Free  ·  Takes 2 minutes

How compliant is your agency?

Six questions. No jargon. Find out exactly where your agency stands on AML/CTF and privacy compliance — and what to fix first.

Question 1 of 6 0%
Question 1

Has your agency enrolled with AUSTRAC?

Every real estate agency that buys or sells property on behalf of clients was required to enrol as a reporting entity by 29 July 2026. Operating without enrolment is a breach that attracts daily penalties.

Yes — we're enrolled
No — we haven't enrolled yet
Not sure
Question 2

Have you appointed an AML/CTF Compliance Officer at principal or senior management level?

The compliance officer must sit at management level with real authority — usually the principal. AUSTRAC requires this role to be formally nominated, not informally assumed.

Yes — formally appointed
No
Not sure
Question 3

Do you have a written, risk-assessed AML/CTF Program formally adopted by the principal?

This is your foundational compliance document. It must be based on a risk assessment specific to your agency — not a generic template copied without customisation. AUSTRAC treats a generic program as a red flag.

Yes — written, risk-assessed, and adopted
No
Not sure
Question 4

Are you verifying the identity of every buyer and vendor before acting — including beneficial owners for companies and trusts?

Customer due diligence must happen before you act — before exchange for a buyer, before listing for a vendor. For companies and trusts, you must identify the real people behind the entity.

Yes — on every transaction
No — or only sometimes
Not sure
Question 5

Do you have a published Privacy Policy that reflects your new obligations as a reporting entity?

The moment you became an AML/CTF reporting entity, the small business exemption under the Privacy Act stopped applying. You're now subject to the Australian Privacy Principles and the OAIC — regardless of turnover.

Yes — published and current
No
Not sure
Question 6

Do you have a documented Data Breach Response Plan and a process for handling suspicious matter reports without tipping off?

If personal information is compromised and likely to cause serious harm, you must notify affected individuals and the OAIC. Separately, revealing that a suspicious matter report has been or may be made is a criminal offence. You need written processes for both — before you need them.

Yes — both documented
No
Not sure

Get your detailed gap report

We'll send you a personalised breakdown of your compliance gaps, what each one means, and what to do about it — plus a free consultation to discuss your position.

No spam. Your details are kept confidential.