Real Estate AML/CTF

AUSTRAC Compliance for Real Estate Businesses

Australian AML/CTF guidance for covered real estate agency and direct development sales, including CDD, risk, monitoring, SMRs, records and implementation.

Coverage depends on the service being provided

Australia's AML/CTF regime has applied to specified real estate services since 1 July 2026. Coverage is based on the activity and its connection with Australia. It can include businesses that broker the sale, purchase or transfer of real property on behalf of another person, together with qualifying property developers or other businesses that sell directly without an independent real estate agent. A broad description such as property professional does not establish that every service is regulated.

A genuinely private sale, or an incidental property disposal outside the provision of a business service, is generally outside this designated-service coverage. Direct development sales can be covered when property is sold in the course of business and the statutory conditions are met. Each business should map its actual services, entities and locations against the AML/CTF Act and Rules and document the result.

Customer due diligence occurs in two stages

For a listing agency, the seller who appoints the agency is a customer from engagement. For a buyer's agency, the appointing buyer is a customer from engagement. The agency should complete CDD on that customer within the required statutory timing, identify the person giving instructions, confirm any representative's authority and understand the purpose and expected nature of the relationship.

When the property transaction is reasonably expected to proceed, the agency also starts providing the designated service to the other transaction party. AUSTRAC's real estate guidance generally identifies this point as acceptance of the offer and signing of the sale contract. The buyer then also becomes a customer of the listing agency, while the seller also becomes a customer of the buyer's agency. The agency must complete the CDD required for each customer.

CDD should reflect each customer's legal form and role. Representatives, beneficial owners, controllers, payers and recipients of settlement funds can require identification, authority checks or further enquiries. For a qualifying direct sale by a developer or another business selling on its own behalf, the business should identify the purchaser as required by the applicable designated-service and CDD rules.

CDD timing and auctions

Engagement, listing, buyer-agency and contract workflows should capture both customer triggers and prevent the service from advancing beyond the point permitted by the Act and Rules while required checks remain incomplete. The file should record when each party became a customer, which evidence was obtained and whether any delayed verification provision was used.

Auctions require procedures for sellers, registered bidders, successful bidders and representatives. A specific delayed-verification provision may apply when its statutory conditions are met, including where earlier verification would significantly disrupt the ordinary course of auction business. The agency should document the legal basis, collect available information before the auction and complete verification within the permitted period. A general assumption that all auction CDD can be deferred is insufficient.

Individuals, entities, trusts and estates

CDD for an individual includes collecting and verifying prescribed identity information. Where a person acts for the customer, the agency should verify the representative and confirm authority through an agency agreement, power of attorney, corporate authorisation or other reliable evidence.

For a company or other entity, the agency should verify its existence and relevant details, identify beneficial owners and understand who controls the transaction. Company searches, constitutional records, ownership charts and reliable registry information may be needed. Complex structures require an explanation that is consistent with the stated purpose.

Trust work requires identification of the trust, trustee and other people required by the Rules, together with beneficial ownership and control information. For a deceased estate, the agency should identify and verify the executor or administrator and confirm authority using probate, letters of administration or other appropriate documents. The checks should match the legal capacity in which the property is held or transferred.

Assessing customer and transaction risk

The AML/CTF program should connect the business-wide risk assessment to individual customers and transactions. Relevant factors include the service provided, customer type, ownership complexity, property type and value, delivery channel, countries involved, payment method, source of funds, use of intermediaries and whether the activity fits the customer's known circumstances.

A lower-risk local transaction with transparent ownership may require standard controls. Enhanced measures may be appropriate where ownership is obscured, funds come from an unexpected third party, the structure lacks a clear commercial reason, a PEP is involved or relevant sanctions and high-risk jurisdiction concerns arise. Risk ratings should be supported by recorded facts and should change when new information changes the assessment.

Customer and transaction indicators

Customer indicators can include reluctance to provide identification, inconsistent explanations, unusual concern about reporting, unexplained representatives, documents that appear altered, nominee ownership without a clear reason or a profile that does not support the proposed purchase. A PEP connection, adverse information or links to a higher-risk jurisdiction should be assessed with the wider context.

Transaction indicators can include unexplained physical currency, deposits paid by unrelated parties, settlement proceeds directed elsewhere without a clear basis, rapid resales at materially different values, unusual overpayment or underpayment, repeated deposit refunds, unnecessarily complex structures, opaque offshore funding or pressure to complete before checks are finished. An indicator is a prompt for enquiry and does not by itself prove criminal activity.

