AML/CTF Australia
Jul 02, 2026
8min read

AML/CTF Compliance Checklist for Australian Real Estate Agencies (2026)

AML/CTF Compliance Checklist for Australian Real Estate Agencies

If you're running a real estate agency in Australia and you haven't yet looked closely at your AML/CTF obligations, July 2026 is not a date you want to discover the hard way.

The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 has fundamentally changed who AUSTRAC regulates. Real estate agents, property developers, and conveyancers now sit inside that regulatory boundary — and the full weight of compliance obligations applies from 1 July 2026 as part of Australia's Tranche 2 reforms.

This isn't bureaucratic paperwork. Property has long been identified globally as one of the most commonly exploited sectors for money laundering. Australia has been one of the last jurisdictions among Financial Action Task Force (FATF) member countries to close this gap. That gap is now closing fast.

This checklist is for agency principals, compliance leads, and property professionals who want to understand what's required and how to meet it — practically and clearly.


Why Real Estate Has Been a Target

Consider a scenario that financial intelligence agencies have documented repeatedly across multiple countries: an overseas buyer purchases a high-value property in a major city using funds routed through a series of company and trust structures. The source of funds is never questioned, the transaction settles quickly, and the asset is later sold at market value — converting illicit funds into legitimate capital.

Australia's real estate market, particularly in Sydney and Melbourne, has attracted scrutiny from bodies including AUSTRAC and international law enforcement for exactly this kind of exposure. The Tranche 2 reforms directly address it.


Who Is Now a Reporting Entity Under Tranche 2?

If your real estate business provides one or more designated services with a geographical link to Australia, you now have AML/CTF obligations. This applies if you broker the sale, purchase, or transfer of real estate on behalf of a buyer, seller, transferee, or transferor in the course of carrying on a business.

This includes agents, developers, and conveyancers involved in buying, selling, or transferring property linked to Australia. When a real estate agent acts for the seller and brokers a successful sale, their customer is considered both the buyer and the seller — meaning AML/CTF obligations apply to both parties.

It's also worth noting that a transaction doesn't need to involve a payment to trigger AML/CTF duties. A conveyancer helping a parent transfer the family home to a child without consideration may still be providing a designated service relating to real estate.

Not everything is captured, though. Leases of 30 years or less, easements, restrictive covenants, and personal or family transfers not carried out as part of a business are excluded.


The Core AML/CTF Compliance Checklist for Real Estate Agencies

☑ 1. Enrol With AUSTRAC

This is the foundational step and it cannot be skipped. Enrolment with AUSTRAC opened from 31 March 2026, and entities must apply within 28 days of commencing designated services from 1 July 2026. Failure to enrol is a civil penalty violation under the AML/CTF Act.

Agencies that were already enrolled as reporting entities for other services should confirm their enrolment covers real estate designated services specifically.


☑ 2. Appoint an AML/CTF Compliance Officer

Your AML/CTF governance structure must clearly identify three roles: the governing body (which has primary responsibility for governance and executive decisions), a senior manager or managers who approve AML/CTF programs and compliance decisions, and an AML/CTF compliance officer who manages day-to-day compliance and ensures policies are implemented.

If you were enrolled as a reporting entity on 30 March 2026, you must notify AUSTRAC of your compliance officer by 30 May 2026. For newly regulated businesses, you must notify AUSTRAC within 14 days of appointment once the transitional period ends.

In smaller agencies, one person may carry multiple roles — but the roles themselves must be defined and documented.


☑ 3. Complete a Money Laundering and Terrorism Financing (ML/TF) Risk Assessment

An AML/CTF program must include a risk assessment — you must identify and assess your money laundering, terrorism financing, and proliferation financing risks. This is tailored to your specific business type, customer base, transaction types, and geographic exposure.

For real estate agencies, this means thinking carefully about which transaction types carry heightened risk. High-value cash-adjacent transactions, overseas buyers using complex company or trust structures, and transactions where the source of funds isn't clear are all areas that require closer scrutiny in your risk assessment.

Agencies that primarily handle straightforward residential sales in established suburbs will have a different risk profile to those working in off-the-plan developments or handling significant volumes of investment property for overseas clients.


☑ 4. Develop and Implement an AML/CTF Program

You must establish and maintain a written AML/CTF program tailored to your business's risk profile. The program must comprise two elements: an ML/TF risk assessment and AML/CTF policies covering customer due diligence, ongoing monitoring, suspicious matter reporting, and record-keeping.

