Off-the-plan sales and AML: the settlement gap

Off-the-plan sales and AML: the settlement gap

When developers selling direct are captured, who the customer is, and why ongoing CDD across the deposit-to-settlement gap decides the real risk.

AML/CTF Compliance 21 September 2026 12 min read AML Guard

Unfinished apartment development at dawn

Selling off-the-plan as part of a business, without a genuinely independent agent, makes you a reporting entity under the AML/CTF Act. That triggers AUSTRAC enrolment and a full AML/CTF program. The operational priority is not the identity check at contract signing. It is making sure that check is still valid when settlement finally happens, often years later, and that any nomination or assignment along the way gets re-verified before title changes hands.


TL;DR:


AML Guard
Keep Off-the-Plan Checks Moving
AML Guard connects ongoing due diligence, risk records and reporting workflows for Australian property developers and real estate agencies.
Book a demo

Table of Contents

Who is captured: designated services and off-the-plan sales

The AML/CTF Act defines a set of designated services that trigger reporting entity status, and real estate has its own category. From 1 July 2026, selling or transferring real estate in the course of a business without an independent agent is a designated service. That single clause pulls a lot of developer activity into scope that many assume belongs to their selling agent.

In-house sales teams selling apartments off-the-plan, house-and-land package sellers running their own display suites, and developers transferring title directly to buyers all sit inside this test. The question is not whether a licensed agent exists somewhere in the transaction chain. It is whether the agent is genuinely independent of the developer or is effectively an extension of the developer’s own sales function.

Ask these questions to work out where you sit:

Developers using special purpose vehicles for individual projects should also check whether their obligations sit at the SPV level or roll up to a reporting group. Related entities selling under common ownership or control can often centralise their AML/CTF program rather than duplicating it project by project, but that structure needs to be deliberate, not assumed.

Enrolment, timing and governance obligations for Tranche 2 entities

Once you have established that you provide a designated service with a connection to Australia, enrolment with AUSTRAC is not optional and should not wait until a sale is already underway. The practical sequence looks like this:

  1. Enrol with AUSTRAC as soon as you identify that you provide a designated service, ahead of your first off-the-plan transaction.
  2. Build the business-wide risk assessment and AML/CTF policies, since the program must contain both, with senior management approval and governing body oversight.
  3. Appoint an AML/CTF compliance officer with the authority and time allocation to actually run the program, not a title added to an existing job description.
  4. Confirm reporting group structure where multiple related entities sell project stock, so program obligations, risk assessments and reporting are centralised rather than fragmented.

The governing body’s oversight role matters here. A risk assessment signed off once by a compliance officer and never reviewed by the board or directors will not hold up under scrutiny, particularly for a developer running several concurrent projects with different risk profiles.

Customer due diligence for off-the-plan deals: initial CDD and the re-verification workflow

Standard CDD guidance assumes a transaction closes in weeks. Off-the-plan sales do not work that way. Initial CDD is usually required before providing a designated service, with ongoing CDD applied throughout the relationship. The relationship, in an off-the-plan context, can run two, three, sometimes four years from contract to settlement.

That gap is the entire problem. A buyer verified at exchange of contracts may not be the same risk profile at settlement. Their beneficial ownership structure can change if a company or trust is involved. Their PEP status can shift with a change of role or a change of government overseas. Sanctions lists are updated regularly, and a name clear at contract signing is not guaranteed to stay clear. Long settlement windows and nomination or assignment clauses are a structural feature of off-the-plan contracts, and each of those clauses is a point where the identity of the ultimate buyer can change entirely.

The practical workflow needs to reconcile statutory timing with that reality:

For companies, run the beneficial ownership check against the company’s ACN. For trusts and self-managed super funds, the practical path is through the corporate trustee, which is checked on its own ACN, with the trust deed itself reviewed by a compliance officer rather than run through an automated lookup. Document every verification event, including the date, method and outcome, because a single file may need to show two or three separate rounds of CDD by the time settlement occurs.

Pro Tip: Build re-screening into your compliance calendar the day a contract is signed, not the week before settlement. A file that goes quiet for two years and gets rushed through checks at the last minute is exactly the pattern a supervisor will flag first.

Customer due diligence for off-the-plan deals: initial CDD and the re-verification workflow

Risk indicators and enhanced CDD for off-the-plan transactions

Certain patterns should push a file from standard to enhanced CDD immediately, and off-the-plan sales have a few that are specific to the product.

That last point deserves particular attention in off-the-plan deals, because assignment clauses are common and often legitimate. The risk is not the assignment itself, it is an assignment used to obscure the real buyer behind the original contract holder.

When these indicators appear, enhanced CDD should mean deeper source-of-funds analysis, independent legal verification of trust or corporate structures rather than accepting documents at face value, and senior manager approval with the reasoning recorded in the file. A one-line note saying “approved” is not a record; a paragraph explaining what was checked and why the risk was accepted is.

Reporting, record keeping and the cost of getting it wrong

Suspicious matter reports carry strict statutory timeframes: 24 hours where the suspicion relates to terrorism financing, and a longer window for other grounds for suspicion. In an off-the-plan context, an SMR-worthy event might be a buyer refusing to explain the source of a deposit, an assignment to an unrelated party days before settlement, or a purchasing entity that suddenly changes structure with no commercial explanation.

Threshold transaction reports and other report types such as international funds transfer instructions or cross-border movement reports may also apply depending on how deposits and settlement funds move. AUSTRAC’s tranche 2 factsheet sets out enrolment timing, reporting obligations and record-keeping expectations in detail, and it is worth keeping on hand as a reference rather than a one-time read.

