Customer Due Diligence in Australia
A clear guide to Australian initial, ongoing, simplified and enhanced customer due diligence, including beneficial owners, PEPs, sanctions and source checks.
How this guide was researched and reviewedOn this page
Short answer
Customer due diligence means knowing who the customer is, who owns or controls them, who acts for them, why they want the service and how risky the relationship may be. The work starts before the service and continues while the relationship lasts.
The amount of information and verification should match the risk, but some information and enhanced checks are required when the law sets a trigger.
At a glance
CDD Is a Continuing Process
Identify
Know the customer, beneficial owners and people acting for or behind them.
Verify
Use reliable and independent information that is suitable for the customer and risk.
Understand
Record the nature and purpose of the relationship and assign a customer risk rating.
Keep checking
Monitor activity and update KYC information and risk when needed.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- KYC information
- Information used to know the customer, including identity, ownership, control and the nature and purpose of the relationship.
- Beneficial owner
- The individual who ultimately owns or controls a customer or on whose behalf a transaction is carried out.
- PEP
- A politically exposed person. The law sets extra checks for some PEP relationships.
- Source of funds
- Where the money or other property used for a service or transaction came from.
- Source of wealth
- How a person built their overall wealth.
Part 1
Initial CDD Before the Service
- Step 1
Identify the customer type
Work out whether the customer is an individual, sole trader, company, partnership, trust, association or government body. Each type needs different information.
- Step 2
Find the people behind the customer
Identify beneficial owners and any person acting for the customer or on whose behalf the customer acts.
- Step 3
Collect and verify KYC information
Collect the required information and verify it using reliable and independent documents or electronic data.
- Step 4
Understand the relationship
Record why the customer wants the service, how it is expected to be used and what normal activity may look like.
- Step 5
Screen and rate the risk
Complete PEP and targeted financial sanctions checks, assess the customer’s risk and decide whether enhanced controls are needed.
Initial CDD is generally completed before a designated service is provided. A lawful delayed-CDD rule may apply in limited cases, but it should not be treated as the normal process.
Part 2
Simplified, Standard and Enhanced Work
Enhanced CDD is required in listed situations, including high-risk customers, foreign PEPs, specified high-risk country links, unusual or complex activity, some nested service relationships and when an SMR is required but the service will continue.
Enhanced work should respond to the actual risk. It may include stronger identity checks, source of funds or wealth, senior approval, limits or closer monitoring.
| Approach | When it may apply | What changes |
|---|---|---|
| Simplified CDD | Only when the legal conditions are met | Some information or verification may be reduced, but the decision must be supported. |
| Risk-based CDD | The normal approach for the customer and service | Information and verification are adjusted to the customer’s ML/TF risk. |
| Enhanced CDD | High risk or another listed trigger | Targeted extra information, verification, approval and monitoring are applied. |
Part 3
Ongoing CDD and Monitoring
- Monitor for unusual transactions and behaviour, not only large amounts.
- Compare activity with the customer’s known purpose, risk and expected use.
- Review and update KYC information and the customer risk rating when needed.
- Escalate material changes, failed checks and suspicious indicators.
- Apply enhanced CDD when a trigger is found.
- Record what was reviewed, the decision made and the reason.
Part 4
Simple Worked Examples
| Situation | What to establish | Possible next step |
|---|---|---|
| Family trust buying property | Trust details, trustee, relevant beneficial owners, purpose and funding | Check source of funds and whether enhanced CDD is triggered. |
| Company with layered ownership | The ownership chain and individuals who ultimately own or control it | Use reliable corporate records and resolve any unexplained gaps. |
| Long-standing customer changes behaviour | Why the activity changed and whether KYC remains current | Update the risk rating, conduct enhanced CDD or consider an SMR. |
Part 5
Common Mistakes
- Checking an identity document but not understanding ownership or control.
- Collecting the nature and purpose as a one-word answer that cannot guide monitoring.
- Treating a database result as proof without checking reliability or matching.
- Using simplified CDD because a customer feels familiar or low risk.
- Collecting source information without checking whether it makes sense.
- Completing CDD at onboarding and never updating it.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Is checking a driver licence enough?
Not by itself. The required work depends on the customer type and risk. Ownership, control, authority, purpose, PEP and sanctions issues may also need to be addressed.
Must every address be verified?
The exact information and verification required depends on the customer type, risk and current Rules. The process should follow the applicable AUSTRAC guidance rather than a blanket rule.
When is enhanced CDD required?
It is required for high-risk customers and other listed triggers. The extra measures should be targeted and proportionate to the risk.
Can another business complete the checks?
Reliance is allowed only when the legal conditions are met. Responsibility does not disappear, so the arrangement, information access and reliability should be checked.
What happens if the customer will not provide information?
The business should follow its program, consider whether the service can lawfully proceed and assess whether the refusal creates reasonable grounds for suspicion.
Reference
Official Sources
This guide cites the following sources.
- Primary lawFederal Register of LegislationAnti-Money Laundering and Counter-Terrorism Financing Act 2006
The current Australian AML/CTF Act, including program, CDD, reporting, governance and record-keeping duties.
- Regulator guidanceAUSTRACCustomer due diligence
Current guidance on initial, ongoing, simplified and enhanced customer due diligence.
- Regulator guidanceAUSTRACYour obligations
AUSTRAC’s current overview of the duties that apply to reporting entities.
- Regulator guidanceAUSTRACSuspicious matter reports
How to identify, assess and report a suspicious matter, including submission deadlines.