AML risk assessment for real estate agencies

AML risk assessment for real estate agencies

What section 26C actually requires across its four categories, the property red flags that matter, and how to evidence the work you have done.

AML/CTF Compliance 19 September 2026 11 min read AML Guard

Real estate compliance risk assessment materials

An Australian real estate agency’s AML risk assessment must be a documented, business-wide evaluation of money laundering, terrorism financing and proliferation financing risk, built around the four categories in section 26C of the AML/CTF Act 2006 (Cth): customers, designated services, delivery channels and jurisdictions. It has to sit alongside matching AML/CTF policies, both required under the AML/CTF Rules 2025. This guide walks through each category with property-specific scenarios, a step-by-step method, and the sources to record in your risk register.


TL;DR:


AML Guard
Build a Consistent AML/CTF Program
AML Guard links your risk assessment, policies, action plan and staff training, with due diligence and records in one Australian platform.
Book a demo

Table of Contents

What does an AML risk assessment for real estate actually require?

AUSTRAC treats real estate agencies as Tranche 2 reporting entities, meaning the same obligations that apply to banks and remitters now apply to sales, property management and buyers agency work. The core requirement is a documented AML/CTF program with two linked parts: a business-wide risk assessment of money laundering, terrorism financing and proliferation financing, and a set of AML/CTF policies built to respond to what that assessment finds.

AUSTRAC publishes a real estate program starter kit specifically for this sector. It sets out the building blocks. A generic template is not enough on its own; you need to customise it against your agency’s own services, customer base and geographic footprint, then keep evidence of that customisation. Enrolment with AUSTRAC and ongoing reporting obligations flow from this program, and every decision you make setting it up belongs in a risk register with a date and a reason attached.

How does section 26C apply to property transactions?

Section 26C exists because a generic “we assess risk” statement tells an auditor nothing. AUSTRAC wants to see the assessment broken into four categories, each with reasoning specific to your agency.

Customers. Vendors and purchasers carry different risk profiles, and both differ again from corporate or trust buyers, where you need to trace the beneficial owner through the entity’s ACN via ASIC Connect. Overseas purchasers add a further layer, since verifying identity and source of funds is harder when the customer has never set foot in Australia. Trusts and SMSFs are resolved through their corporate trustee, which runs its own ACN-based determination rather than a document check on the deed alone.

Designated services. Sales, property management, buyers agency and off-the-plan work don’t carry the same risk. A single high-value cash sale carries different exposure to a long-running property management arrangement or a buyers agent acting for an undisclosed principal.

Delivery channels. In-person onboarding lets you sight identity documents directly. Remote onboarding, transactions run through a buyers agent, and auction sales all reduce the direct contact you have with the actual purchaser, and each needs its own control set to compensate.

Jurisdictions. Where do the funds come from, and where does the customer live or hold citizenship? Funds routed from a jurisdiction with weak AML controls, or a customer connected to a sanctioned or FATF-grey-listed country, lift the risk rating and should trigger enhanced due diligence, not just a note in the file.

How section 26C applies to a property transaction

What property-specific scenarios and red flags should you map?

Generic red flag lists don’t translate well to property. The scenarios that actually turn up in Australian real estate transactions look like this:

Proliferation financing is easy to overlook because it sounds like a banking problem, not a real estate one. In practice, it can surface through high-value property purchases linked to entities connected to restricted goods, sanctioned supply chains, or unusual layers of corporate structuring designed to obscure the ultimate purchaser, as AUSTRAC’s own risk insights for the sector note.

Pro Tip: Don’t file red flags as a static list. Attach each one to the specific designated service and customer type it relates to, so your controls and training modules reference the same scenario, not a generic version of it.

How do you complete and evidence the risk assessment step by step?

A risk assessment that exists only in someone’s head, or as a downloaded template nobody edited, fails an audit fast. AUSTRAC’s own guidance stresses active customisation and documented evidence over static paperwork. Five steps get you from a blank page to something an auditor can actually follow:

  1. Map your business profile. List every designated service you provide (sales, property management, buyers agency, off-the-plan) alongside the delivery channels you use for each.
  2. Identify customer typologies. For every service, note the realistic customer types (vendor, purchaser, corporate buyer, overseas buyer) and pull a sample transaction for each.
  3. Score likelihood and consequence. Rate each identified risk, write down the reasoning in a sentence or two, and attach a sample evidence entry, not just a number on a scale.
  4. Capture AUSTRAC’s risk information. Reference the sector’s published risk insights directly in your register, with the date accessed and a short excerpt of what you took from it.
  5. Set controls and a review cadence. Assign monitoring rules to each risk, set a review date, and require the AML/CTF compliance officer to sign off before the assessment is treated as final.

An AML risk assessment template built for Tranche 2 firms can shortcut the formatting, but the reasoning in steps 3 and 4 still has to be your agency’s own.

How do you turn the risk assessment into policies and training?

