info@lookup.com.au 1300 553 559 Remote Assist
    Lookup Logo
    Real Estate & Property Business Outcome

    Meeting AML/CTF Obligations in a Property Business

    AML/CTF obligations now apply to Australian real estate designated services. This page is about the technology that supports compliance — identity, access, information governance, recordkeeping and recovery — not legal advice.

    Abstract editorial illustration representing identity verification captured, held securely in a controlled repository and retrieved on demand over time for AML/CTF compliance in a property business.

    Anti-money-laundering and counter-terrorism-financing (AML/CTF) obligations commenced for Australian real estate professionals providing designated services on 1 July 2026. These obligations are in force now. The deadline to enrol with AUSTRAC was 29 July 2026, and that date has passed.

    If your business provides a designated service, the regime applies to you today. The obligations are not approaching or pending — they are current, and they apply to the work you are doing now.

    This page is about the technology that supports compliance. LOOKUP does not provide AML/CTF advice. The information here is business technology guidance — identity, access, information governance, recordkeeping, email protection and recovery — aimed at helping property businesses assess whether their systems genuinely support what they are required to do.

    What changed for real estate businesses

    From 1 July 2026, Australian real estate professionals providing designated services became reporting entities under the AML/CTF regime. This was part of reforms extending the regime to new professions that had not previously been captured.

    In plain English, a reporting entity is a business that must enrol with AUSTRAC and meet ongoing obligations. It is not optional. Once a business provides a designated service, the obligations attach and continue to apply.

    The shift from unregulated to regulated is significant. A business that has never had to think about AML/CTF obligations now has to enrol, build a program, conduct due diligence on customers, report suspicious matters and keep records for years. Each of these activities involves people, systems and information working together in a way that most property businesses have not previously had to design for.

    Most newly regulated businesses only need to enrol. Registration as well as enrolment applies to remittance and virtual asset services, not to real estate. The AML/CTF compliance officer must be notified to AUSTRAC by 29 July 2026, or within 14 days of enrolling, whichever is later. The precise list of designated services is maintained by AUSTRAC, and businesses should refer to AUSTRAC for the current wording rather than relying on a summary here.

    The practical question for a principal or licensee is not whether the obligations exist — they do — but whether the systems the business runs on today can actually support them. Enrolling with AUSTRAC is a one-time administrative step. Maintaining an AML/CTF program, conducting customer due diligence on every relevant party, tracking deadlines across transactions, reporting suspicious matters and producing records on request are ongoing operational demands. They depend on technology working the way the regime expects it to.

    The obligations technology has to support

    The AML/CTF regime places several obligations on reporting entities. Each one demands something of the business's systems and information — not just its legal position.

    Enrolling with AUSTRAC

    Enrolment is the entry point. The business must be enrolled, and its AML/CTF compliance officer must be notified to AUSTRAC. From a technology perspective, this is straightforward — but it is the trigger for everything that follows.

    Having an AML/CTF program

    The business must maintain an AML/CTF program. Technology supports this by providing a governed environment where policies, procedures, roles and evidence can be stored, versioned and made available to the people who need them.

    Carrying out customer due diligence

    The business must collect and verify identity information for the parties to whom it provides designated services. This is where technology matters most: identity information must be captured, verified, stored securely and retrievable years later.

    Reporting suspicious matters

    The business must report suspicious matters to AUSTRAC. Technology does not decide whether a matter is suspicious — that remains a human and compliance judgement — but it should support the ability to escalate, document and act on concerns without relying on memory.

    Keeping records

    The business must keep records of its AML/CTF activities. From a technology perspective, this means records must be stored in a controlled, retrievable location — not scattered across inboxes, personal drives and individual staff members' devices.

    Meeting AML/CTF obligations is not a single task. It requires systems that support each connected obligation, from collecting identity information to producing records years later.

    AML/CTF Obligations
    Customer Due Diligence
    Identity Documents
    Record Keeping
    Retrieval on Request
    Suspicious Matters
    Access Control
    Compliance Officer
    Both Parties

    Why customer due diligence is a technology problem

    Customer due diligence (CDD) is the obligation that places the most direct demands on technology. Identity information now has to be collected, verified, stored securely and retrievable years later. That is not a legal statement — it is a systems statement.

    The volume point

    Where an agent acts for the seller and brokers a successful sale, the customer is both the buyer and the seller. Obligations attach to both parties. Initial CDD is required on the party you act for and the party you do not act for.

    If you assumed you only verify your own vendor, the real requirement is roughly double that on every brokered transaction. That is a volume problem as much as a legal one — and volume problems are technology problems.

    The timing point

    Initial CDD on the party you act for must be completed before you begin providing them with the designated service. For the other party, the CDD may be delayed. Where you act for the seller, the buyer's initial CDD may be completed 28 days after the exchange of contracts, or at least 3 days before the initially agreed settlement day, whichever is earliest.

