Automation by IndustryAI Security, Privacy and Compliance

How Do Real Estate Agents Automate AML/CTF Customer Due Diligence Under Tranche 2?

Last updated 24 July 2026 · 6 min read

Direct Answer

Real estate agents, buyer's agents, and off-the-plan developers became AUSTRAC-regulated "reporting entities" under Australia's Tranche 2 AML/CTF reforms, with enrolment required by 29 July 2026 and full obligations in force from 1 July 2026. Automating this means: an AML/CTF program document that a compliance officer maintains and staff are trained against; customer due diligence collected and verified at the point of engagement (not after an offer is accepted) with automatic escalation to enhanced due diligence for a politically exposed person or a high-risk jurisdiction link; ongoing sanctions and PEP screening rather than a one-off check; and a workflow that lets staff flag and lodge a suspicious matter report to AUSTRAC without needing to remember the process from memory under time pressure. This sits on top of, not instead of, the listing and transaction management automation most agencies already run.

Detailed Explanation

Australia's AML/CTF regime historically applied to banks, casinos, and a small number of other "Tranche 1" industries. The Tranche 2 reforms extend it to real estate agents, buyer's agents, and developers selling property off-the-plan — bringing an entirely new compliance layer to an industry that previously had no AUSTRAC reporting obligations at all. Enrolment as a reporting entity is required by 29 July 2026, with the substantive obligations (a documented AML/CTF program, customer due diligence, ongoing monitoring, and suspicious-matter reporting) in force from 1 July 2026.

This is a fundamentally different automation problem from listing and transaction management automation, which most agencies already run. Listing and transaction tools manage the deal itself — syndication, inspections, settlement deadlines. AML/CTF compliance runs alongside the deal, gating who the agency does business with and generating a separate paper trail that AUSTRAC, not the buyer or seller, is the audience for.

The AML/CTF program. Every reporting entity needs a documented program describing how it identifies and manages money-laundering and terrorism-financing risk specific to its business, names a compliance officer, and sets out staff training requirements. This is a governance document first — automation supports it (tracking training completions, program review dates) but doesn't replace having one.

Customer due diligence at the point of engagement. Rather than verifying a buyer's or seller's identity only once an offer is close to being accepted, due diligence needs to happen when the agency actually takes the customer on — collecting identity documents, verifying them, and checking for politically exposed person (PEP) status or sanctions-list matches as a standard intake step, not an afterthought triggered by a large or unusual deal.

Ongoing screening, not a one-off check. Sanctions lists and PEP status change over time; a customer who cleared screening at intake might later appear on an updated list. Automating a periodic re-screen against current lists — rather than treating the initial check as permanent — is what "ongoing" due diligence actually requires.

Escalation to enhanced due diligence. A standard identity check is enough for most customers, but a PEP match, a high-risk jurisdiction connection, or an unusual transaction structure should automatically trigger a stricter, better-documented enhanced due diligence process rather than being handled the same way as a routine buyer.

Suspicious matter reporting. Staff need a fast, low-friction way to flag a concern to the compliance officer, who assesses whether it clears AUSTRAC's reporting threshold and lodges a suspicious matter report if so — a process that works poorly if it depends on an agent remembering an unfamiliar procedure under time pressure during a live transaction.

Setting This Up

  1. Enrol with AUSTRAC before the 29 July 2026 deadline and build the AML/CTF program document first. Automation supports a compliance program; it can't substitute for having the governance documentation and named compliance officer AUSTRAC requires as the foundation.
  2. Move identity verification and screening to the start of the customer relationship, using an identity-verification and PEP/sanctions-screening service integrated into the agency's CRM or transaction platform, rather than a manual check performed inconsistently close to settlement.
  3. Automate periodic re-screening against current sanctions and PEP lists, not just a one-time check at intake — a customer's status can change well after the agency first took them on.
  4. Build a simple internal flagging tool any staff member can use to raise a concern, routed directly to the compliance officer for assessment — the harder it is to raise a flag, the more likely a genuine concern goes unreported.
  5. Keep due-diligence and screening records retained and retrievable for as long as AUSTRAC's record-keeping obligations require, separate from the general transaction file, since an AML/CTF file may need to be produced independently of the underlying sale's own paperwork.

Things to Consider

  • This obligation sits on top of existing transaction automation, not in place of it. See how do real estate agents and brokerages automate listing and transaction management for the deal-management layer this compliance program runs alongside.
  • The underlying due-diligence mechanics mirror what financial advisory firms already do. See how do financial advisory firms automate client onboarding and KYC checks — the core CDD/PEP-screening pattern is the same regulatory concept, even though real estate is a brand-new reporting-entity category rather than an established one.
  • A proportionate program still needs to be a real one. AUSTRAC expects a program scaled to the agency's actual size and risk, not a token document — a template copied without adaptation to the agency's actual customer base and transaction types is a weak defence if AUSTRAC ever reviews it.
  • Staff training has to be genuine, not a one-time briefing. Since front-line agents are usually the first to notice an unusual customer or transaction pattern, ongoing (not one-off) training on what a suspicious matter looks like matters more here than in many other compliance programs.

Common Mistakes

  • Treating the 29 July 2026 enrolment deadline as the finish line. Enrolment is the entry point; the program, due-diligence process, and reporting workflow all need to be operating by 1 July 2026 as well — enrolling without the underlying program in place leaves an agency exposed.
  • Only screening a customer once, at the start of the relationship. Sanctions and PEP status can change; a program that never re-screens an existing customer misses exactly the kind of change AUSTRAC expects an ongoing program to catch.
  • Making suspicious-matter reporting hard to start. If raising a concern requires an agent to track down a form or remember an unfamiliar process mid-transaction, genuine concerns go unreported — the reporting path needs to be as close to one click as the compliance officer's assessment step allows.
  • Copying a generic AML/CTF program template without adapting it to real estate's actual customer and transaction patterns. A program built for a bank's customer base doesn't map cleanly onto a real estate agency's, and AUSTRAC's expectation is a program genuinely fitted to the entity's own risk profile.

Frequently Asked Questions

Does this apply to a small independent agency, or only large franchises?
It applies regardless of agency size. Tranche 2 brings real estate agents, buyer's agents, and developers selling off-the-plan property into AUSTRAC's regulated population as "reporting entities" based on the service being provided, not on the agency's headcount or transaction volume — a sole-operator agency handling settlements has the same core obligations (enrolment, an AML/CTF program, customer due diligence, suspicious-matter reporting) as a large franchise, though the program itself should be proportionate to the agency's actual risk profile and size.
Is this the same customer due diligence a mortgage broker or financial advisor already does?
The core mechanics — verifying identity, screening for politically exposed persons and sanctions, escalating to enhanced due diligence for higher-risk customers — are the same regulatory concept a financial advisory firm or bank already applies under AML/CTF law. But a real estate agency wasn't previously a reporting entity at all, so most agencies are building this compliance program from nothing, on a much tighter timeline (2026 enrolment) than firms that have run AML programs for years, rather than extending an existing one.
What counts as a suspicious matter an agent needs to report?
AUSTRAC's threshold is broad by design — a reporting entity must lodge a suspicious matter report when it forms a reasonable suspicion that a transaction may relate to money laundering, terrorism financing, or another relevant offence, which can include patterns like a buyer insisting on an unusual payment structure, third-party funds with no clear connection to the buyer, or a customer who becomes evasive when asked standard due-diligence questions. An automated workflow should make it fast and low-friction for any staff member to raise a concern for the compliance officer to assess, rather than relying on someone remembering the reporting threshold unprompted.

References

Related Questions