Real Estate Agents and AML/CTF Obligations: What the Expanded Regulatory Perimeter Means for Your Business

If you sell property in Australia, the rules governing your business changed significantly on 1 July 2026. Under the AML Tranche 2 reforms, real estate agents, buyer's agents, and property developers are now captured by Australia's Anti-Money Laundering and Counter-Terrorism Financing Act for the first time, placing them under direct AUSTRAC oversight. This is not a minor administrative update. It is a fundamental shift in how real estate professionals must operate.
The property sector has long been identified as a high-risk channel for money laundering, and regulators have moved to close that gap. Whether you are a selling agent, a buyer's agent, or a developer arranging direct sales, you now have legal obligations to meet, including enrolling with AUSTRAC, verifying your clients' identities, applying a risk-based approach to transactions, and lodging reports when required.
This guide breaks down exactly what those obligations mean in practice. You will learn who is covered, how to enrol, what a compliant AML/CTF program looks like, and how to meet every requirement without building a dedicated compliance department from scratch.
What the AML/CTF Reforms Actually Mean for Real Estate Agents
On 1 July 2026, Australia's AML/CTF reforms moved from legislation to live obligation, bringing real estate agents under AUSTRAC's regulatory framework for the first time. This is not a gradual transition; it is a hard compliance date, and it represents one of the most significant regulatory shifts the Australian real estate sector has ever faced.
Under the Anti-Money Laundering and Counter-Terrorism Financing Act, real estate agents are now classified as reporting entities. That classification carries the same category of AUSTRAC obligations that banks and financial institutions have operated under for years, applied specifically to your regulated activities.
The sector was targeted deliberately. Property is a well-documented vehicle for money laundering: transaction values are high, cross-border buyers are common, and settlement processes sit close to cash. The Financial Action Task Force (FATF) publishes risk-based guidance specifically for the real estate sector, reflecting its recognised global vulnerability. Australia's reforms align the domestic regime with those international standards, closing a gap that had left property transactions comparatively exposed.
For real estate professionals, the practical consequence is significant. The shift from unregulated to regulated is not incremental. It requires you to:
Enrol with AUSTRAC before transacting designated services
Build a written AML/CTF compliance program specific to your business
Establish KYC and customer due diligence workflows integrated into your transaction process
If you are unsure where to begin, Personr's Tranche 2 compliance checklist outlines the concrete steps your agency needs to take. The sections that follow break each obligation down in practical detail.
Which Real Estate Professionals Are Covered Under the New Rules
Knowing that obligations now apply is one thing; knowing whether they apply to your business is another. Coverage turns on the nature of the service you provide, not the title on your licence.
Selling agents and buyer's agents are the primary targets of the reforms. Property developers and direct sellers fall into the same category; a developer selling off-the-plan units without a licensed agent in the transaction carries identical obligations to a traditional agency.
Certain services are not designated services under the new regime, refer to AUSTRAC's real estate designated services guidance for the current list of excluded activities, as the boundaries matter for agencies operating across multiple service lines.
If your business arranges the sale, purchase, or transfer of real property as part of a business operation, you are providing a designated service, and enrolment with AUSTRAC follows. When in doubt, understanding how designated services are defined across professional sectors provides useful framing.
For agencies operating across multiple service lines, each service must be assessed separately. A principal running both a selling agency and a property management business is a reporting entity in respect of the sales function only. The management side carries no AML/CTF obligations, but the two must not be conflated in your compliance program. Understanding how professional obligations interact across service types is something Personr's legal partnerships are specifically designed to support.
How to Enrol With AUSTRAC as a Real Estate Reporting Entity
Once you have confirmed your business provides a designated service, enrolment with AUSTRAC is your immediate next step.
Enrol with AUSTRAC through AUSTRAC Online, the regulator's secure portal. Enrolment opened on 31 March 2026 and must be completed before your business provides any designated real estate services after 1 July 2026.
