Skip to main content
CCassandra AML
Scope checkGuidesPricingSecurityAboutSign inStart free
Menu
Scope checkGuidesPricingSecurityAboutSign inStart free
Guides/Trust and company services

For trust & company services

Ongoing monitoring and CDD review triggers for Australian TCSPs

7 min read · Updated 1 August 2026

Formation CDD is a snapshot; ongoing customer due diligence tests whether the picture remains true while a trust and company service provider continues the relationship. Australian reporting entities must monitor customers while providing designated services for unusual transactions and behaviour, review customer risk, and update and reverify KYC information where appropriate. TCSP monitoring is broader than bank-style payment alerts. A change of trustee, an unexplained nominee instruction, a dormant company becoming active or repeated mail for an unknown overseas controller can be as important as a transfer of funds. This guide shows how to define an expected customer profile, combine periodic reviews with event-driven triggers, investigate alerts and preserve evidence that the monitoring system actually operates.

See the trust and company services AML/CTF workspace

On this page

  1. Step-by-step process
  2. Create an expected-use profile at onboarding
  3. Use event-driven TCSP review triggers
  4. Add risk-based periodic reviews
  5. Investigate unusual activity and update the risk response
  6. Test and evidence the monitoring system
  7. Official sources
  8. Frequently asked questions

Step-by-step process

  1. Set the expected profile

    Record how the customer is expected to use each service, who should control it, relevant jurisdictions and anticipated activity.

  2. Configure event triggers

    Define ownership, officeholder, nominee, address, jurisdiction, payment and behaviour changes that require a review.

  3. Schedule periodic reviews

    Assign risk-based dates and specify which KYC, ownership, screening, purpose and risk information each review must reconsider.

  4. Investigate and respond

    Compare an alert with the expected profile, obtain proportionate evidence, update risk and apply enhanced measures or SMR escalation where required.

  5. Test effectiveness

    Sample alerts and overdue reviews, identify missed data flows and update controls when services or risks change.

Create an expected-use profile at onboarding

Monitoring works only when the file records what normal use should look like. For each customer, record the designated services, purpose of each entity or arrangement, expected owners and controllers, relevant jurisdictions, anticipated changes, source and destination of any money or property you will handle, and the expected duration and frequency of the relationship. An item 9 address customer needs a different baseline from a customer for whom the TCSP provides an item 7 acting-director service, where the nominator retains control and the director acts on the nominator's wishes and instructions.

Connect the baseline to the risk rating and controls. A low-volume domestic family structure may be reviewed differently from a layered cross-border group, but the difference must be justified by the risks reasonably faced. Avoid generic profiles such as 'corporate services' that give reviewers no way to identify a meaningful deviation.

Use event-driven TCSP review triggers

A trigger is a prompt to review, not an automatic conclusion of wrongdoing. Configure responsibilities, timeframes and escalation thresholds so the person who sees the event knows what to record and who must assess it. Where systems are separate, ensure formation, registered-office, billing and transaction information can be considered together.

  • A change in beneficial owners, shareholders, trustees, settlors, appointors, protectors, directors, nominee instructions or powers of attorney.
  • A new jurisdiction, offshore intermediary, foreign bank account, virtual-asset exposure or address inconsistent with the stated operating footprint.
  • A dormant or asset-holding structure beginning substantial trading, borrowing, asset transfers or repeated high-value activity without a clear explanation.
  • Instructions from a previously unknown third party, changes in who communicates with the TCSP, or unexplained efforts to prevent contact with the underlying controller.
  • Returned mail, unexplained mail or official notices at a registered office, rapid officer changes, repeated company formations or restructuring without a coherent purpose.
  • New PEP, sanctions or reliable adverse information, material inconsistencies in KYC, or reluctance to provide an ownership or source explanation.

Add risk-based periodic reviews

Event monitoring does not remove the need for periodic review. Your AML/CTF policies should say how often different customer groups are reviewed, what KYC is refreshed, when reverification is appropriate and which review frequencies correspond to risk. AUSTRAC does not prescribe one universal annual cycle for every customer; the schedule must be appropriate to the relationship and risks.

At review, confirm that the ownership and control map, representatives, purpose, activity and risk rating remain accurate. Check whether the customer used services as expected, whether prior conditions were followed and whether the current controls still mitigate the risk. Record a reasoned no-change conclusion rather than treating a tick box as evidence of review.

