Search this phrase and most results explain building inspections, title searches, and planning checks. This article covers something different: the AML/CTF customer due diligence that reporting entities must run on buyers under Australian law. Initial CDD must ordinarily be complete before you provide a designated service, and it starts the moment you’re instructed, not at contract or settlement. The core actions are identify the customer and anyone acting on their behalf, verify their identity and beneficial ownership, screen for sanctions and PEP exposure, and assign and record an ML/TF risk rating.
TL;DR:
- Customer due diligence must be completed before providing a designated service, starting from the moment instructions are received, not at contract exchange.
- Verifying beneficial ownership requires tracing until natural persons with at least 25% ownership or control are identified, often needing multiple document requests.
- Occasional delays in verification are permitted, such as during an auction, but must be documented and resolved promptly once the buyer is known.
- High‑risk scenarios like offshore ownership or unusual fund transfers trigger enhanced due diligence, including sourcing proof for funds and detailed ownership documentation.
- Implementing a strict onboarding process, with signed-off CDD steps and robust recordkeeping, is vital to meet AUSTRAC compliance and withstand audits.
Table of Contents
- What buyer customer due diligence means under the AML/CTF regime
- Onboarding checklist: what to collect the moment you’re instructed
- How to conduct due diligence: the five-step CDD process
- Timing, delays, and what your records need to show
- When to escalate: enhanced CDD and source of funds
- Turning CDD obligations into working systems
- The onboarding gap that catches most agencies out
- Where AML Guard fits into your buyer CDD workflow
- Primary sources to check before you finalise a policy
- Sources
What buyer customer due diligence means under the AML/CTF regime
From 1 July 2026, real estate agents and developers providing designated services became reporting entities under the AML/CTF regime, obliged to apply customer due diligence to buyers and sellers wherever that designated service applies. That’s a distinct obligation from a purchaser’s own property investment due diligence, which covers structural condition, zoning, and encumbrances on title. This article is entirely about the compliance side: who your customer actually is, what you must verify about them, and what AUSTRAC expects you to have on file if it ever asks.
Get the “who is my customer” question wrong and everything downstream is wrong too. An agent instructed by a vendor has the vendor as its customer for that designated service and must conduct CDD on the vendor, not the buyer. A buyer’s agent instructed by a purchaser has the purchaser as its customer. Your obligations toward the other party in the transaction depend on the specific designated service you’re providing at the time, not on a blanket assumption that “the buyer always gets checked.”
Onboarding checklist: what to collect the moment you’re instructed
Property transaction CDD begins the day someone gives you instructions, not the day contracts exchange. Build this into your onboarding workflow as a hard gate.
- Confirm who your customer is for this specific engagement, based on who instructed you and which designated service you’re providing.
- Collect minimum KYC for individuals: full name, date of birth, residential address, and contact details.
- For entities, capture the ACN, constitution or trust deed, and details of any corporate trustee.
- Gather evidence of authority for anyone acting on the customer’s behalf, including powers of attorney.
- Run an initial sanctions and PEP screen, and flag early risk indicators such as offshore ownership, cash offers, or requests for rapid onward transfer of funds.
- Where verification can’t be completed immediately (an auction sale, for instance), record the exception and set a firm deadline to close it out.
Pro Tip: Treat instruction, not contract signing, as your compliance start date. Firms that wait until exchange routinely discover gaps they can’t retrospectively fix.
How to conduct due diligence: the five-step CDD process
Once you know who your customer is, the process itself follows a fixed sequence. Skipping steps, or doing them out of order, is what turns a routine file into an audit problem.
- Confirm the customer and any person acting on their behalf. Collect the KYC information proportionate to the transaction’s risk, whether that’s an individual purchaser or a company director signing on behalf of the entity.
- Resolve beneficial ownership for any non‑individual customer. Trace corporate trustees, shareholding companies, and trust structures through to the natural persons standing behind them. Document each link in the chain and require sign‑off from your AML/CTF compliance officer before the file proceeds.
- Verify identity using reliable, independent data. Document capture and biometric liveness checks are appropriate for higher‑risk files; simpler verification may suffice for straightforward, low‑risk individual buyers.
- Screen for sanctions and politically exposed persons, and decide at this point whether the file warrants enhanced due diligence.
- Record the ML/TF risk rating and the reasoning behind it. AUSTRAC expects documented justification for a low‑risk decision just as much as for an escalation.
Beneficial ownership isn’t optional paperwork. Reporting entities must trace ownership and control chains until they reach the natural persons who ultimately own 25% or more, or control the entity. Naming “Trustee of the Smith Family Trust” as the beneficial owner and stopping there fails this test outright. The tracing has to continue to the actual people who benefit from or control the trust.
For companies with layered shareholding, this can mean several rounds of document requests before you reach a natural person. Build that lead time into your file timelines now, rather than discovering it during a tight settlement window. A structured beneficial ownership tracing process built around the 25% threshold, with officer approval recorded at each resolution, is what turns this from guesswork into a defensible file.
