AML/CTF Training Obligations Under Tranche 2 in 2026
Since 1 July 2026, tens of thousands of Australian firms have carried AML/CTF training obligations for the first time. Moreover, AUSTRAC now expects evidence that your people can recognise and escalate financial crime risk. This guide sets out what the duty requires, who it covers, and how to prove it.
Last updated on August 18, 2026
Tranche 2 Has Commenced and Training Is Now Live
What changed on 1 July 2026
The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 extended Australia’s AML/CTF regime to a new cohort of businesses. Lawyers, accountants, conveyancers, real estate agents, trust and company service providers, and dealers in precious metals and stones all became reporting entities. AUSTRAC has estimated that roughly 80,000 businesses now fall within scope.
Consequently, enrolment opened on 31 March 2026 and closed for most newly captured firms on 29 July 2026. However, enrolment was only the administrative gateway. Substantive duties — risk assessment, customer due diligence, reporting, record keeping and staff training — all commenced on 1 July regardless of whether a firm had enrolled.
Why training is the duty most firms underestimate
Many Tranche 2 firms spent the first half of 2026 writing their AML/CTF programme. Training, by contrast, often got deferred to a single induction email or a slide pack circulated among partners. Notably, that approach leaves the widest gap between what a programme says and what staff actually do.
Your programme is a document. In practice, your people are the control. When a receptionist accepts a third-party cash payment, or a sales agent waves through an unverified buyer, the written programme has already failed.
Who this article is for
Principals, practice managers, AML/CTF compliance officers and learning leads inside newly regulated Australian firms will find the most value here. Furthermore, established reporting entities can use it to benchmark existing programmes against the expanded regime.
Seven weeks into the new rules, the practical question has shifted. Rather than asking whether you are captured, you now need to demonstrate that your controls work.
Executive Summary
- What this blog covers: What AML/CTF training obligations require under the AML/CTF Act 2006, who must be trained, and how to evidence competence to AUSTRAC.
- Who it’s for: Principals, AML/CTF compliance officers, practice managers and learning leads inside newly regulated Tranche 2 firms across Australia.
- Key regulatory context: The Amendment Act 2024 brought roughly 80,000 businesses into the regime from 1 July 2026, with AUSTRAC as the responsible regulator.
- The central risk: Generic training that staff complete but never apply, leaving sector-specific red flags unrecognised and suspicious matters unreported.
- Primary action required: Build role-specific training on your own risk assessment and designated services, then keep dated records of who completed what.
What AML/CTF Training Obligations Actually Require
The short answer
Your AML/CTF programme must include an ongoing training programme for staff, and you must actually run it. Specifically, people who provide or support designated services need to understand your obligations, the risks your firm carries, and the procedures they follow. Training is not a one-off induction task; instead, it repeats as risks, roles and rules change.
What a compliant training programme covers
AUSTRAC does not publish a fixed syllabus. Nevertheless, published guidance and enforcement history point to a consistent set of components that any credible programme addresses.
At minimum, your training should cover the following:
- Your firm’s designated services, and where money laundering risk enters each one
- Customer due diligence steps, including identity verification and beneficial ownership
- Politically exposed person, sanctions and adverse media screening triggers
- Red flags specific to your sector, drawn directly from your own risk assessment
- Internal escalation routes, plus the tipping-off prohibition and why it exists
- Record-keeping duties, including the seven-year retention requirement
Who must be trained
Coverage extends well beyond your compliance officer. Anyone who onboards clients, handles funds, prepares transaction documents or supervises those tasks needs training proportionate to their exposure.
Directors and senior managers sit in scope too. Ultimately, AUSTRAC assesses whether governance understood the risk, not merely whether a mandatory module was assigned.
Why AML/CTF Training Fails in Australian Firms
The generic module problem
Off-the-shelf modules describe the Act competently enough. However, they cannot describe your clients, your settlement process, or the commercial pressure your agents face at the end of a quarter.
- Content written for banks, then delivered to conveyancers and accountants
- Scenarios set overseas, with no Australian designated services in sight
- No connection between the module and the firm’s documented risk assessment
- Assessment questions that reward recall rather than judgement
Completion gets treated as the outcome
Completion rates are easy to report and easy to game. Consequently, boards receive a green dashboard while frontline judgement stays entirely untested.
Compliance officers then discover the gap during an incident rather than during a review. By that point the record shows training was delivered, which makes the failure harder to explain, not easier.
This distance has a useful name borrowed from safety science: the gap between work-as-imagined and work-as-done.
Training stops once the programme is signed off
Money laundering typologies move quickly. Similarly, your own risk profile shifts as you take on new client types, new geographies or new services.
