AML/CTF
AML/CTF Tranche 2 Is Live: 7 Things Accounting Firms Need NowÂ
Â
Â
If you have been following the conversation around AML/CTF Tranche 2, you already know the question accounting firms can no longer afford to avoid.
If your firm provides designated services, AML/CTF obligations are now live.
Your engagement letters need to reflect your AML/CTF obligations. Your staff need training they can prove. Your onboarding workflow needs a designated service trigger check that fires every single time, not just when the partner remembers. Your beneficial ownership records may still be incomplete. Your monitoring system may not exist in any meaningful operational sense.
And 1 July 2026 has now passed.
AML/CTF Tranche 2 is no longer a future compliance deadline. It is now an active operational obligation for accounting firms providing designated services.
For firms that commenced providing designated services from 1 July 2026, 29 July 2026 is also the key AUSTRAC enrolment deadline. If your firm has not completed its AUSTRAC enrolment, this is not a “later” task. It is now.
The good news is this: if your firm is not where it needs to be, it is not too late to act.
But it is now time to move quickly, deliberately, and with the right framework.Â
What AML/CTF operational compliance means nowÂ
Before discussing solutions, it is worth being precise about what operational compliance means, because this is where many firms are still giving themselves far too much credit.
Operational compliance is not a policy document sitting in a folder. It is not a program template with the firm’s name inserted. It is not a team meeting where the partners acknowledged that the new laws exist.
Operational compliance means the firm’s designated service trigger check is embedded in every engagement workflow and fires consistently.
It means the onboarding process requires minimum customer due diligence to be completed before work commences, and that standard holds under commercial pressure, client pushback, and deadline anxiety.
It means beneficial ownership is verified for every designated service client, with the evidence documented on file.
It means staff across every role know their obligations, can apply them in practice, and have the assessed training records to prove it.
It means your firm can show that AML/CTF is not a theoretical compliance project, but a live operating system.
If AUSTRAC reviewed a file tomorrow, the evidence of genuine compliance effort needs to be there. Not the intention to get around to it eventually. That is the standard.
And while 1 July 2026 has passed, the opportunity to demonstrate immediate, structured, good-faith implementation has not.Â
The seven things your firm needs in place nowÂ
There is no mystery about what operational AML/CTF compliance requires for an accounting firm.
The framework is clear. The obligations are specific. The evidence standard is now active.
If one of these seven elements is missing, your firm has an implementation gap. If several are missing, your firm has an operational problem.Â
Â
1. A written AML/CTF program
Not a generic template. Your firm needs a written AML/CTF program that reflects how your firm actually operates: its service lines, its client base, its risk profile, its delivery channels, and its geographic footprint.
It should be approved by the partners, implemented in practice, and reviewed when material changes occur.
A program that sits in a folder and does not change staff behaviour is not an operating system. It is decoration.
Â
2. A functional AML/CTF Compliance Officer
Your AML/CTF Compliance Officer must be appointed with genuine authority. This person needs to perform the role in practice, including overseeing the program, approving high-risk client decisions, managing the escalation pathway, overseeing training, and reporting to senior management on compliance matters.
This cannot simply be a name on an internal document.
If the AML/CTF Compliance Officer cannot hold the line when a partner, client, or deadline pushes back, the role is not functional.
Â
3. A consistent onboarding workflow
Your firm needs a designated service trigger check at the start of every engagement and every time the scope changes.
The onboarding process must collect, verify, and document the required customer due diligence.
Beneficial ownership must be traced to natural persons.
Risk rating must be completed and documented.
Approval must be obtained at the appropriate level.
Engagement letters must include AML/CTF clauses and be issued before designated service work commences.
This is where many firms fail: not because they do not understand the law, but because they have no consistent workflow that forces the right steps to happen every time.
Â
4. An ongoing monitoring system
AML/CTF compliance does not end at onboarding. Your firm needs event-driven triggers that fire when material changes occur in client relationships.
These include changes to directors, shareholders, trustees, appointors, controllers, beneficial owners, overseas links, funding sources, counterparties, transaction activity, or engagement scope.
Your firm also needs periodic refresh reviews scheduled and conducted based on risk tier.
Monitoring reviews must be documented with dates, outcomes, and next steps. If the monitoring system lives in someone’s memory, it is not a monitoring system.
Â
5. An escalation and suspicious matter pathway
Your staff need to know what to do when something does not add up. That means a clear internal process for raising and managing concerns.
