AML Compliance for Real Estate Agents – 2026 Guide
25 AUG 2026

By Jordan Rogers, COO, Finance Director & Co-Founder of Before You Buy.
Quick Answer: What are the new AML/CTF compliance requirements for real estate agents in 2026?
Since 1 July 2026, all Australian real estate professionals involved in property transactions must comply with the Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) Act. This includes client identity verification (KYC), risk assessments, suspicious activity reporting, and maintaining records for at least seven years. Real estate agents must enrol with AUSTRAC and implement an internal AML/CTF program covering staff training, documented processes, and ongoing monitoring – all integrated into their existing transaction workflows.
AML/CTF Reform Overview

What is Tranche 2 and who does it apply to?
Australia's AML/CTF reform has been years in the making. Tranche 2 brings a significant change: for the first time, real estate professionals, lawyers, accountants, and trust and company service providers are classified as reporting entities under the AML/CTF Act.
Previously, AML/CTF obligations sat primarily with financial institutions – banks, credit providers, and other businesses operating within the financial system. Tranche 2 expands that scope considerably. From 1 July 2026, real estate agencies, property developers, and anyone providing services connected to buying, selling, or transferring real estate are captured under the legislation. You can review the full summary of obligations under the reform on the AUSTRAC website.
If you are a real estate agent involved in selling property, managing property transactions, or facilitating commercial property deals, you are a new reporting entity. This applies whether you operate as a sole trader, a boutique agency, or a large franchise. The obligations are the same.
For existing reporting entities already operating under AML/CTF frameworks, the Tranche 2 reforms introduce updated requirements and an expanded definition of designated services. New reporting entities that have not yet built their compliance infrastructure are now operating in breach of the Act and should treat this as an urgent priority.
Why real estate is considered high-risk for money laundering
The real estate sector has long been identified by the Financial Action Task Force (FATF) and AUSTRAC as a high-risk channel for financial crime. Money laundering through property transactions involves large sums, often moves quickly, and can obscure the true source of funds through layered ownership structures, trusts, and third-party arrangements.
Cross-border capital flows add further complexity. International buyers purchasing Australian residential or commercial property have historically been able to do so with limited scrutiny – making the sector attractive for concealing illicit funds derived from serious and organised crime.
According to AUSTRAC's real estate services reform guidance, property transactions remain one of the primary mechanisms for large-scale money laundering and terrorism financing in Australia. The combination of high transaction values, rapid asset appreciation, and opacity around beneficial ownership creates the conditions that allow criminal activity to go undetected.
For real estate professionals, this context matters. The anti-money laundering reforms are not administrative box-ticking – they represent a genuine effort to bring the real estate sector into the same compliance framework as financial institutions, and to close the gaps that have allowed illicit funds to flow through Australian property markets for decades.
Key Requirements for Compliance

ID verification and KYC rules for agents
Customer due diligence (CDD) is the foundation of AML/CTF compliance for real estate agents. Initial CDD must be completed before you provide designated services – that means before a property transaction is facilitated, not after.
At a minimum, your initial CDD process must include:
- Collecting and verifying government-issued identification documents,
- Identifying beneficial ownership structures (including trusts, companies, and third-party arrangements),
- Screening clients against lists of politically exposed persons (PEPs), and
- Verifying the source of funds where a high-risk profile is identified (Enhanced CDD).
Enhanced CDD applies in higher-risk situations – for example, where a client is a foreign national, uses complex ownership structures, or exhibits behaviours inconsistent with their known financial profile. In these cases, identity checks alone are not sufficient. You must take additional steps to understand where the money is coming from. The Real Estate Institute of Victoria outlines the specific due diligence expectations placed on agents under the new framework.
From an operational standpoint, real estate agencies should embed customer due diligence into the same stage as buyer onboarding and the commencement of a genuine transaction. Treating initial CDD as a separate compliance task that runs parallel to the sales process creates unnecessary friction and delays.
Baking verification into existing workflows – at the point where a buyer demonstrates genuine intent and the agency begins providing a designated service – keeps reporting obligations manageable and transactions moving. A risk‑based approach allows agencies to prioritise verification efforts toward buyers who are progressing toward an offer or exchange, while still meeting AML/CTF timing requirements.
Consistency and documentation remain critical: every client interaction that materially advances a property transaction should leave a clear, auditable record that supports both commercial decision‑making and regulatory review.
Risk assessment protocols and red flags
Every reporting entity must develop and maintain a documented AML/CTF risk assessment. Your risk profile forms the foundation of your entire compliance program.
A sound risk assessment for a real estate agency should:
- Identify the types of clients, transactions, and geographies your agency deals with,
- Document high-risk transaction profiles (e.g. all-cash purchases, rapid resales, opaque ownership structures),
- Establish procedures for monitoring unusual buyer behaviour throughout the transaction, and
- Include clear escalation procedures when red flags are identified.
Red flags to watch for include: buyers who are reluctant to provide identification, transactions funded entirely through cash or cryptocurrency, purchases made through a third party with limited explanation, buyers who show little interest in the property itself but urgency around settlement, and significant changes between the initial offer and final settlement without clear rationale.
Your risk assessment is not a one-time document. It must be reviewed regularly, particularly when your agency's risk profile changes – for example, if you move into a new market segment, take on commercial property clients, or significantly increase transaction volumes.
Suspicious activity reporting to AUSTRAC
One of the three key objectives of the AML/CTF framework is ensuring that suspicious activities are identified and reported promptly. As a reporting entity, you have a legal obligation to submit a Suspicious Matter Report (SMR) to AUSTRAC whenever a transaction gives you reasonable grounds to suspect financial crime.
Reporting obligations include:
- Suspicious Matter Reports (SMRs) – submitted when you have reasonable grounds to suspect criminal activity, money laundering, or terrorism financing,
- Threshold Transaction Reports (TTRs) – required for any single transaction involving physical currency of $10,000 or more, and
- Annual compliance reports – submitted to AUSTRAC as part of your ongoing reporting obligations.
The AML/CTF Rules 2025 for the real estate sector provide practical guidance on exactly what triggers a reporting obligation and how reports should be structured. The threshold for reporting is suspicion, not certainty. Failure to report suspicious activity is a serious compliance breach.
Internal reporting channels are just as important as external ones. Staff must know how to escalate concerns internally, and your compliance officer must have a clear process for assessing and submitting SMRs in a timely manner.
Record-keeping requirements and timelines
All reporting entities must maintain records for a minimum of seven years. This applies to customer identification documents, transaction records, risk assessments, staff training logs, and any SMRs or TTRs submitted to AUSTRAC.
Best practice is to maintain records in secure digital storage with a clear audit trail. Where possible, integrate your record-keeping into your existing property file management system to reduce duplication and compliance friction. Records must be sufficient to allow AUSTRAC or an independent reviewer to reconstruct each transaction and verify that your obligations were met.
Meeting your July 2026 obligations

