What Is Customer Due Diligence in Real Estate? A Plain English Guide for Australian Agencies

Casey Cossu

Every real estate transaction carries risk. And in Australia, one of the most important ways agencies manage that risk is through a process called customer due diligence. Yet despite how frequently the term gets used, many people working in or around the industry are still unsure what it actually means in practice.
So what is due diligence in real estate, and why does it matter so much for Australian agencies specifically? At its core, customer due diligence is a formal process of verifying who your clients are, where their money comes from, and whether they pose any financial or legal risk to your business. It is a cornerstone of anti-money laundering compliance, and it is becoming increasingly scrutinised by Australian regulators.
In this guide, we will walk you through everything you need to know as a beginner. You will learn what customer due diligence involves, when it applies, and how to carry it out correctly within an Australian real estate context. By the end, you will have a clear, practical understanding of your obligations and how to meet them with confidence.
What Does Due Diligence Actually Mean in Real Estate AML/CTF Compliance?
If you have ever purchased a property, you already know one meaning of "due diligence": inspecting the building, searching the title, checking zoning, and reviewing strata records before committing to a contract. That is a commercial process, driven by personal risk management, and it has no fixed legal definition under Australian anti-money laundering law. The statutory meaning of due diligence in the AML/CTF context is an entirely different obligation, and for real estate agencies operating from 1 July 2026, understanding that difference is the starting point for everything else in your compliance program.
Under Australia's Anti-Money Laundering and Counter-Terrorism Financing framework, Customer Due Diligence (CDD) is a mandatory legal obligation imposed on reporting entities by AUSTRAC. As set out in AUSTRAC's overview of customer due diligence, CDD requires you to identify your customer, verify that identity using reliable and independent sources, identify the beneficial owners behind any company or trust structure, understand the nature and purpose of the relationship, and monitor that relationship on an ongoing basis. It is not a form you file once and forget; it is a live obligation that follows the customer throughout their dealings with your agency.
These obligations apply once your business provides a designated service. In the real estate context, designated services include acting as an agent in the purchase or sale of real property, and certain leasing and property management activities. When your agency facilitates a property transaction that falls within this scope, AUSTRAC's full regulatory framework applies to you, including enrolment, risk assessment, written policies, and CDD on every relevant customer.
A point that surprises many agency principals is that CDD is not a standalone administrative task. It sits inside a broader AML/CTF compliance program that must also include a documented risk assessment, staff training, suspicious matter reporting, and record keeping for a minimum of seven years. The AML/CTF Rules 2025 guidance on customer due diligence for the real estate sector confirms that the depth of verification required is risk-proportionate, meaning your approach must be calibrated to the specific money laundering and terrorism financing risk each customer and transaction presents.
That calibration is structured through three tiers: standard CDD, which applies to most customers as the default; simplified CDD, which is available for demonstrably lower-risk situations; and enhanced CDD, which is required for higher-risk customers including Politically Exposed Persons, complex ownership structures, and high-value transactions. The sections that follow in this guide examine each tier in practical detail, so you can begin mapping them to the real transactions moving through your agency right now.
Why CDD Now Applies to Real Estate Agencies in Australia
For nearly two decades after Australia's foundational AML/CTF legislation was enacted in 2006, real estate agencies operated almost entirely outside the country's anti-money laundering framework. Banks, casinos, and digital currency exchanges were brought into scope under what became known as Tranche 1, but real estate professionals, lawyers, and accountants were deliberately excluded. That regulatory gap left the property sector exposed as a channel for illicit funds, and it drew direct criticism from the Financial Action Task Force (FATF) as far back as 2015, when FATF formally identified Australia's failure to regulate these "gatekeeper" professions as a significant shortcoming in its international compliance standing. As a FATF member, Australia was obligated to address this misalignment, and that obligation ultimately drove the reforms now in effect.
The response came through the AML/CTF Amendment Act 2024, which introduced what is now known as the Tranche 2 reforms. These reforms extend AML/CTF obligations to real estate professionals and a range of other non-financial businesses providing designated services. Obligations for real estate agencies commenced 1 July 2026, and the scale of this expansion is significant. Prior to Tranche 2, AUSTRAC regulated approximately 19,000 reporting entities, drawn largely from banking and financial services. Tranche 2 adds roughly 90,000 more, bringing the total regulated population to approximately 100,000 businesses across Australia. That is not a modest adjustment; it is a fundamental transformation of the country's compliance landscape. You can review your obligations as a reporting entity directly on AUSTRAC's website.
