AML for Real Estate Agents: What You Must Do and How to Get It Done

Casey Cossu

Professional header image for educational tutorial: AML for Real Estate Agents: What You Must Do and How to G...

Money laundering is a serious criminal activity, and the real estate industry is one of its most common targets. If you are a real estate agent, you have a legal and ethical responsibility to help prevent it. That is where AML comes in.

AML for real estate agents is not optional. Anti-Money Laundering regulations require you to follow specific steps to verify your clients, assess risk, and report suspicious activity. Failing to comply can result in heavy fines, damage to your reputation, and even criminal liability.

The good news is that compliance does not have to be complicated. This tutorial will walk you through everything you need to know as a beginner. You will learn what AML obligations apply to real estate agents, how to carry out customer due diligence, what red flags to watch for, and how to build simple processes that keep your business protected and fully compliant.

Whether you are just starting out or looking to get your compliance procedures in order, this guide will give you the clarity and confidence to get it done correctly.

Why Real Estate Agents Are Now Under AUSTRAC Regulation

From 1 July 2026, real estate agents across Australia became subject to formal obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 for the first time in the country's history. The AML/CTF Tranche 2 reforms, enacted through the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, represent the broadest expansion of Australia's compliance regime in almost 20 years, bringing an estimated 90,000 new entities into the AUSTRAC-regulated population. Before these reforms took effect, only around 19,000 entities — primarily banks and financial services firms — were regulated. That number has now grown to roughly 100,000 businesses nationwide.

The reason this reform took so long is straightforward: Australia's original AML/CTF laws were drafted in 2005 and had simply not kept pace with how financial crime evolved. Prior to Tranche 2, Australia was one of the few member jurisdictions of the Financial Action Task Force (FATF) that had not brought real estate agents under a formal AML/CTF framework. That regulatory gap left the property market exposed, and intelligence agencies had taken notice. You can review AUSTRAC's real estate designated services guidance to understand exactly which activities now trigger compliance obligations.

The risk was well-documented long before the reforms arrived. FATF consistently identified real estate as a high-risk sector for layering and integrating illicit funds, and the Australian Criminal Intelligence Commission's 2023 Organised Crime in Australia report named real estate as a key conduit for proceeds of crime, including funds linked to drug trafficking and foreign corruption. Property transactions are attractive to criminals precisely because they allow large sums to move through the layering and integration stages of the money laundering cycle, converting illicit cash into what appears to be a legitimate asset.

The reforms directly address this vulnerability. As AUSTRAC outlines in its obligations guidance, real estate agents providing designated services must now enrol with AUSTRAC, build a documented AML/CTF program, conduct customer due diligence on buyers and sellers, and report suspicious matters. The broader objective is to align Australia's property market with global AML/CTF standards, improve transaction transparency, and close a gap that organised crime had exploited for years.

Are You Actually a Reporting Entity?

Being in real estate does not automatically make your business a reporting entity. Status depends entirely on whether your business provides one or more designated services as defined under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. AUSTRAC publishes a specific list of real estate designated services that determines who is captured. Obligations only attach once that threshold is crossed, which is why confirming your status is the essential first step before building any compliance program.

For most licensed real estate agents, the primary designated service is acting as an agent in the purchase or sale of real property, covering residential, commercial, and rural transactions. Property developers who sell house-and-land packages, off-the-plan apartments, or lots in new subdivisions directly to buyers are also likely captured. However, the precise scope of each service matters, and your specific business model should be assessed against the current AUSTRAC list rather than assumed.

Not every property business falls inside the regime. A property manager whose role is limited to leasing and tenancy management, without facilitating sales, may sit in a different regulatory position entirely. Similarly, a developer who sells exclusively through a separately licensed agent rather than directly may have a different status to one who sells in-house. These distinctions are common sources of confusion and require individual assessment, not guesswork.

Franchise network members should pay particular attention here. As Fair Trading Queensland confirmed, each reporting entity must enrol with AUSTRAC individually. A franchisor's enrolment does not extend to franchisee agencies operating under the same brand. Each agency is a separate legal entity with its own enrolment and program obligations.