    The delay exists because completing CDD on the spot would sometimes disrupt normal business. Auctions are the obvious case — the time between the end of the auction and signing the contract is often too short to complete identity verification on the buyer.

    That concession is useful, but it is also a tracking obligation. Every brokered transaction now carries its own clock. The deadline is derived from two different dates — the exchange date and the settlement date — with the earlier one winning. A reminder set by whoever remembered is not a system. Which transactions have an open CDD obligation, and which are closest to their deadline, should be answerable by looking rather than asking.

    The timing concession is a managed deadline, not a relaxation. If your technology cannot show you, at a glance, which transactions have open CDD obligations and when each one falls due, then the concession has created a risk rather than removed one. The ability to see the status of every transaction — completed, pending, approaching deadline, overdue — is what separates a business that is managing its obligations from one that is hoping nothing falls through the cracks.

    Where property businesses are usually exposed

    Most property businesses do not fail AML/CTF obligations because they intend to. They fail because their technology was never designed to support what the regime now requires. The following are common exposure points.

    Identity documents in email

    Identity documents sitting in inboxes and sent items, with no control over who can view them or how long they are retained. A passport scan emailed by a prospective buyer sits in an agent's inbox indefinitely, forwarded to conveyancers, saved to desktops and never deleted.

    Records spread across systems

    Records distributed across a property platform, a CRM, a trust accounting system and Microsoft 365, with no single retrievable position. When an auditor asks for a complete file, someone has to piece it together from four different systems.

    No control over internal access

    No restriction on who internally can view identity documents. Any staff member with broad access can see sensitive personal information — including casual admin staff, contractors and people who have no involvement in the transaction.

    Departed staff retaining access

    Staff and contractors who have left the business still have active accounts and can still access identity records and client information. Offboarding is inconsistent, and shared mailboxes mean access is never truly removed.

    No tested way to produce records

    If asked to produce records on request, the business cannot retrieve them without a manual search across multiple systems and inboxes. No one has ever tested whether the records actually exist in a retrievable form.

    No tracking of CDD deadlines

    Open CDD obligations on the non-acting party are tracked in someone's head or a spreadsheet, not in a system that shows what is due and when. When that person is on leave, no one else knows which transactions have outstanding obligations.

    These exposure points share a common root: information is being managed the way it always has been, but the rules around it have changed. A property business that has operated for years with identity documents flowing through email, shared drives and individual staff devices is not acting recklessly — it is acting on habit. The problem is that the habit no longer matches the obligation. When a business cannot say with confidence where a specific client's identity records are stored, who has accessed them, and whether they can be produced on request, the technology environment is not supporting the regime — it is working against it.

    The exposure is often invisible until something forces it into view. A departed staff member's account is still active months later. A compliance officer asks for a record that no one can find. A transaction settles and no one realises CDD on the buyer was never completed within the allowed window. These are not catastrophic failures of intent — they are the predictable result of systems that were built for sales efficiency, not for regulatory obligations.

    Consider what happens in a typical agency during a busy sale week. A buyer's driver's licence scan arrives by email and is forwarded to the agent's personal inbox, then to the admin team, then to the conveyancer. Each forward creates a new copy in a new location. No one owns the master. No one is responsible for deleting it when the retention period expires. If the buyer later asks what personal information the agency holds about them, someone has to search across multiple mailboxes, shared drives and local folders — and even then, there is no guarantee every copy will be found. The information is everywhere, which means it is effectively nowhere.

    The same pattern repeats with trust accounting records, tenancy applications and maintenance request histories. A property management team might hold years of tenant identity documents in a shared folder that was set up by someone who left three years ago, with permissions inherited from a generic staff group. No one has reviewed who can access it. No one has tested whether the records can be retrieved quickly. No one has checked whether departed contractors still have logins to the property management platform. The exposure is not a single broken control — it is the absence of a designed information environment.

    Multi-office agencies face an additional layer of risk. Each branch may have its own local IT habits, its own shared drive structure, its own approach to onboarding and offboarding staff. A sales agent who moves between offices may have access in one location but not another, or broad access in both that was never reviewed. When the AML/CTF compliance officer needs a complete picture of who can view identity records across the entire business, the answer is not in one place — it is scattered across branch-level decisions that were never centralised. The regime expects a business-wide position. Most multi-office agencies do not have one.

    The CDD deadline tracking problem deserves specific attention because it is the one most likely to create silent non-compliance. In a busy agency, transactions settle every week. Each one where the agency acted for the seller carries a CDD obligation on the buyer, with a deadline derived from exchange and settlement dates. If that deadline is tracked in a spreadsheet maintained by a single property manager, the business is one resignation, one holiday or one forgotten row away from missing it. There is no system alert, no dashboard, no shared view. The obligation exists, the clock is running, and no one in the business can see it without asking the right person — who may not be available.

