Centralising AML compliance may look efficient for franchise groups, but it can also concentrate risk. The structure you choose matters.
Real estate franchise groups have taken a familiar approach to Tranche 2: build one AML/CTF framework at head office, roll it out across the network and treat the compliance problem as solved.
I understand the appeal. It creates consistency, reduces duplication and gives franchisees access to compliance expertise they may not have in-house.
But there is a much bigger question franchise groups should be asking: where does the AML risk actually sit?
Under the new regime, AML/CTF obligations attach to the entity providing a designated service. In real estate, that includes brokering the sale, purchase or transfer of real estate.
That distinction matters enormously in a franchise model.
If head office does not itself provide a designated service, it does not become a reporting entity simply because its brand appears above the door. Depending on how the network operates, it may instead be the individual franchisee entities providing those services and therefore carrying AML/CTF obligations.
Franchise groups then have an important structural decision to make.
AUSTRAC allows eligible franchisors and franchisees to form a reporting group and nominate a lead entity. That can provide genuine benefits. Functions can be centralised, resources shared and AML/CTF policies coordinated across the network.
But centralisation also brings responsibility with it.
The lead entity is responsible for group-wide AML/CTF compliance. It must oversee the group's money laundering and terrorism financing risks, maintain the group-wide risk assessment and policies, and take reasonable steps to ensure members are complying with their obligations.
Most importantly, if a reporting entity within the group breaches certain civil penalty provisions, both the member and the lead entity can be considered to have breached the requirement.
For a franchise network, that should change the conversation.
The question is no longer simply, "How can we make AML compliance easier for our franchisees?" It is also, "How much compliance risk does head office want to assume across the network?"
Imagine a network of 50 independently operated offices. Forty-nine have strong processes, trained staff and disciplined customer due diligence. One does not.
If head office has chosen to become the lead entity of a reporting group, that poorly managed office is no longer simply a local compliance problem. The structure creates potential exposure for the lead entity as well.
That is why I believe many franchise groups should seriously consider a centrally supported but locally accountable model.
Head office can still do much of the heavy lifting. It can develop the baseline framework, provide technology, training and procedures, establish minimum standards and give franchisees access to specialist AML expertise.
But each reporting entity can remain responsible for its own AML/CTF program, risk assessment, AUSTRAC enrolment and compliance.
There is another important advantage to that approach: risk profiles are local.
A CBD agency regularly handling high-value transactions involving offshore customers does not necessarily face the same risks as a regional agency predominantly dealing with long-standing local clients.
I saw the same principle during my time working with banks. Enterprise-wide AML frameworks were essential for consistency, but effective compliance still had to reflect what was happening where the customer and transaction actually sat. Risk management becomes much weaker when the document describes the organisation in theory rather than the business being conducted in practice.
AUSTRAC's own reporting-group guidance recognises this. A lead entity's AML/CTF program must take account of the nature, size and complexity of the reporting entities within its group. A franchisor cannot simply produce one generic document and assume that every office is covered.
There is no universally correct structure. Some franchise networks will have the governance, systems and oversight to make a reporting group highly effective. For others, making each franchisee accountable for its own compliance while providing strong central support may create a cleaner separation of risk.
What matters is that the decision is deliberate.
For franchise heads, I would be asking three questions now.
Who in our network actually provides the designated service? Who is legally accountable when something goes wrong? And have we structured our AML framework so that one poorly managed office cannot unnecessarily expose the broader network?
Those questions are far more important than whether every franchisee has been given the same AML template.
Tranche 2 compliance is not a document exercise. It is a risk architecture exercise.
The franchise groups that understand that distinction will be far better placed when AUSTRAC starts examining not just whether a program exists, but whether the structure behind it actually works.