From 1 July 2026, Australian law firms providing designated services must have an AML/CTF program in place — and that program must include mandatory staff training. This article covers exactly what that training obligation requires, who it applies to across your firm, and how to build a training process you can evidence when AUSTRAC comes looking.
The legal profession is entering Australia’s anti-money laundering and counter-terrorism financing regime for the first time. AUSTRAC enrolment opened 31 March 2026. The deadline is fixed. The obligation is firm-wide — not just for your risk team or your compliance officer.
Most managing partners understand the broad shape of what’s coming. The gap is in execution. Many firms are still working out what “firm-wide training” actually means in practice: who needs it, how often, what must be covered, and how to prove it happened. That’s what this guide addresses.

TL;DR: AML & CTF Training for Law Firms
From 1 July 2026, Australian law firms providing designated services must have a mandatory AML/CTF training program in place — firm-wide, documented, and audit-ready. That means structured content built around your actual policies, completion records for every staff member, and automated re-training when obligations change. Tribal Habits lets your firm build, deliver, and track all of it without a training department.
What Tranche 2 Means for Australian Law Firms
Australia’s AML/CTF Act has applied to financial institutions and gambling businesses since 2006. Tranche 2 extends the regime to “designated non-financial businesses and professions” — including legal practitioners. This is not a drill. The laws are passed. AUSTRAC is the regulator, and the compliance deadline is 1 July 2026.
Which law firms are affected?
The obligations apply to legal practitioners who provide “designated services.” These are specific activities, not general legal work. A firm that does not provide any designated services falls outside the regime. But most firms handling commercial or property work will be in scope.
What services trigger AML/CTF obligations?
If your firm provides any of the following, your AML/CTF obligations are triggered:
- Acting in transactions involving the buying or selling of real property
- Managing client funds, accounts, securities, or other assets
- Organising contributions for company creation, operation, or management
- Assisting with corporate restructuring or mergers and acquisitions
- Facilitating debt or equity financing arrangements
- Acting as a trustee or nominee in a legal arrangement
For a definitive list of designated services and current AUSTRAC guidance, refer directly to the AUSTRAC Tranche 2 guidance for legal practitioners.
Designated Service Scope at a Glance
| Service | Triggers Obligations? |
|---|---|
| Property transactions (buy/sell) | Yes |
| Managing client trust funds | Yes |
| Corporate restructuring or M&A | Yes |
| Debt or equity financing | Yes |
| General litigation or advice only | No |
| Wills and estates (no asset management) | No |
What the AUSTRAC Staff Training Requirement Actually Says
Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, reporting entities — which now includes law firms providing designated services — must have an AML/CTF program that includes an employee due diligence and training component. This is a statutory obligation, not a recommendation.
Training is not optional — and it is not just for compliance officers
This is where most firms underestimate the scope. The training obligation applies across your workforce — not only to fee earners or the partner responsible for AML compliance. Any staff member who works in or supports a designated service area must receive appropriate AML/CTF training.
That typically includes: fee earners handling in-scope matters, secretaries and paralegals supporting those matters, finance and trust account staff, and practice managers or office managers with oversight of in-scope work.
What does an AML/CTF training program need to cover?
At minimum, your AML/CTF training program must give staff the knowledge to recognise and respond to their obligations. AUSTRAC expects training to be appropriate to each role and proportionate to the level of ML/TF risk the staff member is exposed to.
A well-structured program covers:
- What money laundering and terrorism financing are, and how they occur in legal practice
- Your firm’s AML/CTF program — what it covers and what staff are expected to do
- Customer due diligence procedures — what to collect, when, and how to record it
- How to identify and report suspicious matters internally
- Recordkeeping obligations and document retention requirements
- Consequences of non-compliance — for the firm and for individuals
How often must training be delivered and reviewed?
Training is not a one-time event. Your AML/CTF program must be reviewed and updated as your firm’s risk profile, services, or AUSTRAC’s guidance changes. Staff must receive updated training when the program changes or when they move into roles that involve designated services.
