As of 1 July 2026, many law firms, accounting firms and real estate agencies (Tranche 2 businesses) must update their engagement letters, onboarding forms and client terms to allow their businesses to collect and verify client identities, assess source of funds, use verification providers, pause work where checks are incomplete, protect personal information and avoid tipping off risk.
These documents should match the services actually provided, mapped against those services which are ‘designated services’ under the Tranche 2 AML/CTF reforms. A broad clause copied from another industry may create new problems if it overstates the business’s powers, ignores professional obligations or says something inconsistent with how staff actually onboard clients.
Short answer
What should Tranche 2 businesses update in engagement letters?
Tranche 2 businesses should update engagement letters and client terms to explain that AML/CTF checks may be required, identify the information the business may request, permit use of verification and screening providers, reserve the right to delay or refuse work where checks cannot be completed, align privacy collection notices with customer due diligence, and avoid promising advance notice about suspicious matter reporting. The wording should be tailored to the designated services the business provides from 1 July 2026 and the enrolment or registration obligations that apply to that business.
Why engagement letters need attention now
Australia’s reformed anti-money laundering and counter-terrorism financing laws are now operational for many newly regulated businesses that provide designated services from 1 July 2026. AUSTRAC states that newly regulated businesses providing new designated services after 1 July 2026 must apply to enrol within 28 days (effectively by 29 July 2026 for most Tranche 2 businesses providing such services).
That timing matters because many businesses have focused on policies, risk assessments, AML/CTF programs and AUSTRAC enrolment, while leaving the client-facing documents unchanged. For a law firm, accounting practice, real estate agency, trust and company service provider or advisory practice, the engagement letter is often where AML compliance becomes visible to the client.
If client terms are silent, staff may be left to explain sensitive requests informally. Clients may object to providing information. Transactions may be delayed without clear contractual support. A staff member may over-explain a suspicious matter concern. Privacy collection notices may not match the information being requested. Well-drafted client terms reduce those avoidable points of friction.
Which businesses should review client terms?
The starting point is whether the business provides a designated service with a geographical link to Australia. The industry label alone is not enough. A lawyer, accountant or real estate agent is not automatically regulated for every service, but the business may be a reporting entity when it provides particular designated services.
AUSTRAC’s professional designated services guidance is important for legal, accounting, conveyancing, corporate advisory and trust and company setup services. It explains that table 6 designated services can include assistance with certain real estate transactions, body corporate or legal arrangement transactions, equity or debt financing transactions, shelf companies, company and trust creation or restructuring, certain nominee or officeholder arrangements, and registered office or principal place of business services.
| Business type | Why engagement terms may need updating | Priority |
|---|---|---|
| Law firms & conveyancers | Client identification, beneficial ownership, source-of-funds questions, privilege-sensitive escalation and limits on acting may need to be reflected in retainers. | High priority |
| Accountants, bookkeepers, virtual CFOs and corporate advisers | Company, trust, restructuring, financing and nominee-related work may require onboarding terms that support CDD and ongoing requests. | High priority |
| Real estate agents and buyer’s agents | Agency agreements and onboarding documents may need to support identity checks, transaction delays and higher-risk source-of-funds enquiries. | High priority |
Why engagement letters matter for AML compliance
An AML/CTF program sits behind the scenes. An engagement letter sits in front of the client. The two need to work together.
An AML/CTF program includes a risk assessment and policies, procedures, systems and controls to manage and mitigate money laundering, terrorism financing and proliferation financing risks. Customer due diligence helps a business understand who its customers are and the ML/TF risks they bring, with enhanced due diligence for higher-risk scenarios and simplified due diligence potentially available for lower-risk scenarios.
In practice, those obligations affect what a client must do before and during an engagement. The business may need to identify the client, verify identity information, identify beneficial owners, understand the purpose and nature of the matter, ask questions about source of funds or source of wealth, refresh information during a long matter, and decline to provide a designated service if required information is not provided.
The engagement letter should give the business a calm contractual foundation for AML/CTF checks without suggesting that the client is suspected of wrongdoing.
Clauses to update in engagement letters and client terms
The required wording will differ by industry and business model. The following areas are usually the most important starting points.
Verification and information requests
The engagement letter should say that the business may need to collect and verify information about the client, any person acting for the client, beneficial owners, controllers, source of funds, source of wealth, the purpose of the matter and other information reasonably required for AML/CTF compliance.
