Meeting AML/CTF Obligations in a Property Business
AML/CTF obligations now apply to Australian real estate designated services. This page is about the technology that supports compliance — identity, access, information governance, recordkeeping and recovery — not legal advice.

Anti-money-laundering and counter-terrorism-financing (AML/CTF) obligations commenced for Australian real estate professionals providing designated services on 1 July 2026. These obligations are in force now. The deadline to enrol with AUSTRAC was 29 July 2026, and that date has passed.
If your business provides a designated service, the regime applies to you today. The obligations are not approaching or pending — they are current, and they apply to the work you are doing now.
This page is about the technology that supports compliance. LOOKUP does not provide AML/CTF advice. The information here is business technology guidance — identity, access, information governance, recordkeeping, email protection and recovery — aimed at helping property businesses assess whether their systems genuinely support what they are required to do.
What changed for real estate businesses
From 1 July 2026, Australian real estate professionals providing designated services became reporting entities under the AML/CTF regime. This was part of reforms extending the regime to new professions that had not previously been captured.
In plain English, a reporting entity is a business that must enrol with AUSTRAC and meet ongoing obligations. It is not optional. Once a business provides a designated service, the obligations attach and continue to apply.
The shift from unregulated to regulated is significant. A business that has never had to think about AML/CTF obligations now has to enrol, build a program, conduct due diligence on customers, report suspicious matters and keep records for years. Each of these activities involves people, systems and information working together in a way that most property businesses have not previously had to design for.
Most newly regulated businesses only need to enrol. Registration as well as enrolment applies to remittance and virtual asset services, not to real estate. The AML/CTF compliance officer must be notified to AUSTRAC by 29 July 2026, or within 14 days of enrolling, whichever is later. The precise list of designated services is maintained by AUSTRAC, and businesses should refer to AUSTRAC for the current wording rather than relying on a summary here.
The practical question for a principal or licensee is not whether the obligations exist — they do — but whether the systems the business runs on today can actually support them. Enrolling with AUSTRAC is a one-time administrative step. Maintaining an AML/CTF program, conducting customer due diligence on every relevant party, tracking deadlines across transactions, reporting suspicious matters and producing records on request are ongoing operational demands. They depend on technology working the way the regime expects it to.
The obligations technology has to support
The AML/CTF regime places several obligations on reporting entities. Each one demands something of the business's systems and information — not just its legal position.
Enrolling with AUSTRAC
Enrolment is the entry point. The business must be enrolled, and its AML/CTF compliance officer must be notified to AUSTRAC. From a technology perspective, this is straightforward — but it is the trigger for everything that follows.
Having an AML/CTF program
The business must maintain an AML/CTF program. Technology supports this by providing a governed environment where policies, procedures, roles and evidence can be stored, versioned and made available to the people who need them.
Carrying out customer due diligence
The business must collect and verify identity information for the parties to whom it provides designated services. This is where technology matters most: identity information must be captured, verified, stored securely and retrievable years later.
Reporting suspicious matters
The business must report suspicious matters to AUSTRAC. Technology does not decide whether a matter is suspicious — that remains a human and compliance judgement — but it should support the ability to escalate, document and act on concerns without relying on memory.
Keeping records
The business must keep records of its AML/CTF activities. From a technology perspective, this means records must be stored in a controlled, retrievable location — not scattered across inboxes, personal drives and individual staff members' devices.
Meeting AML/CTF obligations is not a single task. It requires systems that support each connected obligation, from collecting identity information to producing records years later.
Why customer due diligence is a technology problem
Customer due diligence (CDD) is the obligation that places the most direct demands on technology. Identity information now has to be collected, verified, stored securely and retrievable years later. That is not a legal statement — it is a systems statement.
The volume point
Where an agent acts for the seller and brokers a successful sale, the customer is both the buyer and the seller. Obligations attach to both parties. Initial CDD is required on the party you act for and the party you do not act for.
If you assumed you only verify your own vendor, the real requirement is roughly double that on every brokered transaction. That is a volume problem as much as a legal one — and volume problems are technology problems.
The timing point
Initial CDD on the party you act for must be completed before you begin providing them with the designated service. For the other party, the CDD may be delayed. Where you act for the seller, the buyer's initial CDD may be completed 28 days after the exchange of contracts, or at least 3 days before the initially agreed settlement day, whichever is earliest.
The delay exists because completing CDD on the spot would sometimes disrupt normal business. Auctions are the obvious case — the time between the end of the auction and signing the contract is often too short to complete identity verification on the buyer.
