THE NEW AML/CTF REGIME: WHEN COMPLIANCE LOSES TOUCH WITH COMMERCIAL REALITY

Australia’s expanded anti-money laundering and counter-terrorism financing regime was intended to strengthen the integrity of the financial system. That objective is difficult to criticise. No responsible professional opposes sensible measures designed to detect criminal funds, disrupt organised crime, and protect the economy from exploitation.

However, the practical implementation of the new AML/CTF obligations has exposed a serious problem: the regime has become overextended, under-explained, commercially burdensome, and disconnected from the realities of legal and property transactions.

In its current form, the regime risks imposing a disproportionate compliance burden on solicitors, conveyancers, agents, and ordinary clients, while creating a lucrative market for third-party technology providers who assume little responsibility for the consequences of their systems.

WE DISCUSS THE FOLLOWING ISSUES IN THIS ARTICLE:
  • A Risk-Based Regime Without Practical Certainty
  • Solicitors Are Being Turned into Unpaid Compliance Officers
  • The Burden on Clients Is Becoming Unreasonable
  • Agents Should Not Be Expected to Perform Complex AML/CTF Functions
  • Third-Party Technology Providers Are the Real Winners
  • The Data Security Risk Has Been Underestimated
  • The Scope Should Be Targeted to Real Risk
  • Implementation Has Failed Because It Was Not Designed Around Practice
  • Conclusion: Reform the Reform
A Risk-Based Regime Without Practical Certainty

One of the central difficulties with the AML/CTF framework is that almost everything is described as “risk-based”. In theory, a risk-based approach allows flexibility. In practice, it often produces uncertainty.

Practitioners are told to assess risk, document risk, escalate risk, review risk, and manage risk. Yet when clear answers are needed, the response is commonly that the matter depends on the circumstances. That may be legally convenient, but it is operationally unhelpful.

The result is a regime where businesses and professionals are required to make consequential compliance judgments without sufficient practical guidance, while simultaneously facing the prospect of regulatory scrutiny if those judgments are later viewed as inadequate.

That uncertainty is compounded by the insurance issue. If the profession is expected to assume extensive compliance responsibilities, then there must be a realistic risk-transfer mechanism. Yet insurers are frequently unwilling to provide meaningful coverage for AML/CTF exposure, cyber incidents arising from identity verification processes, or losses connected to third-party compliance technology failures.

The result is a troubling imbalance: the Government imposes the obligation, regulators expect compliance, technology vendors sell the solution, but the professional at the coalface carries the operational and liability burden.

Solicitors Are Being Turned Into Unpaid Compliance Officers

The practical burden on legal practitioners is significant.

Solicitors and conveyancers are already subject to professional conduct rules, trust accounting obligations, duties to the court, duties to clients, verification of identity requirements, and obligations relating to fraud prevention. The expanded AML/CTF framework adds another substantial layer of administration.

In practice, practitioners are now required to spend hours each week dealing with compliance tasks that are often peripheral to the actual legal work. Time is consumed by:

  • reviewing identity verification reports;
  • resolving false positive alerts;
  • checking sanctions and politically exposed person screening results;
  • documenting risk assessments;
  • updating internal policies;
  • completing webinars and training modules;
  • reviewing third-party platform outputs;
  • explaining repetitive compliance requirements to frustrated clients; and
  • managing discrepancies generated by automated systems.

Many of these alerts are false positives. Yet each must be reviewed, documented, and resolved. The burden is not theoretical. It diverts time away from core legal work, business transactions, client advice, contract negotiation, settlement preparation, and risk management of the actual transaction.

The effect is that private professionals are being conscripted into a quasi-public enforcement function. Solicitors are expected to operate as part-time compliance officers for the Government, but without public sector resourcing, indemnity, certainty, or compensation.

The Burden on Clients Is Becoming Unreasonable

The client experience has also deteriorated.