AUSTRAC enrolment timeline
The enrolment window for new reporting entities opened on 31 March 2026, with full compliance required by 1 July 2026.
To enrol with AUSTRAC, you need to:
- Confirm your classification as a reporting entity and identify which designated services you provide,
- Complete your enrolment via the AUSTRAC Online portal,
- Nominate a compliance officer responsible for your AML/CTF program, and
- Provide accurate registration details including your business structure, ownership, and the types of transactions your agency facilitates.
If you have not yet enrolled with AUSTRAC, your agency is currently operating outside its legal obligations. Enrolment and program implementation should be treated as an immediate compliance gap, not a future task
Your AML/CTF program
Every reporting entity must have a documented AML/CTF program in place before providing designated services. The program has two core components:
Part A covers your risk assessment and governance framework – who is responsible for compliance, how decisions are made, how your risk profile is reviewed, and how your program is independently assessed.
Part B covers your customer identification and due diligence procedures – the step-by-step processes your staff follow when onboarding new clients, verifying identity, conducting enhanced CDD, and escalating concerns.
Your AML/CTF program should complement, not duplicate, your existing transaction compliance procedures. Agencies that design their program in isolation from their day-to-day workflows end up with two parallel systems that neither integrates well nor gets followed consistently. Build compliance into your existing processes from the start.
The program must also include a process for independent review. You cannot assess your own compliance program – the review must be conducted by someone with appropriate expertise who is not involved in the day-to-day operation of the program.
Staff training and appointing a compliance officer
Staff training is mandatory under the AML/CTF Act. All staff involved in providing designated services must receive appropriate training, and that training must be ongoing – not a one-time onboarding exercise.
Effective AML/CTF training for real estate staff should include:
- An overview of the AML/CTF framework and your agency's obligations,
- Scenario-based training on how to identify red flags in real estate transactions,
- Clear guidance on how to escalate concerns through internal reporting channels, and
- Regular updates as legislation, AUSTRAC guidance, and your agency's risk profile evolve.
Your compliance officer plays a critical role in keeping your program on track. Choose someone with sufficient seniority and authority to make decisions, access all relevant transaction information, and hold staff accountable. In smaller agencies, this may be the principal. In larger ones, a dedicated compliance role may be warranted.
RegTech for Compliance

