AML/CTF Tranche 2 Put Thousands of Firms Under the Privacy Act: What APP 11 Now Means for MSPs

Published on
October 7, 2026
Read time
5 mins

AML/CTF Tranche 2 Put Thousands of Firms Under the Privacy Act: What APP 11 Now Means for MSPs

Veröffentlicht am
October 7, 2026
Lesezeit
5 Min. Lesezeit
Kategorie
5 Min. Lesezeit

AML/CTF Tranche 2 Put Thousands of Firms Under the Privacy Act: What APP 11 Now Means for MSPs

Veröffentlicht am
07 Oct 26

Table of contents

Subscribe to newsletter

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

KEY TAKEAWAYS

  • Tranche 2 is now law. Since 1 July 2026, lawyers, conveyancers, accountants, real estate professionals and precious metals dealers have been AML/CTF reporting entities.
  • The small business exemption no longer applies to their AML/CTF data. Under section 6E(1A) of the Privacy Act, more than 100,000 small firms must now follow the Australian Privacy Principles for the personal information they handle for AML/CTF purposes.
  • APP 11 is the principle most at risk. Firms must take reasonable steps to protect the identity data they collect, and destroy it once it is no longer needed.

‍

Since 1 July 2026, AML/CTF Tranche 2 has made lawyers, conveyancers, accountants, real estate professionals, and precious metals dealers AML/CTF reporting entities. Reporting entities must follow the Privacy Act 1988 for their AML/CTF activities, so the OAIC estimates more than 100,000 small businesses now have to meet the Australian Privacy Principles for the first time, including APP 11's duty to keep personal information secure. Because most breaches begin with people, MSPs that can see, measure, and reduce human risk are best placed to help these firms prove they have taken "reasonable steps."

What Is AML/CTF Tranche 2 and Who Does It Cover?

AML/CTF Tranche 2 is the extension of Australia's anti-money laundering and counter-terrorism financing laws to so-called "gatekeeper" professions, and it took effect on 1 July 2026. AUSTRAC, the national AML/CTF regulator and financial intelligence agency, set two commencement dates: 31 March 2026 for existing reporting entities such as banks and remitters, and 1 July 2026 for newly regulated Tranche 2 entities.

The newly regulated sectors are:

  • Lawyers and conveyancers
  • Accountants and trust and company service providers
  • Real estate professionals, including agents, buyer's agents, and property developers
  • Dealers in precious metals, stones, and products

AUSTRAC estimates the change creates around 100,000 new reporting entities, most of which have never dealt with AML/CTF obligations before. Obligations apply only when a firm provides a "designated service," such as handling a property transaction or setting up a company or trust on a client's behalf.

Once captured, a firm must enroll with AUSTRAC, appoint an AML/CTF compliance officer, run a documented AML/CTF program based on a money laundering risk assessment, verify customer identities, monitor customers on an ongoing basis, report suspicious matters, and keep records. Enrollment had to be completed by 29 July 2026, but the core obligations applied from day one.

For MSPs, the most important consequence is easy to miss. Customer due diligence means these firms now collect and store far more identity data than they did before. That data is exactly what attackers want.

Why Are AML/CTF Reporting Entities Now Covered by the Privacy Act?

AML/CTF reporting entities are covered by the Privacy Act 1988 for their AML/CTF activities, even if they would otherwise qualify for the small business exemption. That is the link that turns an anti money laundering reform into a privacy and cybersecurity issue.

The Privacy Act normally exempts small businesses with annual turnover of $3 million or less, from the Australian Privacy Principles (APPs). That exemption still applies to most small businesses. However, section 6E(1A) removes it for AML/CTF reporting entities. So a small law firm, conveyancer, accountant, or real estate agency that provides designated services must now follow the APPs for the personal information it handles for AML/CTF purposes, no matter how small it is.

‍

Many law practices, accounting firms, agencies, and dealers fall under the $3 million threshold. HWL Ebsworth notes that OAIC estimates put the number of affected small businesses at more than 100,000. The AUSTRAC and OAIC figures measure slightly different things, but both point to the same conclusion: a large population of small firms now has formal privacy obligations for the first time.