Staff should record the question asked, information obtained and effect on the risk assessment. If the explanation does not resolve a material inconsistency, the matter should move to the compliance officer or another authorised decision-maker.

Ongoing monitoring and CDD updates

Monitoring should reflect the duration and risk of the customer relationship. Relevant events include changes to beneficial ownership, representatives, payment instructions, source of funds, settlement recipients, transaction value, property use or countries involved. A material departure from the expected activity may require updated CDD, enhanced measures or escalation.

Periodic reviews can support longer agency or development relationships, while event-driven review is often more useful for a discrete property transaction. The program should define who receives alerts, what information is reviewed and how the outcome is recorded.

Suspicious matters and other reports

A reporting entity must submit an SMR when it has reasonable grounds for the suspicion described in the AML/CTF Act. The usual reporting period is 24 hours for a suspicion related to terrorism financing and three business days for other suspicious matters. Staff should escalate promptly because the reporting period can begin before an internal review is complete. Information about an SMR must be handled in accordance with the tipping-off restrictions.

The purchase price does not by itself create a threshold transaction report. A TTR concerns a reporting entity transferring physical currency of A$10,000 or more, or the foreign currency equivalent, in the course of providing a designated service. Agencies should assess their actual payment handling rather than treating every high-value property sale as a TTR event.

Records, training and accountable implementation

The business should retain required CDD, transaction, risk assessment, monitoring, reporting, approval and AML/CTF program records. Many categories have a seven-year retention period, with the starting point depending on the record. Access controls should protect personal information and the confidentiality of suspicious matter material.

Training should be relevant to each role. Sales agents need to recognise onboarding triggers and escalation indicators. Finance and trust-account staff need procedures for third-party payments, refunds and physical currency. Managers need authority to pause work, approve higher-risk relationships and support reporting decisions.

An appropriately positioned AML/CTF compliance officer should oversee day-to-day compliance with enough authority, access and resources to perform the role. Senior management or the governing body should approve the program where required, receive meaningful compliance information and address deficiencies.

Implementation should include a documented service-coverage assessment, customer and counterparty data fields, CDD workflows, risk rules, screening, monitoring, escalation, record retention, staff training and independent evaluation. Testing with realistic seller, buyer, company, trust, estate, auction and direct-development scenarios can identify gaps before they affect a live transaction.

Real estate AML/CTF controls

  • Confirm service coverage

    Map each agency or direct sale activity to a designated service and confirm its Australian connection.

  • Apply two-stage CDD

    Complete CDD on the appointing party at engagement and on the other transaction party when the sale is expected to proceed.

  • Understand ownership

    Verify entities, trusts, estates, beneficial owners, controllers and each representative's authority.

  • Assess property risk

    Consider the customer, service, transaction, payment method, geography and delivery channel together.

  • Monitor and escalate

    Review material changes and give staff a documented route for enquiries and suspicious matter decisions.

  • Implement the program

    Appoint accountable personnel, train relevant staff, test procedures and retain evidence of operation.

Real estate compliance questions

Are all real estate professionals reporting entities?

Coverage depends on whether a business provides a designated service with the required Australian connection. Relevant services include specified brokering activities and qualifying direct sales by developers or other businesses. A job title alone does not determine coverage.

Are private property sales covered?

A genuinely private sale or an incidental disposal outside a business service is generally outside the real estate designated service. A developer selling property directly in the course of business can be covered where the statutory conditions are met.

Who is the customer of a real estate agency?

At engagement, the appointing seller or buyer is the agency's customer. Once the property transaction is reasonably expected to proceed, both buyer and seller are customers for the relevant designated service. This means the buyer also becomes a customer of the listing agency, and the seller also becomes a customer of the buyer's agency.

When should initial CDD be completed?

Complete initial CDD on the appointing customer at engagement and on the other transaction party when the sale is reasonably expected to proceed. The exact timing must follow the AML/CTF Act and Rules, including the conditions for any delayed verification that applies to an auction.

Does every property transaction require a threshold transaction report?

A property price or settlement amount does not itself create a threshold transaction report. TTR obligations concern a reporting entity's transfer of physical currency at or above the statutory threshold while providing a designated service. The facts and payment method must be assessed.

How long should AML/CTF records be kept?

Many customer identification, transaction and program records must be retained for seven years, although the event that starts the retention period varies by record type. The record schedule should reflect the current Act and Rules.