
An Australian real estate agency’s AML risk assessment must be a documented, business-wide evaluation of money laundering, terrorism financing and proliferation financing risk, built around the four categories in section 26C of the AML/CTF Act 2006 (Cth): customers, designated services, delivery channels and jurisdictions. It has to sit alongside matching AML/CTF policies, both required under the AML/CTF Rules 2025. This guide walks through each category with property-specific scenarios, a step-by-step method, and the sources to record in your risk register.
TL;DR:
- Most real estate transactions involving overseas purchasers or corporate buyers should trigger enhanced due diligence due to difficulty verifying source of funds and beneficial ownership.
- High-value cash purchases with vague explanations or complex layered corporate ownership are key red flags to map specifically to your assessed risk categories.
- Regularly updating and documenting your risk assessment across four categories and aligning it with policies and training is essential for audit readiness.
- The minimum record retention period is seven years, and a tamper-evident audit trail is what makes those records defensible when a supervisor asks.
- Using an integrated compliance platform helps automate risk assessments, screening, policies, and training, reducing the risk of divergence and audit failure.
Table of Contents
- What does an AML risk assessment for real estate actually require?
- How does section 26C apply to property transactions?
- What property-specific scenarios and red flags should you map?
- How do you complete and evidence the risk assessment step by step?
- How do you turn the risk assessment into policies and training?
- What records do you need, and for how long?
- How can a compliance platform operationalise this assessment?
- Why most agencies get this backwards
- Get your risk assessment and policies working as one system
- Sources
- FAQ
What does an AML risk assessment for real estate actually require?
AUSTRAC treats real estate agencies as Tranche 2 reporting entities, meaning the same obligations that apply to banks and remitters now apply to sales, property management and buyers agency work. The core requirement is a documented AML/CTF program with two linked parts: a business-wide risk assessment of money laundering, terrorism financing and proliferation financing, and a set of AML/CTF policies built to respond to what that assessment finds.
AUSTRAC publishes a real estate program starter kit specifically for this sector. It sets out the building blocks. A generic template is not enough on its own; you need to customise it against your agency’s own services, customer base and geographic footprint, then keep evidence of that customisation. Enrolment with AUSTRAC and ongoing reporting obligations flow from this program, and every decision you make setting it up belongs in a risk register with a date and a reason attached.
How does section 26C apply to property transactions?
Section 26C exists because a generic “we assess risk” statement tells an auditor nothing. AUSTRAC wants to see the assessment broken into four categories, each with reasoning specific to your agency.
Customers. Vendors and purchasers carry different risk profiles, and both differ again from corporate or trust buyers, where you need to trace the beneficial owner through the entity’s ACN via ASIC Connect. Overseas purchasers add a further layer, since verifying identity and source of funds is harder when the customer has never set foot in Australia. Trusts and SMSFs are resolved through their corporate trustee, which runs its own ACN-based determination rather than a document check on the deed alone.
Designated services. Sales, property management, buyers agency and off-the-plan work don’t carry the same risk. A single high-value cash sale carries different exposure to a long-running property management arrangement or a buyers agent acting for an undisclosed principal.
Delivery channels. In-person onboarding lets you sight identity documents directly. Remote onboarding, transactions run through a buyers agent, and auction sales all reduce the direct contact you have with the actual purchaser, and each needs its own control set to compensate.
Jurisdictions. Where do the funds come from, and where does the customer live or hold citizenship? Funds routed from a jurisdiction with weak AML controls, or a customer connected to a sanctioned or FATF-grey-listed country, lift the risk rating and should trigger enhanced due diligence, not just a note in the file.

What property-specific scenarios and red flags should you map?
Generic red flag lists don’t translate well to property. The scenarios that actually turn up in Australian real estate transactions look like this:
- A purchaser offers a substantial cash deposit with a vague or shifting explanation of where the money came from.
- A corporate buyer has layered ownership through multiple entities, or lists a nominee director with no clear connection to the underlying business, making beneficial ownership tracing through the corporate trustee essential rather than optional.
