Prepared with reference to AUSTRAC guidance current as at June 2026. Requirements are evolving — seek legal or compliance advice before relying on this document for specific decisions.
Contents
1. What is CDD and when does it apply?
Customer Due Diligence (CDD) is the process of identifying and verifying who you are providing a designated service to, understanding the purpose of the engagement, and assessing the associated ML/TF risk. It is a legally enforceable obligation under the AML/CTF Act 2006.
CDD applies when you provide any of the following designated services:
- Assisting with the sale, purchase or transfer of real estate (item 1)
- Assisting with the sale, purchase or transfer of a body corporate or legal arrangement (item 2)
- Receiving, holding, controlling or managing a person's money, accounts, securities or property (item 3)
- Assisting with equity or debt financing transactions (item 4)
- Selling or transferring a shelf company (item 5)
- Assisting with the creation or restructuring of a company, trust, partnership or other legal arrangement (item 6)
- Acting as, or arranging for another person to act as, a director, trustee, secretary, partner or similar (item 7)
- Acting as, or arranging for another person to act as, a nominee shareholder (item 8)
- Providing a registered office or principal place of business address (item 9)
CDD does not apply to:
- Tax return preparation and BAS services (not designated services)
- Pre-commencement clients (existing clients before 1 July 2026), unless a trigger event occurs
- Clients to whom you provide only non-designated services
2. Identity verification
Identity verification must be completed for the customer, any person acting on their behalf, and any person on whose behalf the designated service is received. The required information varies by entity type.
Verifying individuals
| Information to collect | How to verify |
|---|---|
| Full legal name | Government-issued photo ID (driver's licence or passport) |
| Date of birth | Government-issued photo ID |
| Residential address | Utility bill, bank statement (not older than 3 months), or government record |
| Electronic verification | Document Verification Service (DVS) via Firm Verify / BGLiD — checks against government databases in real time |
For minors (under 18)
Where a minor is a beneficiary or party to a designated service, verification is still required. Acceptable documents include birth certificate, Medicare card, or student ID where a driver's licence or passport is not available.
Verifying companies
| Information to collect | How to verify |
|---|---|
| Full legal name | ASIC company search |
| ACN / ABN | ASIC and ABN Lookup |
| Registered address | ASIC company search |
| Directors | ASIC company search — verify identity of all current directors as individuals (see above) |
| Beneficial owners | Shareholders register — identify anyone with 25%+ ownership or effective control (see Section 3) |
| Type and status | ASIC search — confirm company type (Pty Ltd, Ltd etc.) and registration status |
Verifying trusts
A trust is a legal arrangement, not a separate legal entity. AUSTRAC requires you to identify and verify the key parties to the trust — not just the trustee who engages you.
| Party | Required | Notes |
|---|---|---|
| Trustee(s) | ✓ | Verify as an individual or company. For a corporate trustee, also verify directors and beneficial owners of the trustee company. |
| Settlor | ◐ |
Verification is required if the settlor contributed a material
amount (generally ≥ $10,000) or retains ongoing control or
influence over the trust. Where the settlor contributed only a nominal sum (e.g. $10–$100) and has no ongoing role, a documented risk-based decision to exclude is acceptable. Most Australian discretionary trusts are established with a nominal settlement sum for this reason. If in doubt, verify. Document your reasoning either way. |
| Named beneficiaries | ✓ | Individually identified and verified. A refusal to provide ID for a named beneficiary must be escalated to the Compliance Officer. |
| Class beneficiaries | ◐ | Risk-based approach. Where the class is small and identifiable, individual verification may be required. Where the class is broad (e.g. "all children of the settlor"), a documented risk assessment is generally sufficient unless distributions have been made or are proposed to specific individuals. |
| Appointor / protector | ◐ | Where present, identify and verify. Appointors hold power to remove and replace trustees — they can exercise effective control regardless of formal ownership. |
| Trust deed | ✓ | Obtain and review the trust deed. If the client cannot produce the deed, treat this as a red flag and escalate. |
| Trust ABN / name | ✓ | Verify via ABN Lookup. |
◐ = risk-based, documented approach required ✓ = always required
3. Beneficial ownership
A beneficial owner is any individual who ultimately owns or exercises effective control over a customer. Identifying beneficial owners is mandatory for companies, trusts, and other legal arrangements — not just the entity that engages you directly.
