AML Compliance Guide

Customer due diligence for Financial adviserss — 2026 AUSTRAC Guide

Customer due diligence means checking who your client is before you provide a designated service. For financial advisers, this matters because you may be arranging or providing a service that brings you within the AML/CTF regime from 1 July 2026, and AUSTRAC expects you to collect and verify the right client information before you act. If you get this wrong, you risk breaching federal law, exposing your practice to major penalties, and missing suspicious or sanctioned clients at the onboarding stage.

For a financial advice practice, customer due diligence is part of client onboarding, not a separate box-ticking exercise at the end. Before you provide a designated service, you must identify the client and verify key details using reliable sources. For an individual client, that means verifying their full name, date of birth and residential address against government-issued ID. If the client is a company, you need to verify its name, ACN or ABN and company type through ASIC. If the client is a trust, you need the trustee details, the trust deed and the beneficial owners. A beneficial owner is the natural person who owns 25% or more or exercises effective control.

What a financial adviser should do in practice

  • Work out whether the service you are about to provide is a designated service. Not every advice activity is caught, and some businesses that only arrange a designated service under item 54 have a narrower program requirement, but they still need initial customer due diligence.
  • Collect client information at the start of the engagement, before recommendations are implemented or transactions are arranged. Build this into your fact find, authority forms and onboarding pack.
  • Verify the client using reliable documents and data sources. For individuals, use government-issued ID. For companies, confirm ASIC details. For trusts, review the trust deed, trustee structure and who ultimately controls the trust.
  • Identify whether any beneficial owner, appointor, controller or related party is a politically exposed person or presents higher risk. Higher-risk clients need enhanced due diligence before you proceed.
  • Keep a clear record of what you collected, what you checked, when you checked it and who in your practice approved the onboarding.

Do it before you act

You must verify the identity of every customer before providing a designated service. Leaving ID checks until advice implementation, account establishment or fund movement is too late. If you are dealing with a sanctioned person, providing the service can be a strict-liability criminal offence, so sanctions screening also needs to happen before and during the relationship.

The most common mistake in advice practices is assuming existing know-your-client material is automatically enough. Your standard advice file may contain a driver licence, company extract or trust deed, but AML/CTF rules require you to verify the right information for the right legal customer and keep evidence that the check actually happened. Another frequent problem is treating the individual contact as the client when the real client is a company, family trust or SMSF-related structure behind the engagement. Where there is a trustee company, an appointor, or a person effectively controlling investments, you need to follow the ownership and control chain until you reach the relevant natural persons.

The easiest way to make this workable is to align CDD with your existing advice workflow. Add an AML/CTF check at the point you open the matter, before Statements of Advice are implemented, before product applications are lodged and before overseas money movements are arranged. Use separate onboarding paths for retail individuals, companies, family trusts and complex private groups. Have one escalation rule for anything unusual: source of funds that does not fit the client profile, unexplained third-party contributions, pressure to move funds internationally, or reluctance to provide trust or control documents. Those files should be reviewed by your AML/CTF compliance officer before the service goes ahead.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need to do customer due diligence for every advice client?
You need to do it before providing a designated service. Not every activity in a financial advice practice will be a designated service, so the first step is to map exactly which parts of your service offering are caught. If the service is designated, identity verification happens before you provide it.
Can I rely on the ID documents I already collect for advice file purposes?
Yes, if those documents let you verify the required AML/CTF information and you keep a record showing the verification was actually done. Many practices already collect passports, driver licences, ASIC extracts and trust documents, but they often do not record who checked them, when they were checked, or whether beneficial ownership was confirmed. Re-using existing information is efficient, but it still needs to meet the AML/CTF standard.
What if my client is a family trust with a corporate trustee?
You need to identify and verify the trustee company, review the trust deed, and identify the beneficial owners and controllers behind the structure. That may include directors, shareholders with 25% or more, and any person exercising effective control over the trust, such as an appointor. Do not stop at the company name alone.
Do I have to pay for electronic verification tools?
No. The law requires verification, not a particular vendor or platform. A small practice can use government-issued ID, ASIC searches and trust documents if the process is reliable and well documented, although electronic tools may save time where you onboard a higher volume of clients.
What if a long-term client refuses to provide updated documents?
If you cannot complete the required due diligence for the designated service, you should not proceed until the issue is resolved. A long-standing relationship does not replace verification, especially if the client now uses a company or trust structure, changes controllers, or wants unusual transactions arranged. Refusal to provide information can also be a risk indicator that needs escalation.