3 months into Tranche 2: 5 AML traps accounting firms need to avoid

Regulation

Almost three months into the new Tranche 2 AML/CTF regime, the challenge for accounting firms is changing, writes Dan Ward.

01 October 2026 • By Dan Ward • 6 minutes read
Share this article on:

The question is no longer simply whether a firm has enrolled with AUSTRAC or prepared an AML program. The harder question is whether the framework actually works when staff are dealing with clients and real transactions.

AUSTRAC’s recent use of section 167 notices is a useful reminder of that shift. On 28 August, AUSTRAC announced that it had begun issuing formal information-gathering notices to businesses, including accountants, that appeared to be providing designated services without being enrolled.

A section 167 notice is not simply a reminder. It can compel a person to provide information or documents relevant to compliance or enforcement. Section 169 also provides that a person cannot refuse to comply merely because the material might tend to incriminate them or expose them to a penalty.

For most accounting practices, however, I think the more useful focus is on the practical points where AML processes can break down.

1. Recognising when ordinary accounting work becomes a designated service

Not every service provided by an accountant is regulated under the AML/CTF regime.

The difficulty is that the position can change depending on what the accountant is asked to do.

For example, providing tax advice about the consequences of selling a company may not, by itself, be a designated service. Becoming involved in carrying out or progressing the sale itself may produce a different result. Knowing which activity triggers a designated service is not always straightforward.

 
 

In my view, this is one of the first practical issues firms should address.

The person opening a new matter needs to recognise when AML obligations may arise and know what happens next. It is not enough for that knowledge to sit with one partner or in an AML manual.

2. Identity verification can create a false sense that onboarding is complete

Checking a passport or driver’s licence is visible, familiar and relatively easy to understand.

That can make identity verification feel like the main AML task.

It is not.

Customer due diligence may also involve understanding who ultimately owns or controls a company or trust, assessing the customer’s risk, conducting appropriate screening and deciding whether further enquiries are needed.

This can become more difficult where there are trusts, corporate trustees, layered ownership structures or overseas entities.

Identity verification answers an important question: is this person who they say they are?

It does not answer every question an accounting firm may need to ask.

3. A risk rating is only useful if someone can understand the reasoning

Most firms will have a process for assigning customers a risk rating.

I would focus less on whether the box says Low, Medium or High and more on whether the file explains why.

The assessment may take into account the customer, services being provided, geographic exposure, delivery channels and other relevant risk factors.

If circumstances change, the reasoning may also need to change.

A risk rating should therefore be more than a label generated during onboarding. It should be a decision that another person in the practice can understand and, if necessary, revisit.

4. Unusual cases are where procedures are really tested

Straightforward clients are rarely the hardest part of AML compliance.

The real test comes when something does not fit neatly into the process.

A screening check may produce a possible match. Ownership information may be inconsistent. A customer may resist providing information. A transaction may not make sense based on what the firm knows about the client.

No checklist can anticipate every situation.

Firms therefore need clear escalation processes. Staff should know who to speak to, when further enquiries are required and who has authority to make the final decision.

In my view, recording the reasoning is just as important as recording the outcome.

AML procedures should support professional judgement, not attempt to replace it.

5. Ongoing monitoring needs an owner, not just a policy

Another practical risk is treating AML compliance as something completed when the client is onboarded.

Clients and circumstances change.

Ownership may change. A new trustee or director may be appointed. A client may expand into another jurisdiction. New information may emerge that affects the original risk assessment.

Firms therefore need to decide who is responsible for ongoing monitoring and what should trigger a review.

A policy saying that customer information will be kept up to date is useful. Someone also needs to know when to act on it.

Making the framework work

For accounting practices, I think three practical questions are particularly useful.

Do staff know when the AML process starts?

Do they know who makes the difficult decisions when something unusual occurs?

And does someone take responsibility for reviewing the client relationship when circumstances change?

If the answer to those questions is clear, the firm is much more likely to have an AML framework that works in practice rather than one that exists mainly on paper.

That, in my view, is where the focus should now be.

 

Dan Ward is a commercial lawyer admitted to practise in Australia and Papua New Guinea and co-founder of Flagship AML. 

Accountants DailyWant to see more stories from trusted news sources?
Make Accountants Daily a preferred news source on Google.
Tags: