
Most real estate agencies now understand they need an AML/CTF Program Manual. Far fewer understand what that actually means in practice, and almost none have thought about what happens to that document twelve months after it’s written. A Program Manual isn’t a form you fill in once and file away. It’s meant to describe how your agency actually operates, day to day, and it only does its job if it keeps describing that accurately as your business changes.
Here’s what genuinely needs to be in it, how to structure it so people actually use it, and what “keeping it alive” looks like in practice.
What a Program Manual is actually for
Before the content, it helps to be clear on the purpose. AUSTRAC doesn’t want a document that proves you’ve read the AML/CTF Act. It wants evidence that your agency has a working system for identifying and managing money laundering and terrorism financing risk, and that the people in your business actually know and follow it.
That distinction matters because it changes how you should write the thing. A Program Manual written to satisfy a checklist reads like a legal summary. A Program Manual written to actually be used reads like an operating manual, because that’s what it is: the rulebook your compliance officer, your agents, and your admin staff refer back to when a real situation comes up.
The core components every Program Manual needs
Regardless of exactly how your agency chooses to structure the document, these elements need to be present, documented, and genuinely reflective of how your business runs.
Governance and accountability. Who is your nominated AML/CTF Compliance Officer, what authority do they actually hold, and who do they report to. For a small agency this might be one paragraph. For a multi office business it needs to set out escalation paths clearly enough that a junior agent in a regional branch knows exactly who to call.
Your ML/TF risk assessment. This is the foundation everything else builds on, and it has to describe your agency specifically: the transaction types you handle, the customer profiles you typically see, the geographies you operate in, and where your particular risk sits higher than the industry average. A risk assessment copied from a generic template describes the real estate sector in general. It doesn’t describe your agency, and an examiner will notice the difference immediately.
Customer due diligence procedures. What identification and verification you collect for individuals, companies, trusts, and self managed super funds. When enhanced due diligence applies (foreign politically exposed persons, high risk jurisdictions, unusually complex structures) and what that additional step actually involves.
Your screening approach. How PEP and sanctions checks are conducted, who’s responsible for running them, and what the escalation process looks like when something flags.
Reporting procedures. How your team recognises reasonable grounds for suspicion, how a Suspicious Matter Report actually gets lodged, and how Threshold Transaction Reports are handled when cash of $10,000 or more is involved.
Staff training. Not just a statement that training occurs, but what’s covered, how often it’s refreshed, and how completion is evidenced for every staff member, not just the ones who happened to be in the room the first time.
Record keeping. How CDD files, screening records, and reports are stored, for how long (the obligation runs to seven years), and how a complete file could be produced on request without anyone needing to reconstruct it from memory.
Review and independent evaluation. A statement of when your program will be reviewed internally, and the plan for an independent evaluation at intervals appropriate to your size and risk.
Structuring it so people actually use it
Here’s where a lot of agencies go wrong, even ones that get the content right. A Program Manual that’s technically complete but written entirely in legal language, with no clear structure, will sit unread on a shared drive. If your agents can’t quickly find “what do I do when a buyer wants to pay part of the deposit in cash,” the document has failed regardless of how legally sound it is.
A few practical rules that make a real difference:
Write the procedures in plain language, addressed to the person who’ll actually be doing the task. A sales agent reading your CDD procedure should be able to follow it without needing a law degree to interpret it.
Separate the reference material (your risk assessment, your governance statement) from the day to day procedures your team needs quick access to. Some agencies find it useful to think of this as two layers: the formal program document that sits behind the compliance officer, and a shorter, practical staff handbook drawn from it that agents actually keep at their desk.
Version control every document. Each policy should carry a version number, a date, and a name attached to who approved it. When AUSTRAC or an internal reviewer asks “is this the current version,” you need a clean, immediate answer.
Get genuine senior sign off, not just a signature on the cover page. The point of that sign off is that someone with real authority in the business has actually read it and stands behind it.
Where most Program Manuals actually fail
It’s rarely the content. Most agencies, once they sit down properly, can produce a reasonably thorough document. The failure shows up twelve or eighteen months later, when the manual still describes how the agency operated on the day it was written, while the agency itself has moved on: new staff, a new office, a shift toward higher value listings, an overseas buyer segment that didn’t exist before.
A Program Manual that isn’t maintained doesn’t just become outdated. It becomes actively misleading, because it tells an examiner your agency handles risk one way while your actual practice has quietly become something else. That gap, between the document and reality, is exactly what an audit is designed to find.
What ongoing compliance actually looks like
This is the part almost nobody plans for at the outset, and it’s the difference between a program that survives an examination and one that only looked good on the day it was filed.
Schedule your independent review before you need it. AUSTRAC expects your program to be independently evaluated at intervals suited to your size and risk profile. Don’t wait until year three to think about who’s doing this. Put a rough date on the calendar now, even if the specifics get refined later.
Revisit your risk assessment when something material changes, not just on a fixed annual schedule. A new office opening, a shift into a different property segment, taking on your first overseas buyers in volume: any of these should trigger a genuine review of whether your documented risk profile still matches reality.
Refresh training regularly, and track it properly. New staff need to be trained before they’re handling transactions unsupervised, not months later during a scheduled annual session. Keep a simple record: name, date, module completed. If you can’t produce that record for a specific staff member on request, the training essentially didn’t happen from an evidentiary standpoint.
Keep records in a system that survives staff turnover. If the only person who understands where a file is kept, or how your record keeping actually works, leaves the business, you have a genuine continuity problem. Build the system around the role, not the individual currently in it.
Watch for regulatory change. AUSTRAC’s guidance and AML/CTF rules do get updated, and a program that was compliant when it was written can drift out of alignment if nobody’s tracking those changes. This doesn’t need to consume a day a week, but someone in your business should own the task of periodically checking for updates.
Do an honest annual check in on the whole program. Not a full rebuild, just a genuine read through: does this still describe how we actually operate, is anything missing, has anyone been cutting corners under time pressure. Catching drift early is far less costly than an examiner catching it for you.
Building versus maintaining: two different skills
Writing a Program Manual and running one over years are genuinely different tasks. Plenty of agencies can produce a solid document once, with the right guidance, and then find the ongoing discipline of keeping it current is where things quietly slip: a training record that doesn’t get logged, a risk assessment that never gets revisited after the first year, an independent review date that keeps getting pushed back.
This is exactly why we built Lead Comply as a combination of a custom written Program Manual and an operational portal, rather than either one alone. A document without a system behind it drifts out of date. A portal without a properly written program underneath it is a set of tools with nothing genuine tying them together.
Where Lead Comply fits into this
Our AML/CTF Program Manual is written specifically for your agency, not adapted from a generic template, drawing on genuine experience building auditable management systems in one of Australia’s most heavily scrutinised regulated industries. Alongside that, the Lead Comply AML Portal gives your team the day to day operational layer: customer due diligence workflow, staff training modules, and the ongoing record keeping that makes your program something your team actually runs on, rather than a document nobody opens again after enrolment week.
If you’re not sure whether your current program (or the template you downloaded to get started) would genuinely hold up to a proper examination, our free 30 minute Compliance Gap Audit is built to give you a straight, honest answer on exactly that.