Skip to main content
CCassandra AML
Scope checkGuidesPricingSecurityAboutSign inStart free
Menu
Scope checkGuidesPricingSecurityAboutSign inStart free
Guides/BAS agents

For BAS agents

Small-business KYB and entity CDD: a guide for BAS agents

5 min read · Updated 1 August 2026

Know your business, or KYB, is a useful industry phrase, but the legal task is customer due diligence under the AML/CTF framework. A BAS practice that provides a designated service must first establish who receives that service. It then applies the current requirements and its risk-based program to the entity, anyone acting for it, relevant beneficial owners and the purpose of the relationship. A valid ABN is useful evidence, not a complete result. Small entities can have layered owners, informal authority and trust relationships that require careful mapping, while a proportionate workflow can still avoid asking every low-risk customer for the same document pack.

See the bas agents AML/CTF workspace

On this page

  1. Establish the customer before selecting checks
  2. Verify the entity and the person giving instructions
  3. Understand ownership, control and beneficial owners
  4. Understand purpose and assess the actual risk
  5. Keep CDD current through event-based reviews
  6. Official sources
  7. Frequently asked questions

Establish the customer before selecting checks

Start with the designated service and the legal person receiving it. Determine whether the customer is an individual, sole trader, body corporate, partnership, trust or another arrangement. If an entity or trustee acts for another person, identify the represented person where required. Record the conclusion and do not rely only on the trading name, ABN holder or person who sends instructions.

Service-specific rules matter. When the practice creates a company, the customer population includes the instructing person and the proposed directors and beneficial owners. When it creates an express trust, it includes the instructing person and proposed trustee, settlor and beneficiaries. This may require CDD on people who were not customers of the practice's earlier bookkeeping engagement.

Verify the entity and the person giving instructions

Collect the legal name, legal form, registration or establishment information, principal place of business and other details required for the customer type and risk. Verify them using reliable and independent sources permitted by the program. ABR, ASIC and governing documents can provide different parts of the evidence. Reconcile inconsistencies rather than accepting the first registry match.

Identify the representative and establish their authority. Depending on the entity, evidence might include officeholder data, a board or trustee resolution, a partnership authority, an employment role, an agency instrument or confirmation through an independently verified channel. Record both identity and authority so the file shows why that person could bind or instruct the customer.

Understand ownership, control and beneficial owners

Map direct and indirect owners and the individuals who ultimately own or control the customer under the current legal test. Follow company layers instead of stopping at a corporate shareholder, and consider control through voting, appointments or other means. Keep a simple structure chart, the source data, any calculations and the reasoning for each beneficial-owner conclusion.

For a trust, identify and collect the information required for its type and roles, which may include the trustee, settlor, beneficiaries or class, appointor and other controllers. For partnerships, understand partners and control. If no individual can be identified through ownership or other control, apply the current fallback or senior-managing-official requirements correctly rather than choosing the most convenient contact.

Understand purpose and assess the actual risk

Ask why the customer needs the designated service, how the entity earns and uses funds, expected transaction types and values, relevant jurisdictions, delivery method and the intended duration of the relationship. Compare this information with the proposed formation, transaction, payment authority or address service. The depth of corroboration should respond to risk and inconsistencies, not merely the customer's size.

Screen the relevant people for politically exposed person status and targeted financial sanctions as required, and apply the program's customer, service, delivery-channel and geographic risk factors. Escalate complex unexplained ownership, unusual nominees, unverifiable authority, mismatched business activity or jurisdictions without a credible purpose. Risk indicators call for inquiry and possibly enhanced CDD; they are not a substitute for an evidence-based decision.

Keep CDD current through event-based reviews

Retain collected information, verification sources and dates, representative authority, ownership and control analysis, screening results, purpose, risk rating, rationale, approvals and enhanced checks. Make the evidence accessible to the staff delivering the service while preserving confidentiality and access controls. A folder of identity documents without a customer conclusion is not an auditable KYB record.

Set review triggers for new owners, directors, trustees, controllers or representatives; changes in legal name, address or jurisdiction; expanded bank authority; a new designated service; unexpected transaction patterns; or doubts about earlier information. Ongoing CDD and monitoring should keep the profile reliable and identify when enhanced CDD, re-verification, service restriction or a confidential reporting decision is required.

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

  • AUSTRAC — Overview of initial customer due diligence
  • AUSTRAC — Initial CDD guides by customer type
  • AUSTRAC — Initial CDD for bodies corporate and partnerships
  • Federal Register of Legislation — AML/CTF Act 2006 (current compilation)

Frequently asked questions

Is an ABN lookup enough for small-business KYB?

No. It may help verify registration data, but CDD can also require the correct customer, representative authority, ownership and control, beneficial owners, purpose, screening and risk assessment. Use ABR information as one source within the complete process.

Can a BAS agent reuse existing bookkeeping records?

Existing records may be reused where they are reliable, current and sufficient under the law and program. Document the reuse and fill gaps. Familiarity with the contact does not automatically establish current entity details, authority, beneficial ownership or risk.

Does every entity customer require the same documents?

No. The required information depends on customer type, service, legal requirements and risk. The program should define reliable sources and escalation. Apply proportionate checks while still satisfying every mandatory element and resolving material inconsistencies.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

Run the free scope checkCreate a free workspace

Keep reading

For BAS agents

AML/CTF guide for BAS agents

Read
Obligations

Beneficial ownership

Read
Obligations

CDD explained

Read

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.

CCassandra AML

AML/CTF compliance workspace for Australian tax agents, accountants, lawyers, conveyancers, real estate professionals, trust and company service providers, and precious-metals and stones dealers — with designated-service decisions and review-ready records.

Owned and operated by Cassandra Research Pty Ltd, an Australian company based in Melbourne, Victoria.

Product

Create workspaceFree scope checkSign inPricingSecurity

AML/CTF guides

All guidesTranche 2 foundationsCore obligationsTax agentsBAS agentsAccountantsLawyersConveyancersReal estateTrust & company servicesPrecious-items dealersKnowledge RSS feed

Company

AboutContactEditorial standards

Legal

Privacy PolicyTerms of ServiceCookie NoticeAccessibility

Cassandra AML assists compliance work. It does not provide legal advice, guarantee compliance or imply AUSTRAC endorsement.

© 2026 Cassandra Research Pty Ltd, Melbourne, Australia. All rights reserved.