Free guide: How to use AI in compliance
Back

AML/CTF for Trust and Company Service Providers in Australia: Tranche 2 Obligations Explained

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published September 18, 2026Updated September 18, 2026
A trust and company service provider company file listing table 6 designated services, beside a reporting entity card reading enrol within 28 days

What a trust and company service provider must do under Australia's AML/CTF Act from 1 July 2026: designated services, enrolment, CDD, ECDD and reporting.

Table of contents
  • A trust and company service provider became a reporting entity on 1 July 2026 if it provides any of the professional designated services in table 6 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006: forming or restructuring companies and trusts, selling shelf companies, acting or arranging for someone to act as director, trustee, partner or nominee shareholder, and providing a registered office or principal place of business address.
  • Enrolment with AUSTRAC is due no later than 28 days after the first designated service is provided, and the business then sits on the Reporting Entities Roll. As of 17 September 2026 AUSTRAC recorded 13,780 enrolments from accounting and professional services and 6,580 from lawyers.
  • Enrolment is the smallest duty. The substantive obligations are an AML/CTF programme built on a money laundering and terrorism financing risk assessment, initial and ongoing customer due diligence, enhanced customer due diligence in defined circumstances, suspicious matter and threshold transaction reporting, and record keeping.
  • For a firm that forms companies and trusts for a living, the hard part is beneficial ownership: every trustee, settlor, appointor, guardian, protector and controlling individual behind a trust, and every individual owning 25 percent or more of a company or controlling it, must be identified on reasonable grounds before the service starts.
  • Suspicious matter reports are due within 3 business days of forming a suspicion, or 24 hours where terrorism financing is suspected. Records must show how each matter was established, and AUSTRAC states that copies of identity documents do not have to be kept, only their details.
  • The price lists in this market mark complex structures as bespoke. A trust and company service provider whose clients are complex structures by definition needs a verification model that resolves ownership to natural persons and shows what it could not resolve, without warehousing every director's passport.

A trust and company service provider is a business that forms or restructures companies and trusts for clients, arranges for someone to act as director, trustee or nominee shareholder, or provides a registered office address. In Australia these are designated services under table 6 of the AML/CTF Act from 1 July 2026, making the provider an AUSTRAC reporting entity.

TL;DR

From 1 July 2026 a trust and company service provider in Australia is a reporting entity if it provides any table 6 designated service with a geographical link to Australia. It must enrol with AUSTRAC within 28 days of starting, adopt an AML/CTF programme built on its own ML/TF risk assessment, complete initial customer due diligence on every client, its beneficial owners and the people acting for it before the service begins, apply enhanced customer due diligence where the law requires it, report suspicious matters within 3 business days, and keep records for seven years. Beneficial ownership of trusts and layered companies is where the workload sits, and it is the part worth automating first.

What is a trust and company service provider under the AML/CTF Act?

The Act does not regulate professions. It regulates services, and it uses the term reporting entity for any business that provides one of them. That is why AUSTRAC's own guidance is titled professional designated services rather than lawyers or accountants: the same service is caught whether a law firm, an accounting practice, a corporate services company or a specialist trust administrator provides it.

A trust and company service provider, in the sense the Financial Action Task Force (FATF) uses, is a business that forms companies and trusts for clients, provides people to sit in their governing positions, or gives them an address. Australia had left these services outside the anti-money laundering regime since the original 2006 Act. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, assented to on 10 December 2024, closed that gap in Schedule 3, with obligations commencing on 1 July 2026. The wider reform, and the dates, are covered in our AUSTRAC tranche 2 guide; this article is about the obligations as they land on such a firm specifically.

The test is functional. A firm that provides one designated service, once, in the course of carrying on a business, is a reporting entity for that service, whatever else it does. A firm that provides none is not, whatever its professional title.

Which services make the provider a reporting entity?

Table 6 of subsection 6(5B) of the Act lists the professional designated services. AUSTRAC's professional designated services guidance summarises them as follows.

