AML/CTF compliance for real estate agencies

From 1 July 2026, real estate businesses providing designated services are subject to Australia's AML/CTF regime.

The obligations are now live. The next task is making them work in practice.

Having an AML/CTF program is now the starting point. Agencies need to ensure that the program reflects their actual business and risks, that staff understand what is required of them, that customer and reporting procedures are being followed, and that there is evidence to demonstrate this in practice.

Argus Assurance helps real estate agencies assess whether their AML/CTF arrangements have moved from documented requirements into effective day-to-day operation.

AUSTRAC has recognised that newly regulated businesses will continue to embed their AML/CTF practices during 2026–27 and that the quality of controls will improve over time.

For agencies, this makes implementation the immediate priority.

This includes checking whether:

  • the AML/CTF program and risk assessment reflect the agency's actual services, customers and risks

  • responsibilities for AML/CTF compliance are understood and operating

  • customer due diligence procedures are being applied consistently

  • staff know how to identify and escalate unusual or suspicious activity

  • decisions and customer checks are supported by appropriate records

  • training has translated into practice

  • weaknesses, incidents and changes in risk are identified and used to improve the program.

A well-designed program provides the framework. Effective compliance depends on what happens when staff use it.

From program development to implementation

FIXED-SCOPE AML/CTF REVIEW

AML/CTF Health Check

A practical review of how your AML/CTF arrangements are operating

The Argus AML/CTF Health Check is a targeted, fixed-scope review designed for real estate agencies that have established their AML/CTF arrangements and want an independent view of whether they are working as intended.

The review considers both the design of your arrangements and the evidence of how they are being implemented.

What we review

Depending on the size and circumstances of the agency, the Health Check can examine:

Governance and accountability

Whether AML/CTF responsibilities are clear, the AML/CTF Compliance Officer is appropriately supported, and management oversight is operating as intended.

Suspicious activity and reporting

Whether staff understand relevant indicators, escalation processes are clear, and the agency is positioned to identify and report suspicious matters when required.

Monitoring and improvement

Whether the agency has processes for identifying weaknesses, reviewing changes in risk and updating its AML/CTF arrangements where required.

ML/TF risk assessment and AML/CTF program

Whether the program reflects the agency's services, customers and identified risks, including whether an AUSTRAC starter kit has been appropriately customised for the business.

Training and staff awareness

Whether relevant personnel have received appropriate training and can translate the program's requirements into their day-to-day responsibilities.

Customer due diligence

Whether customer identification, verification, risk assessment and enhanced due diligence processes are understood and being applied consistently.

What you receive

At the conclusion of the Health Check, Argus provides:

  • a structured assessment of the areas reviewed

  • identified gaps, weaknesses and implementation risks

  • practical recommendations prioritised by significance

  • clear actions to strengthen the agency's AML/CTF arrangements

  • a management debrief to discuss findings and next steps.

The scope is agreed upfront and tailored to the size and complexity of the agency.

Records and evidence

Whether the agency retains sufficient evidence to demonstrate the checks performed, decisions made and controls applied.

Other AML/CTF support

Program implementation and uplift

Support to tailor, strengthen or update AML/CTF programs, risk assessments, procedures, responsibilities and supporting documentation.

Remediation support

Independent advice on addressing identified gaps, implementation problems or control weaknesses and assessing whether corrective actions have resolved the underlying issue.

Control effectiveness testing

Assess whether AML/CTF controls are operating as intended in day-to-day practice, supported by evidence and applied consistently across the business.

Ongoing compliance advice

Practical support as obligations, risks and regulatory expectations evolve.

WHY ARGUS ASSURANCE

Argus Assurance combines direct experience in regulatory monitoring and enforcement, including assessing AML/CTF compliance among regulated gambling operators, with performance audit and assurance experience and doctoral research in governance and regulation.

Our approach focuses on the difference between documented compliance and substantive compliance: whether responsibilities, controls and systems actually operate as intended and produce the outcomes they are designed to achieve.

For real estate agencies, that means practical assurance focused on how AML/CTF obligations work within the business, not simply whether the right documents exist.

Dr Scott Brown

Principal, Argus Assurance

Regulator-side insight

Direct experience assessing regulated businesses, controls and supporting evidence, including experience relevant to AML/CTF compliance.

Performance audit discipline

A structured, evidence-based approach to examining whether governance, systems and controls are appropriately designed and operating effectively.

Principal-led delivery

Work directly with Scott throughout the engagement, from initial scoping and evidence gathering through to advice and final reporting.

Local and practical support

Based in Melbourne, Argus provides hands-on support to agencies throughout Victoria.

Vendor-neutral advice

Argus does not sell an AML/CTF software platform. Recommendations are based on the agency’s obligations, risks and operating model.

Outcomes, not just process

The focus is not simply on whether documents exist, but whether responsibilities are understood, controls are applied consistently and decisions are supported by evidence.