In practice, most firms treat annual re-training as the baseline. New staff must be trained before they begin working in designated service areas, not after.

The Scope Problem Most Law Firms Are Underestimating
Running an AML/CTF training session is the easy part. The harder problem — and the one that catches firms out in an audit — is demonstrating that training happened, who attended, what they covered, and when they’re due again.
Why firm-wide training is harder to manage than it sounds
Law firms are not simple organisations. You have partners, associates, paralegals, legal secretaries, trust account staff, and administrative teams — often across multiple offices or practice groups. Roles shift. Staff leave. New people start.
Managing who has completed AML/CTF training, who is overdue, and who needs updated training after a program change becomes a logistical problem fast. A shared spreadsheet is not a training record. An email confirmation is not evidence of completion. And a face-to-face session with no attendance register is invisible to a regulator.
What happens if training records can’t be produced in an audit?
AUSTRAC has real enforcement powers. Civil penalties for serious non-compliance are significant, and reputational consequences for law firms found to have inadequate AML programs are substantial. AUSTRAC can request your training records. If you cannot produce them, “we ran a session” is not an acceptable answer.
Our post on what regulators expect from your training records covers what good record-keeping looks like in practice — and where firms consistently fall short.
Building an AML/CTF Training Program Your Firm Can Actually Run
Here is a practical four-step approach. It applies whether you have 10 staff or 200, and whether you’re starting from scratch or updating what you already have.
Step 1 — Map which staff and roles are in scope
Start with your practice areas. Identify which services you provide that are “designated services” under the AML/CTF Act. Then map the roles that support those services. Not every person in your firm needs the same depth of training, but you need a clear view of who needs what.
Create a role-based matrix: which roles, which practice groups, and what level of training is appropriate for each. This becomes the backbone of your training program and your evidence base.
Step 2 — Build or source training content that matches your firm’s designated services
Generic AML training rarely maps to how a specific firm operates. A firm focused on property transactions has different risk exposure to one focused on corporate finance. Your training content should reflect your firm’s AML/CTF program, your specific designated services, and your actual client due diligence procedures.
Off-the-shelf AML content can provide a useful baseline on concepts, but it should be supplemented with firm-specific material — your policies, your reporting lines, your recordkeeping procedures. Staff need to know what to do in your firm, not a generic version of a law firm.
See also: Can I customise compliance training to include our company policies?
Step 3 — Deliver training and capture completion records
Every staff member who completes AML/CTF training needs a completion record. That record should capture: who completed it, when, what version of the training they completed, and (where applicable) their assessment score.
If you deliver training online, your platform should capture this automatically. If you deliver face-to-face sessions, you need a formal attendance register that is stored and retrievable. “I’m pretty sure everyone did it” is not a compliance record.
Step 4 — Set up annual review and re-training processes
Your AML/CTF program must be reviewed periodically, and when it changes, staff must be trained on what’s new. Build that process before 1 July 2026, not after. Set up reminders for annual re-training. Create a process for onboarding new staff into AML training before they touch in-scope work.
The firms that pass audits are the ones that have training running as a system, not as a one-off event that someone remembered to organise once.
How Tribal Habits Helps Law Firms Meet Their AML/CTF Training Obligations
Here’s what good looks like for a law firm solving this right now: training content that reflects how your firm actually operates, completion records that are available instantly, and re-training that runs automatically when it’s due. That’s the standard AUSTRAC expects. Here’s how Tribal Habits delivers it.
Build your own AML/CTF training, branded to your firm.
Tribal Habits has a built-in authoring tool — your own people can create training that reflects your firm’s designated services, your policies, and your client base. The people who know your firm’s AML procedures build the training. No external consultants required. No waiting for a vendor to update generic content that doesn’t map to how you work.
Track completion across every staff member, every role.
AUSTRAC expects records. Tribal Habits captures who completed what, when, and what score they received. Completion reports are available instantly — no spreadsheets, no chasing managers for attendance lists. If an auditor asks for your training evidence, you can pull it in minutes.
See how this works in practice: audit-proof training — prove compliance in minutes.
