Skip to content

The AML/CTF programme under the 2025 Rules

What an AML/CTF programme has to contain, who has to approve it, when it must be documented, and why most templates you will be offered are out of date.

In short

The Part A / Part B split was abolished on 31 March 2026. Since then an AML/CTF programme has been two things and only two things (s 26B): an ML/TF risk assessment covering the mandatory factors in s 26C(3), plus AML/CTF policies that manage what the assessment found (s 26F). It must be documented in writing before you provide a designated service, and approved by a senior manager — not the board (s 26P). Real estate obligations commenced 1 July 2026, so an agency operating today without a programme is contravening s 26E, separately for every designated service it provides.

Until 2026, the AML/CTF programme had a fixed shape. Part A managed ML/TF risk. Part B set out customer due diligence. Templates written before then follow that structure, and plenty are still in circulation.

The Part A / Part B split has been abolished.

Schedule 1 of the AML/CTF Amendment Act 2024 replaced the old programme provisions with Part 1A of the Act, commencing 31 March 2026 — three months before real estate came into the regime at all. So for an agency reading this, Part A and Part B were never your obligation. Check the date on anything you are handed.

The Act does not prescribe a document structure. It prescribes contents. AUSTRAC's stated test is that the programme is in place before you start providing a designated service, clearly documented in writing, approved by a senior manager, and complied with. How you arrange the headings is your call.

The two components

Under s 26B, a programme is two things:

  1. An ML/TF risk assessment (s 26C) — which since the 2024 reforms expressly covers proliferation financing as well, so substantively it is an ML/TF/PF risk assessment even though the colloquial name keeps "ML/TF".
  2. AML/CTF policies that manage and mitigate the risks the assessment found, and that ensure you comply with each of your obligations (s 26F). You must then actually comply with them (s 26G).

The mandatory risk factors — six, not four

Section 26C(3) makes six matters mandatory for a reporting entity providing designated services at or through an Australian permanent establishment:

  1. Kinds of designated services provided or proposed to be provided — including any new or emerging technologies relating to them
  2. Kinds of customers — individuals, companies, trusts, foreign buyers, PEPs, the mix you actually see
  3. Delivery channels — face-to-face, online, via intermediaries; again including new or emerging technologies
  4. The countries you deal with, or will deal with, in providing the services. That is a wider test than the customer's nationality: it picks up where funds come from, where a corporate buyer was formed, and where a trustee sits
  5. Information AUSTRAC communicates to you, directly or indirectly, identifying or assessing risks in your provision of designated services. Financial crime guides, national risk assessments and sector emails are mandatory inputs — and receiving one is also a statutory trigger to review the assessment
  6. Anything the Rules specify

The "four mandatory factors" shorthand is fine as far as it goes, but items 5 and 6 are mandatory too, and s 26C(4) confirms the list does not limit the general duty in s 26C(1).

On the first item, name your services exactly. Table 5 item 1 is "brokering the sale, purchase or transfer of real estate on behalf of a buyer, seller, transferee or transferor in the course of carrying on a business", and its customer is both the seller or transferor and the buyer or transferee. That wording covers listing agents and buyer's agents alike — if you broker, you are table 5 item 1 whichever side engaged you, and you owe CDD to both parties, not only to the one who signed your agreement. Selling your own stock where the sale is not brokered by an independent agent is table 5 item 2, customer the buyer only.

Table 6 is headed "Professional services" and is not your table — item 1 catches the solicitor or conveyancer assisting a person in the planning or execution of the same transaction, with the person they act for as their customer. It matters to you only because it makes those firms reporting entities, which is what opens the reliance pathways.

Proliferation financing — a carve-out with a burden attached

There is a statutory carve-out for proliferation-financing policies, not for the assessment. Under s 26F(11) you need not have policies specifically dealing with PF if you reasonably assess your PF risk as low and reasonably assess that your existing controls manage and mitigate it.

Two warnings. You must still assess PF in the risk assessment; the carve-out never touches s 26C. And s 26F(12) puts a legal burden on whoever relies on the carve-out — so the reasoning behind the "low" rating has to be written down at the time, not reconstructed later.

What else the programme must document

  • Governance — designating the AML/CTF compliance officer within 28 days (ss 26J–26M), notifying AUSTRAC within 14 days, reporting lines and escalation paths. The compliance officer must report to the governing body at least once every 12 months
  • Ensuring the governing body is sufficiently informed of ML/TF and PF risks, and designating which senior managers approve the policies and the risk assessment (s 26F(4))
  • Initial customer due diligence and ongoing CDD
  • Enhanced customer due diligence triggers and procedures (s 32; Rules s 6-20)
  • Suspicious matter and threshold transaction reporting procedures
  • Record-keeping arrangements
  • Staff training and personnel due diligence
  • The conduct and frequency of independent evaluations — at least once every 3 years

Approval, documentation and review

A senior manager approves it. Section 26P(1) requires the risk assessment and the policies — and every update to either — to be approved by a senior manager. Not the board. AUSTRAC states that a senior manager must fulfil this personally and cannot delegate it.

The governing body has a different and separate duty: appropriate ongoing oversight of your risk identification and of your compliance, and reasonable steps to ensure both actually happen (s 26H(1)). If the governing body fails, the entity contravenes and carries the civil penalty. And every time you update the risk assessment, the governing body must be told in writing as soon as practicable (s 26P(2)).

It must be in writing, before you start. Section 26N requires documentation, and the Rules require it before the first designated service is provided, with updates documented within 14 days. Failing to document is its own civil penalty.