- An overseas purchaser remits funds from a jurisdiction flagged for weak AML controls or sanctions exposure, often through intermediary accounts that obscure the original source.
- An off-the-plan developer structures payments in unusual instalments, or receives deposits from parties with no apparent connection to the eventual buyer.
Proliferation financing is easy to overlook because it sounds like a banking problem, not a real estate one. In practice, it can surface through high-value property purchases linked to entities connected to restricted goods, sanctioned supply chains, or unusual layers of corporate structuring designed to obscure the ultimate purchaser, as AUSTRAC’s own risk insights for the sector note.
Pro Tip: Don’t file red flags as a static list. Attach each one to the specific designated service and customer type it relates to, so your controls and training modules reference the same scenario, not a generic version of it.
How do you complete and evidence the risk assessment step by step?
A risk assessment that exists only in someone’s head, or as a downloaded template nobody edited, fails an audit fast. AUSTRAC’s own guidance stresses active customisation and documented evidence over static paperwork. Five steps get you from a blank page to something an auditor can actually follow:
- Map your business profile. List every designated service you provide (sales, property management, buyers agency, off-the-plan) alongside the delivery channels you use for each.
- Identify customer typologies. For every service, note the realistic customer types (vendor, purchaser, corporate buyer, overseas buyer) and pull a sample transaction for each.
- Score likelihood and consequence. Rate each identified risk, write down the reasoning in a sentence or two, and attach a sample evidence entry, not just a number on a scale.
- Capture AUSTRAC’s risk information. Reference the sector’s published risk insights directly in your register, with the date accessed and a short excerpt of what you took from it.
- Set controls and a review cadence. Assign monitoring rules to each risk, set a review date, and require the AML/CTF compliance officer to sign off before the assessment is treated as final.
An AML risk assessment template built for Tranche 2 firms can shortcut the formatting, but the reasoning in steps 3 and 4 still has to be your agency’s own.
How do you turn the risk assessment into policies and training?
A risk assessment that doesn’t map cleanly onto your policies is the single most common gap AUSTRAC flags. If your assessment rates overseas purchasers as elevated risk, your policy needs a specific enhanced due diligence procedure for that customer type, not a general statement that “extra checks may apply.”
- Map every assessed risk to a specific customer due diligence or enhanced due diligence procedure, naming the trigger that activates it.
- Set escalation thresholds for suspicious matter reports and threshold transaction reports, with a named sign-off point at each stage.
- Build training modules that reference the same policy clauses word for word, and keep completion records that show which staff member finished which module and when.
Guidance on AML training for real estate agencies can help structure this, but the content still has to trace back to your own assessment, not a generic property compliance course.
What records do you need, and for how long?
Auditors don’t just want to see the finished risk assessment. They want to see the paper trail behind it: the risk assessment itself, the risk register, every policy version with change dates, CDD and ECDD files for individual transactions, training logs, and copies of any reports filed with AUSTRAC.
The legal minimum retention period under the Act is a period of several years, commonly at least seven years. Many firms now build for eight, since a tamper-evident audit trail that outlasts the legal floor gives you a buffer against disputes or delayed reviews. Whichever period you commit to, present records the same way every time: cross-referenced folders, clear version history, signed approvals attached to each policy change, and an evidence index that lets an auditor move from a claim in the risk assessment to the document that backs it, without you standing over their shoulder explaining where things are filed.
How can a compliance platform operationalise this assessment?
Writing the assessment is one job. Keeping it consistent with your policies, your training manual and your day-to-day CDD checks is another, and it’s the part most agencies underestimate. AML Guard was built for Australian Tranche 2 reporting entities to close that gap, generating the business-wide risk assessment, AML/CTF policies, compliance action plan and staff training manual as one linked set, drawn from the same underlying answers so the documents don’t drift apart from each other.
On the customer due diligence side, the platform runs:
- Identity verification with document capture and biometric liveness checks.
- Sanctions, PEP and adverse media screening, with ongoing re-screening rather than a one-off check.