If you are uncertain whether your services trigger reporting entity status, AMLX can confirm this as a standalone first step, before you invest time and resources in building a compliance program scoped to the wrong business model.

Enrol With AUSTRAC First: Deadlines and What You Need

Once you have confirmed your reporting entity status, enrolment with AUSTRAC is the first mandatory action you must take. The deadline depends on when your agency commenced providing a designated service. Agencies already operating on 1 July 2026 were required to enrol by that date. If your agency began providing a designated service after 1 July 2026, you have 28 days from first providing that service to complete enrolment. Missing this window exposes your business to regulatory action, so treating this deadline as fixed and non-negotiable is essential.

Enrolment is completed online through the AUSTRAC Online portal, which opened on 31 March 2026. Before you begin, gather the following: your ABN, business contact details, a description of the designated services your agency provides, and the details of your nominated AML/CTF Compliance Officer. AUSTRAC has published a Real Estate Program Starter Kit that outlines exactly what to expect during the process and is worth reviewing before you log in.

It is important to understand that enrolment is not the same as registration. Registration is a more intensive obligation reserved for remittance and virtual asset service providers. Enrolment is a lower-threshold requirement, but it is the gateway to every other compliance obligation your agency must meet, including your AML/CTF program and customer due diligence procedures.

AUSTRAC has signalled a risk-based, educative approach during the early transition period. This does not mean obligations are optional or can be deferred. Programs and CDD procedures were expected to be operational from 1 July 2026.

Once enrolled, you will receive an AUSTRAC reporting entity number. Store this securely; it is required for lodging Suspicious Matter Reports and Threshold Transaction Reports, and for all formal correspondence with AUSTRAC.

Your AML/CTF Program: Part A and Part B Explained in Plain English

Once enrolled, your next obligation is to build and maintain a documented AML/CTF program. This is not optional and it is not a formality. Every reporting entity must have a written program in place before providing a designated service, and the program must be tailored to your specific business.

The program is structured in two parts.

Part A covers your money laundering and terrorism financing risk assessment, together with the controls your agency has put in place to manage the risks you have identified. It requires a written analysis of your inherent risk across four key dimensions: the services you provide, the types of customers you deal with, the geographies involved, and the transaction methods used. AUSTRAC expects to see a genuine assessment of your agency's specific exposure, not a generic description of the real estate sector.

This is what "risk-based" means in practice. A small residential agency operating in a regional Queensland market carries a materially different risk profile than a commercial agency handling high-value off-the-plan transactions with offshore buyers in Sydney or Melbourne. Your Part A document should reflect your actual circumstances. A copied template that describes the industry broadly, rather than your business specifically, is unlikely to satisfy AUSTRAC if your program is evaluated.

Part B sets out the procedures your staff follow to identify and verify customers. It must document which identity documents or data sources are used for verification, how your agency handles customers who cannot produce standard identification, and how higher-risk cases are escalated for additional scrutiny. Verification applies to buyers and sellers alike, across all transaction types, whether at auction, off-the-plan, or private treaty.

Critically, your program is a living document. It must be reviewed when your business model changes, when AUSTRAC updates its guidance, and at minimum annually. A program drafted at launch and never revisited will not withstand independent evaluation. Building in a scheduled review cycle from the outset is a practical step that costs little but protects significantly.

Customer Due Diligence: What You Must Verify for Buyers and Sellers

Customer Due Diligence: What You Must Verify for Buyers and Sellers

One of the most common misconceptions among real estate principals is that CDD only applies to the buyer. It does not. Under the AML/CTF Act, both buyers and sellers are customers for compliance purposes, and your obligation to verify identity covers all parties to a transaction. For sellers, the designated service relationship typically begins when the agency agreement is signed. For buyers, it commences once the transaction is reasonably expected to proceed, generally after offer acceptance. In practical terms, this means you must collect and verify the full legal name, date of birth, and residential address of everyone involved before the transaction moves forward.

For individual customers, verification requires more than simply sighting a document. You need to collect a primary photographic identity document, such as a driver's licence or passport, and then confirm the biographic data against government-held records. The Document Verification Service (DVS) provides real-time confirmation by checking the details you collect against the issuing authority's records. Most agencies access DVS through a third-party compliance platform rather than a direct integration. This step transforms a visual document check into a verified identity record that satisfies AUSTRAC's requirement for reliable and independent verification.