It must be reviewed. The risk assessment must be reviewed on a trigger and at least once every 3 years (s 26D), and the policies at the frequency your policies specify and in any event at least once every 3 years (s 26F(3)(d)).

If you are reading this without a programme

You are not in a grace period; there isn't one. The order of operations is: enrol, designate and notify a compliance officer, do the risk assessment, write the policies, have a senior manager approve both, and document them. Do not backdate anything — a false record is a worse problem than a late one.

The consequence of operating without one is not abstract. Section 26E(1) prohibits commencing a designated service where you do not comply with s 26C or s 26D, s 26E(2) makes it a civil penalty provision, and s 26E(3) makes it a separate contravention in respect of each designated service. The policies mirror this at s 26F(8). For a brokered sale the customer is both the seller and the buyer, so exposure compounds quickly across a book of transactions.

What to do next. Check that any template you have been offered references the AML/CTF Rules 2025 (F2025L01026) and the six mandatory matters in s 26C(3). If it still has Part A and Part B headings, it was drafted for a regime that ended on 31 March 2026 — rebuild it before you provide another designated service, not at your leisure.

Frequently asked questions

Does my AML/CTF programme still need a Part A and a Part B?
No. The AML/CTF Amendment Act 2024 replaced the old programme provisions with Part 1A of the Act on 31 March 2026. A programme is now an ML/TF risk assessment (s 26C) plus AML/CTF policies (s 26F). Any template with Part A / Part B headings was written for a regime that no longer exists — and for real estate it never applied at all, because the sector only came into the regime on 1 July 2026.
Who has to approve an AML/CTF programme — the board or a senior manager?
A senior manager. Section 26P(1) requires the risk assessment, the policies, and every update to either, to be approved by a senior manager of the reporting entity — an individual who makes or is involved in making decisions affecting all or a substantial part of the business. AUSTRAC is explicit that a senior manager must fulfil this personally and cannot delegate it. The governing body does not approve; it oversees (s 26H), and it must be notified in writing as soon as practicable after any update to the risk assessment (s 26P(2)). In a sole-director agency the same person can hold both roles, but the roles must be documented separately because the obligations differ.
What are the mandatory risk factors in an AML/CTF risk assessment?
Section 26C(3) lists six: kinds of designated services provided or proposed (including any new or emerging technologies), kinds of customers, delivery channels (again including new or emerging technologies), the countries you deal with, information AUSTRAC communicates to you about risks in your provision of designated services, and any matters the Rules specify. The common 'four mandatory factors' shorthand covers only the first four.
Does my AML/CTF programme have to be in writing?
Yes. Section 26N requires the programme to be documented, and the Rules require that documentation to exist before you provide your first designated service, with any updates documented within 14 days. Failing to document is its own civil penalty under s 26N(3).
I'm a real estate agent and I still don't have an AML/CTF programme — what happens now?
You are contravening two civil penalty provisions. Section 26E(1) prohibits commencing a designated service without complying with ss 26C and 26D, and s 26F(8) does the same for policies. Section 26E(3) makes it a separate contravention for each designated service you provide. There is no transitional relief for real estate on the programme itself — the staggered timing in the Transitional Rules applies to your first independent evaluation, not to having a programme. Enrol, appoint a compliance officer, build the assessment, write the policies, get senior-manager approval, and document it. Do not backdate anything: a false record is a worse problem than a late one.

Sources

  1. AML/CTF Act 2006 (Cth) s 26B — what an AML/CTF program is (risk assessment plus policies)
  2. AML/CTF Act 2006 (Cth) s 26C — ML/TF risk assessment; s 26C(3)(a)–(f) mandatory matters
  3. AML/CTF Act 2006 (Cth) s 26D — review and update of the risk assessment; at least once every 3 years
  4. AML/CTF Act 2006 (Cth) s 26E — no designated service without an up-to-date risk assessment; s 26E(3) separate contravention per service
  5. AML/CTF Act 2006 (Cth) s 26F — AML/CTF policies; s 26F(3)(d) 3-yearly policy review; s 26F(4)(c) senior-manager approvers; s 26F(4)(f) independent evaluations; s 26F(11)–(12) proliferation-financing carve-out and legal burden
  6. AML/CTF Act 2006 (Cth) s 26G — obligation to comply with your AML/CTF policies
  7. AML/CTF Act 2006 (Cth) s 26H — governing body oversight; entity liable for the governing body's contravention
  8. AML/CTF Act 2006 (Cth) ss 26J–26M — compliance officer: designation, 28-day deadline, functions, 14-day AUSTRAC notification
  9. AML/CTF Act 2006 (Cth) s 26N — AML/CTF program documentation (civil penalty)
  10. AML/CTF Act 2006 (Cth) s 26P — approval by a senior manager; s 26P(2) written notification to the governing body
  11. AML/CTF Act 2006 (Cth) s 6, table 5 items 1–2 and table 6 item 1 — real estate designated services and who the customer is
  12. AML/CTF Act 2006 (Cth) s 32 — enhanced customer due diligence
  13. AML/CTF Rules 2025 (F2025L01026) s 5-15 — programme documented before the first designated service; updates within 14 days
  14. AML/CTF Rules 2025 (F2025L01026) s 5-7 — compliance officer reporting to the governing body at least every 12 months
  15. AUSTRAC — Your AML/CTF program overview (updated 24 July 2026)
  16. AUSTRAC — Senior manager; Governing body (Step 1: Establish your governance framework)

This is general guidance for Australian real estate professionals. It does not constitute legal advice. Consult a qualified AML/CTF practitioner before relying on it for your agency.