What you will need to provide:
Your business's legal structure (sole trader, company, partnership, or trust)
The specific designated services your business provides
Details of the key personnel responsible for your AML/CTF compliance
Enrolment vs registration: use the correct pathway
Real estate agents enrol, they do not register. Registration is a separate AUSTRAC pathway that applies to remittance dealers and virtual asset service providers. Submitting via the wrong pathway causes processing delays, so confirm you are selecting the enrolment option before you begin.
Already enrolled for another reason?
If your business holds an existing AUSTRAC enrolment as a financial services provider or in another capacity, you must still update that enrolment to add your newly designated real estate services. An existing enrolment number does not automatically extend to new service types.
Cost and consequences
Check the AUSTRAC Online portal for any applicable fees before you begin. Providing designated services after 1 July 2026 without completing enrolment is a breach of the AML/CTF Act.
After enrolment
AUSTRAC will issue your business an enrolment number. Keep this on file and include it in your AML/CTF compliance program documentation. It is the reference point for all future AUSTRAC interactions.
Building Your AML/CTF Compliance Program: The Core Requirements
Once enrolment is complete, your next obligation is to have a written AML/CTF program in place before you provide any designated service. This is a legal requirement under the Anti-Money Laundering and Counter-Terrorism Financing Act, not a best-practice document you can defer.
The program must be risk-based. That means it is tailored to your specific business: the types of clients you deal with, your transaction volumes, whether you work with international buyers, and the mix of services you provide. A boutique agency handling five sales per year in a regional market carries different risks than a metro agency transacting high-value properties with offshore buyers. Your program must reflect those differences.
A compliant program must be risk-based and documented. Core elements include customer identification and verification (KYC), an AML/CTF risk assessment, employee training procedures, and an independent review mechanism, refer to AUSTRAC's program guidance for the definitive structural requirements.
The program must be approved by your board or senior management and reviewed at regular intervals as required by AUSTRAC guidance. A material change to your business, such as expanding into new markets or taking on a new buyer demographic, triggers an earlier review.
AUSTRAC does not supply a template. Every agency must develop documentation specific to its own operations. You can create your AML program using Personr's policy templates, risk assessment frameworks, and centralised document hosting, which removes the need to build these from scratch.
For smaller agencies without dedicated compliance staff, document exactly who is responsible for each program element by name. Named accountability is a key indicator AUSTRAC looks for when assessing program adequacy during audits.
KYC and Customer Due Diligence: Verifying Buyers and Sellers at Every Transaction
With your compliance program drafted, KYC is where that program meets every transaction in practice.
For most real estate agents, this means building a consistent verification step into the point of client engagement, before contracts are exchanged.
Verifying individuals
For individual buyers or sellers, collect a primary photographic document (passport or driver's licence) plus a secondary document confirming residential address, such as a utility bill or bank statement. Together, these must establish the person's full legal name, date of birth, and current address. Refer to Personr's KYC Guide for a practical breakdown of acceptable document combinations under the Australian framework.
Verifying companies and trusts (KYB)
When your customer is a company or trust, the process goes deeper. You must verify the entity's registration, confirm it is the legal party to the transaction, and identify any beneficial owners: individuals who ultimately own or control 25% or more. Layered corporate structures require you to look through each layer until you reach a natural person.
When verification must occur
CDD must be completed before or during the provision of the designated service. In a property sale, that means verification must happen no later than contract execution. Deferring it to settlement is non-compliant.
When standard CDD does not apply
Enhanced due diligence (EDD) is required for higher-risk customers: foreign nationals purchasing high-value property, customers connected to high-risk jurisdictions, or transactions involving unusual payment arrangements. EDD requires deeper scrutiny and additional documentation beyond the standard threshold.
Simplified due diligence may apply where the customer is a listed Australian company or a government body, but err toward standard CDD unless the exemption criteria are clearly and documentably met.
Ongoing monitoring
Verification at onboarding is not the end. If a customer's circumstances change materially during the transaction, such as a sanctions match appearing or a politically exposed person designation, you must update their records and reassess risk immediately.