ItemDesignated serviceWhere the service typically arises
1Assisting in the planning or execution of a transaction to sell, buy or transfer real estateProperty holding structures set up around a purchase
2Assisting in the planning or execution of a transaction to sell, buy or transfer a body corporate or legal arrangementShare sales, transfers of trusts and partnerships
3Receiving, holding, controlling or managing a person's property to help in the planning or execution of a transactionClient money and escrow arrangements
4Assisting in organising, planning or executing a transaction for equity or debt financing of a body corporate or legal arrangementCapital raises and shareholder loans for client entities
5Selling or transferring a shelf companyThe classic corporate services product
6Assisting in the planning or execution of the creation or restructuring of a body corporate or legal arrangementCompany incorporations, trust deeds, restructures
7 and 8Acting, or arranging for someone to act, on behalf of a person in particular positions in a body corporate or legal arrangementNominee directors, company secretaries, trustees, partners and nominee shareholders
9Providing a registered office address or principal place of business address for a body corporate or legal arrangementRegistered office and virtual office services

Two interpretive points from the guidance matter for scoping. First, assisting means active steps that directly advance the outcome; general advice that merely influences how a client proceeds is not caught. AUSTRAC's example is a financial adviser who recommends a trust and introduces a solicitor: the solicitor who drafts the deed provides the item 6 service, the adviser does not. Second, a service is only designated if it is provided to an external customer in the course of carrying on a business. A one-off service still counts, and a free service still counts if it furthers the business. Items 1 and 2 carve out transactions made pursuant to a court or tribunal order.

When did the obligations start, and how does a firm enrol?

Obligations for table 6 services commenced on 1 July 2026. Under AUSTRAC's enrolment overview, a business must apply to enrol no later than 28 days after the day it starts providing a designated service, through an AUSTRAC Online account, and is then placed on the Reporting Entities Roll. These firms enrol but do not register; registration is the additional step reserved for remitters and virtual asset service providers. Enrolment details must be updated within 14 days of a change, and an enrolled business must submit an annual compliance report for as long as it stays on the Roll.

The scale of the transition is now visible in AUSTRAC's own figures. Its enrolment table, updated to 17 September 2026, records the following new reporting entities by industry.

IndustryEnrolments recorded by AUSTRAC
Real estate18,350
Accounting and professional services13,780
Lawyer6,580
Conveyancer1,600
Jewellers and dealers in precious metals and goods320

Trust and company services are spread across the accounting, professional services and legal rows rather than counted separately, which is itself a reminder that the regime attaches to the service, not the sign on the door. AUSTRAC has also begun issuing notices to businesses it believes should have enrolled and have not, so a firm that provides a table 6 service and is not on the Roll is already late rather than early.

What must the AML/CTF programme contain?

Schedule 1 of the 2024 Act rewrote the programme obligations for every reporting entity, not only the newly regulated. The firm must have an AML/CTF programme in two parts: a money laundering and terrorism financing (ML/TF) risk assessment that describes the risks the business actually faces, across its customer types, services, delivery channels and jurisdictions, and AML/CTF policies that set out how those risks are managed. AUSTRAC's guidance on initial and enhanced due diligence repeatedly points back to these policies: they must state which know your customer information the firm collects and verifies for each customer type, when it collects source of funds and wealth, when and how it applies enhanced measures, who is responsible, and how it handles tipping off.

The programme also needs a person accountable for it and oversight from the firm's governing body, and it has to be kept current as the business changes. The practical failure mode AUSTRAC describes across its guidance is the template: a risk assessment that could describe any firm in the country reads, to a supervisor, as evidence that no assessment was done. For a firm in this sector the assessment has to say something specific about complex structures, offshore clients, nominee arrangements and trusts, because those are the features that make the sector high risk in AUSTRAC's National Money Laundering Risk Assessment.

What does initial customer due diligence require for companies and trusts?

Initial customer due diligence (CDD) must be complete before a designated service starts, subject to narrow delayed-CDD exceptions. Under AUSTRAC's initial CDD overview, the firm must establish the following matters on reasonable grounds:

  • the identity of the customer
  • the identity of any person on whose behalf the customer receives the service, such as the beneficiaries of a trust
  • the identity of any person acting on behalf of the customer, and their authority to act
  • where the customer is not an individual, the identity of its beneficial owners
  • whether any of those people is a politically exposed person or designated for targeted financial sanctions
  • the nature and purpose of the business relationship
  • source of funds and source of wealth for foreign PEPs and, where enhanced CDD applies, for the customer.

Reasonable grounds is an objective standard: a reasonable person with the same material would reach the same conclusion, and the firm must record how each matter was established. The information collected must be appropriate to the customer's ML/TF risk, and at least one piece of KYC information for each matter must be verified against reliable and independent data.

