From July 2026, the AML/CTF Tranche 2 reforms bring formal anti-money laundering and counter-terrorism financing obligations to a group of professions that have never had to think about them before.
Accountants. Bookkeepers. Lawyers. Conveyancers. Real estate professionals.
If client identification, document collection or ongoing due diligence wasn’t part of your compliance vocabulary before, it is now.
We work with professional services firms across Australia.
Here’s what we’re seeing, and what it means for the systems behind your client intake.
What’s changing
Tranche 2 extends Australia’s AML/CTF regime to “designated non-financial businesses and professions” – DNFBPs, in regulator language.
If you’re an accountant, bookkeeper, lawyer, conveyancer or real estate agent, you’ll be required to:
- Verify the identity of your clients before providing certain services
- Collect and retain specific identification documents
- Conduct ongoing due diligence on client relationships
- Report suspicious matters to AUSTRAC
- Keep records that demonstrate all of the above, on request
For firms that have spent years collecting client documents over email, this is a significant shift.
Why email and shared drives don’t hold up anymore
Most professional services firms collect client documents the same way they always have.
An email thread. A shared Google Drive link. A PDF attachment, then another, then a follow-up asking for the one that’s missing.
It worked when the compliance bar was a signature on an engagement letter.
It doesn’t work when you need to demonstrate, on request, exactly what identification you collected, when, from whom, and who had access to it.
Email has no audit trail in any meaningful sense. Shared drives don’t track who downloaded what.
Neither gives you a defensible answer when AUSTRAC, or your professional body, asks how you’re meeting your obligations.
What a compliant intake process requires
Tranche 2 doesn’t just ask you to collect documents. It asks you to be able to prove how you collected them.
That means you need:
- A clear, auditable trail of what was requested and when
- Secure storage that meets data protection expectations, not just “good enough for now”
- Controlled access – knowing exactly who has seen a client’s identification documents
- Records that hold up if a regulator asks you to demonstrate compliance two years from now
This is the same shift we’ve seen play out in other regulated sectors.
The organisations that get ahead of it build the infrastructure once, properly, rather than patching together a response after the first audit.
Where Gatheroo fits in
We built Gatheroo because we kept seeing this exact problem in professional services firms and because we couldn’t find a tool that met our own ISO 27001 security bar while being practical enough for a small firm to use.
Gatheroo replaces the email-and-shared-drive approach with a structured, secure client document collection portal.
Every submission carries a timestamped audit trail. Sensitive data, including tax file numbers, is field-level encrypted. Two-factor authentication and role-based access controls mean you know exactly who can see what.
It’s built and hosted under the same ISO 27001:2022 certified information security management system we apply to every project we take on.
The short version
Tranche 2 isn’t optional, and it isn’t far away.
If your client intake process still runs on email and goodwill, now is the time to look at what a properly documented, auditable system looks like.
Get in touch with our team or explore how Gatheroo handles secure client document collection for Australian professional services firms.