Investigate unusual activity and update the risk response

Review alerts promptly using the customer history, supporting documents and relevant industry indicators. A red flag is an input to review, not the statutory SMR threshold, and there is no prescribed number of indicators that automatically creates or rules out suspicion. Ask proportionate questions and consider the facts together. If the activity has a supported explanation, record why it resolved the alert. If uncertainty or risk remains, update KYC and reverify information. Collect or verify source-of-funds or source-of-wealth information where required by a PEP or enhanced-CDD rule or where the identified risk and policy make it an appropriate measure.

A change in risk can affect service limits, approval conditions and review frequency. Apply enhanced CDD when the customer is rated high risk or another current trigger applies; do not apply it automatically merely because an alert was generated. If there are reasonable grounds for a suspicion covered by section 41, follow the SMR process and reporting deadline. Where an SMR is required in relation to the customer and the TCSP intends to continue providing a designated service, enhanced CDD is required. Manage any disclosure of protected information by asking whether it would or could reasonably be expected to prejudice an investigation.

Test and evidence the monitoring system

Keep records of customer activity, alerts, analysis, risk changes, KYC updates, decisions and approvals. Sample closed alerts to check that explanations are supported, overdue reviews are escalated and staff apply triggers consistently. Review whether the design covers all delivery channels and whether known changes from company or trust administration actually reach the AML reviewer.

AUSTRAC expects reporting entities to check whether ongoing CDD is effective and address deficiencies promptly. Track missed triggers, false positives, review backlogs and control changes as operational evidence. Update policies when the business adds a service, payment method, jurisdiction or customer type that changes the risk picture.

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

  • AUSTRAC — Overview of ongoing customer due diligence
  • AUSTRAC — Reviewing and updating customer risk and KYC
  • AUSTRAC — How to monitor your customers
  • AUSTRAC — Enhanced customer due diligence
  • AUSTRAC — Source of funds and source of wealth
  • AUSTRAC — Suspicious matter reports
  • AUSTRAC — Tipping off
  • Federal Register of Legislation — AML/CTF Act 2006

Frequently asked questions

How often must a TCSP refresh customer KYC?

There is no single frequency suitable for every customer. Your policies must set risk-based review frequencies and event triggers. Higher-risk, complex or changing relationships generally justify more frequent attention, while any material ownership, control, purpose or behaviour change may require review before the next scheduled date.

Does ongoing CDD apply to an occasional TCSP transaction?

A reporting entity must monitor a customer while providing a designated service, including an occasional transaction. The additional requirement to periodically review and update KYC information and customer risk applies where there is a business relationship. Document whether the engagement is occasional or ongoing and apply the correct monitoring scope.

Is every change of director or address suspicious?

No. It is a review trigger because it may change authority, control, geography, purpose or risk. Check the explanation and supporting evidence in context. Escalate when the change is inconsistent, opaque or part of a concerning pattern rather than treating an ordinary documented change as proof of wrongdoing.

What happens if an alert creates reasonable grounds for suspicion?

Escalate through the controlled SMR process and apply the statutory reporting deadline. A red flag alone is not the test; the decision is whether the available facts create reasonable grounds for a relevant section 41 suspicion. If an SMR is required in relation to the customer and services will continue, apply enhanced CDD. Do not disclose protected information where that disclosure would or could reasonably be expected to prejudice an investigation.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

Run the free scope checkCreate a free workspace

Keep reading

For trust & company services

Complex ownership structures

Read
For trust & company services

TCSP refusal and exit

Read
Obligations

CDD explained

Read

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.

CCassandra AML

AML/CTF compliance workspace for Australian tax agents, accountants, lawyers, conveyancers, real estate professionals, trust and company service providers, and precious-metals and stones dealers — with designated-service decisions and review-ready records.

Owned and operated by Cassandra Research Pty Ltd, an Australian company based in Melbourne, Victoria.

Product

Create workspaceFree scope checkSign inPricingSecurity

AML/CTF guides

All guidesTranche 2 foundationsCore obligationsTax agentsBAS agentsAccountantsLawyersConveyancersReal estateTrust & company servicesPrecious-items dealersKnowledge RSS feed

Company

AboutContactEditorial standards

Legal

Privacy PolicyTerms of ServiceCookie NoticeAccessibility

Cassandra AML assists compliance work. It does not provide legal advice, guarantee compliance or imply AUSTRAC endorsement.

© 2026 Cassandra Research Pty Ltd, Melbourne, Australia. All rights reserved.