How Docusign supports your AML/CTF compliance obligations
Thousands of Australian businesses have been affected by the recent reforms to AUSTRAC AML/CTF rules. Here, we explore what the reforms look like and how you can stay compliant.

Key Takeaways
AUSTRAC’s Tranche 2 AML/CTF reforms are live, placing new obligations on gatekeeper professions.
Manual processes increase risk; an intelligent digital agreement platform is essential for compliant, tamper-proof workflows.
Leverage Docusign’s integration with IDVerse to streamline identity verification with AI-powered, TDIF-accredited checks and local data residency.
Standardise your corporate governance, onboarding, and approvals with audit-ready digital trails.
Overview
Regulatory compliance has long been the bane of many businesses. Yes, it exists to protect customers and stakeholders from harm; but staying compliant can be a burden. Thousands of Australian professional services firms are certainly feeling this burden right now, with the recent implementation of AUSTRAC’s long-anticipated Tranche 2 Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) reforms.
The reforms came into play on 1 July 2026, and saw a vast new cohort of gatekeeper professions enter the regulated perimeter, including lawyers, accountants, real estate agents, trust and company service providers, and virtual asset service providers who provide designated services to clients. You can learn more about designated services for newly regulated entities here opens in a new tab.
Let’s take a look at what these businesses need to know and, more importantly, how you can set your agreement and documentation workflows up for success.
What are the new rules with Tranche 2?
In simple terms, the Tranche 2 reforms close a historical gap in Australia’s financial intelligence framework. Until now, criminals have exploited this gap – targeting non-financial sectors to launder money or move illicit funds. By bringing these gatekeeper professions into the fold, AUSTRAC aims to make the entire Australian economy more resilient.
If your business is one of the aforementioned gatekeeper professions offering designated services, you are now obligated to:
Formally register with AUSTRAC as a reporting entity
Design, implement and maintain a written risk-based AML/CTF compliance program tailored to your business size and risk profile
Verify the identity of your clients (Know Your Customer/Know Your Business) before providing designated services, including identifying ultimate beneficial owners
Report any suspicious matters or large cash transactions to AUSTRAC
Train your team to identify red flags and ensure senior management has oversight of compliance
What do the above tasks have in common? They all rely heavily on documentation – which is why, at its heart, AML/CTF compliance is an agreement and record-keeping challenge.
The front line of AML/CTF compliance
Think about a typical client onboarding sequence under the new rules. It’s no longer enough to send out a standard engagement letter. At this point of initial engagement, you need to:
Gather and verify government-issued IDs or corporate registry documents
Execute complex beneficial ownership checklists for corporate clients
Conduct and document internal risk assessments
Secure management sign-off on high-risk clients
All this, and you also need to retain tamper-proof audit trails of the entire process for a minimum of seven years.
If your firm currently relies on scattered PDFs, manual signatures, paper forms and disjointed email threads, then the new volume of paperwork demanded by AUSTRAC will present real headaches – not to mention business risk. Manual processes increase the risk of errors, gaps in data, unverified signatures and opaque approvals.
How Docusign supports your compliance program
Once you’ve sought legal or compliance advice and have built your AML/CTF program, you need an engine to run this program. That’s where Docusign comes in. Our Intelligent Agreement Management (IAM) platform is a powerful, foundational layer that digitises and automates the many forms, workflows and approvals required to make your program a reality.
By removing administrative friction, Docusign helps newly-regulated entities to standardise compliance across four critical pillars:
Centralised corporate governance: Your written AML/CTF program must be formally approved by governing management or your board. With Docusign, you can route these foundational policies, risk frameworks and subsequent annual reviews through structured, internal approval tracks. Absolute traceability of executive oversight is guaranteed.
Client onboarding: Rather than sending multiple separate emails for engagement letters, identity forms and source-of-funds declarations, you can bundle it all into a single, guided digital experience. Using Docusign, you can embed mandatory Know Your Customer/Know Your Business data fields, conditional logic and secure document upload portals directly into the agreement.
Streamlined approvals: If a client triggers a “medium” or “high” risk rating during your initial assessment, Docusign can automatically route these files to a designated compliance officer or management team for formal authorisation and digital sign-off.
Staff training: You need the ability to prove to AUSTRAC that your employees understand your AML/CTF program policies and procedures. If you use Docusign to distribute internal training logs and policy updates, you can keep a secure record of who has seen what.
Advanced Identity Verification with IDVerse: For businesses requiring robust AML compliance, our integration with IDVerse provides an AI-powered, TDIF-accredited identity verification solution. It delivers a seamless, locally-compliant experience for your clients, with in-country data residency, fully automated biometric and document checks, and secure, tamper-proof audit trails for every verification.
Show AUSTRAC that you mean business
Recognising that small and mid-sized businesses can’t very well overhaul existing operations overnight, AUSTRAC is taking a “pragmatic and proportionate” approach to compliance checks. They want to see that you’re making a concerted effort to comply, and that you have documented implementation plans in place.
With Docusign behind you, every verification, engagement letter and internal risk sign-off is managed through an intelligent digital workflow and comes with a tamper-evident Certificate of Completion. So if AUSTRAC does request an audit, you don’t need to dig through filing cabinets or search old inboxes, but instead have immediately visible and verifiable proof.
And an added bonus? By upgrading to intelligent, automated agreement workflows, you’re also creating a seamless, professional onboarding experience for your clients.
Ready to streamline your AML compliance? Schedule a demo to see how Docusign can automate your workflows and secure your client identity verification.
Docusign IAM is the agreement platform your business needs
