AUSTRAC Tranche 2 for Trust & Company Service Providers (2026)
From 1 July 2026, Australia's anti-money-laundering regime reaches a set of businesses that has sat outside it for two decades: trust and company service providers (TCSPs). If you form companies, establish or administer trusts, act as (or arrange for someone to act as) a director or nominee, or provide a registered office and transfer assets on behalf of clients, you are almost certainly a "reporting entity" under the reformed Anti-Money Laundering and Counter-Terrorism Financing Act 2006. This guide explains what changes, who is caught, what you need to do, and by when.
The short version
- TCSPs are brought into the AML/CTF regime from 1 July 2026 as part of the "Tranche 2" reforms, alongside lawyers, accountants, conveyancers, real estate professionals and dealers in precious metals and stones.
- Being caught means you must enrol with AUSTRAC, run customer due diligence (CDD/KYB), keep records, and lodge Threshold Transaction Reports (TTRs) and Suspicious Matter Reports (SMRs).
- Because TCSPs build and administer the very structures money launderers use to hide ownership, verifying the ultimate beneficial owner (UBO) is the central obligation, not an afterthought.
- AUSTRAC also releases new TTR and SMR forms on 1 July 2026 with expanded reportable details; when you must use them depends on your enrolment date.
- Verifying who your client really is — and who ultimately controls the entity behind them — is where identity, KYB and screening technology does the heavy lifting.
A note on sources. This information is current as of July 2026 and draws on AUSTRAC's published guidance on the Tranche 2 reforms and transaction-reporting changes. Obligations evolve and detail matters; if you spot anything that needs correcting, tell us at didit.me/contact.
What "Tranche 2" actually means
The AML/CTF Act has long applied to banks, remitters, gambling providers and digital-currency exchanges. "Tranche 2" is the long-delayed extension of that regime to Designated Non-Financial Businesses and Professions (DNFBPs) — the professional gatekeepers that criminals rely on to move and disguise money. From 1 July 2026, that group includes:
- Lawyers and legal practitioners
- Accountants
- Conveyancers
- Real estate professionals (agents and property managers)
- Dealers in precious metals and precious stones
- Trust and company service providers (TCSPs)
The obligations bite only when you provide a designated service — a defined activity such as forming or managing companies and trusts, or transferring assets. Simply being an accountant or a lawyer does not automatically enrol you; providing a designated service to a client does.
Who counts as a TCSP
TCSPs are defined by function, not job title. You are likely providing TCSP designated services if you do any of the following for a client, in the course of business:
| Activity | Typical example |
|---|---|
| Forming companies or other legal persons | Incorporating a Pty Ltd for a client |
| Acting as, or arranging for another to act as, a director or secretary | Providing a professional nominee director |
| Acting as, or arranging a nominee shareholder | Holding shares on behalf of an undisclosed owner |
| Establishing, or acting as trustee of, an express trust | Setting up and administering a family or unit trust |
| Providing a registered office or business address | Offering a registered-office service |
| Transferring assets or arranging asset transfers on a client's behalf | Moving property or funds between structures |
The common thread is that TCSPs create and operate the legal wrappers — companies, trusts, nominee arrangements — that can obscure who is really in control. That is precisely why regulators worldwide treat the sector as high-risk, and why the reforms put beneficial ownership front and centre.
What being a reporting entity requires
Once you provide a designated service, you take on the core AML/CTF obligations. In broad terms:
- Enrol with AUSTRAC and, where required, register.
- Adopt and maintain an AML/CTF program — your risk assessment and the policies, procedures and controls that manage it.
- Conduct customer due diligence (CDD): identify and verify your customer, understand the nature and purpose of the relationship, and identify and verify beneficial owners.
- Conduct ongoing due diligence and transaction monitoring across the relationship.
- Report to AUSTRAC — Threshold Transaction Reports and Suspicious Matter Reports (below).
- Keep records for the required retention periods.
For a TCSP, CDD is not a box-tick on the client sitting across the desk. If the client is a company or trust, you must look through it to the natural persons who ultimately own or control it.
