
Before you write a risk assessment, before you draft a single policy, AUSTRAC wants one question answered clearly: who is actually accountable for this. That’s what governance means in an AML/CTF Program Manual, and it’s the section agencies most often treat as a formality when it’s actually the foundation everything else depends on.
Here’s why governance comes first, what it actually needs to contain, and how it scales for an agency your size.
Why governance has to come before everything else
A risk assessment is only as good as the authority behind it. If nobody in your agency has been formally given the power to change how the business operates when a risk is identified, the risk assessment is just a document describing problems nobody’s accountable for fixing. Governance is what turns a written program into something with actual teeth.
This is also why AUSTRAC’s own guidance for developing a program puts establishing your governance framework as the first step, ahead of the risk assessment itself. It’s not a formality at the front of the document. It’s the thing that makes every section after it mean something.
The three roles governance needs to name
A governing body. For most real estate agencies this is simply the principal, the director, or the partners, whoever holds ultimate authority over how the business runs. For a sole trader, this is you. The point isn’t necessarily a formal board, it’s a clear, honest answer to “who has the authority to make this business change how it operates.”
A senior manager. This is the person AUSTRAC expects to have genuinely reviewed and approved the program, not just signed a cover page. In a small agency this is often the same person as the governing body. In a larger multi office business, it might be a general manager or operations lead with real authority across every branch.
Your AML/CTF Compliance Officer. This is the role people focus on, and rightly so, but it only works if the two roles above are genuinely behind it. A compliance officer with no real backing from ownership is a title, not a function.
What your Compliance Officer actually needs
Naming someone isn’t the hard part. Giving them genuine authority is. Your Compliance Officer needs to be able to:
Pause or query a transaction if something looks wrong, without needing to justify that decision to a salesperson under pressure to close a deal.
Require staff to complete training, and follow up when they haven’t, without that being awkward because they’re also, say, the newest person in the office.
Report directly to the governing body or senior manager, rather than through a layer of management that might have its own reasons to want a transaction to proceed quietly.
If your nominated Compliance Officer doesn’t genuinely have this standing in the business, that’s worth fixing before you finalise the rest of your program, not after.
Governance for a small or sole trader agency
If you’re a sole trader or a very small agency, formal governance can feel like it’s been designed for a business much larger than yours, three separate named roles for a team of two or three people. In practice, the principle that matters is proportionality: your governance structure should be honest about your actual size, not artificially padded out to look more elaborate than it is.
For a genuinely small agency, it’s entirely reasonable for the principal to hold all three roles: governing authority, senior sign off, and the Compliance Officer function, provided this is documented clearly and the principal is genuinely engaged with the program rather than treating it as paperwork someone else handles. What AUSTRAC is looking for is honesty and clarity about how accountability actually works in your business, not a structure copied from a large corporate that doesn’t reflect your reality.
Escalation: who does a junior agent actually call
This is the practical test of whether your governance structure works. If a new agent, six weeks into the job, notices something odd about a buyer’s payment, do they know exactly who to tell, right now, without hesitating or guessing?
Your Program Manual should answer this in one sentence a new starter could repeat back to you on their first day. Not a flowchart, not a policy reference number, a name and a next step. “If something feels off about a transaction, tell [Compliance Officer name] immediately.” That’s what a working escalation path looks like, and it only works if that name is genuinely accessible and genuinely willing to be interrupted.
A worked example
A four person agency names the principal as Compliance Officer, which is appropriate for its size. But the actual governance document just says “the Compliance Officer will manage AML/CTF matters,” with no detail on authority, no escalation instruction for staff, and no evidence the principal has ever actually reviewed a transaction flagged by an agent.
Compare that to the same agency with one addition: a one page internal note, given to every staff member at induction, stating plainly who the Compliance Officer is, what to do if something seems unusual, and confirming the principal has personally reviewed and approved the program. Same size business, same person in the role, but only one of these versions gives an examiner, or a new staff member, genuine confidence the structure actually functions.
Building the culture, not just the structure
Governance on paper doesn’t create a compliance culture on its own. That comes from how the principal actually behaves when something inconvenient comes up, whether a flagged transaction gets genuine attention or gets quietly waved through because the sale is worth too much to slow down. Staff notice this faster than any policy document communicates it. If your team sees compliance treated as a genuine priority when it’s inconvenient, that’s the signal that actually shapes behaviour, far more than anything written in the manual itself.
Where this fits into your Program Manual
Governance should be one of the first sections in your actual document, not an afterthought bolted on once the risk assessment and policies are written. It sets the authority that everything else in the program relies on.
The Lead Comply AML Portal supports this structurally with role based permissions, so your Compliance Officer, your admin staff, and your agents each see what’s relevant to their role, and accountability is built into how the system actually works, not just described in a document. If you’re not sure whether your current governance setup would genuinely hold up, whether the right people have the right authority, and whether staff actually know who to call, our free 30 minute Compliance Gap Audit is built to answer exactly that.