Applying a Risk-Based Approach to Your Real Estate Transactions
Knowing what to verify is only half the task. Knowing how deeply to verify it depends on risk.
The AML/CTF framework is risk-based, not rules-based. AUSTRAC does not prescribe identical procedures for every transaction; it requires that your level of scrutiny matches the money laundering or terrorism financing risk each transaction actually presents.
Key risk factors to assess for every transaction:
Transaction value: High-value properties warrant closer attention as standard
Buyer origin: International buyers or entities incorporated offshore carry elevated risk
Ownership complexity: Multiple trusts or layered company structures require deeper investigation
Payment source: Contributions from third parties not named in the contract are a significant red flag
Low-risk transactions involve domestic buyers, established Australian individuals, standard residential property, and straightforward payment structures. For these, standard CDD, a single identity verification check, and routine monitoring are generally sufficient.
Higher-risk transactions requiring enhanced due diligence include cash-adjacent settlement contributions, buyers operating through multiple intermediaries, corporate purchasers where beneficial ownership is unclear, and repeat transactions from the same buyer across a short period.
Your AML/CTF program must document your risk-tiering methodology in writing. AUSTRAC expects to see a risk assessment that explains which risks your business identified and how your procedures respond to each tier. A stated methodology also protects you if your approach is ever questioned during a review.
Critically, your risk assessment is not a one-time document. Review it when you take on materially different transaction types, expand into new geographic markets, or when AUSTRAC publishes updated typologies for the real estate sector.
To get a structured starting point, you can assess your AML/CTF risk exposure before drafting your program documentation.
Reporting Obligations: What You Must Lodge With AUSTRAC and When
Once your risk-based procedures are in place, they need to connect directly to AUSTRAC's reporting framework. Two types of reports apply to real estate agents.
Suspicious Matter Reports (SMRs)
You must lodge an SMR with AUSTRAC whenever you form a suspicion, on reasonable grounds, that a transaction may involve money laundering, terrorism financing, or proceeds of crime. The trigger is suspicion, not proof. Observable indicators are sufficient and legally adequate. Waiting for certainty is not an option; the obligation arises the moment reasonable suspicion forms.
Deadlines for lodging SMRs are set out in the AML/CTF Act, check the current AUSTRAC guidance for the applicable timeframes. There are no grace periods.
Threshold Transaction Reports (TTRs)
TTRs apply to physical cash transactions above the prescribed threshold set out in the AML/CTF Act. In real estate, this most commonly arises from cash deposits paid toward a property purchase. Check the AUSTRAC guidance for the current applicable amount.
The Tipping-Off Prohibition
Once you have lodged, or decided to lodge, an SMR, you must not disclose the existence of that report to the customer or any person named in it. Tipping off is a serious legal prohibition under the AML/CTF Act. Every staff member with any involvement in a transaction must understand this prohibition before your agency begins operating under the new regime.
Maintaining an SMR Register
Keep an internal register of every SMR lodged, with enough detail to reconstruct the basis of each report. Senior management and auditors must be able to access this register; operational staff who have no compliance role should not. Store it centrally, separate from general transaction files, and treat it as a restricted document.
Sanctions Compliance: The Obligation That Runs Alongside AML/CTF
Beyond your AUSTRAC reporting obligations sits a separate but complementary requirement: sanctions compliance, administered by the Department of Foreign Affairs and Trade (DFAT), not AUSTRAC.
Australia maintains two categories of sanctions. UN Security Council sanctions are mandatory under international law. Australian autonomous sanctions are domestic foreign policy instruments. Both prohibit dealings with designated individuals, entities, and countries, and both bind real estate agents. Facilitating a property transaction involving a sanctioned party is a serious offence, whether you knew about the designation or not. Ignorance is not a defence.