That concession is useful, but it is also a tracking obligation. Every brokered transaction now carries its own clock. The deadline is derived from two different dates — the exchange date and the settlement date — with the earlier one winning. A reminder set by whoever remembered is not a system. Which transactions have an open CDD obligation, and which are closest to their deadline, should be answerable by looking rather than asking.
The timing concession is a managed deadline, not a relaxation. If your technology cannot show you, at a glance, which transactions have open CDD obligations and when each one falls due, then the concession has created a risk rather than removed one. The ability to see the status of every transaction — completed, pending, approaching deadline, overdue — is what separates a business that is managing its obligations from one that is hoping nothing falls through the cracks.
Where property businesses are usually exposed
Most property businesses do not fail AML/CTF obligations because they intend to. They fail because their technology was never designed to support what the regime now requires. The following are common exposure points.
Identity documents in email
Identity documents sitting in inboxes and sent items, with no control over who can view them or how long they are retained. A passport scan emailed by a prospective buyer sits in an agent's inbox indefinitely, forwarded to conveyancers, saved to desktops and never deleted.
Records spread across systems
Records distributed across a property platform, a CRM, a trust accounting system and Microsoft 365, with no single retrievable position. When an auditor asks for a complete file, someone has to piece it together from four different systems.
No control over internal access
No restriction on who internally can view identity documents. Any staff member with broad access can see sensitive personal information — including casual admin staff, contractors and people who have no involvement in the transaction.
Departed staff retaining access
Staff and contractors who have left the business still have active accounts and can still access identity records and client information. Offboarding is inconsistent, and shared mailboxes mean access is never truly removed.
No tested way to produce records
If asked to produce records on request, the business cannot retrieve them without a manual search across multiple systems and inboxes. No one has ever tested whether the records actually exist in a retrievable form.
No tracking of CDD deadlines
Open CDD obligations on the non-acting party are tracked in someone's head or a spreadsheet, not in a system that shows what is due and when. When that person is on leave, no one else knows which transactions have outstanding obligations.
These exposure points share a common root: information is being managed the way it always has been, but the rules around it have changed. A property business that has operated for years with identity documents flowing through email, shared drives and individual staff devices is not acting recklessly — it is acting on habit. The problem is that the habit no longer matches the obligation. When a business cannot say with confidence where a specific client's identity records are stored, who has accessed them, and whether they can be produced on request, the technology environment is not supporting the regime — it is working against it.
The exposure is often invisible until something forces it into view. A departed staff member's account is still active months later. A compliance officer asks for a record that no one can find. A transaction settles and no one realises CDD on the buyer was never completed within the allowed window. These are not catastrophic failures of intent — they are the predictable result of systems that were built for sales efficiency, not for regulatory obligations.
Consider what happens in a typical agency during a busy sale week. A buyer's driver's licence scan arrives by email and is forwarded to the agent's personal inbox, then to the admin team, then to the conveyancer. Each forward creates a new copy in a new location. No one owns the master. No one is responsible for deleting it when the retention period expires. If the buyer later asks what personal information the agency holds about them, someone has to search across multiple mailboxes, shared drives and local folders — and even then, there is no guarantee every copy will be found. The information is everywhere, which means it is effectively nowhere.
The same pattern repeats with trust accounting records, tenancy applications and maintenance request histories. A property management team might hold years of tenant identity documents in a shared folder that was set up by someone who left three years ago, with permissions inherited from a generic staff group. No one has reviewed who can access it. No one has tested whether the records can be retrieved quickly. No one has checked whether departed contractors still have logins to the property management platform. The exposure is not a single broken control — it is the absence of a designed information environment.
Multi-office agencies face an additional layer of risk. Each branch may have its own local IT habits, its own shared drive structure, its own approach to onboarding and offboarding staff. A sales agent who moves between offices may have access in one location but not another, or broad access in both that was never reviewed. When the AML/CTF compliance officer needs a complete picture of who can view identity records across the entire business, the answer is not in one place — it is scattered across branch-level decisions that were never centralised. The regime expects a business-wide position. Most multi-office agencies do not have one.
The CDD deadline tracking problem deserves specific attention because it is the one most likely to create silent non-compliance. In a busy agency, transactions settle every week. Each one where the agency acted for the seller carries a CDD obligation on the buyer, with a deadline derived from exchange and settlement dates. If that deadline is tracked in a spreadsheet maintained by a single property manager, the business is one resignation, one holiday or one forgotten row away from missing it. There is no system alert, no dashboard, no shared view. The obligation exists, the clock is running, and no one in the business can see it without asking the right person — who may not be available.
What good looks like
The target state is not complicated, but it is deliberate. Good looks like this:
Identity information held in a controlled location
Not in inboxes. Not on personal drives. In a governed location with appropriate permissions and retention. When a staff member needs to view a client's identity documents, they go to one known place — not a search across email folders.
