Skip to content
Reference · Customer due diligence · AML/CTF Act, Part 2

Customer due diligence: the four types, and what the Act requires

Customer due diligence (CDD) is the AML/CTF work used to establish and understand the customer, verify required information, assess relevant risk and apply the measures required by the Act, Rules and the reporting entity’s own AML/CTF program. People often search for this work as “AML/KYC checks”; the Australian legislation uses customer due diligence. It is owed to the customer of a designated service — whether a service is one is a section 6 question, answered elsewhere.

The four types

Two are about timing, two are about risk

Initial CDD happens before the service; ongoing CDD runs for as long as the relationship does. Simplified and enhanced CDD are not separate stages — they are the amount of work the other two involve, set by the customer’s risk. Three are required; one is permitted.

Top row: the default. Bottom row: what the risk rating changes — simplified where your program allows it for assessed lower risk; enhanced whenever a s 32 trigger is present.

Which form

There is no universal CDD form — it depends on who the customer is

AUSTRAC publishes one initial-CDD guide per customer type, and each sector starter kit carries a matching form. Pick the row for your customer; the Rules set a different minimum for each.

Which AUSTRAC guide and starter-kit form applies to each customer type
CustomerAUSTRAC guideStarter-kit formMinimum KYC
IndividualInitial CDD for individualsInitial customer due diligence form — Individual or sole traderAML/CTF Rules 2025, Part 6, Division 1 (individuals)
Sole traderInitial CDD for sole tradersInitial customer due diligence form — Individual or sole traderr 6-1(2) — quoted below
Body corporate, partnership or unincorporated associationInitial CDD for a body corporate, partnership or unincorporated associationInitial customer due diligence form — Body corporate, partnership or associationr 6-2(2) — quoted below
TrustInitial CDD for a trustInitial customer due diligence form — TrustAML/CTF Rules 2025, Part 6, Division 1 (trusts)
Government bodyInitial CDD for a government bodyInitial customer due diligence form — Government bodyAML/CTF Rules 2025, Part 6, Division 1 (government bodies)

Guides: AUSTRAC, Initial customer due diligence guides by customer type. Forms: the AUSTRAC program starter kits. Which form you use is set by your own AML/CTF policies.

Where the form sits in the day-to-day — the service gate, onboarding, verification, the risk decision, the record — is on the starter-kit page; this page is what the form has to establish.

What the Act says

The Act summarises its own CDD Part

Customer due diligence is Part 2 of the AML/CTF Act. The Part opens with a summary written by the drafter, which is plainer than any paraphrase and is the authority. It is set out here word for word.

The following is a simplified outline of this Part:

  • A reporting entity must undertake initial customer due diligence before providing a designated service to a customer. However, in special cases, initial customer due diligence may be carried out after the provision of the designated service.
  • A reporting entity must undertake ongoing customer due diligence in relation to the provision by the reporting entity of designated services.
  • Simplified customer due diligence may be undertaken in certain low risk circumstances as part of initial and ongoing customer due diligence.
  • Enhanced customer due diligence must be undertaken in certain circumstances as part of initial and ongoing customer due diligence.
  • Certain pre-commencement customers are subject to modified customer due diligence.
  • Exemptions from initial customer due diligence, and ongoing customer due diligence, apply in certain circumstances.
s 27 Simplified outline · Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), Part 2 — Compilation No. 62 (C2026C00274)

The four obligations

Three you must do, one you may

Each is a separate section of the Act, quoted here from its operative subsection. The distinction a summary usually loses is the one that decides how a business behaves: simplified CDD is permitted, the other three are required.

Four people examining customer information, illustrating the four customer due diligence obligations
Initial, ongoing and enhanced CDD are required when their conditions apply; simplified CDD is permitted only where its conditions are met
s 28

Initial customer due diligence

mustBefore you provide the service

A reporting entity must not commence to provide a designated service to a customer if the reporting entity has not established on reasonable grounds each of the matters in subsection (2) in relation to the customer.

s 28(1), verbatim

s 30

Ongoing customer due diligence

mustFor as long as the relationship lasts

A reporting entity must monitor its customers in relation to the provision of its designated services to appropriately identify, assess, manage and mitigate the risks of money laundering, financing of terrorism and proliferation financing that the reporting entity may reasonably face in providing designated services.

s 30(1), verbatim

s 31

Simplified customer due diligence

mayOnly where risk is low

In complying with the obligation imposed on a reporting entity under subsection 28(1) or 30(1) in relation to a customer, the reporting entity may apply simplified customer due diligence measures if: (a) the ML/TF risk of the customer is low; and (b) section 32 does not apply to the customer; and (c) the reporting entity complies with the requirements specified in the AML/CTF Rules.

s 31, verbatim

s 32

Enhanced customer due diligence

mustWhenever a trigger applies

In complying with the obligation imposed on a reporting entity under subsection 28(1) or 30(1) in relation to a customer, the reporting entity must apply enhanced customer due diligence measures appropriate to the ML/TF risk of the customer if one or more of the following apply to the customer

s 32, verbatim

Before you provide the service

Seven matters, and four things you must do to establish them

A professional checking a customer’s identity information during customer due diligence
Initial CDD is about establishing the required customer matters and taking the steps the Act requires to establish them