What to screen and when
Screen every customer against DFAT's Consolidated List at the same point KYC verification occurs, before or at contract execution. If the transaction extends significantly beyond that point, or if new designations are issued while the deal is live, screen again. The Consolidated List currently contains over 9,300 designated individuals, entities, addresses, and vessels across 88 countries, which makes manual checking impractical at any real transaction volume.
For corporate buyers, screening the named entity is not sufficient. You must also screen every beneficial owner, tracing through the ownership structure to the individuals who ultimately control 25% or more of the purchasing entity.
Why real estate is a priority sector
DFAT has published a dedicated Guidance Note on sanctions compliance specifically for real estate professionals. The sector's elevated risk profile reflects its international buyer base, large transaction values, and frequent use of offshore corporate structures.
A practical workflow for smaller agencies
Integrate sanctions screening directly into your KYC workflow rather than treating it as a separate manual step. A compliance platform that runs Consolidated List checks at the point of identity verification creates a timestamped, auditable record of each screening event, without requiring a separate login or process.
Record-Keeping Requirements: What to Keep and for How Long
Once your screening and sanctions records are in order, you face an equally important question: where do all these documents live, and for how long?
You must retain all KYC and CDD records for the period prescribed under the AML/CTF Act, confirm the current retention period in AUSTRAC's guidance for your specific record categories.
Records you must retain include:
Identity verification documents and the method used to verify them
Transaction records and supporting documentation
Risk assessments conducted for specific clients or transactions
All Suspicious Matter Reports and their supporting materials
Records must be stored so they can be retrieved and provided to AUSTRAC within a reasonable timeframe upon request. Confirm with AUSTRAC's guidance what formats are acceptable for record storage, the regulator's requirements should govern your choice of medium. Records must be legible, organised, and clearly attributable to specific customers and transactions.
A common gap to avoid: do not rely solely on your property management or CRM system for AML record-keeping unless it has been specifically configured to meet AUSTRAC's retrieval and retention standards. Most real estate CRMs were built to manage listings and client relationships, not regulatory documentation.
Staff turnover creates another risk. When a team member leaves, their compliance records must stay with the business. KYC documentation stored in personal email accounts or on local device folders is effectively lost to the agency. All records must sit in systems the business controls.
Platforms like Personr centralise KYC records, verification results, and screening history in one auditable location. This eliminates the fragmented documentation that most commonly creates gaps when AUSTRAC conducts an audit or review.
Multi-Agency Sales and Third-Party Relationships: How KYB Obligations Work
Record-keeping covers what you retain. This section addresses a separate complexity: what happens when multiple parties are involved in the same transaction, or when your customer is a company rather than an individual.
Independent obligations in multi-agent transactions
When a selling agent and a buyer's agent both provide designated services in the same transaction, each carries independent AML/CTF obligations. Neither agent can rely on the other's KYC procedures. If the buyer's agent has verified the purchaser's identity, the selling agent cannot treat that verification as satisfying its own obligations. Both must conduct their own checks, maintain their own records, and lodge their own reports where required.
Third-party reliance arrangements
Agents sometimes arrange for a solicitor or mortgage broker to conduct customer identification on their behalf. This is permitted, but the agent retains full legal responsibility for the adequacy of that identification. If the third party's verification is deficient, the agent is exposed. Any reliance arrangement must be documented in your AML/CTF program, and you should review it regularly. AUSTRAC scrutinises these arrangements closely because they are a recurring failure point in multi-party transactions.
KYB when your customer is a corporate entity
When your customer is a company or trust, apply KYB procedures as outlined in the CDD section above, verify registration, trace beneficial ownership to the 25% threshold, and assess structural risk, then apply these same checks to the development entity itself when a developer is the seller.
Penalties for Non-Compliance: What Real Estate Agents Risk
Getting your compliance workflows right matters, but so does understanding what happens when they fall short.
AUSTRAC holds broad enforcement powers: civil penalty orders, enforceable undertakings, injunctions, and criminal prosecution for the most serious breaches. The regulator has a track record of pursuing substantial civil penalties against large financial institutions, and has made clear it will apply the same enforcement rigour to newly regulated sectors.
