Do Real Estate Agencies Need a Compliance Officer? AUSTRAC Requirements Explained
Short answer: Yes. AUSTRAC requires every reporting entity to appoint a Compliance Officer. This is not optional.
This requirement existed before Tranche 2, but post-1 July 2026, enforcement has intensified for real estate professionals. Understanding this obligation and your options for meeting it is essential.
The Legal Requirement
The AML/CTF Act (section 84) requires every reporting entity to appoint a Compliance Officer who is:
- Genuinely fit and proper
- Sufficiently competent in AML/CTF matters
- Sufficiently senior to have authority in the organisation
- Adequately resourced to perform the role
- Free from conflicts of interest
The officer must be a real person (not a position title), must be named to AUSTRAC, and must have clearly defined responsibilities.
What the Compliance Officer Actually Does
The role includes:
- Overseeing day-to-day AML/CTF program compliance
- Evaluating higher-risk transactions and escalations
- Approving Suspicious Matter Reports (SMR) and Threshold Transaction Reports (TTR)
- Managing customer due diligence decisions
- Coordinating staff training and competency
- Managing independent evaluation preparations
- Reporting to board/principal on compliance status
- Ensuring program effectiveness and currency
Key point: The Compliance Officer cannot simply delegate everything. They must personally exercise oversight and make critical decisions.
Your Three Options for Meeting This Requirement
Option 1: Appoint Your Own Internal CO
You: Identify a senior staff member (office manager, principal, business advisor) with AML knowledge or capacity to learn it.
Advantages: No external cost, internal knowledge of your business, direct control
Challenges: Time commitment, ongoing training, liability on that individual, potential absence coverage
Who this works for: Small single-office agencies with a capable senior person and willingness to invest in AML focus
Option 2: Use an External CO Service Provider
You: Contract with a compliance service provider (like AMLHQ) to supply a named Compliance Officer
Advantages: Professional expertise, defined liability, scalability, backup coverage, no internal training burden
Challenges: Monthly cost, less day-to-day internal familiarity, reliance on external provider
Who this works for: Multi-office groups, agencies that want professional oversight, those without internal AML expertise
Option 3: Hybrid (Keep Your Platform + Add External CO)
You: Keep your existing AML software investment but add an external Compliance Officer for oversight and escalation
Advantages: Preserves software investment, adds professional judgment, lower cost than full platform migration, flexibility
Challenges: Integration between systems, some platform features may be redundant
Who this works for: Agencies already committed to software that want professional backup
Questions AUSTRAC Will Ask
During independent evaluation or audit, AUSTRAC will ask:
- Who is your Compliance Officer? (Name required)
- What are their qualifications and experience?
- How much time do they spend on AML compliance monthly?
- Are they adequately resourced?
- What decision authority do they have?
- What is their reporting line?
- Who covers if they are absent?
- Can you show evidence of their involvement in key decisions?
If your answer is "a login to a software platform," you have not met the requirement. AUSTRAC is looking for a real person with authority and evidence of involvement.
Red Flags in CO Arrangements
AUSTRAC is increasingly scrutinizing CO arrangements that don't look genuine. Avoid:
- Naming an absent person (internal staff member who is not actually engaged)
- Over-delegating (CO has no personal involvement in decisions)
- Absence coverage gaps (no backup when CO unavailable)
- Undocumented decisions (no trail of CO reasoning)
- Multiple roles without clarity (CO who also runs operations and has no time)
Reality Check
AUSTRAC's enforcement priorities have shifted post-1 July. They are auditing whether reporting entities actually have a functioning Compliance Officer, not just whether they filed a name with AUSTRAC. Genuine, resourced, involved COs are what matters.
Cost Reality
Internal CO: Salary burden on existing staff (often unpaid addition to existing role) + training costs (estimate: $2,000–$5,000 annually) + time commitment
External CO: $350–$990 per month depending on model and agency size, often recoverable through vendor admin fees
The hidden cost of not having a genuine CO: Potential AUSTRAC penalties of $36.4 million per breach, or compliance gaps discovered during independent evaluation requiring remediation
Ready to Strengthen Your CO Function?
If you don't have a Compliance Officer or yours is under-resourced, AMLHQ can help—whether through fully managed CO service (CO or CFO models) or hybrid arrangement (keep software + add AMLHQ CO oversight).
Key Takeaways
- Compliance Officer is mandatory. Not optional, not a software substitute.
- The officer must be real, qualified, and involved. Not a position title with no person behind it.
- You have three viable options: Internal, external, or hybrid.
- AUSTRAC is scrutinizing CO arrangements. Be prepared to show evidence of genuine involvement.
- An under-resourced CO is worse than none, because you claim compliance you don't have.
Disclaimer: This article provides general information about AML compliance requirements. It is not legal advice. Consult professional advisors about your specific circumstances.