Already selected a cloud-based AML platform? Under AUSTRAC's AML/CTF Rules 2025, franchise networks and large groups face specific governance and uniformity obligations that a platform subscription alone does not fulfil — and a compliance failure at one office exposes the entire network.
What AUSTRAC Actually Requires from Your Network
Fit and Proper Compliance Officer — Mandatory
Every reporting entity must appoint a fit and proper AML/CTF Compliance Officer at management level, notify AUSTRAC within 14 days of appointment, and maintain that appointment at all times. The CO is personally responsible for day-to-day implementation and must be employed or engaged by the reporting entity — the statutory obligation cannot be satisfied by a software platform alone, nor by a sales agent serving in a dual role without appropriate authority and qualification.
Reporting Groups Are Elective for Franchises — Not Automatic
A typical franchise agreement does not give the franchisor legal "control" over franchisees in the sense the Act requires — so franchise networks form what AUSTRAC calls an elective reporting group, not an automatic one. This only happens if every member agrees in writing. Any office can also opt out later, in writing, and go it alone with its own separate program.
Lead Entity Liability Only Applies If You've Formally Formed the Group
AUSTRAC is explicit: if a member of a formal reporting group breaches the Act, both the lead entity and the member are considered to have contravened it. But this only applies once a group has actually been formed in writing. If your network hasn't done this — which is the case for most franchise head offices today — you are not each other's legal liability under this regime.
If You Don't Form a Group, Every Office Stands Alone
If your offices don't join a reporting group, each one must develop and maintain its own separate AML/CTF program — they cannot rely on a shared or group-wide program, because none formally exists. Each office also carries its own compliance officer, its own audit exposure, and its own penalty risk, entirely independent of head office.
CDD Completed Within Prescribed Timeframes
Customer Due Diligence must be completed within 15 calendar days of contract exchange or by settlement, whichever is earlier. Settlement pressure does not pause the obligation. Failure to complete CDD on time is a breach — not an administrative oversight. Each failure is a separate penalty event.
SMR Lodgement — 3 Business Days. No Exceptions.
Suspicious Matter Reports must be lodged with AUSTRAC within 3 business days of suspicion arising (or within 24 hours for terrorism financing matters). Tipping off a client that a report has been filed carries a criminal penalty. This requires a qualified person making a compliance judgment — not a workflow trigger.
Uniform Training Records — 7 Years, Group-Wide
Staff training must be documented and maintained for 7 years across every office. Individual offices cannot set lighter training requirements independently of the group program. The CO must report to the governing body at least annually on compliance effectiveness — and training records are a primary audit target.
Annual Compliance Report to AUSTRAC
An Annual AML/CTF Compliance Report must be lodged with AUSTRAC. The CO must also provide a report to the governing body at least annually. These are not optional — they are a statutory obligation and a primary mechanism by which AUSTRAC identifies under-performing networks.
Independent Evaluation — Every 3 Years
The group AML/CTF program must be independently evaluated at least every 3 years, with findings reported to the lead entity's governing body. AUSTRAC's guidance is clear that an independent evaluator must be engaged — an internal review or platform-generated report alone is unlikely to satisfy this requirement. Independent means external to the reporting entity.
Two Paths for Your Network — And What Each Actually Means for Head Office
Most franchise head offices have not formally become a "lead entity" under AUSTRAC's reporting group rules. Instead, each office has been left to choose its own AML provider, its own Compliance Officer and its own program. It's worth being precise about what that actually means — in both directions.