Access restricted to those who need it
Staff can access identity information only where there is a legitimate business reason. Broad, inherited access has been reviewed and reduced. A new admin assistant cannot see every client's identity records just because they have a general mailbox login.
Retention is deliberate, not accidental
Records are retained for the period required and disposed of securely when that period expires. Retention is a policy, not an accident of inaction. Documents do not sit in inboxes for years because no one thought to delete them.
Records are retrievable without a manual search
If asked to produce records, the business can do so from a known location, without trawling through email and shared drives. A compliance officer or auditor can be shown the records, not told they are probably somewhere in the system.
Reliable joiners and leavers
Joiners receive the right access on day one, and leavers have every account removed promptly — Microsoft 365, property platforms, CRMs and shared mailboxes. No one retains access after they leave, and the offboarding process is consistent rather than dependent on who remembers to do it.
An auditable position that can be demonstrated
The business can show — not merely assert — that identity information is controlled, access is restricted, retention is managed and records are retrievable. The position is visible in the system itself, not dependent on someone's memory.
The difference between the exposed state and the target state is not a different set of software. It is the same Microsoft 365 environment, the same property platform, the same CRM — but configured and governed so that information flows into controlled locations rather than accumulating in inboxes. Good looks like a business where a principal can answer the question "where are this client's identity records?" in seconds, not minutes, and where the answer does not depend on who is in the office that day.
It also looks like a business that can demonstrate its position to an auditor or regulator without scrambling. When records are stored in a governed SharePoint site with appropriate permissions, when access is reviewed periodically, when retention is applied by policy rather than by habit, and when departed staff are offboarded promptly and consistently, the auditable position is the system itself. The business does not need to build a case — it needs to show what is already there.
In practice, this means a property manager opening a matter can see, at a glance, whether CDD has been completed on both parties, where the identity documents are stored, and whether any deadlines are approaching. A sales agent who receives a passport scan by email does not leave it in their inbox — the information is routed to the governed location automatically, or the agent knows exactly where to save it and who will have access. A principal who is asked by AUSTRAC to produce records for a transaction that settled months ago can do so without calling three staff members and searching four systems.
Good also means the business has a clear answer to the question of who is responsible for each part of the process. The AML/CTF compliance officer knows their role. The property management team knows where identity records belong. The IT environment — whether managed internally or by a provider like LOOKUP — supports the process rather than being a separate concern. Responsibility is not diffuse. It is assigned, visible and supported by systems that make the right action the easy action.
The target state is achievable without replacing the systems a property business already relies on. It does not require a new property management platform, a new CRM or a new trust accounting system. It requires the environment around those systems — Microsoft 365, identity, devices, email, backup and governance — to be configured so that information is controlled, access is appropriate, retention is deliberate and records are retrievable. That is the gap LOOKUP fills.
How this maps to the LOOKUP Business Modernisation Framework™
Meeting AML/CTF obligations follows the same eight-stage sequence — so that information is organised and access controlled before anything is automated.
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
Discover
Map where identity information currently lives across the property business — inboxes, shared drives, property platforms, CRMs and trust accounting systems — and identify who can access it.
Secure
Put multi-factor authentication, conditional access and least-privilege permissions in place so that identity documents and client records are protected from the start.
Modernise
Move identity records from inboxes and personal drives into governed SharePoint sites and OneDrive locations with controlled sharing and appropriate retention.
Standardise
Establish consistent onboarding and offboarding processes so that access is granted promptly when someone joins and removed immediately when someone leaves.
Optimise
Review permissions regularly, test record retrieval, and verify that the business can produce records on request without a manual search across multiple systems.
Prepare
Build the governance foundations — documented retention policies, access reviews and CDD deadline tracking — that the business needs before introducing automation.
Implement
Deploy the workflows and tools that support ongoing obligations — automated routing of identity documents, deadline tracking, and auditable recordkeeping.
Improve
Review the AML/CTF technology environment periodically as obligations evolve, ensuring the business can demonstrate its position rather than merely assert it.
How LOOKUP helps
LOOKUP works on the Microsoft 365 environment around the specialist systems a property business uses. We do not replace property management platforms, CRMs or trust accounting systems. We coordinate with them.
The work that supports AML/CTF obligations is the same work that supports good information governance generally:
Identity and access control
Multi-factor authentication, least-privilege access, joiner-mover-leaver processes, and removal of departed staff and contractor access.
Email protection
Email security, phishing protection, and controls that reduce the risk of identity documents sitting uncontrolled in inboxes.
