Real estate guide · Tranche 2

Trust accounts + Tranche 2

The compliance year that changes property agencies: existing discipline around other people’s money now meets new AML/CTF duties about the people behind the transaction.

Workflow, not another generic explainer

The practical question is what happens inside the agency.

Generic Tranche 2 summaries are plentiful. An agency still has to translate the law and AUSTRAC guidance into moments its people recognise: taking a listing, identifying who controls a vendor, receiving changed disbursement details, moving trust money and deciding whether an unusual instruction belongs to the customer.

Trust-account controls and AML/CTF controls are not identical. Trust accounting protects the receipt, holding and disbursement of money under existing state and territory rules. AML/CTF obligations add a risk-based framework for designated services, customer due diligence, monitoring, reporting and records. One does not satisfy the other automatically.

The useful overlap is discipline. Agencies already understand authorisation, reconciliation, separation of duties and evidence. Tranche 2 extends that mindset to customer risk and the continuing question: are we dealing with the person we think we are?

From 1 July 2026

What changes for relevant real estate services

AUSTRAC’s real estate fact sheet is the authoritative starting point. Scope and timing depend on the service provided, so agencies should confirm their position and obtain professional advice rather than treating a website checklist as legal interpretation.

01

Enrolment

Businesses providing designated real estate services need to determine their obligations and enrol with AUSTRAC within the applicable timetable.

02

AML/CTF program

The program must be risk-based and operational: responsibilities, controls, training, governance and review should match the services and customers the agency actually handles.

03

Customer due diligence

CDD requires an agency to know who it is dealing with, assess risk and apply the appropriate identification and verification measures before providing a designated service.

04

Ongoing due diligence

Risk does not freeze at onboarding. Agencies need processes to monitor the relationship, keep information current and respond when conduct or instructions no longer fit the expected pattern.

CDD is more than collecting a licence at the front door. The agency needs a defensible process for the customer, any person acting for them and relevant beneficial ownership, calibrated to risk. Ongoing CDD then asks whether later behaviour and information remain consistent with what the agency knows.

The phone and email channel

Identity documents do not authenticate a changed instruction.

A vendor may have completed onboarding correctly and still have their email compromised weeks later. A criminal who can see the matter can ask for sale proceeds to be sent to a “new” account, explain away the urgency and answer basic questions copied from the thread.

The same gap appears when a supposed owner changes a disbursement account, a buyer requests a refund to a third party, or a representative calls from a new number. These are transaction-time interactions. Reopening the identity-document check may not reveal who controls today’s call or mailbox.

Use risk triggers that staff can apply consistently. Any new payment destination, new contact point, unexplained third party, time pressure or mismatch with expected behaviour should move the instruction into an independent verification and approval path.

The channel rule

Never verify an instruction using contact details supplied by that instruction. Return to a trusted number already in the agency’s records, confirm the person, read payment details out and back, and document the result before money moves.

Evidence trail

A control needs a record, not just a recollection.

What happened

Capture the instruction, risk trigger, decision and any supporting material. Keep the original message rather than copying only the apparently important fields.

Who checked whom

Record the staff member, trusted contact point, verification method, time and outcome. If the check failed or was abandoned, that is part of the record too.

What followed

Link approval, escalation, suspicious-matter consideration and retention to the relevant customer and transaction so reviewers can reconstruct the decision.

Each authorised-contact check creates a timestamped, hash-chained record: who requested it, the masked target, method and outcome. Compliance-authorised users can export records in PDF or CSV. That evidence can support a firm’s procedure, but it does not decide whether CDD is complete or whether reporting is required.

Customer and verification data—recipient details, messages and verification records—is hosted in Australia. Staff sign-in is handled by our identity provider, WorkOS, in the United States.

Practical readiness

A real-estate workflow checklist

Use this as an implementation prompt, not a substitute for AUSTRAC guidance or advice tailored to your business.

  1. 01

    Map which sales activities are designated services and who owns AML/CTF accountability.

  2. 02

    Document how staff identify and verify customers, beneficial owners and representatives at the right time.

  3. 03

    Define high-risk instruction triggers: changed vendor accounts, urgent refunds, third-party payments and unexpected contact details.

  4. 04

    Require independent verification using a contact record that predates the instruction under review.

  5. 05

    Record requester, target, method, time, outcome and any escalation with the matter or transaction file.

  6. 06

    Train sales, trust-account, property-management and reception teams; test the procedure with realistic scenarios.

  7. 07

    Align retention, suspicious-activity and incident processes, then review controls as AUSTRAC guidance evolves.

Sources

Public guidance is cited for context. No AUSTRAC or REIQ endorsement of Vericode is implied.

Make the procedure operable

Connect customer risk to the instruction in front of staff.

Build the AML/CTF program with qualified advice, then give agency teams a repeatable way to verify high-risk instructions—whether they arrive by phone or email—and preserve evidence.

General information only. This guide is not legal, financial, AML/CTF compliance or incident-response advice. Confirm obligations with AUSTRAC guidance and seek professional advice for your circumstances.