Set up automated re-training and expiry reminders.
AML/CTF training is not a one-time project. Obligations change. Staff change. Tribal Habits automates reminders and re-enrolment so training doesn’t quietly expire without anyone noticing. Your annual review cycle becomes a system, not something someone has to remember.
Active user pricing — fair for firms with variable staffing.
Law firms pay only for staff who are actively using the platform in a given month, not a flat fee for your entire headcount. For firms managing varying staffing levels or seasonal workloads, this keeps costs predictable and fair. See more on LMS for law firms and how the platform is built for professional services environments.
See how Tribal Habits helps Australian law firms manage AML/CTF training — Book a free demo →

This information is general in nature and doesn’t constitute legal or compliance advice. Requirements vary by state, sector and organisation, so we’d always recommend checking with your regulator or professional adviser before relying on it.
Frequently Asked Questions About AML/CTF Training for Law Firms
Do all staff in a law firm need AML/CTF training, or just fee earners?
All staff who work in or support designated service areas need training — not just fee earners. This includes paralegals, legal secretaries, trust account and finance staff, and practice managers with oversight of in-scope matters. The training must be appropriate to each person’s role and their level of exposure to ML/TF risk.
What records does AUSTRAC expect a firm to keep?
AUSTRAC expects reporting entities to maintain records of their AML/CTF program, including staff training. At minimum, you should be able to produce: a record of who received training, when they completed it, what the training covered, and any assessment results. Records must be retained for seven years.
Can we use off-the-shelf AML training, or does it need to be customised to our firm?
Generic AML training can cover foundational concepts, but it must be supplemented with firm-specific content — your AML/CTF program, your designated services, your client due diligence procedures, and your internal reporting lines. Staff need to know how to apply obligations in your firm, not in a theoretical law firm. A training platform that lets you build your own content is more useful here than a pre-packaged course library.
What is the penalty for not having an AML/CTF training program in place?
AUSTRAC has significant civil penalty powers for non-compliance with AML/CTF obligations. Penalties for serious or systemic failures can reach into the millions of dollars. Beyond financial penalties, AUSTRAC can issue public warnings and refer matters for criminal investigation. Reputational risk for a law firm found to be non-compliant is substantial. The cost of getting this right is far lower than the cost of getting it wrong.
We’ve never used a training platform before — how quickly can we get this set up?
With the right platform, a law firm can be up and running with AML/CTF training within days, not months. Tribal Habits is designed for teams without dedicated L&D resources — you don’t need a training specialist to build, deliver, or manage your program. With the deadline at 1 July 2026, starting now gives you enough time to build firm-specific content, test it with a small group, and roll it out across all relevant staff before the compliance date.
The Deadline Is Fixed. The Training Obligation Is Real.
Australian law firms have had years of forewarning about Tranche 2. The compliance deadline is now weeks away. The training obligation is statutory, it applies firm-wide, and it requires records — not just effort.
The firms that will find this manageable are the ones that treat AML/CTF training as a system: clear roles, structured content, automatic tracking, and evidence that’s ready the moment someone asks for it. The firms that will struggle are the ones that ran a session, sent an email, and assumed that was enough.
You have the time to do this properly. The question is whether you start now.
Book a free demo and see how Tribal Habits helps Australian law firms manage AML/CTF training →
Further Reading
- Complete Guide to Online Compliance Training Australia
- LMS for Compliance Training: Keeping Teams Certified
- Best LMS for Law Firms 2026 | Compliance & CPD at Scale
- 10 Reasons Compliance Training Fails (and How to Fix Each One)
- What Regulators Expect From Your Training Records
- Audit-Proof Training: Prove Compliance in Minutes
- Free Compliance Training Framework Checklist
- How to Fix CPD and Compliance Training in Law Firms
- How to Build a CPD Pathway for a Multi-Office Law Firm
- Why CPD and Compliance Training Breaks Down in Law Firms
- Manager Training Dashboard: Escalate Overdue Training
- Positive Duty Training for Law Firms: What You Need to Do!