Pricing Privacy Act About Get Started Free
AUSTRAC compliance guide

How to do client due diligence (CDD) for Australian professional services firms

Customer due diligence (CDD) is the process of verifying who your clients are and assessing the risk they pose. Under AML/CTF Tranche 2, it's now a legal requirement for Australian professional services firms providing designated services.

What is CDD and why does it matter?

CDD — also called Know Your Customer (KYC) — is the cornerstone of AML compliance. It's the process of: verifying clients are who they say they are, understanding the nature and purpose of your business relationship, and assessing the money laundering and terrorism financing risk they present.

Without proper CDD, every other part of your AML program is weakened. You can't monitor for suspicious activity if you don't know who your clients actually are.

When must you do CDD?

CDD is required before you provide any designated service to a new client. You must also conduct ongoing CDD throughout the relationship — monitoring transactions, updating information when circumstances change, and re-verifying when documents expire or risk levels increase.

Standard CDD vs enhanced CDD

Not every client requires the same level of scrutiny. AUSTRAC uses a risk-based approach:

The CDD process for individual clients

  1. Collect: full legal name, date of birth, residential address
  2. Collect: identity document (driver's licence, passport, or Medicare card)
  3. Verify: match document details against the Biometric identity verification (Didit) or sight original documents
  4. Record: store verified details and the date/method of verification
  5. Assess: assign a risk rating based on client type, services requested, and other risk factors

The CDD process for entity clients (companies and trusts)

  1. Verify the entity exists: ABN/ACN lookup via Australian Business Register
  2. Collect: registered address, principal business address, nature of business
  3. Identify beneficial owners: anyone owning or controlling 25% or more
  4. Verify each beneficial owner as per individual CDD above
  5. For trusts: obtain and sight the trust deed; identify trustee, settlor, and beneficiaries
  6. Assess: trusts and complex structures generally attract higher risk ratings

Common mistake: Treating entity verification as just looking up an ABN. AUSTRAC expects you to look through the entity to identify the real people who own and control it — the beneficial owners. An ABN check alone is not sufficient CDD.

When CDD cannot be completed

If a client cannot or will not provide the information required for CDD, you must not provide the designated service. You should also consider whether this refusal is itself a suspicious indicator warranting an SMR.

Manage AML compliance for all your clients from one dashboard

CompliDesk is built specifically for Australian professional services firms managing AML/CTF compliance for clients. Sign up free for free signup.

Sign up free today

Client due diligence — quick answers

Standard CDD is the baseline identity verification and risk assessment required for every client. EDD is additional scrutiny — more documentation, senior sign-off, closer monitoring — triggered when a client is rated high risk, is a politically exposed person, or shows other elevated risk indicators.
In limited circumstances, reliance on another reporting entity's due diligence is permitted under the Act, but you remain ultimately responsible for the adequacy of that verification. Most firms find it simpler to run their own independent CDD rather than relying on someone else's work they can't fully verify.
There's no universal fixed interval — refresh frequency should match risk level. High-risk clients typically warrant review every 6 months to a year; lower-risk clients can go longer, but a material change in circumstances (new jurisdiction, ownership change, unusual transaction) should always trigger a fresh look regardless of schedule.