- New designated services added without any matching training update
- Lateral hires and contractors who never receive induction training
- Red-flag guidance that ages quietly while typologies evolve
- No refresher cycle scheduled after the initial rollout
Accordingly, an annual review of the training programme belongs inside your broader AML/CTF programme review, not beside it.
The Legal Framework Behind Your Training Duty
Where the obligation sits in Australian law
The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 requires reporting entities to maintain an AML/CTF programme, and staff training forms part of that programme. In addition, the Amendment Act 2024 received Royal Assent on 10 December 2024 and extended these duties to Tranche 2 sectors from 1 July 2026. AUSTRAC administers and enforces the regime.
Australian regulators apply a consistent logic to training across regimes. Under the Work Health and Safety Act 2011, for example, a PCBU must provide information, training and supervision, while officers exercise due diligence that Safe Work Australia describes as active and ongoing. Similarly, AUSTRAC expects reporting entities to show that training happened, that it suited the role, and that leadership oversaw it.
What regulator scrutiny looks like in practice
AUSTRAC has signalled a risk-based and educative posture during the early transition period. Nevertheless, the obligations themselves carry full legal force, and enforcement powers were never suspended.
- Your written training programme, plus the date it was approved
- Records showing who completed which training, and when
- Role mapping that explains why each cohort received that content
- Evidence that content reflects your documented risk assessment
- Refresher and remediation records following any incident
Crucially, an examiner reads these records together. Gaps between them tell a clearer story than any single document does on its own.
Why documentation carries the weight
Contraventions of the AML/CTF Act can attract substantial civil penalties, and serious conduct carries criminal exposure. Rather than fixating on figures, treat the underlying principle as the point: undocumented compliance is indistinguishable from no compliance.
Good records also protect the firm. Where an individual acts outside procedure, dated training records demonstrate that the organisation set the standard, communicated it, and reinforced it.
Leadership, Governance and the AML/CTF Compliance Officer
What the compliance officer role demands
Every reporting entity must appoint an AML/CTF compliance officer at management level and notify AUSTRAC of that appointment. Most Tranche 2 firms had to complete the notification by 29 July 2026.
- Own the training programme rather than merely approving it once
- Map training content to designated services and roles each year
- Report coverage, gaps and remediation to the board or principals
- Escalate promptly where commercial pressure erodes due diligence
How to choose an AML/CTF training provider
Buying compliance training is a governance decision, not a procurement exercise. Therefore, ask providers the questions that reveal whether the content will actually change behaviour.
- How long has the provider designed workplace training, and for which Australian sectors?
- Will the module be built around our policies, our designated services and our red flags?
- Does content update when Australian legislation or AUSTRAC guidance changes?
- Is it SCORM-ready for our LMS, and do we own it without subscription lock-in?
Tone from the top operates as a control
Staff read what leaders tolerate. When a principal overrides a due diligence hold to protect a settlement, that single decision teaches more than any module ever will.
Conversely, visible support for escalation makes reporting feel normal. Leaders who complete the same training as their teams send that signal quickly and cheaply.
Completion Is Not Competence: The Gap That Creates Risk
Defining the gap
Work-as-imagined is the process described in your AML/CTF programme. Work-as-done is what a sales agent or paralegal actually does at 4.45pm on a Friday with an impatient client waiting.
Training that only teaches work-as-imagined leaves staff unprepared for the second situation. Meanwhile, criminals design their approach around exactly that pressure point.
Closing the gap requires scenario-based practice, not policy recitation.
What competence looks like on the floor
Competence is observable. Specifically, you should be able to walk into any client-facing team and hear the following without prompting.
- A staff member can name three red flags specific to their own service line
- They know exactly who to tell internally, and within what timeframe
- Tipping-off is understood as a legal prohibition, not office etiquette
- Under time pressure, the documented procedure still gets followed
Compliant on paper versus competent in practice
The difference between the two approaches shows up across five dimensions. Use the comparison below to audit where your current programme sits.
| Dimension | Tick-box approach | Competence-based approach |
|---|---|---|
| Trigger | Annual calendar reminder | New service, new hire, new typology or incident |
| Content source | Generic library module | Your risk assessment and your procedures |
| Assessment | Definition recall quiz | Scenario decisions under realistic pressure |
| Evidence held | Completion percentage | Role mapping, dates, versions and remediation |
| Behaviour | Staff defer to the deal | Staff pause, verify and escalate |
Notably, most newly regulated firms sit somewhere between the two columns. Honest self-assessment against this table gives your compliance officer a concrete remediation list.
