Skip to main content
CCassandra AML
Scope checkGuidesPricingSecurityAboutSign inStart free
Menu
Scope checkGuidesPricingSecurityAboutSign inStart free
Guides/Lawyers

For lawyers

Entity customer due diligence for Australian law firms

5 min read · Updated 1 August 2026

When a company, trust, partnership or association receives a designated legal service, copying an extract and one director's licence is not a complete CDD process. A law firm needs to establish the legal customer's identity, the person dealing with the firm and their authority, any person on whose behalf the service is received, beneficial owners and relevant ownership or control. It must understand the relationship's purpose, screen the people required by its program, assess risk and resolve inconsistencies. The customer definition for the designated service comes first: some company or trust creation work produces a broader statutory customer set than an ordinary engagement. This guide provides a structured Australian workflow and should be applied with the current Act, Rules and firm program.

See the lawyers AML/CTF workspace

On this page

  1. Confirm the legal customer and representative
  2. Trace company ownership and control to individuals
  3. Identify trust ownership, benefit and control roles
  4. Connect CDD to purpose and risk
  5. Keep the entity file current
  6. Official sources
  7. Frequently asked questions

Confirm the legal customer and representative

Record the entity's full legal name, type, status, jurisdiction, identifiers, registered office, principal place of business and activities using reliable and independent documents or data. For a company, an ASIC or foreign-registry result can corroborate existence and officeholders. For a trust, obtain the deed and relevant amendments and identify the trust type, trustee and governing roles. Resolve differences in spelling, status, dates or identifiers rather than filing contradictory records.

Identify every individual dealing with the firm for the entity and establish authority through appropriate evidence, such as a board resolution, officeholder record, power of attorney or verified mandate. A representative is not automatically a beneficial owner. Also establish whether the entity receives the service for itself or on behalf of another person. Keep these roles explicit so screening and verification are applied to the right people.

Trace company ownership and control to individuals

Map every direct ownership layer and continue through intermediate companies, trusts, partnerships or nominees until the relevant natural persons are established. Test both ownership and control. Share percentages matter, but control can arise through voting agreements, appointment or removal powers, contractual rights, practical influence or another mechanism without a qualifying economic interest. Preserve the source and calculation supporting every material link.

A customer-supplied organisation chart is useful for orientation but is not independent verification. Reconcile it against current registers, constitutions, shareholder records, trust documents and reliable foreign sources. Where a nominee appears, establish the person for whom the interest is held and the legal basis. If the chain cannot be understood or verified, do not invent a beneficial owner; apply the escalation and inability-to-complete process in the firm's program.

Identify trust ownership, benefit and control roles

For a trust customer, identify and verify the trustee and the individuals who own or control a corporate trustee. Identify relevant settlors, appointors, protectors, guardians and other people able to direct or constrain the trustee. Record beneficiaries or a sufficiently precise class description where the nature of the trust means beneficiaries cannot all be individually named at onboarding. A discretionary beneficiary is not treated identically to a person exercising control, so preserve the role and rationale.

Use the deed, variations, resolutions, distribution information, ABR or other reliable data as appropriate. Look beyond formal titles when instructions or practical decision-making point elsewhere. An unexplained person directing the trustee, a deed inconsistent with the onboarding explanation, rapid role changes or a corporate trustee with opaque owners should trigger further inquiry, not an automatic accusation.

Connect CDD to purpose and risk

Understand why the entity wants the designated service, the nature of its business or activities, expected transaction, source of relevant funds or wealth where required, jurisdictions, delivery channel and anticipated ongoing relationship. Check politically exposed person and targeted-financial-sanctions information for the people required by the Rules and the firm's program. Simplified procedures are conditional and risk based; public, government or regulated status should be evidenced before any concession is used.

Enhanced CDD may be required when risk is high or another trigger in the Act, Rules or program applies. Proportionate measures can include more reliable identity evidence, deeper ownership corroboration, senior approval, source-of-funds or source-of-wealth evidence, transaction-purpose testing and closer monitoring. The aim is to understand and manage risk, not to reject every layered or foreign structure.

Keep the entity file current

Initial CDD is not a one-off archive. Set review triggers for changes in ownership, trustee or appointor roles, representatives, address, business activity, transaction pattern, sanctions or PEP status and risk indicators. A new designated service can also change which person is the customer or which facts need verification. Update the map and risk assessment when the firm learns information that is materially inconsistent with the existing profile.

A review-ready file includes the service classification, entity evidence, authority, ownership and control map, verification sources and dates, screening outcomes, purpose, risk decision, enhanced measures, approvals and unresolved issues. Record why evidence was reliable enough for the assessed risk. This creates a defensible reasoning trail rather than a collection of documents with no conclusion.

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

  • AUSTRAC - Initial CDD for bodies corporate and partnerships
  • AUSTRAC - Initial CDD for a trust
  • AUSTRAC - Determining ownership and control structures
  • AUSTRAC - Enhanced customer due diligence

Frequently asked questions

Is an ASIC or ABR search enough for entity CDD?

Usually not by itself. Registry data can establish or corroborate entity details, but the firm may still need to establish representative authority, the person on whose behalf the service is received, beneficial owners, control, purpose and risk. The required depth depends on the customer type, service and assessed risk.

Is the instructing director always the beneficial owner?

No. The individual may be a representative, officeholder, owner, controller or several of those things, but each role must be established. Trace ownership and control through the structure and verify authority rather than inferring beneficial ownership from who attends the meeting.

Must every beneficiary of a discretionary trust be verified?

The answer depends on the current Rules, the trust and each person's role. AUSTRAC guidance allows beneficiary classes to be described in some circumstances, while trustees, controllers and other relevant people require specific treatment. Apply the trust procedure in the firm's program rather than a blanket rule.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

Run the free scope checkCreate a free workspace

Keep reading

For lawyers

For lawyers

Read
Obligations

Beneficial ownership

Read
Obligations

CDD explained

Read

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.

CCassandra AML

AML/CTF compliance workspace for Australian tax agents, accountants, lawyers, conveyancers, real estate professionals, trust and company service providers, and precious-metals and stones dealers — with designated-service decisions and review-ready records.

Owned and operated by Cassandra Research Pty Ltd, an Australian company based in Melbourne, Victoria.

Product

Create workspaceFree scope checkSign inPricingSecurity

AML/CTF guides

All guidesTranche 2 foundationsCore obligationsTax agentsBAS agentsAccountantsLawyersConveyancersReal estateTrust & company servicesPrecious-items dealersKnowledge RSS feed

Company

AboutContactEditorial standards

Legal

Privacy PolicyTerms of ServiceCookie NoticeAccessibility

Cassandra AML assists compliance work. It does not provide legal advice, guarantee compliance or imply AUSTRAC endorsement.

© 2026 Cassandra Research Pty Ltd, Melbourne, Australia. All rights reserved.