Executive Summary

From 1 July 2026, Australian real estate agencies became regulatory reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). The industry's response has been predictable: a flood of cloud-based compliance software, marketed with phrases like "fully AUSTRAC compliant" and "enterprise-grade compliance at a fraction of the cost".

What hasn't changed: what AUSTRAC actually requires of a reporting entity. And what AUSTRAC requires is not a software subscription. It is a compliance program — documented, evidenced, effectively implemented, with a named eligible CO overseeing compliance and clear governance responsibilities.

The Core Principle: A software platform can log information. A software platform cannot hold a compliance officer position. A software platform cannot make a judgment call about a Suspicious Matter Report. A software platform cannot defend your agency to AUSTRAC. A person has to.

This guide is written for principals, franchisors, directors and other decision-makers in real estate. It explains what the law actually asks of you, what the gap looks like between software-only compliance and genuine compliance, and how to assess whether your current solution would survive an AUSTRAC audit or an enforcement action.

The Regulatory Shift: What Changed on 1 July 2026

The Anti-Money Laundering and Counter-Terrorism Financing Act has been law for two decades. For most of that time, real estate was an anomaly: an industry sitting at the top of the money-laundering risk hierarchy with no equivalent real estate reporting obligations under the AML/CTF regime. Banks, casinos, remittance dealers — all regulated since 2006. Real estate designated services entered the AML/CTF regime on 1 July 2026.

That gap was not accidental. The Financial Action Task Force, the international standard-setter on anti-money laundering, flagged Australia as an outlier for leaving its real estate sector unregulated. Years of international pressure, multiple government reviews, and eventually a bill finally passed in late 2024 — and the obligations commenced on 1 July 2026.

The Eight Core Requirements

1

Tailored AML/CTF Program

A documented risk assessment and AML/CTF policies tailored to your agency. Templates and AUSTRAC starter kits may assist, but must be customised and implemented. AUSTRAC guidance

2

Named Compliance Officer

A named, fit-and-proper person employed or engaged at management level, with sufficient authority, independence, resources and competence to oversee and coordinate day-to-day compliance. AUSTRAC guidance

3

Customer Due Diligence

Initial CDD is ordinarily completed before the designated service begins. For a selling agency, this applies to its vendor. Where the conditions for delaying purchaser CDD are met, complete it as soon as reasonably practicable and no later than 28 days after contract exchange or three days before the initially agreed settlement date, whichever is earlier. Delay must be essential to avoid interrupting ordinary business, create low additional ML/TF risk, and be managed under documented policies. This is not an automatic grace period. AUSTRAC guidance

4

Ongoing Monitoring

Continuous assessment of client relationships for compliance risk — risk isn't fixed at the start of a transaction, it can change.

5

Threshold Transaction Reports

TTRs must be lodged within ten business days for cash transactions of $10,000 or more — AUSTRAC demands these be filed promptly and correctly.

6

Suspicious Matter Reports

Once a suspicion is formed on reasonable grounds, submit an SMR within 24 hours for terrorism financing, or within three business days after the day the suspicion is formed for other matters. Where the applicable legal professional privilege claim provisions apply, the latter period is up to five business days; the terrorism-financing deadline is unchanged. A red flag requires assessment and does not automatically establish reasonable grounds for suspicion. AUSTRAC guidance

7

Seven-Year Record Keeping

Retention depends on the record category. CDD records are generally retained for seven years after the business relationship ends or the occasional transaction is completed. Program records are retained until seven years after they cease to be relevant to demonstrating compliance. General transaction records run for seven years from creation; customer-provided transaction records run from receipt. Records must be accessible and supplied in accordance with applicable requirements and notices. AUSTRAC guidance

8

Staff Training & Independent Evaluation

Provide documented, role-relevant training and keep it current. Arrange an independent evaluation of the AML/CTF program at a frequency appropriate to the business’s nature, size and complexity, generally at least once every three years, subject to applicable transitional deadlines for the first evaluation. An evaluator may be internal or external but must be sufficiently independent of the work evaluated, including program development and operation. This is separate from routine internal reviews and any AUSTRAC-directed audit. AUSTRAC guidance

Annual Reporting and Governance

The next AUSTRAC annual compliance reporting period is 1 July 2026 to 30 June 2027, with submission from 1 July to 30 September 2027. Thereafter, reports cover the previous financial year and are due within three months of its end. This return is separate from the CO’s report to the governing body at least once every 12 months, with the applicable sole-trader and micro-business arrangements considered. AUSTRAC guidance · CO reporting responsibilities

The Software-Only Problem

Over the past eighteen months, a compliance-software industry has sprung up around real estate, with marketing promises of "enterprise-grade compliance" from a cloud dashboard. None of this is malicious. The products are often genuine tools. The problem is that a tool is not a program, and a program is what the law requires.

