Governance Frame Australia — August 2026: After the Tranche 2 Enrolment Deadline
54aac838-9094-4de5-ac24-993672505cbc
Executive Summary: Australia’s expanded AML/CTF regime applies according to the designated services an entity provides and their geographical link to Australia—not merely the entity’s professional title. Businesses commencing newly regulated services on July 1, 2026 generally had to submit their AUSTRAC enrolment application by July 29, while also implementing an approved ML/TF risk assessment, operational AML/CTF policies, customer-due-diligence and suspicious-matter processes, personnel controls and governing-body oversight. Enrolment, compliance-officer designation and officer notification have related but distinct deadlines. Entities should preserve evidence showing how they scoped their services, approved and implemented their controls, trained relevant personnel and addressed residual risk.
Information reviewed through August 4, 2026. Originally staged as a June readiness issue; rewritten after the July 1 commencement and the July 29 enrolment-application window.
I. Exposure Vector
A mid-size conveyancing practice enrolled with AUSTRAC in late July. The partners treat the confirmation email as the finish line. The compliance officer is named on the enrolment form but has no written authority, no reporting line to the governing body, and no schedule for independent evaluation. Intake staff still open files on the strength of a driver’s licence photocopy. A jeweller down the street assumes every ring sale is now a designated service and over-builds a program; another jeweller assumes none of its sales are captured because “we are not a bullion dealer.”
Both patterns miss the institutional point. Tranche 2 is not an industry membership badge. It is a service-by-service perimeter with parallel administrative and substantive clocks.
On July 1, 2026, AUSTRAC announced that the new reporting regime was in force for businesses providing newly regulated designated services. Newly regulated sectors include real estate, conveyancing, legal services, accounting services, and dealers in precious metals, precious stones and related products. Core obligations include AML/CTF risk management, customer due diligence, suspicious-matter reporting and recordkeeping. AUSTRAC’s public guidance states that businesses commencing those newly regulated services on July 1 were required to apply for enrolment by July 29, 2026—the statutory pattern being an application within 28 days after commencing to provide a designated service. July 29 was the deadline to submit the enrolment application, not necessarily the date by which AUSTRAC completed enrolment processing. [1][2][9]
Coverage still turns on designated services with a geographical link to Australia. A law firm, accounting practice, real-estate business or jeweller is not automatically regulated because of its occupational label. Entities must map the services they actually provide against the legislative definitions and confirm the geographical-link requirement before asserting either “we are in” or “we are out.” [3][4][13]
For dealers, the scoping error cuts both ways. Newly regulated dealer services generally concern purchases or sales of precious metals, precious stones or specified products valued at A$10,000 or more where payment involves physical currency or virtual assets, including linked or apparently linked transactions. A dealer that does not accept physical currency or virtual assets for the relevant transactions may not provide that designated service. Value, payment method and linked-transaction rules—not the word “jeweller”—drive the analysis. [5]
Enrolment does not replace substantive compliance. The Act separately requires an ML/TF risk assessment and AML/CTF policies, procedures, systems and controls for managing money-laundering, terrorism-financing and proliferation-financing risks. An entity that enrolled on time without operable controls did not buy readiness; an entity that missed July 29 and continues to provide designated services without enrolment compounds administrative and substantive risk. Entities that commence designated services after July 1 remain on the rolling 28-day enrolment rule. [2][9]
II. Quantitative Context
There is no single “industry average fine” that substitutes for entity-specific exposure. The useful board frame is clocks, service lines and evidence gaps—not a false-precision national penalty average.
| Clock | Rule | Governance meaning |
|---|---|---|
| Obligation commencement | July 1, 2026 for newly regulated designated services | Risk assessment, AML/CTF policies, CDD, training, reporting and oversight duties are live [1][9] |
| Enrolment application (commenced July 1) | Generally by July 29, 2026 | Apply within 28 days after commencing a designated service; application ≠ completed enrolment [1][2] |
| Enrolment application (commenced later) | Generally within 28 days of starting | Ongoing rule for entities that begin designated services after July 1 [2] |
| Enrolment detail changes | Within 14 days | Keep AUSTRAC Online current [2] |
| Compliance-officer designation | If not designated when designated services commence, designate within 28 days | Distinct from enrolment and from AUSTRAC notification [6][9] |
| Compliance-officer notification | Notify AUSTRAC within 14 days of appointment; newly regulated entities generally by the later of July 29, 2026 or 14 days after enrolment | An entity applying on July 29 could have until about August 12 to complete notification [6] |
| Independent evaluation | At least once every three years; first evaluation subject to transitional timing | Mandatory under AML/CTF policies; written report to the governing body and relevant senior manager [7] |
| Scoping test | What it filters |
|---|---|
| Designated-service definition | Whether the entity’s actual work product is captured [3][9] |
| Geographical link to Australia | Whether the service has the required Australian nexus [4] |
| Dealer A$10,000 / cash or virtual-asset / linked-tx tests | Whether ordinary jewellery sales are in or out [5] |
| Remittance or virtual-asset registration overlay | Whether enrolment alone is enough, or registration also applies under staged transitional rules [2][8] |
A defensible governing-body pack separates: services confirmed in scope; services confirmed out of scope with rationale; enrolment status (on time / late / not yet commenced); residual gaps between approved policies and operable intake controls; and the next independent-evaluation milestone.