The matters are as follows:

  1. (a)the identity of the customer;
  2. (b)the identity of any person on whose behalf the customer is receiving the designated service;
  3. (c)the identity of any person acting on behalf of the customer and their authority to act;
  4. (d)if the customer is not an individual—the identity of any beneficial owners of the customer;
  5. (e)whether the customer, any beneficial owner of the customer, any person on whose behalf the customer is receiving the designated service, or any person acting on behalf of the customer is: (i) a politically exposed person; or (ii) a person designated for targeted financial sanctions;
  6. (f)the nature and purpose of the business relationship or occasional transaction;
  7. (g)any other matter relating to the customer that is specified in the AML/CTF Rules.

s 28(2), verbatim

Without limiting subsection (1), a reporting entity must do the following for the purposes of establishing on reasonable grounds the matters in subsection (2):

  1. (a)if the customer is an individual—take reasonable steps to establish that the customer is the person the customer claims to be;
  2. (b)identify the ML/TF risk of the customer, based on KYC information about the customer that is reasonably available to the reporting entity before commencing to provide the designated service;
  3. (c)collect KYC information about the customer that is appropriate to the ML/TF risk of the customer;
  4. (d)verify, using reliable and independent data, such of the KYC information referred to in paragraph (c) as is appropriate to the ML/TF risk of the customer.

s 28(3), verbatim

When enhanced CDD is compulsory

Any one of these, and enhanced measures are required

Not a risk judgement you make — a list the Act sets. One trigger is enough.

  1. (a)the ML/TF risk of the customer is high;
  2. (b)if: (i) a suspicious matter reporting obligation arises for the reporting entity in relation to the customer; and (ii) the reporting entity proposes to continue to provide a designated service or designated services to the customer;
  3. (c)the customer, any beneficial owner of the customer, any person on whose behalf the customer is receiving the designated service, or any person acting on behalf of the customer, is a foreign politically exposed person;
  4. (d)the customer, any beneficial owner of the customer, any person on whose behalf the customer is receiving the designated service, or any person acting on behalf of the customer, is: (i) an individual who is physically present in a high risk jurisdiction for which the international body known as the Financial Action Task Force has called for enhanced due diligence to be applied; or (ii) a body corporate or legal arrangement that was formed in a high risk jurisdiction for which the international body known as the Financial Action Task Force has called for enhanced due diligence to be applied;
  5. (e)the designated service provided or proposed to be provided to the customer is provided or proposed to be provided as part of a nested services relationship;
  6. (f)the customer is of a kind specified in the AML/CTF Rules.

s 32, verbatim · Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), Part 2 — Compilation No. 62 (C2026C00274)

What the Rules add

The Act sets the obligation, the Rules set the floor

The AML/CTF Rules 2025 are made by the AUSTRAC CEO under the Act and bind exactly as the Act does. For CDD they do two things: they say what your policies must set out, and they set a minimum of KYC information to collect for each kind of customer.

The AML/CTF policies of the reporting entity must set out the circumstances in which the reporting entity will, for the purposes of undertaking initial customer due diligence in accordance with section 28 of the Act: (a) collect kinds of KYC information relating to a customer; or (b) both collect and verify kinds of KYC information relating to a customer; including but not limited to the circumstances in which the reporting entity will collect, or collect and verify, information on the customer’s source of wealth and source of funds.

r 5-2(2), verbatim · Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (F2026C00274), Compilation No. 1
Minimum KYC information the AML/CTF Rules 2025 require, by customer type
Customer is sole traderr 6-1(2), verbatimCustomer is body corporate, partnership or unincorporated associationr 6-2(2), verbatim

the reporting entity must collect at least the following KYC information:

  1. a)the customer’s full name;
  2. b)any business name used for the conduct of the business;
  3. c)any other names the customer is commonly known by;
  4. d)a unique identifier for the business or, if none has been given, a unique identifier for the customer (if any has been given);
  5. e)the address of the principal place of business of the customer.

the reporting entity must collect at least the following KYC information:

  1. a)the customer’s full name;
  2. b)any business names of the customer;
  3. c)any other names the customer is commonly known by;
  4. d)a unique identifier for the customer (if any has been given);

Part 6 of the Rules also deals with trusts, government bodies, transferred customers and real estate transactions. These two cover most professional-services clients.

Sources

Every source on this page

This content is general information only. It is not legal, financial or compliance advice. Organisations should check AUSTRAC guidance, legislation, their own AML/CTF Program and professional advice where needed. Published by GetPost Labs Pty Ltd, a technology company building compliance software. Last checked against AUSTRAC’s published guidance on 12 September 2026. If you spot an error, tell us at australia@getpostlabs.io.

CDD that leaves a record

Lex-AML helps organise customer due diligence and supports the audit trail behind it — so the information you collected, the rating you gave and the reason for it are captured as you go. Your organisation makes the decisions.

Request demo access