← All briefings

Governance Frame Australia — August 2026: After the Tranche 2 Enrolment Deadline

54aac838-9094-4de5-ac24-993672505cbc

Executive Summary: Australia’s expanded AML/CTF regime applies according to the designated services an entity provides and their geographical link to Australia—not merely the entity’s professional title. Businesses commencing newly regulated services on July 1, 2026 generally had to submit their AUSTRAC enrolment application by July 29, while also implementing an approved ML/TF risk assessment, operational AML/CTF policies, customer-due-diligence and suspicious-matter processes, personnel controls and governing-body oversight. Enrolment, compliance-officer designation and officer notification have related but distinct deadlines. Entities should preserve evidence showing how they scoped their services, approved and implemented their controls, trained relevant personnel and addressed residual risk.

Information reviewed through August 4, 2026. Originally staged as a June readiness issue; rewritten after the July 1 commencement and the July 29 enrolment-application window.

I. Exposure Vector

A mid-size conveyancing practice enrolled with AUSTRAC in late July. The partners treat the confirmation email as the finish line. The compliance officer is named on the enrolment form but has no written authority, no reporting line to the governing body, and no schedule for independent evaluation. Intake staff still open files on the strength of a driver’s licence photocopy. A jeweller down the street assumes every ring sale is now a designated service and over-builds a program; another jeweller assumes none of its sales are captured because “we are not a bullion dealer.”

Both patterns miss the institutional point. Tranche 2 is not an industry membership badge. It is a service-by-service perimeter with parallel administrative and substantive clocks.

On July 1, 2026, AUSTRAC announced that the new reporting regime was in force for businesses providing newly regulated designated services. Newly regulated sectors include real estate, conveyancing, legal services, accounting services, and dealers in precious metals, precious stones and related products. Core obligations include AML/CTF risk management, customer due diligence, suspicious-matter reporting and recordkeeping. AUSTRAC’s public guidance states that businesses commencing those newly regulated services on July 1 were required to apply for enrolment by July 29, 2026—the statutory pattern being an application within 28 days after commencing to provide a designated service. July 29 was the deadline to submit the enrolment application, not necessarily the date by which AUSTRAC completed enrolment processing. [1][2][9]

Coverage still turns on designated services with a geographical link to Australia. A law firm, accounting practice, real-estate business or jeweller is not automatically regulated because of its occupational label. Entities must map the services they actually provide against the legislative definitions and confirm the geographical-link requirement before asserting either “we are in” or “we are out.” [3][4][13]

For dealers, the scoping error cuts both ways. Newly regulated dealer services generally concern purchases or sales of precious metals, precious stones or specified products valued at A$10,000 or more where payment involves physical currency or virtual assets, including linked or apparently linked transactions. A dealer that does not accept physical currency or virtual assets for the relevant transactions may not provide that designated service. Value, payment method and linked-transaction rules—not the word “jeweller”—drive the analysis. [5]

Enrolment does not replace substantive compliance. The Act separately requires an ML/TF risk assessment and AML/CTF policies, procedures, systems and controls for managing money-laundering, terrorism-financing and proliferation-financing risks. An entity that enrolled on time without operable controls did not buy readiness; an entity that missed July 29 and continues to provide designated services without enrolment compounds administrative and substantive risk. Entities that commence designated services after July 1 remain on the rolling 28-day enrolment rule. [2][9]

II. Quantitative Context

There is no single “industry average fine” that substitutes for entity-specific exposure. The useful board frame is clocks, service lines and evidence gaps—not a false-precision national penalty average.

ClockRuleGovernance meaning
Obligation commencementJuly 1, 2026 for newly regulated designated servicesRisk assessment, AML/CTF policies, CDD, training, reporting and oversight duties are live [1][9]
Enrolment application (commenced July 1)Generally by July 29, 2026Apply within 28 days after commencing a designated service; application ≠ completed enrolment [1][2]
Enrolment application (commenced later)Generally within 28 days of startingOngoing rule for entities that begin designated services after July 1 [2]
Enrolment detail changesWithin 14 daysKeep AUSTRAC Online current [2]
Compliance-officer designationIf not designated when designated services commence, designate within 28 daysDistinct from enrolment and from AUSTRAC notification [6][9]
Compliance-officer notificationNotify AUSTRAC within 14 days of appointment; newly regulated entities generally by the later of July 29, 2026 or 14 days after enrolmentAn entity applying on July 29 could have until about August 12 to complete notification [6]
Independent evaluationAt least once every three years; first evaluation subject to transitional timingMandatory under AML/CTF policies; written report to the governing body and relevant senior manager [7]
Scoping testWhat it filters
Designated-service definitionWhether the entity’s actual work product is captured [3][9]
Geographical link to AustraliaWhether the service has the required Australian nexus [4]
Dealer A$10,000 / cash or virtual-asset / linked-tx testsWhether ordinary jewellery sales are in or out [5]
Remittance or virtual-asset registration overlayWhether enrolment alone is enough, or registration also applies under staged transitional rules [2][8]

A defensible governing-body pack separates: services confirmed in scope; services confirmed out of scope with rationale; enrolment status (on time / late / not yet commenced); residual gaps between approved policies and operable intake controls; and the next independent-evaluation milestone.