III. What Modern GRC Must Enforce
Governance architecture the Act actually requires
The draft question “is a board-approved AML/CTF program written and operable?” collapses two different duties. Under the current Act, a senior manager must approve the ML/TF risk assessment and the AML/CTF policies—including relevant updates. The governing body has a separate obligation to exercise appropriate ongoing oversight and take reasonable steps to ensure that the entity identifies, assesses, manages and mitigates its risks and complies with its obligations. Approval and oversight are related; they are not interchangeable labels. [9][10]
The compliance officer is likewise not a slide title. The officer must be at management level and have sufficient authority, independence and resources. Having an officer operational by July 1 was strong readiness practice. The outside legal structure is different: if the entity has not designated an officer when it commences providing designated services, it must do so within 28 days after commencement, and it must notify AUSTRAC within the applicable notification window. Designation and notification are separate clocks. [6][9]
Independent evaluation is not optional “where required.” AML/CTF policies must provide for regular independent evaluation of the compliance framework. Frequency must suit the entity’s nature, size and complexity, but evaluations must generally occur at least once every three years. Transitional provisions determine when a newly regulated entity’s first evaluation is due. The written evaluation report must be provided to the governing body and the relevant senior manager. [7][9]
Control translation
| Failure mode | What the regime requires | Prudent control response |
|---|---|---|
| “We are a law firm / accountant / jeweller, so we are automatically in (or out)” | Designated services + geographical link—not occupational titles [3][4][13] | Service-by-service scoping memo with out-of-scope rationale retained |
| Enrolment treated as readiness | Substantive risk assessment, policies, CDD and reporting remain mandatory [1][9] | Parallel workstreams: enrolment status and operable controls |
| “Board-approved program” as the only approval language | Senior-manager approval of risk assessment and policies; governing-body oversight of implementation and compliance [9][10] | Separate approval records and oversight minutes |
| Officer named only on the enrolment form | Designation, authority/independence/resources, and AUSTRAC notification on distinct clocks [6] | Written appointment; notification tracker; annual (or more frequent) officer report to the governing body |
| “All training completed before July 1” as a quoted universal deadline | Initial and ongoing role-based training for personnel whose functions are relevant to AML/CTF; PDD before relevant functions begin [11][12] | Train early enough for competent performance from commencement; retain role-based records |
| Generic “sanctions screening” | PEP assessment and targeted-financial-sanctions checks within CDD; enhanced CDD where risk requires [11] | CDD workflow: identification, beneficial ownership, PEP, targeted financial sanctions, enhanced escalation |
| CDD invented after the first awkward client | Initial CDD generally before providing a designated service, with limited exceptions; SMR triggers can arise on inquiry or proposal [9][11] | Intake playbooks that escalate suspicion before the entity agrees to provide the service |
| Ordinary jewellery sales assumed regulated (or never regulated) | A$10,000+, physical currency and/or virtual assets, linked transactions [5] | Threshold / payment-method / linked-tx testing before asserting dealer coverage |
| Remittance/VASP rules collapsed into ordinary Tranche 2 enrolment | Registration may apply in addition to enrolment; some virtual-asset obligations are staged [2][8] | Service-specific registration and transitional check before asserting a single July 1 timetable |
Do not overclaim
- Do not treat entire professions as automatically reporting entities.
- Do not equate enrolment application with completed enrolment or with an operable AML/CTF program.
- Do not collapse senior-manager approval and governing-body oversight into one phrase.
- Do not present “officer appointed before July 1” or “all training finished before July 1” as if those were the only statutory deadlines.
- Do not imply that every jewellery or precious-product sale is a designated service.
- Do not imply that every remittance or virtual-asset obligation followed an identical July 1 timetable.
- Keep this newsletter distinct from APRA CPS 230—different regulator, different perimeter.
Human-in-the-loop attestation before executive publication remains the institutional control: scoping and materiality of designated-service coverage are governed decisions, not headline labels.
IV. Verification Protocol
- Re-read AUSTRAC’s July 1, 2026 “new reporting regime” announcement for sectors, core obligations and the July 29 enrolment-application expectation. [1]
- Confirm enrolment guidance: 28-day application rule, 14-day detail-change rule, and when registration may apply in addition to enrolment. [2]
- Confirm designated-service and geographical-link tooling before asserting coverage of an entire profession. [3][4][13]
- For dealers, verify the A$10,000 / physical-currency / virtual-asset / linked-transaction tests. [5]
- Confirm Act and AUSTRAC governance pages: senior-manager approval (s 26P framework), governing-body oversight, compliance-officer designation and notification, independent evaluation at least every three years. [6][7][9][10]
- Confirm initial CDD timing, PEP and targeted-financial-sanctions checks, and enhanced CDD triggers. [11]
- For remittance and virtual-asset providers, check service-specific registration requirements and any staged transitional provisions. [2][8]
- Treat CPA Australia and law-society materials as secondary sector corroboration, not as substitutes for the Act or AUSTRAC. [12][13]
Key Takeaways
- July 1 started substantive obligations; July 29 was the enrolment-application hard date for new designated services commencing that day—not a substitute for the program.