The number that matters most: records supporting your CDD, risk assessments and reporting must be kept for a minimum of seven years under the Act. That is a floor, not a target, and audit-ready evidence means being able to reconstruct exactly what was checked, when, and by whom.

Non-compliance exposure runs from civil penalties through to reputational damage that outlasts any individual transaction, particularly for developers relying on repeat buyers and referral networks.

Building the compliance program: artefacts, controls and workflow

An AML/CTF program is not a single document. It is four linked artefacts that need to tell the same story: the business-wide ML/TF risk assessment, the AML/CTF policies, a compliance action plan, and a staff training manual. When these are built separately, from different templates, at different times, they drift apart, and that drift is exactly what a supervisor will find first.

  1. Risk assessment first. Map your designated services, customer types, delivery channels and jurisdictions before writing a single policy.
  2. Policies that match the risk assessment. Every control in your policies should trace back to a risk identified in step one.
  3. A compliance action plan that assigns specific tasks, owners and deadlines, not general statements of intent.
  4. A training manual reflecting the same risk categories and control language used in the policies, so staff are trained on the program you actually run.

Operationally, the controls that matter for off-the-plan sales are identity verification with document and biometric checks at contract, sanctions and PEP screening with scheduled re-screening through the settlement period, an officer approval gate before funds release or title transfer, and a tamper-evident record of every check performed.

Picture a single unit sale: CDD runs at contract signing, re-screening fires automatically at set intervals, an assignment six months before completion triggers a fresh verification cycle, and an officer signs off the file the week before settlement based on current, not historical, screening results. That sequence, repeated consistently across every unit in a project, is what turns a policy document into an actual control.

Pro Tip: If your sales team is also fielding compliance questions mid-negotiation, friction goes up and so does the temptation to cut corners. A client-pays verification option, where the transaction party funds their own check, keeps the process moving without your compliance officer becoming a bottleneck.

Integration with the CRM systems your sales team already uses, such as REX, reduces the chance that a compliance status gets missed because it lived in a separate system nobody checked before settlement day.

Why ongoing CDD, not initial CDD, decides your risk

The industry still talks about AML/CTF compliance as if it were a gate at the front door: check the buyer, tick the box, move on. That framing works for an established-property sale that settles in six weeks. It fails off-the-plan, where the gap between contract and settlement can run years and almost nothing about the buyer is guaranteed to stay the same.

Initial CDD is the easy part. Ongoing CDD, scheduled re-screening, and catching an assignment before it slips through as a paperwork formality, that is where real risk sits and where most files quietly go stale. Supervisors do not expect perfection. They expect evidence: a record that shows what was checked, when it was checked again, and who approved release of settlement funds. Review your standard off-the-plan contract today and work out where your re-verification triggers actually sit.

Where AML Guard fits into your off-the-plan compliance program

Off-the-plan risk sits in the gap between contract and settlement, and that is precisely where AML Guard is built to hold the line. Scheduled re-screening runs automatically through the life of a contract, so a file cannot go quiet for two years and surface as a problem only when settlement is imminent. Biometric identity verification and document checks handle initial CDD, ACN-based beneficial ownership determination covers company purchasers, and corporate trustee checks extend that same discipline to trusts and SMSFs.

Every re-screening event, officer approval and document check sits inside a tamper-evident audit trail retained beyond the legal minimum retention period of seven years. For sales teams running high volumes of off-the-plan contracts, REX CRM integration surfaces compliance status against a listing without duplicating data entry, and a client-pays option lets the purchasing party fund their own verification, credited back against your subscription. If your current process relies on a spreadsheet and a diary reminder to catch re-verification dates, it is worth considering how a structured workflow might handle it instead. Book a demo to see how the program artefacts and CDD controls apply to your project pipeline, or check current plans for Standard Individual, High-Risk Individual and Company/Trust verification.

Sources

For anything beyond general guidance, work directly from primary sources. AUSTRAC’s real estate designated services guidance sets the scope test, its program obligations page covers governance requirements, and the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 provide the underlying legal detail behind every CDD and policy requirement discussed above.

FAQ

What are the new AML rules in Australia for real estate?

From 1 July 2026, selling or transferring real estate as a business without an independent agent became a designated service under the AML/CTF Act, bringing developers, in-house sales teams and buyers agents into scope for enrolment, CDD and reporting obligations.

Does selling off-the-plan without an agent trigger AML obligations?

Yes. If a developer negotiates, receives deposits and interfaces with buyers directly, without a genuinely independent licensed agent, that activity is a designated service requiring AUSTRAC enrolment and a full AML/CTF program.

How often should a file be re-screened between contract and settlement?

There is no single mandated interval, but given that ongoing CDD must be applied throughout the relationship, scheduled re-screening at regular fixed intervals through a multi-year settlement period, plus event-driven checks on any nomination or assignment, is the recommended operational approach.

What is the best AML software for real estate agents in Australia?

The right platform depends on your transaction volume and structure, but a system purpose-built for Tranche 2 real estate obligations, covering CDD, ACN-based beneficial ownership checks, scheduled re-screening and audit-ready record-keeping, will fit off-the-plan sales better than a generic compliance tool. AML Guard is built specifically for this sector, with pricing for its Standard Individual, High-Risk Individual and Company/Trust services available on its pricing page.

How long do we need to keep AML/CTF records for off-the-plan sales?

The legal minimum is seven years from when the record was made or the transaction was completed, covering CDD documentation, risk assessments and reporting history. Given multi-year settlement periods, some off-the-plan files may need retention well beyond that point to cover the full transaction lifecycle.

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 21 September 2026.