Verify More, Store Less: Real Estate's New Trust Stack
How real estate agencies can reduce ID-document handling, protect client privacy and keep AML/CTF decisions human-led as PropTech evolves.

Verify more, store less: real estate's new trust stack
Real estate agencies do not need to choose between reliable identity checks and better privacy. The stronger direction for PropTech and RegTech is to verify what is necessary, keep only justified evidence and make human responsibility clear.
For agents, that can mean fewer identity documents moving through inboxes, downloads and shared folders. For principals, it can mean a more defensible answer to four questions: what did we collect, why did we need it, who reviewed it and what did we retain?
This article is general information. It does not determine which obligations apply to a particular business or matter and is not legal, privacy or compliance advice.
The 2026 shift: prove what matters, copy less
The privacy and AML/CTF reforms now meet inside the same client workflow.
The Office of the Australian Information Commissioner (OAIC) says real estate professionals newly brought into the AML/CTF regime also come within the Privacy Act from 1 July 2026. Its updated guidance says reporting entities should collect only personal information that is reasonably necessary for their AML/CTF obligations and broader organisational functions.
The guidance also says businesses should not retain copies of full identity documents for AML/CTF record-keeping purposes after the reforms, unless another law requires it. That does not mean keeping no evidence. It means designing the record around what the agency must be able to demonstrate, rather than treating every passport or driver licence copy as the default record.
A useful internal question is therefore not simply, “Did we see an ID?” It is:
What result, reference, decision and supporting evidence does our program require us to keep, and when should information we no longer need be deleted?
The answer belongs in the agency's approved policies and privacy practices. Frontline staff should not have to invent it one client at a time.
Why the RentTech and Digital ID developments matter
Privacy is not only a policy-document issue. The design of the collection process matters too.
In April 2026, the Privacy Commissioner found that the 2Apply rental technology platform collected some personal information excessively and by unfair means. The determination concerned IRE and 2Apply. It was not a finding against every platform or agency, but the OAIC said other RentTech providers should consider the findings and adapt their practices where needed.
Two months later, the Australian Government published results from a rental application pilot that used Digital ID instead of asking applicants to scan and share multiple identity documents. It also tested Consumer Data Right information as an alternative to sharing payslips and bank statements for rental affordability. The government reported pilot estimates of approximately AUD 150 saved per rental listing and up to 70 hours per month for participating real estate businesses.
Those figures are pilot estimates, not a promise of the result for every agency. More importantly, the contexts must stay separate: The rental pilot is not an AML/CTF rule, and it does not change an agency's sales-side AML/CTF obligations. An agency must still apply the customer due diligence process required by the law and its own program when it provides a designated service.
The pilot is useful as a design signal. It shows what can become possible when a workflow proves a needed fact without passing the largest possible bundle of raw documents between people and systems.
Useful automation still needs visible human control
RegTech is increasingly being used to organise information, identify gaps and move work to the right person. The Australian Communications and Media Authority describes RegTech as a tool that can support efficient decision-making across sectors, while emphasising that it does not replace human oversight.
That boundary is especially important when AI is involved. ASIC reported in May 2026 that AI is becoming embedded in everyday financial operations. At the same time, the OAIC's 2026 community survey found very low trust in AI companies and reported that 68% of respondents would be more likely to use digital services requiring personal information if they knew their data was handled fairly and responsibly.
For a real estate agency, the practical rule is simple: technology can prepare the evidence; people remain responsible for the decision.
Technology can assist with:
- presenting approved collection questions consistently;
- recording that a verification step occurred and linking the supporting evidence;
- identifying incomplete fields, mismatches or tasks that need attention;
- routing an exception to the right agent, principal or compliance officer;
- keeping time-stamped actions and review notes together; and
- reminding the team when a review, follow-up or deletion action is due.
People still need to:
- decide what the agency's program requires for the customer and designated service;
- interpret identity mismatches and other facts in context;
- apply the agency's risk assessment and customer due diligence policies;
- decide whether more information, enhanced due diligence or escalation is needed;
- resolve screening results and approve exceptions; and
- decide whether a reporting obligation may apply.
A neat automated result is not a substitute for professional judgement, especially when the input is incomplete or the circumstances do not fit the normal workflow.
What agents can do now
Frontline agents make the trust stack real. The most useful habits are straightforward:
- Use the approved collection path. Avoid moving client identity material into personal inboxes, local downloads or unapproved apps just because it feels faster.
- Explain the purpose. Tell the client why the information is being requested and direct them to the agency's collection notice. Do not improvise a broader reason for collecting it.
