AML/CTF obligations for Tranche 2 businesses are now in force. Since 1 July 2026 Get compliant
8 required components of an AML/CTF program for Australian property professionals under Tranche 2

What Is an AML/CTF Program? A Plain-English Guide for Property Professionals

You need more than identity checks to comply with Tranche 2. Here is what an AML/CTF program actually is, what it must contain, and what the difference means for your business.

AML/CTF Compliance 30 March 2026 7 min read AML Guard

One of the most common misunderstandings in the lead-up to Tranche 2 is that AML compliance means running identity checks on your clients. It does not. Identity verification is one component of a much broader set of obligations.

What AUSTRAC actually requires is an AML/CTF program: a documented, operational framework that covers how your business will identify, assess, and manage money laundering and terrorism financing risk. If you do not have an appropriate AML/CTF program in place before you start providing designated services from 1 July 2026, you will not meet AUSTRAC’s program requirements, regardless of how many identity checks you run.

Last reviewed: March 2026

What Is an AML/CTF Program?

An AML/CTF program is the documented framework of policies, procedures, systems, and controls your business uses to identify, assess, manage, and evidence ML/TF risk and compliance.

It is not a product you buy. It is not a single document you draft and file. It is an ongoing operational framework that must be tailored to your business, maintained over time, and evidenced when required.

Think of your AML program as the operating system for compliance. CDD checks, sanctions screening, and identity verification are applications that run on it: but without the operating system, the applications have no structure, no governance, and no audit trail.

What a Program Is Not

Before diving into the required components, it is worth being explicit about what does not constitute an AML/CTF program:

What Must an AML/CTF Program Contain?

1. ML/TF Risk Assessment

A documented assessment of the ML/TF risks your business faces, considering the services you provide, your customer types, geographic areas, and delivery channels. Your risk assessment is the foundation of everything else in your program.

2. AML/CTF Policies

Written policies, approved by a senior manager, setting out how your business will identify, mitigate, and manage ML/TF risks. Policies should cover CDD procedures (simplified, standard, and enhanced), beneficial ownership identification, ongoing monitoring, reporting, record keeping, and staff training.

3. AML/CTF Compliance Officer

You must appoint an AML/CTF compliance officer within 28 days of commencing designated services, and notify AUSTRAC within 14 days of the appointment. The compliance officer must be a fit and proper person with the authority, independence, and resources to oversee day-to-day compliance.

4. Customer Due Diligence Procedures

Your program must set out how you will conduct initial CDD, ongoing CDD, and enhanced CDD. Procedures should specify what information you collect, how you verify identity, how you assess risk, what triggers enhanced measures, and how you handle situations where CDD cannot be completed.

5. Staff Training

All employees and agents working in roles that pose ML/TF risk must receive documented, role-appropriate training. Training should be repeated at appropriate intervals and records must be retained.

6. Reporting Procedures

Procedures for identifying, assessing, and submitting SMRs (within 3 business days, or 24 hours for terrorism-financing suspicions) and, where applicable, TTRs for physical currency transfers of A$10,000 or more. Your procedures must also address tipping-off protections.

7. Record Keeping

Records must be retained for at least 7 years and be retrievable within a reasonable timeframe if requested by AUSTRAC.

8. Independent Evaluation

Your AML program must be independently evaluated at least every 3 years. AUSTRAC notes that newly enrolled entities may wish to conduct their first evaluation earlier.

AML Program vs KYC: What Is the Difference?

One of the most frequently searched questions in the lead-up to Tranche 2 is whether AML checks and an AML program are the same thing. They are not.

AML/CTF ChecksAML/CTF Program
Identity verification (KYC)Documented risk assessment
Sanctions/PEP screeningWritten policies approved by senior manager
Adverse media screeningAppointed compliance officer
One-time risk assessmentOngoing monitoring and periodic review
Point-in-time result7-year auditable record of all compliance activity
Can be outsourcedResponsibility cannot be transferred
May satisfy one component of CDDMust be in place before designated services commence

A tool that runs identity checks and screening covers the left column. A compliance platform that manages your AML program covers both columns.

Can I Outsource AML/CTF Functions?

You can outsource specific AML/CTF functions: such as identity verification, screening, or technology provision, to a third-party provider. However, outsourcing does not transfer your legal obligations. The reporting entity remains responsible for its AML/CTF compliance, including the quality and completeness of any work performed by a third party on its behalf.

This means that if an outsourced provider makes an error or fails to meet the required standard, you are still accountable. Your AML program should document how outsourced functions are managed, monitored, and quality-assured.

Buying a compliance tool does not, by itself, make your business compliant. The tool may perform checks, but the obligation to have a program, assess risk, train staff, and report suspicious matters remains with your business.

Can I Use AUSTRAC’s Starter Kit?

AUSTRAC has published a program starter kit for small real estate and buyer’s agencies. The starter kit is intended for businesses that satisfy specific suitability criteria. The published criteria are more detailed than can be summarised briefly here, and include requirements around designated service scope, personnel count, customer mix, geographic focus, delivery model, and business structure. Consult the starter kit directly to confirm whether it is appropriate for your business.

Larger, more complex, or less standardised businesses should not assume the starter kit will be sufficient and should assess the published suitability criteria carefully.

What Happens If You Do Not Have a Program?

AUSTRAC has broad enforcement powers, and the Federal Court may order significant civil penalties in serious cases, up to 20,000 penalty units for an individual and 100,000 penalty units for a body corporate. AUSTRAC’s enforcement toolkit also includes infringement notices, enforceable undertakings, and remedial directions.

Beyond formal penalties, operating without an AML/CTF program means you have no documented basis for your compliance decisions, no evidence to demonstrate due diligence, and no structured way to respond to an AUSTRAC audit.

See How AML Guard Works

AML Guard covers the full AML/CTF program lifecycle, from CDD case management and identity verification to beneficial ownership tracing, risk scoring, program governance, AUSTRAC reporting, and CRM integration.
Book a 20-minute demo.

Book a Demo

Related Reading

This article is for general information purposes only and does not constitute legal or compliance advice. The information reflects current AUSTRAC reform guidance as at the date of publication. Firms should obtain independent professional advice on their specific AML/CTF obligations.