
In March 2025, a practitioner on r/auslaw summed up how people were approaching the incoming AML/CTF regime:
"Of course the vibe would be that the profession is sleep walking into it. Enforceable obligations don’t start till 2026. No one will give a f*ck about recommendations or best practice until it becomes hard law."
Once the obligations commenced in mid-2026, the mood in accounting forums hardened into something more like a calculated assumption:
"At the end of the day, if you’re a small firm, you won’t get in trouble for ignoring tranche 2."
That was a bet that didn’t pay off, however. On 28 August 2026, AUSTRAC confirmed it had begun issuing section 167 notices to businesses that "appear to be providing designated services but have not enrolled."
If you end up with a section 167 notice, it’s vital that you understand exactly what it entails.
Section 167 sits in Part 14 of the AML/CTF Act 2006, "Information-gathering powers," in Division 2, which deals with the powers of authorised officers.
The section is headed "Authorised officer may obtain information and documents," and lets an authorised officer require a person, via written notice, to produce specified information and documents.
This means the notice is a fact-finding instrument, not a penalty, so receiving one is not a signal that you have done something wrong. However, it’s definitely something you should take seriously.
The national law firm, Holding Redlich, put both sides of this story plainly:
"A section 167 notice is not the enforcement outcome. It is often the investigative mechanism that precedes it. That is what makes it such a powerful tool in AUSTRAC’s enforcement arsenal."
The third sentence has the most important commercial implication, and the same analysis makes a key point worth considering closely:
"Complying with the notice may expose deficiencies that become the basis for further enforcement action. Few regulatory powers create potential exposure in both directions."
That is the honest position: a notice is not an accusation, and it is not a formality.
The enrolment window for Tranche 2 entities closed on 29 July 2026, four weeks after the commencement of the reforms on 1 July. Enrolment is the most basic obligation in the regime; the step that lets AUSTRAC know you exist.
AUSTRAC CEO Brendan Thomas explained this in his own statement:
"Enrolment is a basic requirement. If a business is providing designated services, it needs to be enrolled with AUSTRAC and actively managing the risk that criminals could exploit its services to move or hide illicit money. The time for preparation has passed. Businesses covered by Australia’s AML/CTF laws should already be working on managing their risks and meeting their obligations."
On 20 August 2026, Real Estate Business reported that 17,970 real estate agencies had enrolled, against approximately 45,000 offices across Australia.
It’s important to keep in mind that this is not a count of businesses in breach. The denominators are not like-for-like (agencies against offices), and many of those offices will not be providing a designated service at all, instead sitting under another entity’s enrolment. There will also be others that have enrolled since the date of publication.
From what we can tell, that enrolment data is what drove this because it is the one dataset AUSTRAC holds with complete confidence, and checking it doesn’t require any investigation.
That is an inference, not something AUSTRAC has said, and Holding Redlich says that a notice is equally likely to be prompted by intelligence holdings, transaction analysis, risk indicators, industry-wide reviews or concerns about a compliance framework.
AUSTRAC’s statement is clear about who received section 167 notices:
"The notices require businesses including real estate agents, accountants, lawyers and jewellers to provide information to help AUSTRAC determine whether they are providing regulated services and meeting their obligations under the AML/CTF Act."
One cohort, four professions, all named together. The second detail is particularly important for small practices because the notices went to individual offices identified as unenrolled, not to entire networks automatically.
The commonly-held theory that a resource-constrained regulator works top-down, leaving small independents effectively invisible, falls flat when confronted by a register.
A register is a list, so size was never the filter.

The notices issued to agencies sought a broad set of records:
| Category | What was sought |
|---|---|
| Enrolment | AUSTRAC enrolment records |
| The business | Business structure, operations and the services actually provided |
| Money | Payment methods accepted and cash-handling policies and arrangements |
| Transactions | Invoices, receipts, purchase orders and transaction records for deals involving cash or virtual assets |
| Agreements | Brokering arrangements, including agency agreements and contracts of sale |
There’s also a second layer aimed at firms that are enrolled, which looks for evidence of how the business assessed its obligations, how it identified and managed risk, how customer due diligence was actually performed and how compliance has been monitored since.
In practice, this means AML/CTF programme approval and implementation records; staff training evidence; customer identification and verification documentation; beneficial ownership checks; and customer risk assessments.
The first set establishes whether you are captured, and the second establishes whether your programme is real.
The power of the section 167 notice isn’t limited to those who are yet to enrol. It applies where an authorised officer reasonably believes a person holds information or documents relevant to compliance with, or enforcement of, an offence or civil penalty provision of the AML/CTF Act.
An enrolled reporting entity can hold information relevant to compliance with the Act, which is what the second layer of records above is used for.
There is a version of Tranche 2 compliance that consists of enrolling, adopting a template programme and continuing as before. This might satisfy the register, but it doesn’t survive a request for evidence of how customer due diligence was performed on a particular matter in a particular month, because that evidence either exists in your records or it doesn’t.
One practitioner described the prevailing approach as: "as long as you have something in place by the 1st of July, it doesn’t have to be perfect, it’s acceptable by AUSTRAC."
That is a fair reading of the fact that the regulator expects genuine effort rather than perfection in year one, but effort is a claim about what you have done, while a notice asks you to evidence it.
One thing AUSTRAC went out of its way to say, and which is worth taking at face value, is:
"Contacting AUSTRAC for help isn’t a red flag. Our Contact Centre exists to help businesses comply, not catch out those who are making a genuine effort to do the right thing."
The Contact Centre number in that statement is 1300 021 037.
These patterns and datasets aren’t very glamorous, and that is the entire point.
It doesn’t require an investigation to spot who enrolled but has filed nothing, whose reporting looks inconsistent with the size of their business, or whose records do not match those of their counterparties.
For the roughly 80,000 firms newly captured by the regime on 1 July, against a regulated population that AUSTRAC says grew from around 19,000 to close to 100,000, the practical implication is narrow.
The question is no longer whether the regime will be enforced; it’s whether you can produce records showing what you did and when on request, regardless of when you’re asked or what you’re asked about.
That is a records problem first and foremost. Customer due diligence done properly, but documented incorrectly or poorly, looks identical on paper to customer due diligence that never happened. And it’s the paper that a notice asks for.
Firms running verification through a system that timestamps each step and retains the evidence can answer that question by simply exporting a file, but firms relying on a folder of scanned licences and an email trail can only answer by reconstructing the entire year.
VeriEzi keeps a timestamped audit trail of every verification for seven years, which matches the retention period the Act requires. It does not make a firm compliant automatically, because that obligation stays where the Act puts it, but it does mean the evidence is in one place and is readily retrievable when somebody asks for it.
Firms wanting to see what that looks like can claim 5 free verifications today.
For the underlying obligations these notices are testing, our guide to Tranche 2 for lawyers and conveyancers and the equivalent for real estate agencies set out what a compliant programme is meant to contain.
VeriEzi provides identity-verification software to support firms preparing for AUSTRAC Tranche 2 reporting obligations. The information in this article is general in nature and does not constitute legal or compliance advice. Firms remain responsible for their own AML/CTF Program and reporting-entity obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). For advice specific to your firm’s obligations, consult AUSTRAC guidance materials or a qualified compliance adviser.
More insights from the same category: Legal Updates
Legal UpdatesJuly 1, 2026
It is a compelling message. In its strongest form, it is also wrong.
Read More
Legal UpdatesMay 14, 2026
AUSTRAC Tranche 2 starts 1 July 2026. Lawyers, conveyancers, real estate agents and accountants. Here’s what AML compliance now requires.
Read More