Path A — No Formal Reporting Group (Most Networks Today)
- Each office is its own separate reporting entity, with its own AML/CTF program, own CO and own AUSTRAC obligations
- Head office has no formal AUSTRAC liability if one office falls short — legally, they are not each other's problem under this regime
- But AUSTRAC's own stated approach explicitly targets "serious and/or systemic" non-compliance patterns, and enforcement actions are public
- If several offices under the same recognisable brand are separately found non-compliant, that's a reputational risk to the network — even without shared legal liability
- Head office typically has little to no visibility into how well (or poorly) each office is actually managing its obligations
Path B — Formal Reporting Group (Head Office as Lead Entity)
- Requires every member office to agree in writing — franchise agreements alone don't create this automatically
- Head office takes on real, shared legal responsibility: if a member breaches the Act, both the lead entity and the member are considered to have contravened it
- Head office must maintain a program that reflects the size and risk profile of every member office — not just its own business
- Real uniformity and governance become possible — but so does the exposure most franchise head offices haven't fully considered
- Can be exited by any member opting out in writing, or the group can be built with fewer than all offices only if a business-group control relationship doesn't apply (elective groups)
Sourced directly from AUSTRAC: "In a reporting group, non-compliance by one entity may pose risks to the entire group. If a member breaches a civil penalty provision, both the lead entity and the member are considered to have contravened the AML/CTF Act." This is real, and it only applies once a group has actually been formed in writing — not automatically because you share a franchise brand.
A Third Option: Oversight Without Taking On Legal Liability
Most franchise head offices don't want the shared legal exposure of formally becoming a lead entity (Path B) — but staying completely blind to how 50 or 100 independent offices are actually managing compliance (Path A) isn't a comfortable position either, given AUSTRAC's own stated focus on systemic patterns.
AML HQ's model is built around this exact gap, with two coordinated portals:
Under this model, no office is forced to migrate. Those that stay with their current arrangement simply report their compliance status back to head office through the portal, giving your network real visibility — and an early warning if a pattern starts to look systemic — without head office taking on the formal shared liability of Path B unless it genuinely chooses to.
Uniformity Is the Standard. Diversity of Execution Is the Risk.
Whichever path your network takes, the underlying risk described below is the same one AUSTRAC has flagged repeatedly across other regulated sectors — inconsistent execution between offices is exactly the pattern regulators notice.
The reality in most franchise networks right now: your franchise has selected a cloud-based AML platform. Each franchisee has been given a login. Each office has nominated a "Responsible Manager" — typically the office principal, a senior property manager, or an experienced agent — to serve as the local compliance contact. That person has their own interpretation of the platform, their own workload, and their own judgment about what constitutes a suspicious matter. This is not a reporting group with a standardised program. This is 50 offices running 50 slightly different compliance approaches — with your brand, and your lead-entity liability, attached to all of them.
⚠ Cloud Platform + Diverse Responsible Managers
- Each office nominates its own "Responsible Manager" — different roles, different capabilities, different risk tolerance
- No consistent interpretation of what triggers an SMR across offices
- Training varies by manager — one office does it quarterly, another hasn't done it since onboarding
- CDD timeframes managed differently between offices — some miss deadlines without realising
- EDD decisions made by sales agents under settlement pressure, not compliance professionals
- An AUSTRAC audit covers the entire network — inconsistent records across offices create cascading exposure
✓ AML HQ — Unified CO & CFO Model
- Dedicated, qualified Compliance Officers assigned across the network under a single unified framework — one standard, applied everywhere
- SMR and TTR decisions made by a compliance professional, not a sales agent under time pressure
- Group-wide training delivered and documented centrally — every office, same standard, same records
- CDD deadline tracking managed by the CO — not left to individual office calendars
- Annual compliance report authored and lodged — included in the managed service
- Audit trail maintained at licence level — AUSTRAC-ready at any time, across all offices
"In a group/franchise, the real setup risk is uneven execution between offices — and regulators tend to notice. Expectations around control, documentation, consistency, and governance discipline only scale up."
