AML Tranche 2 Compliance: Essential Steps for Australian Legal Firms (Updated July 2026)

Your ongoing compliance checklist under the AML/CTF Rules

Mastering AML Tranche 2 Compliance Essential Steps for Australian Legal Firms

Detailed Obligations and Compliance Steps for the Australian Legal Industry (Updated July 2026)

AML Tranche 2 is now in effect. From 1 July 2026, Australian law firms are legally obligated under the AML/CTF Rules 2025. This checklist covers the detailed obligations and practical steps your firm needs to follow to stay compliant and manage ongoing risk.

AML Tranche 2 came into full effect on 1 July 2026. If your firm is enrolled and your program is in place, use this checklist to confirm your obligations are being met. If your firm still has gaps, the steps below remain the same — the compliance requirements do not change because the deadline has passed. Speak to the KMTech team →

FREE GUIDE

AML Tranche 2 IS NOW LAW

AML Tranche 2: Your Ongoing Compliance Guide

Our practical guide covers every obligation under the AML/CTF Rules 2025: for law firms, accounting practices, and financial services. 16 pages. No fluff.

AUSTRAC enrolment and what comes next

CDD, SMR and TTR obligations explained

Ongoing compliance checklist

AML/CTF program requirements

AML software comparison

Cybersecurity obligations under the new rules

No cost. Updated July 2026.

Key Dates to Remember

  • 31 March 2026: AUSTRAC enrolment deadline (now passed).
  • 1 July 2026: Full compliance commenced. All AML/CTF obligations are now in effect.
  • From 1 July 2026 onwards: Ongoing compliance, AUSTRAC monitoring and enforcement period.

Navigating the New AML Tranche 2 Regulations: A Guide for CIOs and Senior Partners in Legal Firms

The AML Tranche 2 compliance deadline is 1 July 2026. From that date, Australian legal firms providing designated services are legally required to have their AML/CTF programs in place, customer due diligence procedures operational, and staff trained and compliant.

The Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) Amendment Act 2024, commonly known as AML Tranche 2, is now law. This is not preparation time. This is implementation time.

Read the complete guide: AML Tranche 2 Obligations for Australian Firms

Conduct a Risk Assessment

Legal firms must adhere to stringent Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) obligations to ensure compliance and mitigate risks. One of the primary responsibilities is conducting a comprehensive risk assessment. This involves identifying and understanding the specific money laundering and terrorism financing risks that the firm may encounter. It is crucial to document these risk assessments meticulously and review them regularly to stay updated with any changes in the risk landscape.

Key Action Steps:

    1. Conduct a Comprehensive Risk Assessment: Identify and understand the money laundering and terrorism financing risks specific to your firm.
    2. Document the Risk Assessment: Ensure all findings and assessments are thoroughly documented.
    3. Regular Review: Periodically review and update the risk assessment to reflect any changes in the risk environment.

Implementing an Effective AML/CTF Program

Develop and implement a tailored AML/CTF program. This program should be customised to fit the firm’s size, nature, and complexity. It is essential that the program includes two key components: Part A, which focuses on general risk management, and Part B, which covers customer identification and verification.

Key Action Steps:

  1. Develop a Tailored AML/CTF Program: Create a program that aligns with the specific size, nature, and complexity of your firm.
  2. Include Part A (General Risk Management): Ensure the program addresses overall risk management strategies.
  3. Include Part B (Customer Identification and Verification): Incorporate procedures for identifying and verifying customers to prevent money laundering and terrorism financing.

Strengthening Customer Due Diligence (CDD) Practices

Embed a robust Customer Due Diligence (CDD) procedures to comply with Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) regulations. This involves establishing effective Know Your Customer (KYC) processes for customer identification and verification. Additionally, firms should conduct ongoing monitoring of customer transactions to detect any suspicious activities. For higher-risk customers, enhanced due diligence (EDD) measures are necessary to ensure thorough scrutiny.

Key Action Steps:

  1. Implement KYC Procedures: Establish comprehensive processes for customer identification and verification.
  2. Ongoing Monitoring: Continuously monitor customer transactions to identify and report suspicious activities.
  3. Enhanced Due Diligence (EDD): Apply additional scrutiny and verification for higher-risk customers to mitigate potential risks.

Understanding Reporting Obligations for Legal Firms

Legal firms must fulfill several critical reporting obligations to comply with Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) regulations. These obligations ensure that firms actively contribute to the detection and prevention of financial crimes.