Timing, delays, and what your records need to show
Initial CDD ordinarily must be complete before you provide the designated service, and the clock starts at instruction. That’s the rule AUSTRAC sets out for reporting entities generally, and real estate has no special carve‑out.
Delayed verification is permitted in limited circumstances, an auction sale where the successful bidder is unknown until the fall of the hammer is the classic example, but the exception has to be documented, time‑bound, and closed out promptly once the buyer is known.
Your recordkeeping needs to survive scrutiny years after the file closes:
- Retain CDD records for a period consistent with legal recordkeeping requirements, including the reasoning behind each risk decision, not just the final rating.
- Use a tamper‑evident digital system rather than shared spreadsheets or email trails.
- Log who approved each beneficial‑owner determination, what evidence they relied on, and when.
When to escalate: enhanced CDD and source of funds
Some buyers warrant more than the standard checklist. High‑value purchases, opaque or multi‑layered ownership structures, foreign PEPs, and unusual payment routing (third‑party payers, offshore transfers, structured deposits) are the common triggers for enhanced CDD.
- Request bank statements covering the source funds, not just proof they exist in an account today.
- For proceeds of an asset sale, obtain settlement statements or transfer documents showing the chain from sale to purchase.
- Where finance is involved, sight loan approval documentation rather than accepting a verbal assurance.
- Scale the depth of proof to the risk: a routine domestic purchase doesn’t need the same paper trail as a high‑value cash purchase by an offshore entity.
Pro Tip: If the source‑of‑funds explanation doesn’t match the buyer’s known profile, don’t just ask for more paperwork; document the mismatch and assess whether it triggers a suspicious matter report under section 41.
Turning CDD obligations into working systems
Legal obligations only hold up if they’re mapped to roles, approvals, and systems your staff actually use day to day.
- Assign clear responsibility: who collects documents, who verifies identity, and who, specifically your AML/CTF compliance officer, approves each beneficial‑owner determination.
- Record every risk score with its reasoning in a tamper‑evident log, so an AUSTRAC review finds a complete trail rather than a gap.
- Push only compliance status flags into your CRM (a “cleared” or “pending” indicator against a listing), never the underlying CDD evidence itself.
- Where appropriate, let the transaction party cover their own verification fee through a client‑pays option, rather than the firm absorbing every check.
- Produce the four supporting artefacts every Tranche 2 reporting entity needs: an ML/TF risk assessment, AML/CTF policies, a compliance action plan, and a staff training manual.
| Compliance artefact | What it captures |
|---|---|
| ML/TF risk assessment | Business‑wide exposure to money laundering, terrorism financing, and proliferation financing |
| AML/CTF policies | Procedures for CDD, enhanced CDD, and reporting obligations |
| Compliance action plan | Scheduled tasks, reviews, and remediation items |
| Staff training manual | Role‑specific guidance and completion records |
The onboarding gap that catches most agencies out
I’ve seen the same failure pattern repeat across firms of every size: CDD gets treated as a contract‑stage task, something that happens once terms are agreed rather than the moment instructions land. By then, the file is already exposed, and unpicking it after the fact is far harder than doing it right the first time.
The fix isn’t complicated. Make CDD a mandatory onboarding gate with named officer sign‑off before any file progresses, and record the reasoning behind every decision, not just the outcome. That single habit is what separates a file that survives an AUSTRAC review from one that doesn’t.
Where AML Guard fits into your buyer CDD workflow
AML Guard is built for exactly the workflow described above, not as a generic identity checker bolted onto a real estate CRM, but as the compliance layer that runs the whole obligation.

Identity verification with document capture and biometric liveness, beneficial ownership tracing run against a company’s ACN, and sanctions and PEP screening with ongoing re‑screening are handled end to end, with an officer approving each beneficial‑owner determination before a file proceeds. Risk scoring is recorded with its reasoning, not just a final number, and the platform’s REX integration pushes only a compliance status flag against a listing, never the underlying CDD detail. A client‑pays option lets the buyer or vendor cover their own verification fee. If your agency, conveyancing practice, or law firm needs a system that turns customer due diligence into a repeatable, audit‑ready process rather than a file‑by‑file scramble, book a demo with AML Guard and see how your existing workflow maps onto it.
Primary sources to check before you finalise a policy

Don’t take secondary summaries, including this one, as the final word on your obligations. Start with AUSTRAC’s own guidance on real estate designated services and its overview of initial customer due diligence, then read the legislation itself: the Anti‑Money Laundering and Counter‑Terrorism Financing Act 2006 (Cth) sets the legal framework, and the AML/CTF Rules 2025 fill in the operational detail on simplified and enhanced measures. A printable readiness checklist can help you confirm nothing’s been missed before your next file lands.
Sources
Recommended
- Tranche 2 customer due diligence in Australia
- Beneficial Ownership in Property Transactions: How to Trace UBOs Under Tranche 2
- AML/CTF Compliance Checklist for Real Estate Agents: What You Need Before 1 July 2026
- AML risk assessment template for Tranche 2 firms
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.