Skip to content
Q10 Systems
Home Pricing Switching providers Resources Call Q101300 110 210 Talk to Q10
← Resources

AML/CTF Tranche 2: what it means for your IT and data security

What the 2026 AML/CTF changes mean for record storage, access, privacy, backup and Microsoft 365 for professional services firms in North Queensland.

Business records and document folders representing AML and compliance information

For accountants, lawyers, conveyancers and real estate businesses in Townsville and Cairns.

Last reviewed: 11 August 2026

AML/CTF Tranche 2 obligations commenced on 1 July 2026, bringing a range of professional services and other newly regulated sectors into the regime. Enrolment for newly regulated entities was due by 29 July 2026.

Most commentary focuses on enrolment, AML/CTF programs, customer due diligence and reporting. This article focuses on a narrower question: what do those obligations mean for the systems used to store, access, retain and recover the information behind the program?

Q10 Systems provides managed IT and cybersecurity services across Townsville and Cairns. This article covers the technology side only. It is not legal or AML/CTF compliance advice.

Checked business and tax documents representing evidence and compliance records

Photo by Markus Spiske via Unsplash.

My firm turns over less than $3 million. Weren’t we exempt from the Privacy Act?

For AML/CTF-related personal information, the usual small-business exemption no longer protects a reporting entity simply because turnover is under $3 million. From 1 July 2026, Privacy Act obligations apply to personal information handled in connection with AML/CTF activities by Tranche 2 reporting entities.

That matters for smaller firms that may not previously have operated under the Privacy Act. In practice, it raises the importance of access control, secure storage, incident response, data minimisation and breach response for the identity and due diligence information collected through the AML/CTF process.

Does AML/CTF Tranche 2 require specific IT or cybersecurity controls?

No. The AML/CTF framework does not prescribe a fixed technology checklist. AUSTRAC does, however, expect sensitive records to be stored securely, access to be limited to authorised people, and electronic records to be protected and backed up.

In a technology review, the practical controls Q10 would look at include multi-factor authentication, access permissions, audit logging, endpoint protection, record retention, backup and recovery, and a documented incident response process. These are implementation controls that help the systems support the business’s program; they are not a substitute for legal or compliance advice.

Where should AML/CTF records be stored?

There is no single mandated platform, but the records should be kept in a location where access can be controlled, records can be retained for the required period, and the information can be backed up and recovered.

A common weakness in small firms is sensitive identity information sitting in general shared folders where access is broader than necessary. The better approach is deliberate permissions, clear ownership of the record location and a retention process that does not depend on someone remembering not to delete something later.

Do I need to keep copies of passports and driver licences?

Generally, no. The reformed regime does not usually require businesses to retain full copies of identity documents simply to prove that verification occurred. The focus is on keeping the information and records needed to demonstrate the verification process, the outcome and the relevant risk decisions.

That is also important from a privacy perspective. Holding full identity-document images creates additional risk if they are not actually required. If your current onboarding process involves routinely saving scans into a general client folder, it is worth reviewing whether that practice is still necessary.

Who should be able to access suspicious matter information?

Access should be limited to the people who genuinely need it for their role. Information connected with suspicious matter reporting sits alongside strict secrecy and tipping-off obligations, so the system should support restricted access rather than relying on an informal understanding that team members will not open a folder.

In practice, that normally means a separate restricted location, explicit membership rather than broad inherited permissions, and useful access logging where the platform supports it.

What happens if there is a data breach involving AML/CTF information?

A breach involving AML/CTF information may need additional care before notifying affected individuals. The Notifiable Data Breaches scheme contains exceptions where notification would be inconsistent with secrecy provisions.

Your incident response process should account for that possibility before an incident occurs and involve the appropriate legal or AML adviser where the notification path is unclear. Q10’s role is to help make sure the technical response process, evidence and containment capability are in place.

Can we store AML/CTF records in Microsoft 365 or SharePoint?

Yes, Microsoft 365 can be a practical platform for smaller firms when it is configured properly. SharePoint and Microsoft 365 can provide permissions, audit capability, retention controls, version history and administrative controls around business records.

The important point is configuration. A default tenant does not automatically mean the right permissions, retention periods or evidence are in place. Microsoft provides Australian data-at-rest commitments for applicable core Microsoft 365 workloads when the tenant meets the relevant Product Terms conditions, but data location should still be checked against the services and licensing actually in use rather than assumed across every Microsoft service.

Does seven-year record retention mean we need seven years of backup versions?

No. Record retention and backup are related, but they are not the same thing. The system needs to preserve the required records for the applicable retention period, and those records also need to be adequately protected and recoverable.

A seven-year retention requirement does not automatically mean keeping seven years of historical backup snapshots. The practical review is whether the required record remains available for the full period, and whether there is a secure recovery path if the primary system or data is lost.

We enrolled with AUSTRAC. What should we do next?

Check whether the systems underneath the AML/CTF program actually support the way the program is meant to operate.

A practical technology review looks at whether MFA is enforced where appropriate, who can access identity and due diligence information, whether retention settings match the required record types, what audit evidence is available, whether unnecessary identity-document copies are being kept, and whether backup and incident response arrangements are workable.

How Q10 Systems can help

AML/CTF requirements place greater importance on how sensitive client information is stored, accessed, protected and recovered.

Q10 helps businesses strengthen the cybersecurity and IT controls that support these requirements. We can review your existing environment, identify gaps and help put the right controls in place.

  • multi-factor authentication and Conditional Access
  • secure access to sensitive client information
  • Microsoft 365 and SharePoint security
  • administrator and privileged access
  • endpoint security and patching
  • backup and recovery
  • audit logging and security monitoring
  • record retention and data protection
  • incident-response readiness
  • security awareness and user access reviews

Where appropriate, we can also assess these controls against recognised cybersecurity frameworks such as SMB1001 and the Essential Eight. This gives the business a broader view of its security posture rather than treating AML/CTF as a standalone IT exercise.

The same improvements can support a range of business requirements, including privacy, cyber insurance, client security expectations and other regulatory obligations.

Your legal or AML adviser can guide the business on its specific AML/CTF obligations and processes. Q10 works alongside that by making sure the technology and cybersecurity controls supporting those processes are secure, manageable and properly implemented.

If your business is working through the new AML/CTF requirements, Q10 can review the technology behind the process, identify areas that need attention and help strengthen the security controls around your client information.

Official sources

This article is general information about IT and data-security considerations arising from the AML/CTF reforms. It is not legal advice or AML/CTF compliance advice and does not consider your firm’s circumstances. Obligations depend on the designated services your business provides.

Start a conversation

Tell us what you need help with.

Tell us what is happening in plain English. You do not need to diagnose the issue first.