For real estate agencies, being a reporting entity carries concrete legal responsibilities. Any business providing a designated service must apply to enrol with AUSTRAC within 28 days of commencing that service from 1 July 2026. Compliance is not discretionary. Agencies that provide designated services and fail to enrol, fail to conduct customer due diligence, or fail to maintain the required AML/CTF program are in breach of the Act. The AUSTRAC Tranche 2 reform overview outlines how these obligations apply across newly regulated sectors, including real estate.
The Three Tiers of CDD: Standard, Simplified, and Enhanced
Not every customer who walks through your door carries the same level of risk, and Australia's AML/CTF framework reflects that reality. AUSTRAC's reformed CDD framework establishes three tiers of verification, each calibrated to the risk profile of the customer and the transaction. The tier you apply is not a matter of preference or workload; it is a compliance decision that must be justified, documented, and defensible under regulatory scrutiny.
Standard CDD: The Baseline for Every Transaction
Standard CDD is the default position. Unless you have formally assessed a customer as lower risk, or identified factors that elevate their risk, standard CDD applies. For a typical individual Australian buyer or vendor, this means collecting their full legal name along with either their date of birth or residential address. You must then verify that identity using reliable documentation, such as a current passport or driver's licence. A photocopy is not sufficient; the document must be verified as genuine, either through physical examination against document security features or, increasingly, through an Electronic Identity Verification tool that checks government records in real time. Every customer must also be screened against the DFAT Consolidated List and applicable United Nations sanctions lists before you proceed. You then conduct a risk assessment based on who the customer is, what they are doing, and where they are from. All of this must be recorded and retained for a minimum of seven years. Timing matters: vendors must be verified before you sign the agency agreement, and buyers must be verified before or at the point of contract execution.
Simplified CDD: Reduced Depth, Not Reduced Rigour
Simplified CDD allows a reduction in the depth of verification steps where a customer has been formally assessed as presenting a demonstrably lower risk. Examples might include established Australian government bodies or locally regulated financial institutions acting as the purchasing entity. The critical point for any agency to understand is that simplified CDD is not a licence to skip the process. Before you apply a reduced verification approach, your risk assessment must affirmatively establish that the lower-risk classification is warranted, and that reasoning must be written down. Choosing simplified CDD because a transaction is straightforward or a client seems familiar is a compliance failure. The tier must be earned through documented analysis, not assumed for convenience.
Enhanced CDD: Higher-Risk Scenarios You Will Encounter
Enhanced Due Diligence is triggered when risk indicators elevate a customer above the standard baseline. In a real estate context, the scenarios you are most likely to encounter include foreign purchasers from high-risk or high-corruption jurisdictions, company buyers where you must identify all beneficial owners holding 25 percent or more of the entity, trust structures where the trust deed must be reviewed to identify who actually benefits, and Politically Exposed Persons, for whom Enhanced CDD is mandatory under the legislation. In each of these cases, additional steps apply: deeper scrutiny of source of funds and source of wealth, senior management approval for the relationship, and thorough documentation of every verification step taken. A wealth-circumstance mismatch, such as a client with no apparent income purchasing a high-value property in cash, is a textbook trigger. For a practical overview of how these obligations apply in practice, the Customer Due Diligence guide for real estate agents provides useful context on each scenario.
Documenting Your Reasoning for Every CDD Decision
AUSTRAC's framework is explicitly risk-based, meaning the tier you apply to any given customer must be traceable back to your risk assessment methodology. Regulators will not simply ask whether you collected a document; they will ask whether your systems and processes produced that outcome consistently and for the right reasons. Each CDD decision, including the decision to apply standard rather than enhanced procedures, must have recorded reasoning that would withstand independent review. According to iDeedworks' CDD guidance, this includes documenting the risk factors considered, the tier applied, and the rationale for that determination at the time of onboarding.
One final point applies to any agency that was previously using legacy ACIP (Account and Customer Identity Process) procedures. Those procedures ceased to be acceptable from 31 March 2026. From that date, the reformed CDD framework under the AML/CTF Rules 2025 became the only compliant basis for customer verification. If your agency was operating under ACIP protocols, those workflows need to have been replaced entirely, not updated incrementally.
