Specialist Compliance Solutions for AML/CTF Tranche 2, ISO 9001 & ISO 42001.

  0437 801 021    1/457-459 Elizabeth Street, Surry Hills, NSW 2010

You’ve Enrolled. Now What? The First 30 Days as a Reporting Entity

Enrolment is done, the deadline pressure has eased, and now comes the question nobody warned you about clearly enough: what do you actually build in the next 30 days, and in what order?

AUSTRAC’s own guidance sets out five steps to develop an AML/CTF program: establish your governance framework, assess your risks, put policies in place to manage those risks, review and update the program, and have it independently evaluated. Layered underneath those five steps are two obligations that start immediately and never stop: customer due diligence and record keeping.

That’s the official sequence. Here’s what it looks like in practice for a real estate agency trying to catch up in a month, not a quarter.

If you haven’t read them yet, this article follows on from the 29 July enrolment deadline and why enrolment alone isn’t compliance — this is where the actual building starts.

Week one: governance, not paperwork

Before you write a single policy, AUSTRAC wants to know who’s accountable. That’s what “establish your governance framework” means in plain terms:

  • Confirm your AML/CTF Compliance Officer. If you named an interim contact at enrolment, decide now whether that’s permanent. For a small agency, this is usually the principal — but it needs to be someone with actual authority to change how the business operates, not just someone who fills in a form.
  • Get senior sign-off on the fact that a program is being built. AUSTRAC expects your finished program to be approved by a senior manager. Start that habit now, not at the end.
  • Set the tone with your team. A one-page note from the principal saying “this is now how we operate, and here’s who to ask” does more for a genuine compliance culture than any policy document will.

This week is short and it’s mostly about clarity, not output. Don’t let it stretch — everything else depends on this being settled.

Week two: the risk assessment

This is the document everything else in your program is built on, and it’s the one agencies most often try to skip or copy from a template.

Your risk assessment needs to reflect your actual business: the types of transactions you handle, the customer profiles you typically deal with, the geographies involved, and any higher-risk patterns specific to your patch — off-the-plan sales, overseas buyers, cash-heavy segments, high-value listings, whatever applies to you. A generic industry template describes the sector. Your risk assessment has to describe your agency.

Practically, this week should produce:

  • A written assessment of your ML/TF risk exposure, dated and attributed to whoever prepared it
  • Identification of which customer types or transaction types carry higher risk for your agency specifically
  • A clear statement of what “enhanced due diligence” will mean for you when a higher-risk customer shows up

Weeks three and four: policies and customer due diligence

With the risk assessment done, you can now write policies that actually manage the risks you identified, rather than generic statements that could apply to any agency in the country. This is also when your customer due diligence procedure needs to be live — not planned, live, because every transaction from 1 July required it whether your paperwork existed yet or not.

At minimum, by the end of this stretch you should have:

  • A CDD procedure describing what identification and verification you collect for individuals, companies, trusts and SMSFs, and when enhanced due diligence kicks in
  • A screening approach — how you check for PEPs and sanctions matches, and what happens when something flags
  • Staff training completed or actively underway, with attendance or completion evidence attached to real names and dates
  • A record-keeping system that can produce a complete file for any transaction on request — this is a 7-year obligation, so whatever you build now needs to still make sense in 2033

What sits outside the 30-day window, but needs a date on the calendar

Two things don’t need to be finished in month one, but do need to be scheduled, or they quietly fall off the list:

  • Independent review. AUSTRAC requires your program to be independently reviewed at intervals appropriate to your size and risk. You don’t need this in week one, but you do need to know roughly when it’s happening and who’s doing it.
  • Ongoing due diligence. Initial CDD isn’t a one-off. Customer relationships need to be revisited over time, particularly if risk indicators change.

The mistake that costs agencies the most

The single most common failure in the first month isn’t missing a document — it’s producing documents that don’t match how the agency actually operates. A risk assessment that was clearly adapted from a template in an afternoon. A CDD policy that no salesperson has actually read. Training that happened once, for one person, months before anyone else joined the team.

An examiner isn’t grading your paperwork against a rubric. They’re checking whether what’s written down is what actually happens. A thinner program that’s genuinely followed beats a comprehensive one that exists only on a laptop.

What day 30 should actually look like

By the end of the month, a real estate agency that’s genuinely caught up should have:

  • A governance structure with a named, accountable Compliance Officer
  • A risk assessment specific to their business, not a template
  • A CDD procedure that staff are actually using on live transactions
  • Training completed and evidenced for everyone customer-facing
  • A record-keeping system that could produce a clean file today, for a transaction from three weeks ago
  • A rough date on the calendar for an independent review

That’s not a finished program forever — AML/CTF programs are living documents that get revisited as your risk profile changes. But it’s a program that would hold up if AUSTRAC asked to see it, which is the only test that actually matters.

Lead Comply’s free account gets you moving on the parts you can start today — CDD workflow and staff training, with no cost and no credit card. If you want an honest read on where the governance and risk assessment pieces actually stand, our free 30-minute Compliance Gap Audit will tell you exactly what’s built, what’s missing, and what to prioritise next.

Create your free account → Lead Comply AML Portal



Leave a Reply

Your email address will not be published. Required fields are marked *