AML HQ — AML/CTF Master Guide for Groups & Franchises, 2026
How Each Platform Meets AUSTRAC's Group Requirements
Legend: ✓ Confirmed available | ✗ Not available | ~ Partial / add-on cost / requires verification
| Requirement / Feature | AML HQ | PEXA Clear | AMLHUB | First AML |
|---|---|---|---|---|
| Human Governance — AUSTRAC Mandatory Requirements | ||||
| Named, fit & proper Compliance OfficerRequired within 28 days of enrolment | ✓Assigned CO — real person | ✗You provide your own CO | ✗Software only | ✗You provide your own CO |
| CO manages SMR/TTR lodgementsHuman judgment — not a workflow trigger | ✓CO owns end-to-end | ✗ | ✗ | ✗ |
| CO continuity managed for youVacancy must be filled within 14 days | ✓AML HQ manages continuity | ✗ | ✗ | ✗ |
| Annual compliance report — authored & lodged | ✓Included (scheduled fee) | ✗ | ~Consulting add-on | ~Guidance only |
| Independent program evaluation — 3 yearly | ✓ | ✗ | ~Separate engagement | ✗ |
| Franchise & Multi-Office Group Governance | ||||
| Group-wide uniformity enforced by a professional | ✓CO enforces across all offices | ✗Tool only — each user independent | ✗Dashboard per office only | ~Group workflows — no CO |
| Audit trail at licence / network level | ✓ | ✗ | ~Per-office only | ✓ |
| Franchise compliance schedule for agreements | ✓Master Guide & Schedule | ✗ | ✗ | ✗ |
| AUSTRAC audit representation & support | ✓Full support (scheduled fee) | ✗ | ~Consulting engagement | ✗ |
| Commercial — What No Other Provider Offers | ||||
| Cost-neutral option available | ✓Available for qualifying agencies | ✗ | ✗ | ✗ |
| CFO Model — compliance generates revenue | ✓Unique — no competitor offers this | ✗ | ✗ | ✗ |
| No lock-in contract | ✓ | ✓ | ✗Exit fee: 50% annual sub | ~Annual commitment |
All competitor information from publicly available sources as at June 2026: pexaclear.com.au, amlhub.com.au, firstaml.com/au, getapp.com.au. Verify directly with each vendor. ~ = partial, add-on cost, or unconfirmed — not a claim the feature is absent.
The Subscription Fee Is Not the Full Cost of Compliance
From Compliance Cost to Revenue-Generating Asset — the CFO Model
AUSTRAC Does Not Give Warnings to Well-Resourced Networks
⚠ What non-compliance looks like for a franchise network: a franchise of 30 offices uses a cloud platform. Each office has a different agent serving as "Responsible Manager." Over 12 months: 6 offices miss CDD deadlines under settlement pressure; 3 offices fail to document training completion; 2 offices do not recognise a suspicious transaction pattern that should have triggered an SMR. AUSTRAC conducts a network audit. It finds systemic inconsistency in program execution. The lead entity is held accountable for the program as a whole. At $33 million per breach, 11 separate failures across a 30-office network creates potential exposure of $363 million in civil penalties — before individual director liability is assessed separately.
- AUSTRAC enforcement actions are public — media coverage of a real estate franchise penalty would be immediate and damaging to brand value, vendor relationships and property management revenue
- Enforceable undertakings require mandatory remediation at the network's cost — typically $200,000 to $500,000+ for a mid-sized franchise
- Increased regulatory supervision following an enforcement action means AUSTRAC has enhanced oversight of your network for years
- A compliance failure during a property transaction can delay or void settlement — creating legal exposure to vendors, purchasers and financiers simultaneously with the AUSTRAC matter
Sources: amlhouse.com.au (August 2025); amltranche.com.au (March 2026); tranchetwoconsultants.com (March 2026); corporatealliance.com (October 2025); AML/CTF Act 2006 (Cth); AUSTRAC enforcement history (public record).
The question is not whether to comply. It's whether your current approach will withstand an audit.
AML HQ works exclusively with real estate franchise networks and large groups to build compliance programs that are uniform, defensible and — for qualifying agencies — cost-neutral. If your network has already selected a cloud platform, we can assess the gaps and show you exactly what is missing before 1 July 2026.
Book a Network Assessment