
You need an AML/CTF program covering a business-wide risk assessment and policies, and you need to start customer due diligence at the point of instruction, not when contracts are signed. Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), overseen by AUSTRAC, this applies to every Australian real estate agent brokering property transactions. Get a compliance officer assigned, a risk assessment underway, and verified ID collection starting at instruction this week.
TL;DR:
- Customer due diligence must start immediately at instruction, with verification of ID and beneficial ownership before any marketing or transaction activity begins.
- A comprehensive AML/CTF program must include a risk assessment, tailored policies, ongoing monitoring, and record-keeping for at least seven years, linked to actual risks identified.
- The designated compliance officer is responsible for overseeing the program, signing off on CDD escalations, and maintaining reporting channels with AUSTRAC.
- Most compliance failures stem from procedural gaps, such as starting CDD too late, mishandling corporate structures, or inconsistent record-keeping across multiple branches.
- Automated platforms that integrate identity verification, screening, and reporting workflows help maintain a living, interconnected program and prevent fragmented compliance efforts.
Table of Contents
- What law applies, and which of your activities are covered
- When CDD starts and who your customer actually is
- What your AML/CTF program actually has to include
- Your first week: an ordered compliance checklist
- Where agents actually go wrong
- Why consistent systems beat disconnected paperwork
- Compliance as a business asset, not a burden
- Getting your program running with AML Guard
- Sources
- FAQ
What law applies, and which of your activities are covered
Your obligations sit in the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and the operative detail in the AML/CTF Rules 2025. AUSTRAC is the regulator that supervises and enforces both.
For most agents, the designated service is brokering the purchase, sale or transfer of real estate on behalf of a client. That is the trigger for your obligations, not every conversation you have with a member of the public. If you are engaged by a vendor to sell a property, the vendor is your customer for that engagement. Buyer’s agents have the buyer as their customer instead. Tranche 2 obligations for Australian real estate and buyer’s agents apply the moment you broker a purchase, sale or transfer of real estate. There is no grace period to wait out.

When CDD starts and who your customer actually is
Customer due diligence generally commences at the point of instruction and should be completed before you provide the designated service. Waiting until exchange or settlement is too late. It also means the person you verify depends entirely on who has engaged you, not on who happens to be the other party to the deal.
Three scenarios cover most of what agents encounter:
- Vendor instruction (sales agency): the vendor is your customer. You identify and verify the vendor, and where relevant, the beneficial owners behind any corporate or trust seller, before marketing begins.
- Buyer engagement (buyer’s agent): the buyer is your customer. CDD starts when they engage you to search or negotiate, not when an offer is accepted.
- Property management (tenancy onboarding): the obligations differ from sales work and hinge on which designated service you’re actually providing and to whom. Treat this separately in your program rather than folding it into your sales CDD process.
You can rely on CDD another party has already conducted in limited circumstances, but reliance never shifts accountability away from your agency. If a salesperson under your licence carries out the verification, the principal remains responsible for whether it was done properly.
What your AML/CTF program actually has to include
An AML/CTF program is not a single document. It is a linked set of components that each do a specific job, and AUSTRAC expects them to work together rather than sit as separate paperwork exercises.
- Business-wide ML/TF risk assessment. Required under section 26C of the Act, this must cover money laundering, terrorism financing, and proliferation financing risk across your client base, property types, and the geographies you operate in.
- Policies and processes. These flow directly from the risk assessment and set out how you conduct CDD, when you escalate to enhanced due diligence, how you check beneficial ownership, and how you monitor customers on an ongoing basis.
- Reporting workflows. You need a clear process for lodging a suspicious matter report under section 41 when something doesn’t add up, plus threshold transaction reporting where it applies.
- Record-keeping and training. Records must be kept for seven years in a form that can withstand scrutiny, and staff training has to be tied to the actual policies your agency runs, not a generic module.
Pro Tip: Treat your risk assessment as the source document. If your policies, training manual, and reporting workflow don’t all trace back to the same risk findings, a supervisor will spot the mismatch immediately.
Your first week: an ordered compliance checklist
Turning the program components into action starts with clear ownership. Someone in your agency has to be the AML/CTF compliance officer, and that role needs teeth, not just a title.
- Confirm your compliance officer. Their three immediate duties: oversee the risk assessment, sign off on CDD escalations, and own the reporting relationship with AUSTRAC.
- Run or refresh your risk assessment. Map your existing controls against the risks you’ve actually identified, not a generic industry list.
- Start CDD at instruction. Collect and verify photo ID and proof of address at the outset, and escalate to enhanced due diligence for politically exposed persons, complex ownership structures, or unusual funding sources.
- Build your screening and reporting infrastructure, covering:
- sanctions and PEP screening at onboarding and on an ongoing basis
- beneficial ownership checks for any corporate or trust customer
- a clear internal pathway for raising and lodging an SMR
- a seven-year record retention system that survives staff turnover
- Schedule training and log completions. A training session nobody can prove happened is functionally the same as no training at all.
Where agents actually go wrong
Most compliance failures AUSTRAC encounters aren’t dramatic. They’re procedural gaps that compound over time.
- Downloading a template once and treating it as finished, rather than as a foundation for a tailored, living program.
- Starting CDD at contract exchange or settlement instead of at instruction.
- Missing beneficial owners behind corporate vendors, or mishandling SMSF trustee structures because they look simpler than they are.
- Running inconsistent record-keeping across multiple branches, so head office can’t demonstrate what any single office actually did.
Pro Tip: If your agency has more than one office, you still run one AML/CTF program, not one per branch. Fragmented records across locations are one of the first things a supervisor will pull apart.
Why consistent systems beat disconnected paperwork
Supervisors don’t assess your risk assessment, your policies, and your training records in isolation. They check whether they tell the same story. A policy that references risks your assessment never identified, or training that doesn’t match your actual procedures, reads as a program assembled to look compliant rather than one built to function.
That’s the practical case for platforms built around linked artefacts rather than standalone documents. Look for systems that offer:
- identity verification with document capture and biometric liveness checks
- sanctions and PEP screening with ongoing re-screening, not a one-off check
- beneficial ownership determination on a company’s ACN, with trusts and SMSFs reached through their corporate trustee
- risk scoring that records the reasoning behind each score, not just the number
- SMR and threshold transaction reporting workflows built into daily use
- a tamper-evident audit trail and integration with the CRM your agency already runs
Some platforms generate the risk assessment, policies, compliance action plan, and training manual as one linked set from the same inputs, and may include CRM integration and onboarding processes that configure the platform to an agency’s risk profile.
Compliance as a business asset, not a burden
Treating your AML/CTF program as a genuine risk management tool, not a compliance chore, protects your licence and your reputation when a transaction turns out to involve dirty money. A program that’s actually maintained, not just filed away, scales as your agency grows and shields the principal, who carries the accountability regardless of which salesperson handled the file.
Getting your program running with AML Guard
Building four consistent artefacts from scratch, a risk assessment, policies, a compliance action plan, and a training manual, while also running identity verification, sanctions screening, and beneficial ownership tracing manually is a genuine operational load for a busy agency.

