Executive Summary

From 1 July 2026, Australian real estate agencies became regulatory reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). The industry's response has been predictable: a flood of cloud-based compliance software, marketed with phrases like "fully AUSTRAC compliant" and "enterprise-grade compliance at a fraction of the cost".

What hasn't changed: what AUSTRAC actually requires of a reporting entity. And what AUSTRAC requires is not a software subscription. It is a compliance program — documented, evidenced, professionally managed, and led by a named human being who is personally accountable.

The Core Principle: A software platform can log information. A software platform cannot hold a compliance officer position. A software platform cannot make a judgment call about a Suspicious Matter Report. A software platform cannot defend your agency to AUSTRAC. A person has to.

This guide is written for principals, franchisors, directors and other decision-makers in real estate. It explains what the law actually asks of you, what the gap looks like between software-only compliance and genuine compliance, and how to assess whether your current solution would survive an AUSTRAC audit or an enforcement action.

The Regulatory Shift: What Changed on 1 July 2026

The Anti-Money Laundering and Counter-Terrorism Financing Act has been law for two decades. For most of that time, real estate was an anomaly: an industry sitting at the top of the money-laundering risk hierarchy with zero regulatory obligations whatsoever. Banks, casinos, remittance dealers — all regulated since 2006. Real estate — completely unregulated until now.

That gap was not accidental. The Financial Action Task Force, the international standard-setter on anti-money laundering, flagged Australia as an outlier for leaving its real estate sector unregulated. Years of international pressure, multiple government reviews, and eventually a bill finally passed in late 2024 — and the obligations commenced on 1 July 2026.

The Eight Core Requirements

1

Tailored AML/CTF Program

A written program specific to your agency's actual risk profile — not a generic template downloaded from a website.

2

Named Compliance Officer

A designated, fit-and-proper person, appointed and named to AUSTRAC, personally responsible for your compliance program and holding that role with sufficient seniority.

3

Customer Due Diligence

Identity verification completed before your designated service begins, risk-based and proportionate, with enhanced checks for higher-risk clients.

4

Ongoing Monitoring

Continuous assessment of client relationships for compliance risk — risk isn't fixed at the start of a transaction, it can change.

5

Threshold Transaction Reports

TTRs must be lodged within ten business days for cash transactions of $10,000 or more — AUSTRAC demands these be filed promptly and correctly.

6

Suspicious Matter Reports

Once reasonable suspicion is formed, an SMR must be lodged within the applicable statutory timeframe — generally within 3 business days, or within 24 hours for terrorism-financing suspicions. The obligation is triggered by the suspicion, but the timeframe is statutory, not immediate.

7

Seven-Year Record Keeping

All records related to your compliance program must be kept for a minimum of seven years, secure, searchable, and producible on request to AUSTRAC within 10 business days.

8

Staff Training & Independent Review

Documented, current staff training on your program (not outsourced awareness-raising), plus an independent triennial review of your whole compliance operation.

The Software-Only Problem

Over the past eighteen months, a compliance-software industry has sprung up around real estate, with marketing promises of "enterprise-grade compliance" from a cloud dashboard. None of this is malicious. The products are often genuine tools. The problem is that a tool is not a program, and a program is what the law requires.

What Software Can Do

What Software Cannot Do

The Critical Gap: AUSTRAC's expectation is that somewhere in your agency is a real human being, with a real name, with real professional accountability, who can walk an auditor through your program file by file and explain every decision that was made. A software dashboard cannot do that. That is why AUSTRAC requires a named Compliance Officer, not a software subscription.

The Big Bank Precedent

Real estate principals often assume that if they have a software platform and some policies, they will be fine. The finance sector has already shown what that assumption looks like in practice:

$700M
Commonwealth Bank, 2018 — 53,750 breaches of AML/CTF Act
$1.3B
Westpac, 2020 — 23 million breaches of AML/CTF reporting

These were not small banks run by people who didn't care. These were Australia's largest financial institutions, with compliance departments in the hundreds, legal teams, risk committees, and systems built by professionals. They had software. They had policies. They had people. And they still got caught out at a scale that should terrify any real estate business relying on software alone.

The reason: their programs failed because nobody was personally accountable for ensuring the program actually ran as designed. Decisions were delegated to junior staff without proper oversight. Flags were raised but not acted on. Accountability was diffused across so many people that nobody was actually responsible.

