What reliance is and is not
Reliance is a statutory mechanism that allows a reporting entity to rely on know-your-customer information collected and verified by a third-party reporting entity or a foreign business subject to AML/CTF regulation. It can operate under an ongoing customer due diligence arrangement or case-by-case. The relying entity must satisfy the conditions in the Act and Rules.
Receiving a copy of a driver's licence from a lawyer is not reliance. The mechanism attaches to another entity's completed customer identification procedures, with the conditions met and the arrangement documented. A referral or an email of documents without the statutory framework is not compliance.
The agreement the agency needs
A written arrangement is the operating contract for reliance. The agency should verify the third party's status as a reporting entity or equivalent foreign business, keep the executed agreement and test that the promised information actually arrives for a real purchaser.
- The parties and the customers or transactions covered
- The identification procedures the third party performs and maintains
- Ongoing CDD information, including changes to KYC
- How the agency obtains the information it needs
- The term, review cycle and termination process
What the agency still owns
Reliance transfers the identification procedures, not the program. AUSTRAC's reliance guidance makes clear the relying entity still has obligations. An agency that treats reliance as 'the lawyer did it all' will fail when AUSTRAC asks for its own assessment.
- Its own ML/TF/PF risk assessment and program
- The purchaser's or seller's risk rating on its file
- Ongoing customer due diligence and monitoring
- Its own SMR, TTR and other reporting decisions
- Its own records and retention obligations
Running reliance in the sale workflow
Reliance should make the workflow faster, not looser. The agency's file should show the reliance basis, the information received, the agency's own assessment and the outcome - the same evidence any transaction file needs.
- Confirm the counterparty arrangement before the purchaser is onboarded
- Receive the identification outcome and record what was relied on
- Complete the agency's own risk assessment
- Escalate where the shared information is incomplete or inconsistent
- Record the reliance decision on the transaction file
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Can an agency rely on a lawyer's checks?
Yes, where the statutory conditions are met, typically under an ongoing arrangement or case-by-case reliance. The agency must still complete its own risk assessment and remaining obligations.
Does reliance remove the agency's CDD duties?
No. Reliance applies to customer identification procedures. The agency remains responsible for its risk assessment, ongoing CDD, monitoring, reporting and records.
What if the shared information is incomplete?
Escalate. Reliance does not authorise proceeding on incomplete or inconsistent information; the agency's own obligations and the transaction timeline still apply.
Is a referral of documents the same as reliance?
No. Reliance requires the statutory conditions and documentation. A referral without the framework does not satisfy either party's obligations.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.