Bottleneck — Financial Services
AML/CTF Tranche 2 — Operational Admin Automation
From 1 July 2026, Australia's AML/CTF regime formally extends to Tranche 2 entities — accountants, legal practitioners, real estate agents and dealers in precious metals providing designated services. The operational admin is significant. Automation makes it manageable.
Tranche 2 has been discussed in Australia for two decades. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 fixed the timeline. Reporting entities in scope from 1 July 2026 include accountants and legal practitioners providing designated services, real estate agents involved in the sale or transfer of real estate, and dealers in precious metals and stones. Firms in scope must have an AML/CTF program, conduct customer identification (KYC) and ongoing customer due diligence, screen for politically exposed persons (PEPs) and sanctions, keep records for 7 years, and submit suspicious matter reports where required.
Where automation genuinely helps
- **Customer identification collection.** A client-facing portal that asks for ID documents, verifies format, checks against biometric match if configured, and stores the verified record in your matter file.
- **PEP and sanctions screening.** A screening check against commercial data providers (Refinitiv, Dow Jones, FrankieOne, Trulioo) triggered automatically at onboarding and on scheduled review intervals.
- **Ongoing customer due diligence reminders.** The workflow schedules a review at the appropriate cadence based on customer risk rating.
- **Record keeping.** Every step above produces a timestamped, exportable audit record retained for the statutory 7-year period.
- **Threshold monitoring on designated services.** Where a designated service crosses a monitored threshold, an alert routes to your AML/CTF Compliance Officer.
Where automation must never sit
- The AML/CTF program itself — a document written by the firm and approved by governance.
- Customer risk rating decisions — these are judgement calls with legal consequence.
- The decision to file (or not file) a Suspicious Matter Report — this rests with the AML/CTF Compliance Officer and, ultimately, the firm's board.
- Any interpretation of whether a specific service is a 'designated service' under the Act.
How we build it inside a licensed environment
- 1We start with your firm's existing AML/CTF program and map the operational touchpoints.
- 2We wire customer identification into your identity provider of choice (FrankieOne, Trulioo, GreenID, Onfido).
- 3PEP/sanctions checks run at defined trigger points (onboarding, matter creation, review cadence).
- 4The audit trail lives in your matter management system or CRM, not in a shadow database.
- 5Your Compliance Officer keeps a dashboard view and a kill switch on every automation.
Related
Common questions
Are you giving AML/CTF advice?
No. We are not lawyers and not licensed AML/CTF advisers. Everything on this page is about automating the operational admin around obligations that your firm's own compliance function has already defined.
Which identity verification providers do you integrate with?
FrankieOne, Trulioo, GreenID, Onfido, and several other Australian-friendly providers. Choice depends on your existing tech stack and cost tolerance.
What about SMRs?
The decision to file a Suspicious Matter Report always rests with your AML/CTF Compliance Officer. Automation only surfaces the underlying data — it does not decide.
Book a Free Automation Audit
30 minutes. No pitch. We map the specific bottleneck and quote real numbers.