- Entities that commence designated services later remain on the rolling 28-day enrolment rule; entities that missed July 29 should enrol immediately and document residual risk.
- Designated services—not job titles—determine whether Tranche 2 applies; dealers must still pass the value, payment-method and linked-transaction tests.
- Senior-manager approval, governing-body oversight, officer designation/notification and independent evaluation are related but distinct controls.
V. Sources & Citations
-
[1] AUSTRAC, New reporting regime now in force (July 1, 2026) https://www.austrac.gov.au/new-reporting-regime-now-force Announces the regime in force for newly regulated designated services; lists expanded sectors (including real estate, conveyancing, legal services, accounting, and precious stones and metals); summarises core obligations; states the July 29, 2026 enrolment-application expectation for services commencing July 1. Retrieved 2026-08-04.
-
[2] AUSTRAC, Enrol with us overview https://www.austrac.gov.au/new-austrac/enrol-us/enrol-us-overview Enrolment duties for designated services with a geographical link to Australia; apply within 28 days after commencing a designated service; notify enrolment-detail changes within 14 days; distinguishes ordinary enrolment from remittance / virtual-asset registration overlays. Retrieved 2026-08-04.
-
[3] AUSTRAC, Check if you may be regulated https://www.austrac.gov.au/new-austrac/check-if-you-may-be-regulated Designated-service and geographical-link analysis rather than occupational titles. Retrieved 2026-08-04.
-
[4] AUSTRAC, Geographical link requirement https://www.austrac.gov.au/new-austrac/geographical-link-requirement When a designated service has the required link to Australia. Retrieved 2026-08-04.
-
[5] AUSTRAC, Precious metals, stones and products designated services https://www.austrac.gov.au/new-austrac/designated-services-newly-regulated-entities/precious-metals-stones-and-products-designated-services A$10,000 threshold; physical-currency and/or virtual-asset payment conditions; linked or apparently linked transactions. Retrieved 2026-08-04.
-
[6] AUSTRAC, AML/CTF compliance officer https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/develop-your-amlctf-programs/step-1-establish-your-governance-framework/amlctf-compliance-officer Designate within 28 days of providing designated services if not already designated; notify AUSTRAC within 14 days of appointment; officer must have sufficient authority, independence and resources. Retrieved 2026-08-04.
-
[7] AUSTRAC, Step 5: Conduct an independent evaluation https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/develop-your-amlctf-programs/step-5-conduct-independent-evaluation Policies must provide for regular independent evaluation at least once every three years; written report to the governing body and relevant senior manager; transitional timing for first evaluation. Retrieved 2026-08-04.
-
[8] AUSTRAC, Virtual asset designated services https://www.austrac.gov.au/new-austrac/designated-services-newly-regulated-entities/virtual-asset-designated-services Service-specific registration and staged or deferred transitional arrangements for certain virtual-asset obligations. Retrieved 2026-08-04.
-
[9] Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (compilation effective July 1, 2026) https://www.legislation.gov.au/C2006A00169/latest/text Controlling source for enrolment (Part 3A), ML/TF risk assessment, AML/CTF policies, governing-body oversight, compliance officer, program approvals (including senior-manager approval), CDD and suspicious-matter reporting. Retrieved 2026-08-04.
-
[10] AUSTRAC, Senior manager https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/develop-your-amlctf-programs/step-1-establish-your-governance-framework/senior-manager Senior manager must personally approve the risk assessment, AML/CTF policies and updates. Retrieved 2026-08-04.
-
[11] AUSTRAC, Overview of initial customer due diligence; Enhanced customer due diligence; AML/CTF training; Personnel due diligence (PDD) https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/customer-due-diligence/initial-customer-due-diligence/overview-initial-customer-due-diligence https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/customer-due-diligence/enhanced-customer-due-diligence https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/personnel-due-diligence-and-training/amlctf-training https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/personnel-due-diligence-and-training/personnel-due-diligence-pdd Initial CDD timing; PEP and targeted-financial-sanctions checks; enhanced CDD triggers; role-based training; personnel due diligence before relevant functions begin. Retrieved 2026-08-04.
-
[12] CPA Australia, AML/CTF obligations factsheet for tranche 2 reporting entities (secondary corroboration) https://www.cpaaustralia.com.au/-/media/project/cpa/corporate/documents/public-practice/my-firm-my-future/compliance-and-governance/aml_ctf---obligations-factsheet-for-tranche-2-res.pdf Independent professional-body summary of timetable and governance structure; secondary to the Act and AUSTRAC guidance. Retrieved 2026-08-04.
-
[13] Law Society of New South Wales, Understanding designated services: when legal services trigger Tranche 2 AML/CTF obligations https://www.lawsociety.com.au/understanding-designated-services-when-legal-services-trigger-tranche-2-amlctf-obligations Sector interpretation explaining why only specified legal services are captured. Retrieved 2026-08-04.