Six questions. No jargon. Find out exactly where your agency stands on AML/CTF and privacy compliance — and what to fix first.
Every real estate agency that buys or sells property on behalf of clients was required to enrol as a reporting entity by 29 July 2026. Operating without enrolment is a breach that attracts daily penalties.
The compliance officer must sit at management level with real authority — usually the principal. AUSTRAC requires this role to be formally nominated, not informally assumed.
This is your foundational compliance document. It must be based on a risk assessment specific to your agency — not a generic template copied without customisation. AUSTRAC treats a generic program as a red flag.
Customer due diligence must happen before you act — before exchange for a buyer, before listing for a vendor. For companies and trusts, you must identify the real people behind the entity.
The moment you became an AML/CTF reporting entity, the small business exemption under the Privacy Act stopped applying. You're now subject to the Australian Privacy Principles and the OAIC — regardless of turnover.
If personal information is compromised and likely to cause serious harm, you must notify affected individuals and the OAIC. Separately, revealing that a suspicious matter report has been or may be made is a criminal offence. You need written processes for both — before you need them.
We'll send you a personalised breakdown of your compliance gaps, what each one means, and what to do about it — plus a free consultation to discuss your position.