From 1 July 2026, accounting firms providing designated services under Australia’s AML/CTF Tranche 2 reforms become reporting entities — whether they feel ready or not. For many small and mid-sized practices, the question isn’t “do the rules apply to us?” anymore. It’s “what actually happens if we miss the deadline?”
Here’s what’s at stake, and why “we’ll get to it eventually” is a risky strategy.
The Civil Penalties Are Not Symbolic
AUSTRAC has both civil penalty and criminal enforcement powers under the AML/CTF Act. For body corporates, maximum civil penalties can run into the tens of millions of dollars per contravention. For individuals — including compliance officers and practice principals — penalties can reach into the millions as well, calculated per penalty unit at current rates.
This isn’t a regulator that issues a warning letter and moves on. AUSTRAC has a track record of pursuing major enforcement actions against Australia’s largest financial institutions, and Tranche 2 brings accounting firms directly into that same enforcement framework for the first time.
Reputational Damage Often Outlasts the Fine
A civil penalty is a number. A finding against your firm becomes public record. AUSTRAC publishes enforcement actions, which means a contravention doesn’t just cost you financially — it can trigger separate disciplinary consequences with your professional body, whether that’s CPA Australia or CA ANZ.
For an accounting practice, trust is the entire business model. Clients hand over financial details, trust structures, and sensitive transaction history on the assumption that your firm operates with integrity and rigour. A public compliance failure undermines exactly that.
What Counts as “Non-Compliance”
It’s not just about ignoring AUSTRAC altogether. You can fall short by:
- Failing to enrol with AUSTRAC by the deadline
- Skipping customer due diligence (CDD) checks before providing designated services
- Not keeping the required records for the mandated retention period
- Operating without a documented, risk-based AML/CTF program
- Failing to report suspicious matters within the required timeframe
Many firms assume they’re “too small” or “too low-risk” to be a target. AUSTRAC’s guidance makes clear that obligations apply to any firm providing designated services, regardless of size — though the complexity of your program can scale with your risk profile.
The Compounding Risk of Delay
Firms that start early generally absorb the changes with minimal disruption. Firms that wait until the weeks before the deadline tend to face a different set of problems: rushed risk assessments, incomplete documentation, and policies that look compliant on paper but haven’t been tested against real client scenarios.
If an AUSTRAC review finds your program was assembled in a hurry, “we tried” carries far less weight than a program built with genuine planning.
Where to Start
If your firm hasn’t yet:
- Confirmed whether you provide a “designated service” under the Act
- Enrolled (or prepared to enroll) with AUSTRAC Appointed an AML/CTF compliance officer at management level
- Begun building a written, risk-based AML/CTF program
…now is the time, not after the deadline passes. AUSTRAC’s free starter kits are a reasonable entry point for low-complexity practices, but most firms will need a program tailored to their actual client base, services, and risk exposure — something a generic template can’t fully provide.
The bottom line: the cost of preparing now is predictable. The cost of non-compliance is not.
This article provides general information and is not a substitute for legal advice. Speak with a compliance professional to understand how Tranche 2 applies to your specific practice.


