For trust & company services
Ongoing monitoring and CDD review triggers for Australian TCSPs
Formation CDD is a snapshot; ongoing customer due diligence tests whether the picture remains true while a trust and company service provider continues the relationship. Australian reporting entities must monitor customers while providing designated services for unusual transactions and behaviour, review customer risk, and update and reverify KYC information where appropriate. TCSP monitoring is broader than bank-style payment alerts. A change of trustee, an unexplained nominee instruction, a dormant company becoming active or repeated mail for an unknown overseas controller can be as important as a transfer of funds. This guide shows how to define an expected customer profile, combine periodic reviews with event-driven triggers, investigate alerts and preserve evidence that the monitoring system actually operates.
See the trust and company services AML/CTF workspaceStep-by-step process
Set the expected profile
Record how the customer is expected to use each service, who should control it, relevant jurisdictions and anticipated activity.
Configure event triggers
Define ownership, officeholder, nominee, address, jurisdiction, payment and behaviour changes that require a review.
Schedule periodic reviews
Assign risk-based dates and specify which KYC, ownership, screening, purpose and risk information each review must reconsider.
Investigate and respond
Compare an alert with the expected profile, obtain proportionate evidence, update risk and apply enhanced measures or SMR escalation where required.
Test effectiveness
Sample alerts and overdue reviews, identify missed data flows and update controls when services or risks change.
Create an expected-use profile at onboarding
Monitoring works only when the file records what normal use should look like. For each customer, record the designated services, purpose of each entity or arrangement, expected owners and controllers, relevant jurisdictions, anticipated changes, source and destination of any money or property you will handle, and the expected duration and frequency of the relationship. An item 9 address customer needs a different baseline from a customer for whom the TCSP provides an item 7 acting-director service, where the nominator retains control and the director acts on the nominator's wishes and instructions.
Connect the baseline to the risk rating and controls. A low-volume domestic family structure may be reviewed differently from a layered cross-border group, but the difference must be justified by the risks reasonably faced. Avoid generic profiles such as 'corporate services' that give reviewers no way to identify a meaningful deviation.
Use event-driven TCSP review triggers
A trigger is a prompt to review, not an automatic conclusion of wrongdoing. Configure responsibilities, timeframes and escalation thresholds so the person who sees the event knows what to record and who must assess it. Where systems are separate, ensure formation, registered-office, billing and transaction information can be considered together.
- A change in beneficial owners, shareholders, trustees, settlors, appointors, protectors, directors, nominee instructions or powers of attorney.
- A new jurisdiction, offshore intermediary, foreign bank account, virtual-asset exposure or address inconsistent with the stated operating footprint.
- A dormant or asset-holding structure beginning substantial trading, borrowing, asset transfers or repeated high-value activity without a clear explanation.
- Instructions from a previously unknown third party, changes in who communicates with the TCSP, or unexplained efforts to prevent contact with the underlying controller.
- Returned mail, unexplained mail or official notices at a registered office, rapid officer changes, repeated company formations or restructuring without a coherent purpose.
- New PEP, sanctions or reliable adverse information, material inconsistencies in KYC, or reluctance to provide an ownership or source explanation.
Add risk-based periodic reviews
Event monitoring does not remove the need for periodic review. Your AML/CTF policies should say how often different customer groups are reviewed, what KYC is refreshed, when reverification is appropriate and which review frequencies correspond to risk. AUSTRAC does not prescribe one universal annual cycle for every customer; the schedule must be appropriate to the relationship and risks.
At review, confirm that the ownership and control map, representatives, purpose, activity and risk rating remain accurate. Check whether the customer used services as expected, whether prior conditions were followed and whether the current controls still mitigate the risk. Record a reasoned no-change conclusion rather than treating a tick box as evidence of review.
Investigate unusual activity and update the risk response
Review alerts promptly using the customer history, supporting documents and relevant industry indicators. A red flag is an input to review, not the statutory SMR threshold, and there is no prescribed number of indicators that automatically creates or rules out suspicion. Ask proportionate questions and consider the facts together. If the activity has a supported explanation, record why it resolved the alert. If uncertainty or risk remains, update KYC and reverify information. Collect or verify source-of-funds or source-of-wealth information where required by a PEP or enhanced-CDD rule or where the identified risk and policy make it an appropriate measure.
A change in risk can affect service limits, approval conditions and review frequency. Apply enhanced CDD when the customer is rated high risk or another current trigger applies; do not apply it automatically merely because an alert was generated. If there are reasonable grounds for a suspicion covered by section 41, follow the SMR process and reporting deadline. Where an SMR is required in relation to the customer and the TCSP intends to continue providing a designated service, enhanced CDD is required. Manage any disclosure of protected information by asking whether it would or could reasonably be expected to prejudice an investigation.
Test and evidence the monitoring system
Keep records of customer activity, alerts, analysis, risk changes, KYC updates, decisions and approvals. Sample closed alerts to check that explanations are supported, overdue reviews are escalated and staff apply triggers consistently. Review whether the design covers all delivery channels and whether known changes from company or trust administration actually reach the AML reviewer.
AUSTRAC expects reporting entities to check whether ongoing CDD is effective and address deficiencies promptly. Track missed triggers, false positives, review backlogs and control changes as operational evidence. Update policies when the business adds a service, payment method, jurisdiction or customer type that changes the risk picture.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
- AUSTRAC — Overview of ongoing customer due diligence
- AUSTRAC — Reviewing and updating customer risk and KYC
- AUSTRAC — How to monitor your customers
- AUSTRAC — Enhanced customer due diligence
- AUSTRAC — Source of funds and source of wealth
- AUSTRAC — Suspicious matter reports
- AUSTRAC — Tipping off
- Federal Register of Legislation — AML/CTF Act 2006
Frequently asked questions
How often must a TCSP refresh customer KYC?
There is no single frequency suitable for every customer. Your policies must set risk-based review frequencies and event triggers. Higher-risk, complex or changing relationships generally justify more frequent attention, while any material ownership, control, purpose or behaviour change may require review before the next scheduled date.
Does ongoing CDD apply to an occasional TCSP transaction?
A reporting entity must monitor a customer while providing a designated service, including an occasional transaction. The additional requirement to periodically review and update KYC information and customer risk applies where there is a business relationship. Document whether the engagement is occasional or ongoing and apply the correct monitoring scope.
Is every change of director or address suspicious?
No. It is a review trigger because it may change authority, control, geography, purpose or risk. Check the explanation and supporting evidence in context. Escalate when the change is inconsistent, opaque or part of a concerning pattern rather than treating an ordinary documented change as proof of wrongdoing.
What happens if an alert creates reasonable grounds for suspicion?
Escalate through the controlled SMR process and apply the statutory reporting deadline. A red flag alone is not the test; the decision is whether the available facts create reasonable grounds for a relevant section 41 suspicion. If an SMR is required in relation to the customer and services will continue, apply enhanced CDD. Do not disclose protected information where that disclosure would or could reasonably be expected to prejudice an investigation.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.