For corporate clients, the wording should cover directors, shareholders, trustees, partners, officeholders, authorised representatives and beneficial owners where relevant. For trusts, it should allow requests for trust deeds, trustee details, appointor or guardian details, beneficiary information and information about persons who control the trust.
Authority to use verification providers
Many businesses will use electronic verification, document verification, sanctions screening, politically exposed person screening, adverse media tools or other third-party providers. The engagement terms should explain that the business may disclose information to verification, screening, technology, data, compliance and identity service providers for those purposes.
This wording must be consistent with the business’s privacy policy and collection notices. If the business handles sensitive information, health information, biometric verification data or identity documents, privacy wording needs extra care. The engagement letter should connect with the privacy policy and onboarding workflow rather than try to replace them.
Delays, refusal to act and termination
Client terms should make clear that the business may delay starting work, pause work, refuse to provide a designated service, withhold transaction steps or terminate the engagement if required information is not provided or if the business is not satisfied it can meet its AML/CTF obligations.
Professional firms should also check whether professional conduct rules, court deadlines, existing retainers, consumer law obligations or unfair contract terms laws affect how those rights can be used. A clause should give the business practical room to comply with AML/CTF obligations while still being applied fairly and lawfully.
Source of funds and source of wealth
AUSTRAC guidance explains that source-of-funds and source-of-wealth information can help a reporting entity determine whether funds come from a legitimate source or may be from unlawful activity. Engagement letters should support proportionate requests for evidence, particularly in higher-risk matters or transactions.
The wording should avoid implying that every client must provide the same documents in every matter. A better approach is to reserve the right to ask for information and documents reasonably required having regard to the business’s AML/CTF obligations, risk assessment and the nature of the matter.
Suspicious matter reporting and tipping off
Engagement letters should be careful when referring to suspicious matter reports (SMRs). AUSTRAC guidance states that it is a criminal offence to share SMR details if that disclosure could reasonably prejudice an investigation. Client terms should not promise advance notice, seek client consent to report, or describe internal suspicion triggers in a way that creates tipping off risk.
A cautious clause may say that the business may be required or permitted to report certain matters to a regulator or authority and may be legally restricted from telling the client about that report or related action.
Privacy and retention
OAIC guidance states that reporting entities and authorised agents required to comply with the AML/CTF Act must comply with the Privacy Act 1988 when handling personal information for AML/CTF purposes. From 1 July 2026, this can include Tranche 2 entities once they become reporting entities.
The engagement letter should direct clients to a privacy collection notice or privacy policy that accurately explains what information is collected, why it is collected, who it may be disclosed to, whether overseas disclosure may occur, and how individuals can access privacy information. The wording should also reflect OAIC guidance that the AML/CTF Act does not require scanned copies or photocopies of identity documents themselves to be kept for record-keeping purposes under the new laws.
Sample AML clause wording
The following examples are starting points for drafting. They should be tailored to the business’s designated services, AML/CTF program, privacy documents, professional obligations and customer workflows.
Example: client due diligence
We may be required to collect, verify and update information about you, persons acting for you, beneficial owners, controllers, your source of funds or source of wealth, the purpose of the matter and other information reasonably required to comply with anti-money laundering and counter-terrorism financing laws, sanctions requirements, fraud prevention procedures, professional obligations and our internal risk management policies.
Example: use of verification providers
We may use identity verification, screening, technology, data and compliance service providers to assist with client due diligence, sanctions screening, politically exposed person screening, adverse media checks, fraud prevention, record keeping and related compliance activities. This may involve disclosing personal information to those providers for those purposes.
Example: delay or refusal
We may delay commencing or continuing work, decline to provide a service, withhold a transaction step, restrict access to a service, or terminate the engagement if you do not provide information we reasonably request, if we cannot complete required checks, or if continuing would be inconsistent with our legal, regulatory, professional or risk management obligations.
Before adopting any sample wording, ask: does this clause match what staff will actually do when onboarding a client, pausing a matter or escalating a suspicious matter concern?
Sector-specific issues
Standard AML clauses should be adapted for the sector. A professional services retainer or real estate agency agreement will not manage the same risks.
Law firms, conveyancers and accountants
Law firms, conveyancers and accountants should avoid wording that undermines client trust, confidentiality or professional obligations. For law firms, legal professional privilege and confidentiality need explicit attention. For accountants and tax advisers, client authority, tax agent obligations, confidentiality and data handling may need to be considered.
