AML/CTF program: documented policies, procedures, and controls, including a money laundering and terrorism financing risk assessment for your business.
  • Customer due diligence (CDD), also called know your customer (KYC): identifying and verifying customers, beneficial owners, and politically exposed persons, plus ongoing due diligence across the life of the relationship.
  • Reporting: suspicious matter reports (SMRs), threshold transaction reports (TTRs) for cash transactions of AUD $10,000 or more, and international funds transfer reporting where relevant.
  • Record keeping for the periods specified in the legislation, in a form that survives an AUSTRAC inspection.

If your firm has built its compliance posture around the Privacy Act and professional conduct rules, Tranche 2 adds an entirely separate regulatory axis. The two interact, because AML/CTF requires you to collect and retain more personal information, which then becomes a privacy and security obligation in its own right.

Are you actually in scope?

Many firms assume they are exempt because they "do not handle client money". That is not the test. The test is whether you provide a designated service as defined in the legislation. Use the guide below as a first filter, then confirm against current AUSTRAC guidance and your own legal advice.

Tranche 2 Scope Check

Does your firm provide any of these services to clients?
Real estate sales, leasing or property settlements
→ In scope: real estate sector obligations apply
Company formation, trusts, or acting as nominee director
→ In scope: trust and company service provider obligations
Legal services involving property, money handling or structures
→ Likely in scope: assess each designated service
Accounting, tax structuring or managing client funds
→ Likely in scope: assess each designated service
Pure advisory with no designated services
→ May be out of scope: document the assessment anyway

The critical discipline is documenting the scope assessment for every service line, because AUSTRAC expects firms to be able to show their reasoning, not just their conclusion. This is where many midsize firms underestimate the work: scoping is not a one-off. New service lines, new client types, and new jurisdictions all reopen the question.

The compliance timeline working backwards from 1 July

With obligations live from 1 July 2026 and the enrolment window closing on 29 July 2026, the realistic planning horizon is now measured in weeks, not quarters. The phases below assume a firm that is starting close to scratch.

Tranche 2 Readiness Phases

1
Phase 1
Scope and enrol
Confirm designated services, enrol and register with AUSTRAC, appoint an AML/CTF compliance officer
2
Phase 2
Risk assessment
Document the ML/TF risk assessment across customer types, services, channels and jurisdictions
3
Phase 3
Build the program
Write the AML/CTF program, CDD procedures, and reporting workflows; integrate with your practice systems
4
Phase 4
Operate and monitor
Run CDD on new and existing clients, monitor transactions, file SMRs and TTRs, retain records

Firms that already have mature client onboarding can compress Phases 1 to 3, but Phase 4 is permanent. It is the steady-state operating cost that determines whether compliance becomes a drag on billable hours or runs quietly in the background. That steady-state is exactly where AI earns its place.

Where AI genuinely reduces the burden

AML/CTF compliance is, at its core, a document-heavy, repetitive, exception-driven workflow. That profile is well suited to AI assistance, provided a qualified person stays accountable for every regulated decision. The four highest-value applications are below.

1. Customer due diligence and identity verification

Onboarding a client under Tranche 2 means collecting identity documents, verifying them, identifying beneficial owners, screening against sanctions and politically exposed persons lists, and forming a risk rating. Done manually, this is 30 to 90 minutes per client for a midsize firm, and it is error-prone under deadline pressure.

AI streamlines the mechanical steps: extracting data from identity documents, cross-checking it against the application, flagging mismatches, and pre-populating the customer risk profile. The verified data then flows into your practice management system rather than living in a spreadsheet.

AI-Assisted Customer Due Diligence

Collect
Client submits ID and entity documents
Extract
AI reads documents, structures the data
Screen
Check sanctions, PEP and adverse media lists
Risk rate
Draft a risk rating for officer review
Decide
Compliance officer approves or escalates

The final step is non-negotiable. AI can draft the risk rating, but a human with the right authority must approve it, and the system must record who approved what and when. This is the same human-override principle we apply across our AI governance framework.

2. Ongoing transaction and behaviour monitoring

Tranche 2 is not a one-time check at onboarding. You must monitor the relationship for activity inconsistent with what you know about the client. For a firm processing hundreds of matters a year, manual monitoring simply does not happen consistently. AI monitoring can surface anomalies, such as a sudden change in transaction size, unusual structuring around the $10,000 cash threshold, or a settlement that does not match the client's stated profile, and route them to a human for assessment.

3. Suspicious matter report preparation

An SMR must be lodged within strict timeframes once a suspicion is formed. The bottleneck is rarely the decision to report. It is assembling the narrative, the supporting records, and the chronology into AUSTRAC's required format. AI can draft the factual narrative from the matter file, leaving the compliance officer to verify accuracy and exercise the actual judgement about suspicion. The judgement stays human; the typing does not.

4. Record keeping and audit readiness

Every regulated decision must be retained in a defensible form. AI helps by automatically indexing CDD records, linking them to matters, and maintaining a complete, timestamped trail, the kind of automated compliance reporting infrastructure that turns an AUSTRAC inspection from a fire drill into a query.

Manual versus AI-assisted: the realistic comparison

The point of automation here is not to remove the compliance officer. It is to let one officer supervise the volume that Tranche 2 creates, instead of hiring three.

Onboarding and Monitoring: Manual vs AI-Assisted

Metric
Manual Process
AI-Assisted, Human-Approved
Improvement
Time per client onboarding45-90 mins10-20 mins~75%
Document data entry errorsCommonFlagged at sourceMaterial
Ongoing monitoring coverageAd hocContinuousFull coverage
SMR drafting time2-4 hours30-60 mins~70%
Audit trail completenessVariableComplete by defaultDefensible

The numbers above are illustrative ranges based on typical professional services onboarding workloads, not a specific client result. Your actual figures depend on matter mix and current process maturity. Run a short time-and-motion study on your own onboarding before you size the investment.

