AML/CTF Tranche 2 compliance software: mandated vs optional requirements
You just want to do what's mandated — nothing more. Compliance is not interesting enough to dedicate too much time, effort and expenditure on.
Is AML software legally required?
No. The AML/CTF Act 2006 (Cth) requires a documented AML/CTF program, an ML/TF risk assessment, a customer due diligence process and 7 years of records — not any particular software.[2] Software is one way to run and evidence those obligations; it is not itself an obligation.
Mandated requirements
These are the outcomes the AML/CTF Act 2006 (Cth) and AUSTRAC's rules actually require of every Tranche 2 reporting entity — regardless of whether you use software to meet them:
| Requirement | What's mandated |
|---|---|
| AUSTRAC enrolment | Enrol with AUSTRAC before providing a designated service. |
| AML/CTF program | A program document covering all 6 of AUSTRAC's minimum components: governance, risk assessment, ongoing CDD, third-party reliance, personnel due diligence and training, and independent evaluation. |
| Compliance officer | Appointed at management level within 28 days of first providing a designated service, with AUSTRAC notified within 14 days. |
| Staff due diligence | Background checks and suitability assessments for personnel involved in providing a designated service, before they take on AML/CTF-related functions. |
| Staff training | Training for anyone involved in providing a designated service, with retraining as it falls due. |
| Customer due diligence | Verify customer identity, screen against sanctions and politically exposed person (PEP) lists, and apply enhanced due diligence to higher-risk customers. |
| Suspicious matter reporting | A defensible record of every suspicious-matter assessment — including decisions not to file — which AUSTRAC expects you to be able to explain. |
| Threshold Transaction Reporting | A report lodged with AUSTRAC within 10 business days for any cash transaction of $10,000 or more. |
| Record keeping | Retention of all of the above for 7 years. |
| Independent evaluation | Evaluation of the program by an independent party at least once every 3 years. |
Optional requirements
None of the following is required by the AML/CTF Act 2006 (Cth) or AUSTRAC. They're capabilities software vendors sell on top of the legal minimum — useful in the right circumstances, but not something a Tranche 2 firm has to buy:
| Capability | Why it's optional |
|---|---|
| Automated transaction monitoring | AUSTRAC accepts a documented, consistently applied manual process for Tranche 2 — this is built for Tranche 1 entities processing high transaction volumes.[1] |
| Automated identity verification | Speeds up CDD but a manual document check, applied consistently, satisfies the requirement. |
| Bundled sanctions/PEP screening | Convenient, but the underlying obligation can be met with free government and ASIC-adjacent watchlists checked manually. |
| Case management workflow automation | Helps consistency at higher client volumes; not necessary at low volume. |
| Integrations with practice management or trust accounting software | A convenience layer, not a compliance requirement. |
| Dashboards, analytics and multi-user permissions | Useful for larger teams; irrelevant to a sole practitioner. |
What AML compliance software cannot do
AML compliance software cannot make your business compliant by subscription — under the AML/CTF Act 2006 (Cth), responsibility for the program always sits with the reporting entity. In practice, four things stay with you no matter what you buy:
- Owning the risk assessment. A tool can structure your ML/TF risk assessment, but the judgments — which customers, services and channels are higher risk for your firm — must be yours, and AUSTRAC expects the document to reflect your business, not a template's.[2]
- Approving the program. Your governing body or senior management must approve the AML/CTF program and its material updates. Software can generate the draft; it cannot sign it.
- Forming suspicion. Deciding whether a matter is suspicious enough to report to AUSTRAC is a human judgment. Software can log the decision and its reasoning — the part firms most often fail to evidence — but cannot make it.
- Holding the compliance officer role. A person at management level must be appointed within 28 days of first providing a designated service, with AUSTRAC notified within 14 days of the appointment.[7]
Any vendor implying its product removes these responsibilities is overselling. The honest pitch for software is narrower: it makes the work you must do anyway faster, more consistent and provable.
Getting the obligations right
- You need to be sure you're covering everything AUSTRAC actually requires — not more, not less.
- You need to be sure you're doing it correctly, not just filling in a generic template.
- You need it done on time — before enrolment closes, before your first designated service, before retraining falls due.
- You need to know which obligations actually apply to your profession, because Tranche 2 doesn't ask a conveyancer for the same thing it asks a real estate agent.
Keeping the effort proportionate
- You don't care about AML compliance as a subject — you want it handled, not studied.
- You don't want to spend more than the risk justifies, especially while client volume is still low.
- You want to try it against your real business before paying for anything.
Being able to prove it later
- You need a record you can hand over, not a memory of having done the work, if AUSTRAC ever examines your firm.
- You need the same evidence ready for your 3-yearly independent evaluation.[6]
- You need the compliance officer role — and the personal exposure that comes with it — to not be quietly resting on someone's memory of a decision made 18 months ago.
