CCassandra AML
Scope checkGuidesPricingSecurityAboutSign inStart free
Menu
Scope checkGuidesPricingSecurityAboutSign inStart free
All AML/CTF guides

Obligations

Customer due diligence (CDD) explained: KYC, KYB, beneficial owners and screening

8 min read · Updated 29 July 2026

Customer due diligence is the obligation your practice will feel every day: before you provide a designated service, you must know who you are dealing with — really dealing with — and you must be able to prove it. This guide breaks CDD into its working parts.

The three layers of CDD

CDD must be completed before the designated service is provided. 'We will get to it after the work starts' is a breach, not a workflow.

  • Identify: who is the client — an individual, a company, a trust, a partnership?
  • Verify: prove it against reliable, independent sources — identity documents, registers, or electronic verification
  • Understand: the purpose and nature of the relationship, and the risk it carries

Beneficial owners: the 25% rule and beyond

For companies, trusts and partnerships you must identify the beneficial owners — the real humans who ultimately own or control the client. The standard trigger is ownership or control of 25% or more, directly or through layers of entities. Control matters as much as percentage: a trustee, an appointor, or someone with veto rights can be a beneficial owner with no shares at all.

Layered structures are where professional practices earn their fee and where launderers hide. Mapping the ownership chain — entity owns entity owns entity — and calculating effective ownership is core CDD work, not an optional extra.

Screening: sanctions, PEPs and adverse media

A possible match is not a verdict. Your process must record how each possible match was resolved — confirmed or cleared, by whom and why.

  • Sanctions: check clients and beneficial owners against the DFAT consolidated list — dealing with a listed person can itself be an offence
  • PEPs: politically exposed persons are not prohibited clients, but they require senior approval and enhanced due diligence
  • Adverse media: credible negative news changes the risk picture and should be considered in the rating

Risk rating and enhanced due diligence

Every client relationship gets an ML/TF risk rating with recorded reasons. Higher-risk relationships — PEPs, complex offshore structures, cash-intensive businesses, high-risk jurisdictions — trigger enhanced due diligence: deeper verification, source-of-funds or source-of-wealth evidence, senior approval and more frequent review.

Ongoing due diligence

CDD is not one-and-done. Review cycles should follow risk — a common pattern is six-monthly for high risk, annually for medium, every two years for low — plus trigger-based reviews when circumstances change: new owners, expired documents, unusual activity or a screening hit.

Frequently asked questions

Can I do CDD manually, without electronic verification?

Yes. The framework accepts document-based verification done properly: sighting reliable identity documents, verifying entity details against registers, and keeping the evidence. Electronic verification is faster and scales better, but it is an option, not a mandate. What is not optional is the evidence: what you verified, against which source, on what date, approved by whom.

What if a client has no 25% owner?

Then control decides. Identify anyone who controls the entity through other means — trustees, appointors, senior managing officials. The file should show you worked through ownership and control, not just that no shareholding reached 25%.

When exactly must CDD be finished?

Before you provide the designated service. For recurring engagements, verification can be reused where your program allows it and the information remains current — but the decision to rely on prior verification should itself be recorded.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

Run the free scope checkCreate a free workspace

Keep reading

Obligations

AUSTRAC enrolment

Read
Obligations

Your AML/CTF program

Read
Obligations

SMRs & tipping off

Read

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser.

CCassandra AML

AML/CTF compliance workspace for Australian tax agents, accountants, lawyers, conveyancers and real estate professionals — designated services, customer due diligence, program controls and review-ready records.

Owned and operated by Cassandra Research Pty Ltd, an Australian company based in Melbourne, Victoria.

Product

Create practiceFree scope checkSign inPricingIntegrationsSecurity

AML/CTF guides

All guidesTranche 2 explainedFor tax agentsFor lawyersFor real estateAUSTRAC enrolment

Company

AboutContact

Legal

Privacy PolicyTerms of ServiceCookie NoticeAccessibility

Cassandra AML assists compliance work. It does not provide legal advice, guarantee compliance or imply AUSTRAC endorsement.

© 2026 Cassandra Research Pty Ltd, Melbourne, Australia. All rights reserved.