Where your customer is a company, trust, or other non-individual entity, which is common in commercial transactions and increasingly in residential purchases, Know Your Business (KYB) procedures apply. You must verify the entity's legal name, ABN or ACN, and registered address. Critically, you must also identify the beneficial owners or controlling persons sitting behind the entity. The AML/CTF Rules 2025 guidance on CDD for the real estate sector addresses these layered structures directly. Complex arrangements involving shell companies, trusts, or nominees are recognised red flags, and your procedures must be capable of working through them.

Timing matters significantly here. CDD must be completed before, or as early as practicable in, the establishment of the business relationship. Waiting until settlement is a compliance failure, not a minor procedural oversight.

The most effective approach is to embed CDD directly into your existing workflow rather than treating it as a separate task. Collect seller verification documents at the listing appointment. Collect buyer documents when presenting an offer. This positions identity verification as a natural step in every transaction, removes the awkwardness of requesting documents at an unfamiliar point in the process, and ensures your obligations are met well before exchange.

Higher-Risk Customers: PEPs, Sanctions Screening, and Enhanced Due Diligence

Standard CDD gets you to the baseline. It confirms who your customer is. But for some customers, knowing their identity is not enough. Where your risk assessment flags a customer as higher risk, you are required to apply Enhanced Due Diligence (EDD), which goes significantly further. EDD requires you to gather additional information about the customer's source of funds, source of wealth, and the specific purpose of the transaction. For example, if an offshore buyer is purchasing a high-value property using funds transferred from a foreign account, EDD would require you to understand and document where those funds originated and how that wealth was accumulated.

Politically Exposed Persons (PEPs) are automatically treated as higher risk under the AML/CTF framework, regardless of any other factors. A PEP is any individual who holds or has held a prominent public function, domestically or internationally. This includes heads of state, senior politicians, senior government officials, judicial officers, and senior executives of state-owned enterprises. Critically, PEP status also extends to close family members and known associates, even if those individuals hold no public position themselves. Identifying whether a client is a PEP is a core component of any compliant CDD programme for real estate agents.

Sanctions screening is a separate and equally serious obligation. DFAT's guidance for real estate professionals makes clear that dealing with a sanctioned individual or entity is a criminal offence, regardless of whether you knew they were sanctioned. This strict liability makes pre-transaction screening non-negotiable on every deal.

Adverse media screening adds a further layer by checking customers against negative news coverage. Its value is that formal sanctions and PEP lists are backward-looking; adverse media can surface emerging financial crime risk before those lists are updated. As noted in AUSTRAC's risk insights for the real estate sector, identifying unusual patterns early is central to a risk-based approach.

Finally, none of these obligations are a one-time exercise at onboarding. Screening must continue throughout the relationship. If a customer's risk profile changes mid-transaction, for instance they appear on a sanctions list or become subject to adverse media coverage, your agency must identify that change and respond to it accordingly.

Suspicious Matter Reports: What Triggers One and How to Lodge It

When you have reasonable grounds to suspect that a customer or transaction is connected to money laundering, tax evasion, terrorism financing, or any other serious offence, you are required to lodge a Suspicious Matter Report (SMR) with AUSTRAC. The deadlines are strict: suspicions involving terrorism financing must be reported within 24 hours; all other suspicious matters must be reported within three business days. These timeframes run from the point at which suspicion arises, not from when a transaction completes.

What Counts as a Red Flag in Property

Certain patterns appear repeatedly in property-related money laundering, and your staff need to recognise them. Key red flags include a buyer insisting on cash payment or attempting to split payments into smaller instalments to stay below reporting thresholds; a purchase price that is significantly above or below market value with no credible explanation; a buyer who shows no genuine interest in the property itself, its condition, or its suitability for any stated purpose; the use of layered corporate structures, trusts, or offshore entities that make it difficult to identify who actually benefits from the purchase; and funds originating from jurisdictions with weak AML controls. Any one of these factors may be explainable in isolation. In combination, they can establish reasonable grounds for suspicion.