For a company customer that means the entity's identity, its directors and its beneficial owners. For a trust, AUSTRAC's initial CDD guide for trusts sets out the fuller list: the trust's name, kind, business names and identifier, its principal place of operation, evidence of its existence (the deed, will or letters of administration), the powers that govern it, and the individuals responsible for its governance, which for most trusts means all trustees, appointors, guardians and protectors, and for a corporate trustee, the individuals on its board. Beneficiaries, or each class of beneficiaries where they cannot be named, must be identified as the people on whose behalf the trust receives the service.

The trust deed and its variations are the primary verification source, with the Australian Business Register for the ABN and letters from an independent professional adviser as alternatives. AUSTRAC also notes that trusts rated high risk nationally are not automatically high-risk customers; the firm still has to rate each one on its own circumstances.

When must the firm apply enhanced customer due diligence?

Enhanced customer due diligence (ECDD) is mandatory, not discretionary, in the circumstances AUSTRAC's enhanced CDD guidance lists:

  • the customer's ML/TF risk is high, whether identified at onboarding or later
  • the firm is required to submit a suspicious matter report about the customer and intends to keep providing the service
  • the requested service involves transactions that are unusually complex or large, have no apparent economic or legal purpose, or form an unusual pattern
  • the service is part of a nested services relationship
  • the customer, a beneficial owner, a person acting for the customer or a person on whose behalf the service is received is a foreign politically exposed person
  • any of those people is located or formed in a jurisdiction the FATF has called for enhanced CDD to be applied to.

The measures have to be targeted to the reason the risk is high: more KYC information, source of funds and wealth for the customer or beneficial owner, the reason for particular transactions, closer monitoring, more frequent reviews, and escalation to senior management. AUSTRAC is explicit that enhanced CDD means active steps to manage the risk, including declining the service, not only extra monitoring. For such a firm, a layered structure with an offshore owner in a listed jurisdiction hits two of these triggers at once, and the file has to show that the firm noticed.

How do you identify the beneficial owners of a trust or a company?

A beneficial owner is an individual who directly or indirectly owns 25 percent or more of the customer, or who otherwise controls it. A customer may have several, and AUSTRAC accepts that some customers have none, in which case the file must say why and identify who does control the entity.

The work is in the chain. AUSTRAC's own example is a trust controlled by a company: if the company's owner is an individual, identify them; if it is another entity, keep following the chain until the individuals who ultimately own or control the customer are reached. Indirect holdings multiply along each link, so a person holding half of a company that owns 60 percent of the customer holds 30 percent and is a beneficial owner. Nominee shareholders are looked through, corporate trustees are unwrapped to their own beneficial owners, and settlors, appointors, guardians and protectors are identified because they control the trust without owning it. A customer-supplied ownership chart is a starting point, never the evidence.

This is the seam the whole sector prices as bespoke. Standard verification products stop at the first corporate shareholder; the clients of firms in this sector rarely do. Our guides on what a KYB check involves and ultimate beneficial owners cover the mechanics, and the companion piece on beneficial ownership through multi-layer trusts with offshore owners works a four-layer example step by step.

What must be reported to AUSTRAC, and by when?

Three reporting duties apply. Under AUSTRAC's suspicious matter report guidance, a suspicious matter report (SMR) is due within 3 business days after the day a suspicion is formed on reasonable grounds, or within 24 hours where the suspicion relates to terrorism financing, and within 5 business days where legal professional privilege is claimed over part of the information. The obligation applies even where the firm declines to provide the service, and a new SMR is due each time a new suspicion forms. A threshold transaction report is due within 10 business days where a designated service involves physical currency of 10,000 dollars or more. And every enrolled business files an annual compliance report.

The tipping off offence, rewritten in Schedule 5 of the 2024 Act, governs what may be said to a client once a report is made or contemplated. It is the rule firms new to the regime break most naturally, by explaining to a client why a matter has stalled. Staff who talk to clients need to know it before they need it.

What records must be kept, and for how long?

Records must show how each initial CDD matter was established on reasonable grounds, what enhanced measures were applied and why, what was reported, and the programme itself, and they must be retained for seven years. AUSTRAC's trust guidance makes a point that matters for the operating model: a firm is not required to keep copies of identity documents and can instead record their details. That is the difference between a compliance file and a database of clients' passports, and it is worth designing for from the start rather than discovering after a breach notification.

How does a small firm run this without a compliance team?

The obligations above are the same for a two-partner practice and a national firm, and the fixed costs of verification, screening and record keeping do not scale down. The way a small firm carries them is to automate the parts that are mechanical and keep judgment for the decisions the Act reserves to the firm.

