$33M
Maximum civil penalty per breach — corporations (AML/CTF Act 2006, 100,000 penalty units × $330)
$6.6M
Maximum civil penalty per breach — individuals. Directors and COs face personal liability separately
$19,800
Daily fine for late AUSTRAC enrolment, per day until enrolment is completed
$15B+
Total AUSTRAC fines imposed since 2018 against Tranche 1 entities — same standards now apply

Already selected a cloud-based AML platform? Under AUSTRAC's AML/CTF Rules 2025, franchise networks and large groups face specific governance and uniformity obligations that a platform subscription alone does not fulfil — and a compliance failure at one office exposes the entire network.

What AUSTRAC Actually Requires from Your Network

01

Fit and Proper Compliance Officer — Mandatory

Every reporting entity must appoint a fit and proper AML/CTF Compliance Officer at management level, notify AUSTRAC within 14 days of appointment, and maintain that appointment at all times. The CO is personally responsible for day-to-day implementation and must be employed or engaged by the reporting entity — the statutory obligation cannot be satisfied by a software platform alone, nor by a sales agent serving in a dual role without appropriate authority and qualification.

AUSTRAC, AML/CTF Act s.26J–26L; AML/CTF Rules 2025 s.5-14. Effective 31 March 2026.
02

Reporting Groups Are Elective for Franchises — Not Automatic

A typical franchise agreement does not give the franchisor legal "control" over franchisees in the sense the Act requires — so franchise networks form what AUSTRAC calls an elective reporting group, not an automatic one. This only happens if every member agrees in writing. Any office can also opt out later, in writing, and go it alone with its own separate program.

AUSTRAC, Understanding reporting groups & Forming reporting groups (Act s.10A(1)(b); Rules s.2-2).
03

Lead Entity Liability Only Applies If You've Formally Formed the Group

AUSTRAC is explicit: if a member of a formal reporting group breaches the Act, both the lead entity and the member are considered to have contravened it. But this only applies once a group has actually been formed in writing. If your network hasn't done this — which is the case for most franchise head offices today — you are not each other's legal liability under this regime.

AUSTRAC, Obligations for lead entities and members; AUSTRAC Quick guide — reporting groups, February 2026.
04

If You Don't Form a Group, Every Office Stands Alone

If your offices don't join a reporting group, each one must develop and maintain its own separate AML/CTF program — they cannot rely on a shared or group-wide program, because none formally exists. Each office also carries its own compliance officer, its own audit exposure, and its own penalty risk, entirely independent of head office.

AUSTRAC, Understanding reporting groups.
05

CDD Completed Within Prescribed Timeframes

Customer Due Diligence must be completed within 15 calendar days of contract exchange or by settlement, whichever is earlier. Settlement pressure does not pause the obligation. Failure to complete CDD on time is a breach — not an administrative oversight. Each failure is a separate penalty event.

AML/CTF Rules 2025, Part 6; Grant Thornton, April 2026 (KYC verification extension to 28 days where verified by another transaction party).
06

SMR Lodgement — 3 Business Days. No Exceptions.

Suspicious Matter Reports must be lodged with AUSTRAC within 3 business days of suspicion arising (or within 24 hours for terrorism financing matters). Tipping off a client that a report has been filed carries a criminal penalty. This requires a qualified person making a compliance judgment — not a workflow trigger.

AML/CTF Act 2006, s.41; AUSTRAC Core Guidance, October 2025.
07

Uniform Training Records — 7 Years, Group-Wide

Staff training must be documented and maintained for 7 years across every office. Individual offices cannot set lighter training requirements independently of the group program. The CO must report to the governing body at least annually on compliance effectiveness — and training records are a primary audit target.

AML/CTF Rules 2025, s.57; AUSTRAC Compliance Officer guidance, March 2026.
08

Annual Compliance Report to AUSTRAC

An Annual AML/CTF Compliance Report must be lodged with AUSTRAC. The CO must also provide a report to the governing body at least annually. These are not optional — they are a statutory obligation and a primary mechanism by which AUSTRAC identifies under-performing networks.

AML/CTF Rules 2025, s.57; AUSTRAC, Summary of Changes for Current Reporting Entities, March 2026.
09

Independent Evaluation — Every 3 Years

The group AML/CTF program must be independently evaluated at least every 3 years, with findings reported to the lead entity's governing body. AUSTRAC's guidance is clear that an independent evaluator must be engaged — an internal review or platform-generated report alone is unlikely to satisfy this requirement. Independent means external to the reporting entity.

AML/CTF Rules 2025, Part 5; AML HQ, AML/CTF Master Guide 2026.

