Almost three months into Tranche 2, a useful question for professional firms is: could someone follow a recent client file and understand the AML checks, risk decisions and follow-up?

AUSTRAC section 167 notices put that question into sharper focus. On 28 August 2026, AUSTRAC announced notices to businesses that appeared to provide regulated services but had not enrolled.[1] Almost four weeks later, that announcement remains relevant—but September’s enrolment figures and regulatory guidance make this a good time to review what happens after enrolment.

This article explains the notices and offers a practical September review for firms at different stages of implementation.

What has changed since the August announcement?

AUSTRAC’s enrolment page, updated on 18 September, reports the following figures as at 17 September 2026.[11]

AUSTRAC enrolment counts by industry category, as at 17 September 2026.
Industry category used by AUSTRAC Enrolments
Accounting and professional services 13,780
Conveyancer 1,600
Jewellers and dealers in precious metals and goods 320
Lawyer 6,580
Real estate 18,350

These are enrolment counts, not compliance scores. They do not show whether a firm’s procedures work or establish how many businesses should have enrolled. Coverage depends on designated services, not simply membership of a profession.[7][11]

On 22 September, AUSTRAC also introduced AUSTRAC Central, the new name for its Contact Centre. Its announcement expressly reassures businesses that seeking guidance does not increase regulatory scrutiny.[19]

Together, these updates give firms a useful September agenda: clarify coverage, confirm enrolment where required and examine whether their processes operate consistently.

What did the section 167 announcement actually say?

AUSTRAC identified real estate agents, accountants, lawyers and jewellers among recipients. It sought information to determine whether businesses provided regulated services and met their obligations.[1]

The August announcement does not say every Tranche 2 business received a notice. Nor does receiving one itself establish a breach.[1][3]

What is an AUSTRAC section 167 notice?

Section 167 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 allows an authorised officer to require specified information or documents through a written notice.[3]

The officer must reasonably believe that the person has relevant information, or possession or control of a relevant document. The statutory scope concerns compliance with or enforcement of offence or civil penalty provisions of the Act or regulations, and certain related offences under the Crimes Act 1914 or Criminal Code.[3]

In everyday terms, AUSTRAC can formally require material that helps it examine compliance. The power is not limited to businesses already enrolled.[2][3]

AUSTRAC says the notice and covering letter will explain the power used, why the notice was issued, what the recipient needs to do and the possible consequences of failing to comply. They also provide contact details for questions or difficulties complying.[2]

Is a section 167 notice an enforcement action?

It is a compulsory information-gathering step that can support supervision or enforcement. It is not itself a fine, court ruling or determination that the recipient has contravened the law.[2][3]

That distinction follows from the nature of the power; it does not guarantee that no enforcement action will follow. Information obtained may inform AUSTRAC’s next steps. Equally, the notice is not a voluntary survey: AUSTRAC warns that failure to comply can have serious consequences.[2]

What does AUSTRAC expect by September?

The relevant Tranche 2 obligations commenced on 1 July 2026. AUSTRAC’s commencement update identified AML/CTF programs, customer due diligence, suspicious matter reporting and recordkeeping among the requirements for newly regulated businesses.[4]

Its 2026–27 regulatory priorities include intervention where newly regulated reporting entities have not enrolled or are recklessly involved in, or complicit with, criminal activity. AUSTRAC also expects businesses to complete risk assessments, allocate governance responsibilities and put appropriate policies into daily use.[5]

There is room for improvement as businesses gain experience. AUSTRAC’s May 2026 expectations statement recognises that controls and reporting will improve over time. That sits alongside expectations of enrolment, an AML/CTF program, a compliance officer, staff training and readiness to report suspicious matters.[6]

Which Tranche 2 businesses may be affected?

The newly regulated sectors include legal professionals, accountants, conveyancers, real estate professionals, trust and company service providers, and dealers in precious metals and stones.[7]

The starting point is the designated service: a service specified in the legislation. Coverage depends on the activities undertaken, the required connection to Australia and any applicable exceptions—not simply the business’s professional title.[7]

These are starting points for understanding coverage, not a complete classification of any business.

Is enrolling with AUSTRAC enough?

No. Enrolment places a business on AUSTRAC’s Reporting Entities Roll; it does not establish that all applicable compliance requirements have been implemented.[11][12]

AUSTRAC’s general rule is to apply for enrolment no later than 28 days after the day a business starts providing a designated service. Its commencement guidance specified 29 July 2026 for newly regulated businesses operating from 1 July.[4][11]

That enrolment timeframe is not a general extension for implementing other obligations. AUSTRAC says an AML/CTF program must be in place before a business starts providing a designated service.[12]

An enrolment confirmation therefore answers one question. It does not show how staff identify customers, recognise unusual activity or document decisions.

A September review — can you follow one client file?

A useful internal exercise is to select a recent matter involving a designated service and follow its records from onboarding to the latest decision. The questions below draw on AUSTRAC’s program and customer due diligence guidance. They are a practical review aid, not an AUSTRAC checklist or a complete compliance assessment.[12][16]

A practical file-review aid. It is not an AUSTRAC checklist or a complete compliance assessment.
Question to consider Evidence that may help explain the work
Why was the matter treated as a designated service? Service description and recorded scope decision
Who was the customer, and who owned or controlled it? Customer information and relevant beneficial ownership records
How was customer risk assessed? Risk assessment, supporting information and reasons for the rating
Were relevant PEP and sanctions checks addressed? Checks, potential matches and their resolution
Did circumstances require enhanced due diligence? Additional enquiries, findings and required approvals
What happens next? Monitoring arrangements, escalation responsibilities and review records

A missing record is a reason to investigate; this exercise alone cannot establish a breach. Conversely, a folder of completed forms does not prove that decisions were sound.