SharePoint and OneDrive governance
Governed locations for identity records, controlled sharing, permission reviews, and retention policies that make retention deliberate.
Device management
Managed laptops and mobile devices with encryption and remote-wipe capability, so identity information on devices is protected.
Backup and tested recovery
Backup that is tested, not assumed. The ability to recover records on request is a requirement, not a nice-to-have.
Coordination with specialist platforms
Coordination with property management, CRM and trust accounting vendors to ensure the surrounding environment supports — not undermines — recordkeeping.
For a broader view of how LOOKUP approaches technology for property businesses, see our Real Estate & Property Services industry page. For the Microsoft 365 environment specifically, see how we approach Microsoft 365 governance, and for security baselines, our work on the Essential Eight.
What LOOKUP does not do
This needs to be stated plainly, because the boundary matters.
Those remain with the business and its advisers. What LOOKUP does is build the technology environment that supports the processes a business uses to meet its obligations — identity, access, information governance, recordkeeping, email protection and recovery.
Frequently asked questions
Yes. From 1 July 2026, Australian real estate professionals providing designated services became reporting entities under the AML/CTF regime, and newly regulated businesses were required to enrol with AUSTRAC by 29 July 2026. These obligations are in force today, not approaching. If your business provides a designated service, the regime applies to you now.
A reporting entity must enrol with AUSTRAC, maintain an AML/CTF program, carry out customer due diligence, report suspicious matters and keep records. Each obligation places demands on how a business collects, stores, protects and retrieves information. The technology environment — not just the legal position — determines whether these obligations can be met consistently.
Yes. Where an agent acts for the seller and brokers a successful sale, the customer is both the buyer and the seller, and obligations attach to both parties. Initial CDD on the party you act for must be completed before you begin providing the designated service. CDD on the other party may be delayed — 28 days after exchange of contracts, or at least 3 days before the initially agreed settlement day, whichever is earliest.
The delay exists because completing CDD on the spot would sometimes disrupt normal business — auctions being the obvious case — but the concession is a tracking obligation, not a relaxation. Every brokered transaction carries its own clock, derived from two different dates with the earlier one winning. A reminder set by whoever remembered is not a system; which transactions have an open CDD obligation should be answerable by looking, not asking.
No. LOOKUP does not provide AML/CTF, legal or compliance advice, does not determine whether a business provides a designated service, does not decide whether a matter is suspicious, and does not make compliance determinations. Those remain with the business and its advisers. LOOKUP works on the technology environment — identity, access, information governance, email protection, devices and recovery — that supports the processes a business uses to meet its obligations.
Start by understanding where identity information lives today, who can access it, and how records are kept. Then review identity and access controls, Microsoft 365 governance, email security, device management and tested recovery. The objective is an environment where records are retrievable, access is controlled, and the business can demonstrate its position rather than merely assert it.
Executive guides
How LOOKUP can help
AI & Workflow Automation
Practical automation that reduces repetitive work.
Microsoft 365
Implement, optimise and secure your Microsoft 365 environment.
AI Readiness
Prepare data, permissions and governance for AI.
Virtual CIO
Senior technology leadership without a full-time hire.
Managed IT Services
Proactive support that keeps the business running.
Sources & Further Reading
The following primary and authoritative sources support the research, guidance and industry context discussed on this page:
AUSTRAC — Real Estate Designated Services — 2026
Official AUSTRAC guidance on the AML/CTF obligations that apply to real estate professionals providing designated services, including enrolment, AML/CTF programs, customer due diligence and recordkeeping.
View Source →Evidence Standard
LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.
Related outcomes
Protecting Personal Information in a Property Business
Strengthen identity, access, Microsoft 365 and information governance around tenant, client and transaction information.
Building a Technology Roadmap for a Property Business
Bring cyber security, Microsoft 365, automation, AI and AML/CTF technology implications into one coordinated roadmap.
Does Your Technology Actually Support What You Are Required to Do?
AML/CTF obligations are in force. If your technology cannot show you where identity information lives, who can access it, and which transactions have open CDD deadlines, that is a technology problem worth fixing. Book a strategy session with LOOKUP to assess your current environment and build a practical path forward.
Peter Kantarelis
Founder, LOOKUP — Business Technology Strategist
Peter Kantarelis is the Founder of LOOKUP and a business technology strategist helping Australian organisations modernise technology, strengthen cyber security and prepare for practical AI adoption. He regularly works with business owners and leadership teams to improve productivity, reduce operational risk and implement technology that delivers measurable business outcomes. The LOOKUP Business Modernisation Framework™ reflects more than 25 years of helping Australian businesses make better technology decisions.
View More Insights →