Services

Customer Due Diligence AML Australia

Customer due diligence (CDD) sits at the centre of every AML/CTF program. It enables you to identify your customers, verify who you are dealing with and assess the money laundering and terrorism financing risks they present. Getting CDD wrong is one of the most common reasons reporting entities fail an AUSTRAC review. 

At One AML, we help businesses design and implement practical customer due diligence processes that align with AUSTRAC requirements and can be applied consistently across day-to-day operations. Our approach helps you meet your compliance obligations while reducing the risk of errors and regulatory breaches.

Illustration showing a checklist with blue check marks connected by an arrow to two documents labeled 'AML/CTF Compliance Program' and 'AML/CTF Risk Assessment' on a dark background with a purple circle.

We’re proud to assist small to enterprise-scale businesses across all industry sectors.

What Is Customer Due Diligence?

Customer due diligence, often shortened to CDD, is the process of identifying and verifying your customers and assessing the ML/TF risk they present before and during the course of your business relationship. Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, reporting entities must conduct CDD before providing a designated service to a customer. 

CDD is not a one-off check. It continues throughout the relationship as customer behaviour, risk and circumstances change.

CDD generally involves:
  • Verifying the identity of your customer
  • Identifying beneficial owners where the customer is a company, trust or other legal arrangement
  • Screening customers against politically exposed persons (PEP) and sanctions lists
  • Assessing the ML/TF risk the customer presents
  • Applying an appropriate level of ongoing monitoring based on that risk

The Three Levels of Customer Due Diligence?

AUSTRAC expects reporting entities to apply CDD on a risk-based approach. Not every customer carries the same risk, and your CDD effort should reflect that.

Simplified Due Diligence: Applied to lower-risk customers where the ML/TF risk is assessed as low. This may involve a reduced level of identity verification and monitoring, though it must still meet minimum legislative requirements.

Standard Due Diligence
: The baseline level of CDD applied to most customers. This includes identity verification, beneficial ownership identification where relevant and standard ongoing monitoring.

Enhanced Due Diligence: Required for higher-risk customers, including politically exposed persons, customers from high-risk jurisdictions, complex ownership structures or customers whose behaviour raises concerns. Enhanced due diligence involves more detailed verification, closer monitoring and senior management sign-off in many cases.

Your risk assessment determines which customers fall into which category. If you do not yet have a documented risk assessment, this is the place to start. See our [AML Risk Assessment] page for more detail.

Who Needs to Conduct Customer Due Diligence?

Every reporting entity under the AML/CTF Act must conduct CDD on its customers before providing designated services. This applies across all regulated sectors, including businesses newly captured under the Tranche 2 reforms from 1 July 2026.

Sectors required to conduct CDD include:
  • Financial services providers
  • Remittance dealers and digital currency exchange providers
  • Lawyers and law firms
  • Accountants and bookkeepers
  • Real estate agents
  • Conveyancers
  • Trust and company service providers
  • High-value dealers in precious metals and stones

If you are a Tranche 2 entity, you need CDD processes operational by 1 July 2026, alongside the rest of your AML/CTF program.

Common CDD Mistakes Reporting Entities Make

We see the same issues come up repeatedly when reviewing AML/CTF programs. Avoiding these from the outset will save you significant rework later.

Our process includes:
  1. Applying the same level of due diligence to every customer regardless of risk
  2. Failing to identify beneficial owners behind companies and trusts
  3. Treating CDD as a one-time check rather than an ongoing process
  4. Not screening customers against PEP and sanctions lists at onboarding and on an ongoing basis
  5. Inadequate record-keeping of identity verification and risk assessments
  6. No clear escalation process when a customer's risk profile changes

An independent audit will often surface these gaps. Our Audit and Review service can identify where your current CDD process falls short.

How One AML Helps You Build Your CDD Process

We design customer due diligence frameworks that work in practice, not just on paper. Our approach is built around your customer base, your risk profile and how your business actually operates.