Standard CDD Step by Step: What You Actually Do at the Desk
Once you have determined that standard CDD applies to a customer, the process follows a clear sequence. The first step is collecting the right identity information before you do anything else on the file.
For an individual customer, you must collect their full legal name, date of birth, residential address, and enough information to understand the nature and purpose of the business relationship. These four elements are not suggestions; they are the baseline identity data your AML/CTF program must capture for every standard CDD customer.
Collecting a document and verifying it are two different things. Acceptable verification documents include a government-issued photo ID, a current Australian passport, or a current driver's licence. Collecting means receiving a copy of the document. Verifying means confirming the document is genuine, is current, and actually belongs to the person in front of you. In practice, verification involves comparing the photo to the individual, checking the document has not expired, and, where your program requires it, running the details through an electronic verification service. A photocopy sitting in a file without any confirmation step does not meet the verification requirement.
Understanding the nature and purpose of the business relationship means recording why the client is transacting, not just that they are. For a sales transaction, that means noting whether the buyer is purchasing as a primary residence, an investment property, or for development purposes, along with the expected transaction value and the general source of funds. It is worth noting that property management, leasing, and rental management are not designated services under Australia's AML/CTF Act. CDD obligations attach to sales and transfers, not to leasing activity, which is one of the most commonly misunderstood scope questions agencies face.
Once the CDD process is complete, you must record everything and store it securely, whether in a paper file or a compliant electronic system, in a way that can be retrieved for an AUSTRAC examination. The retention period is seven years from the date the record is made, not from settlement or completion of the transaction.
Finally, the most important sequencing rule: verification must be completed before you begin providing the designated service. That means before you list a property, before you begin negotiating on a buyer's behalf, and well before contracts are exchanged. Starting to act as the client's agent is the trigger. Leaving verification until later in the transaction is a breach of your obligations, not a minor administrative oversight.
Beneficial Ownership: Who Are You Actually Identifying?
A beneficial owner is the natural person who ultimately owns or controls a customer entity, even when another company, trust, or individual sits between them and the transaction. The name on the contract is not necessarily the person you need to identify. Your obligation under Australia's AML/CTF framework is to look through whatever structure is presented and find the real human being who holds genuine economic interest or control. This principle is fundamental to AML compliance in real estate because layered ownership structures are among the most common tools used to move criminal proceeds through property markets undetected.
When a Company Is Buying
When a company appears as the purchasing entity, your CDD obligation does not stop at verifying the company itself. You must identify any individual who holds 25% or more of the company's shares or voting rights, because at that threshold a person has sufficient control or economic interest to be treated as a beneficial owner. In practice, this means requesting the company's certificate of incorporation, a current shareholder register, and government-issued identification documents for each person above that threshold. If shares are held through an intermediate holding company rather than directly, you must follow the chain upstream and repeat the analysis at each level until you reach the natural person at the top. A company that cannot or will not produce a shareholder register, or that presents an ownership structure with no identifiable human at the end of it, is not providing a satisfactory response and should be escalated accordingly.
When a Trust Is Buying
Trust structures are a particularly common vehicle for obscuring ultimate ownership in property transactions, and they require careful handling. When a trust is the purchasing entity, you generally need to consider verifying the trustee (the legal owner who executes the transaction and is your customer of record), the settlor (the person who originally established and funded the trust), and the beneficiaries (those entitled to benefit from trust assets). Where beneficiaries are named individuals, they should be identified. Where they are described as a class, you should understand and document who falls within that class. The risk with trusts is that they legally separate control from economic benefit, which creates opacity that can be exploited. As beneficial ownership guidance in banking and finance makes clear, the core obligation is always to look through intermediary structures to reach the humans who hold genuine interest or control.
When Ownership Is Complex or Deliberately Obscured
If a customer presents a structure that is unusually layered, provides inconsistent explanations about who controls the entity, or is evasive when asked to produce ownership documentation, that difficulty is itself a risk signal. Complexity that serves no obvious commercial purpose is a recognised money laundering typology in real estate. Your response in that situation is to escalate to enhanced CDD, document everything you have observed, and consider whether a suspicious matter report is required. You do not need to have proven that money laundering is occurring. The obligation to report arises when you have reasonable grounds to suspect it, and a customer who cannot satisfactorily explain their own ownership structure provides those grounds.