| Who qualifies | Definition |
|---|---|
| 25%+ shareholder | Any individual who directly or indirectly holds 25% or more of the shares or voting rights in a company. |
| Effective controller | Any individual who exercises control through other means — including veto rights, shareholder agreements, right to appoint/remove directors, or de facto control — regardless of their equity stake. AUSTRAC focuses on actual control, not just formal ownership percentage. |
| Trust settlor |
A beneficial owner if they contributed a material amount
to the trust (generally ≥ $10,000) or retain ongoing control
or influence over its affairs. A nominal settlor — one who contributed only a small settlement sum (e.g. $10–$100) and has no ongoing role — does not meet the beneficial ownership threshold. Document your assessment. |
| Trust beneficiary | Named beneficiaries. Class beneficiaries are assessed on a risk basis. |
| Appointor | Holds power to remove and replace trustees — treated as exercising effective control. |
Layered structures
When a company is owned by another company, you must look through each layer to identify the ultimate individual beneficial owners. There is no maximum depth — continue until you reach a natural person or a listed public company (which has reduced beneficial ownership requirements).
4. Risk assessment
Every client must be assigned an ML/TF risk rating before you provide a designated service. The risk rating determines the level of CDD required and the intensity of ongoing monitoring. Your AML/CTF program must document your risk rating methodology.
Risk factors to consider
| Factor | Lower risk indicators | Higher risk indicators |
|---|---|---|
| Customer type | Australian resident individual, established local business, regulated entity (bank, AFSL holder) | Foreign nationals, PEPs, cash-intensive businesses, complex layered structures |
| Country of origin | Australia, New Zealand, UK, Canada, other FATF-compliant countries | FATF grey or black list countries, countries with known corruption, secrecy jurisdictions |
| Service type | Registered office for a long-standing client entity, routine director appointment | Large one-off property transaction, complex offshore trust restructure, nominee arrangements |
| Transaction profile | Consistent with known business, industry benchmarks, disclosed income | Unexplained large transactions, structuring patterns, offshore flows |
| Source of funds | Documented salary, known business revenue, inheritance with records | Cannot be explained, inconsistent with lifestyle, offshore without documentation |
Low risk clients — Simplified CDD
Simplified CDD applies to customers your risk assessment identifies as low risk. Most Australian resident individuals and established local businesses will fall here.
| Individual — Simplified CDD | Company / Trust — Simplified CDD |
|---|---|
|
|
High risk clients — Standard to Enhanced CDD
Clients assessed as medium or high risk require additional steps beyond simplified CDD.
| Standard CDD — medium risk | Enhanced CDD — high risk |
|---|---|
|
|
Politically Exposed Persons (PEPs)
The AML/CTF Rules 2025 define three PEP categories, each with different CDD obligations:
- Foreign PEP — a person who holds or has held a prominent public position in the government of a foreign country
- Domestic PEP — a person who holds or has held a prominent public position in an Australian government body
- International organisation PEP — a person who holds or has held a senior position in an international organisation (e.g. UN, IMF, World Bank)
In all three categories, immediate family members and known close associates of the PEP are also treated as PEPs for CDD purposes.
| PEP type | Required CDD level | Notes |
|---|---|---|
| Foreign PEP | Enhanced CDD — mandatory | Automatically treated as high ML/TF risk under the AML/CTF Act. Senior manager approval required before proceeding. |
| Domestic PEP | Risk-based — Standard CDD minimum; ECDD likely for higher-risk cases | Not automatically high risk, but requires documented risk assessment. Standard CDD is the floor. Where the risk assessment identifies elevated risk, ECDD elements apply — including deeper source of wealth and source of funds analysis, and potentially senior manager approval. Document your reasoning either way. |
| Former PEP | Risk-based | PEP status does not automatically end when the person leaves public office. Apply a risk-based judgment and document it. |
| Close associate / family | Risk-based | 'Close associate' is defined broadly and can include persons with a close personal or business relationship. When in doubt, apply a conservative approach and document your reasoning. |
5. Enhanced Due Diligence (ECDD)
ECDD applies when you assess a customer as high ML/TF risk, or when specific circumstances require it regardless of the overall risk rating.