The coverage is scoped. It applies to identity documents, verification records, transaction details, and other personal information handled to meet AML/CTF requirements, not necessarily to every activity the business carries out. In practice, though, that information usually sits in the same inboxes, file shares, and practice management systems as everything else. Securing one part of the environment while leaving the rest open is rarely realistic.

The regulator is already watching. The OAIC has begun its first privacy policy compliance sweep, and the 2024 amendments gave the Information Commissioner new civil penalties for failures as basic as an inadequate privacy policy.

What Does APP 11 Require?

APP 11 requires an organization to take reasonable steps to protect the personal information it holds and to destroy or deidentify that information once it is no longer needed. It is the security principle of the Privacy Act, and for a newly covered firm it is the principle most likely to be tested by a breach.

It has three working parts:

What does taking "reasonable steps" mean in practice?

The first civil penalty case under the Privacy Act answered that question. In October 2025, the Federal Court ordered Australian Clinical Labs to pay $5.8 million over a 2022 breach at its Medlab Pathology business that affected about 223,000 people. Of that total, $4.2 million related to failing to take reasonable steps under APP 11.1, with the rest tied to slow breach assessment and notification.

Three lessons from the judgment matter most for MSPs and their clients:

  • Reasonable steps are risk-based and must evolve. What was adequate three years ago may not be adequate against today's known threats.
  • Data you do not hold cannot be breached. The court treated data minimization and defensible retention as part of APP 11.1.
  • Outsourcing does not transfer the obligation. The court found that relying on third parties is not enough on its own. A client that "leaves security to the IT provider" still owns the APP 11 duty, which makes clear, reportable evidence from that provider valuable to both sides.

The stakes have also risen. The 2024 amendments introduced tiered penalties: the top tier for serious interferences reaches $50 million, 30% of adjusted turnover, or three times the benefit obtained, whichever is greatest. A new mid-tier now covers interferences that are not serious, and the OAIC can issue infringement notices for administrative failures.

How Do the Privacy Act, Tranche 2, and APP 11 Fit Together?

Tranche 2 creates the obligation to collect identity data, section 6E(1A) of the Privacy Act brings that data under the APPs, and APP 11 requires it to be protected. Each reform on its own looks like a compliance task for a different team; together they form a single chain that ends with staff behavior.

‍Why Is the Human Layer the Biggest APP 11 Risk for These Firms?

Most of the breaches APP 11 is meant to prevent start with a person rather than a system. Verizon's 2026 Data Breach Investigations Report found the human element in 62% of breaches, and Australia's own figures tell the same story.

The cost data points the same way. In IBM's 2026 research, the three most expensive ways into an Australian organization all ran through people.

What does this look like in the sectors Tranche 2 now covers?

The newly regulated professions are already being targeted, and the attacks follow a familiar pattern:

Every one of these incidents started with a mailbox, a phone call, or a trusted relationship, not an unpatched server. For a Tranche 2 entity, customer due diligence raises the payoff: a compromised inbox now also holds verified identity documents.

What Do Toxic Combinations Look Like in a Small Professional Firm?

A toxic combination occurs when several risk factors overlap within a single user account, so that together they create a far more likely and damaging attack path than any one of them alone. Attackers look for exactly these overlaps, and small firms are full of them because one person often handles client data, payments, and system administration.

Taken one at a time, each of these signals might sit in a different report: the email admin console, a dark web alert, a phishing dashboard, a training spreadsheet. None of them would look urgent. Combined on one account at a firm that now holds verified identity documents, they describe almost exactly how the settlement fraud cases above began.

This is why measuring human risk at the individual level matters for APP 11. A firm that can identify and close its toxic combinations is taking reasonable steps against the threats it knows about. A firm that only reports training completion rates is not.

What Do "Reasonable Steps" Look Like in Practice?

For a Tranche 2 entity, taking reasonable steps under APP 11 increasingly means being able to show that human risk is measured, prioritized, and falling over time. Ticking a training box once a year will not stand up against a court that expects controls to evolve with known threats.

This is where a Human Risk Intelligence approach fits. Instead of treating training completion, phishing results, identity hygiene, dark web exposure, and policy records as separate reports, it correlates them into one view of each user's risk. That turns the APP 11 question "Did you take reasonable steps?" into something an MSP can answer with evidence.

