Skip to content
Reference · Customer due diligence · AML/CTF Act, Part 2

Customer due diligence, as the Act and the Rules define it

What the Act says

The Act summarises its own CDD Part

Customer due diligence is Part 2 of the AML/CTF Act. The Part opens with a summary written by the drafter, which is plainer than any paraphrase and is the authority. It is set out here word for word.

The following is a simplified outline of this Part:

  • A reporting entity must undertake initial customer due diligence before providing a designated service to a customer. However, in special cases, initial customer due diligence may be carried out after the provision of the designated service.
  • A reporting entity must undertake ongoing customer due diligence in relation to the provision by the reporting entity of designated services.
  • Simplified customer due diligence may be undertaken in certain low risk circumstances as part of initial and ongoing customer due diligence.
  • Enhanced customer due diligence must be undertaken in certain circumstances as part of initial and ongoing customer due diligence.
  • Certain pre-commencement customers are subject to modified customer due diligence.
  • Exemptions from initial customer due diligence, and ongoing customer due diligence, apply in certain circumstances.
s 27 Simplified outline · Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), Part 2 — Compilation No. 62 (C2026C00274)

The four obligations

Three you must do, one you may

Each is a separate section of the Act, quoted here from its operative subsection. The distinction a summary usually loses is the one that decides how a business behaves: simplified CDD is permitted, the other three are required.

28

Initial customer due diligence

mustBefore you provide the service

A reporting entity must not commence to provide a designated service to a customer if the reporting entity has not established on reasonable grounds each of the matters in subsection (2) in relation to the customer.

s 28(1), verbatim

30

Ongoing customer due diligence

mustFor as long as the relationship lasts

A reporting entity must monitor its customers in relation to the provision of its designated services to appropriately identify, assess, manage and mitigate the risks of money laundering, financing of terrorism and proliferation financing that the reporting entity may reasonably face in providing designated services.

s 30(1), verbatim

31

Simplified customer due diligence

mayOnly where risk is low

In complying with the obligation imposed on a reporting entity under subsection 28(1) or 30(1) in relation to a customer, the reporting entity may apply simplified customer due diligence measures if: (a) the ML/TF risk of the customer is low; and (b) section 32 does not apply to the customer; and (c) the reporting entity complies with the requirements specified in the AML/CTF Rules.

s 31, verbatim

32

Enhanced customer due diligence

mustWhenever a trigger applies

In complying with the obligation imposed on a reporting entity under subsection 28(1) or 30(1) in relation to a customer, the reporting entity must apply enhanced customer due diligence measures appropriate to the ML/TF risk of the customer if one or more of the following apply to the customer

s 32, verbatim

Before you provide the service

Seven matters, and four things you must do to establish them

The matters are as follows:

  1. (a)the identity of the customer;
  2. (b)the identity of any person on whose behalf the customer is receiving the designated service;
  3. (c)the identity of any person acting on behalf of the customer and their authority to act;
  4. (d)if the customer is not an individual—the identity of any beneficial owners of the customer;
  5. (e)whether the customer, any beneficial owner of the customer, any person on whose behalf the customer is receiving the designated service, or any person acting on behalf of the customer is: (i) a politically exposed person; or (ii) a person designated for targeted financial sanctions;
  6. (f)the nature and purpose of the business relationship or occasional transaction;
  7. (g)any other matter relating to the customer that is specified in the AML/CTF Rules.

s 28(2), verbatim

Without limiting subsection (1), a reporting entity must do the following for the purposes of establishing on reasonable grounds the matters in subsection (2):

  1. (a)if the customer is an individual—take reasonable steps to establish that the customer is the person the customer claims to be;
  2. (b)identify the ML/TF risk of the customer, based on KYC information about the customer that is reasonably available to the reporting entity before commencing to provide the designated service;
  3. (c)collect KYC information about the customer that is appropriate to the ML/TF risk of the customer;
  4. (d)verify, using reliable and independent data, such of the KYC information referred to in paragraph (c) as is appropriate to the ML/TF risk of the customer.

s 28(3), verbatim

When enhanced CDD is compulsory

Any one of these, and enhanced measures are required

Not a risk judgement you make — a list the Act sets. One trigger is enough.

  1. (a)the ML/TF risk of the customer is high;
  2. (b)if: (i) a suspicious matter reporting obligation arises for the reporting entity in relation to the customer; and (ii) the reporting entity proposes to continue to provide a designated service or designated services to the customer;
  3. (c)the customer, any beneficial owner of the customer, any person on whose behalf the customer is receiving the designated service, or any person acting on behalf of the customer, is a foreign politically exposed person;
  4. (d)the customer, any beneficial owner of the customer, any person on whose behalf the customer is receiving the designated service, or any person acting on behalf of the customer, is: (i) an individual who is physically present in a high risk jurisdiction for which the international body known as the Financial Action Task Force has called for enhanced due diligence to be applied; or (ii) a body corporate or legal arrangement that was formed in a high risk jurisdiction for which the international body known as the Financial Action Task Force has called for enhanced due diligence to be applied;
  5. (e)the designated service provided or proposed to be provided to the customer is provided or proposed to be provided as part of a nested services relationship;
  6. (f)the customer is of a kind specified in the AML/CTF Rules.

s 32, verbatim · Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), Part 2 — Compilation No. 62 (C2026C00274)

What the Rules add

The Act sets the obligation, the Rules set the floor

The AML/CTF Rules 2025 are made by the AUSTRAC CEO under the Act and bind exactly as the Act does. For CDD they do two things: they say what your policies must set out, and they set a minimum of KYC information to collect for each kind of customer.

The AML/CTF policies of the reporting entity must set out the circumstances in which the reporting entity will, for the purposes of undertaking initial customer due diligence in accordance with section 28 of the Act: (a) collect kinds of KYC information relating to a customer; or (b) both collect and verify kinds of KYC information relating to a customer; including but not limited to the circumstances in which the reporting entity will collect, or collect and verify, information on the customer’s source of wealth and source of funds.

r 5-2(2), verbatim · Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (F2026C00274), Compilation No. 1

Customer is sole trader

the reporting entity must collect at least the following KYC information:

  • the customer’s full name;
  • any business name used for the conduct of the business;
  • any other names the customer is commonly known by;
  • a unique identifier for the business or, if none has been given, a unique identifier for the customer (if any has been given);
  • the address of the principal place of business of the customer.

r 6-1(2), verbatim

Customer is body corporate, partnership or unincorporated association

the reporting entity must collect at least the following KYC information:

  • the customer’s full name;
  • any business names of the customer;
  • any other names the customer is commonly known by;
  • a unique identifier for the customer (if any has been given);

r 6-2(2), verbatim

Part 6 of the Rules also deals with trusts, government bodies, transferred customers and real estate transactions. These two cover most professional-services clients.

Sources

Every source on this page

This content is general information only. It is not legal, financial or compliance advice. Organisations should check AUSTRAC guidance, legislation, their own AML/CTF Program and professional advice where needed. Published by GetPost Labs Pty Ltd, a technology company building compliance software. Last checked against AUSTRAC’s published guidance on 17 August 2026. If you spot an error, tell us at australia@getpostlabs.io.

CDD that leaves a record

Lex-AML helps organise customer due diligence and supports the audit trail behind it — so the information you collected, the rating you gave and the reason for it are captured as you go. Your organisation makes the decisions.

Book a demo