Facts-only escalation. Restricted-access records.A functioning pathway for Suspicious Matter Report consideration and lodgement where required.
It also means staff know what not to say to clients, colleagues, or third parties once a suspicious matter is under consideration.
Tipping off is a criminal offence. This is not an area for improvisation.
Â
6. Documented staff training
Attendance is not enough. Your firm needs role-based training content that covers what each person in the firm needs to know and do.
Partners need to understand governance, approvals, risk culture, and escalation. Managers need to understand scope, CDD, beneficial ownership, risk rating, monitoring, and client conversations. Accountants and administrative staff need to understand document collection, trigger identification, escalation, tipping off, and file hygiene.
The training must be documented. The outcomes must be assessed.
The firm must maintain a training register showing who completed what, when, and with what result.
If it is not documented, it did not happen. Harsh, but true.
Â
7. Updated engagement letters
Your engagement letters now matter more than ever.
They need to support your firm’s AML/CTF obligations, including identity verification, customer due diligence, ongoing monitoring, screening, record keeping, source of funds and wealth requests where relevant, and the right to pause or cease services if the client does not cooperate.
There are eight clause categories every designated service engagement letter should address:
- Identity verification and customer due diligence obligation
- Ongoing notification of material changes
- Screening consent
- Right to pause or cease services
- Confidentiality limitation and AML/CTF reporting obligations
- Record keeping and data handling
- Source of funds and source of wealth for higher-risk engagements
- Client acknowledgement and cooperation obligation
If your firm is still using old engagement letters for designated service work, that should be treated as an immediate implementation priority.
Why building this from scratch is now the wrong approachÂ
Some firms have tried to build their AML/CTF compliance framework from scratch: working from AUSTRAC guidance, legal templates, and internal drafting effort.
For a small or medium accounting firm with a full workload and active obligations already in effect, building from scratch has significant limitations.
Building a risk rating tool that is calibrated correctly for accounting firm service lines takes time and expertise.
Engagement letter clauses now need to manage the overlap between TASA, the AML/CTF Act, and the Privacy Act. That is not casual drafting. It requires legal and compliance judgement.
Developing a beneficial ownership verification process that is defensible for complex structures, layered trusts, corporate trustees, overseas holding entities, and family groups is not straightforward.
Building a training and certification pathway that creates assessed, documented evidence is also not something that can be thrown together as an afterthought.
The firms that were ready for 1 July did not build from scratch.
They adopted a structured framework that gave them what they needed, then focused their energy on implementation rather than construction.
For firms that are still behind, that principle matters even more now.
The fastest path forward is not to improvise. It is to implement a complete, structured AML/CTF operating system immediately.
Â
What Best Practice Group’s program deliversÂ
Best Practice Group has built a complete, turnkey AML/CTF Tranche 2 Training and Certification Program specifically for public accounting firms.
It is not generic compliance training. It is not a template pack with a covering email. It is an integrated implementation program designed to help firms become operational. The program includes:
A complete compliance playbook. The Accounting Firm AML/CTF Playbook is a 23-chapter implementation guide covering the obligations, workflows, service-line risks, evidence standards, and implementation actions accounting firms need to understand.
It is written in plain language for accounting professionals, not regulators or lawyers.
Two live implementation sessions. Part One covers the onboarding and client acceptance operating system: scope, customer due diligence, beneficial ownership, risk rating, acceptance decisions, and engagement controls.
Part Two covers the ongoing compliance layer: monitoring, escalation, tipping-off safe communication, evidence standards, training records, and certification.
These sessions are delivered as operational implementation sessions, not lectures.
Sixteen operational templates. The program includes the operational tools firms need to embed AML/CTF into their workflows, including:
- Scope Decision Tree
- CDD and KYC Checklist
- Risk Rating Tool
- Client Acceptance Decision Record
- Monitoring Schedule and Event Trigger Review
- Escalation Form and Decision Log
- Training Register
- Micro-Assessment
- Annual AML/CTF Monitoring Review for Tax and Compliance
- CFO Monthly AML/CTF Checkpoint
- Advisory Engagement Change Log
- SMSF Annual AML/CTF Checkpoint
- Related-Party Transaction Checklist for LRBAs
- UBO Mapping Form
- Beneficial Ownership Declaration Form
- Source of Wealth and Funds Declaration Form
These are designed to be uploaded into the firm’s practice management system as standard workflow tasks, not optional documents.
Mandatory compliance assessments. The program includes mandatory compliance assessments. These are not attendance-based tick boxes. Participants must complete the required assessments, with unlimited retakes available. The purpose is simple: staff need to be able to apply the process, not merely say they attended a session.
