For Franchise Networks & Large Groups
AML/CTF Compliance
Requires More Than
a Subscription.
What AUSTRAC actually demands from franchise networks and large groups — and why a platform subscription alone is not enough.
AUSTRAC Tranche 2 — 1 July 2026
Reporting Groups — AML/CTF Rules 2025
June 2026
$36.4M
Maximum civil penalty per breach — corporations
AML/CTF Act 2006 (Cth), 100,000 penalty units from 1 July 2026
$7.28M
Maximum civil penalty per breach — individuals
Directors and COs face personal liability separately
$19,800
Daily fine for late AUSTRAC enrolment
Per day until enrolment is completed
$15B+
Total AUSTRAC fines imposed since 2018 against
Tranche 1 entities — same standards now apply
⚠
Already selected a cloud-based AML platform? Read this before you go live. Under AUSTRAC's AML/CTF Rules 2025, franchise networks and large groups face specific governance and uniformity obligations that a platform subscription alone does not fulfil — and a compliance failure at one office exposes the entire network.
The Regulatory Framework
What AUSTRAC Actually Requires
from Your Network
From 1 July 2026, every agency in your network facilitating property sales or managing trust accounts becomes a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). This is not a registration exercise — it is a continuous compliance obligation with direct personal liability for principals, directors and Compliance Officers.
The AML/CTF Rules 2025 introduced a specific Reporting Group framework for connected businesses and franchise networks. The key change effective 31 March 2026: related entities in a corporate group or control structure automatically form a reporting group unless they formally opt out in writing. Most franchise networks are already inside a reporting group — whether they know it or not.
REQUIREMENT 01
Fit and Proper Compliance Officer — Mandatory
Every reporting entity must appoint a fit and proper AML/CTF Compliance Officer at management level, notify AUSTRAC within 14 days of appointment, and maintain that appointment at all times. The CO is personally responsible for day-to-day implementation and must be employed or engaged by the reporting entity — the statutory obligation cannot be satisfied by a software platform alone, nor by a sales agent serving in a dual role without appropriate authority and qualification.
AUSTRAC, AML/CTF Act s.26J–26L; AML/CTF Rules 2025 s.5-14. Effective 31 March 2026.
REQUIREMENT 02
One Program — Standardised Across All Offices
Under a reporting group, the lead entity's AML/CTF program applies to every member office. Training, CDD, EDD, reporting and evaluations must be standardised group-wide. A business group cannot form a reporting group with only some of its members — it is all or nothing.
AML/CTF Rules 2025, Part 2; AUSTRAC Core Guidance, October 2025; Norton Rose Fulbright analysis, Rule 2-1 and 2-2.
REQUIREMENT 03
Lead Entity — Active Governance, Not Passive Oversight
The lead entity must be nominated in writing, must have real authority to set and enforce AML/CTF policy, and must actively govern the program for all members. Passive oversight converts efficiency into liability. AUSTRAC can sanction a non-compliant office, but the lead entity remains accountable for the program as a whole.
AML/CTF Rules 2025, Part 2; First AML, Reporting Groups for Real Estate Sector, September 2025.
REQUIREMENT 04
CDD Completed Within Prescribed Timeframes
Customer Due Diligence must be completed within 15 calendar days of contract exchange or by settlement, whichever is earlier. Settlement pressure does not pause the obligation. Failure to complete CDD on time is a breach — not an administrative oversight. Each failure is a separate penalty event.
AML/CTF Rules 2025, Part 6; Grant Thornton, April 2026 (KYC verification extension to 28 days where verified by another transaction party).
REQUIREMENT 05
SMR Lodgement — 3 Business Days. No Exceptions.
Suspicious Matter Reports must be lodged with AUSTRAC within 3 business days of suspicion arising (or within 24 hours for terrorism financing matters). Tipping off a client that a report has been filed carries a criminal penalty. This requires a qualified person making a compliance judgment — not a workflow trigger.
AML/CTF Act 2006, s.41; AUSTRAC Core Guidance, October 2025.
REQUIREMENT 06
Uniform Training Records — 7 Years, Group-Wide
Staff training must be documented and maintained for 7 years across every office. Individual offices cannot set lighter training requirements independently of the group program. The CO must report to the governing body at least annually on compliance effectiveness — and training records are a primary audit target.
AML/CTF Rules 2025, s.57; AUSTRAC Compliance Officer guidance, March 2026.
REQUIREMENT 07
Annual Compliance Report to AUSTRAC
An Annual AML/CTF Compliance Report must be lodged with AUSTRAC. The CO must also provide a report to the governing body at least annually. These are not optional — they are a statutory obligation and a primary mechanism by which AUSTRAC identifies under-performing networks.