A practical playbook for MSPs

  1. Map the exposure. Identify which clients provide designated services and where their AML/CTF identity data actually lives: inboxes, shared drives, scanned documents, and practice software.
  2. Prioritize the roles that matter. Settlement clerks, conveyancers, practice managers, and principals with admin access carry more risk than the average user. Score them first.
  3. Close toxic combinations before anything else. One account with several weaknesses at once is a bigger risk than several accounts with one weakness each (the previous section shows why).
  4. Train for the attacks these firms actually face. Payment redirection, mailbox compromise, and phone impersonation should be the core of simulations, not generic examples.
  5. Put verification into policy. A rule requiring staff to confirm bank details by calling a known number and never to retain copies of identity documents in email closes two of the most common gaps.
  6. Report in compliance language. Monthly reporting that ties risk trends to APP 11 helps principals answer the regulator, their insurer, and their professional body.
  7. Rehearse the breach. Under the current scheme, a suspected eligible data breach must be assessed within 30 days. Firms that have never done it need a plan before they need to use it.

For MSPs, the scale is the opportunity. More than 100,000 small firms have new privacy obligations. Few employ security staff, and most already rely on an outside provider for IT. Helping them demonstrate that they have taken reasonable steps is a natural extension of that relationship.

What Is Coming Next for APP 11?

APP 11 is set to become more demanding. On 31 August 2026, the government released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, the second tranche of Privacy Act reform. Consultation closed on 17 September 2026, and the bill has not yet been introduced to Parliament.

If passed in its current form, the draft would require organizations to consider destroying personal information they no longer need, identify what personal information they hold, and regularly evaluate their compliance measures. It would also require eligible data breaches to be reported to the OAIC within 72 hours.

Each of those proposals favors firms that already have continuous visibility. Regular evaluation is far easier with a live risk view than with an annual audit, and a 72-hour reporting window leaves no time to work out who clicked what.

One naming trap is worth flagging to clients: "Tranche 2" now describes two different reforms. AML/CTF Tranche 2 is law and has applied since 1 July 2026. Privacy Act Tranche 2 is still a proposal.

Compliance Now Depends on Seeing Human Risk

AML/CTF Tranche 2 did more than add a new set of reporting entities. Through section 6E(1A) of the Privacy Act, it brought more than 100,000 small professional firms under the Australian Privacy Principles, and APP 11 now requires each of them to take reasonable steps to protect the identity data that customer due diligence obliges them to collect.

The evidence shows where those steps matter most. People are involved in 62% of breaches, human error caused 37% of notified breaches in early 2025, and the costliest attack routes in Australia all run through staff. The first civil penalty under the Privacy Act made clear that outsourcing does not move the obligation, and the proposed reforms would raise the bar again.

MSPs that can see, score, and reduce human risk across their client base, and report it in the language of APP 11, are in the strongest position to help these firms comply.

Frequently Asked Questions

Does the Privacy Act now apply to every small law firm, accountant, and real estate agency?

No. It applies to small businesses that provide AML/CTF designated services, and only to the personal information they handle for AML/CTF purposes. A firm that provides no designated services keeps the small business exemption, unless another rule brings it into scope.

Is MFA enough to meet APP 11?

No single control is enough. Since December 2024, reasonable steps expressly include technical and organizational measures, and courts assess them against the risks an organization knows about. MFA is essential, but so are training, policies, access reviews, and evidence that they reduce risk.

How long do Tranche 2 entities need to keep identity records?

The AML/CTF Act sets record-keeping periods, generally seven years for customer identification records. APP 11.2 then requires the information to be destroyed or deidentified once no legal reason to keep it remains. Firms should also avoid storing copies of identity documents the AML/CTF regime does not require.

What happens if a Tranche 2 entity has a data breach?

For AML/CTF information, it falls under the Notifiable Data Breaches scheme. It must assess a suspected breach within 30 days and notify the OAIC and affected individuals if serious harm is likely. The proposed second tranche of privacy reform would shorten notification to 72 hours.

How can MSPs help clients show reasonable steps?