In a typical property transaction, a client may now be required to verify identity and provide personal information to multiple participants, including:

  • the selling agent;
  • the buying agent;
  • the solicitor or conveyancer;
  • the mortgage broker;
  • the bank;
  • verification technology providers; and
  • settlement or transaction platforms.

From the client’s perspective, this is repetitive, confusing, intrusive, and frustrating. Clients are being asked to provide sensitive identification documents repeatedly, often to different systems, with limited understanding of who is storing the data, where it is being stored, how long it will be retained, and what recourse exists if something goes wrong.

The property transaction process in Australia has never been more difficult. What should be a legally supervised commercial transaction is increasingly becoming a multi-stage compliance exercise. Ordinary buyers and sellers are being forced through excessive red tape, even where there is no obvious risk indicator beyond the fact that a transaction is taking place.

Agents Should Not Be Expected to Perform Complex AML/CTF Functions

The complexity of the regime also raises serious concerns about its application to real estate agents.

Agents perform an important commercial role, but they are not legal practitioners, forensic investigators, or financial crime specialists. Expecting agents to undertake nuanced AML/CTF assessments creates obvious risks. The regime requires judgment, escalation, documentation, and an understanding of legal and financial concepts that may sit outside the ordinary scope of an agent’s training and professional function.

This is not a criticism of agents. It is a criticism of the architecture of the regime.

If the Government considers property transactions to be a key AML/CTF risk area, then the compliance obligation should be concentrated in the hands of those best placed to manage legal risk: solicitors and licensed conveyancers. Even then, the obligation should be proportionate, clearly defined, and supported by reliable centralised infrastructure.

Extending complex obligations across every participant in the transaction chain creates duplication, inconsistency, and confusion.

Third-Party Technology Providers Are the Real Winners

One of the most concerning features of the current environment is the extent to which compliance has been outsourced to private technology providers.

Many practitioners now feel compelled to use third-party verification and screening platforms because manual compliance is too time-consuming and too risky. These providers charge significant fees, often on a per-transaction or subscription basis. Yet their terms frequently contain broad disclaimers, limitations of liability, and exclusions.

This creates a commercially unacceptable position.

Technology providers profit from the compliance burden, but often accept little or no liability if their systems generate false positives, miss relevant information, mishandle data, or contribute to delay or loss. Practitioners are then left to interpret platform outputs, explain them to clients, and bear the professional consequences.

The problem is intensified by the fact that many of these systems are technology-led rather than legally-led. Automated screening may identify names, locations, or data points, but it does not necessarily understand legal context, transaction structure, client instructions, evidentiary standards, or professional obligations.

AML/CTF compliance cannot be reduced to a software subscription. Yet the regime is pushing the profession in precisely that direction.

The Data Security Risk Has Been Underestimated

The current approach also creates a serious data security problem.

The regime requires the collection and storage of highly sensitive personal information, including passports, driver licences, identity documents, residential addresses, dates of birth, corporate records, trust information, and beneficial ownership details.

In practice, that information is now being uploaded, stored, transmitted, and re-transmitted across multiple platforms and organisations. Identification documents are being passed from one participant to another, often through systems clients do not understand and cannot meaningfully interrogate.

This is a recipe for data breaches.

A more coherent implementation model would have involved a Government-controlled portal or centralised verification infrastructure. Under such a model, identity documents could be verified once, securely, through an authorised system, with regulated participants receiving confirmation of verification rather than retaining copies of sensitive documents across multiple private databases.

Instead, the current regime appears to have created a fragmented compliance marketplace. Sensitive data is being distributed across numerous private providers and transaction participants. That increases the attack surface for cyber criminals and heightens the risk of identity theft.

If the Government mandates the collection of sensitive identity information, it should also provide the secure infrastructure through which that information is verified and controlled.

The Scope Should Be Targeted to Real Risk

The principal flaw in the current approach is its breadth.