Individual Buyers Are Not Automatically Exempt
A common question at the staff level is whether beneficial ownership checks apply when a buyer says they are purchasing in their own name. The answer is yes, assessment is still required. The question you must answer is whether that individual is the true beneficial owner, or whether they are acting as a nominee, agent, or intermediary for someone else. People do purchase property on behalf of others, and a name on a contract does not confirm that the person named will be the ultimate beneficiary of the asset. If there are any indicators that suggest the buyer is not acting solely on their own behalf, those indicators must be explored, resolved, and documented before you proceed.

CDD in Sales vs. Property Management: Is There a Difference?
Both sales and property management functions in a typical Australian real estate agency can constitute designated services under the reformed AML/CTF framework, meaning the CDD obligation is not limited to your sales team. The specific trigger is whether your business is providing a real estate service in connection with the buying, selling, or transferring of real property on behalf of a client. Property management activities that involve receiving or handling funds, particularly rental payments or bond money, are also captured. This means principals cannot treat CDD as a front-of-house sales concern and leave property management to operate under a different standard.
How CDD Differs Operationally Across Each Function
The obligation may be equal, but the practical execution differs in meaningful ways. In a sales transaction, CDD is typically completed at the point of engagement, before you take any steps to market, negotiate, or facilitate the sale. The client is a vendor or buyer, the transaction value is high and clearly defined, and the principal or a senior agent is usually involved from the outset. That visibility creates a natural checkpoint. In property management, the client relationship begins at the landlord onboarding stage, and the risk profile is structurally different. Rental values are lower than sale prices, transaction frequency is higher, and the ongoing nature of the relationship means the initial CDD moment can feel less consequential than it actually is. Document types required at onboarding are broadly similar, covering identity verification and beneficial ownership where applicable, but the timing and risk rating may differ based on rental amounts and the source of landlord funds.
When a Property Management Client Moves Into Sales
One of the most common CDD gaps in agencies that run both functions is the assumption that a landlord already on your books does not need to be re-verified when they instruct you to sell. Existing CDD can only be relied upon if it remains current, accurate, and was collected to a standard that meets your program requirements. If a client was onboarded into property management years ago with minimal documentation, that record almost certainly will not satisfy your sales CDD obligations. Your procedures must specify how client records are reviewed and updated at the point of a new designated service, rather than leaving staff to assume prior work is sufficient.
The Property Management Oversight Gap
Property management is routinely managed by junior staff, often without the same level of principal oversight that accompanies a sales transaction. This creates a structural risk: the CDD steps that a principal would instinctively apply during a sales listing can be skipped, abbreviated, or delayed in a busy property management context. AUSTRAC's expectation is that your compliance program addresses this risk directly. Relying on informal supervision or the assumption that property management clients are lower risk does not satisfy your obligations, particularly where a landlord's financial profile or ownership structure warrants enhanced scrutiny.
Your written AML/CTF program must treat sales and property management as distinct operational streams, each with its own documented workflows, staff responsibilities, and escalation pathways. A single generic policy that does not distinguish between the two functions is unlikely to satisfy AUSTRAC's requirement for a program that reflects how your business actually operates.
What If You Cannot Complete CDD?
The legal position is unambiguous: if you cannot complete customer due diligence, you must not commence or continue providing the designated service. This is not a commercial judgment call, and it is not something you can defer until after exchange. It is a statutory obligation under Australia's AML/CTF Act. An incomplete CDD file means the legal threshold for providing that service has not been met, full stop.
When CDD Fails in Practice
Three situations account for the vast majority of CDD failures in a real estate context. First, the customer refuses to provide documents. This is one of the most common questions agents are asking right now, and the answer is clear: if a customer will not cooperate, you cannot proceed. AUSTRAC has confirmed that agents who take reasonable steps to collect and verify identity information but are blocked by a customer's non-cooperation will not be found in breach, provided those reasonable steps are documented. Second, documents are produced but cannot be verified as genuine. Collecting a document and verifying it are different obligations. Where a document raises doubts about authenticity, or where the details cannot be confirmed, CDD remains incomplete. Third, the beneficial ownership structure of a company or trust cannot be established. Where the layered entity structure obscures who ultimately owns or controls the customer, you do not have a completed file.
