What changed on 1 July
The second tranche of Australia's anti-money laundering reforms brought the professions into a regime that previously covered banks, casinos and remitters. AUSTRAC opened enrolment on 31 March 2026, the obligations started on 1 July, and the enrolment deadline was 29 July. If your practice provides a designated service, which for a law firm covers things like handling client funds, acting on a conveyance, or setting up a company or trust, you're a reporting entity for that work.
Reporting entities have to carry out customer due diligence before they act. That means collecting and verifying who the client is: full name, date of birth, residential address, and a document to check it against. In practice that document is a driver licence or a passport, and in practice it arrives as a photo.
The turnover test stopped protecting you
Here's the bit that caught people out. Section 6E(1A) of the Privacy Act treats a reporting entity as an APP entity for the personal information it handles under the AML/CTF Act. The $3 million small business exemption is still sitting in the Act, untouched, and it does nothing for this. A three-person conveyancing practice turning over $500,000 is now bound by the Australian Privacy Principles for its onboarding files, needs a privacy policy and a collection notice, and falls under the Notifiable Data Breaches scheme.
So the same client folder now answers to two regulators. AUSTRAC wants to know you verified the client and kept the record. The OAIC wants to know you only collected what you needed and didn't hang on to it longer than you had to. We wrote about where the small business exemption actually stands if you want the wider picture.
Collect more, keep less
The OAIC's position on this is blunter than most firms expect. Its guidance says reporting entities should not retain copies of full ID documents for AML/CTF record-keeping, because the AML regime doesn't require the copies. Information Commissioner Carly Kind's framing was that holding images of identity documents creates risk for the client and for the business the moment there's a breach. The old allowance to keep them covers documents collected before the reforms, and for Tranche 2 entities the expectation applies from 1 July 2026.
What the AML/CTF Act wants is the record of verification, not the document. That you checked, what you checked it against, when, and by whom. Those records run on a seven-year clock, and for customer identification it's the length of the relationship plus seven years after you stop providing designated services. Seven years of verification notes is a modest text file. Seven years of passport photographs is a liability sitting in your email.
The distinction sounds like paperwork until you picture the breach notification. A compromised mailbox holding verification notes is awkward. A compromised mailbox holding 400 driver licence scans is the kind of incident that gets a letter to every client and a look from both regulators.
Where those scans actually end up
This is the part we see on the ground, and it's remarkably consistent across practices. The practice management system holds the official copy, which is fine. The problem is the trail that got it there.
- The client emails a photo of their licence, so it's now in your mailbox, in their Sent Items, and in every backup that covers either.
- Someone forwards it to a colleague to action. Two mailboxes.
- The office multifunction is set up to scan to email, so there's a copy in a scanner mailbox nobody really owns, often with a shared password and no second factor on it.
- Staff photograph documents on a personal phone at a signing. That camera roll syncs to a personal iCloud or Google account the practice has no control over.
- Something gets dropped into a Teams chat or a WhatsApp group because it was the fastest way to get it across.
- Someone saves it to the desktop "to upload properly later" and never deletes it.
Six copies, one of which you can account for. The mailbox ones worry us most, because mailboxes are what attackers actually get into. We handled an incident recently where a remote access tool was installed from a phishing email and the attacker ran an extractor against Outlook to harvest addresses. Had that mailbox been full of client identity documents, the conversation afterwards would have been very different. The write-up is here.
What actually helps
None of this needs a compliance project. It needs a few decisions and someone to enforce them in the systems.
Pick one place ID documents are allowed to live, and write it down. Everything else is a shadow copy by definition, and once people know which location is the real one they stop improvising.
Turn off scan to email for identity documents and scan to a controlled folder instead. Put multi-factor authentication on every mailbox in the tenant, including the shared ones and the scanner account, which is usually the one nobody remembers. In Microsoft 365, data loss prevention rules can flag or block an outbound message carrying what looks like a licence or passport image, which catches the forward before it leaves.
Set a retention rule that deletes the image once the verification record exists, rather than trusting anyone to remember. Then audit backwards: search your existing mailboxes and shared drives for the attachments that are already there. Most practices find more than they expect, and clearing that out does more for your exposure than any policy you write this year.
And write the breach plan before you need it, because the NDB scheme applies to you now. Who gets called, who decides whether harm is likely, what gets preserved, and how you tell clients. Thirty days sounds generous until the clock starts.
We're not lawyers and we don't advise on AML obligations. Your law society or professional body is the place for that. What we can tell you is where your client identity documents are currently sitting, and we can usually find out in an afternoon.
