$36.4M
Potential maximum for applicable corporate contraventions (AML/CTF Act 2006, 100,000 penalty units × $364 from 1 July 2026)
$7.28M
Potential maximum for applicable non-corporate contraventions; personal liability depends on the law and conduct
Risk-based
Ongoing compliance requires people, policies and evidence
1 July 2026
Real estate AML/CTF obligations commenced for in-scope designated services

Already selected a cloud-based AML platform? Review how your people, policies and systems operate together. Formal reporting groups have specific obligations; other networks can use commercial oversight to improve visibility. A software subscription alone does not demonstrate that the required controls are operating.

What AUSTRAC Actually Requires from Your Network

01

Fit and Proper Compliance Officer — Mandatory

Appoint a fit-and-proper CO employed or engaged at management level, with sufficient authority, independence, resources and competence. The ordinary rule is appointment within 28 days of starting designated services and notification within 14 days of appointment; specific commencement transitional provisions also apply. An eligible principal or externally engaged professional may perform the role. AUSTRAC guidance

02

Reporting Group Status Depends on Structure and Election

A franchise brand or shared platform does not by itself create a statutory reporting group. Control-based business groups can automatically form a reporting group where the requirements are met; eligible entities may instead form an elective group through written agreement. A business group requires a lead entity within 28 days, and a reporting entity’s written opt-out prevents that business group from being a reporting group. Head-office oversight can also be provided commercially without creating statutory reporting-group membership. AUSTRAC guidance

03

Lead Entity Responsibilities and Civil Penalty Exposure

For a statutory reporting group, AUSTRAC explains that a member’s breach of a civil penalty provision is also treated as a breach by its lead entity. The lead entity has group-wide oversight and risk-management obligations. This does not mean every franchisee or director is automatically liable for another office’s conduct. Establish the actual group structure and applicable obligations. AUSTRAC guidance

04

If You Don't Form a Group, Every Office Stands Alone

Outside a statutory reporting group, each reporting entity must maintain and implement an AML/CTF program appropriate to its own risks. Common templates, service providers, training and outsourced CO support can still be used, provided each entity meets its obligations. A commercial oversight portal does not itself create reporting-group membership. AUSTRAC guidance

05

CDD Completed Within Prescribed Timeframes

Initial CDD is ordinarily completed before the designated service begins. For a selling agency, this applies to its vendor. Where the conditions for delaying purchaser CDD are met, complete it as soon as reasonably practicable and no later than 28 days after contract exchange or three days before the initially agreed settlement date, whichever is earlier. Delay must be essential to avoid interrupting ordinary business, create low additional ML/TF risk, and be managed under documented policies. This is not an automatic grace period. AUSTRAC guidance

06

SMR Lodgement — Statutory Deadlines Apply

Once a suspicion is formed on reasonable grounds, submit an SMR within 24 hours for terrorism financing, or within three business days after the day the suspicion is formed for other matters. Where the applicable legal professional privilege claim provisions apply, the latter period is up to five business days; the terrorism-financing deadline is unchanged. A red flag requires assessment and does not automatically establish reasonable grounds for suspicion. AUSTRAC guidance Apply tipping-off restrictions when handling and sharing report information.

07

Relevant Training and Documented Evidence

Provide role-relevant training and retain evidence of delivery and completion. Group-wide policies should support consistent standards while addressing different roles and risks. Training records are program records, retained until seven years after they cease to be relevant to demonstrating compliance. AUSTRAC guidance

08

Annual Compliance Report to AUSTRAC

The next AUSTRAC annual compliance reporting period is 1 July 2026 to 30 June 2027, with submission from 1 July to 30 September 2027. Thereafter, reports cover the previous financial year and are due within three months of its end. This return is separate from the CO’s report to the governing body at least once every 12 months, with the applicable sole-trader and micro-business arrangements considered. AUSTRAC guidance · CO reporting responsibilities

09

Independent Evaluation — Risk-Based Frequency

Arrange an independent evaluation of the AML/CTF program at a frequency appropriate to the business’s nature, size and complexity, generally at least once every three years, subject to applicable transitional deadlines for the first evaluation. An evaluator may be internal or external but must be sufficiently independent of the work evaluated, including program development and operation. This is separate from routine internal reviews and any AUSTRAC-directed audit. AUSTRAC guidance

Two Paths for Your Network — And What Each Actually Means for Head Office

The starting point is to establish whether the businesses form a control-based reporting group or have elected to form one. Sharing a franchise brand does not settle that question. The following paths distinguish statutory group responsibilities from commercial oversight.

