How it works

One screen per obligation. Nothing else.

What the AML/CTF Act requires of a Tranche 2 reporting entity from 1 July 2026, and how each obligation maps to a screen: program, clients and KYC, reviews, reports, training, audit trail.

A blank identification card and a navy passport on an open client folder, with a loupe and a fountain pen.

1. Enrol with AUSTRAC

What the law asks. A firm that provides a designated service must enrol with AUSTRAC as a reporting entity within 28 days of starting to provide it. Enrolment is done on AUSTRAC Online; it is free and takes under an hour.

In RealtyAML. RealtyAML keeps enrolment on your Overview checklist so it is not forgotten, and records the designated services you selected so your enrolment and your program say the same thing.

An Australian city business district at dusk seen from an office window.

2. Adopt an AML/CTF program

What the law asks. The Act requires a written program with two parts: an assessment of the money laundering and terrorism financing risk your firm faces, and the policies and procedures you use to manage that risk. It must be approved by senior management and kept current.

In RealtyAML. You answer a short questionnaire about your practice: services, staff, the risk factors that apply, and who your compliance officer is. The program is generated from those answers as a document you can print, sign and adopt. Every save creates a new version with a date, so when AUSTRAC asks when the program was last reviewed, the answer is on file.

A bound trust deed with a navy cover and ribbon on a walnut desk, beside reading glasses.

3. Appoint a compliance officer

What the law asks. Every reporting entity must appoint an AML/CTF compliance officer at management level. In a small firm that is usually the principal. The officer is responsible for the program, staff training and reporting to AUSTRAC.

In RealtyAML. The officer is named in your program and shown on the Overview, and the annual review reminder is addressed to them.

4. Verify every client

What the law asks. Before you provide a designated service you must collect and verify the identity of the client, and of the beneficial owners of a company or trust, using a reliable and independent document. You must also understand the purpose of the relationship.

In RealtyAML. The Clients screen records the client type, the document sighted, who verified it and when, and any extra risk factors such as a politically exposed person, cash payments, a third party instructing, or an unclear source of funds. A rule set scores each client and rates them low, medium or high risk as you type.

A blank identification card and a navy passport on an open client folder, with a loupe and a fountain pen.

5. Rate and review risk

What the law asks. Due diligence does not end at onboarding. Client files must be reviewed on a schedule set by risk, and high-risk clients need enhanced due diligence: source of funds, senior approval and closer monitoring.

In RealtyAML. The Reviews screen lists everything due, in date order: high-risk clients every 6 months, medium every 12, low every 24, plus the annual review of the program itself. One button marks a review done and records it in the audit trail.

A desk calendar with one day marked with a small teal flag, next to an analogue desk clock.

6. Report to AUSTRAC

What the law asks. If you form a suspicion that a matter may involve money laundering or terrorism financing, you must lodge a suspicious matter report within 3 business days (24 hours for terrorism financing). Cash transactions of AU$10,000 or more need a threshold transaction report within 10 business days. Each year you lodge a compliance report.

In RealtyAML. The Reports screen logs the suspicion or the cash transaction, starts the clock and shows the due date. When you lodge with AUSTRAC you mark it done. At year end it generates a summary of the year from your records to help with the annual compliance report.

Banded stacks of polymer banknotes beside a deposit envelope and a receipt printer on a counter.

7. Keep records for 7 years

What the law asks. Identification records, transaction records, reports and the program itself must be kept for 7 years after the client relationship ends.

In RealtyAML. RealtyAML never physically deletes a client record; archiving removes it from your register but keeps it stored. Every action in the firm is written to an audit trail with a timestamp that cannot be edited, and you can download it as a CSV at any time.

Seven navy archive box files with teal labels in a row on an office shelf.

Questions people ask

Does the program count as my firm's official AML/CTF program?
It becomes your program once your senior management approves and adopts it. The document says clearly that it is a template generated from your answers; you should read it and change anything that does not fit your practice before adopting it.
What happens if a client refuses identification?
Under the Act you must not provide the designated service until identification is complete. Record the refusal; a refusal can itself be a reason to consider a suspicious matter report.
What about staff training?
Staff who deal with clients must be trained on commencement and kept trained. The Training screen has a short module with eight questions; a pass is recorded with the staff member's name and score, and the next training date is set 12 months out.
Is RealtyAML legal advice?
No. It is software that helps you record and manage your obligations. The program it generates is a template built from your answers; your agency decides whether it fits and adopts it.

Set up your program in the first ten minutes.

Fourteen days free. No card details until you decide to keep it.

How it works: one screen per AML/CTF obligation · RealtyAML