What is CDD and why does it matter?
CDD — also called Know Your Customer (KYC) — is the cornerstone of AML compliance. It's the process of: verifying clients are who they say they are, understanding the nature and purpose of your business relationship, and assessing the money laundering and terrorism financing risk they present.
Without proper CDD, every other part of your AML program is weakened. You can't monitor for suspicious activity if you don't know who your clients actually are.
When must you do CDD?
CDD is required before you provide any designated service to a new client. You must also conduct ongoing CDD throughout the relationship — monitoring transactions, updating information when circumstances change, and re-verifying when documents expire or risk levels increase.
Standard CDD vs enhanced CDD
Not every client requires the same level of scrutiny. AUSTRAC uses a risk-based approach:
- Standard CDD: Applied to most clients — individual verification, basic entity checks, standard monitoring
- Enhanced CDD (EDD): Required for higher-risk clients — Politically Exposed Persons, clients from high-risk jurisdictions, complex corporate structures, or clients whose transactions don't match their apparent profile
The CDD process for individual clients
- Collect: full legal name, date of birth, residential address
- Collect: identity document (driver's licence, passport, or Medicare card)
- Verify: match document details against the Biometric identity verification (Didit) or sight original documents
- Record: store verified details and the date/method of verification
- Assess: assign a risk rating based on client type, services requested, and other risk factors
The CDD process for entity clients (companies and trusts)
- Verify the entity exists: ABN/ACN lookup via Australian Business Register
- Collect: registered address, principal business address, nature of business
- Identify beneficial owners: anyone owning or controlling 25% or more
- Verify each beneficial owner as per individual CDD above
- For trusts: obtain and sight the trust deed; identify trustee, settlor, and beneficiaries
- Assess: trusts and complex structures generally attract higher risk ratings
Common mistake: Treating entity verification as just looking up an ABN. AUSTRAC expects you to look through the entity to identify the real people who own and control it — the beneficial owners. An ABN check alone is not sufficient CDD.
When CDD cannot be completed
If a client cannot or will not provide the information required for CDD, you must not provide the designated service. You should also consider whether this refusal is itself a suspicious indicator warranting an SMR.
Manage AML compliance for all your clients from one dashboard
CompliDesk is built specifically for Australian professional services firms managing AML/CTF compliance for clients. Sign up free for free signup.
Sign up free today