Executive Summary
From 1 July 2026, Australian real estate agencies became regulatory reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). The industry's response has been predictable: a flood of cloud-based compliance software, marketed with phrases like "fully AUSTRAC compliant" and "enterprise-grade compliance at a fraction of the cost".
What hasn't changed: what AUSTRAC actually requires of a reporting entity. And what AUSTRAC requires is not a software subscription. It is a compliance program — documented, evidenced, effectively implemented, with a named eligible CO overseeing compliance and clear governance responsibilities.
The Core Principle: A software platform can log information. A software platform cannot hold a compliance officer position. A software platform cannot make a judgment call about a Suspicious Matter Report. A software platform cannot defend your agency to AUSTRAC. A person has to.
This guide is written for principals, franchisors, directors and other decision-makers in real estate. It explains what the law actually asks of you, what the gap looks like between software-only compliance and genuine compliance, and how to assess whether your current solution would survive an AUSTRAC audit or an enforcement action.
The Regulatory Shift: What Changed on 1 July 2026
The Anti-Money Laundering and Counter-Terrorism Financing Act has been law for two decades. For most of that time, real estate was an anomaly: an industry sitting at the top of the money-laundering risk hierarchy with no equivalent real estate reporting obligations under the AML/CTF regime. Banks, casinos, remittance dealers — all regulated since 2006. Real estate designated services entered the AML/CTF regime on 1 July 2026.
That gap was not accidental. The Financial Action Task Force, the international standard-setter on anti-money laundering, flagged Australia as an outlier for leaving its real estate sector unregulated. Years of international pressure, multiple government reviews, and eventually a bill finally passed in late 2024 — and the obligations commenced on 1 July 2026.
The Eight Core Requirements
Tailored AML/CTF Program
A documented risk assessment and AML/CTF policies tailored to your agency. Templates and AUSTRAC starter kits may assist, but must be customised and implemented. AUSTRAC guidance
Named Compliance Officer
A named, fit-and-proper person employed or engaged at management level, with sufficient authority, independence, resources and competence to oversee and coordinate day-to-day compliance. AUSTRAC guidance
Customer Due Diligence
Initial CDD is ordinarily completed before the designated service begins. For a selling agency, this applies to its vendor. Where the conditions for delaying purchaser CDD are met, complete it as soon as reasonably practicable and no later than 28 days after contract exchange or three days before the initially agreed settlement date, whichever is earlier. Delay must be essential to avoid interrupting ordinary business, create low additional ML/TF risk, and be managed under documented policies. This is not an automatic grace period. AUSTRAC guidance
Ongoing Monitoring
Continuous assessment of client relationships for compliance risk — risk isn't fixed at the start of a transaction, it can change.
Threshold Transaction Reports
TTRs must be lodged within ten business days for cash transactions of $10,000 or more — AUSTRAC demands these be filed promptly and correctly.
Suspicious Matter Reports
Once a suspicion is formed on reasonable grounds, submit an SMR within 24 hours for terrorism financing, or within three business days after the day the suspicion is formed for other matters. Where the applicable legal professional privilege claim provisions apply, the latter period is up to five business days; the terrorism-financing deadline is unchanged. A red flag requires assessment and does not automatically establish reasonable grounds for suspicion. AUSTRAC guidance
Seven-Year Record Keeping
Retention depends on the record category. CDD records are generally retained for seven years after the business relationship ends or the occasional transaction is completed. Program records are retained until seven years after they cease to be relevant to demonstrating compliance. General transaction records run for seven years from creation; customer-provided transaction records run from receipt. Records must be accessible and supplied in accordance with applicable requirements and notices. AUSTRAC guidance
Staff Training & Independent Evaluation
Provide documented, role-relevant training and keep it current. Arrange an independent evaluation of the AML/CTF program at a frequency appropriate to the business’s nature, size and complexity, generally at least once every three years, subject to applicable transitional deadlines for the first evaluation. An evaluator may be internal or external but must be sufficiently independent of the work evaluated, including program development and operation. This is separate from routine internal reviews and any AUSTRAC-directed audit. AUSTRAC guidance
Annual Reporting and Governance
The next AUSTRAC annual compliance reporting period is 1 July 2026 to 30 June 2027, with submission from 1 July to 30 September 2027. Thereafter, reports cover the previous financial year and are due within three months of its end. This return is separate from the CO’s report to the governing body at least once every 12 months, with the applicable sole-trader and micro-business arrangements considered. AUSTRAC guidance · CO reporting responsibilities
The Software-Only Problem
Over the past eighteen months, a compliance-software industry has sprung up around real estate, with marketing promises of "enterprise-grade compliance" from a cloud dashboard. None of this is malicious. The products are often genuine tools. The problem is that a tool is not a program, and a program is what the law requires.
What Software Can Do
- Store customer identity information and verification documents
- Flag transactions that meet certain criteria (amount thresholds, destination countries, etc.)
- Log decisions and create an audit trail
- Send notifications and reminders
- Generate reports
What Software Cannot Do
- Make a legal judgment about whether a Suspicious Matter Report is required
- Hold the statutory appointment of a named Compliance Officer
- Explain a compliance decision to a regulator under cross-examination
- Adapt your program to your specific business risk
- Be "fit and proper" — software is code, not a person
- Fulfil the role of an eligible, named Compliance Officer
The Practical Requirement: Appoint an eligible CO with the authority, competence and resources to oversee compliance, and retain evidence of the program’s operation. An internal or externally engaged person may perform that role. Software supports the work but does not itself hold the appointment. AUSTRAC guidance
The Big Bank Precedent
Real estate principals often assume that if they have a software platform and some policies, they will be fine. The finance sector has already shown what that assumption looks like in practice:
These were not small banks run by people who didn't care. These were Australia's largest financial institutions, with compliance departments in the hundreds, legal teams, risk committees, and systems built by professionals. They had software. They had policies. They had people. And they still got caught out at a scale that should terrify any real estate business relying on software alone.
