FAQ

Frequently Asked Questions

Tranche 2 scope, the AML/CTF program, customer due diligence, reporting, and the ClearTrace platform, answered.

These answers cover Australia's Tranche 2 AML/CTF requirements for accounting firms, deciding when the regime applies, setting up the compliance framework, conducting customer due diligence, and meeting ongoing monitoring and reporting obligations, alongside common questions about the ClearTrace platform. This is general information only and is not legal advice; apply AUSTRAC guidance and the legislation to the facts of each engagement.

About ClearTrace

Does ClearTrace integrate with our existing systems?
Yes. ClearTrace offers API access (Professional and above) and integrates with practice and company data tools such as ASIC company verification and CAS360. Our team scopes integrations with your existing CRM, document and practice management systems during onboarding.
How long does implementation take?
Most firms are live within 1–3 weeks. Essential plans can be self-onboarded in days; larger firms with multi-office setups, SSO and integrations typically take 2–4 weeks with guided onboarding included at no extra cost.
Where is our compliance data stored?
All data is hosted in Australia. ClearTrace is designed to minimise storage of identity documents and sensitive PII, retaining compliance workflow records only as required by law. Data is encrypted in transit (TLS 1.3) and at rest (AES-256), with role-based access control and MFA.
Is ClearTrace priced per user or per firm?
Per firm, not per user. See the pricing page for full tiers.
Does ClearTrace replace our AML/CTF Program?
No. ClearTrace is a technology platform that operationalises and evidences your obligations. Your firm remains responsible for maintaining a compliant AML/CTF Program. We recommend consulting a qualified AML/CTF specialist for program documentation.

Scope and application

What is Tranche 2?
Tranche 2 extends Australia's AML/CTF regime to specified higher-risk services provided by accountants, lawyers, conveyancers, real estate professionals and certain dealers. It applies to designated services, not to every service a professional firm provides.
When did the new obligations commence?
The obligations for newly regulated professional services commenced on 1 July 2026.
Does every accounting firm have to enrol with AUSTRAC?
No. A firm must enrol if it provides at least one designated service with the required Australian geographical link.
What professional services are designated services?
They include actively assisting with real estate or business transfers, managing client property for a transaction, equity or debt financing, creating or restructuring entities or legal arrangements, selling shelf companies, arranging certain fiduciary roles, and providing a registered office or principal business address.
Are tax returns, bookkeeping and payroll automatically regulated?
No. These activities are not designated simply because an accountant performs them. The firm must assess what it actually does and whether its work directly advances a transaction, entity creation or another Table 6 outcome.
Can a one-off service bring a firm into scope?
Yes. A service can be provided in the course of a business even if it is provided only once. The facts and the firm's actions determine whether it is designated.
What should a firm do if it provides no designated services?
Document a service-scope assessment explaining why the firm is out of scope, and review it whenever services, clients or engagement processes change.
When does advice become regulated assistance?
General or hypothetical advice is not necessarily enough. The stronger trigger is taking active steps that directly advance the relevant transaction, creation or restructure; sufficiently complete advice that enables the client to complete the outcome without further professional help may also be captured.

AML/CTF program and risk assessment

What are the main implementation steps?
Establish governance, assess the firm's ML/TF risks, develop AML/CTF policies and controls, conduct customer due diligence, train relevant personnel, monitor customers and designated-service activity, and meet reporting and record-keeping obligations.
What must the firm risk assessment consider?
At a minimum, assess risk arising from the designated services offered, customer types, delivery channels and geographic exposure. Document both the risk before controls and the risk remaining after controls.
Does a complex firm automatically have a high risk rating?
No. Size and complexity influence the assessment method, but the rating should reflect the firm's actual exposure, likelihood, impact and controls.
What is the difference between a program, policy and procedure?
The program is the overall compliance framework. Policies state what the firm requires; procedures explain how staff perform the required steps.
Can a reporting group use one group program?
A valid reporting group may share compliance arrangements through a group AML/CTF program maintained by its lead entity. The assessment must still cover the services, risks and controls of all relevant members.
Who is responsible for AML/CTF compliance?
Governance should clearly identify the governing body, senior manager or managers, and an AML/CTF compliance officer. Small firms may have one person perform more than one role, but the responsibilities must remain clear.

