23 September 2026

Foreign Buyer Approvals (FIRB) and AML/CTF: Two Separate Regimes, One Client File

Foreign Buyer Approvals (FIRB) and AML/CTF: Two Separate Regimes, One Client File

Ask most real estate agents, buyers' agents or conveyancers what they check when a foreign client walks in, and you'll usually get one answer: FIRB. Has the buyer got approval, or do they need to apply for it. That question genuinely matters, and getting it wrong can unwind a purchase entirely. But it isn't the only question you're required to ask anymore, and treating it as a stand-in for your AML/CTF obligations is one of the more common and more dangerous mix-ups happening across the property sector right now.

FIRB approval and AML/CTF compliance sit next to each other on the same file, often for the same client, sometimes triggered by the same fact. But they're answering completely different questions, run by different regulators, with different consequences for getting it wrong. Understanding where they overlap and where they genuinely don't is the difference between a file that holds up under scrutiny and one that just looks thorough.

What FIRB approval is actually for

The Foreign Investment Review Board process exists to decide whether a particular acquisition of Australian property is allowed to happen at all. It's administered under the Foreign Acquisitions and Takeovers Act, with day-to-day monitoring and enforcement now largely sitting with the Australian Taxation Office. The question FIRB is asking is fundamentally about national interest and market settings, not about who the buyer is as a person.

For residential property, the monetary screening threshold is generally zero. A foreign person will typically need approval before acquiring an interest in residential land regardless of whether the property is worth $500,000 or $5 million. On top of that, foreign persons are currently barred from buying established dwellings, with that ban running from April 2025 through to the end of June 2029, subject to a narrow set of exceptions. These questions need to be resolved before a buyer signs a contract or raises their hand at auction, not afterwards.

Critically, the FIRB obligation belongs to the buyer. It's their acquisition, their application, their approval to obtain or their penalty to wear if they get it wrong. Approved purchases can come with ongoing conditions too, things like registering the acquisition on the Register of Foreign Ownership of Australian Assets, lodging annual vacancy fee returns, or notifying the ATO of a later disposal. None of that is a task for the selling agent, the buyer's agent or the conveyancer. You might help a client understand that they need it, or refer them to someone who handles the application, but the compliance obligation itself sits with the buyer.

What AML/CTF is actually for

AML/CTF is a completely different animal, aimed at a completely different question. It doesn't ask whether this purchase is allowed to happen. It asks who is really behind the money, and whether the transaction carries a risk of laundering proceeds of crime or financing terrorism, regardless of whether the buyer needed FIRB approval or not.

And here's the part that trips people up most: the AML/CTF obligation doesn't belong to the buyer. It belongs to you, the reporting entity. If you're a real estate agent, a buyer's agent, a conveyancer or a lawyer providing a designated service, you are the one who has to enrol with AUSTRAC, verify the client's identity, understand the source of their funds, screen for sanctions and politically exposed persons, and lodge a suspicious matter report if something doesn't sit right. The client doesn't apply for anything. You do the work, and you carry the liability if it's done badly.

This is precisely the opposite arrangement to FIRB, where the buyer carries the obligation and you're, at most, a helpful bystander. Two regimes, same transaction, obligations running in opposite directions. Miss that distinction and you'll end up either doing work that isn't yours to do, or skipping work that very much is.

Where the confusion actually happens

None of this would matter much if the two regimes stayed neatly separated on the file. In practice, they blur together in a handful of predictable, avoidable ways.

Treating FIRB approval as proof of AML clearance. This is the big one. A client with a valid FIRB approval letter has cleared a national interest test. They have not had their identity verified to AUSTRAC's standard, and nobody has looked at where their deposit actually came from. FIRB doesn't examine source of funds in the way AML/CTF requires, and it certainly doesn't screen for PEP status or sanctions exposure. An approved FIRB application sitting in the file tells you almost nothing about whether your AML/CTF obligations have been met.

Assuming the two regimes define "foreign" the same way. FIRB's test for a foreign person is about citizenship, residency status and control of foreign entities, built for the purpose of deciding whether an acquisition needs approval. AML/CTF's risk categories run on a different logic entirely. A client who is an Australian citizen, and therefore entirely outside FIRB's scope, can still be a foreign politically exposed person if they or a close associate hold or have recently held a prominent public position overseas. Foreign PEP status triggers automatic enhanced due diligence under AML/CTF, with no FIRB question involved at all. Conversely, a buyer who very much needs FIRB approval might present no elevated AML risk once their funds and identity check out cleanly. The two tests simply aren't measuring the same thing, and running one instead of the other leaves a genuine gap.