Trusting the tool itself
- You need to know it's actually built around what AUSTRAC requires, not a generic global AML checklist.
- You need to know it's sized for a Tranche 2 practice, not repurposed bank software you're paying to not use.
- You need a human to ask when a client situation doesn't fit the workflow.
Trusting the vendor
- You need reasonable confidence this vendor will still be operating in 7 years — that's how long you're required to keep the records it's storing.
- You need an easy way out if it doesn't work: your data exported, no long lock-in, on something this new and this regulated.
Ready to shortlist actual providers? See which AML software providers serve Tranche 2 businesses, with real pricing for each.
How we designed a lightweight AML platform to meet this criteria
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.
- Built around AUSTRAC's actual requirements
- Single maintained compliance file
- No compliance expertise required
- 25 minute initial compliance setup
- Obligations calendar & reminders
- Instant data export
Frequently asked questions
Can I comply with Tranche 2 using spreadsheets instead of AML software?
Yes. AUSTRAC requires a documented AML/CTF program, risk assessment, customer due diligence process and 7-year record keeping — it does not require software. A firm that runs these on spreadsheets and document templates, applied consistently, can be compliant. Software mainly reduces the effort of keeping records complete, consistent and audit-ready.
Does AUSTRAC approve, accredit or endorse AML compliance software?
No. AUSTRAC does not certify, accredit or endorse any AML compliance software, and no vendor can truthfully claim to be "AUSTRAC approved". Responsibility for the program always sits with the reporting entity, whatever tools it uses. Treat any "AUSTRAC certified" marketing claim as a red flag.
What is the difference between AML compliance software and an identity verification service?
An identity verification (IDV) service performs one task: confirming a person is who they claim to be, usually against document and government-database checks. AML compliance software covers the whole obligation set — program, risk assessment, CDD workflow, registers and reporting decisions — and often plugs an IDV service in as one step. Buying IDV alone does not give you an AML/CTF program.
Can Xero, MYOB or my practice management system handle AML compliance?
Not on their own. Accounting and practice management systems do not produce an AML/CTF program, an ML/TF risk assessment or suspicious-matter records. Some AML platforms integrate with them — for example, trust-accounting products that connect to Xero, MYOB and QuickBooks — but the AML/CTF capability is a separate product layer.
Do I still need an AML/CTF compliance officer if I buy software?
Yes. Every reporting entity must appoint a compliance officer at management level within 28 days of first providing a designated service, and notify AUSTRAC within 14 days of the appointment. Software can record the appointment and support the role, but it cannot hold it.
Am I personally liable if something is missed, even though I'm using AML software?
Software doesn't transfer responsibility. Under the AML/CTF Act 2006 (Cth), obligations sit with the reporting entity and the individuals who hold governance roles — your compliance officer and the management that approved the program — regardless of what tools you use. A platform can reduce the chance something is missed and give you a record to point to, but it cannot stand in for you if AUSTRAC asks why a decision was made.
Can I trial AML compliance software before committing to a paid plan?
Most Tranche 2 platforms let you build at least a draft program or risk assessment for free before any payment is required — identity verification is usually the first genuinely paid step. Test the free parts against your actual business before paying for anything; a platform that only shows its workflow after a card is on file is much harder to evaluate honestly.
Is free AML compliance software enough for a small firm?
For a straightforward, lower-risk practice, a free toolkit that maps to AUSTRAC's 6 minimum program components can be enough to build and evidence a proportionate program. Higher-risk or more complex businesses may justify a paid platform with bundled screening, or tailored advice from a consultant or lawyer.
What happens to my compliance records if my software vendor shuts down or is acquired?
Worth checking before you sign up, not after. AML/CTF records must be kept for 7 years, which will likely outlast some vendors in a market this new. Before committing, confirm you can export your full history — program documents, CDD records, registers and SMR decision logs — in a usable format at any time, not only while the subscription is active.
What does "AUSTRAC compliance software" actually mean?
It is an informal label for software that helps an Australian reporting entity meet its obligations under the AML/CTF Act 2006 (Cth), which AUSTRAC regulates — the same category as "AML compliance software" or an "AML platform". AUSTRAC itself does not sell, certify or endorse software.
References
- Tranche 2 reforms — guidance for newly regulated businesses — AUSTRAC
- AML/CTF programs — core guidance — AUSTRAC
- Customer due diligence — core guidance — AUSTRAC
- AML/CTF program starter kits — AUSTRAC
- Record keeping — overview — AUSTRAC
- Step 5: Conduct an independent evaluation — AUSTRAC
- AML/CTF compliance officer — AUSTRAC
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) — Federal Register of Legislation
Written from AUSTRAC's published Tranche 2 guidance and the AML/CTF Act 2006 (Cth). Market pricing sourced from vendor public websites, checked 3 July 2026 — confirm current plans directly with any vendor before buying. General guidance only, not legal advice.