Zyphe's KYB software runs the entity and ownership layers: when a client submits, the authoritative register record is purchased live from the relevant register and the submission is graded against it, across more than 240 registries in three published latency tiers. Ownership discovery then follows corporate shareholders through every available tier until it reaches natural persons, bounded by a credit budget the firm sets. Branches the budget cuts stay visible as truncated; a branch that reaches a jurisdiction with no register coverage stays visible as unresolved and is held as a proxy, never reported as a person; where discovery cannot complete, the client is asked to declare the owners and the declaration is marked as declared. That is the evidence trail AUSTRAC's reasonable grounds standard asks for, including for the cases where the answer is that a person could not be found.

Each beneficial owner, trustee and director then receives a linked KYC flow, and the business verification cannot be approved until it completes; sanctions, PEP and adverse media screening runs on the entity and on every person found. Where the file needs a human decision on enhanced due diligence, the UBO and EDD review desk assembles the ownership trace, the screening results and a draft rationale, and the firm's own responsible person approves it, which is where the Act puts the decision.

On the question Australian buyers ask first, where the documents go, the position is in writing on the security and data handling page: identity documents and biometrics are processed transiently and stored encrypted in the individual's own vault, and Zyphe retains the verification results, audit logs and proofs. For a firm whose regulator has just told it that copies of documents need not be kept, that is the model that matches the rule.

The bottom line

Tranche 2 turned the corporate services firm from an unregulated professional into a reporting entity with the same categories of obligation as a bank: enrol, assess, programme, verify, escalate, report, retain. Enrolment was the visible deadline and the small part. The work that decides whether a supervisory review goes well is beneficial ownership on layered structures, evidenced on reasonable grounds and documented where it could not be finished, and that is precisely the work that automation with an honest edge does better than a spreadsheet and a shared drive of passport scans.

This article is general information, not legal advice. Obligations depend on the services a business provides, and firms should take advice on their own circumstances.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

Yes, from 1 July 2026, if it provides any of the professional designated services in table 6 of the AML/CTF Act with a geographical link to Australia: forming or restructuring companies and trusts, selling shelf companies, acting or arranging for someone to act as director, trustee, partner or nominee shareholder, providing a registered office address, or assisting in the sale or financing of a body corporate or legal arrangement.

No later than 28 days after the day it first provides a designated service, through AUSTRAC Online. The business is then placed on the Reporting Entities Roll, must update its details within 14 days of any change, and must submit an annual compliance report. Trust and company service providers enrol but do not need the additional registration that applies to remitters and virtual asset service providers.

Yes. Every reporting entity must have an AML/CTF programme made up of a money laundering and terrorism financing risk assessment specific to its own business and AML/CTF policies that set out how it manages those risks, including what KYC information it collects and verifies, when it applies enhanced customer due diligence, who is responsible and how tipping off is handled.

Before the service starts the firm must establish, on reasonable grounds, the identity of the trust, its beneficiaries or classes of beneficiaries, every person acting for it including the trustees, and its beneficial owners, which include individual trustees, the beneficial owners of any corporate trustee, settlors, appointors, guardians, protectors and any other controlling individual. It must also check for politically exposed persons and sanctions designations and establish the nature and purpose of the relationship.

An individual who directly or indirectly owns 25 percent or more of the customer, or who otherwise controls it. Where ownership runs through other entities the chain must be followed until the individuals at the end are identified, with indirect holdings calculated through each link. A customer can have several beneficial owners, or none, in which case the file must record why and who controls the entity.

When the customer's ML/TF risk is high, when a suspicious matter report must be submitted and the firm intends to keep providing the service, when transactions are unusually large or complex or have no apparent purpose, when the service is part of a nested services relationship, when any relevant person is a foreign politically exposed person, and when any relevant person is located or formed in a jurisdiction the FATF has called for enhanced due diligence on.

Within 3 business days after the day the suspicion is formed on reasonable grounds, or within 24 hours where the suspicion relates to terrorism financing. Where legal professional privilege is claimed over part of the information, the deadline is 5 business days. The report is submitted through AUSTRAC Online and is due even if the firm decides not to provide the service.

No. AUSTRAC states that reporting entities are not required to keep copies of identity documents under their record keeping obligations and can instead record the details of those documents. Records of how each customer due diligence matter was established must be kept for seven years, which is why retaining verification results and proofs, rather than a store of passports, is the model that fits the rule.

AML compliance without the PII liability

Screening, monitoring and reporting built on a privacy-first identity layer.

See Zyphe AML