Mistaking the foreign ownership register for a CDD record. The Register of Foreign Ownership of Australian Assets exists for tax and national interest monitoring. It is not your customer due diligence file, it wasn't built to AUSTRAC's evidentiary standard, and referencing it in place of your own identity verification and source of funds documentation won't survive a proper review. Two different registers, two different purposes, two different sets of retention obligations.

Assuming no FIRB trigger means no AML risk. A local buyer, a citizen buyer, an exempt category purchase, none of these situations remove your AML/CTF obligations. If you're providing a designated service, you're conducting CDD regardless of whether the transaction needed FIRB approval at all. Plenty of high-risk transactions from an AML perspective never touch FIRB in the first place.

The confidentiality clash that catches people off guard

There's a sharper practical problem sitting underneath all of this, and it's one most guides don't mention at all. FIRB conversations are, by nature, open. You can discuss a client's FIRB status with them directly, ask whether they've applied, help them understand the established-dwelling restrictions, and none of that is sensitive in the way AML/CTF information can be.

A suspicious matter report is entirely different. If you form a suspicion that leads you to lodge, or even consider lodging, an SMR, you are prohibited from telling the client, or telling anyone outside your compliance function, that you've done so or that you're thinking about it. That's the tipping-off offence, and it's a criminal one, not a slap on the wrist.

The risk is that a single "foreign buyer file" ends up mixing the two. If your FIRB correspondence, your general notes on the client, and any internal flag connected to a suspicion all sit in the same accessible folder, you're one careless email or one junior staff member away from an accidental disclosure. The FIRB side of the file can be shared with the client freely. The AML/CTF suspicion side, if one exists, cannot be shared with anyone outside your compliance process, full stop. These need to be kept genuinely separate, not just labelled differently within the same folder.

What actually belongs in the file

None of this means you need two entirely disconnected systems that never talk to each other. It means being deliberate about which document answers which question, and not letting one stand in for the other.

For the FIRB side, keep a record of the buyer's FIRB status, whether an application was needed and lodged, the outcome, and any conditions attached to approval, largely so you can sanity-check that the transaction is legally able to proceed and flag it early if it isn't. This is information you can generally hold openly and discuss with the client.

For the AML/CTF side, your file needs identity verification carried out to the standard your program requires, source of funds and source of wealth information proportionate to the risk, PEP and sanctions screening results, your risk rating and the reasoning behind it, and a clearly separated, access-controlled record of anything connected to a suspicion or a report. This is the material that has to stand on its own regardless of what FIRB decided.

A few practical habits worth building in:

  • Never record "FIRB approved" as a reason for skipping or shortcutting CDD
  • Screen every client for PEP and sanctions status independently of their FIRB status, since the two tests aren't asking the same question
  • Keep your SMR-related notes and any suspicion documentation in a restricted, separate location from the general client and FIRB correspondence
  • Train your team to answer routine FIRB questions from clients normally, while understanding exactly where that conversation has to stop if an AML concern exists
  • Treat the absence of a FIRB requirement as irrelevant to whether CDD is required, because it usually is anyway

Where AML SoftServe fits in

Running two regulatory regimes cleanly through one client file is a genuinely fiddly problem, and it's exactly the kind of thing that looks fine until an AUSTRAC review or a tipping-off incident proves it wasn't. AML SoftServe builds AML/CTF programs and CDD workflows for real estate professionals, buyer's agents, conveyancers and lawyers that keep the FIRB conversation and the AML/CTF file properly separated, without turning every foreign buyer transaction into a paperwork headache for your team.

If your current process treats a FIRB approval letter as the end of the conversation rather than the start of a separate one, get in touch with AML SoftServe and we'll help you build a file that actually satisfies both regimes.


Put us to work on your compliance.

Serious compliance, softly served.

Get in touch
Foreign Buyer Approvals (FIRB) and AML/CTF: Two Separate Regimes, One Client File | AML SoftServe