  • Risk-Based CDD Design: We build a CDD framework structured around simplified, standard and enhanced due diligence tiers, aligned to your risk assessment.
  • Identity Verification Procedures: We help you establish clear, compliant procedures for verifying individual and entity customers, including beneficial ownership identification.
  • PEP and Sanctions Screening: We advise on appropriate screening processes and tools to identify politically exposed persons and sanctioned individuals or entities at onboarding and throughout the relationship.
  • Ongoing Monitoring Framework: We design monitoring processes that flag changes in customer behaviour or risk, so your CDD stays current rather than static.
  • Documentation and Record-Keeping: We set up clear documentation standards so your CDD records meet the seven-year record-keeping requirement and stand up to AUSTRAC scrutiny.
  • Staff Training: We train your team to apply CDD procedures correctly and consistently across your customer base.

CDD as Part of Your Wider AML/CTF Program

Customer due diligence does not operate in isolation. It connects directly to your risk assessment, your transaction monitoring and your suspicious matter reporting obligations.

A properly designed CDD process:

  • Reflects the risk ratings established in your AML risk assessment
  • Feeds into your transaction monitoring thresholds and triggers
  • Supports timely and accurate Suspicious Matter Reporting
  • Gives your AML/CTF Compliance Officer the information needed to manage risk day to day

If you need your full AML/CTF program built or reviewed alongside your CDD process, see our [AML/CTF Program] and [Consulting and Advisory] pages.

Why Choose One AML for Customer Due Diligence Support?

We have helped over 1,000 reporting entities across Australia and New Zealand design and implement CDD processes that hold up under scrutiny. Our team understands the practical challenges of running CDD day to day, not just the legislative requirements behind it.

  • CDD frameworks tailored to your customer base and risk profile
  • Practical procedures your staff can actually apply consistently
  • Specialist knowledge across financial services, real estate, law, accounting and more
  • Support available from initial design through to ongoing advisory
  • 70+ verified Google reviews

We’re qualified to consult for all Phase 1 and 2 reporting entities across Australia.

Calculator and paperwork Icon

Accounting

The easy access and wide geographic spread of accounting services, coupled with accountants' gatekeeper role and use in every phase of ML/TF.
Piggy Bank Icon

Financial Services

Domestic and international evidence suggests that financial institutions are vulnerable to ML/TF. The Act. and regulations place obligations on Australian financial institutions to detect and deter ML/TF.
Scale Icon

Law

The easy access and wide geographic spread of legal services, coupled with lawyers’ gatekeeper role and use in every phase of ML/TF.
Certificate Icon

Other Captured Sectors

Other industries that are widely spread and easy to access by ML. The nature of these industries lends itself to all stages of ML/TF.
House Icon

Real Estate

The use of real estate in ML/TF is well-known and demonstrable. FIU research indicates real estate is the ML asset of choice.
Wallet Icon

Virtual Assets / Crypto

The easy access and wide geographic spread of VASP services, coupled with their pseudo-anonymous nature and use in every phase of ML/TF.

Frequently Asked Questions

What is the difference between Part A and Part B of an AML/CTF program?
Blue circular icon with a black question mark and upward arrow inside.
Part A covers your business-wide AML/CTF controls, including your risk assessment, policies and governance framework. Part B covers your customer due diligence procedures. Both parts are required under the AML/CTF Act.
How long does it take to build an AML/CTF program?
Blue circular icon with a black question mark and upward arrow inside.
It depends on the size and complexity of your business. For most small to mid-sized businesses, we can deliver a complete program within a few weeks of engagement. We recommend starting as early as possible, particularly if your obligations begin 1 July 2026.
Do I need an independent audit after my program is in place?
Blue circular icon with a black question mark and upward arrow inside.
Yes. The AML/CTF Act requires reporting entities to have their program independently reviewed at least every three years, or when requested by AUSTRAC. One AML also provides independent audit and review services.
Can One AML help if I already have a program but need it updated?
Blue circular icon with a black question mark and upward arrow inside.
Yes. We review and update existing AML/CTF programs to ensure they remain current with regulatory changes and reflect any changes to your business.

Build a CDD Process That Actually Works

Whether you are designing your customer due diligence process from scratch or fixing gaps in an existing one, One AML can help you get it right. Get in touch with our team today.