12 September 2026

AUSTRAC's First Tranche 2 Enforcement Action: What We Know So Far

AUSTRAC's First Tranche 2 Enforcement Action: What We Know So Far

If you run a law firm, an accounting practice, a real estate agency or a trust and company service provider in Australia, you have probably been asking the same question all winter. Not "will AUSTRAC come after us" but "when, and who's going to be first."

That question matters more than it might seem. The first enforcement action against a genuine Tranche 2 gatekeeper (as opposed to a bank, casino or crypto exchange, all of which have lived under this regime for years) will set the tone for everyone else. It will tell 90,000-odd newly regulated businesses exactly what "serious non-compliance" looks like in AUSTRAC's eyes, and exactly how much good faith buys you.

So let's go through what has actually happened, what's still speculation, and what the pattern so far tells you about how to spend the next few months.

A quick recap of where Tranche 2 stands

The AML/CTF Amendment Act passed in December 2024 and finally bit on 1 July 2026. That date brought lawyers, conveyancers, accountants, real estate agents and property managers, dealers in precious metals and stones, and trust and company service providers into AUSTRAC's regulatory net for the first time. Overnight, AUSTRAC's population of directly supervised entities jumped from roughly 19,000 to close to 100,000.

Enrolment opened on 31 March and closed on 29 July. If your business provides a designated service and you weren't enrolled by that date, you are already sitting outside the law, not approaching it.

Has AUSTRAC actually taken action against a Tranche 2 gatekeeper yet?

Here's the honest answer, and it's the reason this blog post is framed as "what we know so far" rather than "here's the case everyone's talking about": at the time of writing, there is no publicly confirmed enforcement action, whether that's a civil penalty order, an infringement notice or an enforceable undertaking, against a law firm, accounting practice, real estate agency, conveyancer or precious metals dealer specifically for breaching their new Tranche 2 obligations.

That doesn't mean nothing has happened. Quite the opposite. AUSTRAC has been unusually active in the weeks either side of 1 July, and if you read the signals closely, they tell you a lot about what to expect.

The regulator flexed its muscle almost immediately

Within days of the regime expanding fivefold, AUSTRAC closed two long-running matters against existing reporting entities in the wagering sector. On 3 July it finalised an enforceable undertaking with Sportsbet after an independent audit confirmed the operator had completed remediation across five compliance areas. Three days later, on 6 July, it entered a fresh enforceable undertaking with bet365, after an audit turned up gaps in the operator's risk assessment methodology and its suspicious matter reporting. Bet365 now has to hand in progress reports and sit through a further compliance audit through to mid-2027.

Neither of those cases involves a Tranche 2 entity. But the timing wasn't an accident. Closing one matter and opening another in the same week, right as the regulator's supervised population quintupled, reads as a deliberate show of capacity. AUSTRAC CEO Brendan Thomas put it plainly when discussing the bet365 matter: when controls fall behind, the consequences extend well past the one company involved.

The crypto ATM sector took a serious hit

In August, AUSTRAC suspended the Virtual Asset Service Provider registration of Cryptolink Pty Ltd for three months, effective from 9 August. That took all 96 of the company's cash-to-crypto ATMs offline nationally. This followed an earlier action against the same operator in October 2025, when AUSTRAC issued a $56,340 infringement notice and accepted a court-enforceable undertaking after finding late reporting of large cash transactions and weaknesses in its risk assessments. When the follow-up review found Cryptolink still wasn't meeting basic threshold transaction reporting requirements and wasn't responding to information requests, AUSTRAC pulled the licence rather than negotiate again.

Virtual asset services sit in an odd spot in this story. Digital currency exchanges have technically been regulated since the original Tranche 1 reforms, but the definitions were widened and new obligations, including the travel rule for virtual asset transfers, came in as part of the same 1 July 2026 wave that brought the classic gatekeeper professions on board. So while Cryptolink isn't a lawyer or a real estate agent, its case is the closest thing we have right now to a live demonstration of how AUSTRAC behaves once patience runs out.