Path A — Outside a Statutory Reporting Group

  • Each office is its own separate reporting entity, with its own AML/CTF program, own CO and own AUSTRAC obligations
  • Sharing a brand does not itself impose statutory lead-entity liability on head office. Its own conduct, services, control relationships and other applicable duties still require assessment.
  • But AUSTRAC's own stated approach explicitly targets "serious and/or systemic" non-compliance patterns, and enforcement actions are public
  • If several offices under the same recognisable brand are separately found non-compliant, that's a reputational risk to the network — even without shared legal liability
  • Head office typically has little to no visibility into how well (or poorly) each office is actually managing its obligations

Path B — Formal Reporting Group (Head Office as Lead Entity)

  • For an elective group, members elect in writing and agree on a lead entity. Control-based business groups follow the automatic-formation rules and required lead-entity appointment process.
  • Where head office is the lead entity, a member’s civil penalty contravention also engages the statutory lead-entity liability rule.
  • Head office must maintain a program that reflects the size and risk profile of every member office — not just its own business
  • Real uniformity and governance become possible — but so does the exposure most franchise head offices haven't fully considered
  • Joining and leaving depend on the group type. Members of a control-based business group cannot split that business group into selected members; elective membership and notice rules must also be followed.

Reporting-group liability: For a statutory reporting group, AUSTRAC explains that a member’s breach of a civil penalty provision is also treated as a breach by its lead entity. The lead entity has group-wide oversight and risk-management obligations. This does not mean every franchisee or director is automatically liable for another office’s conduct. Establish the actual group structure and applicable obligations. AUSTRAC guidance

A Third Option: Commercial Oversight Without Electing a Reporting Group

A network may want visibility over office compliance without electing to form a reporting group. Assess the existing control structure first: a portal arrangement cannot override automatic group formation or remove obligations that already apply.

AML HQ's model is built around this exact gap, with two coordinated portals:

The AML HQ Portal — For Offices That Migrate
Offices that move to AML HQ get a real, experienced Compliance Officer and a consistent program under our model — the same standard, applied the same way, for every office that joins.
The Head Office Reporting Portal — For Offices That Don't
Offices retaining another provider can report status and outstanding actions through a separate portal. Head office gains oversight information; the portal itself does not establish statutory reporting-group membership.

Offices can retain their existing provider and report compliance status through the head-office portal. Visibility depends on the completeness and timeliness of those updates. Portal participation alone does not appoint head office as a statutory lead entity or guarantee freedom from liability. Information sharing must comply with confidentiality, privacy and tipping-off requirements.

Uniformity Is the Standard. Diversity of Execution Is the Risk.

Whichever path your network takes, the underlying risk described below is the same one AUSTRAC has flagged repeatedly across other regulated sectors — inconsistent execution between offices is exactly the pattern regulators notice.

A practical governance risk: Separate office logins and local compliance contacts do not establish whether controls are working consistently. Assess authority, training, escalation, reporting and evidence across participating offices. The legal responsibilities depend on the actual structure; differing workflows do not themselves create lead-entity liability.

⚠ Cloud Platform + Diverse Responsible Managers

  • Each office nominates its own "Responsible Manager" — different roles, different capabilities, different risk tolerance
  • No consistent interpretation of what triggers an SMR across offices
  • Training varies by manager — one office does it quarterly, another hasn't done it since onboarding
  • CDD timeframes managed differently between offices — some miss deadlines without realising
  • EDD decisions made by sales agents under settlement pressure, not compliance professionals
  • An audit may examine local or systemic issues; consistent evidence supports the relevant review

✓ AML HQ — Unified CO & CFO Model

  • Dedicated, qualified Compliance Officers assigned across the network under a single unified framework — one standard, applied everywhere
  • SMR and TTR decisions made by a compliance professional, not a sales agent under time pressure
  • Group-wide training delivered and documented centrally — every office, same standard, same records
  • CDD deadline tracking managed by the CO — not left to individual office calendars
  • Annual compliance report preparation and lodgement — available at the scheduled fee
  • Audit trail maintained at licence level — AUSTRAC-ready at any time, across all offices

"In a group/franchise, the real setup risk is uneven execution between offices — and regulators tend to notice. Expectations around control, documentation, consistency, and governance discipline only scale up."

