All posts
tranche-2austracreal-estatecompliance-2026cddworkflow

What changed in a sales agency's daily workflow on 1 July 2026

AML/CTF obligations are live. Here is what actually changed in the day-to-day work of running a residential sale, from first contact to settlement, and where a tool fits into a live transaction.

By AML Simple Team

What changed in a sales agency's daily workflow on 1 July 2026

Obligations commenced 1 July 2026.

Real estate agencies are now reporting entities providing a designated service. That is not a setup task anymore. It is a Tuesday.

One option for agencies still adjusting their workflow is the AML Simple 3-step path. Sign up, run the AUSTRAC Readiness Check, then let the Program Generator produce a written program consistent with AUSTRAC's Program Starter Kit structure. Typically under 25 minutes combined. That gets the framework in place. This post is about what happens after, once a real buyer or seller walks in and a transaction actually runs.

Before 1 July vs now

Before. A listing came in. You met the vendor, took the appraisal, signed the agency agreement, found a buyer, negotiated, exchanged contracts. Identity checks existed for other reasons (110 points for a bank, agent's licence obligations) but nothing tied to money laundering risk sat inside the sales process itself.

Now. The same listing-to-settlement sequence has a parallel compliance track running underneath it. Reporting entities are required to conduct customer due diligence in connection with a designated service. For real estate, that designated service is brokering the sale, purchase, or transfer of real property. The default rule is CDD before the service is provided, not after.

That single sentence changes where in the transaction certain things need to happen.

Where the obligation actually bites

Four points in a typical sale now carry a compliance step that did not exist as a formal requirement before 1 July.

1. Taking on the vendor. Before you provide the designated service (acting for them on the sale), a common approach is verifying who the vendor is: identity, and if it is a company or trust, who controls it. This sits earlier in the relationship than most agents are used to. Waiting until near exchange is the pattern that creates problems.

2. Qualifying a serious buyer. Once someone is a genuine prospective purchaser rather than a browser at an open home, the same due diligence logic applies to them. A typical approach is to trigger identity verification when an offer is put in writing, not after it is accepted.

3. Auction day. This is the one exception worth knowing about. Under s 29 of the AML/CTF Act 2006, a reporting entity may in limited circumstances defer completing CDD until immediately after the designated service is provided, where completing it beforehand is not reasonably practicable. A competitive auction, where the winning bidder is only known once the hammer falls, is the illustrative case AUSTRAC guidance points to. This is not a general licence to skip CDD at auctions. It applies only where specific conditions are met, and CDD still has to be completed as soon as practicable afterward. Whether it applies to a given auction is a decision for the agency, not something this post can determine for you.

4. Anything that doesn't sit right. Reporting entities need to stay alert to grounds for suspicion throughout a transaction, not just at the CDD stage. An unusual funding pattern, a buyer who won't produce ID, a related-party transfer priced well off market. Being alert to these is now an ongoing part of running the file, not a one-off check at the start.

A worked walk-through

Take a fairly ordinary suburban sale.

Listing taken. Agency agreement signed with the vendor. A typical record at this point would include the vendor's verified identity documents, the date verification was completed, and who did it.

Open homes run. No compliance step yet. Browsers are not customers.

Offer received in writing. The buyer moves from prospect to someone the designated service is being provided to. A common approach here is to send a verification request before the offer is formally accepted, so the identity check is underway in parallel with negotiation rather than tacked on afterward.

Contracts exchanged. By this point, a typical file would show completed CDD on both vendor and buyer, any risk rating applied (a cash buyer moving quickly on an unfinanced purchase might warrant a closer look), and screening results against sanctions and PEP lists, each with a timestamp.

Something looks off. Say the buyer's funds are coming from a third party with no clear connection to them. That is a suspicious indicator. Reporting entities need to be alert to grounds for a possible Suspicious Matter Report at this point, whatever else is happening in the transaction. It is a criminal offence to tell the customer a report has been or will be filed.

Settlement. The file closes, but the records don't. They need to be kept for 7 years, whatever format they were captured in.

None of this replaces the actual selling. It runs alongside it.

Where the tool fits

One option for handling this without building a manual parallel process is AML Simple. The CDD, screening, and record-keeping steps above map to the same workflow the Program Generator sets up during onboarding, so the sales team is working from the same system that produced the written program.

  • Verification links go out to vendors and buyers from inside the platform, rather than chasing paperwork.
  • Sanctions and PEP screening runs against daily-updated lists, with results and timestamps stored automatically.
  • Records sit in one place for the full retention period, rather than in a mix of email threads and physical files.
  • If a suspicious indicator comes up, the platform helps structure an SMR narrative. The agent reviews and finalises it before anything is filed.

None of this replaces judgment. The tool handles the workflow. The agency still makes the compliance decisions, including whether a delayed CDD exception applies, whether something meets the threshold for a report, and how a risk rating is set.

Penalties for getting this wrong are real (up to A$36.4 million per contravention for a body corporate, up to A$7.28 million for an individual), but that is not really the point of a Tuesday. The point is that CDD, screening, and record-keeping are now part of running a file, the same way the agency agreement and the contract of sale are.

See how the workflow fits together at AML Simple.

We use cookies for advertising measurement. See our Privacy Policy.