Key Action Steps:

  1. Report Suspicious Matters: report any suspicious matters to the appropriate authorities, such as AUSTRAC in Australia. Suspicious Matter Reports (SMRs) should be submitted within 24 hours if related to terrorism financing, or within three business days for other suspicions.
  2. Lodge Threshold Transaction Reports (TTRs): Firms must lodge TTRs for any transactions involving physical currency of AUD 10,000 or more (or the foreign currency equivalent). These reports must be submitted within 10 business days of the transaction.
  3. Submit International Funds Transfer Instructions (IFTIs): For cross-border transactions, firms must submit IFTI reports. These reports cover instructions to transfer funds into or out of Australia and must be submitted within 10 business days of the transfer instruction.

Effective Record Keeping

Maintaining accurate and comprehensive records is a critical component of complying with Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) regulations. Legal firms must keep records of customer identification, transaction records, and risk assessments for a specified period, typically seven years. This practice not only ensures compliance but also aids in managing risks and supporting investigations if needed.

Key Action Steps:

  1. Maintain Customer Identification Records: Keep detailed records of all customer identification procedures. This includes copies of identification documents and verification processes.
  2. Transaction Records: Document all transactions related to designated services provided to customers. This includes transaction details, amounts, dates, and any relevant correspondence.
  3. Risk Assessments: Regularly update and store records of risk assessments, including the methodologies used and the findings.

Tips for Effective Record Keeping:

  • Use Reliable Software: Implement AML/CTF compliance software that offers secure storage, easy retrieval, and audit capabilities. Some popular options include:
    • ComplyAdvantage: Provides real-time AML risk data and compliance solutions.
    • AML360: Offers comprehensive AML compliance management, including risk assessments and transaction monitoring.
    • Thomson Reuters CLEAR: Facilitates due diligence and investigation with extensive data and analytics tools.
  • Regular Audits: Conduct periodic audits of your records to ensure they are complete, accurate, and up-to-date.
  • Secure Storage: Store records securely, whether in hard copy or electronic format, to prevent unauthorised access and ensure data integrity.
  • Training: Ensure staff are trained on record-keeping requirements and the use of compliance software to maintain consistency and accuracy.

Appointing a Compliance Officer

Appoint a dedicated Compliance Officer. This individual plays a crucial role in ensuring the firm adheres to all AML/CTF regulations and mitigates associated risks.

Who is the Best Fit?

The ideal candidate for the Compliance Officer role should be at a management level and possess a strong understanding of AML/CTF laws and regulations. They should have excellent analytical skills, attention to detail, and the ability to communicate effectively with both internal and external stakeholders.

Key Responsibilities:

  1. Overseeing the AML/CTF Program: The Compliance Officer is responsible for developing, implementing, and maintaining the firm’s AML/CTF program. This includes ensuring that the program is tailored to the firm’s size, nature, and complexity.
  2. Conducting Risk Assessments: Regularly assess the firm’s exposure to money laundering and terrorism financing risks, and update the risk assessment as necessary.
  3. Ensuring Compliance: Monitor and ensure the firm’s compliance with all relevant AML/CTF regulations. This includes staying updated with any changes in legislation and adjusting the firm’s policies and procedures accordingly.
  4. Training and Awareness: Provide ongoing training to staff on AML/CTF obligations and best practices. Ensure that all employees are aware of their responsibilities and know how to identify and report suspicious activities.
  5. Reporting: Prepare and submit required reports, such as Suspicious Matter Reports (SMRs), Threshold Transaction Reports (TTRs), and International Funds Transfer Instructions (IFTIs), to the appropriate authorities.
  6. Liaison with Authorities: Act as the primary point of contact between the firm and regulatory bodies, such as AUSTRAC in Australia. Ensure timely and accurate communication with these authorities.

By appointing a qualified Compliance Officer, legal firms can ensure robust oversight of their AML/CTF program, maintain compliance with legal obligations, and effectively mitigate the risks.

Training and Awareness

Providing regular training and awareness programs is essential for legal firms to ensure that all relevant staff understand their Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) obligations. Effective training helps employees identify and report suspicious activities, thereby enhancing the firm’s overall compliance framework.

