IronbarkAML
AUSTRAC Tranche 2

7 things that became true when Tranche 2 started.

The deadline is 53 days behind us. For accountants, lawyers, conveyancers and real estate agents providing designated services, these seven things are already true, and an unwritten program is already a gap rather than an upcoming task.
Published 2026-08-13Last reviewed 2026-08-13

TL;DR

  • Reporting-entity status follows the service you provide, not the enrolment you have completed.
  • There is no grandfathering. Matters opened since commencement carried the obligations at the time.
  • An unwritten AML/CTF program is itself the contravention, not merely evidence of one.
  • The seven-year record-keeping clock is already running on files you have closed.
  • Nobody sends a notice. The useful question is the size of your gap today, not the date behind you.

Start with what you can measure

Every item below is a statement about the present. None of them is a countdown, because there is nothing left to count down to. That changes what a practice should do first: the deadline was a date to prepare for, and a gap is a thing to size and close in priority order.

If you want the specific answer for your practice before reading further, the readiness check is free, needs no login, and takes about two minutes.

  1. You are a reporting entity, whether or not you have enrolled

    Status follows the service, not the paperwork. If you provide a designated service listed for your profession, you are a reporting entity from the day the obligation commenced. Enrolment is something a reporting entity is required to do, not the thing that makes you one. A practice that has not enrolled is not outside the regime. It is inside the regime and behind.
  2. Every matter you have opened since is inside the regime

    There is no grandfathering for work started after commencement. Each designated service provided since then carried customer due diligence and record-keeping obligations at the time it was provided, and those obligations do not become retrospectively satisfied by writing a program later. The file was either built to the standard or it was not.
  3. An unwritten program is a contravention in its own right

    The Part A risk assessment and Part B customer identification procedures are not documentation of compliance. They are the compliance. Sections 81 to 85 of the AML/CTF Act 2006 (Cth) require a reporting entity to adopt and maintain the program. Doing the right things without a written program does not satisfy it, because there is nothing to independently review.
  4. Somebody in your practice is the AML compliance officer

    The role has to exist and has to be held by a person with the authority to do it. In a sole practice that person is you, which means the officer reviewing the file and the practitioner who opened it are the same person. That is permitted, and it is exactly why the written procedures matter more, not less.
  5. The record-keeping clock is already running on files you have closed

    Records must be retained for seven years from the date the service was provided or the customer relationship ended, whichever is later. That clock started on the first captured matter, not on the day you get organised. Files closed months ago are already inside a retention period, and the gap in them is not fixable by a future process.
  6. You can be required to report a suspicion about a client you cannot warn

    A suspicious matter report is lodged within three business days of forming a suspicion on reasonable grounds, and within 24 hours where it relates to terrorism financing. Section 123 makes it an offence to tell the customer, or anyone else, that the report has been formed, lodged or contemplated. For a professional whose instinct is to raise things with the client, this is the obligation most likely to be breached by good manners.
  7. Nobody is going to send you a letter about any of this

    There is no activation notice, no onboarding email, no regulator-issued checklist arriving in the post. The obligation attached quietly and the first formal contact for most practices will be a compliance question rather than a reminder. Which is why the useful measure right now is not what the deadline was. It is how large your gap is today.

What Ironbark does, and what it does not

Of the seven, Ironbark touches two: the customer due diligence in item 2 and the ongoing monitoring that keeps a file current after it is opened. It is a Trust Score per ABN, built from six published sub-scores against Australian registers, with a source and a last-refreshed timestamp on every field so the output is usable in a working paper.

It does not write your program, does not act as your AML compliance officer, does not lodge your reports, and is not legal advice. Items 1, 3, 4, 5 and 6 above are yours. Anyone selling you a tool that claims otherwise is selling you a compliance problem with a login.

The weights, sources and refresh cadence are published at /methodology with a change log, so the method can be checked rather than trusted.

Frequently asked

I have not enrolled with AUSTRAC yet. What should I do first?

Enrol, and do not wait until the program is finished to do it. Enrolment is via AUSTRAC Online and is a precondition to lodging anything, including a suspicious matter report you may need to lodge before your program is complete. Take your own advice on how to describe the position in the enrolment, but do not treat an incomplete program as a reason to stay unenrolled.

Is a template AML/CTF program from my professional body enough?

A template is a starting structure, not a completed Part A. The risk assessment has to reflect your actual customers, services, delivery channels and jurisdictions, and a document that could belong to any practice in the country is evidence that no assessment was performed. Use the template as scaffolding and put your own risk analysis inside it.

How far behind am I, realistically?

That depends on which obligations you already meet through existing professional practice, which is more than most practitioners expect. Identity verification, record-keeping and file discipline often partly exist already. The free readiness check at /aml-readiness-check scores 12 obligation domains and returns your gaps in priority order, so you get a specific answer instead of a general anxiety.

Does Ironbark write my AML/CTF program?

No. Ironbark is the verification and ongoing monitoring layer that sits inside a program: ABN status, entity type, directorship, sanctions and PEP screening, insolvency and court signals, with a timestamped citation on every field. The written program, the AML compliance officer, the reporting, the independent review and the training remain yours. Scope and method are published at /methodology.

What does verification cost while I sort the rest out?

The free tier is 10 checks a month with no card. A single check is $0.49 with credits that never expire. Continuous monitoring of an active counter-party list starts at $29 a month. Prices are in Australian dollars and are the amount billed: IRONBARKTECH holds an ABN but is not registered for GST, so no GST is added.

Keep reading