Quick answer: Australia's AML/CTF reforms, enacted through the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, do three things: extend the regime to "tranche 2" professions (lawyers, accountants, real estate professionals, trust and company service providers, dealers in precious metals and stones) from 1 July 2026; restructure the AML/CTF program around a documented ML/TF risk assessment and policies from 31 March 2026; and modernise customer due diligence, the travel rule and tipping-off rules. For technology teams, the practical consequence is a shift from periodic, rules-only compliance to continuous, risk-based monitoring and perpetual KYC.
Australia was one of the last FATF members to regulate the gatekeeper professions, and the reform package that finally did it also rewrote the obligations of every existing reporting entity. Banks, insurers, super funds, remitters and digital-currency exchanges have spent 2025-2026 re-papering their AML/CTF programs, re-assessing customer risk and renegotiating with their monitoring and screening vendors. Tranche 2 entities, many of them small firms, are entering a regime for the first time, and the banks that serve them have to understand their new obligations too.
This guide is for heads of financial crime, MLROs and AML/CTF compliance officers, and the technology and data leaders who run transaction monitoring, screening and KYC platforms. It covers what changed and when, how the new program model works, and what it means for AML transaction monitoring and perpetual KYC in practice.
What are the AML/CTF reforms?
The reforms amend the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 and are supported by new AML/CTF Rules made by AUSTRAC in 2025 and extensive AUSTRAC guidance. The headline changes:
- Tranche 2 — What changed: Legal, accounting, real estate, conveyancing, trust and company services, precious metals and stones dealers become reporting entities · Who it affects: New entities (AUSTRAC's working estimate was tens of thousands, in the order of 90,000) · Key date: Enrolment from 31 March 2026; obligations from 1 July 2026
- AML/CTF program redesign — What changed: Program = ML/TF risk assessment + AML/CTF policies; "Part A / Part B" structure retired; clearer senior-manager and compliance-officer roles; group-wide programs · Who it affects: All reporting entities · Key date: 31 March 2026
- Customer due diligence — What changed: Simplified and outcomes-based: initial CDD, ongoing CDD, enhanced CDD tied to risk; pre-commencement customers handled on a risk basis · Who it affects: All reporting entities · Key date: 31 March 2026
- Virtual assets — What changed: Expanded regulation of virtual asset service providers · Who it affects: Digital currency exchanges and related services · Key date: 31 March 2026
- Travel rule — What changed: Modernised obligations to pass payer and payee information with transfers, including virtual assets · Who it affects: Financial institutions, remitters, VASPs · Key date: 31 March 2026
- Tipping off — What changed: Offence reframed to focus on disclosures that would reasonably prejudice an investigation, enabling more information sharing · Who it affects: All reporting entities · Key date: 31 March 2025
The theme running through all of it is outcomes over prescription: AUSTRAC wants entities to understand and manage their own risk, and to be able to show the reasoning, rather than tick a prescribed list.
Who is covered by tranche 2, and why it matters to banks
Tranche 2 brings in the professions that structure, hold and move value for clients: lawyers and conveyancers acting on property or company transactions, accountants providing certain services, real estate agents handling sales, trust and company service providers, and dealers in precious metals and stones above thresholds. Each becomes a reporting entity with enrolment, risk assessment, program, CDD, suspicious matter reporting and record-keeping obligations.
For banks, two consequences follow. First, the trust accounts, settlement flows and client money of tranche 2 firms are now a regulated customer segment with its own risk profile; your customer risk models and monitoring scenarios should reflect it. Second, tranche 2 firms will look to their bankers, software providers and professional bodies for practical help, and the quality of information flowing between a law firm's trust account and a bank's monitoring team is about to matter more.
The new AML/CTF program: risk assessment first
Under the reformed regime an AML/CTF program has two parts: a documented ML/TF risk assessment covering customers, products and services, delivery channels and jurisdictions, and a set of AML/CTF policies that respond to the assessed risk. A senior manager must approve the program and the Board or equivalent retains oversight; an AML/CTF compliance officer at management level is required.
Technology consequences:
- The risk assessment must be evidenced by data: customer risk distributions, transaction volumes by channel and corridor, product exposure, alert and SMR outcomes.
- Monitoring scenarios and screening rules must trace back to the risks identified. "Because the vendor shipped it" is not a rationale.
- When the risk assessment changes (new product, new corridor, tranche 2 segment), the controls must change with it, and the change must be recorded.
How AML transaction monitoring works, and what has to change
A transaction monitoring system runs customer activity against scenarios and models to detect patterns indicative of money laundering or terrorism financing: structuring below reporting thresholds, rapid movement of funds, activity inconsistent with the customer's profile, high-risk corridors, and typologies published by AUSTRAC and the Fintel Alliance. Alerts go to analysts, who investigate and either close them or escalate to a suspicious matter report (SMR), due to AUSTRAC within three business days of forming a suspicion (24 hours for terrorism financing). Threshold transaction reports and international funds transfer instruction reports run alongside.