Key Components of an Effective Training Program:

  1. Comprehensive Curriculum:
    • AML/CTF Regulations: Educate staff on the latest AML/CTF laws and regulations, including their specific obligations under the AML/CTF Act.
    • Risk Awareness: Highlight the types of money laundering and terrorism financing risks the firm may face and the consequences of these risks.
    • Identification and Reporting: Train staff on how to identify suspicious activities and transactions, and the procedures for reporting them to the appropriate authorities.
  2. Regular Updates:
    • Ongoing Training: Conduct regular training sessions to keep staff updated on new regulations, emerging risks, and changes in internal policies.
    • Refresher Courses: Provide periodic refresher courses to reinforce key concepts and ensure continuous awareness.
  3. Practical Scenarios:
    • Case Studies: Use real-life case studies and examples to illustrate common money laundering and terrorism financing techniques.
    • Interactive Sessions: Incorporate interactive elements such as quizzes, role-playing, and group discussions to engage staff and enhance learning.
  4. Tailored Training:
    • Role-Specific Training: Customise training programs based on the roles and responsibilities of different staff members. For example, front-line staff may need more focus on customer due diligence, while senior management may require training on risk management and compliance oversight.
    • E-Learning Modules: Utilise e-learning platforms to provide flexible, self-paced training options. AUSTRAC offers several e-learning modules that can be integrated into your training program.
  5. Documentation and Record-Keeping:
    • Training Records: Maintain detailed records of all training sessions, including attendance, topics covered, and assessment results. This helps demonstrate compliance and track the effectiveness of the training program.
    • Feedback Mechanism: Implement a feedback system to gather input from staff on the training program and identify areas for improvement.

Implementation Steps:

  1. Appoint a Training Coordinator: Designate a compliance officer or training coordinator to oversee the development and delivery of the AML/CTF training program.
  2. Develop Training Materials: Create comprehensive training materials, including presentations, handouts, and e-learning modules, tailored to the firm’s specific needs.
  3. Schedule Regular Sessions: Plan and schedule regular training sessions, ensuring all relevant staff members participate.
  4. Utilise Technology: Leverage technology to deliver training, such as webinars, online courses, and interactive e-learning platforms.
  5. Evaluate and Improve: Regularly evaluate the effectiveness of the training program through assessments and feedback, and make necessary adjustments to improve its impact.

Conducting Regular Independent Reviews

Regular independent reviews or audits are essential for assessing the effectiveness and compliance of a legal firm’s Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) program. These reviews help identify any gaps or weaknesses in the program and ensure that it meets all legal requirements.

Key Components of an Independent Review:

  1. Objective Assessment:
    • Impartial Evaluation: An independent review provides an unbiased assessment of the AML/CTF program. This can be conducted by an external auditor or an internal auditor who was not involved in developing or maintaining the program.
    • Scope of Review: The review should cover all aspects of the AML/CTF program, including risk assessments, customer due diligence, transaction monitoring, and reporting procedures.
  2. Methodology and Planning:
    • Risk-Based Approach: The review should be tailored to the firm’s specific risk profile, considering factors such as the size, nature, and complexity of the business.
    • Comprehensive Testing: Use a combination of sampling, analytical procedures, and detailed testing to evaluate the program’s effectiveness.
  3. Regular Frequency:
    • Scheduled Reviews: Conduct independent reviews at regular intervals, such as annually or biennially, depending on the firm’s risk exposure and regulatory requirements.
    • Ad-Hoc Reviews: Perform additional reviews when significant changes occur in the firm’s operations, risk profile, or regulatory environment.
  4. Reporting and Follow-Up:
    • Detailed Reporting: Prepare a comprehensive report detailing the findings, including any deficiencies or areas for improvement. The report should provide actionable recommendations to address identified issues.
    • Management Response: Ensure that senior management reviews the report and implements the recommended changes. Follow up on the implementation of these changes to verify their effectiveness.

Practical Implementation Steps:

  1. Engage Qualified Reviewers: Select experienced and independent reviewers who understand AML/CTF obligations and have no conflicts of interest.
  2. Prepare for the Review: Gather all relevant documentation, including policies, procedures, risk assessments, and transaction records. Ensure that staff are available to provide information and answer questions during the review.
  3. Conduct the Review: The reviewers will assess the AML/CTF program’s design and implementation, test its effectiveness, and identify any gaps or weaknesses.
  4. Report Findings: The reviewers will compile their findings into a detailed report, highlighting any deficiencies and providing recommendations for improvement.
  5. Implement Recommendations: Senior management should review the report, prioritise the recommendations, and develop an action plan to address the identified issues. Regularly monitor the implementation of these changes to ensure they are effective.

