AUSTRAC Tranche 2 for Queensland Law Firms: What Partners Need Ready by 1 July 2026
On 1 July 2026, your firm stops being a law practice and starts being an AUSTRAC reporting entity. You have a little over ten weeks until commencement (1 July) and around fourteen weeks to the formal enrolment deadline (29 July). The enrolment window is already open. If you think this is someone else’s problem, you haven’t read Table 6 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 lately.
This isn’t a drill and it isn’t optional. The Law Council of Australia has been fighting the shape of it for years. The legislation passed. The start date is locked in. And the maximum civil penalty for a body corporate that gets this wrong is 100,000 penalty units, which at the current $330 rate works out to $33 million per contravention.
Here’s what managing partners in Brisbane, the Gold Coast, and Sunshine Coast firms need to have in place before 1 July.
Will this actually apply to your firm?
Probably yes. AUSTRAC is not regulating “lawyers” as a profession. It is regulating a list of “designated services” that most Queensland firms provide as core work.
You’re captured if you provide any of these services in the course of business:
- Conveyancing. Assisting in the sale, purchase, or transfer of real estate. This is the headline trigger for most SE QLD firms.
- Buying, selling, or transferring a body corporate or legal arrangement. Share sales, business sales, trust restructures.
- Receiving, holding, controlling, or managing a client’s property as part of a transaction. Trust account activity, settlement funds, deposit holding.
- Organising equity or debt financing relating to a body corporate or legal arrangement.
- Acting as a director, secretary, trustee, or nominee shareholder, or arranging for someone else to do so.
- Creating or restructuring a body corporate or legal arrangement.
- Providing a registered office or principal place of business address for a client entity.
If your firm does residential or commercial conveyancing, company formations, trust set-ups, or SMSF structuring, you are in. If you run a purely litigation practice with no trust account movement tied to asset transfers, you might be out. AUSTRAC’s reform guidance and decision aids on austrac.gov.au cover the scoping question, and the Queensland Law Society’s resource centre and CPD program have been running scoping sessions through late 2025 and early 2026.
“We think we’re probably okay” isn’t an answer. You need to document the scoping decision.
What does AUSTRAC actually expect you to have ready?
Five things, and none of them are optional.
1. An enrolment on the AUSTRAC Reporting Entities Roll. Enrolment opened on 31 March 2026. You must be enrolled by 29 July 2026, but AUSTRAC expects you to be operating as if enrolled from 1 July. Leaving this to late July is asking for trouble.
2. A written AML/CTF program. This is your firm’s risk assessment plus the policies and procedures you use to manage that risk. AUSTRAC has released Legal Profession and Conveyancing Program Starter Kits specifically for small, low-complexity firms. They are a starting point, not a finish line. You still need to customise them to your actual client base, your actual matter types, and your actual risk exposure.
3. Customer Due Diligence (CDD) procedures. Before you provide a designated service, you need to identify the client, verify that identity using reliable documents, understand the nature and purpose of the matter, and identify the beneficial owner where the client is a company or trust. Enhanced due diligence applies to higher-risk clients: politically exposed persons, offshore structures, unusually complex trust arrangements.
4. Suspicious Matter Report (SMR) capability. If you form a suspicion on reasonable grounds that a matter relates to money laundering, terrorism financing, or a proceeds-of-crime offence, you have three business days to submit an SMR to AUSTRAC (24 calendar hours for terrorism-related suspicions). Where you assess that the SMR involves information covered by legal professional privilege, the timeframe extends to five business days while you make that assessment. Not three weeks. Not “when the partner gets back from holiday.”
5. Record-keeping for seven years. CDD records, transaction records, SMR copies, and your AML/CTF program documentation must be kept for seven years from the end of the business relationship or the completion of the occasional transaction. That is a seven-year, searchable, auditable records problem, which is exactly the document management problem most firms already fail at.
What about client legal privilege?
The Act preserves legal professional privilege. You are not required to disclose privileged communications in an SMR, and AUSTRAC’s guidance confirms this.
But here’s the nuance the Law Council has been banging on about: privilege protects legal advice, not the fact of a transaction. If you are receiving funds into a trust account and you form a reasonable suspicion about the source of those funds, the transaction details and the identity of the parties are not privileged. The legal advice you gave around the transaction may be. Working out where the line sits in a specific matter will be the single hardest judgment call your firm has to make post-July.
The tipping-off offence carries a maximum penalty of two years imprisonment or 120 penalty units (currently $39,600), or both. The post-March 2025 reforms reframed the test around whether a disclosure “would or could reasonably be expected to prejudice an investigation,” which is broader and more nuanced than the old blanket prohibition. There is also a specific carve-out for legal practitioners under s123(4), but it is narrow and you cannot tell a client you have lodged, or intend to lodge, an SMR. Get the test wrong and the personal consequences are criminal, not civil.
