AML Compliance for Real Estate Franchise Groups: Network-Wide Governance
Franchise groups face unique AML compliance challenges. You operate multiple offices, each with its own agent-run transactions, but AUSTRAC holds the lead entity accountable for the entire network.
This is where centralised governance meets decentralised execution.
AUSTRAC's View: The Network is One Entity
AUSTRAC considers a franchise group as a single reporting entity. The lead entity is responsible for:
- An AML/CTF program that covers all franchisees
- Compliance consistency across all offices
- Training and competency across the network
- Risk assessment for the group
- Monitoring and escalation frameworks
This means: if one franchisee in one office fails to complete CDD on a customer, the entire group is potentially noncompliant.
Post-1 July, AUSTRAC has made clear that it will audit networks, not just individual offices. It will review whether the lead entity has established genuine group-wide governance.
The Franchise Compliance Gap
Many franchise groups have a problem: they have set up AML software for each franchisee, but no centralised oversight.
Why this is risky:
- Each office operates independently with its own "Compliance Officer" (often not qualified)
- No consistency in decisions across the network
- No central visibility into risks across offices
- No single authority to make network-wide escalation decisions
- Training is inconsistent or non-existent
An AUSTRAC audit will eventually discover this and find noncompliance.
What Network-Wide Governance Looks Like
Structure
Central: Lead entity appoints a network Compliance Officer (or engages external CO) to oversee group governance
Local: Each office has a designated person (franchisee or franchisee-appointed) responsible for local CDD workflow, but this person does not have authority to make network-level escalation decisions
Governance Flows
Customer onboarding: Local office performs initial CDD and documents information
Escalations: Higher-risk customers are flagged by local office and escalated to network CO
SMR Decisions: Network CO has authority over all SMR filings across the group
Training: Network CO coordinates training across all offices; records participation centrally
Risk Assessment: Network CO updates group risk assessment annually and ensures consistency across offices
Technology for Franchise Groups
The right platform setup enables centralised oversight:
- Single platform or integrated platforms where network CO can see all office activity
- Escalation routing that automatically sends flagged customers to network CO
- Reporting dashboards that show compliance metrics across all offices
- Training tracking that verifies completion across the network
- Audit trails that show what each office did and when
Without this infrastructure, your "group compliance" is actually just disconnected office compliance.
The AUSTRAC Audit Scenario
Scenario: 30-office franchise network
AUSTRAC conducts a network audit. It samples 10 offices and reviews 50 files across the network.
Findings:
- Office A: 2 customer files with incomplete CDD (trustee beneficial owner not identified)
- Office B: 1 customer with PEP alert that was never escalated
- Office D: Staff training records missing for 3 agents
- Office F: SMR filed without documented CO decision; appears to have been auto-generated
AUSTRAC finding: Systemic compliance gaps across the network. Lead entity failed to establish effective group-wide governance. Multiple breaches identified.
Penalty calculation: 11 breaches (2 + 1 + 3 + 1 + others discovered) × $36.4 million = $400.4 million potential civil penalty exposure, before director liability assessed separately.
How this would have been different with centralised governance: A network CO would have caught these gaps, provided guidance to local offices, and remediated before audit.
Best Practices for Franchise Groups
1. Centralised Governance Officer
Best: Engage an external network Compliance Officer who oversees all offices and has no conflict with individual franchisee operations
Good: Appoint a senior network staff member who has authority and resources dedicated to group compliance
Risky: Leave each office to manage its own compliance with no central oversight
2. Consistent Policies Across the Network
The AML/CTF program, risk assessment, policies, and procedures must be documented centrally and applied consistently across all offices.
Franchisees cannot opt out or create local variations.
3. Centralised Risk Assessment
The network must conduct an annual risk assessment that considers:
- Risk across all 30 offices combined
- Geographic risk (some postcodes may be higher-risk than others)
- Customer types (commercial properties may be higher-risk than residential)
- Network-wide patterns (e.g., multiple offices processing trust purchases)
4. Escalation Authority
Define clearly: what decisions can local offices make, and what must escalate to the network CO?
Example:
- Local: Standard CDD, identity verification, normal transaction processing
- Network CO: Complex entities, PEPs, SMR decisions, significant risk escalations
5. Training Coordination
Coordinate training across all offices. Verify completion. Maintain centralised records that AUSTRAC can audit.
Do not rely on individual offices to arrange training.
6. Compliance Reporting
The network CO provides monthly or quarterly reporting to the board/leadership showing:
- Escalations across all offices
- Training completion rates
- Compliance incidents or trends
- Risk assessment updates
- Audit readiness status
Cost Considerations
Option 1: Internal Network CO
Salary + training + time commitment = $60k–$120k annually, depending on network size
Option 2: External Network CO Service
Monthly service fee scaled to network size: typically $2000–$5000/month for a 20–30 office network
The real cost of NOT having centralised governance: A single AUSTRAC finding across a network of 30 offices can result in hundreds of millions in potential penalties.
Key Takeaways
- AUSTRAC audits networks, not individual offices. Centralised governance is essential.
- Lead entity is liable for the entire network. You cannot delegate compliance to franchisees and claim you are compliant.
- A network Compliance Officer is the infrastructure that enables consistent, defendable compliance across all offices.
- Technology alone is not enough. You need human oversight and judgment at the centre.
- The cost of a network CO is insurance against the catastrophic cost of network-wide compliance failures.