Enhancing Cyber Security Posture

Legal firms must prioritise upgrading their cyber security posture to protect sensitive customer information and financial data. This is not only crucial for safeguarding client trust but also for ensuring compliance with Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) requirements. Here’s a detailed look at how legal firms can enhance their cyber security measures:

Key Components of a Robust Cyber Security Posture:

  1. Data Protection Measures:
    • Encryption: Implement data encryption both at rest and in transit to protect sensitive information from unauthorised access.
    • Access Controls: Use strong access control mechanisms to ensure that only authorised personnel can access sensitive data. This includes role-based access controls and multi-factor authentication (MFA).
    • Regular Backups: Conduct regular backups of critical data to ensure recovery in case of data loss or ransomware attacks.
  2. Monitoring Systems:
    • Intrusion Detection and Prevention Systems (IDPS): Deploy IDPS to monitor network traffic for suspicious activities and potential threats.
    • Security Information and Event Management (SIEM): Utilise SIEM systems to collect and analyse security data from various sources, providing real-time insights and alerts on potential security incidents.
    • Regular Audits and Penetration Testing: Conduct regular security audits and penetration testing to identify and address vulnerabilities in the firm’s IT infrastructure.
  3. Compliance with AML/CTF Requirements:
    • Risk-Based Approach: Implement a risk-based approach to cyber security, aligning with AML/CTF regulations that require firms to assess and mitigate risks related to money laundering and terrorism financing.
    • Incident Response Plan: Develop and maintain an incident response plan to quickly and effectively respond to cyber security incidents, minimising potential damage and ensuring compliance with reporting obligations.
    • Employee Training: Provide regular training to staff on cyber security best practices and AML/CTF obligations. This includes recognising phishing attempts, securing devices, and understanding data protection protocols.

Practical Implementation Steps:

  1. Conduct a Cyber Security Audit: Start with a comprehensive audit of your current cyber security measures to identify gaps and areas for improvement.
  2. Upgrade Technology: Invest in advanced cyber security technologies such as firewalls, anti-virus software, and secure cloud solutions.
  3. Develop Policies and Procedures: Create detailed cyber security policies and procedures that outline the firm’s approach to data protection, access controls, and incident response.
  4. Engage Cyber Security Experts: Consider partnering with cyber security experts or firms that specialise in protecting legal practices. They can provide tailored solutions and ongoing support to enhance your security posture.
  5. Continuous Monitoring and Improvement: Implement continuous monitoring systems and regularly review and update your cyber security measures to adapt to evolving threats.

Conclusion

In today’s complex regulatory environment, legal firms must prioritise compliance with Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) obligations. By implementing comprehensive risk assessments, developing tailored AML/CTF programs, enhancing customer due diligence practices, and maintaining robust record-keeping, firms can effectively mitigate risks and ensure compliance. Appointing a dedicated Compliance Officer, conducting regular independent reviews, and upgrading cyber security measures further strengthen the firm’s defenses against financial crimes. Through continuous training and awareness programs, legal firms can empower their staff to identify and report suspicious activities, fostering a culture of compliance and vigilance. By taking these proactive steps, legal firms not only protect themselves and their clients but also contribute to the broader effort to combat money laundering and terrorism financing.

If your firm has gaps in its AML/CTF program or needs help with the technology controls that underpin compliance, speak to the KMTech team.

Related Stories

IT professional working in a security operations environment, representing the transition and ongoing evolution of the ACSC Essential Eight framework.

The Essential Eight Is Evolving, Not Disappearing

Around mid-2028: full retirement. The Essential Eight is expected to be retired as a whole at roughly the 24-month mark, with the cloud and operational technology chapters landing before then.

Person seated at a desk facing a large screen during a video conference, with text overlay reading “AI Compliance Frameworks.”

AI Compliance Frameworks

AI adoption is accelerating across Australian businesses, but so is regulatory scrutiny. From ethical use and data integrity to accountability and transparency, organisations can no longer afford a “move fast and hope for the best” approach to artificial intelligence.

The Evolution of Web Filtering | Modern Cyber Security Solutions

The Evolution of Web Filtering & Shadow AI Governance

This article explores how web filtering has changed, why older DNS‑based models are no longer sufficient, and what modern organisations need to control web, cloud, and AI‑driven risk effectively.

Want to be part of the crowd?

html