The Standard Is Suspicion, Not Proof

This distinction matters enormously. You do not need to establish that a crime has occurred. You need reasonable grounds to suspect one might have. Turning a suspicious customer away and declining to proceed does not extinguish your reporting obligation. If grounds for suspicion existed at any point during your engagement, the obligation to report remains. Failing to lodge when grounds exist is itself a breach of the AML/CTF Act, and AUSTRAC's guidance on suspicious matter reports makes clear that agencies will be held to this standard.

How to Lodge and What to Include

SMRs are lodged through AUSTRAC Online. Your report must capture who was involved, what the transaction or matter consisted of, where and when it occurred, why you formed a suspicion, and how the activity was structured. AUSTRAC introduced updated SMR forms on 1 July 2026 with more structured fields around beneficial ownership and trust information, reflecting the reporting obligations now applicable to the real estate sector. One critical rule applies without exception: informing the customer, or anyone outside your compliance function, that a report has been made or considered is a criminal offence. SMR information must be held separately from standard client files.

Why Staff Training Is Non-Negotiable

Red flags can surface at listing, during negotiation, or at settlement. Every staff member who interacts with customers at any stage must be trained to recognise warning signs and escalate them internally so your designated compliance officer can make the reporting decision. This is not an administrative nicety. Staff training is a core program obligation precisely because the compliance chain breaks at the point where a frontline agent notices something unusual but has no process for acting on it.

Record-Keeping: The 7-Year Retention Obligation

Every AML/CTF record your agency creates must be retained for a minimum of seven years. This covers a broad range of document types: identity verification records collected during CDD for every buyer and seller, transaction records, copies of every SMR lodged with AUSTRAC, threshold transaction reports, your AML/CTF program in full, all superseded versions of that program with revision history, prior risk assessments, and staff training completion records. The obligation is comprehensive by design. Regulators need to be able to reconstruct any customer relationship or transaction if an investigation requires it, and your records are how that reconstruction happens.

The format of your records matters as much as what you keep. AUSTRAC requires that records be retrievable and legible within a reasonable time on request. Paper files stored in a back office, or identity documents scattered across individual email threads, create obvious retrieval risks and are difficult to search systematically. Cloud-based document management systems and purpose-built AML platforms handle storage, apply retention flags, and maintain audit trails in ways that informal systems simply cannot replicate reliably. If AUSTRAC requests records during an audit, the ability to produce them quickly and completely will directly shape how the regulator assesses your compliance posture.

Understanding how the seven-year clock operates is important because it is not always straightforward. For transaction records, the clock starts from the date of the transaction. For CDD and customer identification records, it starts from the date the customer relationship ends, not from the date of the most recent transaction. For ongoing clients who transact with your agency across multiple dealings over several years, this means records may need to be held for considerably longer than seven years in practice.

Your AML/CTF program itself must document how and where records are stored, who has access, and what the retrieval process looks like. Record-keeping should be a formal, documented procedure within your program rather than an informal practice left to individual staff. Gaps in records are treated as compliance failures regardless of whether the underlying transactions were legitimate, with penalties reaching up to A$33,500 per contravention.

The AML/CTF Compliance Officer Role: Who It Is, What They Must Do, and What Support Looks Like

Every reporting entity must nominate an AML/CTF Compliance Officer, a senior person within the business who holds formal accountability for the AML/CTF program. For most small and mid-sized agencies, this person will be the principal or licensee-in-charge. The appointment must be documented inside the AML/CTF program before notifying AUSTRAC through AUSTRAC Online, and that notification must be submitted by 29 July 2026, which is 28 days after obligations commenced. If the compliance officer changes at any point after notification, AUSTRAC must be updated within 14 days of the change.

The responsibilities attached to this role are substantive, not ceremonial. The compliance officer is accountable for overseeing the AML/CTF program, ensuring staff are trained, monitoring CDD and sanctions screening processes, making reporting decisions on suspicious matters, and keeping the program current as obligations evolve. Critically, the compliance officer is also the person who must decide whether to lodge a Suspicious Matter Report when a sales agent brings a red flag to their attention. That decision cannot be delegated informally; it requires genuine authority within the business to stop a transaction, require additional documentation, and lodge the report with AUSTRAC when warranted. There is also a tipping-off prohibition that applies directly to the compliance officer: you must not disclose to a customer that an SMR has been or may be lodged.