III. What Modern GRC Must Enforce

Governance architecture the Act actually requires

The draft question “is a board-approved AML/CTF program written and operable?” collapses two different duties. Under the current Act, a senior manager must approve the ML/TF risk assessment and the AML/CTF policies—including relevant updates. The governing body has a separate obligation to exercise appropriate ongoing oversight and take reasonable steps to ensure that the entity identifies, assesses, manages and mitigates its risks and complies with its obligations. Approval and oversight are related; they are not interchangeable labels. [9][10]

The compliance officer is likewise not a slide title. The officer must be at management level and have sufficient authority, independence and resources. Having an officer operational by July 1 was strong readiness practice. The outside legal structure is different: if the entity has not designated an officer when it commences providing designated services, it must do so within 28 days after commencement, and it must notify AUSTRAC within the applicable notification window. Designation and notification are separate clocks. [6][9]

Independent evaluation is not optional “where required.” AML/CTF policies must provide for regular independent evaluation of the compliance framework. Frequency must suit the entity’s nature, size and complexity, but evaluations must generally occur at least once every three years. Transitional provisions determine when a newly regulated entity’s first evaluation is due. The written evaluation report must be provided to the governing body and the relevant senior manager. [7][9]

Control translation

Failure modeWhat the regime requiresPrudent control response
“We are a law firm / accountant / jeweller, so we are automatically in (or out)”Designated services + geographical link—not occupational titles [3][4][13]Service-by-service scoping memo with out-of-scope rationale retained
Enrolment treated as readinessSubstantive risk assessment, policies, CDD and reporting remain mandatory [1][9]Parallel workstreams: enrolment status and operable controls
“Board-approved program” as the only approval languageSenior-manager approval of risk assessment and policies; governing-body oversight of implementation and compliance [9][10]Separate approval records and oversight minutes
Officer named only on the enrolment formDesignation, authority/independence/resources, and AUSTRAC notification on distinct clocks [6]Written appointment; notification tracker; annual (or more frequent) officer report to the governing body
“All training completed before July 1” as a quoted universal deadlineInitial and ongoing role-based training for personnel whose functions are relevant to AML/CTF; PDD before relevant functions begin [11][12]Train early enough for competent performance from commencement; retain role-based records
Generic “sanctions screening”PEP assessment and targeted-financial-sanctions checks within CDD; enhanced CDD where risk requires [11]CDD workflow: identification, beneficial ownership, PEP, targeted financial sanctions, enhanced escalation
CDD invented after the first awkward clientInitial CDD generally before providing a designated service, with limited exceptions; SMR triggers can arise on inquiry or proposal [9][11]Intake playbooks that escalate suspicion before the entity agrees to provide the service
Ordinary jewellery sales assumed regulated (or never regulated)A$10,000+, physical currency and/or virtual assets, linked transactions [5]Threshold / payment-method / linked-tx testing before asserting dealer coverage
Remittance/VASP rules collapsed into ordinary Tranche 2 enrolmentRegistration may apply in addition to enrolment; some virtual-asset obligations are staged [2][8]Service-specific registration and transitional check before asserting a single July 1 timetable

Do not overclaim

  • Do not treat entire professions as automatically reporting entities.
  • Do not equate enrolment application with completed enrolment or with an operable AML/CTF program.
  • Do not collapse senior-manager approval and governing-body oversight into one phrase.
  • Do not present “officer appointed before July 1” or “all training finished before July 1” as if those were the only statutory deadlines.
  • Do not imply that every jewellery or precious-product sale is a designated service.
  • Do not imply that every remittance or virtual-asset obligation followed an identical July 1 timetable.
  • Keep this newsletter distinct from APRA CPS 230—different regulator, different perimeter.

Human-in-the-loop attestation before executive publication remains the institutional control: scoping and materiality of designated-service coverage are governed decisions, not headline labels.

IV. Verification Protocol

  1. Re-read AUSTRAC’s July 1, 2026 “new reporting regime” announcement for sectors, core obligations and the July 29 enrolment-application expectation. [1]
  2. Confirm enrolment guidance: 28-day application rule, 14-day detail-change rule, and when registration may apply in addition to enrolment. [2]
  3. Confirm designated-service and geographical-link tooling before asserting coverage of an entire profession. [3][4][13]
  4. For dealers, verify the A$10,000 / physical-currency / virtual-asset / linked-transaction tests. [5]
  5. Confirm Act and AUSTRAC governance pages: senior-manager approval (s 26P framework), governing-body oversight, compliance-officer designation and notification, independent evaluation at least every three years. [6][7][9][10]
  6. Confirm initial CDD timing, PEP and targeted-financial-sanctions checks, and enhanced CDD triggers. [11]
  7. For remittance and virtual-asset providers, check service-specific registration requirements and any staged transitional provisions. [2][8]
  8. Treat CPA Australia and law-society materials as secondary sector corroboration, not as substitutes for the Act or AUSTRAC. [12][13]

Key Takeaways

  • July 1 started substantive obligations; July 29 was the enrolment-application hard date for new designated services commencing that day—not a substitute for the program.
  • Entities that commence designated services later remain on the rolling 28-day enrolment rule; entities that missed July 29 should enrol immediately and document residual risk.
  • Designated services—not job titles—determine whether Tranche 2 applies; dealers must still pass the value, payment-method and linked-transaction tests.
  • Senior-manager approval, governing-body oversight, officer designation/notification and independent evaluation are related but distinct controls.

V. Sources & Citations