Check the business framework too

The client file sits within a broader AML/CTF program: a business ML/TF risk assessment and policies, procedures, systems and controls. AUSTRAC uses ML/TF risk to include proliferation financing risk. Programs require implementation, review and periodic independent evaluation, proportionate to the business.[12]

Staff need training and clear responsibilities.[6] Processes also need to cover suspicious matter reporting and threshold transaction reporting where applicable. The latter generally concerns $10,000 or more in physical currency in providing a designated service—not every electronic payment above that amount.[4][17]

Adverse media can inform risk assessment; additional checks should reflect the applicable requirements and risk. Ongoing monitoring helps identify changes and unusual activity.[15][16]

As September ends, this offers a manageable starting point: identify a gap, assign responsibility and record the follow-up. The month-end is an editorial review point, not a new statutory deadline.

Hypothetical example — enrolled, but still joining the pieces

A small accounting practice enrolled with AUSTRAC in July. For this hypothetical, assume its company formation work meets the designated-service conditions. In late September, a partner reviews one recent company formation file.

The identity checks are saved in an email folder. An ownership diagram sits in a spreadsheet. The customer risk rating appears on a separate form, but the reasons are unclear. A staff member remembers resolving a screening match; the file does not explain how.

The practice has not received a section 167 notice. Its partner nevertheless uses the August announcement as a prompt to examine how the team records its work.

The review does not, by itself, establish whether the firm has complied with every obligation. It reveals practical questions worth resolving: where decisions are recorded, who checks outstanding issues and how a colleague can reconstruct the work. Enrolment has been completed; consistent implementation remains a separate task.[12][16]

Practical considerations if a business receives a notice

Practical considerations may include:

AUSTRAC’s guidance identifies the contact details supplied with a notice as a route for raising uncertainty or difficulty complying.[2] These are general organisational considerations; they do not determine what a particular notice legally requires.

Making the next client file easier to manage

If that example feels familiar, a useful software evaluation starts with the workflow: can the team connect customer information, beneficial ownership, risk decisions and follow-up records without repeatedly assembling them by hand?

Flagship AML brings customer due diligence, beneficial ownership analysis, risk assessments, enhanced due diligence and monitoring into a structured workflow. Subscriptions include unlimited Initial KYC due diligence reports, enhanced due diligence and risk review reports, ML/TF risk assessments and use of the Beneficial Ownership Calculator.[18][20]

To assess whether it suits your practice, ask about a free trial and explore the workflow using a fictional example.[21] Consider whether a colleague could understand the checks and decisions from the resulting records. Software supports the process; the business remains responsible for its obligations.

Explore how a structured workflow can help your team record its customer checks and risk decisions.

Explore Flagship AML with a free trial

View subscription options

Frequently asked questions

Is a section 167 notice a penalty?

No. It requires information or documents. It is not itself a penalty or a finding of breach, although it may support an enforcement process.[2][3]

Can AUSTRAC require documents?

Yes. Section 167 permits written notices requiring relevant documents or information, subject to the statutory conditions.[3]

Who can receive a section 167 notice?

The power can extend to any person meeting its conditions, including someone who is not already enrolled with AUSTRAC.[2][3]

Does AUSTRAC enrolment mean a business is AML compliant?

No. Applicable program, due diligence, reporting and recordkeeping requirements extend beyond enrolment.[4][12]

Do all professionals have identical obligations?

No. Coverage depends on designated services and applicable conditions; compliance measures also reflect business and customer risk.[6][7]

Sources and further reading

  1. AUSTRAC — Issues notices to non-enrolled businesses, 28 August 2026.
  2. AUSTRAC — New information gathering powers.
  3. Anti-Money Laundering and Counter-Terrorism Financing Act 2006 — current text, particularly section 167.
  4. AUSTRAC — New reporting regime now in force, 1 July 2026.
  5. AUSTRAC — Regulatory priorities for 2026–27.
  6. AUSTRAC — Update to regulator statement of expectations, May 2026.
  7. AUSTRAC — Who and what we regulate.
  8. AUSTRAC — Professional designated services.
  9. AUSTRAC — Real estate designated services.
  10. AUSTRAC — Precious metals, stones and products designated services.
  11. AUSTRAC — Enrol with us overview.
  12. AUSTRAC — Your AML/CTF program overview.
  13. AUSTRAC — Overview of customer due diligence.
  14. AUSTRAC — Overview of initial customer due diligence.
  15. AUSTRAC — Enhanced customer due diligence.
  16. AUSTRAC — What you must monitor for.
  17. AUSTRAC — Threshold transaction reports.
  18. Flagship AML — Platform features (product information only).
  19. AUSTRAC — Introducing AUSTRAC Central, 22 September 2026.
  20. Flagship AML — Pricing and subscription inclusions (product information only).
  21. Flagship AML — Free-trial invitation and contact page (product information only).

This article provides general information only and is not legal advice. AML/CTF obligations depend on the services a business provides and its particular circumstances. Businesses should obtain independent legal or compliance advice where appropriate.