Australia's expanded anti-money laundering and counter-terrorism financing laws now apply to certain high-risk services commonly provided in property, legal, accounting and high-value goods transactions. The new obligations started on 1 July 2026, bringing thousands more businesses into the AUSTRAC reporting regime.
The important qualification is that regulation is based on the service being provided, not a business label alone. A lawyer, accountant, real estate business or jeweller is not automatically regulated for every activity it performs. The first step is to identify whether the business provides a designated service with a geographical link to Australia.
Key takeaways
- The main newly regulated groups are real estate professionals, legal and conveyancing providers, accountants and trust or company service providers, and dealers in precious metals, stones and products.
- KYC is one part of customer due diligence. It does not replace a complete AML/CTF program, ongoing monitoring, reporting, governance, training and record keeping.
- Whether the law applies depends on a designated service, the particular transaction and the Australian geographical-link rules.
- Newly regulated businesses were required to have their compliance arrangements operating from 1 July 2026 and to enrol with AUSTRAC by 29 July 2026.
What changed under Australia's 2026 AML/CTF reforms?
On 1 July 2026, Australia extended AML/CTF regulation to designated services that are often called tranche two. AUSTRAC's new reporting regime announcement identifies real estate, conveyancing, legal services, accounting, and precious stones and metals among the newly regulated sectors.
A regulated business must do more than collect an identity document. AUSTRAC says the core obligations include implementing an AML/CTF program, conducting customer due diligence, reporting suspicious matters and keeping relevant records. AUSTRAC's May 2026 statement of expectations also says newly regulated businesses should have an AML/CTF compliance officer and train staff on their program.
The reform is therefore wider than a new identity-checking rule. It creates an ongoing, risk-based compliance responsibility around customers, transactions and the services a business provides.
Which industries are affected by the new KYC and AML rules?
The reforms primarily affect five industry groups. Each group is covered only when it provides a relevant designated service.
| Industry group | Examples of potentially covered activity | AuthNTick industry page |
|---|---|---|
| Real estate and property | Brokering a sale, purchase or transfer as an agent or buyers agent, or certain direct sales by property developers. | Real estate and property |
| Legal and conveyancing | Directly advancing certain real-estate, business, trust, financing or property transactions. | Legal and conveyancing |
| Accounting and advisory | Assisting with covered transactions, company or trust structures, property or financing arrangements. | Accounting and advisory |
| Trust and company services | Creating or restructuring companies and legal arrangements, or providing certain nominee, registered-office or management services. | Trust and company services |
| Precious metals, stones and products | Buying or selling qualifying goods for at least $10,000 in physical currency, virtual assets or linked transactions using those payment types. | Jewellers and precious metals |
AUSTRAC also lists businesses providing certain additional virtual asset services. Many financial services were already regulated, while the reforms updated their obligations from 31 March 2026. For that reason, financial services should not be grouped wholesale with the newly added tranche-two industries. See AUSTRAC's overview of the reforms for the regulator's current breakdown.
Does every business in these industries need to conduct KYC?
No. A business is regulated only if it provides a designated service and the service has the required geographical link to Australia. AUSTRAC's regulation checker is the practical starting point, but a business should obtain professional advice if its activities do not fit neatly within the examples.
The service-based approach matters because work performed by the same profession can fall on different sides of the line. AUSTRAC's guidance for professional designated services explains that preparing or executing documents that directly advance a covered transaction can be regulated, while advice about a completed event may not be. The facts and timing of each engagement matter.
Jewellery transactions illustrate the same point. AUSTRAC states that the designated service applies when qualifying precious goods worth at least $10,000 are bought or sold using physical currency, virtual assets or linked transactions using those payment types. A purchase paid only by card or bank transfer is not covered by that particular designated service. Businesses still need systems capable of detecting transactions that are linked or appear to be linked.
What is the difference between KYC and AML?
KYC means knowing who the customer is. It covers collecting and verifying relevant information so the reporting entity can establish the customer's identity on reasonable grounds. Depending on the customer and risk, the process can also involve beneficial owners, control information, the purpose of the relationship and politically exposed person screening.
AML is the broader system for managing financial-crime risk. Customer due diligence uses KYC information at onboarding and throughout the relationship, but AML/CTF duties can extend to risk assessments, policies, governance, transaction and behaviour monitoring, enhanced due diligence, suspicious matter reports, threshold transaction reports where applicable, training and record keeping.
| KYC check | KYC and AML workflow |
|---|---|
| Identifies and verifies a person or organisation. | Adds risk and watchlist screening appropriate to the workflow. |
| Supports initial customer due diligence. | May support onboarding and ongoing review, but does not itself create the reporting entity's compliance program. |
| Best suited to identity and entity verification needs. | Best suited where customer verification must be combined with broader financial-crime risk screening. |
AUSTRAC's guidance on ongoing customer due diligence requires reporting entities with a business relationship to review and, where appropriate, update and reverify KYC information and reassess customer risk. That is why a one-time identity check should not be marketed as a complete AML solution.
What should affected businesses do now?
A business that may provide a designated service should first map its actual services and transactions against AUSTRAC's guidance. If it is regulated, the priority is to confirm that its governance, program and customer due diligence processes are operating, not merely documented.