- Beneficial ownership determination by ACN, with trusts and SMSFs reached through their corporate trustee’s own determination.
- An 8-year tamper-evident audit trail, REX CRM status integration, and a client-pays option for verification fees.
Every determination still requires sign-off from your named AML/CTF compliance officer before it proceeds. This is one operational route among several, not the only way to meet the obligation.
Why most agencies get this backwards
The conventional advice treats the risk assessment as a compliance document to file once and revisit only if AUSTRAC comes knocking. That gets the priority wrong. The assessment is the thing every other artefact has to agree with, and most of the audit failures in this sector trace back to a policy or training module that quietly drifted away from what the risk assessment actually said.

The other consistent gap is proliferation financing. It reads as a nuclear-proliferation problem for banks, not a property problem, so agencies leave it out or write a single throwaway sentence about it. That’s a mistake AUSTRAC’s own guidance doesn’t excuse, and it’s one of the first things a reviewer checks for precisely because it’s so often missing.
Start with the four categories, and be honest about which of your customer types and delivery channels genuinely carry elevated risk rather than rating everything as “low” to get the document finished faster. A risk assessment that rates every customer the same way isn’t a risk assessment. It’s a formality wearing the shape of one, and AUSTRAC’s reviewers have seen enough of them to spot the difference immediately.
Get your risk assessment and policies working as one system
Some compliance platforms generate the risk assessment, policy document and training manual as an integrated set from the same guided workflow, helping ensure consistency across these artefacts as required for an AUSTRAC review.
The platform suits real estate agencies, buyers agents and property developers who need customer due diligence, beneficial ownership tracing and an audit-ready record set without building each piece from scratch. Approvals still sit with your named compliance officer; AML Guard handles the lookups, screening and record-keeping underneath that decision. Plans include Standard Individual, High-Risk Individual and Company/Trust services alongside the core platform subscription, with pricing available on the pricing page. If you want to see how your own designated services and customer base would map onto the platform, book a demo and get your tenant configured to your agency’s actual risk profile.
Sources
- Obligations and guidance | AUSTRAC
- AML/CTF Rules 2025 | Federal Register of Legislation
- About sanctions | DFAT
FAQ
What are the AML obligations for real estate agents in Australia?
Real estate agencies are Tranche 2 reporting entities under the AML/CTF Act 2006 (Cth), which means they must hold a documented business-wide ML/TF/PF risk assessment and matching AML/CTF policies. AUSTRAC’s obligations and guidance hub sets out enrolment, customer due diligence and reporting requirements specific to the sector.
What are the new AML rules in Australia?
The AML/CTF Rules 2025 extended reporting entity status to real estate agents, lawyers, accountants, and trust and company service providers, requiring the same risk-based program structure long applied to banks. The obligation centres on a section 26C risk assessment covering customers, designated services, delivery channels and jurisdictions, backed by policies and staff training.
What is the best AML software for real estate agents in Australia?
The right platform depends on how much of the workflow you want automated versus handled manually. AML Guard is built specifically for Australian Tranche 2 entities, generating the risk assessment, policies, compliance action plan and training manual from one linked data set, with CDD, screening and beneficial ownership tracing built in.
Is AML compliance a legal requirement for real estate agents?
Yes. Real estate agencies fall within the designated services covered by the AML/CTF Act 2006 (Cth), and failing to hold a documented risk assessment and policies is a breach of that obligation, not an optional best practice. Records supporting the assessment must be retained for a minimum of seven years under the Act.
How often should a real estate agency reassess its AML risk?
There’s no single fixed interval set in legislation, but a risk assessment should be reviewed whenever your services, customer base or delivery channels change materially, and at a minimum on a regular cycle set by your compliance officer. Building a review date into the risk register at the point of each assessment keeps this from slipping.
Recommended
- AML/CTF Compliance Checklist for Real Estate Agents: What You Need Before 1 July 2026
- AML training real estate: what agencies must do
- AML risk scoring that stands up to AUSTRAC
- AML risk assessment template for Tranche 2 firms
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.