AML Compliance Guide

Record keeping (7 years) for Real estate agents — 2026 AUSTRAC Guide

If your real estate agency provides a designated service from 1 July 2026, you must make and keep AML/CTF records for 7 years. For real estate agents, that means keeping clear records of customer checks, transaction documents and your AML/CTF program so AUSTRAC can see what you did in a sale, purchase or other covered property transaction. If you cannot produce those records, AUSTRAC can treat that as a breach in its own right, with civil penalties up to $33.5 million per contravention and criminal penalties for intentional contraventions.

This obligation is not just about filing documents away. You must create records that fully show how you met your AML/CTF duties in each covered matter. For a real estate agency, that will usually include customer due diligence records for the vendor, purchaser and any other customer receiving the designated service; beneficial ownership records for company or trust buyers; sanctions screening results; internal notes about higher-risk situations; copies of contracts, authorities, trust-related instructions and payment directions the customer gave you; and records showing what your staff did when something looked unusual. AUSTRAC’s record-keeping guidance also requires transaction records to contain enough detail and supporting documents to fully and accurately reconstruct the transaction.

What a real estate agency should keep

  • CDD records: name, date of birth, address and ID details for individuals, plus verification results
  • Entity records: ABN or ACN, ASIC checks, trust deed details, trustee details and beneficial owner information for companies and trusts
  • Transaction records for each designated service, including dates, amounts, payment method, account details, contracts, invoices, deposit records and settlement-related instructions
  • Customer-provided transaction documents, such as signed sale contracts, payment authorities, source-of-funds documents and written instructions about deposits or disbursements
  • AML/CTF program documents, ML/TF risk assessment, staff training records, senior management approvals and any records explaining an SMR decision

Know the 7-year clock

Keep customer due diligence records for 7 years after the business relationship ends. Keep transaction records for 7 years from the date the transaction record was created or the transaction was completed, and keep customer-provided transaction documents for 7 years from the day the customer gave them to you. Records must be in English, or easily translated into English, and retrievable if AUSTRAC asks for them.

A practical approach for an agency is to build one AML file for each property matter. First, open the file as soon as you start acting in a covered transaction. Second, save identity checks, ASIC extracts, trust deed extracts, sanctions screening results and beneficial owner notes before any designated service is provided. Third, add every key document that shows movement of money or instructions connected with the transaction, including deposit receipts, trust account directions, variations to settlement instructions and emails or text messages giving payment details. Fourth, if something is escalated internally because the structure is unusual or the buyer is a PEP, save the review notes and the outcome. Fifth, lock the file at the end of the matter and set a destruction date no earlier than 7 years after the relevant retention period starts.

Common mistakes for real estate agents are very practical. One is assuming the sale contract alone is enough; it is not, because AUSTRAC expects enough records to reconstruct what happened and what checks you performed. Another is losing payment instructions that came by SMS, WhatsApp or email, especially where deposits or settlement funds were redirected. Agencies also often keep ID documents but not the record of how they verified them, or they keep the trust deed but not the note identifying the beneficial owners behind the trust. A good system is to use a standard AML checklist in your CRM or property management platform, restrict access to sensitive records, back up electronic files, and make sure front-office staff know that printed copies, inboxes and mobile phones are all part of the record-keeping problem.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need to keep records if the sale falls over before settlement?
Yes, if you provided a designated service and carried out AML/CTF checks or received transaction documents, keep those records even if the deal did not complete. The retention period still applies because the records show what you did in connection with that matter.
Can I keep everything electronically, or do I need paper copies?
You can keep records electronically if they are secure, complete and easy to retrieve. They must also be in English, or easily translated into English, and protected from unauthorised access, loss or tampering.
What if the buyer is a company or trust and I only dealt with their solicitor or accountant?
You still need records showing how you identified the customer and, where required, the beneficial owners. If a company or trust is involved, keep the ASIC search results, trustee details, trust documents and your record of who ultimately owns or controls the entity.
Do text messages and emails about deposit instructions count as records I must keep?
Yes. If they relate to the designated service or show transaction instructions, they should be retained as part of your transaction record set. AUSTRAC guidance specifically points to records being easily retrievable even where they include text and chat messages across multiple apps and smartphones.
Will I need to buy expensive software to comply?
Not necessarily. A small agency can comply with a disciplined file structure, secure cloud storage, access controls, backups and a checklist-driven process. The key is that the records are complete, secure, searchable and retained for the full 7-year period.