AML/CTF obligations for Tranche 2 businesses are now in force. Since 1 July 2026 Get compliant

Tranche 2: What You Need to Know

From 1 July 2026, real estate agents become reporting entities under Australia's AML/CTF Act.

Tranche 2: What You Need to Know

From 1 July 2026, real estate agents become reporting entities under Australia's AML/CTF Act.

What is Tranche 2?

+
Australia's AML/CTF reforms extend anti-money laundering obligations to real estate agents, conveyancers, lawyers, and accountants from 1 July 2026. Real estate agents will need to verify customer identities, screen against sanctions and PEP lists, assess risk, and maintain records for 7 years.

What specific obligations apply to real estate agents?

+
Before providing a designated service (facilitating the purchase, sale, or transfer of real estate), agents must: enrol with AUSTRAC as a reporting entity, establish an AML/CTF program, identify and verify customers (CDD), identify beneficial owners for companies and trusts, assess customer risk, screen against sanctions/PEP lists, maintain records for 7 years, report suspicious matters (SMRs) and threshold transactions (TTRs), and submit annual compliance reports.

What is beneficial ownership and why does it matter?

+
When a customer is a company, trust, or other entity, you must identify the natural persons who ultimately own or control it. AUSTRAC expects you to trace ownership and control structures, not just accept the entity at face value. AML Guard automates this through ASIC company extracts, tracing through holding companies up to 5 levels deep.

Do I need to check source of funds for every transaction?

+
Source of funds checks apply where enhanced due diligence is required: typically for higher-risk customers, unusual transactions, or politically exposed persons. Standard CDD covers identity verification, sanctions screening, and risk assessment. SoF is part of the enhanced due diligence layer, not a universal requirement for every sale.

Can I rely on another party's CDD checks?

+
Yes, the AML/CTF Act allows formal CDD reliance arrangements under sections 37A and 38. This means an agent can rely on KYC verification completed by another reporting entity (e.g., a conveyancer). AML Guard includes a statutory reliance register and secure evidence sharing between parties.

What happens if I don't comply?

+
AUSTRAC has enforcement powers including civil penalties, infringement notices, enforceable undertakings, and remedial directions. For serious or systemic non-compliance, penalties can be significant. The reforms are designed to be proportionate to business size, but ignorance is not a defence.

Does AML Guard integrate with REX CRM?

+
Yes. AML Guard has deep REX CRM integration. Compliance status pushes to REX with no sensitive data leaving the system. Cases link to REX contacts and listings. You can pre-check your database against REX before calling.

Can I outsource my AML/CTF compliance?

It’s a fair question. With around 90,000 new reporting entities coming online by July 2026, the compliance consulting industry is growing fast. Some providers offer to handle everything: your risk assessment, your CDD, your monitoring, even your AUSTRAC reporting.

But there’s a catch. And it’s not a small one.

The regulatory position

AUSTRAC’s guidance on outsourcing is unambiguous:

“If you outsource AML/CTF functions, you remain responsible for complying with your obligations under the Act and Rules. Generally, your business will remain legally liable for any breach of its AML/CTF obligations, even under outsourcing arrangements, and will incur any penalty that arises from a breach.”

: AUSTRAC, “Using outsourcing to help meet your AML/CTF obligations,” 2026

What you can outsource

Operational tasks, the mechanics of compliance:

  • Running identity verification checks
  • Screening names against sanctions and PEP lists
  • Preparing required AUSTRAC reports
  • Monitoring transactions for unusual patterns

These are the tasks that technology handles well, and where tools like AML Guard automate what would otherwise be manual, error-prone work.

What you cannot outsource

Accountability, governance, and decision-making:

  • Your risk assessment, understanding your own business’s specific ML/TF risks
  • Your AML/CTF policies: approved by your governing body or senior management, tailored to your services
  • Your AML/CTF compliance officer: an eligible, fit and proper person with sufficient authority, independence and resources to oversee day-to-day compliance
  • Your governance structure, your governing body has primary responsibility for executive decisions and oversight
  • The decision framework around suspicious matter identification and reporting, the reporting entity owns the judgement on whether to report
  • Your record-keeping, you must maintain accurate and complete records for at least 7 years

These obligations sit with the reporting entity. If a consultant makes a mistake or misses a suspicious matter, it’s your agency that faces the penalty, not theirs.

What AUSTRAC expects if you do outsource

AUSTRAC “expects” reporting entities to take steps to manage the risks of outsourcing and have appropriate oversight of their providers. That means if you do outsource, you need to monitor the outsourcer: review their processes, sample their work, check outcomes. You’re adding a layer of management, not removing one.

The better approach

Rather than paying someone else to do your compliance (and then paying to oversee them doing it), the more practical path is to use tools that make self-compliance straightforward.

AML Guard is designed for exactly this:

  • Step-by-step workflows that guide your team through CDD, screening, and risk assessment
  • Plain-English tooltips on every field explaining what’s required and why
  • Automated risk scoring based on configurable rules your compliance officer controls
  • Notifications with direct links to the action required, no guessing what to do next
  • A complete audit trail that documents every decision, every check, and every outcome
  • AUSTRAC reporting workflows built into the platform

Your team runs the process. The platform makes it simple. Your audit trail proves you did the work. That’s what AUSTRAC wants to see.

A note on record-keeping: The AML/CTF Act requires records to be kept for at least 7 years. AML Guard retains compliance records for at least 7 years, with secure tiered storage so your evidence is always available when AUSTRAC asks.

Ready to see AML Guard in action?

Book a 20-minute demo. See identity verification, beneficial ownership tracing, and audit-ready record keeping, all integrated with REX.

Book a Demo

No commitment required