- Confirm the regulatory scope. Record which designated services the business provides, when each service starts and which customers are involved.
- Check AUSTRAC enrolment. The general deadline for newly regulated businesses was 29 July 2026. A regulated business that has not enrolled should address this promptly.
- Complete the ML/TF risk assessment. Consider customers, services, delivery channels, countries and transaction characteristics rather than applying identical controls to everyone.
- Implement and govern the AML/CTF program. Assign an AML/CTF compliance officer, obtain the required approval and oversight, train staff and establish review processes.
- Design customer workflows. Define initial, ongoing and enhanced due diligence, reporting, escalation and record-keeping steps for each relevant customer type and risk level.
- Select supporting technology carefully. Confirm what each provider verifies, what evidence is returned, how exceptions are handled and how records fit into the wider compliance program.
AUSTRAC says its approach is risk-based and proportionate. Its FY26/27 expectations focus on enrolment, a working AML/CTF program, an appointed compliance officer, staff training and readiness to report suspicious matters. This does not remove the obligation to comply, but it reinforces that controls should reflect the business's real risks rather than a one-size-fits-all checklist.
Where can AuthNTick support a KYC workflow?
AuthNTick's verification products can support defined parts of customer onboarding and due diligence. Organisations can choose a KYC Check for identity-focused verification, a KYC + AML Check where the workflow also needs broader risk screening, or a KYB Check for business verification.
A verification result is an input to the reporting entity's compliance decision. AuthNTick does not determine whether a business is regulated, replace legal advice or assume responsibility for the business's AML/CTF program, risk assessment, monitoring or statutory reports.
Frequently asked questions
Which Australian industries became newly regulated from 1 July 2026?
The reforms cover certain designated services commonly provided by real estate professionals, lawyers, conveyancers, accountants, trust and company service providers, and dealers in precious metals, stones and products. Some additional virtual asset services are also covered.
Does every lawyer, accountant or real estate business now need KYC checks?
No. AUSTRAC regulation depends on whether the business provides a designated service with the required geographical link to Australia, not simply on its profession or industry label.
What is the difference between KYC and AML?
KYC is the process of identifying a customer and verifying relevant information about them. AML is the wider compliance framework, which can also include risk assessment, ongoing customer due diligence, transaction monitoring, suspicious matter reporting, governance, training and record keeping.
Are conveyancing and property transactions covered?
Certain services that directly advance the sale, purchase or transfer of real estate are covered. Real estate agents, buyers agents, conveyancers and some property developers may provide designated services, depending on the facts of the transaction.
When are jewellers and precious-goods dealers regulated?
A purchase or sale of precious metals, stones or products is a designated service when it involves at least $10,000 in physical currency, virtual assets or a combination of both, including linked transactions. Card-only or bank-transfer-only purchases do not fall within that particular designated service.
What customer information may need to be checked?
The required KYC information depends on the customer type and risk. It may include identity information, beneficial ownership and control information, the purpose and nature of the relationship, and politically exposed person status.
Is completing a KYC check enough to comply with the AML/CTF laws?
No. KYC can support customer due diligence, but a regulated business may also need an AML/CTF program, an AML/CTF compliance officer, staff training, ongoing due diligence, reporting processes and appropriate records.
What should a business do if it missed the AUSTRAC enrolment deadline?
A business that provides a designated service and has not enrolled should review AUSTRAC guidance and act promptly. It should obtain professional advice where its regulatory position is uncertain.
Are financial services and virtual assets newly regulated industries?
Many financial services were already regulated. The reforms changed obligations for existing reporting entities and extended coverage to certain additional virtual asset services, so these should not all be described as newly added tranche-two industries.
Can an identity-verification provider make a business AML compliant?
An identity-verification provider can support parts of a customer due diligence workflow, but the reporting entity remains responsible for assessing its obligations and maintaining an AML/CTF program appropriate to its business and risks.
Important notice
This article provides general information about Australian AML/CTF reforms and identity verification. It is not legal or compliance advice. AUSTRAC guidance may include exceptions and qualifications, and the application of the law depends on the facts of each business and service.
The article was last reviewed on 26 August 2026. Check current AUSTRAC guidance and obtain professional advice before deciding whether your business is regulated or how it must comply.
Choose the verification workflow that fits your customers
Compare identity verification, KYC with AML screening and business verification, then speak with AuthNTick about the evidence and workflow your organisation needs.
About the author
Rahul Tripathi
Engineering and technology contributor
Rahul Tripathi is an engineer with interests in computer networks, digital systems and applied technology. At AuthNTick, he contributes to guides about digital identity, verification technology and practical screening workflows.
Editorial references
Official and authoritative sources
Use these primary and authoritative references to confirm current requirements for the topic covered in this guide.
- New reporting regime now in force AUSTRAC
- About the reforms AUSTRAC
- Check if you may be regulated AUSTRAC
- Professional designated services AUSTRAC
- Precious metals, stones and products designated services AUSTRAC
- Overview of ongoing customer due diligence AUSTRAC
This guide is general information, not legal advice. Government processes and employer requirements can change, so check the linked source and the requesting organisation’s instructions before acting. Read our editorial and corrections policy.
Next step
Ready to move from research to action?
Use AuthNTick to complete secure Australian background checks, or speak with our team if you need the right workflow for your organisation.