AML/CTF Rules 2025, s.57; AUSTRAC, Summary of Changes for Current Reporting Entities, March 2026.
REQUIREMENT 08
Independent Evaluation — Every 3 Years
The group AML/CTF program must be independently evaluated at least every 3 years, with findings reported to the lead entity's governing body. AUSTRAC's guidance is clear that an independent evaluator must be engaged — an internal review or platform-generated report alone is unlikely to satisfy this requirement. Independent means external to the reporting entity.
AML/CTF Rules 2025, Part 5; AML HQ, AML/CTF Master Guide 2026.
⚠ One Failure Exposes the Entire Group
Under the reporting group framework, a compliance failure at a single office — a missed CDD deadline, an unfiled SMR, inadequate training records — is not contained to that office. The lead entity is accountable for the program as a whole. AUSTRAC can sanction the non-compliant office and hold the network's lead entity responsible. Each incident is assessed as a separate breach, each carrying its own penalty. With 20, 50, or 100 offices in your network, exposure is not linear — it is multiplicative.
Sources: AUSTRAC.gov.au; AML/CTF Act 2006 (Cth); AML/CTF Rules 2025; First AML Reporting Groups analysis (Sept 2025); Hall & Wilcox, AUSTRAC Core Guidance summary (Oct 2025); Grant Thornton, April 2026.
The Critical Problem
Uniformity Is the Standard.
Diversity of Execution Is the Risk.
AUSTRAC is explicit: the group program must be standardised and consistently executed across every office. This is where a platform subscription alone, without embedded human expertise enforcing group-wide standards, creates a governance risk in a franchise or multi-office environment — and where most franchise groups that have already selected a software tool may have an unaddressed gap.
The Reality in Most Franchise Networks Right Now
Your franchise has selected a cloud-based AML platform. Each franchisee has been given a login. Each office has nominated a "Responsible Manager" — typically the office principal, a senior property manager, or an experienced agent — to serve as the local compliance contact. That person has their own interpretation of the platform, their own workload, and their own judgment about what constitutes a suspicious matter. This is not a reporting group with a standardised program. This is 50 offices running 50 slightly different compliance approaches — with your brand, and your lead-entity liability, attached to all of them.
⚠ Cloud Platform + Diverse Responsible Managers
The Uniformity Gap
- Each office nominates its own "Responsible Manager" — different roles, different capabilities, different risk tolerance
- No consistent interpretation of what triggers an SMR across offices
- Training varies by manager — one office does it quarterly, another hasn't done it since onboarding
- CDD timeframes managed differently between offices — some miss deadlines without realising
- EDD decisions made by sales agents under settlement pressure, not compliance professionals
- Annual compliance report requires someone to author it — the platform doesn't do this
- An AUSTRAC audit covers the entire network — inconsistent records across offices create cascading exposure
- If the nominated manager leaves, the compliance function is vacant — AUSTRAC must be notified within 14 days
- Software logs actions but doesn't enforce quality, judgment, or governance discipline
✓ AML HQ — Unified CO & CFO Model
Built-In Uniformity
- Dedicated, qualified Compliance Officers assigned across the network under a single unified framework — one standard, applied everywhere. Smaller groups (up to ~20 offices) typically operate with one CO; larger networks of 30+ offices are supported by a scalable CO infrastructure, all operating independently under the same program, platform and compliance methodology. Available upon application.
- SMR and TTR decisions made by a compliance professional, not a sales agent under time pressure
- Group-wide training delivered and documented centrally — every office, same standard, same records
- CDD deadline tracking managed by the CO — not left to individual office calendars
- EDD triggered automatically and managed by the CO, with documented decisions
- Annual compliance report authored and lodged — included in the managed service
- Audit trail maintained at licence level — AUSTRAC-ready at any time, across all offices
- CO continuity managed by AML HQ — vacancy does not fall to the franchisor to resolve
- Platform + human governance = actual uniformity, not the appearance of it
"In a group/franchise, the real setup risk is uneven execution between offices — and regulators tend to notice. Expectations around control, documentation, consistency, and governance discipline only scale up."
