The three layers of CDD
Initial CDD is ordinarily completed before the designated service is provided. Use delayed CDD only where the Act, Rules and documented policies permit it, and apply the separate pre-commencement, simplified and deemed-compliance provisions where relevant. Record the provision relied on and how every condition was satisfied.
- Identify: who is the client — an individual, a company, a trust, a partnership?
- Verify: prove it against reliable, independent sources — identity documents, registers, or electronic verification
- Understand: the purpose and nature of the relationship, and the risk it carries
Beneficial owners: the 25% rule and beyond
For companies, trusts and partnerships you must identify the beneficial owners — the real humans who ultimately own or control the client. The standard trigger is ownership or control of 25% or more, directly or through layers of entities. Control matters as much as percentage: a trustee, an appointor, or someone with veto rights can be a beneficial owner with no shares at all.
Layered structures are where professional practices earn their fee and where launderers hide. Mapping the ownership chain — entity owns entity owns entity — and calculating effective ownership is core CDD work, not an optional extra.
Screening: sanctions, PEPs and adverse media
A possible match is not a verdict. Your process must record how each possible match was resolved — confirmed or cleared, by whom and why.
- Sanctions: check clients and beneficial owners against the DFAT consolidated list — dealing with a listed person can itself be an offence
- PEPs: foreign PEPs trigger enhanced CDD and senior approval; domestic and international-organisation PEPs trigger those additional PEP measures when the customer is high ML/TF risk
- Adverse media: credible negative news changes the risk picture and should be considered in the rating
Risk rating and enhanced due diligence
Every client relationship gets an ML/TF risk rating with recorded reasons. Enhanced CDD applies to high-risk customers and other prescribed triggers, including foreign PEPs, certain high-risk jurisdictions, specified unusual transactions and an SMR obligation where service will continue. Measures must respond to the actual risk and can include deeper verification, source-of-funds or source-of-wealth evidence, senior approval and closer monitoring.
Ongoing due diligence
CDD is not one-and-done. Set risk-based periodic-review frequencies in the AML/CTF program and review customers following material events, changes or doubts about KYC information. AUSTRAC does not prescribe one universal high-, medium- and low-risk calendar; the file should explain why its frequency and trigger response are proportionate.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Can I do CDD manually, without electronic verification?
Yes. The framework accepts document-based verification done properly: sighting reliable identity documents, verifying entity details against registers, and keeping the evidence. Electronic verification is faster and scales better, but it is an option, not a mandate. What is not optional is the evidence: what you verified, against which source, on what date, approved by whom.
What if a client has no 25% owner?
First test control through other means after working through ownership. If no beneficial owner exists, or none can be established after the required steps, apply Rules 6–8 by establishing the CEO or equivalent. Do not label that fallback person a beneficial owner unless the ownership-or-control definition is independently satisfied, and retain the working behind the conclusion.
When exactly must CDD be finished?
Initial CDD is ordinarily finished before the designated service. Use delayed CDD only where the Act, Rules and documented policies permit it, and separately apply any pre-commencement, simplified or deemed-compliance provisions. For recurring engagements, prior verification can be used where the governing rules and program allow it and the information remains reliable; record the basis for reliance.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.