Step-by-step process
Define every required person
Identify the legal customer, representatives, beneficial owners, service beneficiaries, payers, payees and wallet controllers relevant to the service.
Verify identity and authority
Use reliable independent material, resolve inconsistencies and document what each person is authorised to do.
Map ownership and control
Trace each entity and trust layer to individuals owning at least 25% or otherwise exercising ultimate control.
Establish purpose, expected activity and risk
Record intended services, assets, channels, values, frequency, counterparties and jurisdictions and assign the customer risk under the program.
Apply and evidence ongoing measures
Apply enhanced measures when triggered, approve the relationship, monitor changes and retain the CDD decision record.
Identify the customer for the designated service
Start with the customer definition attached to the service. For item 50A, the customer is the person whose money or virtual asset is exchanged; for item 50B, the person whose virtual asset is exchanged; for safekeeping, the customer of that service; and for transfer services, the payer or payee relevant to the institution's role. Keep the account user, funder, wallet controller, representative and legal customer separate where they are different.
Record whether the relationship is ongoing or an occasional transaction and what the customer wants to achieve. Establish expected assets, chains, fiat methods, transfer directions, value, frequency, counterparties and jurisdictions. This information supports the service-scope decision, customer-risk assessment and later identification of activity that does not fit the stated purpose.
Establish individuals, representatives and authority
Collect and verify KYC information appropriate to the individual and assessed risk using reliable and independent material. Resolve name, date-of-birth, address and identity inconsistencies rather than treating a technical verification score as the final decision. A non-face-to-face channel, reused device, third-party funding or synthetic-identity indicator may require additional measures.
For a person acting for a customer, establish both identity and authority. A director, employee, trustee, adviser, agent or API operator should not gain control merely because they can access an email address or company document. Define account permissions, transaction approval rights and withdrawal controls, and retain the authority evidence and any limits.
Trace beneficial ownership and control
A beneficial owner is an individual who directly or indirectly ultimately owns 25% or more of the customer or otherwise controls it. There can be more than one beneficial owner, and control can exist without a qualifying shareholding. Trace each company, partnership, trust, nominee and foreign layer until the relevant individuals are established on reasonable grounds.
For companies, reconcile registers, extracts, constitutions, shareholder information and control arrangements. For trusts, review the trustee and relevant governance or control roles and continue through any corporate trustee. Record percentages, indirect paths, voting or appointment rights, source documents, dates and unresolved differences. A customer-supplied chart is useful but is not independent verification by itself.
Assess risk and apply the correct level of CDD
AUSTRAC states that a VASP must apply enhanced CDD when a customer deposits or receives physical currency in exchange for virtual assets, including through a crypto ATM. The VASP must collect and verify the customer's source of funds and hold source-of-wealth information through ongoing CDD. This is a specific trigger; it should be built into the channel and transaction workflow rather than left to discretionary manual review.
- Consider customer type, beneficial ownership, PEP and sanctions exposure, service, asset, chain, custody model, transaction purpose, delivery channel and relevant jurisdictions.
- Consider whether the customer uses mixers, higher-risk decentralised services, offshore or unregistered VASPs, crypto ATMs, over-the-counter brokers, self-hosted wallets or privacy-enhancing assets, without assuming one feature decides the rating.
- Apply enhanced CDD when a current statutory trigger is met, document the trigger and select measures that manage the identified risk.
- Update and reverify KYC and customer risk when transactions, ownership, control, purpose, behaviour or external information materially change.
Approve, monitor and retain the CDD record
Initial CDD is generally completed before the designated service, subject to the defined delayed-CDD framework. Commercial urgency, market volatility or a customer waiting to trade is not by itself permission to delay. If required matters cannot be established, follow the hold, escalation, rejection and reporting process in the AML/CTF policies.
Retain the information collected, verification source and result, ownership map, authority, purpose, expected activity, risk assessment, enhanced measures and approval. AUSTRAC says CDD records are generally kept for seven years after the business relationship ends or the relevant occasional transaction is complete. Avoid retaining unnecessary copies of identity documents when the required type-and-content record can demonstrate compliance with less privacy risk.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
- AUSTRAC - Initial customer due diligence overview (updated 27 March 2026)
- AUSTRAC - Determining ownership and control structures (updated 31 March 2026)
- AUSTRAC - Enhanced customer due diligence (updated 15 July 2026)
- AUSTRAC - How to monitor your customers (updated 27 March 2026)
- AUSTRAC - Virtual asset designated services (updated 10 July 2026)
- AUSTRAC - Record keeping overview (updated 10 July 2026)
Frequently asked questions
Is a 25% shareholder always the only beneficial owner?
No. Every individual who directly or indirectly ultimately owns 25% or more is relevant, and an individual can be a beneficial owner through control even without that ownership percentage. A customer may have several beneficial owners.
Can a company extract complete VASP CDD?
Not by itself. It can corroborate existence, identifiers, offices or officeholders, but the VASP must also establish relevant beneficial owners, representatives and authority, purpose, expected activity, risk and individual identities on reasonable grounds.
When must a VASP apply enhanced CDD to a cash exchange?
AUSTRAC says enhanced CDD is required when a VASP customer deposits or receives physical currency in exchange for virtual assets, including at a crypto ATM. Source-of-funds information must be collected and verified, and source-of-wealth information must be held through ongoing CDD.
Can a VASP delay CDD because a token price is moving?
Market urgency alone is not a delayed-CDD condition. Use delayed CDD only where the Act, Rules and documented policies permit it and all required safeguards and timeframes are met.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.