    What good looks like

    The target state is not complicated, but it is deliberate. Good looks like this:

    Identity information held in a controlled location

    Not in inboxes. Not on personal drives. In a governed location with appropriate permissions and retention. When a staff member needs to view a client's identity documents, they go to one known place — not a search across email folders.

    Access restricted to those who need it

    Staff can access identity information only where there is a legitimate business reason. Broad, inherited access has been reviewed and reduced. A new admin assistant cannot see every client's identity records just because they have a general mailbox login.

    Retention is deliberate, not accidental

    Records are retained for the period required and disposed of securely when that period expires. Retention is a policy, not an accident of inaction. Documents do not sit in inboxes for years because no one thought to delete them.

    Records are retrievable without a manual search

    If asked to produce records, the business can do so from a known location, without trawling through email and shared drives. A compliance officer or auditor can be shown the records, not told they are probably somewhere in the system.

    Reliable joiners and leavers

    Joiners receive the right access on day one, and leavers have every account removed promptly — Microsoft 365, property platforms, CRMs and shared mailboxes. No one retains access after they leave, and the offboarding process is consistent rather than dependent on who remembers to do it.

    An auditable position that can be demonstrated

    The business can show — not merely assert — that identity information is controlled, access is restricted, retention is managed and records are retrievable. The position is visible in the system itself, not dependent on someone's memory.

    The difference between the exposed state and the target state is not a different set of software. It is the same Microsoft 365 environment, the same property platform, the same CRM — but configured and governed so that information flows into controlled locations rather than accumulating in inboxes. Good looks like a business where a principal can answer the question "where are this client's identity records?" in seconds, not minutes, and where the answer does not depend on who is in the office that day.

    It also looks like a business that can demonstrate its position to an auditor or regulator without scrambling. When records are stored in a governed SharePoint site with appropriate permissions, when access is reviewed periodically, when retention is applied by policy rather than by habit, and when departed staff are offboarded promptly and consistently, the auditable position is the system itself. The business does not need to build a case — it needs to show what is already there.

    In practice, this means a property manager opening a matter can see, at a glance, whether CDD has been completed on both parties, where the identity documents are stored, and whether any deadlines are approaching. A sales agent who receives a passport scan by email does not leave it in their inbox — the information is routed to the governed location automatically, or the agent knows exactly where to save it and who will have access. A principal who is asked by AUSTRAC to produce records for a transaction that settled months ago can do so without calling three staff members and searching four systems.

    Good also means the business has a clear answer to the question of who is responsible for each part of the process. The AML/CTF compliance officer knows their role. The property management team knows where identity records belong. The IT environment — whether managed internally or by a provider like LOOKUP — supports the process rather than being a separate concern. Responsibility is not diffuse. It is assigned, visible and supported by systems that make the right action the easy action.

    The target state is achievable without replacing the systems a property business already relies on. It does not require a new property management platform, a new CRM or a new trust accounting system. It requires the environment around those systems — Microsoft 365, identity, devices, email, backup and governance — to be configured so that information is controlled, access is appropriate, retention is deliberate and records are retrievable. That is the gap LOOKUP fills.

    The Framework

    How this maps to the LOOKUP Business Modernisation Framework™

    Meeting AML/CTF obligations follows the same eight-stage sequence — so that information is organised and access controlled before anything is automated.

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    Discover

    Map where identity information currently lives across the property business — inboxes, shared drives, property platforms, CRMs and trust accounting systems — and identify who can access it.

    Secure

    Put multi-factor authentication, conditional access and least-privilege permissions in place so that identity documents and client records are protected from the start.

    Modernise

    Move identity records from inboxes and personal drives into governed SharePoint sites and OneDrive locations with controlled sharing and appropriate retention.

    Standardise

    Establish consistent onboarding and offboarding processes so that access is granted promptly when someone joins and removed immediately when someone leaves.

    Optimise

    Review permissions regularly, test record retrieval, and verify that the business can produce records on request without a manual search across multiple systems.

    Prepare

    Build the governance foundations — documented retention policies, access reviews and CDD deadline tracking — that the business needs before introducing automation.

    Implement

    Deploy the workflows and tools that support ongoing obligations — automated routing of identity documents, deadline tracking, and auditable recordkeeping.

    Improve

    Review the AML/CTF technology environment periodically as obligations evolve, ensuring the business can demonstrate its position rather than merely assert it.

    How LOOKUP helps

    LOOKUP works on the Microsoft 365 environment around the specialist systems a property business uses. We do not replace property management platforms, CRMs or trust accounting systems. We coordinate with them.

