For tax agents
Entity customer due diligence for Australian tax practices
Entity CDD is more than checking an ABN or downloading a company extract. Before providing a designated service, a tax practice must establish who its customer is, collect and verify information appropriate to the customer type and risk, identify relevant beneficial owners and representatives, understand the nature and purpose of the relationship, and assess the money laundering, terrorism financing and proliferation financing risk. Companies, partnerships, trusts and SMSFs each present different legal roles. A structured sequence prevents the practice from verifying the contact person while missing the entity, the authority to act or the individuals who ultimately own or control it.
See the tax agents AML/CTF workspaceStart by establishing who receives the designated service
Do not assume the entity named in an email is the customer. Establish whether the body corporate, partnership, trust or another person is receiving the service and whether anyone is acting on its behalf. Where an entity acts for someone else, the represented person may be the customer. Record the service, the customer conclusion and the facts supporting it before selecting a CDD form.
For creation services, table 6 can identify additional customers. A company-creation service includes the proposed beneficial owners and directors, while creation of an express trust includes the proposed trustee, settlor and beneficiaries. This service-specific customer population sits alongside the general need to identify persons acting for or on behalf of a customer and verify their authority.
Verify the entity and the representative's authority
Collect the legal name, legal form, registration or establishment details, principal place of business and other information required by the practice's customer-type procedure. Verify using reliable and independent data appropriate to the risk. ABR and ASIC information can support the process, but a registry match does not by itself establish every ownership, control, authority or risk question.
Identify the person dealing with the practice and establish their authority. Evidence might include company officeholder information, a board or trustee resolution, employment confirmation, an agency instrument, partnership authority or another reliable source. Keep the authority record connected to the customer file so a reviewer can distinguish the representative from the customer and see why that person could instruct the practice.
Trace ownership and control to the relevant individuals
Collect information about the ownership and control structure and follow corporate layers until the relevant individuals are identified. Consider both ownership and other means of control; do not stop merely because the first shareholder is another company. Record the structure, sources consulted, calculations or reasoning, and any deeming provisions applied to a listed public company or government body.
For trusts, record the trust type and the roles relevant to the customer and service, including trustee, settlor, beneficiaries or beneficiary class, appointor and any other person exercising control where applicable. For an SMSF, distinguish the fund, trustee structure, members, directors of a corporate trustee and the person giving instructions. Apply the current AUSTRAC trust guide rather than forcing trust relationships into a company-ownership template.
Complete risk, screening and purpose checks
Understand why the customer wants the designated service, the expected nature of the relationship, the relevant transaction or structure, jurisdictions involved and expected use. Apply the practice's risk methodology across customer, service, delivery-channel and geographic factors. Determine whether relevant people are PEPs or persons designated for targeted financial sanctions and apply enhanced CDD when required by the program and law.
Retain the information collected, verification sources and dates, representative authority, ownership and control analysis, screening results, risk rating, rationale, approvals and any enhanced checks. Set review triggers for changes in directors, trustees, owners, controllers, representatives, jurisdictions, service scope or unusual activity. Entity CDD is a maintained conclusion, not a once-only document pack.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Is an ABR lookup enough to complete KYB for an entity customer?
No. An ABR lookup can verify useful registration information, but entity CDD can also require representative authority, ownership and control, beneficial owners, purpose, screening and risk assessment. Use registry evidence as one part of the complete process.
Who is verified when a company instructs the tax practice?
Verify the company information required by the applicable procedure, establish and evidence the representative's authority, and identify and complete required checks on beneficial owners and other relevant persons. A company-creation service can also make proposed directors and beneficial owners customers under table 6.
Can the practice reuse information collected for tax purposes?
Potentially, if the information is reliable, current and sufficient for the AML/CTF requirement and the practice follows its program. Reuse should be documented; a longstanding tax file does not automatically establish current identity, authority, ownership, control, screening or risk.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.