Two certificates per participant. Participants receive a Part One Certificate and a Part Two Certificate issued by Best Practice Group once the required completion steps are satisfied.
The certificates support the firm’s training evidence by showing assessed, structured, program-based completion. They do not replace implementation on client files, but they do help demonstrate that staff completed a structured AML/CTF training pathway.
A structured evidence trail. The program supports a structured evidence trail, including attendance records, assessment completion, certificate issuance, firm-level decisions documented during the sessions, workbook outputs, and training register records.
This helps firms demonstrate genuine, proactive compliance effort if AUSTRAC reviews the firm’s program or client files.
Engagement letter clause guidance. The program includes guidance on the eight AML/CTF clause categories your engagement letters need to address. It also includes drafting notes, a master review checklist, interim minimum clause guidance, and a practical rollout approach for existing client engagement terms.
Client conversation scripts.  Staff need the right language when clients push back.
The program includes three practical client conversation scripts:
- New client onboarding
- Existing client CDD rollout
- Client who refuses or continues to delay
It also includes pushback handling for the most common client objections.
Tipping-off protocol. The tipping-off protocol explains the criminal offence in plain language. It covers when tipping-off risk begins, what staff must not say, safe default responses, and how client communication should be managed once a suspicious matter is under consideration.
This is one of the most important parts of the whole program, because one careless sentence can create serious personal and firm-level risk.
Partner accountability framework. The program also includes a partner accountability framework.
This is a signed partner commitment document that makes the firm’s non-negotiables explicit and creates a documented record of leadership commitment to the compliance standard.
Because let us be honest: if partners do not enforce the process, the process will not survive contact with clients, deadlines, and fees.
The firms that were readyÂ
The firms that moved into 1 July 2026 operationally ready were not necessarily the largest firms or the best-resourced firms.
They were the firms whose leadership recognised early enough that this was a genuine operational obligation, not a compliance exercise.
They understood that AML/CTF required structured implementation, trained staff, updated engagement controls, documented evidence, and a practical monitoring system.
Those firms enrolled in a structured program.
They completed the live sessions. Their staff completed the assessments and received their certificates. They updated their engagement letters, embedded their onboarding workflows, and built their monitoring systems with the operational tools provided.
They are not guessing. They are operating from a documented system.Â
The firms that are still behindÂ
The firms that are now exposed are the ones that waited.
They waited for certainty. They waited for a quieter period. They waited for a competitor to go first. They waited for AUSTRAC to clarify one more thing. They waited for the deadline to feel more immediate.
But the deadline has now passed.
The old engagement letters may still be in use. Staff training may not have happened. The onboarding workflow may not have changed. Beneficial ownership records may still be incomplete. The monitoring system may still be informal or undocumented.
And AML/CTF obligations are now active.
That does not mean your firm should panic. Panic is useless. Action is not.
The most important thing now is to stop treating AML/CTF as a future project and start treating it as a live operating requirement.
Â
The decision your firm needs to make nowÂ
The question is no longer whether your firm needs to act.
If your firm provides designated services, AML/CTF obligations are live.
The question is whether your firm has a working operating system: documented onboarding, completed CDD, beneficial ownership verification, risk rating, updated engagement letters, trained staff, monitoring triggers, escalation pathways, and evidence on file.
If not, the gap is no longer theoretical.
It is operational.
The May, June, and July rounds have now taken place. The next intake is August, and capacity is limited.
The firms enrolling now are the ones moving quickly to close the gap.
Best Practice Group delivers a turnkey AML/CTF Tranche 2 Training and Certification Program designed specifically for public accounting firms. It includes a complete compliance playbook, two live implementation sessions, 16 operational templates, mandatory compliance assessments, and two certificates per participant issued by Best Practice Group.
Your AML/CTF obligations are live now. If your firm still needs to get operational, the time to enrol is now.
If your firm is still relying on old engagement letters, informal onboarding, incomplete CDD, undocumented staff training, or a monitoring system that lives in someone’s head, now is the time to move.
👉 Register for the AML/CTF Tranche 2 Training Program
👉 Get the Free AML Playbook
Or contact us directly:
đź“§Â team@bestpracticegroup.com.au
📞 1300 274 636
This article is general guidance only and does not constitute legal advice. Firms should confirm their specific obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and seek independent legal advice where required.
Your Engagement Letter Is a Compliance Control Most Accounting Firms Miss
Coming Soon