Another Firm Already Verified Your Client. AUSTRAC Lets You Rely on That in Two Ways, and Both Come With Paperwork.
Ten weeks into the regime, the CDD question that keeps coming up is not how to verify a client. It is whether you have to, when another firm in the same transaction already did. AUSTRAC's answer is yes, in two forms: a case-by-case file note, or a written arrangement a senior manager approves and you reassess at least every two years. Here are the conditions, what the referring firm has to hand over, and why an ID-check vendor never counts.
AUSTRAC Is Investigating Western Union. The Test It Named Is 'Known Patterns', and It Has Already Published Yours.
On 1 September 2026 AUSTRAC opened an enforcement investigation into Western Union and, unusually, published both the file behind the decision and the three tests it will run: does the program work, does monitoring catch known patterns, and who really makes the decisions. Here is each test at the scale of a four-person practice, and why the sequence that led here matters more than the name on the release.
The Letters Have Started. What a Section 167 Notice Means When a Business Never Enrolled.
On 28 August 2026 AUSTRAC began issuing section 167 notices to businesses that appear to provide designated services but never enrolled. Here is what a notice actually compels, how to tell a real one from the impersonation scams AUSTRAC warned about two days earlier, and why enrolling late still beats waiting for a letter.
Your Client Exists. Their ID Doesn't. AUSTRAC Wrote a Playbook for Exactly This.
A real client who cannot produce a driver licence or passport is not a dead end. AUSTRAC publishes an alternative identification playbook, and it is more generous than most firms assume. Referee statements, government correspondence, expired ID and, as a last resort, self-attestation are all on the table, provided you assess the risk and write down what you did. Here is the whole toolkit, translated for a suburban practice.
AUSTRAC's 2026-27 Regulatory Priorities: The Five-Line Checklist It Expects You to Finish by Mid-2027
AUSTRAC's regulatory priorities for 2026-27 spell out what newly regulated firms should have done by mid-2027, and who it will intervene against first. The five-line checklist ends with the hard part: policies embedded in daily operations. Here is the document read from a small firm's desk, what each line means, and the three moves worth making this week.
Gold Bullion, Luxury Watches, 280,000 Vapes: AUSTRAC's Tobacco Strike Is a Tour of the Sectors It Now Regulates
AUSTRAC's illicit tobacco strike seized cash, gold bullion, luxury watches and 280,000 vapes, and restrained $25 million in property and shares. The network ran through legitimate freight businesses, and the asset list reads like a map of the sectors AUSTRAC now regulates. Here is what the operation looks like from inside a client file, and which routine obligations are built to catch it.
Your First AUSTRAC Compliance Report Is Not Due Until 2027. It Is Being Written Right Now.
Your first AUSTRAC compliance report covers 1 July 2026 to 30 June 2027 and is lodged between July and September 2027, not 31 March. The questions are mostly yes/no answers and counts, and nearly all of them can only be answered from records you keep during the year. Here is what the report asks, the register that answers each question, and the small monthly habit that makes next July boring.
Your Business Changed. AUSTRAC Gives You 14 Days to Say So.
New partner, new office, new service line, a compliance officer who resigned: AUSTRAC expects to hear about it within 14 days of the change. Here is what counts as an enrolment detail, where the update form lives in AUSTRAC Online, and the other 14 day clocks the reformed Act starts every time something changes inside your firm.
Your First AUSTRAC Compliance Report Is Not Due in March. The Year It Asks About Started in July.
AUSTRAC moved the annual compliance report to financial years, so your first one is not due until the 1 July to 30 September 2027 window. Nothing is due this September. But the reporting period it asks about opened on 1 July 2026, which means the answers are being written right now, in the records you either keep or do not.
Two Digits of Your AUSTRAC Account Number Have Already Scheduled Your First Independent Evaluation
Every AML/CTF program must be independently evaluated at least once every 3 years, and for newly regulated firms the deadline for the first one is already fixed by the last two digits of the AUSTRAC account number. Here is how to read your date, who is allowed to run the evaluation, what the written report must cover, and why the paperwork about it is due years before the evaluation itself.
Three Governance Jobs, Probably One Head: Who Signs What in a Small Firm
The Act created three governance roles in your firm: governing body, senior manager and AML/CTF compliance officer. In most small firms all three are you. Wearing every hat does not merge the duties: some approvals cannot be delegated, one report is owed every 12 months, and AUSTRAC expects records showing each role actually did its job.
Your Client File Says 'Low Risk'. Who Decided That?
A stored risk rating and a risk assessment are not the same thing, and AUSTRAC asks you to keep a record of the second one. If your client files were rated low by a default rather than by a person, the rationale AUSTRAC expects to see does not exist. Here is how to tell the difference, and a three-step check you can run on your own files this morning.
Two Entities, One Program: The Reporting Group You Might Already Be In
If your practice sits under a trust or holding company that owns something else, you may already be in a reporting group without having chosen one. Business groups become reporting groups automatically, a lead entity has to be appointed in writing within 28 days, and the entity that ends up carrying the group program may be one that has never provided a designated service in its life. Here is the test, the clock, and what you actually get in return.