When ECDD is mandatory
| Circumstance | Why it's high risk |
|---|---|
| Foreign PEP | Automatically classified as high risk by the AML/CTF Act |
| High-risk jurisdiction | FATF grey/black list countries, countries with known deficient AML/CTF regimes or high corruption |
| Complex or unusual structure | Layered corporate or trust structure with no apparent commercial rationale |
| Unexplained wealth or transactions | Asset base or transaction profile inconsistent with known income or business activity |
| High-risk industry | Cash-intensive businesses, construction, property development in high-risk jurisdictions, foreign government contracting |
| Overall high-risk rating | Your risk assessment concludes the customer presents high ML/TF risk for any reason |
What ECDD involves
|
1
|
All standard CDD steps first Complete identity verification, beneficial ownership, PEP/sanctions screening, and risk assessment as per standard CDD. |
|
2
|
Senior manager approval Obtain explicit approval from a senior manager before proceeding with the designated service. This approval must be documented. |
|
3
|
Enhanced source of wealth documentation Collect and document evidence of the source of the client's wealth — not just the source of funds for the specific transaction. This may include salary records, business financials, inheritance documentation, or property sale records. |
|
4
|
Adverse media screening Screen the client and key associated individuals against adverse media sources. Firm Verify Tier 2 and above include adverse media screening via BGLiD. |
|
5
|
Increased monitoring frequency High-risk clients require more frequent review of their transactions and relationship profile throughout the engagement. |
6. Ongoing monitoring
CDD is not a one-time event at onboarding. From 1 July 2026, ongoing monitoring obligations apply to all clients to whom you provide designated services — including pre-commencement clients.
| Activity | What it means |
|---|---|
| Keep information current | Update client records when you become aware of changes — director appointments, trustee changes, new beneficial owners, address changes, or changes in business activity. |
| Monitor for red flags | Be alert to transactions, instructions, or behaviour inconsistent with your knowledge of the client. Trust your professional judgment — if something doesn't make sense, ask. |
| Review risk ratings | Reassess the client's ML/TF risk rating when circumstances change. A client who enters a new business line, acquires overseas assets, or comes into association with a PEP may need their risk rating elevated. |
| Periodic reviews | Your AML/CTF program should set a review frequency for each risk tier. Low risk clients may be reviewed every 2–3 years; high risk clients may require annual or more frequent review. Annual re-verification of identity documents is not required unless circumstances change or your risk assessment warrants it. |
| Trigger-event reviews |
Certain events automatically trigger a CDD review: an SMR
obligation arises, a significant change in the nature or
purpose of the relationship occurs, or the client's ML/TF
risk rating changes to medium or high. Pre-commencement clients: The full ongoing CDD regime does not apply retrospectively. For pre-commencement clients (those in an ongoing business relationship with you before 1 July 2026), you are required to monitor for changes that could raise their ML/TF risk to medium or high, or that could trigger an SMR obligation. If such a change occurs, full initial and ongoing CDD must then be applied. This is a narrower obligation than applies to new clients. |
| Record keeping | All CDD records — including initial verification, risk assessments, updates, and the reasoning behind decisions — must be retained for 7 years from when the business relationship ends (or from when an occasional transaction is completed). At the end of that 7-year period, retained information must be deleted. |
7. Example scenarios
Scenario 1
New client onboarding — sole trader setting up a Pty Ltd
Situation: A new client asks you to set up a Pty Ltd company for their consulting business and act as registered office.