What Software Can Do

What Software Cannot Do

The Practical Requirement: Appoint an eligible CO with the authority, competence and resources to oversee compliance, and retain evidence of the program’s operation. An internal or externally engaged person may perform that role. Software supports the work but does not itself hold the appointment. AUSTRAC guidance

The Big Bank Precedent

Real estate principals often assume that if they have a software platform and some policies, they will be fine. The finance sector has already shown what that assumption looks like in practice:

$700M
Commonwealth Bank, 2018 — 53,750 breaches of AML/CTF Act
$1.3B
Westpac, 2020 — 23 million breaches of AML/CTF reporting

These were not small banks run by people who didn't care. These were Australia's largest financial institutions, with compliance departments in the hundreds, legal teams, risk committees, and systems built by professionals. They had software. They had policies. They had people. And they still got caught out at a scale that should terrify any real estate business relying on software alone.

These cases illustrate the consequences of systemic AML/CTF failures. They do not establish that software, outsourcing or a particular staffing structure alone causes non-compliance. The practical lesson is to implement effective controls and retain evidence that they operate.

The Compliance Program vs. The Software Platform

Aspect Software-Only Approach Genuine Compliance Program
Accountability Diffused across multiple users; no single person accountable Named Compliance Officer overseeing compliance; reporting entity retains statutory obligations
Decision-Making Based on automated flags and rules; human judgment is often absent Professional judgment applied to each file; decisions documented and defensible
Program Tailoring Standard template applied; same for all users Program written specifically for your agency's actual risks
Escalation Flags sit in a dashboard until someone manually reviews them Structured escalation with a named person responsible for each level
AUSTRAC Audit Difficult to explain why decisions were made; audit trail is incomplete Clear, documented reasoning for every decision; full audit trail available
Regulatory Exposure High — lack of named accountability creates systemic risk Lower — clear accountability chain and documented decision-making

The Business Governance Principle

This isn't really about AML/CTF compliance. It's about business governance. The principle that applies to every regulated business is straightforward: the people who own a business remain accountable for the regulatory obligations that business carries.

The reporting entity retains its statutory obligations when it outsources work. An eligible external CO can oversee and coordinate compliance, provided they have the required authority, resources and expertise. Senior managers and the governing body retain their respective responsibilities. AUSTRAC guidance

Good Businesses Don't Become Successful Because They Avoid Risk. They become successful because they understand risk, manage it, and continuously improve. That principle — understand it, manage it, improve it — is exactly what a compliance program demands. A software login is not managing risk. A real person, with accountability, managing a documented program — that is managing risk.

What Happens If You Get This Wrong

The Regulatory Spectrum

AUSTRAC's enforcement actions range from informal warnings through to civil penalties running into tens of millions of dollars. Here's what the regulatory spectrum looks like:

⚠ Evidence Matters: Repeated CDD, reporting or recordkeeping gaps can indicate systemic weaknesses. Investigate and remediate the underlying causes. A count of affected offices or records is not a calculation of contraventions or penalties; those depend on the relevant law, conduct and evidence.

The Principal's Accountability

AMLHQ’s CO oversees and coordinates day-to-day compliance, assesses escalated matters and manages reporting under the agency’s AML/CTF policies. A senior manager approves matters where the law or those policies require it, including specified PEP relationships. SMR assessment and lodgement are distinct from governance decisions about starting or continuing a customer relationship; internal approvals must not cause a statutory reporting deadline to be missed. The reporting entity retains its statutory obligations. AUSTRAC guidance · CO responsibilities

Business size does not itself remove obligations for an in-scope designated service. A sole trader, company and statutory reporting group have different structures and responsibilities; the program must reflect the actual business and its risks.

Building a Defensible Compliance Program

A defensible program has four essential components:

1. A Named, Accountable Compliance Officer

Not a role assigned to the busiest person available. Not a title given to the finance manager as an add-on. A real person, with time allocated, with seniority within the business, with the authority to make decisions and the responsibility for the outcome.

2. A Tailored, Written Program

A program reflecting your agency’s markets, customers, services, transaction patterns and personnel risks. A template or AUSTRAC starter kit can be a starting point, but must be tailored and implemented. AUSTRAC guidance

3. Systems That Support The Program

Software can be part of this, but it is not the whole of it. Systems include: documented procedures, escalation pathways, training schedules, record-keeping protocols, decision-making frameworks — all of which support a real human being in executing the program consistently.

4. Evidence That The Program Actually Ran

Files reviewed, decisions documented, Suspicious Matter Reports lodged, training completed, meetings held. Audit trails showing that the program was not just written down, but executed, monitored, and continuously improved.

Your Next Step

Real estate AML/CTF obligations commenced on 1 July 2026 for in-scope designated services. Review whether your people, policies and systems are operating effectively and retain evidence of the work performed. A software subscription alone does not demonstrate compliance.

The question isn't whether to comply — it's whether your current approach will survive an audit.

Book a Compliance Assessment

Disclaimer: This guide is provided for general information and educational purposes only. It does not constitute legal, financial, regulatory, or compliance advice. Real estate agencies are required to comply with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), administered by AUSTRAC. All reporting entities should seek independent professional advice tailored to their specific circumstances. Penalty figures and enforcement data cited are drawn from publicly available AUSTRAC information current at time of publication. Prepared by Business Advice Agency Pty Ltd (ABN 56 637 480 132), trading as AMLHQ. AMLHQ is not certified, endorsed or approved by AUSTRAC. Australian Credit Licence 392611 held by EZFinance Pty Ltd.