    The work that supports AML/CTF obligations is the same work that supports good information governance generally:

    Identity and access control

    Multi-factor authentication, least-privilege access, joiner-mover-leaver processes, and removal of departed staff and contractor access.

    Email protection

    Email security, phishing protection, and controls that reduce the risk of identity documents sitting uncontrolled in inboxes.

    SharePoint and OneDrive governance

    Governed locations for identity records, controlled sharing, permission reviews, and retention policies that make retention deliberate.

    Device management

    Managed laptops and mobile devices with encryption and remote-wipe capability, so identity information on devices is protected.

    Backup and tested recovery

    Backup that is tested, not assumed. The ability to recover records on request is a requirement, not a nice-to-have.

    Coordination with specialist platforms

    Coordination with property management, CRM and trust accounting vendors to ensure the surrounding environment supports — not undermines — recordkeeping.

    For a broader view of how LOOKUP approaches technology for property businesses, see our Real Estate & Property Services industry page. For the Microsoft 365 environment specifically, see how we approach Microsoft 365 governance, and for security baselines, our work on the Essential Eight.

    What LOOKUP does not do

    This needs to be stated plainly, because the boundary matters.

    1.LOOKUP does not provide AML/CTF advice.
    2.LOOKUP does not determine whether a business provides a designated service.
    3.LOOKUP does not decide whether a matter is suspicious.
    4.LOOKUP does not make compliance determinations.

    Those remain with the business and its advisers. What LOOKUP does is build the technology environment that supports the processes a business uses to meet its obligations — identity, access, information governance, recordkeeping, email protection and recovery.

    Frequently asked questions

    Yes. From 1 July 2026, Australian real estate professionals providing designated services became reporting entities under the AML/CTF regime, and newly regulated businesses were required to enrol with AUSTRAC by 29 July 2026. These obligations are in force today, not approaching. If your business provides a designated service, the regime applies to you now.

    A reporting entity must enrol with AUSTRAC, maintain an AML/CTF program, carry out customer due diligence, report suspicious matters and keep records. Each obligation places demands on how a business collects, stores, protects and retrieves information. The technology environment — not just the legal position — determines whether these obligations can be met consistently.

    Yes. Where an agent acts for the seller and brokers a successful sale, the customer is both the buyer and the seller, and obligations attach to both parties. Initial CDD on the party you act for must be completed before you begin providing the designated service. CDD on the other party may be delayed — 28 days after exchange of contracts, or at least 3 days before the initially agreed settlement day, whichever is earliest.

    The delay exists because completing CDD on the spot would sometimes disrupt normal business — auctions being the obvious case — but the concession is a tracking obligation, not a relaxation. Every brokered transaction carries its own clock, derived from two different dates with the earlier one winning. A reminder set by whoever remembered is not a system; which transactions have an open CDD obligation should be answerable by looking, not asking.

    No. LOOKUP does not provide AML/CTF, legal or compliance advice, does not determine whether a business provides a designated service, does not decide whether a matter is suspicious, and does not make compliance determinations. Those remain with the business and its advisers. LOOKUP works on the technology environment — identity, access, information governance, email protection, devices and recovery — that supports the processes a business uses to meet its obligations.

    Start by understanding where identity information lives today, who can access it, and how records are kept. Then review identity and access controls, Microsoft 365 governance, email security, device management and tested recovery. The objective is an environment where records are retrievable, access is controlled, and the business can demonstrate its position rather than merely assert it.

    Sources & Further Reading

    The following primary and authoritative sources support the research, guidance and industry context discussed on this page:

    AUSTRAC — Real Estate Designated Services — 2026

    Official AUSTRAC guidance on the AML/CTF obligations that apply to real estate professionals providing designated services, including enrolment, AML/CTF programs, customer due diligence and recordkeeping.

    View Source →

    Evidence Standard

    LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.

    Does Your Technology Actually Support What You Are Required to Do?

    AML/CTF obligations are in force. If your technology cannot show you where identity information lives, who can access it, and which transactions have open CDD deadlines, that is a technology problem worth fixing. Book a strategy session with LOOKUP to assess your current environment and build a practical path forward.

    PK

    Peter Kantarelis

    Founder, LOOKUP — Business Technology Strategist

    Peter Kantarelis is the Founder of LOOKUP and a business technology strategist helping Australian organisations modernise technology, strengthen cyber security and prepare for practical AI adoption. He regularly works with business owners and leadership teams to improve productivity, reduce operational risk and implement technology that delivers measurable business outcomes. The LOOKUP Business Modernisation Framework™ reflects more than 25 years of helping Australian businesses make better technology decisions.

    View More Insights →
    Avatar
    Hi there! Have a question? Chat with us here.