By measuring human risk continuously, closing the highest-risk combinations first, training staff against the attacks their sector actually sees, and reporting progress in terms of APP 11. Documented trends are far more persuasive to a regulator than a list of tools.

BOOK A DEMO

See Human Risk Intelligence in action

A 30-minute walkthrough of how to cut human risk across your users, tailored to MSPs and IT teams.

Get a Demo

Subscribe to newsletter

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Since 1 July 2026, AML/CTF Tranche 2 has made lawyers, conveyancers, accountants, real estate professionals, and precious metals dealers AML/CTF reporting entities. Reporting entities must follow the Privacy Act 1988 for their AML/CTF activities, so the OAIC estimates more than 100,000 small businesses now have to meet the Australian Privacy Principles for the first time, including APP 11's duty to keep personal information secure. Because most breaches begin with people, MSPs that can see, measure, and reduce human risk are best placed to help these firms prove they have taken "reasonable steps."

What Is AML/CTF Tranche 2 and Who Does It Cover?

AML/CTF Tranche 2 is the extension of Australia's anti-money laundering and counter-terrorism financing laws to so-called "gatekeeper" professions, and it took effect on 1 July 2026. AUSTRAC, the national AML/CTF regulator and financial intelligence agency, set two commencement dates: 31 March 2026 for existing reporting entities such as banks and remitters, and 1 July 2026 for newly regulated Tranche 2 entities.

The newly regulated sectors are:

  • Lawyers and conveyancers
  • Accountants and trust and company service providers
  • Real estate professionals, including agents, buyer's agents, and property developers
  • Dealers in precious metals, stones, and products

AUSTRAC estimates the change creates around 100,000 new reporting entities, most of which have never dealt with AML/CTF obligations before. Obligations apply only when a firm provides a "designated service," such as handling a property transaction or setting up a company or trust on a client's behalf.

Once captured, a firm must enroll with AUSTRAC, appoint an AML/CTF compliance officer, run a documented AML/CTF program based on a money laundering risk assessment, verify customer identities, monitor customers on an ongoing basis, report suspicious matters, and keep records. Enrollment had to be completed by 29 July 2026, but the core obligations applied from day one.

For MSPs, the most important consequence is easy to miss. Customer due diligence means these firms now collect and store far more identity data than they did before. That data is exactly what attackers want.

Why Are AML/CTF Reporting Entities Now Covered by the Privacy Act?

AML/CTF reporting entities are covered by the Privacy Act 1988 for their AML/CTF activities, even if they would otherwise qualify for the small business exemption. That is the link that turns an anti money laundering reform into a privacy and cybersecurity issue.

The Privacy Act normally exempts small businesses with annual turnover of $3 million or less, from the Australian Privacy Principles (APPs). That exemption still applies to most small businesses. However, section 6E(1A) removes it for AML/CTF reporting entities. So a small law firm, conveyancer, accountant, or real estate agency that provides designated services must now follow the APPs for the personal information it handles for AML/CTF purposes, no matter how small it is.

‍

Many law practices, accounting firms, agencies, and dealers fall under the $3 million threshold. HWL Ebsworth notes that OAIC estimates put the number of affected small businesses at more than 100,000. The AUSTRAC and OAIC figures measure slightly different things, but both point to the same conclusion: a large population of small firms now has formal privacy obligations for the first time.

The coverage is scoped. It applies to identity documents, verification records, transaction details, and other personal information handled to meet AML/CTF requirements, not necessarily to every activity the business carries out. In practice, though, that information usually sits in the same inboxes, file shares, and practice management systems as everything else. Securing one part of the environment while leaving the rest open is rarely realistic.

The regulator is already watching. The OAIC has begun its first privacy policy compliance sweep, and the 2024 amendments gave the Information Commissioner new civil penalties for failures as basic as an inadequate privacy policy.

What Does APP 11 Require?

APP 11 requires an organization to take reasonable steps to protect the personal information it holds and to destroy or deidentify that information once it is no longer needed. It is the security principle of the Privacy Act, and for a newly covered firm it is the principle most likely to be tested by a breach.

It has three working parts:

What does taking "reasonable steps" mean in practice?