Having the Conversation With the Client
How you frame this conversation matters, both commercially and legally. Present the request as a legal requirement that applies to every client, not as a reflection of suspicion about the individual in front of you. A straightforward approach works well: "We are required by law to collect and verify identity information before we can proceed. This applies to all our clients." If you have formed a suspicion and are considering a suspicious matter report, you must not disclose that a report is being made or that the person's conduct is under review. That is a tipping-off obligation, and it carries its own penalties.
Documenting the Failure
When a transaction is declined or suspended because CDD could not be completed, record everything contemporaneously: what was requested, when, the customer's response, and the specific verification gap that remained. Keep those records for seven years. That documentation may become directly relevant if you later decide that a suspicious matter report is warranted, forming part of the factual foundation for that report.
Two Separate Obligations
Declining to proceed is a compliance outcome. Filing a suspicious matter report is a separate, independent obligation triggered by reasonable grounds to suspect money laundering or related conduct. A customer forgetting their passport does not warrant a report. A customer who refuses to identify beneficial owners of an offshore structure, cannot explain their source of funds, and is pushing an unusually large transaction very possibly does. Ask both questions independently, and answer them independently.
Ongoing CDD: Your Obligations Do Not End at Onboarding
Initial CDD is a snapshot. Ongoing CDD is the obligation to ensure that snapshot never becomes outdated, misleading, or dangerously incomplete. Once you have verified a customer's identity and begun providing a designated service, your responsibilities do not pause until the next transaction. They continue for the entire life of the relationship, requiring you to monitor activity, refresh records when circumstances change, and act decisively when something does not add up.
When a Review is Triggered
Several specific events should prompt a formal CDD review in a real estate context. A change in beneficial ownership is one of the most important: if a company client restructures, adds new directors, or shifts control to a different natural person, the ownership profile you verified at onboarding is no longer accurate and must be updated. A change in the nature of the transaction also triggers a review; a landlord client who suddenly moves to purchase high-value commercial property represents a materially different risk profile from the one you originally assessed. A significant gap in time between transactions carries similar weight, because a client re-engaging after years of inactivity should be treated with close to the same scrutiny as a new onboarding. Finally, any red flag identified during routine transaction monitoring, such as payments structured in amounts just below reporting thresholds, requires an immediate review and potentially a Suspicious Matter Report to AUSTRAC.
What Transaction Monitoring Actually Looks Like
Transaction monitoring at an agency level does not require sophisticated software. It requires a documented process for reviewing each transaction against your agency's own risk assessment framework. In practical terms, that means recording what was reviewed, by whom, when it occurred, what was observed, and what action followed. If a client's payment behaviour, source of funds, or instructions do not match their known profile, that inconsistency needs to be noted and assessed, not ignored because it feels awkward to raise. According to research on CDD compliance frameworks, the inability to explain a transaction pattern is itself a compliance event that demands a documented response.
Updating Records and Responding to Failed Re-Verification
When a trigger event occurs, you must attempt to re-verify the affected information and update the client's records accordingly. If a client refuses to provide updated identification or declines to disclose changes in beneficial ownership, that refusal is itself a red flag. The correct response is to suspend or refuse the transaction, file a Suspicious Matter Report if warranted, and document everything in the client file. Proceeding despite an inability to complete re-verification is not a proportionate commercial decision; it is a compliance failure with potential penalty consequences.
Assigning Ownership of the Ongoing CDD Function
Ongoing CDD does not happen unless someone in your agency is explicitly responsible for it. That person may be your designated AML/CTF compliance officer, the agency principal, or an external compliance support service engaged for that purpose. Whoever holds the responsibility, it must be documented: job descriptions, internal policies, review logs, and escalation procedures should all reflect who owns the function, how often reviews occur, and what the response process looks like when a trigger event is identified. An undocumented process is, in AUSTRAC's view, effectively no process at all.
How CDD Fits Into Your Broader AML/CTF Program
CDD does not stand alone. It is one essential pillar within a broader AML/CTF program, and understanding its place in that architecture matters because the obligations surrounding it are equally binding. A complete program for a real estate agency includes a documented risk assessment, written policies and procedures, staff training, transaction monitoring, suspicious matter reporting, and record keeping. CDD sits alongside each of these elements, not above them. Treating CDD as the entirety of your compliance obligations leaves significant gaps that AUSTRAC can identify and act on.