The engagement letter should also distinguish between general advice and work that directly advances a designated service. Not every conversation about a transaction will necessarily trigger the same onboarding position. Once the firm accepts instructions and starts taking active steps that directly advance a regulated transaction, AML onboarding may need to be completed before those steps proceed.
Real estate agencies
Real estate businesses should align AML clauses with agency agreements, buyer onboarding, seller onboarding, open home procedures, offer processes, contract exchange and settlement workflows. The terms should support identity checks on vendors and purchasers where required, beneficial ownership checks for company or trust clients, source-of-funds questions in higher-risk transactions, and delays where checks are incomplete.
Staff training is important. A calm explanation that AML/CTF laws require certain checks is usually better than language that implies the client is personally suspected of wrongdoing.
Implementation checklist
Before issuing updated engagement letters or client terms, check the following items.
- Confirm which designated services the business provides and when AML/CTF obligations apply.
- Map each clause to the AML/CTF program, customer due diligence procedure and staff workflow.
- Check whether the business must enrol only or also register with AUSTRAC.
- Align engagement letter wording with privacy collection notices, privacy policy and onboarding screens.
- Confirm what information will be requested from individuals, companies, trusts, beneficial owners and authorised representatives.
- Review whether verification providers, screening providers and other outsourced vendors are accurately described.
- Reserve rights to delay, refuse, restrict or terminate work where checks cannot be completed.
- Remove wording that promises advance notice of suspicious matter reporting or creates tipping off risk.
- Check whether professional obligations, privilege, confidentiality or unfair contract terms laws require narrower wording.
- Train staff to use the clauses consistently and avoid informal explanations that contradict the written terms.
Frequently asked questions
Do all law firms, accountants and real estate agents need AML clauses?
Not every service is regulated merely because the provider is a lawyer, accountant or real estate business. The question is whether the business provides a designated service with a geographical link to Australia. Many affected businesses should still update standard terms because AML/CTF checks may apply to some matters even if not every matter is regulated.
Can a business refuse to act if a client does not provide AML information?
Engagement terms should reserve the right to delay, refuse or terminate work where required information is not provided or where the business cannot satisfy its AML/CTF obligations. The business should also consider professional obligations, existing retainers, court deadlines, consumer law issues and any duty to avoid unfair or misleading conduct.
Can engagement letters tell clients about suspicious matter reports?
A carefully drafted clause may say that the business may be required or permitted to report certain matters and may be restricted from telling the client. It should not promise advance notice, seek consent to report, or describe internal suspicion triggers in a way that could create tipping off risk.
Are AML checks the same as conflict checks?
No. Conflict checks identify whether the business can act consistently with professional and commercial duties. AML checks focus on customer identity, beneficial ownership, risk, source of funds, transaction purpose, sanctions and suspicious activity. The workflows can be combined, but the legal purpose is different.
Should engagement letters include a privacy collection notice?
The engagement letter can refer to privacy collection information, but it should not be the only privacy document if the business collects detailed identity, verification or screening information. OAIC guidance includes a template privacy collection notice for reporting entities under the AML/CTF Act, and the business’s privacy notice should match the actual onboarding workflow.
Sources
- AUSTRAC, Professional designated services
- AUSTRAC, Enrol with us overview
- AUSTRAC, New reporting regime now in force
- AUSTRAC, Your obligations
- AUSTRAC, Overview of initial customer due diligence
- AUSTRAC, Source of funds and source of wealth
- AUSTRAC, Suspicious matter reports
- AUSTRAC, Tipping off
- OAIC, Privacy guidance for reporting entities under the AML/CTF Act
- OAIC, Template privacy collection notice for reporting entities under the AML/CTF Act
- Federal Register of Legislation, Anti-Money Laundering and Counter-Terrorism Financing Act 2006
- Federal Register of Legislation, Anti-Money Laundering and Counter-Terrorism Financing Rules 2025
Disclaimer
This article provides general information only and is not legal advice. AML/CTF obligations, privacy obligations, professional duties, client confidentiality, privilege, unfair contract terms and consumer law issues can apply differently depending on the business, designated services, clients, documents and workflows involved. Businesses should obtain legal advice before adopting AML clauses or changing client onboarding processes.