The cost picture for a midsize firm

For a firm processing a meaningful volume of designated services, the choice is rarely "automate or not". It is "automate or staff up". The economics typically favour automation once volume passes a few hundred onboardings a year.

Indicative Annual Impact: 600 Onboardings/Year

Onboarding time saved (~40 mins each)~400 hours
Monitoring and SMR drafting saved~150 hours
Avoided cost of additional compliance headcountSignificant
Reduced risk of late or missed reportsLower penalty exposure

These figures are a planning framework, not a guarantee. The genuine value is dual: hours returned to fee earners, and a lower probability of the kind of process failure that leads to enforcement action. AUSTRAC has shown in the gaming and remittance sectors that it pursues civil penalties at scale, so the downside of weak controls is not theoretical.

The traps: where AI adds risk instead of removing it

AI is an assistant, not a decision maker, and Tranche 2 has three specific failure modes worth calling out.

Legal professional privilege. For law firms, AML/CTF obligations interact with privilege in ways that demand care. Any AI system touching matter files must respect privilege boundaries and the firm's professional conduct rules. This is one reason firms with sensitive data often choose private AI infrastructure over public AI tools, keeping data inside their own controlled environment.

Data sovereignty and security. Tranche 2 forces you to collect more sensitive personal information, which raises the stakes on where it is stored and who can reach it. Sending client identity documents to an offshore AI service may breach both privacy expectations and your own client agreements. The safer pattern is to keep regulated data onshore, which is the central argument of our data sovereignty guide and a recurring theme in our cyber security requirements for Australian businesses.

The accountability gap. An AI that auto-approves a client or auto-decides not to report is a liability. The AUSTRAC obligation sits with the reporting entity and its officers, not the vendor. Every workflow must keep a qualified human in the approval loop for any regulated decision, with the rationale recorded. Treat AI output as a draft to be checked, never as a determination.

If you are evaluating tools, the questions in our AI vendor selection guide apply directly: where is data processed, who can access it, how is the audit trail maintained, and can the vendor support an AUSTRAC inspection.

A pragmatic implementation sequence

The firms that will handle 1 July most calmly are not the ones that bought the most software. They are the ones that mapped their designated services, wrote a clear program, and then automated the repetitive parts of that program rather than automating chaos.

A sensible sequence: enrol and appoint your compliance officer first; complete and document the risk assessment; design the CDD and reporting workflows on paper; only then layer AI onto the steps that are genuinely repetitive and high volume. Integrating AML workflows into the systems your team already uses, your practice management and document systems, is usually a system integration and process automation exercise rather than a rip-and-replace project.

Professional services firms looking at the broader operational picture often find the same automation foundation supports adjacent work, which is why we treat AML readiness as part of a wider professional services automation strategy rather than a standalone compliance bolt-on.

What AUSTRAC expects to see in practice

Newly captured firms often ask what "good" looks like, because they have no history with the regulator to draw on. AUSTRAC's published guidance and its enforcement record in already-regulated sectors point to a consistent set of expectations.

First, your AML/CTF program must be genuinely risk based, not a generic template downloaded and rebranded. The regulator expects the program to reflect your specific client base, services, delivery channels, and the jurisdictions you deal with. A suburban conveyancer and a national accounting firm should not have identical risk assessments. AI can help here by analysing your actual matter data to surface the risk patterns that should inform the assessment, but the judgement about risk appetite and controls remains a human, board-level decision.

Second, the regulator expects evidence that the program is operating, not merely that it exists. That means records showing CDD was actually performed, that monitoring actually ran, and that suspicious matters were actually escalated and assessed. A program that lives in a PDF but is not reflected in day-to-day records is a red flag. This is the single strongest argument for automating the evidence trail: a system that logs every CDD decision, every screening result, and every escalation produces the proof of operation that an inspection demands.

Third, the regulator expects timely reporting. SMRs and TTRs have legislated timeframes, and late or missing reports are a common enforcement trigger. The bottleneck is rarely awareness; it is the manual effort of assembling and lodging the report under time pressure. Reducing that friction with AI-assisted drafting directly lowers your risk of a timing breach.

Common scoping mistakes to avoid

Three errors recur among firms approaching Tranche 2 for the first time. The first is assuming a whole firm is either "in" or "out", when in reality scope is assessed service by service. The second is treating the assessment as a one-time event rather than a living judgement that must be revisited when service lines change. The third is conflating AML/CTF obligations with existing professional conduct rules and assuming compliance with one satisfies the other. They are separate regimes with separate regulators, and both must be met. Documenting your reasoning at each step is what protects you if the regulator later questions a decision.

The bottom line

Tranche 2 is not a temporary compliance project. From 1 July 2026 it is a permanent operating obligation for tens of thousands of Australian firms that have never reported to AUSTRAC before. The administrative load is real, but most of it is repetitive document and data work that AI handles well under human supervision. The firms that come out ahead will use AI to absorb the volume while keeping every regulated decision in qualified human hands, and will keep their clients' sensitive data onshore and auditable.

Get the program right first. Automate the parts that are genuinely mechanical. Keep a human accountable for every report. Do that, and Tranche 2 becomes a manageable process rather than a tax on your billable hours.


Related reading

Ready to make Tranche 2 a background process rather than a burden? Explore our process automation services or learn how private AI infrastructure keeps regulated client data onshore and under your control.