For trust & company services

AML/CTF checklist for Australian trust and company service providers

Trust and company service providers sit at the formation point of the structures criminals use, which is why Tranche 2 captures them directly: company and trust creation, registered offices, nominee roles and trustee services. The checklist for a TCSP must therefore be structure-aware, not just document-aware. This guide sequences the work AUSTRAC's program guidance expects - service mapping, CDD, ownership, monitoring, reporting and records - with the TCSP-specific questions that make a file defensible.

See the trust and company services AML/CTF workspace

Map the services and the customer set

A TCSP can provide several designated services in one engagement. Each service has its own customer set and timing, so the file should map the services and the parties rather than carrying one label across the whole relationship.

  • Test company and trust formation against item 6 and the shelf-company item
  • Identify item 7 role services, item 8 nominee services and item 9 address services
  • Record the customer set for each service: instructing person, beneficial owners, directors, trustees, settlors and beneficiaries
  • Confirm general entity administration is not assumed to be designated

Complete CDD before formation work

For item 6 company formation, the customer population can extend beyond the person giving instructions to the proposed beneficial owners and directors. For trusts, it can include the proposed trustee, settlor and beneficiaries. The formation file should show the identification before documents are lodged or executed.

  • Identify and verify each customer required by the service
  • Map beneficial owners and controllers, including indirect holdings
  • Identify trustees, settlors and beneficiaries or classes for trust work
  • Screen for PEPs, sanctions and adverse media
  • Record the risk rating and the reason

Monitor the structure, not just the client

The structure is the product, and changes to the structure are the risk signal. A sudden change of trustee, a new beneficiary class or a nominee arrangement without purpose should trigger review under the program, not a stamp of approval.

  • Review ownership and control on trigger events and risk-based cycles
  • Watch for unexplained changes to directors, trustees or beneficiaries
  • Review registered-office correspondence and nominee activity
  • Assess transactions and distributions for consistency with the structure's purpose
  • Lodge SMRs within the deadline and protect SMR-related information

Records and evaluation

A TCSP's records are often the only way an examiner can reconstruct who controlled what and why. The checklist should produce a structure-level file: formation, parties, ownership, decisions and monitoring in one connected record.

  • Retain formation files, CDD, ownership mapping, monitoring and reporting records
  • Keep the evidence connected to each service and structure
  • Deliver role-based training and record completion
  • Conduct the independent evaluation on the program's calendar

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

Frequently asked questions

Which TCSP services are designated?

Company and trust formation, selling or transferring shelf companies, certain acting roles, nominee shareholding and registered-office or principal-place-of-business address services can be designated. General entity administration is not automatically.

Who must be verified for a trust formation?

The instructing person and the proposed trustee, settlor and beneficiaries (or a description of each class where individual identification is not yet possible), together with beneficial owners or controllers where the customer is an entity.

Is a registered-office service always captured?

Item 9 applies where the address is provided in the course of carrying on a business. The customer, the use of the address and the business context determine the analysis.

What should a TCSP file show?

The service map, each customer's identity and verification, ownership and control mapping, risk ratings, monitoring events, reporting decisions and retention.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.