Two Paths for Your Network — And What Each Actually Means for Head Office

Most franchise head offices have not formally become a "lead entity" under AUSTRAC's reporting group rules. Instead, each office has been left to choose its own AML provider, its own Compliance Officer and its own program. It's worth being precise about what that actually means — in both directions.

Path A — No Formal Reporting Group (Most Networks Today)

  • Each office is its own separate reporting entity, with its own AML/CTF program, own CO and own AUSTRAC obligations
  • Head office has no formal AUSTRAC liability if one office falls short — legally, they are not each other's problem under this regime
  • But AUSTRAC's own stated approach explicitly targets "serious and/or systemic" non-compliance patterns, and enforcement actions are public
  • If several offices under the same recognisable brand are separately found non-compliant, that's a reputational risk to the network — even without shared legal liability
  • Head office typically has little to no visibility into how well (or poorly) each office is actually managing its obligations

Path B — Formal Reporting Group (Head Office as Lead Entity)

  • Requires every member office to agree in writing — franchise agreements alone don't create this automatically
  • Head office takes on real, shared legal responsibility: if a member breaches the Act, both the lead entity and the member are considered to have contravened it
  • Head office must maintain a program that reflects the size and risk profile of every member office — not just its own business
  • Real uniformity and governance become possible — but so does the exposure most franchise head offices haven't fully considered
  • Can be exited by any member opting out in writing, or the group can be built with fewer than all offices only if a business-group control relationship doesn't apply (elective groups)

Sourced directly from AUSTRAC: "In a reporting group, non-compliance by one entity may pose risks to the entire group. If a member breaches a civil penalty provision, both the lead entity and the member are considered to have contravened the AML/CTF Act." This is real, and it only applies once a group has actually been formed in writing — not automatically because you share a franchise brand.

A Third Option: Oversight Without Taking On Legal Liability

Most franchise head offices don't want the shared legal exposure of formally becoming a lead entity (Path B) — but staying completely blind to how 50 or 100 independent offices are actually managing compliance (Path A) isn't a comfortable position either, given AUSTRAC's own stated focus on systemic patterns.

AML HQ's model is built around this exact gap, with two coordinated portals:

The AML HQ Portal — For Offices That Migrate
Offices that move to AML HQ get a real, experienced Compliance Officer and a consistent program under our model — the same standard, applied the same way, for every office that joins.
The Head Office Reporting Portal — For Offices That Don't
Offices that keep their existing provider (an existing contract, or simply a preference not to move) get a separate reporting-back portal, so head office can see that compliance is actually being managed — without formally becoming their AUSTRAC lead entity.

Under this model, no office is forced to migrate. Those that stay with their current arrangement simply report their compliance status back to head office through the portal, giving your network real visibility — and an early warning if a pattern starts to look systemic — without head office taking on the formal shared liability of Path B unless it genuinely chooses to.

Uniformity Is the Standard. Diversity of Execution Is the Risk.

Whichever path your network takes, the underlying risk described below is the same one AUSTRAC has flagged repeatedly across other regulated sectors — inconsistent execution between offices is exactly the pattern regulators notice.

The reality in most franchise networks right now: your franchise has selected a cloud-based AML platform. Each franchisee has been given a login. Each office has nominated a "Responsible Manager" — typically the office principal, a senior property manager, or an experienced agent — to serve as the local compliance contact. That person has their own interpretation of the platform, their own workload, and their own judgment about what constitutes a suspicious matter. This is not a reporting group with a standardised program. This is 50 offices running 50 slightly different compliance approaches — with your brand, and your lead-entity liability, attached to all of them.

⚠ Cloud Platform + Diverse Responsible Managers

  • Each office nominates its own "Responsible Manager" — different roles, different capabilities, different risk tolerance
  • No consistent interpretation of what triggers an SMR across offices
  • Training varies by manager — one office does it quarterly, another hasn't done it since onboarding
  • CDD timeframes managed differently between offices — some miss deadlines without realising
  • EDD decisions made by sales agents under settlement pressure, not compliance professionals
  • An AUSTRAC audit covers the entire network — inconsistent records across offices create cascading exposure

✓ AML HQ — Unified CO & CFO Model

  • Dedicated, qualified Compliance Officers assigned across the network under a single unified framework — one standard, applied everywhere
  • SMR and TTR decisions made by a compliance professional, not a sales agent under time pressure
  • Group-wide training delivered and documented centrally — every office, same standard, same records
  • CDD deadline tracking managed by the CO — not left to individual office calendars
  • Annual compliance report authored and lodged — included in the managed service
  • Audit trail maintained at licence level — AUSTRAC-ready at any time, across all offices

"In a group/franchise, the real setup risk is uneven execution between offices — and regulators tend to notice. Expectations around control, documentation, consistency, and governance discipline only scale up."

