AML/CTF obligations for Tranche 2 businesses are now in force. Since 1 July 2026 Get compliant
10-step AML/CTF compliance checklist for Australian real estate agents preparing for Tranche 2

AML/CTF Compliance Checklist for Real Estate Agents: What You Need Before 1 July 2026

A practical, step-by-step guide to preparing your agency for Tranche 2 AML/CTF obligations, based on current AUSTRAC reform guidance.

AML/CTF Compliance30 March 20268 min readAML Guard

From 1 July 2026, real estate agents who provide designated services will be required to comply with Australia’s AML/CTF regime. The new obligations begin on 1 July 2026 under the reformed AML/CTF framework.

But what does “compliance” actually look like in practice? This checklist breaks it down into practical steps based on current AUSTRAC reform guidance. It is not a substitute for professional advice, but it gives you a clear picture of the work ahead.

Last reviewed: March 2026

1. Determine Whether You Provide a Designated Service

Not every real estate business will be caught by the AML/CTF regime. Your obligations depend on whether you provide a designated service as defined in the AML/CTF Act.

Activities that are generally in scope include brokering the sale, purchase, or transfer of real estate on behalf of a buyer, seller, transferee, or transferor in the course of carrying on a business. This typically covers seller’s agents, buyer’s agents, and property developers who sell directly.

Activities that are generally not in scope include property management and rental services, leases of 30 years or less, open-home attendance and general enquiries, mortgagee interests, easements and restrictive covenants, and private sales of residential property by individuals (not businesses). This list is not exhaustive, AUSTRAC’s published guidance should be consulted for the full scope of exclusions.

AUSTRAC provides an online tool to help you check whether your services are regulated. Use it as a starting point, but consider seeking professional advice if your situation is unclear.

2. Enrol with AUSTRAC

If you provide a designated service, you must enrol with AUSTRAC. Enrolment for tranche 2 entities opened on 31 March 2026, and newly regulated tranche 2 entities must be enrolled by 29 July 2026.

You must also appoint an AML/CTF compliance officer within 28 days of commencing designated services, and notify AUSTRAC within 14 days of the appointment. For many real estate agencies, this may be the licensee in charge or another senior person with appropriate authority, independence, and resources.

3. Conduct Your ML/TF Risk Assessment

Before you start providing designated services, you must identify and assess the money laundering, terrorism financing, and proliferation financing (ML/TF) risks your business faces.

Your risk assessment should consider the types of designated services you provide, the types of customers you deal with (individuals, companies, trusts, foreign persons), the geographic areas in which you operate, and how you deliver your services.

Your risk assessment is the foundation of your AML/CTF program. Everything else: your policies, CDD procedures, training, and monitoring, should be calibrated to the risks you identify here.

4. Establish Your AML/CTF Program

You must have a documented AML/CTF program in place before you start providing designated services. Under the reformed framework, your program should include:

Your AML/CTF program is not a document you write once and file away. It is a living operational framework that must be maintained, followed, and evidenced. The platform you choose should help you manage and evidence your program, not just run CDD checks.

5. Set Up Customer Due Diligence (CDD) Procedures

CDD is the practical process of identifying your customers, verifying their identity, and assessing their ML/TF risk. For real estate agents, CDD generally needs to be completed before or at the start of the designated service for the party you are acting for.

For individuals, you must collect identifying information and verify identity using reliable and independent sources. For entity customers, you must identify the entity, its beneficial owners, and in some cases its senior managing officials.

Sanctions screening cannot be delayed, even where other CDD steps may be deferred. Ongoing CDD requires monitoring customers and transactions throughout the business relationship.

6. Establish Reporting Procedures

You should have documented procedures to identify, assess, and report the following to AUSTRAC where required:

Suspicious Matter Reports (SMRs): report within 3 business days, or 24 hours for terrorism-financing suspicions. Threshold Transaction Reports (TTRs), for physical currency transfers of A$10,000 or more.

You must not disclose to the customer that an SMR has been or will be made (“tipping off”). Your reporting procedures should include safeguards to prevent inadvertent disclosure.

7. Train Your Team

All employees and agents working in roles that pose ML/TF risk must complete documented, role-appropriate training. Training should be repeated at appropriate intervals and records must be retained.

8. Set Up Record Keeping

You must retain records of your AML/CTF program, risk assessments, CDD procedures and results, transaction records, SMRs and TTRs, training records, and any other compliance activities for at least 7 years.

9. Plan for Independent Evaluation

Your AML/CTF program must be independently evaluated at least every 3 years. AUSTRAC notes that newly enrolled entities may wish to conduct their first evaluation earlier.

10. Choose Your Compliance Platform

A purpose-built compliance platform can help automate CDD workflows, manage program documents, track training, support AUSTRAC reporting processes, and maintain an auditable compliance record over the required retention period.

What Happens If You Do Not Comply?

AUSTRAC has broad enforcement powers including infringement notices, enforceable undertakings, remedial directions, and civil penalty proceedings. The Federal Court may order significant civil penalties, up to 20,000 penalty units for an individual and 100,000 penalty units for a body corporate.

See How AML Guard Works

Tranche 2 obligations commence 1 July 2026.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo

Related Reading

This article is for general information purposes only and does not constitute legal or compliance advice. The information reflects current AUSTRAC reform guidance as at the date of publication. Firms should obtain independent professional advice on their specific AML/CTF obligations.