AML Software vs Managed AML Compliance: Which Meets AUSTRAC Requirements?
If you are building an AML compliance program for your real estate agency, you will face a choice: buy software, engage a managed service, or combine both.
This comparison shows what each approach actually delivers and helps you determine which fits your agency.
The Three Approaches
| Aspect | AML Software Only | Managed CO Service Only | Hybrid (Software + CO) |
|---|---|---|---|
| What You Get | Workflow platform, document storage, automated alerts, audit trail | Named Compliance Officer, decision support, escalation management, reporting | Your software + external CO oversight and escalation support |
| Decision-Making | Automated rules (software decides) | Human judgment (CO decides) | Hybrid (software flags, CO decides) |
| Typical Cost | $200–$600/month | $500–$1000/month | $350–$700/month |
| Time to Deploy | Weeks | Weeks (onboarding) + ongoing | Weeks (minimal training on new layer) |
| Internal Effort | High (staff training, escalation workflows) | Medium (staff awareness, external CO management) | Medium (existing workflows continue) |
What Software Actually Provides
Quality AML software is valuable. It handles:
- Repeatable, documented onboarding
- Information capture and storage
- Automated risk assessment (Green/Amber/Red)
- Rule-based alerting
- Transaction monitoring
- Record retention and audit trails
- Reporting reminders
What it does NOT do: Make judgment calls. An alert is not a decision.
What Managed CO Service Actually Provides
A managed Compliance Officer service handles:
- Named, qualified Compliance Officer (accountability)
- Review of escalations with human judgment
- SMR/TTR decisions and filing
- Complex entity analysis and KYB decisions
- Staff training coordination
- Absence coverage and backup
- Compliance reporting and governance
- Independent evaluation support
What it does NOT do: Daily transaction processing (that is too granular). It handles governance and escalations.
The Real-World Scenario
Customer Arrives: UK Discretionary Trust
Software-Only Path:
- System flags as "higher risk"
- Alert sits in dashboard
- Staff member sees alert but doesn't know what to do
- File moves forward anyway (missing CDD gap)
- AUSTRAC audit finds inadequate beneficial owner identification
- No record of who evaluated the trust or why it was accepted
- Noncompliance finding
Software + CO Path:
- System flags as "higher risk" (software does its job)
- Alert escalates to CO
- CO investigates trust structure using available sources
- CO documents findings: names trustee, identifies controllers where possible, notes gaps
- CO makes judgment: "Additional documentation required before settlement" OR "Acceptable — gaps documented"
- Evidence trail is clear: what was found, what gaps exist, who decided, why
- If AUSTRAC audits, you have defensible reasoning
Cost Reality
Software Only
Direct cost: $200–$600/month
Hidden costs:
- Staff time managing alerts (5–10 hours/week for larger agencies)
- Training for staff on what escalations mean
- Uncertainty about decisions ("Is this enough CDD?")
- Risk of AUSTRAC findings due to inadequate judgment layer
- Potential penalty exposure if gaps found
CO Service (Full Migration)
Direct cost: $500–$1000/month
Hidden benefits:
- Professional oversight reducing decision uncertainty
- Liability shifted partially to provider
- Independent evaluation support included
- Audit readiness built in
Hybrid (Software + CO)
Direct cost: $350–$700/month
Advantages:
- Preserves software investment (often locked into contract anyway)
- Adds professional judgment layer at lower cost
- Faster to deploy (no retraining staff on new software)
- Flexibility (can migrate later if needed)
AUSTRAC's Perspective
AUSTRAC does not care what you use. It cares whether you have:
- A named, qualified Compliance Officer ✓
- Documented decisions with reasoning ✓
- Evidence of judgment on escalations ✓
- Adequate resources for the person ✓
- Coverage for absences ✓
- Training and competency records ✓
Software alone meets zero of these requirements.
Software + judgment (CO) meets all of them.
Which Approach for Which Agency?
Software Only (Small risk if...)
- You have a highly experienced internal person who can take on CO role
- You are willing to invest heavily in training
- Your transaction volume and risk profile are low
- You are prepared for AUSTRAC audit risk
Managed CO Service (Fully Outsourced)
- You want complete professional oversight
- You are migrating to a new platform anyway
- You value liability sharing with provider
- You have complex transaction types (international, trusts, etc.)
Hybrid (Best of Both)
- You are locked into existing software contract
- Your software is working operationally
- You want professional judgment without platform disruption
- You want to test external CO model before full migration
Not Sure Which Approach Fits?
AMLHQ offers all three (Solo/internal, CO/managed, Hybrid/bridge). We can review your current setup and advise which model makes sense.