AML HQ — AML/CTF Master Guide for Groups & Franchises, 2026

How Each Platform Meets AUSTRAC's Group Requirements

Legend: Confirmed available  |  Not available  |  ~ Partial / add-on cost / requires verification

Requirement / Feature AML HQ PEXA Clear AMLHUB First AML
Human Governance — AUSTRAC Mandatory Requirements
Named, fit & proper Compliance OfficerRequired within 28 days of enrolment Assigned CO — real person You provide your own CO Software only You provide your own CO
CO manages SMR/TTR lodgementsHuman judgment — not a workflow trigger CO owns end-to-end
CO continuity managed for youVacancy must be filled within 14 days AML HQ manages continuity
Annual compliance report — authored & lodged Included (scheduled fee) ~Consulting add-on ~Guidance only
Independent program evaluation — 3 yearly ~Separate engagement
Franchise & Multi-Office Group Governance
Group-wide uniformity enforced by a professional CO enforces across all offices Tool only — each user independent Dashboard per office only ~Group workflows — no CO
Audit trail at licence / network level ~Per-office only
Franchise compliance schedule for agreements Master Guide & Schedule
AUSTRAC audit representation & support Full support (scheduled fee) ~Consulting engagement
Commercial — What No Other Provider Offers
Cost-neutral option available Available for qualifying agencies
CFO Model — compliance generates revenue Unique — no competitor offers this
No lock-in contract Exit fee: 50% annual sub ~Annual commitment

All competitor information from publicly available sources as at June 2026: pexaclear.com.au, amlhub.com.au, firstaml.com/au, getapp.com.au. Verify directly with each vendor. ~ = partial, add-on cost, or unconfirmed — not a claim the feature is absent.

The Subscription Fee Is Not the Full Cost of Compliance

Software Platform — True Annual Cost (Single Agency, Year 1)
Platform subscription$1,200–$3,000
Compliance Officer (staff/outsourced)$8,000–$20,000
Written AML/CTF program$3,000–$8,000
Annual compliance report$1,500–$3,000
Staff training delivery$950–$2,250/session
Audit support (if required)$2,200–$5,500
Indicative true total — year one$16,000–$42,000+
AML HQ — CO Model (All-Inclusive, Year 1)
Setup & implementation$1,150 (one-time)
Monthly managed service$990/mo × 12 = $11,880
Annual compliance reportFrom $1,250
CO continuity, AUSTRAC liaisonIncluded
Written program, platform, audit trailIncluded
Indicative true total — year one~$14,280

From Compliance Cost to Revenue-Generating Asset — the CFO Model

$209K
Indicative annual finance commission income — industry standard metrics
$120K
Indicative referred listing income per year under CFO Model
$324K
Saleable loan trail book asset over 5 years — owned by the agency
Indicative 5-year value — CFO Model $953,000+
Full Compliance
Complete AUSTRAC obligation management — CO, program, training, SMR/TTR, annual report
Group Uniformity
One CO standard applied across every office — consistent execution, one audit trail
Cost-Neutral Option
For qualifying agencies, the net ongoing compliance cost can be reduced to zero
New Revenue Stream
CFO Model converts compliance into a positive income asset — unique in the market

AUSTRAC Does Not Give Warnings to Well-Resourced Networks

$33M
Maximum civil penalty per breach — corporations (100,000 penalty units × $330 as at Jan 2026)
$6.6M
Maximum civil penalty per breach — individuals. Directors, principals and COs face personal liability separately
25 yrs
Maximum criminal imprisonment for proceeds-of-crime offences (2–5 years for reckless ID verification failures)

⚠ What non-compliance looks like for a franchise network: a franchise of 30 offices uses a cloud platform. Each office has a different agent serving as "Responsible Manager." Over 12 months: 6 offices miss CDD deadlines under settlement pressure; 3 offices fail to document training completion; 2 offices do not recognise a suspicious transaction pattern that should have triggered an SMR. AUSTRAC conducts a network audit. It finds systemic inconsistency in program execution. The lead entity is held accountable for the program as a whole. At $33 million per breach, 11 separate failures across a 30-office network creates potential exposure of $363 million in civil penalties — before individual director liability is assessed separately.

Sources: amlhouse.com.au (August 2025); amltranche.com.au (March 2026); tranchetwoconsultants.com (March 2026); corporatealliance.com (October 2025); AML/CTF Act 2006 (Cth); AUSTRAC enforcement history (public record).

The question is not whether to comply. It's whether your current approach will withstand an audit.

AML HQ works exclusively with real estate franchise networks and large groups to build compliance programs that are uniform, defensible and — for qualifying agencies — cost-neutral. If your network has already selected a cloud platform, we can assess the gaps and show you exactly what is missing before 1 July 2026.

Book a Network Assessment