Civil penalties for serious breaches can be substantial for corporations of all sizes. For sole traders and small agencies, penalties are proportionally scaled but remain material enough to threaten business viability.
Remedial directions add another layer. AUSTRAC can direct a business to take specific corrective steps within a defined timeframe. Failing to comply with a remedial direction is itself a separate offence, compounding the original liability.
Reputational damage compounds financial penalties. AUSTRAC publishes all enforcement outcomes on its public register. An adverse finding against your agency is visible to prospective clients, competitors, industry bodies, and the press. In a relationship-driven industry, that exposure carries consequences well beyond any fine.
Tipping off carries serious criminal liability under the AML/CTF Act, and any staff member who could be involved in a suspicious matter report scenario must understand this prohibition.
AUSTRAC has signalled a compliance-first approach for new Tranche 2 entities in the early period after 1 July 2026. Demonstrable good-faith efforts will be taken into account. Wilful non-compliance will not be excused, and enforcement is not suspended during this period.
How to Meet Your Obligations Without Building a Compliance Department
The good news is that proportionality is built into the framework. A sole trader completing ten transactions a year does not need the compliance infrastructure of a national franchise; the program must fit the actual risk profile and scale of your business.
Step 1: Designate a compliance officer now. This does not require a specialist hire. Appoint a principal, partner, or senior property manager to own the AML/CTF program, complete baseline training, and serve as the internal escalation point. The role needs documented accountability, not a new headcount.
Step 2: Use technology to carry the administrative load. A purpose-built platform like Personr consolidates KYC verification, KYB checks, sanctions screening, ongoing monitoring, policy hosting, and risk assessments into one workflow. That eliminates spreadsheets, separate tools, and the manual effort of stitching processes together across a transaction.
Step 3: Start with authoritative reference materials. REIA's published fact sheets and AUSTRAC's guidance materials, including the Real Estate Program Starter Kit, give you a compliant baseline. Supplement these with platform-driven workflows that prompt the right action at the right point in the transaction, so staff are guided rather than left to remember.
Step 4: Train client-facing staff on the essentials. Every staff member who interacts with clients needs to know what to collect, when to collect it, what raises a suspicion, and who to escalate to. This does not need to be a formal course, but it must be documented as having occurred. A short briefing with a sign-off record satisfies the requirement.
Step 5: Build your compliance calendar. Set recurring reminders for your annual program review, staff training refreshers, and the mandatory independent review cycle. Compliance does not end at enrolment; it is an ongoing operational responsibility that must be actively maintained.
Conclusion: Your Next Steps Before and After 1 July 2026
The groundwork covered in previous sections gives you everything you need to act. What remains is sequence and timing.
Step 1: Confirm your status. If your business arranges the sale, purchase, or transfer of real property as part of a business operation, you are almost certainly providing a designated service, refer to AUSTRAC's real estate designated services guidance to confirm where your specific services fall.
Step 2: Enrol early. Enrolment via AUSTRAC Online opened on 31 March 2026. Do not defer this until June. Delays compress your implementation window further.
Step 3: Finalise your compliance program before 1 July 2026. Your written AML/CTF program must be risk-based and specific to your business. A generic template that has not been adapted to your client types, transaction volumes, and geographic exposure will not satisfy AUSTRAC's requirements.
Step 4: Embed KYC and sanctions screening into your contract workflow as set out earlier in this guide. Build this into your standard transaction checklist so it becomes routine rather than reactive.
Step 5: Use a centralised platform. Managing KYC, KYB, sanctions screening, records, and policy documentation across separate tools creates gaps that a single compliance platform eliminates, and the efficiency case and the risk case point in the same direction.
Step 6: Schedule regular reviews. The AML/CTF regime will continue to develop beyond 1 July 2026. Build annual program reviews into your calendar now, and monitor AUSTRAC guidance for updates specific to the real estate sector.