CDD steps required:
- Verify the client as an individual: name, DOB, residential address, government-issued ID.
- Screen for PEP status and targeted financial sanctions.
- Assess ML/TF risk: Australian resident, clean professional background, no adverse indicators — likely low risk.
- Apply Simplified CDD: one government ID, address confirmed, no PEP or sanctions hits.
- Document the purpose of the engagement: company formation for legitimate consulting services.
- Once the company is formed, record its details (ACN, registered address, directors) in the client file.
- You are now providing a registered office service — ongoing monitoring applies from this point.
Scenario 2
Offshore ownership — Australian company with a foreign parent
Situation: A long-standing client, an Australian Pty Ltd, asks you to help set up a new subsidiary. You discover the Australian company is 60% owned by a company incorporated in a FATF grey-list country.
Risk indicators present:
- Foreign ownership from a high-risk jurisdiction
- Layered corporate structure (foreign parent → Australian Pty Ltd → new subsidiary)
- Beneficial owner through the foreign parent is unknown to you
CDD steps required:
- Look through the corporate structure to identify the ultimate individual beneficial owners behind the foreign parent company.
- Verify those individuals: name, DOB, address, and passport or national ID.
- Screen all identified individuals for PEP status and sanctions.
- Assess ML/TF risk: high-risk jurisdiction and layered structure elevate this to high risk — apply Enhanced CDD.
- Obtain senior manager approval before proceeding.
- Collect source of wealth documentation for the beneficial owners.
- Run adverse media screening.
- Document all steps and decisions. If the beneficial owners cannot be identified or refuse to engage, decline the engagement and consider whether an SMR is warranted.
Scenario 3
Complex trust structure — discretionary family trust with offshore elements
Situation: A new client asks you to review and update a discretionary family trust deed. The trust has a corporate trustee, a settlor who lives overseas, and a list of named and class beneficiaries.
CDD steps required:
- Obtain and review the trust deed. If it cannot be produced, treat this as a red flag.
- Verify the corporate trustee as a company: ASIC search, ACN, registered address.
- Verify all directors of the corporate trustee as individuals.
- Identify and verify the beneficial owners of the corporate trustee (25%+ shareholders).
- Assess whether the settlor requires verification: if the settlor contributed a material sum or retains ongoing control, verify — collect name, DOB, address, and a certified government-issued ID if overseas. If they contributed only a nominal settlement sum and have no ongoing role, document your risk-based decision to exclude.
- Verify all named beneficiaries individually.
- For class beneficiaries: document your risk-based approach — if the class is identifiable and small, verify individually; if broad, document your assessment.
- Screen all identified parties for PEP status and sanctions — the overseas settlor may warrant closer scrutiny if verified.
- Determine whether the deed update constitutes a structural change (restructure → designated service) or administrative amendment. Document your reasoning.
Scenario 4
SMSF clients — new fund with corporate trustee
Situation: An existing tax client asks you to set up a new SMSF with a new corporate trustee. The fund will have two individual members.
CDD steps required:
- The SMSF is the customer — it is a trust and a designated service (creation of a legal arrangement).
- Verify the corporate trustee as a company: ASIC search, ACN, registered address.
- Verify both directors of the corporate trustee as individuals (name, DOB, address, photo ID). If these are your existing clients, a prior verified identity record can be linked — you do not need to re-verify if the verification is current and adequate.
- Verify the members/beneficiaries: in an SMSF, members are also the beneficial owners — verify each member as an individual.
- The settlor in an SMSF is typically a nominal party who contributes a small initial settlement sum (e.g. $10–$100) and has no ongoing role. Verify them only if they contributed a material amount or retain ongoing involvement; otherwise document your risk-based decision to exclude.
- Screen all parties for PEP status and sanctions.
- Assess ML/TF risk: typically low risk for a straightforward domestic SMSF with verified Australian resident members.
- Document the purpose: retirement savings fund for the two members.
- Note: SMSF administration and annual tax compliance are not designated services. Only the creation/restructuring events trigger CDD.