The eCompliance Central AML/CTF Training Framework
Building training that survives regulator scrutiny follows a repeatable sequence. Furthermore, each step produces an artefact you can show an examiner, which means the work doubles as your evidence trail.
An 8-Step Framework for Control
Map Your Designated Services
Begin with a written list of every designated service your firm provides. Each one anchors a different risk profile and a different training need.
Translate Risk Into Scenarios
Convert your risk assessment into short, realistic situations staff will recognise instantly. Abstract risk categories rarely change behaviour.
Segment Roles and Cohorts
Group people by what they actually do: onboarding, funds handling, supervision, governance. Depth of content should follow exposure.
Build On Your Own Policies
Embed real forms, thresholds and escalation paths into the module itself. Generic content only ever teaches generic responses.
Assess Judgement, Not Recall
Test decisions inside scenarios rather than definitions in isolation. A pass should mean somebody can act correctly under pressure.
Evidence It Automatically
Capture completion, scores, dates and content version history in your LMS. Manual spreadsheets tend to fail under examination.
Refresh On A Fixed Cycle
Schedule refreshers alongside update triggers tied to legislative change or new services. Currency forms part of the obligation itself.
Report Coverage To Governance
Give principals a quarterly view of coverage, gaps and remediation progress. Oversight only exists once somebody documents it.
Making the framework operational
Sequence matters more than speed here. Firms that start at step four, buying a module before mapping services, consistently end up retrofitting content to a risk assessment it was never designed to match.
Instead, treat steps one to three as a half-day workshop with your compliance officer and service line leads. Everything downstream becomes faster, cheaper and considerably easier to defend.
What Weak AML/CTF Training Costs Australian Firms
The consequence chain
Failures rarely announce themselves as training failures. Rather, they surface as a missed suspicious matter report, an unverified beneficial owner, or a transaction nobody questioned.
The chain typically runs in this order:
- Staff cannot recognise a red flag that sits outside the generic examples they were shown
- Escalation never happens, so the suspicious matter goes unreported within the required timeframe
- AUSTRAC identifies the pattern later, and the firm’s training records become the first exhibit
The reputational and commercial cost
Enforcement outcomes are public. Consequently, a compliance failure follows the firm into tender processes, professional indemnity renewals and client onboarding conversations for years afterwards.
Insurers and banking partners increasingly ask newly regulated firms to evidence their AML/CTF controls directly. Solid training records answer that question in minutes rather than weeks.
Compliance Intelligence: Key Insights
Key Takeaways
- Map every designated service your firm provides before you buy or build any training content.
- Segment your workforce by exposure, then match training depth to each role rather than issuing one module to everyone.
- Build scenarios from your own risk assessment so staff practise decisions they will genuinely face.
- Test judgement through realistic situations instead of definition-recall quizzes.
- Document completion, dates, content versions and role mapping inside a single retrievable system.
- Refresh content whenever legislation, AUSTRAC guidance, services or typologies change.
- Report training coverage and gaps to your principals or board every quarter.
Frequently Asked Questions
Obligations and coverage
Do we need AML/CTF training if we only occasionally provide designated services?
Who has to complete AML/CTF training in a Tranche 2 business?
How often should AML/CTF training be refreshed?
Evidence, providers and common mistakes
What records does AUSTRAC expect us to keep for AML/CTF training?
Is generic online AML training enough to meet our obligations?
What is the most common AML/CTF training mistake newly regulated firms make?
About the Author
This comprehensive article was actively developed by the expert content team at eCompliance Central, under the highly skilled direction of Dr. Denise Meyerson. Dr. Meyerson is the successful founder, a PhD-qualified educator, and a leading learning innovation specialist boasting over 35 years of deep, practical experience in learning and development, strict compliance, and vocational education. She has consulted extensively for leading global organisations and currently remains a highly recognised authority on behaviour-based compliance training within the complex Australian context. We firmly help ambitious organisations meet their strict compliance obligations through highly customised, deeply engaging, SCORM-ready training modules. We proudly build these robust tools precisely around your specific policies, your unique people, and your actual, daily operational realities. Note: We are professional educators, absolutely not legal advisors. For specific legal advice tailored precisely to your exact situation, please consult a fully qualified legal professional.
Turn Your AML/CTF Programme Into Trained Behaviour
Our AML/CTF and sector-specific modules are built around your designated services, your policies and your real red flags, then delivered SCORM-ready to your LMS with no subscription lock-in. Talk to us about a module your team will actually apply.
Explore Custom Compliance Solutions
Looking for a broader overview?
Read our definitive Australian Workplace Compliance Guide.