How strict is AUSTRAC going to be on day one?
AUSTRAC CEO Brendan Thomas has been clear in public statements through late 2025: the regulator “doesn’t expect perfection on day one” and “won’t be throwing the book at businesses who are trying to follow the law.” AML, in his framing, is a practice, not a test you pass once.
Don’t confuse that with a grace period. Thomas has been equally clear that there will be “no excuses for wilful non-compliance.” If your firm hasn’t enrolled, hasn’t written a program, and hasn’t done any CDD by mid-2026, that’s not “trying to follow the law.” That’s ignoring it.
The realistic read: AUSTRAC will be educative with firms making genuine efforts and punitive with firms that treat 1 July as an aspiration.
What will this cost to set up properly?
For a typical 10 to 50 lawyer firm in SE QLD, budget for:
- AML/CTF Compliance Officer time. Partner-level, with enough delegation to a Practice Manager or dedicated compliance lead to keep it running. Expect 0.2 to 0.5 FTE once established, more during the ramp.
- Customer identification and verification technology. Third-party ID verification tools (InfoTrack, First AML, GBG, and similar) starting around $5 to $15 per verification. If you do 300 conveyances a year, do the maths.
- Training. Every staff member who onboards clients, handles trust accounts, or touches a designated service needs annual AML/CTF training. Non-negotiable and documented.
- Document management upgrades. Seven-year retention, auditable access logs, clean metadata, and searchable records. If your firm still runs on shared drives and email attachments, this is now a compliance blocker, not just a productivity issue.
- Policy drafting and independent review. The AUSTRAC Starter Kit gets you 60% of the way. A lawyer or consultant familiar with the regime closes the gap.
The firms that will struggle most are the ones that have been deferring IT and compliance spend for years. A well-run managed IT environment with proper permissions, retention, and audit logging makes Tranche 2 a policy exercise. A messy one makes it a rebuild.
The Privacy Act overlap nobody’s talking about
Tranche 2 is landing at the same time the Commonwealth is moving on the small business exemption under the Privacy Act. The Government’s 2023 response to the Privacy Act Review agreed in principle to remove the under-$3M turnover exemption. The Privacy and Other Legislation Amendment Act 2024 didn’t make that change, but further tranches of reform are flagged for 2026.
Most mid-size Queensland firms are already over the $3M threshold and covered by the Privacy Act regardless. But even if your firm has been relying on the small business carve-out, AUSTRAC obligations will blow it up anyway. The moment you’re doing CDD, you’re collecting and holding sensitive personal information at scale, and APP 11 requires reasonable technical and organisational measures to protect it. Multifactor authentication. Access controls. Encryption at rest and in transit.
If your insurance renewal is coming up, this matters for a different reason too. Insurers are tightening cyber policy requirements and asking harder questions about how law firms store and protect client data. Tranche 2 makes your answers verifiable, for better or worse.
What you should do before 1 July 2026
- Scope your designated services this month. Sit down with each practice group head. List every service the firm provides. Use AUSTRAC’s online tool. Document the decision in writing, including services you’ve determined are not captured and why.
- Appoint an AML/CTF Compliance Officer. A named partner, in writing, with authority to stop a matter if CDD isn’t complete. This is not a role you can leave vacant.
- Enrol with AUSTRAC. Don’t wait for the July deadline. Enrol now, work out any system issues while the queue is short.
- Download and customise the AUSTRAC Legal Profession Starter Kit. Treat it as a template, not a deliverable. Your firm’s risk profile is not generic.
- Get your CDD technology chosen and integrated with your practice management system by end of May. Running identity verification through email attachments is not going to work.
- Run a full staff training session in June. Every fee earner, every paralegal, every legal secretary. Record attendance.
- Fix your document management and retention now. Seven-year auditable records don’t happen by accident. If your matter files are in OneDrive folders named after lawyers instead of matters, start there.
- Write the tipping-off protocol. What happens when a staff member forms a suspicion? Who do they tell? Who decides? How is the conversation with the client handled? Document it before you need it.
If you’re not sure where your gaps sit, our cyber compliance work covers the technology and records side of Tranche 2 readiness: access controls, retention, document governance, and the security posture insurers and regulators will be testing. We don’t write your AML/CTF program (that’s for your AML lawyer or specialist consultant), but we make sure the plumbing underneath it actually works.
Book a conversation before May if you want to go into enrolment knowing your systems won’t be the thing that fails on 2 July.
Straight answer, no surprises.
Need to prove where you stand?
Compare Essential Eight, SMB1001 and DISP side by side, and see the evidence each one expects you to produce.
More on this: Compliance articles · Cyber Compliance