- Collect the defined information. More data is not automatically better evidence. Follow the agency's program and privacy process instead of adding “just in case” fields or copies.
- Check for mismatches. Notice differences in names, ownership information, contact details or the person giving instructions. Record the observable fact rather than labelling the client.
- Treat remote friction carefully. AUSTRAC identifies attempts to avoid KYC, documents that appear altered, unusual insistence on online-only verification and unexplained intermediaries as possible real-estate risk indicators. A red flag is a prompt to investigate, not proof of wrongdoing.
- Escalate instead of improvising. Use the agency's defined path when the normal process does not fit. The agent's job can be to spot and record the issue; they do not have to make every compliance decision alone.
- Finish the record. Capture what was checked, what exception arose, who reviewed it and the next action. Follow the agency's retention and deletion rules rather than keeping an extra copy.
For more detail on the difference between entity verification and the agency's CDD decision, read How AMLHive uses KYB to support CDD decisions.
What principals can do now
Principals and AML/CTF compliance officers own the design around the agent's work. A practical review can start with seven actions:
- Map each field to a purpose. For every identity or financial field, record the operational, AML/CTF or other legal reason for collecting it.
- Define acceptable evidence. State when the process needs a verified result, a reference, a document detail or a document copy. Record any separate legal basis for retaining a full copy.
- Set access deliberately. Limit who can view sensitive information and make access visible in the audit trail.
- Set retention and deletion rules. Cover successful matters, abandoned enquiries, duplicate uploads, expired links and exceptions. Make the action operational rather than leaving it as a sentence in the privacy policy.
- Give staff an exception path. Define who reviews an identity mismatch, an inaccessible standard document, a remote customer or an unusual ownership structure.
- Train with real workflow examples. Show staff what to collect, where to put it, what not to copy and when to escalate.
- Review the evidence trail. Sample completed and abandoned matters. Look for unnecessary copies, access that is too broad, missing rationales and unresolved exceptions.
AUSTRAC's real-estate risk-indicators article provides a useful structure for staff escalation without turning indicators into automatic conclusions.
Seven questions to ask a PropTech or RegTech vendor
A product demonstration should answer operational questions, not only show a fast happy path:
- What information does the product collect, and why is each field needed?
- Does it retain full identity documents, or can it retain an appropriate verification result, reference and decision record instead?
- Where is the information stored and processed, which service providers can receive it, and can the vendor support the agency's disclosure obligations?
- Which users can see sensitive information, and does the product keep a usable access and decision history?
- Where is human approval required, especially for risk ratings, screening matches, exceptions and reporting decisions?
- How can the agency apply retention, deletion, correction and export requirements without relying on a support ticket for every record?
- What happens when verification is unavailable, data conflicts, an AI extraction is wrong or an integration fails?
The best answer is not always “we automate everything.” It is a clear description of the input, the result, the person responsible, the evidence retained and the failure path.
Where AMLHive fits
AMLHive helps Australian real estate agencies organise customer due diligence, screening, assigned actions, escalation and evidence around their documented AML/CTF program. Its guided workflow and audit support can reduce scattered administration while keeping review and approval visible.
AMLHive does not provide legal advice or determine the legal outcome for a customer. It does not automatically lodge reports with AUSTRAC. The agency retains its AML/CTF decisions and legal responsibility. The product does not currently claim an integration with the Australian Government Digital ID System or Consumer Data Right; those developments are discussed here as property-industry signals.
Explore AMLHive's current product capabilities and security approach, or start a 14-day free trial to see how a structured workflow can support your team.
Sources
- OAIC - Updated AML/CTF privacy guidance (published 27 February 2026; accessed 16 July 2026)
- OAIC - RentTech platforms must stop unfair and excessive personal information collection (published 22 April 2026; accessed 16 July 2026)
- Australian Government Digital ID System - Digital ID renters' pilot (published 26 June 2026; accessed 16 July 2026)
- ACMA - Research on emerging technologies (updated 21 April 2026; accessed 16 July 2026)
- ASIC - Innovation in financial technology and RegTech (published 21 May 2026; accessed 16 July 2026)
- OAIC - Australian Community Attitudes to Privacy Survey release (published 28 May 2026; accessed 16 July 2026)
- AUSTRAC - Risk insights and indicators for the real-estate sector (accessed 16 July 2026)
This article is general information only and is not legal, financial, privacy or compliance advice. Check current AUSTRAC and OAIC guidance and obtain independent advice for your agency's circumstances.
Disclaimer:This article is general information only and is not legal, financial or compliance advice. Always consider your agency's specific circumstances and seek professional advice where needed.