The first civil penalty case under the Privacy Act answered that question. In October 2025, the Federal Court ordered Australian Clinical Labs to pay $5.8 million over a 2022 breach at its Medlab Pathology business that affected about 223,000 people. Of that total, $4.2 million related to failing to take reasonable steps under APP 11.1, with the rest tied to slow breach assessment and notification.

Three lessons from the judgment matter most for MSPs and their clients:

  • Reasonable steps are risk-based and must evolve. What was adequate three years ago may not be adequate against today's known threats.
  • Data you do not hold cannot be breached. The court treated data minimization and defensible retention as part of APP 11.1.
  • Outsourcing does not transfer the obligation. The court found that relying on third parties is not enough on its own. A client that "leaves security to the IT provider" still owns the APP 11 duty, which makes clear, reportable evidence from that provider valuable to both sides.

The stakes have also risen. The 2024 amendments introduced tiered penalties: the top tier for serious interferences reaches $50 million, 30% of adjusted turnover, or three times the benefit obtained, whichever is greatest. A new mid-tier now covers interferences that are not serious, and the OAIC can issue infringement notices for administrative failures.

How Do the Privacy Act, Tranche 2, and APP 11 Fit Together?

Tranche 2 creates the obligation to collect identity data, section 6E(1A) of the Privacy Act brings that data under the APPs, and APP 11 requires it to be protected. Each reform on its own looks like a compliance task for a different team; together they form a single chain that ends with staff behavior.

‍Why Is the Human Layer the Biggest APP 11 Risk for These Firms?

Most of the breaches APP 11 is meant to prevent start with a person rather than a system. Verizon's 2026 Data Breach Investigations Report found the human element in 62% of breaches, and Australia's own figures tell the same story.

The cost data points the same way. In IBM's 2026 research, the three most expensive ways into an Australian organization all ran through people.

What does this look like in the sectors Tranche 2 now covers?

The newly regulated professions are already being targeted, and the attacks follow a familiar pattern:

Every one of these incidents started with a mailbox, a phone call, or a trusted relationship, not an unpatched server. For a Tranche 2 entity, customer due diligence raises the payoff: a compromised inbox now also holds verified identity documents.

What Do Toxic Combinations Look Like in a Small Professional Firm?

A toxic combination occurs when several risk factors overlap within a single user account, so that together they create a far more likely and damaging attack path than any one of them alone. Attackers look for exactly these overlaps, and small firms are full of them because one person often handles client data, payments, and system administration.

Taken one at a time, each of these signals might sit in a different report: the email admin console, a dark web alert, a phishing dashboard, a training spreadsheet. None of them would look urgent. Combined on one account at a firm that now holds verified identity documents, they describe almost exactly how the settlement fraud cases above began.

This is why measuring human risk at the individual level matters for APP 11. A firm that can identify and close its toxic combinations is taking reasonable steps against the threats it knows about. A firm that only reports training completion rates is not.

What Do "Reasonable Steps" Look Like in Practice?

For a Tranche 2 entity, taking reasonable steps under APP 11 increasingly means being able to show that human risk is measured, prioritized, and falling over time. Ticking a training box once a year will not stand up against a court that expects controls to evolve with known threats.

This is where a Human Risk Intelligence approach fits. Instead of treating training completion, phishing results, identity hygiene, dark web exposure, and policy records as separate reports, it correlates them into one view of each user's risk. That turns the APP 11 question "Did you take reasonable steps?" into something an MSP can answer with evidence.

A practical playbook for MSPs

  1. Map the exposure. Identify which clients provide designated services and where their AML/CTF identity data actually lives: inboxes, shared drives, scanned documents, and practice software.
  2. Prioritize the roles that matter. Settlement clerks, conveyancers, practice managers, and principals with admin access carry more risk than the average user. Score them first.
  3. Close toxic combinations before anything else. One account with several weaknesses at once is a bigger risk than several accounts with one weakness each (the previous section shows why).
  4. Train for the attacks these firms actually face. Payment redirection, mailbox compromise, and phone impersonation should be the core of simulations, not generic examples.
  5. Put verification into policy. A rule requiring staff to confirm bank details by calling a known number and never to retain copies of identity documents in email closes two of the most common gaps.
  6. Report in compliance language. Monthly reporting that ties risk trends to APP 11 helps principals answer the regulator, their insurer, and their professional body.
  7. Rehearse the breach. Under the current scheme, a suspected eligible data breach must be assessed within 30 days. Firms that have never done it need a plan before they need to use it.