Some compliance platforms are designed specifically for Australian reporting entities subject to relevant obligations for real estate agencies and buyer’s agents, producing linked program artefacts drawn from the same inputs. Such platforms can offer identity verification with document capture and liveness checks, ongoing sanctions and PEP screening, beneficial ownership tracing through company identifiers (extending to trusts and SMSFs via corporate trustees), risk scoring with reasoning recorded, suspicious matter and threshold transaction reporting workflows, backed by an 8-year tamper-evident audit trail, above the Act’s seven-year minimum. Integration with popular CRM systems may also be available to reflect compliance status against listings.
AML Guard isn’t self-service. You start by booking a demo, after which your tenant is configured to your agency’s designated services and risk profile.

Sources
For the primary law, read the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and the AML/CTF Rules 2025. AUSTRAC’s real estate program starter kit is the practical starting point, and FATF’s real estate sector guidance adds useful international context on beneficial ownership risk, though it carries no force in Australia.
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Real estate program starter kit: Getting started | AUSTRAC
FAQ
Do sole trader agents need a full AML/CTF program?
Yes. If you broker the purchase, sale, or transfer of real estate as a designated service, the size or structure of your business doesn’t exempt you from having a program.
Is the buyer or the vendor my customer for CDD purposes?
It depends entirely on who instructed you. A vendor’s agent treats the vendor as the customer; a buyer’s agent treats the buyer as the customer.
Can I use a downloaded AML template as my whole program?
A template is a reasonable starting point, but AUSTRAC expects a tailored, living program built around your actual risk assessment, not a static document filed and forgotten.
Does property management carry the same AML obligations as sales?
No. Property management is assessed against the specific designated service you’re providing in that context, so it needs its own treatment in your program rather than reusing your sales CDD process.
What happens if my agency doesn’t comply?
Non-compliance exposes your agency and its principal to regulatory action from AUSTRAC, reputational damage, and potential involvement in facilitating financial crime, regardless of whether a salesperson or the principal handled the file.
How does AML Guard help with ongoing obligations?
AML Guard keeps the risk assessment, policies, and training manual linked as a single set, and layers on identity verification, screening, and reporting workflows so your program stays current rather than static.
Recommended
- When Does AML Compliance Actually Start?
- AML/CTF Compliance Checklist for Real Estate Agents: What You Need Before 1 July 2026
- AML training real estate: what agencies must do
- Tranche 2 customer due diligence in Australia
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.