AUSTRAC has made a free starter program available that agencies can customise for their business. This is particularly useful for smaller agencies that don't have the resources to build a program from scratch.

The program isn't a document that gets filed away. It needs to reflect how your agency actually operates and be reviewed and updated when your business changes or when new regulatory guidance is issued.


☑ 5. Conduct Customer Due Diligence (CDD) on Every Transaction

Customer due diligence is the practical engine of AML/CTF compliance. It's where agencies will spend most of their day-to-day compliance effort.

The AML/CTF regime is risk-based, which means not all transactions are treated the same way. The level of due diligence required depends on the risk level identified, and staff need to understand when additional checks are required.

At minimum, CDD involves:

  • Collecting and verifying the identity of buyers and sellers (KYC — Know Your Customer)
  • Verifying the beneficial ownership of companies, trusts, or other entities involved
  • Assessing the source of funds for higher-risk transactions
  • Screening customers against relevant sanctions and politically exposed persons (PEP) lists

New ongoing CDD obligations applied to all customers from 31 March 2026. Any operational overlap should be temporary, documented, and controlled.

An overseas buyer using a shelf company with obscure ownership structure to purchase a $4 million apartment without clear explanation of fund origins is not a standard transaction. It's a red flag, and your CDD process should be designed to catch it.


☑ 6. Monitor Transactions on an Ongoing Basis

CDD doesn't stop at the start of a transaction. You will be expected to monitor transactions throughout their lifecycle. This includes identifying changes in ownership structures, unusual payment patterns, or situations where new information raises questions about the original risk assessment.

If a transaction you assessed as low-risk at the beginning starts showing characteristics that weren't initially apparent — new parties entering the transaction, funds being redirected, ownership structures changing — your monitoring process needs to detect that and trigger a reassessment.


☑ 7. Submit Suspicious Matter Reports (SMRs) to AUSTRAC

When your due diligence or monitoring process raises genuine concern that a transaction may involve money laundering or terrorism financing, you have a legal obligation to report it to AUSTRAC via a Suspicious Matter Report. This obligation applies regardless of whether the transaction ultimately proceeds or not.

Critically, tipping off a customer that they are the subject of a suspicious matter report is also a criminal offence. Staff need to understand this clearly.

AUSTRAC's published risk insights and indicators for the real estate sector provide practical guidance on what suspicious activity looks like in property transactions — this is worth reviewing as part of your staff training.


☑ 8. Train Your Staff

Preparing your personnel is critical. You must provide AML/CTF training to make sure personnel understand your AML/CTF obligations and know how to follow your policies, procedures, and systems so they can identify, manage, and mitigate ML/TF risks.

Training isn't a once-off exercise. It should be refreshed when the law changes, when your internal program is updated, or when staff take on new roles involving compliance responsibilities.

The AML/CTF Compliance for Real Estate Professionals at Australian Compliance Training is purpose-built for Australian legislative requirements, covering customer due diligence, suspicious matter reporting, transaction monitoring, and FATF framework alignment. It's practical, self-paced, and designed for real workplace application — which is exactly what agencies need when getting staff up to speed before enforcement begins in earnest.


☑ 9. Maintain Records for Seven Years

Every verification, screening result, and case decision must be logged, and the default retention requirement is seven years — aligning with AUSTRAC's record-keeping obligation.

Records need to be accessible if AUSTRAC requests them. That means a documented process for how records are stored, who can access them, and how they're retrieved. A spreadsheet managed by one person who changes roles isn't an adequate system for a regulated entity.


☑ 10. Review and Audit Your Program Regularly

An AML/CTF program that isn't reviewed is not a functioning program. Regulators are prioritising the experiences of consumers and members over mere review of documented compliance systems — organisations need to implement regular reviews to align with evolving regulatory standards.

For real estate agencies, this means scheduling annual reviews of your risk assessment and program policies, keeping across AUSTRAC guidance updates, and building in a mechanism for staff to flag compliance concerns without fear of consequences.


What Happens If You Don't Comply?

Non-compliance may result in AUSTRAC enforcement action, including significant financial penalties and increased audit or supervision. Australia has demonstrated in the financial services sector that it is willing to impose penalties running into the hundreds of millions for sustained compliance failures. Real estate agencies shouldn't assume their scale protects them — AUSTRAC has a track record of acting across all entity sizes when obligations are clearly breached.

Beyond penalties, non-compliance exposes an agency to the reputational consequences of being publicly linked to money laundering investigations — a risk no business in the trust-dependent property sector can afford.