Customer due diligence

What is the first CDD question for an accounting client?
Confirm whether the engagement includes a designated service. If it does not, record the client or engagement as out of scope for AML/CTF CDD, while noting that other identity-check obligations may still apply.
What must initial CDD establish?
Establish the customer's identity, relevant representatives and their authority, persons receiving the service on the customer's behalf, beneficial owners, PEP and targeted-financial-sanctions status, the relationship's nature and purpose, and the customer's ML/TF risk.
Who is a beneficial owner?
A beneficial owner is an individual who directly or indirectly owns 25% or more of the customer, or controls the customer. Ownership chains must be followed until the relevant individuals are identified.
Does someone below 25% always fall outside beneficial ownership?
No. A person with less than 25% ownership may still be a beneficial owner if they control the entity through voting power, board composition, contractual rights or practical influence.
How is CDD different for a discretionary trust?
Review the trust deed and control structure. Identify relevant trustees, settlors, appointors, guardians, protectors, other controllers and identifiable beneficiaries; where individual beneficiaries cannot be identified because of the trust's nature, record the beneficiary classes.
When must initial CDD be completed?
As the default, complete initial CDD before starting the designated service. If the required matters cannot be established on reasonable grounds, the firm must not start the service.
Can verification ever be delayed?
Only in limited circumstances and under documented controls. The firm must determine that delay is essential to avoid interrupting ordinary business and creates low additional ML/TF risk, then complete the checks as soon as reasonably practicable within the applicable deadline.
Is a long-standing client exempt from identity checks?
No. Personal familiarity does not replace formal CDD when the firm starts providing a designated service.
Must all existing clients be reverified immediately?
No. Existing clients should be assessed under AUSTRAC's transition rules and the firm's risk-based policies. A new designated service, material change or suspicion may trigger CDD or an update.
How often must ongoing CDD be repeated?
There is no single interval for every customer. Use risk-based reviews and event triggers, such as ownership or control changes, a new jurisdiction, unusual funding, inconsistent transactions or a move into a designated service.

Screening, monitoring and reporting

Must a firm reject every PEP?
No. PEP status is a risk factor, not an automatic prohibition. Apply the required risk assessment and enhanced CDD measures where applicable.
What if there is a targeted financial sanctions match?
Escalate immediately and do not deal with the person's or entity's assets unless authorised by the Australian Sanctions Office. A true sanctions match is different from PEP status.
What does transaction monitoring mean for an accounting firm?
Compare activity connected with the designated service and customer relationship against the expected profile. The approach may be manual or technology-assisted and should be proportionate to the firm's risks.
When is a suspicious matter report required?
An SMR may be required when a suspicion arises in connection with a prospective, proposed or actual designated service. The obligation can arise even if the firm declines the engagement.
When is a threshold transaction report required?
A TTR is generally required when the firm receives or pays physical currency of AUD 10,000 or more in connection with a designated service. Merely hearing that a client holds cash does not itself create a TTR.
What is the annual compliance report timetable?
The current annual cycle is 1 July to 30 June, with the report due within three months after year-end. The first new reporting period is 1 July 2026 to 30 June 2027, with submission due by 30 September 2027.
Is AML/CTF compliance a once-a-year exercise?
No. Maintain the risk assessment, policies, CDD, training, monitoring, escalation and records throughout the year, and update them when the business or risk profile changes.
Powered by AccSource 18+ Years Compliance Experience ISO 27001:2022 Aligned Team Australian Owned & Operated Data Hosted in Australia

Get Tranche 2 updates in your inbox

Practical guidance from AccSource's compliance team. No spam.

By subscribing, you agree to receive updates from ClearTrace and accept our Privacy Policy. Unsubscribe at any time.