Many principals nominate themselves as compliance officer without fully appreciating what that means in practice. The role carries personal exposure. Civil penalties for individuals reach up to A$7,280,000 per contravention. If the agency runs a deficient CDD process or fails to report a suspicious matter, the compliance officer is directly accountable.

The key distinction to understand is this: accountability cannot be outsourced, but operational capacity can and should be. The compliance officer owns the decisions; a specialist handles the work. That is exactly how AMLX operates alongside nominated compliance officers at client agencies, drafting the program, building CDD workflows, designing staff training, supporting SMR lodgement, and providing a dedicated support line for real transaction questions as they arise. You keep the accountability. AMLX provides everything else.

Ongoing Obligations: Program Maintenance, Independent Evaluation, and Annual Reporting

Getting your program built and your enrolment lodged is a significant achievement, but it is not the finish line. The obligation to maintain an effective, current AML/CTF program continues for as long as your agency provides designated services. That means the program must be reviewed and updated whenever your business model changes, new AUSTRAC guidance is issued, or your risk assessment identifies exposures that were not present at launch. AUSTRAC publishes ongoing guidance that reporting entities are expected to monitor and incorporate. Treating your program as a static document is one of the most common compliance mistakes newly regulated agencies make.

Independent Evaluation Is a Legal Requirement

The AML/CTF Act requires that your program be reviewed by someone independent of its design and operation. For most real estate agencies, this means engaging an external specialist to assess whether the program is adequate and appropriately implemented in practice. The evaluator must be genuinely independent; your compliance officer cannot evaluate their own work. Evaluation findings must be formally reported to senior management and, critically, used to update the program. This is not a tick-box exercise. The evaluation is the mechanism through which your agency identifies gaps before AUSTRAC does.

Annual Compliance Reporting

Every reporting entity must submit an Annual Compliance Report to AUSTRAC covering the relevant financial year. The report asks the entity to confirm the state of its AML/CTF program, staff training, and key obligations. Missing or submitting late reports attracts regulatory attention and signals to AUSTRAC that your compliance governance may be deficient.

Ongoing CDD and the "Set and Forget" Risk

Existing customer relationships must be reviewed periodically, not just at onboarding. If a customer's risk profile changes or new information emerges, updated due diligence is required. Agencies that build a compliant program at launch and leave it untouched typically find themselves out of step with regulatory expectations within 12 to 24 months. Ongoing support, covering program currency, AUSTRAC update monitoring, and independent evaluation preparation, is where most agencies will need sustained external assistance well beyond the initial implementation phase.

Penalties for Non-Compliance: What Is at Stake

Non-compliance with your AML/CTF obligations is not a technical formality with minor administrative consequences. The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) carries serious civil and criminal penalties that apply directly to real estate agencies and their responsible officers. Civil penalty provisions for failing to maintain an AML/CTF program, failing to conduct adequate customer due diligence, or failing to lodge a suspicious matter report can reach into the tens of millions of dollars for body corporates. Individual officers can also face personal liability where they have authorised or permitted a contravention.

AUSTRAC's enforcement record makes clear that this is not a regulator that issues warnings and moves on. The $1.3 billion civil penalty against Commonwealth Bank in 2018 and the $1.3 billion penalty against Westpac in 2020 remain the two largest corporate penalties in Australian history. Both arose from systemic AML/CTF failures: poor transaction monitoring, inadequate CDD, and failure to report suspicious matters at scale. AUSTRAC has publicly signalled that the same regulatory seriousness will apply to newly regulated sectors as the transition period matures.

Financial penalties are not the only exposure. AUSTRAC holds a broad toolkit of enforcement responses, including infringement notices, injunctions, remedial directions requiring a business to fix specific failures, and in serious cases, action that could result in licence cancellation. For a real estate agency, a public enforcement action carries reputational damage that can outlast any financial penalty, affecting referral relationships, vendor listings, and buyer trust in ways that are difficult to recover from.