Beneficial ownership is the whole point
A beneficial owner is the natural person who ultimately owns or controls a customer — commonly framed as an individual holding 25% or more, or otherwise exercising control. For a straightforward company that can be simple. For the layered structures TCSPs routinely build — a trust owning a holding company owning an operating company, perhaps with a nominee director in between — it is anything but.
Your obligation is to see through those layers and verify the real UBO. That means:
- Collecting the ownership and control structure of the customer entity.
- Identifying each beneficial owner as a natural person.
- Verifying that person's identity, not merely recording a name.
- Screening those individuals against sanctions and politically-exposed-person (PEP) lists.
- Keeping the picture current through ongoing due diligence.
Because TCSPs can be the mechanism by which a beneficial owner is hidden, weak UBO verification is both the biggest money-laundering risk in the sector and the obligation AUSTRAC will scrutinise most closely.
Where Didit helps: Didit's KYB (business verification) resolves a corporate customer to its underlying ownership and control structure, and its identity verification (KYC) confirms each beneficial owner is a real, verified natural person — with sanctions and PEP screening layered on top. Didit does not decide your obligations for you, but it produces the verified UBO evidence that underpins accurate CDD records.
The two reports you need to know
Two reports do the most work for a TCSP.
| Threshold Transaction Report (TTR) | Suspicious Matter Report (SMR) | |
|---|---|---|
| Triggered by | A cash transaction of AUD 10,000 or more (or the foreign-currency equivalent) | Forming a suspicion on reasonable grounds about a customer or transaction |
| Deadline | Within 10 business days | Within 3 business days of forming the suspicion |
| Terrorism-financing suspicion | — | Within 24 hours |
A TCSP handling large cash movements, or asked to structure an arrangement in a way that raises red flags, may need to lodge either. The quality of those reports depends entirely on the quality of the identity and ownership data you hold on the parties involved.
New TTR and SMR forms from 1 July 2026
Separately from the sector expansion, AUSTRAC is refreshing its reporting machinery. On 1 July 2026 it releases new TTR and SMR forms, and the new AML/CTF Rules expand the reportable details required in both. The aim is better data quality and a more streamlined AUSTRAC Online experience.
When you must use the new forms depends on your enrolment date:
| Your situation | Which forms |
|---|---|
| Enrolled with AUSTRAC on or before 30 March 2026 | May transition to the new forms any time between 1 July 2026 and 30 March 2029 |
| Enrolled after 30 March 2026 | Must use the new forms from 1 July 2026 |
Most newly-captured TCSPs will be enrolling in 2026, so plan to use the new forms from day one. The forms ask for more detail — which again rewards entities that have already verified identities and ownership up front. For the exact new field lists, refer directly to austrac.gov.au, as AUSTRAC is the authoritative source for form specifics.
What a TCSP should do now
A practical sequence to be ready:
- Confirm your status. Map your services against the designated-service definitions. If you form companies, administer trusts, provide nominee directors or shareholders, offer registered offices, or transfer assets, assume you are in scope.
- Enrol with AUSTRAC by the required date and understand which reporting forms apply to you.
- Build your AML/CTF program around a documented risk assessment of your client base and services.
- Stand up CDD and KYB workflows that verify both the customer and every beneficial owner — including sanctions and PEP screening.
- Set up transaction monitoring and reporting so TTRs and SMRs can be prepared and lodged inside the deadlines.
- Fix your record-keeping so verification evidence is retained and retrievable.
Starting early matters: the harder work is not lodging the occasional report, it is being able to prove, on every engagement, who your client is and who ultimately stands behind the structure you are building.
How Didit fits
Meeting these obligations comes down to reliable identity and ownership data. Didit is a KYC / KYB / AML platform with one API, public per-check pricing, and 500 free verifications a month. For a TCSP that means: verify the identity of each individual client (KYC), resolve corporate clients to their real owners (KYB), screen individuals against sanctions and PEP lists, and monitor transactions for the activity that drives an SMR. Didit does not lodge your TTRs or SMRs and does not decide your obligations — it helps you collect and verify the underlying data so the reports you do lodge are accurate and defensible. Explore it at didit.me.
This article is general information, not legal advice. AML/CTF obligations depend on your specific services and circumstances — confirm how they apply to you with AUSTRAC or your professional adviser.