A risk assessment that doesn’t map cleanly onto your policies is the single most common gap AUSTRAC flags. If your assessment rates overseas purchasers as elevated risk, your policy needs a specific enhanced due diligence procedure for that customer type, not a general statement that “extra checks may apply.”

Guidance on AML training for real estate agencies can help structure this, but the content still has to trace back to your own assessment, not a generic property compliance course.

What records do you need, and for how long?

Auditors don’t just want to see the finished risk assessment. They want to see the paper trail behind it: the risk assessment itself, the risk register, every policy version with change dates, CDD and ECDD files for individual transactions, training logs, and copies of any reports filed with AUSTRAC.

The legal minimum retention period under the Act is a period of several years, commonly at least seven years. Many firms now build for eight, since a tamper-evident audit trail that outlasts the legal floor gives you a buffer against disputes or delayed reviews. Whichever period you commit to, present records the same way every time: cross-referenced folders, clear version history, signed approvals attached to each policy change, and an evidence index that lets an auditor move from a claim in the risk assessment to the document that backs it, without you standing over their shoulder explaining where things are filed.

How can a compliance platform operationalise this assessment?

Writing the assessment is one job. Keeping it consistent with your policies, your training manual and your day-to-day CDD checks is another, and it’s the part most agencies underestimate. AML Guard was built for Australian Tranche 2 reporting entities to close that gap, generating the business-wide risk assessment, AML/CTF policies, compliance action plan and staff training manual as one linked set, drawn from the same underlying answers so the documents don’t drift apart from each other.

On the customer due diligence side, the platform runs:

Every determination still requires sign-off from your named AML/CTF compliance officer before it proceeds. This is one operational route among several, not the only way to meet the obligation.

Why most agencies get this backwards

The conventional advice treats the risk assessment as a compliance document to file once and revisit only if AUSTRAC comes knocking. That gets the priority wrong. The assessment is the thing every other artefact has to agree with, and most of the audit failures in this sector trace back to a policy or training module that quietly drifted away from what the risk assessment actually said.

Where agencies get the risk assessment backwards

The other consistent gap is proliferation financing. It reads as a nuclear-proliferation problem for banks, not a property problem, so agencies leave it out or write a single throwaway sentence about it. That’s a mistake AUSTRAC’s own guidance doesn’t excuse, and it’s one of the first things a reviewer checks for precisely because it’s so often missing.

Start with the four categories, and be honest about which of your customer types and delivery channels genuinely carry elevated risk rather than rating everything as “low” to get the document finished faster. A risk assessment that rates every customer the same way isn’t a risk assessment. It’s a formality wearing the shape of one, and AUSTRAC’s reviewers have seen enough of them to spot the difference immediately.

Get your risk assessment and policies working as one system

Some compliance platforms generate the risk assessment, policy document and training manual as an integrated set from the same guided workflow, helping ensure consistency across these artefacts as required for an AUSTRAC review.

The platform suits real estate agencies, buyers agents and property developers who need customer due diligence, beneficial ownership tracing and an audit-ready record set without building each piece from scratch. Approvals still sit with your named compliance officer; AML Guard handles the lookups, screening and record-keeping underneath that decision. Plans include Standard Individual, High-Risk Individual and Company/Trust services alongside the core platform subscription, with pricing available on the pricing page. If you want to see how your own designated services and customer base would map onto the platform, book a demo and get your tenant configured to your agency’s actual risk profile.

Sources

FAQ

What are the AML obligations for real estate agents in Australia?

Real estate agencies are Tranche 2 reporting entities under the AML/CTF Act 2006 (Cth), which means they must hold a documented business-wide ML/TF/PF risk assessment and matching AML/CTF policies. AUSTRAC’s obligations and guidance hub sets out enrolment, customer due diligence and reporting requirements specific to the sector.

What are the new AML rules in Australia?

The AML/CTF Rules 2025 extended reporting entity status to real estate agents, lawyers, accountants, and trust and company service providers, requiring the same risk-based program structure long applied to banks. The obligation centres on a section 26C risk assessment covering customers, designated services, delivery channels and jurisdictions, backed by policies and staff training.

What is the best AML software for real estate agents in Australia?

The right platform depends on how much of the workflow you want automated versus handled manually. AML Guard is built specifically for Australian Tranche 2 entities, generating the risk assessment, policies, compliance action plan and training manual from one linked data set, with CDD, screening and beneficial ownership tracing built in.

Yes. Real estate agencies fall within the designated services covered by the AML/CTF Act 2006 (Cth), and failing to hold a documented risk assessment and policies is a breach of that obligation, not an optional best practice. Records supporting the assessment must be retained for a minimum of seven years under the Act.

How often should a real estate agency reassess its AML risk?

There’s no single fixed interval set in legislation, but a risk assessment should be reviewed whenever your services, customer base or delivery channels change materially, and at a minimum on a regular cycle set by your compliance officer. Building a review date into the risk register at the point of each assessment keeps this from slipping.

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 19 September 2026.