Obligations
Ongoing CDD reviews and customer trigger events in Australia
Ongoing customer due diligence keeps the customer profile, risk assessment and KYC information aligned with what the reporting entity learns while providing designated services. It is more than an annual expiry-date check. AUSTRAC expects monitoring of customers and, for a business relationship, risk-based review and updating of information, with reverification where appropriate. Strong programs combine periodic review with event-driven triggers from people, matters, transactions, systems and external information. A trigger starts an assessment; it does not automatically prove suspicion or require the same response in every case. This guide provides an operational trigger catalogue and evidence workflow distinct from initial CDD. Specific item 54-only exemptions may apply where all conditions are met, but mixed-service businesses should not assume those settings extend to them.
Step-by-step process
Detect the event
Capture periodic and real-time changes across customer, service, payment and external data.
Review the customer
Assess the event in the context of identity, ownership, purpose, activity and existing risk.
Update and escalate
Refresh or reverify information, apply enhanced controls and protect reporting decisions.
Close the loop
Record evidence and rationale, set the next review and quality-test closure outcomes.
Define what ongoing CDD must keep current
The relationship record should support a current understanding of customer identity, representatives and authority, beneficial ownership and control, nature and purpose, expected activity, relevant PEP or sanctions exposure and ML/TF/PF risk. Ongoing monitoring compares actual services and behaviour with that understanding. Where information changes, becomes doubtful or is no longer reliable, the reporting entity should review and update it and reverify appropriate matters under its policies and current requirements.
Set review depth and frequency by risk. A low-risk stable customer may need less frequent periodic attention than a complex, high-risk or rapidly changing relationship, but every customer remains subject to relevant monitoring while designated services are provided. Calendar reviews provide a backstop; event triggers should open a review sooner. Define what constitutes a business relationship and when it ends so monitoring and record-retention clocks are not left ambiguous.
Capture identity, ownership and authority triggers
Trigger review when a customer changes legal name, address, legal form, ownership, controllers, directors, trustees, partners, beneficiaries, representatives or authorised signatories. Also trigger when a registry result conflicts with the file, documents expire where validity matters, correspondence is returned, a representative's authority is challenged, or the business doubts the truth or adequacy of previous KYC information. Layering or a new nominee should prompt ownership analysis rather than a simple profile edit.
The response should identify what changed, who authorised it, why it changed, the effective date and whether the change affects customer status, beneficial ownership, PEP or sanctions screening, service scope and risk. Reverify new people and material facts where appropriate. Preserve both the previous and updated structure so historic transactions remain intelligible. A minor administrative change can be closed with brief evidence; a control change through an opaque jurisdiction may require enhanced CDD and senior approval.
Detect service, payment and behaviour triggers
Operational triggers include a new designated service, changed purpose, unexpectedly large or complex transaction, rapid formation and disposal, unexplained urgency, early termination, unusual refunds, payment from or to an unrelated third party, multiple linked payments, cash or virtual-asset use, inconsistent settlement instructions, movement through client accounts and activity outside the expected profile. Profession-specific monitoring is essential because a suspicious pattern in property settlement differs from one in company formation or precious-item sales.
Configure systems to capture enough structured data for rules and review, but preserve professional observations. Frontline staff may see reluctance to identify owners, changing explanations, unusual intermediaries or documents that do not fit the transaction. Give them a secure escalation path and protect reporting confidentiality. A threshold or alert should initiate analysis, not a mechanical conclusion. Review the customer's complete activity and connected parties before clearing or escalating.
Use external and risk-change triggers
New PEP information, a sanctions-list update, credible adverse information, law-enforcement contact, high-risk jurisdiction exposure, a changed national or sector risk assessment, or a relevant typology can require review. A change in the reporting entity's own risk assessment, appetite, service delivery or controls may also mean existing customers need reassessment. Do not rely on periodic screening if list or ownership changes can create immediate legal exposure.
Decide the response using the customer's context and applicable policy. Actions can include updating KYC, reverification, remapping ownership, obtaining source of funds or wealth, enhanced monitoring, senior approval, restricting a service, exiting and considering an SMR. If suspicion is formed, follow the statutory reporting timeframe and tipping-off controls. Continuing the relationship after an SMR can require enhanced due diligence; an SMR does not end the need to manage the customer safely.
Operate a closed-loop review workflow
Management information should distinguish generated, open, overdue, cleared, escalated and repeatedly triggered cases. Measure alert quality, review timeliness, data gaps and the effect of outcomes, not simply closure volume. Where a trigger repeatedly closes without useful analysis, tune the rule or improve data. Where expected triggers never appear, test whether source systems are feeding the monitoring process at all.
- Create periodic and event triggers covering identity, authority, ownership, service, payment, behaviour, jurisdiction, PEP, sanctions and external intelligence.
- Route each trigger to a risk-appropriate owner with service holds or deadlines where necessary.
- Review the complete customer profile and connected activity, not only the field that changed.
- Update and reverify relevant KYC, reassess risk and apply enhanced measures or approvals when required.
- Consider reporting through a protected process and prevent customer communications from revealing an SMR decision.
- Record outcome, rationale, evidence, reviewer and next-review date, then quality-test closures and overdue cases.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Does every trigger mean the customer is suspicious?
No. A trigger indicates that information or activity requires review. The outcome may be a documented legitimate explanation, updated KYC, higher risk, enhanced CDD or suspicion. Staff should assess evidence without treating a single event as automatic guilt or automatically clearing it.
Are annual customer reviews enough for ongoing CDD?
Not by themselves. Periodic review is a useful backstop, with frequency based on risk, but material identity, ownership, activity, sanctions or service changes require event-driven review when they occur. Higher-risk relationships may also require more frequent monitoring.
When should identity information be reverified?
Reverify when appropriate under current requirements and policy, including where identity information is doubtful, inconsistent, materially changed or no longer reliable. Do not require every unchanged document to be recollected mechanically; record the risk-based reason and evidence for the action taken.
What happens if a relationship continues after an SMR?
The reporting entity must continue to manage the risk and comply with tipping-off restrictions. Current AUSTRAC guidance can require enhanced CDD in connection with continuing the relationship. Apply additional monitoring, approvals or restrictions as appropriate without revealing the report to the customer.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.