What is RegTech? Real estate use cases
RegTech (regulatory technology) refers to software platforms and digital tools designed to help businesses manage compliance obligations efficiently. For real estate agencies navigating new AML/CTF requirements, RegTech offers a practical path to staying compliant without building entirely manual processes.
Common RegTech applications in real estate compliance include automated identity verification, digital document management, risk scoring dashboards, and audit trail generation. These tools can dramatically reduce the time your team spends on compliance administration while improving consistency and accuracy. The latest PropTech trends shaping the real estate industry offer useful context on how digital tools are reshaping the way agents manage both client relationships and compliance workflows.
How digital ID verification supports KYC
Digital identity verification tools allow agents to complete initial CDD quickly and accurately without relying on manual document checks. Most platforms use a combination of biometric verification, document authentication, and real-time database checks to confirm a client's identity within minutes.
For busy agents managing multiple listings simultaneously, this matters enormously. Manual ID checks are time-consuming, inconsistent, and easy to skip under pressure. Automated verification removes the friction while creating an auditable record of every check performed – exactly what AUSTRAC requires.
Using AI for anomaly detection and reporting
Artificial intelligence tools are increasingly being used to support AML/CTF compliance through pattern recognition and behavioural monitoring. Rather than relying on staff to identify red flags manually, AI-powered platforms can analyse transaction data in real time and flag anomalies that may indicate suspicious activity.
For real estate agencies handling high transaction volumes, automated anomaly detection reduces the risk that suspicious activity goes unnoticed due to workload or human error. Some platforms also support automated SMR triggers – generating draft reports for compliance officer review when predefined risk thresholds are met.
Cost of Compliance vs Non-Compliance

Common penalties and risks for non-compliance
The financial and reputational consequences of non-compliance are significant. Under the AML/CTF Act, civil penalties for serious or repeated breaches can reach $19,800 per day. For real estate agencies operating on commission-based revenue, even a short period of regulatory disruption can cause serious financial harm.
Beyond direct penalties, non-compliance carries reputational risk. Regulatory investigations are rarely private. An agency that appears on AUSTRAC's enforcement radar will find that vendors, buyers, and industry peers take notice. In a sector where trust is already in short supply – only 5% of Australians currently rate real estate agents as trustworthy – a compliance breach can do lasting damage to the relationships that drive referral-based business.
There are also indirect costs: legal fees, remediation work, business interruption during regulatory review, and the management time consumed by enforcement proceedings. The cost of getting compliance right upfront is a fraction of what non-compliance can cost.
Cost-effective strategies to stay compliant
Compliance does not have to be expensive or disruptive if it is approached thoughtfully. The agencies that will manage this transition most effectively are those that embed AML/CTF compliance into their daily operations rather than treating it as a separate overhead.
Practical strategies to manage compliance costs include:
- Automating repetitive checks using RegTech tools that integrate with your existing CRM,
- Standardising client onboarding processes so that identity verification and risk assessment happen consistently from the first point of contact, and
- Centralising documentation in a secure digital system that doubles as your compliance record.
Frequently Asked Questions
Do all real estate agents need to comply with AML laws in 2026?
Yes. All reporting entities involved in property transactions must comply under Tranche 2 reforms from 1 July 2026. This includes residential sales agents, commercial property agents, property managers involved in certain transactions, and property developers. If you provide designated services connected to buying, selling, or transferring real estate, you are captured by the legislation.
What happens if an agency fails to enrol with AUSTRAC?
Failure to enrol may result in daily civil penalties and regulatory enforcement action. AUSTRAC has the authority to investigate non-compliant entities, issue infringement notices, and pursue court-ordered penalties for serious breaches. Enrolment is not optional – it is a legal requirement for all new reporting entities.
How do I verify the source of client funds?
Source of funds verification is part of Enhanced CDD and applies in higher-risk situations. It typically involves requesting and reviewing documentation such as bank statements, loan approval letters, sale contracts for a prior property, or statutory declarations. The level of verification required depends on the risk profile of the client and the transaction.
What is Enhanced Due Diligence (EDD)?
Enhanced CDD is additional identity and source-of-funds verification applied to clients or transactions that present a higher risk of money laundering or terrorism financing. Triggers for enhanced CDD include politically exposed persons, transactions involving unusual structures or large cash components, and clients who are reluctant to provide standard documentation.
Do I need to train my staff in AML/CTF compliance?
Yes. Ongoing staff training is mandatory under the internal AML program requirements. Training must be role-appropriate, regularly updated, and documented. Your compliance records should include evidence that all relevant staff have completed required training.
What is considered a suspicious transaction?
Any transaction that appears inconsistent with a client's known profile, lacks clear economic rationale, or involves behaviours associated with financial crime may warrant a Suspicious Matter Report. Examples include clients who are unusually focused on settlement speed, who change ownership structures mid-transaction without explanation, or who offer to pay significantly above market value without clear reason.
Can software automate AML/CTF reporting for my agency?
Yes. Many RegTech platforms support automated reporting, audit trail generation, and SMR drafting. The right platform will integrate with your existing CRM and document management systems, reducing the administrative burden on your team while ensuring reporting obligations are met consistently.
How often do I need to review my AML/CTF program?
Your program must be reviewed regularly and independently, particularly when there is a significant change in your agency's risk profile, ownership structure, or the types of designated services you provide. AUSTRAC guidance recommends a formal independent review at least annually, with internal reviews conducted more frequently.
Stay ahead of your AML/CTF compliance obligations

Whether you are one of the new reporting entities building an AML/CTF program from scratch, or an existing reporting entity updating your processes to meet the expanded requirements, closing this gap now limits your exposure to the penalties outlined above.
If you'd like to find out more about compliance prior to offers, drop us a line.