Under the reforms, four things change in how monitoring must be run:
- Risk-based scenario design. Scenarios and thresholds segmented by customer risk tier, product and channel, each documented against the risk assessment.
- Ongoing CDD integration. Monitoring outputs feed the customer risk rating, and the customer risk rating tunes the monitoring. This loop is the mechanism of perpetual KYC (below).
- Model governance. Where machine learning prioritises or suppresses alerts, AUSTRAC and APRA both expect validation, explainability and drift monitoring; a monitoring model supporting regulatory reporting is an operational risk under APRA CPS 230, covered in our guide to governing AI under CPS 230.
- Information sharing. The reformed tipping-off rule and the Fintel Alliance public-private partnership make it easier to share intelligence across institutions, which is where mule-account and scam-network detection lives; see fraud detection systems, scams and mule accounts.
What is perpetual KYC, and why the reforms favour it
Traditional KYC refresh works on a calendar: high-risk customers reviewed annually, medium every three years, low every five. It is expensive, intrusive, and the customer is usually out of date the day after the review.
Perpetual KYC (pKYC) replaces the calendar with events. Triggers such as a change in transaction behaviour flagged by monitoring, a new director or beneficial owner in a registry feed, adverse media or sanctions hits, a change of address or jurisdiction, or a product change prompt a targeted review of only the data that changed. Low-risk customers with no triggers may never need a full refresh; high-risk customers are reviewed when something actually happens.
The reformed ongoing CDD obligation is explicitly risk-based and outcomes-focused, which makes event-driven review a natural fit, provided you can show that the triggers are comprehensive and that reviews happen. Building blocks:
- Entity resolution and a single customer view across products and channels.
- Data feeds: ASIC and ABR registry changes, beneficial ownership sources, sanctions and PEP lists, adverse media, internal behaviour signals.
- Trigger rules and risk-rating engine with documented thresholds.
- Workflow and agents: assembling the case, drafting outreach, parsing responses and updating the record are well-suited to AI agents with human sign-off on risk-rating changes (see agentic AI use cases in banking and insurance).
- Evidence: an audit trail showing what triggered each review, what was checked and what changed.
Reducing false positives in transaction monitoring without losing coverage
- Segment first. Most false positives come from applying one threshold to customers with very different baselines.
- Tune with outcomes. Use SMR conversion and analyst dispositions to adjust thresholds, with the change documented against the risk assessment.
- Prioritise with models, suppress with care. Machine learning can rank alerts; auto-closing alerts needs validation, sampling and regulator-ready explanations.
- Fix the data. Poor entity resolution, missing occupation and industry codes and stale beneficial ownership data generate noise no model can remove.
- Share infrastructure with fraud. Graph analytics and case management built for mule detection surface laundering networks too.
Compliance technology checklist for 2026-2027
- Program documents reissued in the risk assessment plus policies structure, approved by a senior manager, with Board oversight recorded.
- Monitoring scenarios and screening rules mapped to the risk assessment; orphan scenarios retired or justified.
- Customer risk model updated for tranche 2 segments and virtual asset exposure.
- Ongoing CDD moved to event-driven triggers where risk justifies it, with calendar refresh retained as a backstop.
- Travel rule data fields and virtual asset transfer handling tested end to end.
- Model risk governance for any ML in monitoring, screening or risk rating; vendor models included.
- Information-sharing arrangements updated for the reformed tipping-off rule.
- Vendor platforms assessed as material service providers under APRA CPS 230.
Key takeaways
- The AML/CTF reforms change every reporting entity's program, not just the tranche 2 newcomers; the 31 March 2026 and 1 July 2026 dates are the anchors.
- The program is now a risk assessment plus policies; every monitoring scenario and screening rule must trace back to an assessed risk.
- Transaction monitoring must become segmented, outcome-tuned and model-governed, with monitoring outputs feeding customer risk ratings.
- Perpetual KYC is the natural implementation of risk-based ongoing CDD, built on entity resolution, data feeds, trigger rules and auditable workflow.
- Share graph analytics, case management and intelligence with fraud teams; mule accounts and scam networks are both fraud and laundering problems.
Join your peers at the Clutch Fraud and Financial Crime Technology Summits
Clutch Events runs free-to-attend, invite-curated, practitioner-led fraud and financial crime technology summits for senior financial crime, fraud, risk and technology leaders at Australian financial institutions:
- Sydney Financial Crime and Fraud Technology Summit 2026 — 29 October 2026
- Sydney Fraud and Financial Crime Technology Summit 2027 — 13 May 2027
- Melbourne Fraud and Financial Crime Technology Summit 2027 — 18 August 2027
See all upcoming Clutch events · More guides on Clutch Events Insights