Customer Due Diligence AML Australia
Customer due diligence (CDD) sits at the centre of every AML/CTF program. It enables you to identify your customers, verify who you are dealing with and assess the money laundering and terrorism financing risks they present. Getting CDD wrong is one of the most common reasons reporting entities fail an AUSTRAC review.
At One AML, we help businesses design and implement practical customer due diligence processes that align with AUSTRAC requirements and can be applied consistently across day-to-day operations. Our approach helps you meet your compliance obligations while reducing the risk of errors and regulatory breaches.

We’re proud to assist small to enterprise-scale businesses across all industry sectors.









.png)

























.png)





What Is Customer Due Diligence?
Customer due diligence, often shortened to CDD, is the process of identifying and verifying your customers and assessing the ML/TF risk they present before and during the course of your business relationship. Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, reporting entities must conduct CDD before providing a designated service to a customer.
CDD is not a one-off check. It continues throughout the relationship as customer behaviour, risk and circumstances change.
CDD generally involves:
- Verifying the identity of your customer
- Identifying beneficial owners where the customer is a company, trust or other legal arrangement
- Screening customers against politically exposed persons (PEP) and sanctions lists
- Assessing the ML/TF risk the customer presents
- Applying an appropriate level of ongoing monitoring based on that risk
The Three Levels of Customer Due Diligence?
AUSTRAC expects reporting entities to apply CDD on a risk-based approach. Not every customer carries the same risk, and your CDD effort should reflect that.
Simplified Due Diligence: Applied to lower-risk customers where the ML/TF risk is assessed as low. This may involve a reduced level of identity verification and monitoring, though it must still meet minimum legislative requirements.
Standard Due Diligence: The baseline level of CDD applied to most customers. This includes identity verification, beneficial ownership identification where relevant and standard ongoing monitoring.
Enhanced Due Diligence: Required for higher-risk customers, including politically exposed persons, customers from high-risk jurisdictions, complex ownership structures or customers whose behaviour raises concerns. Enhanced due diligence involves more detailed verification, closer monitoring and senior management sign-off in many cases.
Your risk assessment determines which customers fall into which category. If you do not yet have a documented risk assessment, this is the place to start. See our [AML Risk Assessment] page for more detail.
Who Needs to Conduct Customer Due Diligence?
Every reporting entity under the AML/CTF Act must conduct CDD on its customers before providing designated services. This applies across all regulated sectors, including businesses newly captured under the Tranche 2 reforms from 1 July 2026.
Sectors required to conduct CDD include:
- Financial services providers
- Remittance dealers and digital currency exchange providers
- Lawyers and law firms
- Accountants and bookkeepers
- Real estate agents
- Conveyancers
- Trust and company service providers
- High-value dealers in precious metals and stones
If you are a Tranche 2 entity, you need CDD processes operational by 1 July 2026, alongside the rest of your AML/CTF program.
Common CDD Mistakes Reporting Entities Make
We see the same issues come up repeatedly when reviewing AML/CTF programs. Avoiding these from the outset will save you significant rework later.
Our process includes:
- Applying the same level of due diligence to every customer regardless of risk
- Failing to identify beneficial owners behind companies and trusts
- Treating CDD as a one-time check rather than an ongoing process
- Not screening customers against PEP and sanctions lists at onboarding and on an ongoing basis
- Inadequate record-keeping of identity verification and risk assessments
- No clear escalation process when a customer's risk profile changes
An independent audit will often surface these gaps. Our Audit and Review service can identify where your current CDD process falls short.
How One AML Helps You Build Your CDD Process
We design customer due diligence frameworks that work in practice, not just on paper. Our approach is built around your customer base, your risk profile and how your business actually operates.
- Risk-Based CDD Design: We build a CDD framework structured around simplified, standard and enhanced due diligence tiers, aligned to your risk assessment.
- Identity Verification Procedures: We help you establish clear, compliant procedures for verifying individual and entity customers, including beneficial ownership identification.
- PEP and Sanctions Screening: We advise on appropriate screening processes and tools to identify politically exposed persons and sanctioned individuals or entities at onboarding and throughout the relationship.
- Ongoing Monitoring Framework: We design monitoring processes that flag changes in customer behaviour or risk, so your CDD stays current rather than static.
- Documentation and Record-Keeping: We set up clear documentation standards so your CDD records meet the seven-year record-keeping requirement and stand up to AUSTRAC scrutiny.
- Staff Training: We train your team to apply CDD procedures correctly and consistently across your customer base.
CDD as Part of Your Wider AML/CTF Program
Customer due diligence does not operate in isolation. It connects directly to your risk assessment, your transaction monitoring and your suspicious matter reporting obligations.
A properly designed CDD process:
- Reflects the risk ratings established in your AML risk assessment
- Feeds into your transaction monitoring thresholds and triggers
- Supports timely and accurate Suspicious Matter Reporting
- Gives your AML/CTF Compliance Officer the information needed to manage risk day to day
If you need your full AML/CTF program built or reviewed alongside your CDD process, see our [AML/CTF Program] and [Consulting and Advisory] pages.
Why Choose One AML for Customer Due Diligence Support?
We have helped over 1,000 reporting entities across Australia and New Zealand design and implement CDD processes that hold up under scrutiny. Our team understands the practical challenges of running CDD day to day, not just the legislative requirements behind it.
- CDD frameworks tailored to your customer base and risk profile
- Practical procedures your staff can actually apply consistently
- Specialist knowledge across financial services, real estate, law, accounting and more
- Support available from initial design through to ongoing advisory
- 70+ verified Google reviews
We’re qualified to consult for all Phase 1 and 2 reporting entities across Australia.
Accounting
Financial Services
Law
Other Captured Sectors
Real Estate
Virtual Assets / Crypto
Frequently Asked Questions




Build a CDD Process That Actually Works
Whether you are designing your customer due diligence process from scratch or fixing gaps in an existing one, One AML can help you get it right. Get in touch with our team today.