AML HQ — AML/CTF Master Guide for Groups & Franchises, 2026

Provider Comparison — Selected Capabilities and Service Options

Legend: Confirmed available  |  Not available  |  ~ Partial / add-on cost / requires verification

Requirement / Feature AML HQ PEXA Clear AMLHUB First AML
Governance — Legal Obligations and Service Options
Named, fit & proper Compliance OfficerOrdinarily within 28 days of starting designated services; transitional rules may apply Assigned CO — real person You provide your own CO Software only You provide your own CO
CO manages SMR/TTR lodgementsHuman judgment — not a workflow trigger CO owns end-to-end
CO continuity managed for youReplacement appointment and notification follow the applicable statutory timeframes AML HQ manages continuity
Annual compliance report — authored & lodged Available at scheduled fee ~Consulting add-on ~Guidance only
Independent program evaluation — risk-based frequency ~Separate engagement
Franchise & Multi-Office Group Governance
Group-wide uniformity enforced by a professional CO enforces across all offices Tool only — each user independent Dashboard per office only ~Group workflows — no CO
Audit trail at licence / network level ~Per-office only
Franchise compliance schedule for agreements Master Guide & Schedule
AUSTRAC audit representation & support Full support (scheduled fee) ~Consulting engagement
Commercial — AMLHQ Service Options
Cost-neutral option available Available for qualifying agencies
CFO Model — compliance generates revenue Available under the CFO model
No lock-in contract Exit fee: 50% annual sub ~Annual commitment

All competitor information from publicly available sources as at June 2026: pexaclear.com.au, amlhub.com.au, firstaml.com/au, getapp.com.au. Verify directly with each vendor. ~ = partial, add-on cost, or unconfirmed — not a claim the feature is absent.

The Subscription Fee Is Not the Full Cost of Compliance

Software Platform — True Annual Cost (Single Agency, Year 1)
Platform subscription$1,200–$3,000
Compliance Officer (staff/outsourced)$8,000–$20,000
Written AML/CTF program$3,000–$8,000
Annual compliance report$1,500–$3,000
Staff training delivery$950–$2,250/session
Audit support (if required)$2,200–$5,500
Indicative true total — year one$16,000–$42,000+
AML HQ — CO Model (Managed Service, Year 1)
Setup & implementation$1,150 (one-time)
Monthly managed service$990/mo × 12 = $11,880
Annual compliance reportFrom $1,250
CO continuity, AUSTRAC liaisonIncluded
Written program, platform, audit trailIncluded
Indicative true total — year one~$14,280

Cost illustrations are estimates, not quotes or compulsory expenditure. The $14,280 base illustration excludes verification and any additional scheduled services. Staff training, enhanced due diligence and audit support may attract scheduled fees. Compare agreed service scope and total costs.

From Compliance Cost to Revenue-Generating Asset — the CFO Model

Finance returns and asset values are illustrative, depend on activity and commercial terms, and are not guaranteed. Any finance services are provided separately through EZFinance Pty Ltd, Australian Credit Licence 392611.

$209K
Indicative annual finance commission income — industry standard metrics
$120K
Indicative referred listing income per year under CFO Model
$324K
Saleable loan trail book asset over 5 years — owned by the agency
Indicative 5-year value — CFO Model $953,000+
Full Compliance
Complete AUSTRAC obligation management — CO, program, training, SMR/TTR, annual report
Group Uniformity
One CO standard applied across every office — consistent execution, one audit trail
Cost-Neutral Option
For qualifying agencies, the net ongoing compliance cost can be reduced to zero
New Revenue Stream
CFO Model adds a potential finance revenue stream alongside compliance oversight

AUSTRAC Enforcement Depends on the Conduct and Applicable Law

$36.4M
Potential maximum for applicable corporate contraventions (100,000 penalty units × $364 from 1 July 2026)
$7.28M
Potential maximum for applicable non-corporate contraventions; personal liability is not automatic
Remediation
AUSTRAC can require corrective action; its scope and cost depend on the circumstances

⚠ Illustrative governance risk: Repeated CDD, training or reporting gaps across offices can indicate systemic weaknesses requiring investigation and remediation. Counting affected offices or records does not establish the number of contraventions or penalties. Liability and any court-imposed penalty depend on the applicable provisions, structure and evidence. AUSTRAC guidance

Source: AUSTRAC guidance

The question is not whether to comply. It's whether your current approach will withstand an audit.

AMLHQ supports individual agencies, franchise networks and large groups with compliance implementation and oversight. We can assess the processes supporting an existing platform and identify where additional CO support may help. Cost recovery depends on agreed fees collected, transaction volume and the costs included.

Book a Network Assessment