Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) Check-In 2 answered the questions conveyancers and property lawyers are facing seven weeks into the Tranche 2 obligations. It’s moved from getting set up to the matter-by-matter details of applying the rules in practice.
Mark Pinto, Major Account Manager at triSearch, hosted the session, joined by Richard Storey, Partner, Risk Consulting at Grant Thornton, and Nicholas Gould, Managing Director at Colwell Conveyancing Group.
Nic Gould reminded everyone how early it still is: “We’re only six or seven weeks into one of the biggest reforms we’ve seen in decades, so it’s okay to give yourself a bit of a pat on the back.”
In this recap: what’s new in the Compliance Centre, verifying identity when a client can’t go digital, trusts and beneficial owners, when customer due diligence must be done, source of funds, reporting a suspicion via a suspicious matter report (SMR), and record keeping.
Here’s a recap of the most popular topics and questions:
A run of updates has gone live since 1 July 2026, many requested by conveyancers. You can now start an AML order without triggering a verification of identity (VOI) first, so a company onboarding can begin from an Australian Securities and Investments Commission (ASIC) search before anything goes to the client. If a clients know your customer (KYC) or know your business (KYB) form isn’t up to standard, you can request a resubmission within the same order, with their existing answers retained. Risk assessments can now be edited without restarting, so a change in a client’s circumstances is recorded as it happens.
Reliance reports are now viewable any time from the AML Summary, and the providing practitioner’s risk assessment pre-fills into the relying party’s assessment, though they still make their own low, medium, or high determination. Training was refreshed too; with foundational and role-specific modules you can rewatch.
How do you complete a VOI when a client can't go digital?
Some clients can’t or won’t complete a VOI digitally, whether they are elderly clients, aren’t computer literate, or won’t upload identity documents to a platform. Work down a sliding scale that keeps digital verification in place for as long as possible: ideally the client completes their VOI on their own phone, and failing that, a family member, friend, or agent helps them.
If neither is workable, bring the client into the office, where you still have two ways to keep the process digital. The first is to guide the client through the steps on their own device while you sit with them. The second, for a client who can’t manage a device at all, is to send the tasks to yourself and complete each step on your own computer with the client alongside, entering their answers into the KYC form as they present their identity documents. The client brings the same documents a paper process would need, with one advantage: the system verifies the documents digitally, which is far better suited to detecting fraudulent or altered identity than a visual check by a conveyancer or property lawyer, and it keeps the full digital audit trail intact.
Only as a genuine last resort do you complete a face-to-face VOI on your standard form, run the KYC in person, and upload the scan. The Compliance Centre supports a practitioner-assisted option and document upload for these situations.
When is a UBO check required for trusts and companies?
For a trust, the trust deed schedule names the parties in control or benefiting, and those named parties go through full VOI and AML screening. Where the trustee is a company, treat it as any other company: identify the directors, then check any shareholder holding 25 per cent or more, who becomes an ultimate beneficial owner (UBO). If no one holds more than 25 per cent, don’t stop there: step back to the principle of control and ask who directs the assets and funds, and who gives instructions, usually a director. Named beneficiaries need onboarding. Where beneficiaries are described as a class rather than named, record the class — the requirement doesn’t disappear, it changes shape.
Richard and Nic agreed: complex structures take real time and analysis, so build a commercial arrangement for that work rather than absorbing the cost.
When does customer due diligence need to be done?
Many asked when customer due diligence (CDD) must be done relative to acting, including pre-purchase advice and off-the-plan steps. Start with what counts as a designated service: for lawyers and conveyancers, Section 6, Table 6 of the AML/CTF Act lists the nine designated services, and your initial CDD must be completed before you start providing one. General contract advice, where no designated service is delivered, may sit outside that, and the law societies, the Law Council of Australia, and the Australian Transaction Reports and Analysis Centre (AUSTRAC) have issued guidance on these pinch points.
AUSTRAC has also set rules for delayed due diligence in property. Acting for a vendor, you can’t delay; acting for a buyer, you complete your checks as the purchase progresses. At auction, a vendor’s agent isn’t expected to run due diligence on the buyer before the hammer falls, with a defined window afterwards: up to 28 days after the exchange of contracts, or at least three days before the initially agreed settlement date, whichever is earliest.
Do you need source of funds checks on every matter?
Several asked how far source of funds and wealth checks need to go, and whether they’re required on every matter. They aren’t. For a clearly low-risk client, a long-standing Australian resident, a straightforward purchase, clean screening, and funds from a normal lender, you generally don’t need to dig further. The panel drew the line between gathering the information, which can come from a conversation or a short form, and verifying it, which matters when the amount doesn’t fit what you know about the client. A few months of salary deposits on a bank statement is usually enough for an otherwise low-risk individual, and reluctance to share basic information is the flag worth noticing.
Nic Gould’s point was that the groundwork happens at onboarding: “We focus on onboarding across the firm, whether it’s AML/CTF, legal work, or a conveyancing transaction. The onboarding is critical, and you get a lot out of it with the right questions.”
The bank of mum and dad follows the same logic: verify and screen the contributor and apply source of funds checks only if they come back higher risk. AUSTRAC’s guidance on source of funds and wealth addresses this directly.
Reporting a suspicion: do you file an SMR, and are you exposed?
Nic Gould put the concern directly: “If we’re writing an SMR on a client, am I now in danger, given I’m the one who reported him?”
When a transaction looks off or you suspect funds aren’t legitimate, and you form a suspicion, you file a suspicious matter report (SMR). You aren’t expected to investigate, build a brief of evidence, or pause the transaction. You report what you know, factually and chronologically, and AUSTRAC and law enforcement take it from there.
On the exposure, two protections apply. Tipping off is a criminal offence: you can’t disclose an SMR, or information from which a suspicion could be inferred, where that disclosure could reasonably be expected to prejudice an investigation. In practice, keep it between you, your compliance officer, and AUSTRAC, with limited exceptions such as obtaining legal advice. SMRs are also protected information and, subject to limited exceptions, aren’t admissible as evidence in court proceedings, so a client is not in a position to trace one back to you.
How long do you keep AML/CTF records?
Reporting is through AUSTRAC Online, where you lodge an SMR or a threshold transaction report (TTR, for cash of $10,000 or more). Sanctions matches are handled separately: where a match means you are holding a controlled asset, freeze it and notify the Australian Sanctions Office at the Department of Foreign Affairs and Trade (DFAT), and the Australian Federal Police (AFP), as soon as possible. SMRs are due within three business days of forming your suspicion, reduced to 24 hours where the suspicion relates to terrorism financing, and TTRs within 10 business days of the transaction.
On record keeping, Richard Storey was specific: “You have to keep your AML records for seven years after the last transaction.”
The Compliance Centre holds it for the full seven years. How much detail you keep is risk-based: where a matter doesn’t need an SMR, record why, and why you rated it low or medium rather than high. It doesn’t need to be exhaustive, just what you found, what you did, and why, saved against the order with Add notes and Add documents. You’ll need it: every firm faces an independent evaluation of its AML/CTF program at least once every three years, with staggered deadlines for a newly regulated firm’s first evaluation.
Missed the session?
Watch the full recording below.
Our next AML/CTF Check-In is on 15 September. Register and sign up here.
Have a question before then? Contact your Account Manager or raise a support ticket through triConvey or triSearch.
This article is a general summary of the discussion at AML/CTF Check-In 2 and is not legal or compliance advice. Firms should confirm their own obligations against AUSTRAC’s guidance and the AML/CTF Act, or with their adviser. triSearch provides software solutions for conveyancing processes. Users remain responsible for compliance with applicable laws and regulations.

