Indium OS overall brand banner
Resources>AML/CTF Guides

The Complete AML/CTF Compliance Guide for Australian Real Estate Agencies

Published 2026-06-24 · Built to AUSTRAC Standards

Australian real estate groups represent one of the final sectors being brought under the Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) net. Tracing beneficial ownership and validating digital identity is no longer an administrative option — it is a statutory federal mandate.

The Commencement Moat: Why Point-In-Time Auditing Fails

Starting 1 July 2026, real estate agencies across Australia must maintain a comprehensive, written AML/CTF program to identify and report suspicious activities. Point-in-time checks (taking a photocopy of a license at listing and saving it in a folder) fail under AUSTRAC criteria. If a check is not continuously monitored, role-gated, and tracked on a tamper-proof ledger, your agency remains exposed to audit penalties.

Pillar A vs. Pillar B: Structuring Your Written Program

A legally compliant AML program is split into two halves. Pillar A details your organizational risk assessment, staff training logs, and compliance officer governance. Pillar B mandates customer due diligence (CDD) checking. For real estate, this requires validating both vendors and active buyers before any property contract exchange or listing agreement is legally signed.

Tracing Beneficial Ownership: The 25% UBO Threshold

One of the most complex obligations is beneficial ownership vetting. When a property is listed or purchased by a company, trust, or SMSF structure, you must trace the ownership chain to identify the Ultimate Beneficial Owners (UBOs) — any individual holding 25% or more of the shares or control. Doing this manually is a massive administrative bottleneck; Indium OS automates this via ASIC registry queries in seconds.

Which real estate services are actually captured?

The designated services for real estate centre on brokering the sale, purchase or transfer of real property on behalf of a client. If your agency sells property, those transactions are captured and both vendor and purchaser sides carry obligations. Routine property management on its own — collecting rent, arranging maintenance, managing tenancies — is not a designated service, so a pure rent roll does not make you a reporting entity. Most agencies are mixed businesses, though: the sales side of a mixed agency is fully captured. AUSTRAC's Tranche 2 obligations factsheet is the authoritative summary, and our separate explainer covers the property-management boundary in detail.

When do the obligations start, and when must you enrol?

The reforms commence on 1 July 2026. From that date, providing a designated service without meeting your obligations is a contravention — there is no grace period for CDD on new transactions. Newly captured businesses must also enrol with AUSTRAC; enrolment opened in advance of commencement and must be completed within 28 days of first providing a designated service. Practically: an agency that lists a property for sale in July 2026 needs its AML/CTF program adopted, its compliance officer appointed, and its enrolment lodged before that listing settles.

What is customer due diligence, in plain terms?

CDD means knowing who your customer actually is before you act for them: collecting identity information, verifying it against reliable and independent sources, screening for politically exposed persons and sanctions, understanding ownership structures where the customer is a company or trust, and assessing the money-laundering risk of the relationship. Standard CDD applies to most matters; enhanced CDD — deeper source-of-funds and source-of-wealth enquiries — applies where risk is higher, such as foreign PEPs or opaque structures. The obligation is ongoing: a customer cleared at listing must still be monitored through settlement.

What must you report, and how fast?

Three reporting obligations matter most. Suspicious matter reports (SMRs) are due within 3 business days of forming a suspicion — 24 hours where the suspicion concerns terrorism financing. Threshold transaction reports (TTRs) are due within 10 business days for physical currency transactions of A$10,000 or more. And you must not tip off the customer that an SMR has been made or is contemplated — the tipping-off offence carries criminal penalties. Records evidencing all of it must be retained for 7 years.

What happens if an agency does nothing?

The AML/CTF Act carries civil penalties that scale far beyond what any compliance program costs, and AUSTRAC has shown — in banking, gaming and remittance — that it litigates. For a newly captured sector the more immediate risks are practical: banks de-risking agencies that cannot evidence a program, purchasers' solicitors asking questions an agency cannot answer, and the reputational cost of being the local example. The defensible position is not perfection; it is a written program, evidence of CDD actually performed, and records that show the system working.

A realistic first-90-days plan

Month one: appoint your compliance officer, adopt a written AML/CTF program proportionate to your agency's size and risk, and enrol with AUSTRAC. Month two: train everyone who touches a sales transaction, stand up your CDD workflow so identity, screening and risk assessment happen on every new matter, and run your existing pipeline through it. Month three: test the uncomfortable paths — a screening hit, an incomplete verification at exchange, an SMR drill — and fix what breaks. An agency that has done these three months of work can face any AUSTRAC enquiry with a straight back.

Disclaimer: This asset is provided for educational and scoping purposes built to AUSTRAC standards with independent legal review. Individual real estate organizations remain legally responsible for implementing and auditing their own compliance platforms to satisfy the AML/CTF Act.
Indium OS overall brand banner
AUDIT READY

Secure your agency before the deadline.

Talk with a compliance strategist to assess your pipeline and secure your written AML program today.

OFFLINE READING

Download Brief PDF

Download a secure, audit-vetted PDF copy of this compliance asset for offline review.