Run AML day to day • AustraliaRead the New Zealand version

Customer Due Diligence in Australia

A clear guide to Australian initial, ongoing, simplified and enhanced customer due diligence, including beneficial owners, PEPs, sanctions and source checks.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. CDD Is a Continuing Process
  3. Key words explained
  4. Part 1: Initial CDD Before the Service
  5. Part 2: Simplified, Standard and Enhanced Work
  6. Part 3: Ongoing CDD and Monitoring
  7. Part 4: Simple Worked Examples
  8. Part 5: Common Mistakes
  9. Common questions
  10. Official sources

Short answer

Customer due diligence means knowing who the customer is, who owns or controls them, who acts for them, why they want the service and how risky the relationship may be. The work starts before the service and continues while the relationship lasts.

The amount of information and verification should match the risk, but some information and enhanced checks are required when the law sets a trigger.

At a glance

CDD Is a Continuing Process

  • Identify

    Know the customer, beneficial owners and people acting for or behind them.

  • Verify

    Use reliable and independent information that is suitable for the customer and risk.

  • Understand

    Record the nature and purpose of the relationship and assign a customer risk rating.

  • Keep checking

    Monitor activity and update KYC information and risk when needed.

Plain English

Key Words Explained

These words are used in the law and official guidance. This is what they mean on this page.

KYC information
Information used to know the customer, including identity, ownership, control and the nature and purpose of the relationship.
Beneficial owner
The individual who ultimately owns or controls a customer or on whose behalf a transaction is carried out.
PEP
A politically exposed person. The law sets extra checks for some PEP relationships.
Source of funds
Where the money or other property used for a service or transaction came from.
Source of wealth
How a person built their overall wealth.

Initial CDD Before the Service

  1. Step 1

    Identify the customer type

    Work out whether the customer is an individual, sole trader, company, partnership, trust, association or government body. Each type needs different information.

  2. Step 2

    Find the people behind the customer

    Identify beneficial owners and any person acting for the customer or on whose behalf the customer acts.

  3. Step 3

    Collect and verify KYC information

    Collect the required information and verify it using reliable and independent documents or electronic data.

  4. Step 4

    Understand the relationship

    Record why the customer wants the service, how it is expected to be used and what normal activity may look like.

  5. Step 5

    Screen and rate the risk

    Complete PEP and targeted financial sanctions checks, assess the customer’s risk and decide whether enhanced controls are needed.

Timing

Initial CDD is generally completed before a designated service is provided. A lawful delayed-CDD rule may apply in limited cases, but it should not be treated as the normal process.

Simplified, Standard and Enhanced Work

Enhanced CDD is required in listed situations, including high-risk customers, foreign PEPs, specified high-risk country links, unusual or complex activity, some nested service relationships and when an SMR is required but the service will continue.

Enhanced work should respond to the actual risk. It may include stronger identity checks, source of funds or wealth, senior approval, limits or closer monitoring.

How the level of CDD changes
ApproachWhen it may applyWhat changes
Simplified CDDOnly when the legal conditions are metSome information or verification may be reduced, but the decision must be supported.
Risk-based CDDThe normal approach for the customer and serviceInformation and verification are adjusted to the customer’s ML/TF risk.
Enhanced CDDHigh risk or another listed triggerTargeted extra information, verification, approval and monitoring are applied.

Ongoing CDD and Monitoring

  • Monitor for unusual transactions and behaviour, not only large amounts.
  • Compare activity with the customer’s known purpose, risk and expected use.
  • Review and update KYC information and the customer risk rating when needed.
  • Escalate material changes, failed checks and suspicious indicators.
  • Apply enhanced CDD when a trigger is found.
  • Record what was reviewed, the decision made and the reason.

Simple Worked Examples

How common CDD issues can be approached
SituationWhat to establishPossible next step
Family trust buying propertyTrust details, trustee, relevant beneficial owners, purpose and fundingCheck source of funds and whether enhanced CDD is triggered.
Company with layered ownershipThe ownership chain and individuals who ultimately own or control itUse reliable corporate records and resolve any unexplained gaps.
Long-standing customer changes behaviourWhy the activity changed and whether KYC remains currentUpdate the risk rating, conduct enhanced CDD or consider an SMR.

Common Mistakes

  • Checking an identity document but not understanding ownership or control.
  • Collecting the nature and purpose as a one-word answer that cannot guide monitoring.
  • Treating a database result as proof without checking reliability or matching.
  • Using simplified CDD because a customer feels familiar or low risk.
  • Collecting source information without checking whether it makes sense.
  • Completing CDD at onboarding and never updating it.

Common Questions

Short answers to the questions businesses ask most often.

Is checking a driver licence enough?

Not by itself. The required work depends on the customer type and risk. Ownership, control, authority, purpose, PEP and sanctions issues may also need to be addressed.

Must every address be verified?

The exact information and verification required depends on the customer type, risk and current Rules. The process should follow the applicable AUSTRAC guidance rather than a blanket rule.

When is enhanced CDD required?

It is required for high-risk customers and other listed triggers. The extra measures should be targeted and proportionate to the risk.

Can another business complete the checks?

Reliance is allowed only when the legal conditions are met. Responsibility does not disappear, so the arrangement, information access and reliability should be checked.

What happens if the customer will not provide information?

The business should follow its program, consider whether the service can lawfully proceed and assess whether the refusal creates reasonable grounds for suspicion.

Official Sources

This guide cites the following sources.

  1. Primary lawFederal Register of Legislation
    Anti-Money Laundering and Counter-Terrorism Financing Act 2006

    The current Australian AML/CTF Act, including program, CDD, reporting, governance and record-keeping duties.

  2. Regulator guidanceAUSTRAC
    Customer due diligence

    Current guidance on initial, ongoing, simplified and enhanced customer due diligence.

  3. Regulator guidanceAUSTRAC
    Your obligations

    AUSTRAC’s current overview of the duties that apply to reporting entities.

  4. Regulator guidanceAUSTRAC
    Suspicious matter reports

    How to identify, assess and report a suspicious matter, including submission deadlines.

This guide provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Need advice for your situation?

Turn the Guidance Into a Clear Next Step.

Tell us what your Australia business does and where the uncertainty sits. We will help you work out the practical AML/CTF response.

Tell us about your situation