For MSPs, the scale is the opportunity. More than 100,000 small firms have new privacy obligations. Few employ security staff, and most already rely on an outside provider for IT. Helping them demonstrate that they have taken reasonable steps is a natural extension of that relationship.

What Is Coming Next for APP 11?

APP 11 is set to become more demanding. On 31 August 2026, the government released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, the second tranche of Privacy Act reform. Consultation closed on 17 September 2026, and the bill has not yet been introduced to Parliament.

If passed in its current form, the draft would require organizations to consider destroying personal information they no longer need, identify what personal information they hold, and regularly evaluate their compliance measures. It would also require eligible data breaches to be reported to the OAIC within 72 hours.

Each of those proposals favors firms that already have continuous visibility. Regular evaluation is far easier with a live risk view than with an annual audit, and a 72-hour reporting window leaves no time to work out who clicked what.

One naming trap is worth flagging to clients: "Tranche 2" now describes two different reforms. AML/CTF Tranche 2 is law and has applied since 1 July 2026. Privacy Act Tranche 2 is still a proposal.

Compliance Now Depends on Seeing Human Risk

AML/CTF Tranche 2 did more than add a new set of reporting entities. Through section 6E(1A) of the Privacy Act, it brought more than 100,000 small professional firms under the Australian Privacy Principles, and APP 11 now requires each of them to take reasonable steps to protect the identity data that customer due diligence obliges them to collect.

The evidence shows where those steps matter most. People are involved in 62% of breaches, human error caused 37% of notified breaches in early 2025, and the costliest attack routes in Australia all run through staff. The first civil penalty under the Privacy Act made clear that outsourcing does not move the obligation, and the proposed reforms would raise the bar again.

MSPs that can see, score, and reduce human risk across their client base, and report it in the language of APP 11, are in the strongest position to help these firms comply.

Frequently Asked Questions

Does the Privacy Act now apply to every small law firm, accountant, and real estate agency?

No. It applies to small businesses that provide AML/CTF designated services, and only to the personal information they handle for AML/CTF purposes. A firm that provides no designated services keeps the small business exemption, unless another rule brings it into scope.

Is MFA enough to meet APP 11?

No single control is enough. Since December 2024, reasonable steps expressly include technical and organizational measures, and courts assess them against the risks an organization knows about. MFA is essential, but so are training, policies, access reviews, and evidence that they reduce risk.

How long do Tranche 2 entities need to keep identity records?

The AML/CTF Act sets record-keeping periods, generally seven years for customer identification records. APP 11.2 then requires the information to be destroyed or deidentified once no legal reason to keep it remains. Firms should also avoid storing copies of identity documents the AML/CTF regime does not require.

What happens if a Tranche 2 entity has a data breach?

For AML/CTF information, it falls under the Notifiable Data Breaches scheme. It must assess a suspected breach within 30 days and notify the OAIC and affected individuals if serious harm is likely. The proposed second tranche of privacy reform would shorten notification to 72 hours.

How can MSPs help clients show reasonable steps?

By measuring human risk continuously, closing the highest-risk combinations first, training staff against the attacks their sector actually sees, and reporting progress in terms of APP 11. Documented trends are far more persuasive to a regulator than a list of tools.

Newsletter abonnieren

Newsletter abonnieren

Mit einem Klick auf „Anmelden“ bestätigen Sie, dass Sie unseren Nutzungsbedingungen zustimmen.
Vielen Dank! Ihre Anmeldung ist eingegangen!
Hoppla! Beim Senden des Formulars ist ein Fehler aufgetreten.

Erfahren Sie, wie Unternehmen im Bereich Professional Services mit usecure menschliche Risiken reduzieren

Erfahren Sie, wie IT-Teams in Professional-Services-Unternehmen usecure nutzen, um sensible Kundendaten zu schützen, Compliance-Anforderungen zu erfüllen und ihre Reputation zu wahren — ohne abrechenbare Arbeit zu beeinträchtigen.

Related posts

Explore more insights, updates, and resources from usecure.