← Resources
Professional Services AML/CTFAUSTRACCompliance

AML Tranche 2 Is Live: The Onboarding Admin Workflow Lawyers and Accountants Actually Need

AML/CTF Tranche 2 is live for lawyers and accountants. Here's the practical onboarding workflow, not the legal commentary, firms need to run it well.

18 August 2026

Minimalist hand-drawn identity card with a small checkmark stamp beside it and a subtle amber accent, representing a verified, logged onboarding record.

AML/CTF obligations extended to Tranche 2 entities, lawyers, accountants, conveyancers, and trust and company service providers, from 1 July 2026, after enrolment opened at the end of March. Firms now need to be enrolled with AUSTRAC, running an AML program, training staff, verifying clients, and keeping records that can be produced on request. At the same time, updated privacy guidance makes clear that Tranche 2 entities fall under the Privacy Act and shouldn’t be retaining full copies of ID documents simply because it feels safer for AML purposes.

Most commentary on this change explains what the law requires. Less gets said about what it actually looks like on a Tuesday morning when a new client walks in and someone in the firm has to run a compliant onboarding process without it eating the fee-earner’s whole afternoon.

What Tranche 2 actually generates in day-to-day admin

Client verification means collecting and checking identity documents against a defined standard, every time, for every new client that triggers a designated service, not just the ones that feel higher risk. Ongoing monitoring means periodically reviewing existing client relationships rather than treating verification as a one-off box tick at intake. Record-keeping means the business can produce evidence of what was checked, when, and by whom, for as long as the obligation requires. Staff training means every person touching client onboarding actually understands the current process, not just the person who read the AUSTRAC guidance once.

What makes these tasks a genuine admin project is that they all have to happen consistently, for every client, indefinitely, which is a different kind of work than the occasional compliance task most small firms are used to.

Where privacy rules collide with AML habits

The instinct in a lot of small firms has been to keep a full copy of every ID document indefinitely, on the theory that more evidence is always safer. Updated privacy guidance pushes back on that instinct directly: Tranche 2 entities are now squarely inside the Privacy Act, and holding onto full ID copies beyond what AML record-keeping actually requires creates its own compliance exposure.

That means the admin workflow needs two decisions built in that didn’t exist before: what evidence of verification actually needs to be retained, and for how long, before the underlying document itself should be handled according to normal privacy practice rather than kept indefinitely in a client file. Getting this wrong in either direction, holding too much or not enough, creates a different regulator’s problem either way.

For a small firm, this usually means the verification checklist needs a second column next to each document type: what’s captured as evidence of the check, and what happens to the source file afterward, deleted, returned, or retained for a defined period. Without that second column written down, the default tends to be “keep everything forever,” which was a reasonable instinct before Tranche 2 and a genuine liability now.

What a lean onboarding workflow actually looks like

For a small law or accounting firm, a workable process runs on a defined checklist per new client: what documents are collected, how they’re checked, what gets logged as evidence of that check, and what happens to the source documents afterward. That checklist needs to be the same every time, run by someone other than the fee-earner handling the matter, so verification doesn’t quietly become optional on a busy week. HIPPO’s earlier look at the tiered checklist model firms are running covers how standard and higher-risk matters get split so most onboarding volume runs on a checklist rather than a case-by-case judgment call.

Take an eight-partner conveyancing and property law firm onboarding four or five new matters a week. Before Tranche 2, ID checking was largely informal, handled by whichever paralegal had a spare ten minutes. Now every one of those four or five matters needs a documented, consistent verification step, a monitoring flag if the relationship continues, and a clear record of what was retained and what wasn’t. Run informally, that’s the kind of process that holds up fine until the week someone’s away and a step gets skipped.

Which parts belong to a specialist versus the lawyer or accountant

The technical judgment, deciding whether a client relationship is genuinely higher risk, how to respond to a suspicious activity trigger, and how the firm’s AML program is structured, needs to stay with a partner or the person accountable for AML compliance. That’s not admin work, and treating it as such is where firms get into real trouble.

Collecting documents against a defined checklist, logging what was checked and when, tracking which client relationships are due for periodic review, and maintaining the record-keeping system are a different category entirely. This is exactly the kind of structured, repeatable admin work a dedicated coordinator, onshore or offshore, can own directly for law and accounting firms, once the firm’s checklist and escalation triggers are clearly documented.

Building the role: an AML onboarding coordinator

A coordinator role built around this usually starts with mapping the firm’s actual verification checklist against what’s currently happening in practice, since most firms discover the two don’t quite match once they look closely. From there, the coordinator owns running new client verification against the checklist, flagging anything that doesn’t fit the standard pattern to the accountable partner, tracking periodic review dates, and maintaining the record-keeping trail that shows the process was actually followed.

What the coordinator doesn’t do is make the risk assessment call. Every flag goes to the person with the technical accountability. The value of the role is that the flag actually gets raised consistently, rather than depending on whoever happened to process that particular client.

This division holds up under scrutiny in a way an informal process doesn’t. If AUSTRAC or an external auditor asks how a specific client was verified eighteen months ago, a firm running a coordinator-owned checklist can produce the record in minutes. A firm relying on whichever paralegal handled that file at the time is reconstructing the answer from memory, if the person who handled it is even still there.

What to check this month

  • Confirm your firm’s current verification process matches what’s documented in your AML program, not just what’s supposed to happen.
  • Check how long ID documents are being retained and whether that matches current privacy guidance rather than old habit.
  • Identify who owns tracking periodic review dates for existing clients, and whether that’s currently happening at all.

If AML onboarding is still running informally through whoever has a spare ten minutes, that’s a specific, definable role worth building properly before a gap gets found the hard way. Book a Connect Session

Work with HIPPO

Ready to build
your back office?

Book a Connect Session to talk through how a specialist role fits your business. You leave with a written Leverage Plan the same day.

Book a Connect Session