Rather than focusing enforcement and compliance obligations on genuinely high-risk transactions, the regime risks subjecting ordinary Australians to disproportionate scrutiny. The sale of a suburban home by a long-term Australian resident should not be treated in the same practical manner as a transaction involving opaque structures, unexplained foreign funds, high-risk jurisdictions, or cash settlements.

A more rational model would be to limit the focus on objectively higher-risk indicators, including:

  • transactions involving high-risk jurisdictions;
  • cash purchases or unexplained source of funds;
  • transactions involving nominees or third-party payers;
  • rapid resale or unusual transaction patterns.

Such an approach would preserve the integrity objective of the legislation while reducing unnecessary burden on ordinary clients and low-risk transactions.

Putting every client through extensive processes, regardless of risk, is not targeted regulation. It is administrative overreach.

Implementation Has Failed Because It Was Not Designed Around Practice

The failure is not merely that the regime is burdensome. The failure is that, although it may have been intended to operate on sensible principles of proportionality, risk assessment and practical compliance, its implementation has not been designed around the realities of legal and property transactions.

A workable regime required:

  • clear and practical guidance;
  • standardised Government-approved processes;
  • a secure centralised verification mechanism;
  • proportionate obligations for low-risk transactions;
  • meaningful safe harbours for practitioners acting reasonably;
  • recognition of existing professional obligations;
  • realistic implementation timeframes;
  • affordable compliance infrastructure;
  • proper consideration of insurance availability; and
  • liability settings that do not unfairly shift all risk to practitioners.

Instead, practitioners are spending considerable time investigating false positive matches and contextual risk flags, particularly for clients with common names or clients whose circumstances trigger automated alerts (heaven forbid, we have a client called John Smith). These are not minor administrative inconveniences. They require careful review, documentation and resolution, often in circumstances where the apparent “risk” has no realistic connection to money laundering or terrorism financing.

Examples we have incurred to date include a potential match with a judge in Louisiana, that, after spending time following that trail, it became clear that the person identified in the alert was deceased and plainly not our 30-year-old client living in Queensland. Similarly, we had clients completing their checks while travelling on holiday in a jurisdiction treated as ‘high risk’. This then required us to undertake further inquiries to confirm that the client was in fact merely on holiday, including obtaining evidence of flights, accommodation and travel arrangements. This is a disproportionate use of professional time. Solicitors are lawyers, not detectives.

If the Government expects solicitors, conveyancers and other regulated parties to manage these obligations, the system needs to be significantly tightened. Screening tools must be more accurate, guidance must be more practical, and the regime must not require professionals to spend disproportionate amounts of time resolving alerts that should never have been escalated in the first place.

Conclusion: Reform the Reform

Australia needs an AML/CTF framework that targets real criminal risk without paralysing legitimate commerce. The present approach does not strike that balance.

The regime is overreaching because it imposes broad, complex, and uncertain obligations across ordinary transactions. Implementation has failed because it has relied too heavily on private compliance technology, provided insufficient practical certainty, underestimated data security risks, and ignored the operational realities of legal practice and property transactions.

AUSTRAC and the Government should recalibrate the framework. The focus should be on genuine risk, not blanket suspicion. Compliance should be centralised where possible, simplified for low-risk transactions, and supported by clear guidance and secure infrastructure.

The objective of preventing money laundering is important. But a regime that turns ordinary property transactions into a bureaucratic obstacle course, exposes sensitive client data to unnecessary risk, and forces professionals into unpaid enforcement roles is not sound regulation.

It is compliance without proportion.

Should you have any queries please do not hesitate to contact us on 1300 680 584 or contact@maplawyers.com.au
MAP Lawyers logo

SELLING BUT NOT YET READY TO GET YOUR SELLER DISCLOSURE?

If you need a Queensland Seller Disclosure Form 2 but you are not quite ready to submit your request now, no problem. Please complete the information below and we will email you with the next steps when you are ready:

Seller Disclosure - Start Later Form

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Call Now Button