Your Risk Assessment Comes First
The sequencing here is not arbitrary. Your risk assessment must be completed before you design your CDD workflows, because the level of scrutiny you apply to any given customer is determined by the risk that customer poses relative to your agency's specific risk environment. An agency operating in a high-volume prestige market with frequent offshore buyers will have a different risk profile to a regional agency handling standard residential sales. Because AML/CTF is explicitly risk-based legislation, its application is different for every business. Agencies that build CDD workflows before completing their risk assessment are working backwards, and the resulting processes may be either inadequate for their actual exposure or disproportionate in ways that create operational friction without compliance benefit.
CDD Is Where Red Flags First Appear
The connection between CDD and suspicious matter reporting is direct. CDD is the process through which red flags most commonly surface: a buyer who cannot explain their source of funds, a purchaser who is evasive about beneficial ownership, or a transaction structure that does not match the customer's stated profile. When those red flags appear, the information already gathered during CDD forms the factual foundation for a suspicious matter report. The identity documents collected, the verification steps taken, and the notes recorded during the CDD process all become critical inputs to an SMR if one is required.
Record Keeping Is Not Optional
Every step of your CDD process generates records that must be retained. This includes the documents collected, the verification steps taken, and the decisions made at each point. Under the AML/CTF framework, those records must be kept for seven years from the date they are made. This applies whether the transaction proceeded, was declined, or was abandoned because CDD could not be completed. Consistent, structured record keeping from day one is not administrative housekeeping; it is a statutory obligation.
Understanding the Evaluation Deferral
Newly regulated entities can defer the first independent evaluation of their AML/CTF program, including their CDD processes, until 1 July 2029. That deferral applies to the evaluation only. It is not a grace period for building or operating the program. Your program must be functioning correctly from 1 July 2026, the mandatory commencement date. The evaluation in 2029 will assess whether your program has been working as required since commencement, not whether you have assembled something presentable by that date. Starting well matters more than the deferral timeline suggests.
Penalties for CDD Non-Compliance: What Is Actually at Stake
Non-compliance with your CDD obligations carries consequences that extend well beyond a fine. AUSTRAC's enforcement framework is graduated, publicly visible, and now fully available against real estate agencies.
Civil penalties can reach into the tens of millions of dollars. AUSTRAC can issue infringement notices for lower-tier breaches, currently up to approximately $18,780 per contravention for a body corporate, without any court proceedings. For serious or systemic failures, AUSTRAC can apply to the Federal Court for civil penalty orders reaching 100,000 penalty units per contravention. At the current Commonwealth penalty unit rate of $364, that equates to approximately $36.4 million for a corporate entity and $7.28 million for an individual. Penalties apply per contravention, meaning multiple CDD failures across multiple transactions compound total exposure rapidly. You can review AUSTRAC's published enforcement consequences directly on their website.
Personal liability is real. The AML/CTF Act does not limit exposure to the corporate entity. Agency principals, licensees, and appointed compliance officers can face individual civil penalties and, in serious cases, criminal prosecution. Deliberate facilitation of money laundering can attract up to 10 years imprisonment. The tipping-off offence, disclosing information that could compromise an investigation, carries up to two years imprisonment. These are not theoretical outcomes reserved for major banks.
AUSTRAC's toolkit extends beyond financial penalties. The regulator can issue remedial directions, accept enforceable undertakings requiring costly external audits at the agency's own expense, and seek injunctions halting specific business activities. Every enforcement action is published on AUSTRAC's public record, creating reputational damage that operates independently of any fine. The same powers used against institutions that paid $700 million and $1.3 billion in penalties now apply to property businesses. For more detail on AUSTRAC fines applicable to real estate agents, specialist guidance is available.
A conviction is not required to cause serious disruption. An audit, investigation, or enforceable undertaking can consume months of management time and significant legal costs for a small agency, long before any penalty is formally imposed. AUSTRAC has signalled a risk-based enforcement approach that prioritises wilful non-compliance over good-faith effort; however, good faith must be evidenced through dated records, screening logs, and documented procedures.
The law commenced 1 July 2026. Agencies providing designated services from that date are expected to be compliant. Ignorance of the obligation is not a statutory defence, and "we were planning to get to it" will not satisfy an AUSTRAC audit.
Who Is Responsible for CDD in Your Agency?
