Real estate was the largest newly regulated sector by enrolment volume, and it is also the one where group structure is most often assumed rather than analysed. A shared brand does not create a reporting group, and centralising onboarding does not move accountability off the office that provided the service.
What is a reporting group, and how does one form?
Australia's reformed AML/CTF framework introduced reporting groups in place of designated business groups. A business group becomes a reporting group automatically where the required control relationship exists and at least one person in that group provides a designated service.
A franchise network can be different, and AUSTRAC's own example makes the point. It describes a real estate franchisor and its franchisees forming an elective reporting group where the franchise agreement does not give the franchisor control over the franchisees.
That example matters because it shows shared branding, common operating standards and a single marketing identity do not by themselves establish the control relationship an automatic business-group reporting group requires. Two networks that look identical to a consumer can sit in different places under these rules depending on what their agreements actually say about control.
The consequence is that a network has to analyse its legal and control structure rather than assume every office is either wholly isolated or automatically consolidated. Both of those defaults are wrong more often than they are right, and they lead to opposite mistakes: one leaves obligations unowned, the other assumes a head office programme covers offices it was never designed around.
Who has to oversee the programme once a group exists?
A reporting group must have a lead entity, and the role carries real obligations rather than a coordinating title. AUSTRAC says the lead entity is responsible for the group-wide ML/TF risk assessment and AML/CTF policies, for implementation of those policies, and for risk management and compliance management.
The lead entity also needs to consider the nature, size and complexity of the other reporting entities in the group. That is the requirement most likely to be missed in practice, because it prevents a head office from designing a programme around itself.
A network programme built only around the franchisor or parent entity, without accounting for how customer onboarding, property transactions and local risks actually work across member offices, does not meet that expectation. A single office in a regional market with a different buyer profile is exactly the case the requirement exists to cover.
In practice this changes what the lead entity has to collect. A group risk assessment that reflects the network needs office-level information about customer types, transaction values, foreign buyer exposure, cash handling and the local market, which means the lead entity has to be able to ask member offices for that data and get it. Networks that discover this late tend to find the information exists but has never been reported upwards in a comparable form.
Does delegation move accountability?
No, and this is the most commercially significant point for a network that has invested in a central compliance function. Reporting-group structures can allow obligations to be discharged by another member, but AUSTRAC states that members remain legally accountable for their AML/CTF obligations. The Act separately contains provisions that can make the lead entity responsible for certain contraventions by group members.
Accountability therefore runs in both directions at once, which is unusual and worth spelling out to office principals. Centralising a control does not release the office, and providing a central control does not insulate head office.
| Function | Where it runs | Who stays accountable |
|---|---|---|
| Group ML/TF risk assessment | Lead entity | Lead entity |
| Group AML/CTF policies | Lead entity | Lead entity |
| Customer onboarding and due diligence | Often centralised | Member providing the service |
| Screening and match review | Often centralised | Member providing the service |
| Suspicious matter escalation | Local detection, central reporting | Both, per the group structure |
| Records and retrieval | Central system | Member, with access rights |
Centralised onboarding or screening should therefore be governed through clear responsibilities, service levels, escalation paths and evidence access. A branch should be able to say what the central team performs on its behalf and what remains local, without having to ask.
Does one weak office make the whole network liable?
Not automatically, and it is worth resisting that framing when it appears in market commentary. If one branch or member receives regulatory attention, the legal consequences depend on the group structure, the entity involved and the specific contravention.
The practical enterprise consequence can still be much wider than the single office. A control failure in one place frequently reveals inconsistent policies, an incomplete group risk assessment, weak oversight or poor evidence access, none of which are confined to the office where the failure surfaced.
It can also create reputational and commercial questions for the network as a whole, including with banking counterparties. The appropriate management response is therefore to test whether the issue is isolated or systemic, and to be able to show which of the two it was.
That test is worth designing before it is needed. If a member office receives attention, the lead entity should be able to run the same control check across comparable offices quickly and produce the result, rather than starting an ad hoc review whose scope is set by whoever is available. A network that can demonstrate the issue was contained is in a materially different position from one that cannot say either way.
How should network controls be designed?
Around a group-wide minimum standard, with local escalation preserved for materially different risk. Trying to run a single identical process everywhere fails in a network with genuinely different local markets, and letting each office design its own fails the group risk assessment.
Core elements of the minimum standard include common customer data requirements, beneficial ownership rules, screening parameters, match-review standards, escalation thresholds, record retention, training and management reporting. Those are the items where inconsistency between offices is hardest to defend later, because each of them produces a record that can be compared directly across the network.
The lead entity should also maintain a current membership record and a clear view of changes in offices, ownership and service scope. A central control that does not know which entities and branches it covers cannot be governed, and in a franchise network membership changes more often than the programme is reviewed. Our Tranche 2 checklist sets out the underlying sequence, and the real estate sector guidance covers how the obligations land on an agency.
Where does technology fit?
Where a network centralises or coordinates customer and business screening, a platform can support consistent workflows, ongoing monitoring, role-based processes and comparable evidence across organisational units. That consistency is the thing a group risk assessment depends on, because a group cannot assess what its members record differently.
The reporting-group structure and the legal allocation of obligations have to be determined independently of any system. Technology can operationalise the model a network has chosen. It cannot create a reporting group, and it cannot remove entity-level responsibilities. The Tranche 2 hub covers the rest of the programme.
Important information
This article provides general information about Australia's AML/CTF framework and does not constitute legal advice. Whether an obligation applies depends on the designated services provided and the circumstances of the business.
Reporting-group status turns on control relationships and on the terms of the agreements between entities, so take your own legal advice on your own structure before relying on a group position. Reporting entities remain responsible for meeting their obligations under the AML/CTF Act, the Rules and applicable AUSTRAC guidance, alongside its published regulatory expectations.