Casual gaming venues and banks are also under the microscope

In May, AUSTRAC ordered an independent audit of Bankstown District Sports Club under section 162 of the AML/CTF Act, over concerns that its controls weren't strong enough to stop organised crime exploiting poker machines. And in August, the regulator's Operation Claw work surfaced what it described as coordinated mortgage fraud, with properties, mostly in Sydney, bought in ways that dodged responsible lending checks. AUSTRAC's message to banks was blunt: lenders need to actively look for warning signs and report suspicious activity, because this isn't something any institution can afford to ignore.

None of these are Tranche 2 actions either. But they show a regulator that is currently running hot across every sector it touches, not one easing into its new remit quietly.

The warning shots aimed squarely at Tranche 2

The clearest signal came on 7 August, just over a week after the enrolment deadline closed. CEO Brendan Thomas warned that conveyancers and other newly regulated entities who still hadn't enrolled were facing looming regulatory action. AUSTRAC has also picked up a $100 million funding boost, which it's clearly positioning as the war chest for supervising its much larger population of reporting entities.

Combine that with AUSTRAC's repeated public position, stated in guidance throughout the lead-up to 1 July, that its initial enforcement focus will fall on entities that wilfully ignore their obligations or are complicit in or wilfully blind to money laundering, rather than businesses making genuine good-faith efforts. Read together, this points to a fairly predictable sequence: enrolment sweeps first, information requests and desk-based reviews next, then formal action against whoever stands out as either unregistered, unresponsive, or obviously going through the motions without a real program behind it.

What the pattern tells gatekeepers right now

Even without a confirmed Tranche 2 case to dissect, the Cryptolink and bet365 matters give a fairly reliable preview of AUSTRAC's playbook, because the regulator applies the same escalation logic across every sector it supervises.

Basic reporting failures get you noticed before program quality does. Both cases centred on late or missing threshold transaction reports and slow responses to information requests, not on subtle deficiencies in a written AML/CTF program. If your firm can't produce accurate records of what it reported and when, that's the first thing an investigator will find.

A first action is rarely the end of the story. Cryptolink got an infringement notice and an enforceable undertaking in October 2025. Ten months later, when a follow-up review found the same weaknesses persisting, AUSTRAC didn't negotiate again, it suspended the licence outright. First contact with the regulator is a chance to fix things properly. It is not a warning you can quietly ignore and hope goes away.

Non-response is treated as seriously as non-compliance. Both AUSTRAC actions this year flagged a failure to respond to information requests as part of the case against the entity, not as a footnote. If AUSTRAC writes to you, silence is its own contravention in the making.

Good faith is measured in evidence, not intention. AUSTRAC's own language distinguishes wilful disregard from genuine effort. But "genuine effort" in a regulator's eyes means a documented risk assessment, staff who've actually been trained, records that exist and can be produced, and a program that's been reviewed since it was written. Saying you meant to get to it doesn't count.

What to do between now and whenever that first case lands

If you're a Tranche 2 entity and you're reading this hoping for reassurance that you have more time, the honest answer is that the runway is shorter than it feels. Enrollment date has passed for existing reporting entities.  The funding is in place. The CEO has already put newly regulated sectors on notice by name. The only open question is which business becomes the example, and there is no reason to volunteer for that role.

A few things worth checking this week rather than next quarter:

  • Confirm your AUSTRAC enrolment actually went through, not just that you submitted the form
  • Pressure-test whether your AML/CTF program reflects what your business actually does, rather than a generic template
  • Check that someone in your firm actually owns compliance day to day, and that they know what a threshold transaction report and a suspicious matter report look like in practice
  • Make sure your customer due diligence records could survive an information request landing in your inbox tomorrow
  • Run through your last three months of transactions and ask honestly whether anything should have been reported and wasn't

Where AML SoftServe fits in

Building an AML/CTF program that actually holds up under scrutiny, rather than one that just looks tidy in a folder, is a genuinely different job to running a law firm, an agency or an accounting practice. That's exactly the gap AML SoftServe is built to close. We help Tranche 2 businesses turn their obligations into a working program: proper risk assessments, customer due diligence and screening that fits how you actually work, and reporting workflows your team can follow without needing a compliance degree.

If you'd rather not find out the hard way what AUSTRAC considers "wilful disregard," get in touch with AML SoftServe and let's get your program sorted before it has to be tested.


Put us to work on your compliance.

Serious compliance, softly served.

Get in touch