These cases illustrate the consequences of systemic AML/CTF failures. They do not establish that software, outsourcing or a particular staffing structure alone causes non-compliance. The practical lesson is to implement effective controls and retain evidence that they operate.
The Compliance Program vs. The Software Platform
| Aspect | Software-Only Approach | Genuine Compliance Program |
| Accountability | Diffused across multiple users; no single person accountable | Named Compliance Officer overseeing compliance; reporting entity retains statutory obligations |
| Decision-Making | Based on automated flags and rules; human judgment is often absent | Professional judgment applied to each file; decisions documented and defensible |
| Program Tailoring | Standard template applied; same for all users | Program written specifically for your agency's actual risks |
| Escalation | Flags sit in a dashboard until someone manually reviews them | Structured escalation with a named person responsible for each level |
| AUSTRAC Audit | Difficult to explain why decisions were made; audit trail is incomplete | Clear, documented reasoning for every decision; full audit trail available |
| Regulatory Exposure | High — lack of named accountability creates systemic risk | Lower — clear accountability chain and documented decision-making |
The Business Governance Principle
This isn't really about AML/CTF compliance. It's about business governance. The principle that applies to every regulated business is straightforward: the people who own a business remain accountable for the regulatory obligations that business carries.
The reporting entity retains its statutory obligations when it outsources work. An eligible external CO can oversee and coordinate compliance, provided they have the required authority, resources and expertise. Senior managers and the governing body retain their respective responsibilities. AUSTRAC guidance
Good Businesses Don't Become Successful Because They Avoid Risk. They become successful because they understand risk, manage it, and continuously improve. That principle — understand it, manage it, improve it — is exactly what a compliance program demands. A software login is not managing risk. A real person, with accountability, managing a documented program — that is managing risk.
What Happens If You Get This Wrong
The Regulatory Spectrum
AUSTRAC's enforcement actions range from informal warnings through to civil penalties running into tens of millions of dollars. Here's what the regulatory spectrum looks like:
- Audit & Advice: AUSTRAC identifies gaps, issues recommendations, gives you time to remediate.
- Compliance Notice: AUSTRAC formally requires you to take specific steps within a set timeframe.
- Enforceable Undertaking: A written commitment offered to and accepted by AUSTRAC to take specified compliance action; costs depend on the required work.
- Civil Penalty: For applicable contraventions, potential maxima include 100,000 penalty units for a body corporate ($36.4 million) and 20,000 for a non-corporate person ($7.28 million), using the $364 unit value from 1 July 2026. The court determines the penalty on the facts. AUSTRAC guidance
- Criminal Prosecution: For serious or reckless breaches, criminal charges including potential imprisonment.
⚠ Evidence Matters: Repeated CDD, reporting or recordkeeping gaps can indicate systemic weaknesses. Investigate and remediate the underlying causes. A count of affected offices or records is not a calculation of contraventions or penalties; those depend on the relevant law, conduct and evidence.
The Principal's Accountability
AMLHQ’s CO oversees and coordinates day-to-day compliance, assesses escalated matters and manages reporting under the agency’s AML/CTF policies. A senior manager approves matters where the law or those policies require it, including specified PEP relationships. SMR assessment and lodgement are distinct from governance decisions about starting or continuing a customer relationship; internal approvals must not cause a statutory reporting deadline to be missed. The reporting entity retains its statutory obligations. AUSTRAC guidance · CO responsibilities
Business size does not itself remove obligations for an in-scope designated service. A sole trader, company and statutory reporting group have different structures and responsibilities; the program must reflect the actual business and its risks.
Building a Defensible Compliance Program
A defensible program has four essential components:
1. A Named, Accountable Compliance Officer
Not a role assigned to the busiest person available. Not a title given to the finance manager as an add-on. A real person, with time allocated, with seniority within the business, with the authority to make decisions and the responsibility for the outcome.
2. A Tailored, Written Program
A program reflecting your agency’s markets, customers, services, transaction patterns and personnel risks. A template or AUSTRAC starter kit can be a starting point, but must be tailored and implemented. AUSTRAC guidance
3. Systems That Support The Program
Software can be part of this, but it is not the whole of it. Systems include: documented procedures, escalation pathways, training schedules, record-keeping protocols, decision-making frameworks — all of which support a real human being in executing the program consistently.
4. Evidence That The Program Actually Ran
Files reviewed, decisions documented, Suspicious Matter Reports lodged, training completed, meetings held. Audit trails showing that the program was not just written down, but executed, monitored, and continuously improved.
Your Next Step
Real estate AML/CTF obligations commenced on 1 July 2026 for in-scope designated services. Review whether your people, policies and systems are operating effectively and retain evidence of the work performed. A software subscription alone does not demonstrate compliance.
The question isn't whether to comply — it's whether your current approach will survive an audit.
Book a Compliance AssessmentDisclaimer: This guide is provided for general information and educational purposes only. It does not constitute legal, financial, regulatory, or compliance advice. Real estate agencies are required to comply with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), administered by AUSTRAC. All reporting entities should seek independent professional advice tailored to their specific circumstances. Penalty figures and enforcement data cited are drawn from publicly available AUSTRAC information current at time of publication. Prepared by Business Advice Agency Pty Ltd (ABN 56 637 480 132), trading as AMLHQ. AMLHQ is not certified, endorsed or approved by AUSTRAC. Australian Credit Licence 392611 held by EZFinance Pty Ltd.