The Compliance Program vs. The Software Platform

Aspect Software-Only Approach Genuine Compliance Program
Accountability Diffused across multiple users; no single person accountable Named Compliance Officer, personally accountable to AUSTRAC
Decision-Making Based on automated flags and rules; human judgment is often absent Professional judgment applied to each file; decisions documented and defensible
Program Tailoring Standard template applied; same for all users Program written specifically for your agency's actual risks
Escalation Flags sit in a dashboard until someone manually reviews them Structured escalation with a named person responsible for each level
AUSTRAC Audit Difficult to explain why decisions were made; audit trail is incomplete Clear, documented reasoning for every decision; full audit trail available
Regulatory Exposure High — lack of named accountability creates systemic risk Lower — clear accountability chain and documented decision-making

The Business Governance Principle

This isn't really about AML/CTF compliance. It's about business governance. The principle that applies to every regulated business is straightforward: the people who own a business remain accountable for the regulatory obligations that business carries.

That accountability cannot be outsourced to a software vendor. It cannot be delegated to the cheapest staff member. It must be held by someone within the business who has the authority, the knowledge, and the personal responsibility to ensure the program runs as designed.

Good Businesses Don't Become Successful Because They Avoid Risk. They become successful because they understand risk, manage it, and continuously improve. That principle — understand it, manage it, improve it — is exactly what a compliance program demands. A software login is not managing risk. A real person, with accountability, managing a documented program — that is managing risk.

What Happens If You Get This Wrong

The Regulatory Spectrum

AUSTRAC's enforcement actions range from informal warnings through to civil penalties running into tens of millions of dollars. Here's what the regulatory spectrum looks like:

⚠ Real Numbers, Real Risk: A 30-office agency using a cloud platform as its sole compliance mechanism might look compliant. If AUSTRAC audits that network and finds: 6 offices missing customer due diligence deadlines; 3 offices with incomplete training records; 2 offices failing to identify a suspicious transaction pattern — that's 11 separate breaches. At $33 million per breach for a corporation, that's potential exposure of $363 million in civil penalties, before personal director liability is assessed separately.

The Principal's Accountability

It's important to understand that AUSTRAC holds the principal accountable — not the software vendor, not the cloud provider, not a compliance contractor who doesn't have accountability baked into their arrangement. You do.

This is true whether you're a sole trader with one office or a 40-office franchise network. The same law applies. No exemptions for size, no exemptions for "not knowing", no exemptions for having "trusted" a software vendor.

Building a Defensible Compliance Program

A defensible program has four essential components:

1. A Named, Accountable Compliance Officer

Not a role assigned to the busiest person available. Not a title given to the finance manager as an add-on. A real person, with time allocated, with seniority within the business, with the authority to make decisions and the responsibility for the outcome.

2. A Tailored, Written Program

Not a downloaded template. A program that reflects your agency's actual risks: the markets you operate in, the client base you serve, the transaction volume, the types of transactions, the risk profile of your staff. A program that's specific to you.

3. Systems That Support The Program

Software can be part of this, but it is not the whole of it. Systems include: documented procedures, escalation pathways, training schedules, record-keeping protocols, decision-making frameworks — all of which support a real human being in executing the program consistently.

4. Evidence That The Program Actually Ran

Files reviewed, decisions documented, Suspicious Matter Reports lodged, training completed, meetings held. Audit trails showing that the program was not just written down, but executed, monitored, and continuously improved.

Your Next Step

AUSTRAC won't be waiting for you to get this right. The deadline has passed. Agencies are now under active regulatory scrutiny, and the first enforcement actions are beginning. If your current compliance arrangement relies on a software login as its core accountability mechanism, you are materially exposed.

The question isn't whether to comply — it's whether your current approach will survive an audit.

Book a Compliance Assessment

Disclaimer: This guide is provided for general information and educational purposes only. It does not constitute legal, financial, regulatory, or compliance advice. Real estate agencies are required to comply with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), administered by AUSTRAC. All reporting entities should seek independent professional advice tailored to their specific circumstances. Penalty figures and enforcement data cited are drawn from publicly available AUSTRAC information current at time of publication. Business Advice Agency Pty Ltd (ABN 56 637 480 132), trading as AMLHQ, is prepared by AUSTRAC-compliant advisors working with AML HQ. Australian Credit Licence 392611 held by EZFinance Pty Ltd.