The practical good news is that AUSTRAC has adopted a risk-based, educative approach during the early transition period. Agencies that have made genuine, documented attempts to build and implement a compliant program are treated materially differently from those that have taken no steps at all. Good faith matters.

The compliance failures most commonly identified in newly regulated sectors are consistently the same: no documented program, or a generic template not tailored to the business; no evidence of staff training; inadequate or absent CDD records; and failure to report suspicious matters. Each of these is addressable now, and addressing them proactively is the single most effective risk mitigation strategy available to your agency.

Where AMLX Fits: Your Compliance Team Without the Hire

Most real estate agencies entering AUSTRAC regulation are doing so without a compliance team, without an in-house legal function, and without any prior experience building the kind of infrastructure the obligations require. Understanding what the law demands is one challenge. Having the time, capacity, and specialist knowledge to actually implement it across a busy, transaction-driven agency is another challenge entirely. That gap is precisely where AMLX was built to operate.

AMLX provides full-service compliance support across every stage of the obligation lifecycle. That means confirming your reporting entity status, handling AUSTRAC enrolment, conducting your money laundering and terrorism financing risk assessment, drafting your AML/CTF program, setting up your CDD and KYC workflows, training your staff, supporting your compliance officer with SMR decisions, and building your record-keeping framework. As regulations evolve, AMLX keeps your program current and ready for independent evaluation, so maintenance does not fall through the cracks in a busy office.

The model is straightforward: support is outsourced, but accountability is retained. Your agency remains the reporting entity. Your nominated compliance officer retains legal responsibility under the Act. What AMLX provides is the operational engine behind that accountability, doing the work, guiding decisions, and being available on a dedicated support line when a real transaction question arises mid-deal and your compliance officer needs an expert answer fast.

AMLX is also vendor agnostic. Rather than locking clients into a single proprietary system, AMLX works alongside the leading AML platforms and software. If your agency or franchise network has already adopted a CDD platform, AMLX can operate within that environment without disruption.

The practice is led by Casey Cossu, Head of AML/CTF Compliance, formerly Legal Counsel at REIQ, Queensland's largest real estate body. That background means AMLX brings both technical regulatory expertise and genuine understanding of how agencies actually operate, which is a combination that matters when translating complex compliance obligations into practical, workable processes for a principal running a busy office.

Your Next Steps: A Practical Compliance Checklist

Your Next Steps: A Practical Compliance Checklist

Everything covered in this guide comes down to seven concrete actions. Work through them in order.

1. Confirm your reporting entity status. Do not assume the answer. Property management, leasing, and referral-only activity are excluded. If your agency brokers, plans, or executes property sales or transfers, you are almost certainly captured. Verify your specific services before taking any further steps.

2. Enrol with AUSTRAC through AUSTRAC Online if you have not already done so. You will need your ABN, designated service details, and compliance officer information ready.

3. Nominate your AML/CTF Compliance Officer and ensure that person accepts the full weight of the accountability that role carries.

4. Build a documented AML/CTF program covering Part A and Part B, tailored to your agency. A generic template will not satisfy your obligations.

5. Implement CDD workflows for buyers and sellers, and train every staff member on collection, verification, and red flag recognition.

6. Establish record-keeping systems that retain CDD and transaction records for seven years in a retrievable format.

7. Book a free compliance assessment with AMLX. We will confirm your reporting entity status, identify gaps in what you have built so far, and give you a clear picture of what still needs to be done and in what order. You keep the accountability; we do the work.

Conclusion

AML compliance is not a bureaucratic burden; it is a fundamental part of running a trustworthy real estate business. By understanding your obligations, completing thorough customer due diligence, recognizing suspicious activity, and building consistent internal processes, you put yourself in a strong position to protect your clients, your reputation, and your livelihood.

The key takeaways are simple: know the rules, verify your clients, stay alert to red flags, and keep clear records. These steps are manageable when you approach them systematically.

Now it is time to take action. Review your current compliance procedures, identify any gaps, and start implementing the steps outlined in this guide. If you are unsure where to begin, start with your client onboarding process today.

Staying compliant is not just about avoiding penalties. It is about being a professional the industry can trust.