AML HQ — AML/CTF Master Guide for Groups & Franchises, 2026
Platform Comparison
How Each Platform Meets
AUSTRAC's Group Requirements
Legend: ✓ Confirmed available | ✗ Not available | ~ Partial / add-on cost / requires verification
| Requirement / Feature |
AML HQ Agency |
PEXA Clear |
AMLHUB |
First AML |
| Human Governance — AUSTRAC Mandatory Requirements |
| Named, fit & proper Compliance OfficerRequired by AUSTRAC within 28 days of enrolment |
✓Assigned CO — real person |
✗You provide your own CO |
✗Software only |
✗You provide your own CO |
| CO manages SMR/TTR lodgementsHuman judgment — not a workflow trigger |
✓CO owns end-to-end |
✗ |
✗ |
✗ |
| CO continuity managed for youVacancy must be filled — AUSTRAC notified within 14 days |
✓AML HQ manages continuity |
✗ |
✗ |
✗ |
| Annual compliance report — authored & lodgedStatutory obligation — requires a qualified person to author it |
✓Included (scheduled fee) |
✗ |
~Consulting add-on |
~Guidance only |
| Independent program evaluation — 3 yearlyRequired under AML/CTF Rules 2025 |
✓ |
✗ |
~Separate engagement |
✗ |
| Franchise & Multi-Office Group Governance |
| Group-wide uniformity enforced by a professionalAUSTRAC requires consistent execution — not just access |
✓CO enforces across all offices |
✗Tool only — each user independent |
✗Dashboard per office only |
~Group workflows — no CO |
| Audit trail at licence / network levelAUSTRAC audits the network — not just the branch |
✓ |
✗ |
~Per-office only |
✓ |
| Tiered supervision — 25+ staff / multi-branchCentralised reporting + monthly audit sampling |
✓ |
✗ |
✗ |
~Platform support only |
| Franchise compliance schedule for agreementsLegally structured document for franchise agreements |
✓Master Guide & Schedule |
✗ |
✗ |
✗ |
| Staff training delivery — uniform across networkNot just a module — documented group-wide delivery |
✓Included + add-on sessions |
~REIQ partnership |
~Separate engagement |
~Separate engagement |
| AUSTRAC audit representation & supportSupport when AUSTRAC conducts an audit |
✓Full support (scheduled fee) |
✗ |
~Consulting engagement |
✗ |
| Platform, CDD & Compliance Workflows |
| Written AML/CTF program (Part A & B)Tailored per agency — not a generic template |
✓Tailored & maintained |
✗ |
~Consulting add-on |
~Framework support only |
| Digital identity verification (KYC/KYB)Individuals, companies, trusts, SMSFs |
✓GreenID — ISO 27001 |
✓FrankieOne — ISO 27001 |
✓ |
✓Incl. foreign & SMSF |
| PEP, sanctions & adverse media screening |
✓ |
✓ |
✓ |
✓ |
| Enhanced Due Diligence (EDD) — auto-triggeredOffshore buyers, PEPs, complex structures |
✓CO manages EDD decisions |
~Risk flagging only |
✓ |
✓ |
| Ongoing monitoring across transaction lifecycle |
✓ |
✓Key differentiator |
✓ |
✓ |
| 7-year record retention — Australian hostedMandatory under AML/CTF Act s.107 |
✓Sydney — confirmed |
~Confirm in writing |
~Exit fee for retention |
~Abandoned cases billed |
| Commercial — What No Other Provider Offers |
| Cost-neutral option availableNet compliance cost can be reduced to zero |
✓Available for qualifying agencies |
✗ |
✗ |
✗ |
| CFO Model — compliance generates revenueEmbedded licensed finance manager — unique in market |
✓Unique — no competitor offers this |
✗ |
✗ |
✗ |
| No lock-in contract |
✓ |
✓ |
✗Exit fee: 50% annual sub |
~Annual commitment |
All competitor information from publicly available sources as at June 2026: pexaclear.com.au, amlhub.com.au, firstaml.com/au, getapp.com.au. Verify directly with each vendor. ~ = partial, add-on cost, or unconfirmed — not a claim that the feature is absent.
The Commercial Case
The Subscription Fee Is Not
the Full Cost of Compliance.
The true cost of AML/CTF compliance is not the platform subscription. It is the total cost of meeting every AUSTRAC obligation — including the Compliance Officer, the written program, the annual report, the training delivery, and the audit support. When these are factored in, a subscription-only approach requires the agency to separately fund significant additional obligations — and when that total is compared to AML HQ's all-inclusive managed service, the difference is clear. For qualifying agencies, AML HQ can be structured to be effectively cost-neutral.