Someone Else's Data Breach Is Your AML Problem Too
The AML/CTF Act tells you to collect identity information and keep the record for seven years, which quietly turns your practice into something worth stealing. AUSTRAC's data breach guidance covers that, and it also covers the case nobody expects: a breach at some other organisation that never touches your systems and still weakens every identity check you run. Here is what it expects you to do about both.
You Checked Every Client. AUSTRAC Also Expects You To Check Your Own People.
There is a due diligence obligation in the AML/CTF Act that points at your own staff rather than your clients, and most firms have not read it. It asks you to assess the skills and the integrity of everyone who performs an AML/CTF function, before you engage them and for as long as they stay. Here is who it covers, what AUSTRAC's own worked example does, and the two parts of it almost nobody has written down.
The Client Won't Hand Over ID. The Act Has Already Decided What Happens Next.
If you cannot establish who your customer is on reasonable grounds, you must not provide the designated service. That is the whole rule, and it is short. What it does not tell you is the difference between a client who will not prove who they are and one who cannot, which are two different situations that look identical from your side of the desk. Here is how to tell them apart, and what has to be in the file either way.
The Deadlines Are Done. Your Next AUSTRAC Date Is 1 July 2027.
Enrolment closed on 29 July 2026. For most Tranche 2 firms the next date AUSTRAC actually puts in your calendar is 1 July 2027, when the first annual compliance report window opens. Everything in between runs on triggers you have to notice yourself, not dates anyone reminds you about. Here is what those triggers are, and what should be in your file by the end of August.
How to Rate a Client's Risk: The Step Most Firms Skip
Most Tranche 2 firms nail the business risk assessment and skip the other one: rating each client low, medium or high. It is a separate AUSTRAC obligation, and it decides whether you can use simplified CDD or must do enhanced. Here is the method AUSTRAC expects, the four factor categories, the low/medium/high examples, and a worked conveyancer example.
How to Find a Company Client's Beneficial Owners: The ASIC Extract
You've enrolled with AUSTRAC and a company walks in as a client. The rules say identify its beneficial owners, but the free ASIC search won't tell you who owns it. Here is exactly which ASIC product actually carries the ownership data, the free one that looks right but isn't, how to read directors and shareholders off it, and where the extract stops and you take over.
What Actually Happens if You Miss the 29 July AUSTRAC Deadline?
Eight days out, every Tranche 2 firm that hasn't enrolled is quietly asking the same question: what happens if I just don't? Here is the honest answer. The theoretical penalties, the realistic enforcement ladder, why enrolment is the cheapest genuine-effort evidence you will ever buy, and what to do if the date has already passed by the time you read this.
CDD on a Family Trust: Who Do You Actually Have to Identify?
Half the client files in an Australian accounting or legal practice have a discretionary trust in them, and trusts are where Tranche 2 CDD gets genuinely hard. AUSTRAC rated trusts a high national money laundering risk, and the new rules ask for more than the trustee's driver licence. Here is who you actually have to identify on a family trust file, what verifies what, and the discretionary trust wrinkle that trips people up.
Filed Zero Suspicious Matter Reports? AUSTRAC Now Treats That as a Red Flag
AUSTRAC's CEO told the non-bank lending sector that suspicious matter reporting is rising, but many businesses still file none. The real message for every Tranche 2 firm: a clean sheet of zero SMRs is no longer read as proof you are low-risk. It is something AUSTRAC now reverse-checks.
1 July Didn't Just Add AML. It Removed Your Privacy Act Exemption.
Most Tranche 2 coverage stops at AUSTRAC. But the same law that made you a reporting entity also stripped away the Privacy Act small business exemption for your CDD data. From 1 July 2026, a solo accountant or one-agent real estate office is bound by the Australian Privacy Principles regardless of turnover. Here is what actually changed, what you now have to have, and the one scope nuance that keeps it from being as big as it sounds.
FATF Grey List 2026: The High-Risk Countries That Trigger Enhanced Due Diligence
The FATF updated its grey list on 19 June 2026, adding Iraq and Bosnia and Herzegovina and removing Algeria and Namibia. Here is the full current list, what a high-risk jurisdiction actually means for your Tranche 2 obligations, and when a country connection pushes a client into enhanced due diligence.
Your Client Matched a PEP or Sanctions List. Now What?
Screening a client and getting a hit is the moment most firms dread. But a match is not a verdict. Here is how to tell a false positive from a real one, what a PEP match actually requires, why a sanctions match is different, and when a match becomes a report to AUSTRAC.
AML/CTF Record Keeping: What to Keep, and What You Now Have to Destroy
Under the amended AML/CTF rules, keeping every scanned ID on file is no longer the safe option. It can be a privacy breach. Here is what a Tranche 2 firm must retain for seven years, and what it should now destroy once identity is verified.
Does an ID Check Make You AML/CTF Compliant? What Tranche 2 Actually Requires
Since 1 July 2026, accountants, lawyers and real estate agents are reporting entities. A client identity check is one small part of that, not the whole of it. Here is what AUSTRAC actually requires, and why 'my software already does AML' can leave you exposed.