Every reporting entity must appoint an AML/CTF compliance officer, and for real estate agencies, the deadline to notify AUSTRAC of that appointment was 29 July 2026. This is not a formality. The compliance officer carries specific, documented responsibilities: approving the agency's CDD policy, reviewing staff decisions on higher-risk transactions, overseeing the triggers that activate ongoing CDD, and maintaining records for the mandatory seven-year retention period. AUSTRAC's focus is on whether agencies have functional systems in place, not simply whether a name appears on an enrolment form.
When the Principal Is Also the Compliance Officer
In most small to mid-sized agencies, there is no compliance team to delegate to. The principal or licensee-in-charge absorbs the compliance officer role alongside their existing responsibilities. In practice, this means personally signing off on CDD decisions for elevated-risk transactions, managing escalation when a staff member identifies a red flag, and owning the record-keeping obligation without a back-office function to support it. That concentration of responsibility is workable, but it requires deliberate systems. A mental note is not a record. A conversation is not an escalation pathway.
What "Sufficient Authority" Actually Requires
The compliance officer role carries a specific structural requirement that is easy to underestimate: the person appointed must have genuine authority to decline or pause a transaction on CDD grounds, without being overridden by commercial pressure from a principal, director, or high-performing salesperson. Where the compliance officer and the commission-motivated decision-maker are the same person, that tension becomes internal. Agencies need documented procedures that make the CDD obligation senior to the deal, not subordinate to it. Penalties of up to $19.8 million for businesses, and personal criminal liability for the licensee in charge, exist precisely because that hierarchy matters.
Outsourcing Support Without Outsourcing Accountability
Small agencies can meet these obligations without hiring a full-time compliance professional. Specialist compliance support services, such as AMLX, provide the practical resourcing behind the compliance officer role: drafting policies, building CDD workflows, training staff, and providing a dedicated line for real transaction questions as they arise. Critically, legal accountability as the reporting entity remains with the agency and its appointed compliance officer. Outsourcing the work does not transfer the obligation. What it does is give a time-poor principal the infrastructure and expertise to discharge that obligation properly.
Key Takeaways and Next Steps for Your Agency
Every agency principal needs to action five things before providing any designated service: confirm whether your business is a reporting entity, enrol with AUSTRAC within 28 days of commencing designated services, appoint an AML/CTF compliance officer, complete a money laundering and terrorism financing risk assessment, and establish working CDD workflows. These are not sequential suggestions; they are concurrent legal obligations under the reformed AML/CTF framework.
CDD must be embedded into daily operations across both sales and property management functions, not treated as a one-time onboarding formality. Two administrative deadlines carry particular urgency: the 29 July 2026 deadline to notify AUSTRAC of your appointed compliance officer, and the seven-year record keeping obligation that applies to every CDD record your agency creates from commencement.
AMLX provides the compliance infrastructure that small to mid-sized agencies need without the cost of hiring in-house. From AUSTRAC enrolment and risk assessments to CDD workflow design and staff training, AMLX covers the full compliance lifecycle, including a dedicated support line for real transaction questions as they arise. Contact AMLX for an initial consultation on CDD workflow setup, enrolment support, or a complete AML/CTF program build.

Conclusion
Customer due diligence is not just a regulatory checkbox. It is a fundamental part of running a trustworthy, compliant, and future-ready real estate agency in Australia.
To recap the key takeaways: CDD requires you to verify client identities, understand the source of funds, assess risk levels, and keep thorough records. It applies across a range of transactions and must be applied consistently across your team. Simplified and enhanced measures exist for different risk profiles, so a one-size-fits-all approach will not cut it. And with Australian regulators increasing scrutiny on the real estate sector, the cost of getting it wrong has never been higher.
Now is the time to review your current processes, train your staff, and build compliance into your everyday operations. Start with one transaction this week and apply what you have learned here. Compliance protects your clients, your agency, and your reputation.
Related Articles
Latest insights in AML.

What Is Customer Due Diligence in Real Estate? A Plain English Guide for Australian Agencies
CDD is now a statutory obligation for Australian real estate agencies under AUSTRAC's Tranche 2 reforms. This guide explains what it means, how the three tiers work, and what you must do at the desk level.

AML for Real Estate Agents: What You Must Do and How to Get It Done
Australia's Tranche 2 reforms mean real estate agents are now regulated under AUSTRAC for the first time. Here is what your agency must do, in what order, and how to build compliance without a dedicated legal team.

Choosing an Eligible Compliance Officer
Before handing AML/CTF compliance to your office manager, check the eligibility rules under section 26J — and who's the right fit for your agency.