Platform subscription$1,200 – $3,000
Compliance Officer (staff / outsourced)$8,000 – $20,000
Written AML/CTF program (legal / consultant)$3,000 – $8,000
Annual compliance report$1,500 – $3,000
Staff training delivery$950 – $2,250/session
Audit support (if required)$2,200 – $5,500
Indicative true total — year one$16,000 – $42,000+
Setup & implementation$1,150 (one-time)
Monthly managed service (CO Model)$990/mo × 12 = $11,880
Annual compliance reportFrom $1,250
Staff training, audit support, EDD — availableScheduled fees
CO continuity, AUSTRAC liaison, SMR/TTR managementIncluded
Written program, platform, audit trailIncluded
Indicative true total — year one~$14,280
Cost-Neutral Option Available for Qualifying Agencies — Ask Us How
Indicative figures only. Software-only costs based on market rate analysis for outsourced AML compliance services, legal program authoring, and consulting rates. All figures ex GST. AML HQ figures from published fee schedule.
The CFO Model — Unique to AML HQ
From Compliance Cost to
Revenue-Generating Asset
The CFO (Compliance & Finance Officer) Model is available exclusively through AML HQ. By embedding a licensed Finance Manager who simultaneously manages AML/CTF compliance and builds a mortgage broking revenue stream under your brand, compliance cost is not merely reduced — it is converted into a commercial asset. No other AML/CTF provider in Australia offers anything comparable.
$209K
Indicative annual finance commission income — industry standard metrics
$120K
Indicative referred listing income per year under CFO Model
$324K
Saleable loan trail book asset over 5 years — owned by the agency
Indicative 5-Year Value — CFO Model
Individual results will vary. Based on industry-standard metrics. Compliance cost offsets included.
$953,000+
🔐
Full Compliance
Complete AUSTRAC obligation management — CO, program, training, SMR/TTR, annual report
🏢
Group Uniformity
One CO standard applied across every office — consistent execution, one audit trail
💰
Cost-Neutral Option
For qualifying agencies, the net ongoing compliance cost can be reduced to zero
📈
New Revenue Stream
CFO Model converts compliance into a positive income asset — unique in the market
Risk & Enforcement
AUSTRAC Does Not Give Warnings
to Well-Resourced Networks.
AUSTRAC has imposed over $15 billion in penalties against Australian financial institutions since 2018 — including $1.3 billion against Westpac and $700 million against CBA. These were not small operators with poor intentions. They were well-resourced institutions with established compliance teams that had systemic gaps. AUSTRAC has explicitly signalled the same enforcement standards apply to Tranche 2 entities from 1 July 2026.
$36.4M
Maximum civil penalty per breach — corporations (100,000 penalty units, effective 1 July 2026)
Each missed CDD, each unfiled SMR, each inadequate training record is a separate breach event
$7.28M
Maximum civil penalty per breach — individuals. Directors, principals and Compliance Officers face personal liability separate from the corporate penalty
A corporate fine does not shield the individual — they can both be penalised for the same failure
25 yrs
Maximum criminal imprisonment — proceeds of crime offences. 2–5 years for reckless identity verification failures
Criminal liability is not theoretical. AUSTRAC has prosecuted individuals in other regulated sectors
⚠ What Non-Compliance Looks Like for a Franchise Network
A franchise of 30 offices uses a cloud platform. Each office has a different agent serving as "Responsible Manager." Over 12 months: 6 offices miss CDD deadlines under settlement pressure; 3 offices fail to document training completion; 2 offices do not recognise a suspicious transaction pattern that should have triggered an SMR. AUSTRAC conducts a network audit. It finds systemic inconsistency in program execution. The lead entity is held accountable for the program as a whole. At $33 million per breach, 11 separate failures across a 30-office network creates potential exposure of $363 million in civil penalties — before individual director liability is assessed separately. The business may be required to engage a court-appointed compliance administrator. Operations may be disrupted. Reputational damage is immediate and public.
- AUSTRAC enforcement actions are public — media coverage of a real estate franchise penalty would be immediate and damaging to brand value, vendor relationships and property management revenue
- Enforceable undertakings require mandatory remediation at the network's cost — typically $200,000 to $500,000+ for a mid-sized franchise
- Increased regulatory supervision following an enforcement action means AUSTRAC has enhanced oversight of your network for years — affecting operations and additional compliance costs
- A compliance failure during a property transaction can delay or void settlement — creating legal exposure to vendors, purchasers and financiers simultaneously with the AUSTRAC matter
Sources: amlhouse.com.au (August 2025); amltranche.com.au (March 2026); tranchetwoconsultants.com (March 2026); corporatealliance.com (October 2025); AML/CTF Act 2006 (Cth); AUSTRAC enforcement history (public record).
The question is not whether to comply.
The question is whether your current approach will withstand an audit.
AML HQ works exclusively with real estate franchise networks and large groups to build compliance programs that are uniform, defensible and — for qualifying agencies — cost-neutral. If your network has already selected a cloud platform, we can assess the gaps and show you exactly what is missing before 1 July 2026.