What is KYC and why do accountants now need it?
KYC — Know Your Customer — is the process of verifying that your clients are who they claim to be. It's been required of banks and financial institutions since 2006. From 1 July 2026, it's now required of Australian accountants providing designated services under the AML/CTF Act.
The reason is simple: accountants are 'gatekeepers' to the financial system. Setting up companies, managing trusts, and handling transactions on behalf of clients creates opportunities for money laundering if the accountant doesn't know who they're really dealing with.
AUSTRAC deadline: 29 July 2026. You must be enrolled with AUSTRAC and have your KYC processes operational before this date.
KYC checklist — individual clients
For every individual client receiving designated services, you must collect and verify:
- Full legal name — as it appears on their identity document
- Date of birth
- Residential address
- Identity document — Australian driver's licence, passport, Medicare card, or other AUSTRAC-accepted document
- Purpose of the business relationship — why are they using your firm?
KYC checklist — company clients
For companies, partnerships, and incorporated associations:
- Company name and ACN
- ABN
- Registered and principal place of business address
- Directors — name, date of birth, and verification for each director
- Beneficial owners — anyone owning or controlling 25% or more
- Nature of business
KYC checklist — trust clients
Trusts are the most complex and highest-risk structure for Tranche 2 reporting entities:
- Trust name and type (family trust, unit trust, charitable trust etc.)
- Trustee details — individual or corporate trustee, verified
- Settlor — who established the trust and what assets they settled
- Beneficiaries — named beneficiaries where ascertainable
- Trust deed — sighted and stored
- Ultimate beneficial owners — the real individuals who benefit
Record keeping requirements
All KYC records must be retained for a minimum of 7 years from the date the client relationship ends or the last transaction occurs. Records must be stored securely and be readily available to AUSTRAC on request.
Manual photocopies are not enough. If AUSTRAC audits your firm, you need to demonstrate not just that you collected documents, but that you verified them. Electronic verification via the Biometric identity verification (Didit) creates an automatic audit trail. Manual photocopies do not.
When to re-verify
Initial verification is not a one-time event. You must re-verify when:
• The client's details change significantly
• Your firm's risk appetite indicates re-verification is needed
• A transaction or behaviour triggers enhanced due diligence
• The client relationship has been dormant for an extended period
Manage AML compliance for all your clients from one dashboard
CompliDesk is built specifically for Australian professional services firms managing AML/CTF compliance for clients. Sign up free for free signup.
Sign up free today