AML/CTF for Accountants

AML/KYC vs TPB client verification: what accounting firms need to do

Australian accounting firms can now have two quite different reasons for verifying a client.

Registered tax practitioners already have client verification obligations and procedures designed to protect the tax system and make sure they are dealing with the correct client or authorised representative.

From 1 July 2026, firms that provide designated services under the AML/CTF regime can also have customer due diligence obligations directed to money laundering, terrorism financing and proliferation financing risk.

There is overlap between the two processes, but they are not interchangeable. A firm can sensibly collect information once and use it across its compliance systems where the law permits. It should still be clear about which obligation each step is intended to satisfy.

Published 23 August 2026. Last reviewed 23 August 2026. Technically reviewed by the Taxpartna tax team.

The short version

TPB client verification asks, in practical terms, whether the tax practitioner is dealing with the right person and has appropriately verified the client's identity for the tax service.

AML/CTF customer due diligence goes further. It is designed to help a reporting entity understand who the customer really is, who owns or controls them, who may be acting for them, the purpose of the relationship and the financial crime risk presented by the customer and service.

That difference is why a driver's licence check alone is not an AML program. Our AML/CTF obligations guide for accountants sets out the wider framework.

Side-by-side comparison

AreaTPB client verificationAML/CTF customer due diligence
Main purposeProtect integrity of tax agent services and confirm client identityIdentify and manage money laundering, terrorism financing and proliferation financing risk
Applies toRegistered tax practitioners in relevant circumstancesReporting entities providing designated services
Identity verificationYesYes
Person acting for clientAuthority and identity can be relevantIdentity and authority are expressly relevant to CDD
Beneficial ownershipMay be relevant to the tax engagementA core area for non-individual customers
Customer risk ratingNot the same risk-based AML requirementRequired as part of the AML/CTF risk framework
PEP checksNot a general TPB identity verification stepRelevant under AML/CTF CDD
Targeted financial sanctionsNot a general TPB identity verification stepRelevant under AML/CTF CDD
Source of funds / wealthNot a normal TPB identity requirementCan be required depending on risk and circumstances
Ongoing monitoringTax practitioner obligations continue over the engagementOngoing CDD can require monitoring of changes and activity
Suspicious matter reportingNo equivalent TPB processCan arise under the AML/CTF regime

Why the same identity document can serve different purposes

Suppose an individual client gives the firm a passport.

For the tax engagement, the passport may form part of the evidence used to confirm that the practitioner is dealing with the correct client.

For AML/CTF, the same document may also support identity verification, but the firm may still need to consider other matters. If the customer is acting through a company or trust, the firm may need to understand ownership and control. It may need to establish whether relevant people are PEPs or sanctioned. The nature and purpose of the designated service also matter.

The document is the same. The compliance question is different.

Beneficial ownership is a major difference

One of the areas most likely to require additional work is beneficial ownership.

For a company, the person named as the client contact is not necessarily the person who ultimately owns or controls the entity.

For a trust, the legal and practical control position can involve trustees, appointors, beneficiaries and other relevant persons depending on the structure and the applicable CDD rules.

The AML process is intended to look through the customer structure so the reporting entity understands the people behind it.

A firm should not assume that information already held in its tax software is complete enough for this purpose without checking it.

PEP and sanctions screening are not ordinary tax identity checks

AML/CTF customer due diligence includes establishing whether relevant people are politically exposed persons and whether targeted financial sanctions apply.

A PEP is not automatically a prohibited customer. The result affects the firm's risk analysis and can trigger additional procedures.

A sanctions issue is more serious and should be dealt with under the firm's sanctions and escalation procedure.

These are financial crime controls. They are not simply additional fields on a tax agent identity form.

Customer risk is also different from engagement risk

Accounting firms already think about client risk in several ways.

A tax client might be high risk because their records are poor, their tax affairs are complex or they have a history of late lodgement. Those matters may be important to the engagement, but they are not necessarily the same as money laundering and terrorism financing risk.

An AML customer risk assessment looks at factors relevant to financial crime risk, such as:

  • the type of designated service
  • ownership and control complexity
  • countries and jurisdictions involved
  • delivery channel
  • transaction features
  • unusual funding arrangements
  • PEP or sanctions exposure
  • information that does not fit the customer's known circumstances

A firm can use a single client acceptance workflow, but the AML risk assessment should remain identifiable within it.

Can firms combine the two processes?

Yes, operationally this will often make sense.

A firm might design one onboarding workflow that collects:

  1. 1identity information required for the tax engagement
  2. 2authority information for people acting on behalf of the client
  3. 3ownership and control information
  4. 4AML/KYC screening results
  5. 5customer risk assessment
  6. 6engagement acceptance approval

The advantage is that staff do not need to ask the client for the same information twice.

The risk is that the firm compresses everything into a generic "ID complete" checkbox and loses sight of the different obligations.

The workflow should show what was checked and why.

Existing clients create a practical challenge

A firm may have verified a client's identity years ago for tax purposes and still need to consider what AML/CTF due diligence is required when providing a designated service.

AUSTRAC has specific rules for pre-commencement customers, including circumstances where initial CDD can be triggered later.

The correct approach is not necessarily to re-identify every existing tax client on the same day. It is to identify which clients receive designated services, determine how the transitional rules apply and then follow the firm's AML/CTF program.

Where Taxpartna fits

Taxpartna's AML/KYC screening is designed to assist the firm's risk and review process by bringing together information relevant to matters such as beneficial ownership, PEPs, sanctions, industry risk and adverse media.

That information can sit alongside the identity information the firm already obtains through its tax practice procedures.

Taxpartna does not replace the firm's TPB client verification procedure or its AML/CTF program. It is a supporting control that can reduce the manual work involved in gathering and reviewing relevant information.

The firm remains responsible for deciding whether the evidence is sufficient, assessing the customer risk and taking any required action. For related tax practitioner guidance, see TPB AI guidance for tax practitioners.

A sensible combined onboarding record

For a client receiving a designated service, the file should make it easy to see:

  • who the customer is
  • how identity was verified
  • who is authorised to act
  • who the beneficial owners are, where relevant
  • the PEP and sanctions outcome
  • the purpose of the designated service
  • the AML customer risk rating
  • any enhanced checks completed
  • any issues escalated
  • who approved onboarding or continuation

That is more useful than a single line saying "KYC done".

Authoritative sources

Client verification and customer due diligence requirements depend on current TPB and AUSTRAC guidance. The following primary sources should be checked when this page is technically reviewed or materially updated.

Frequently asked questions

No. There is overlap in identity information, but the regimes have different purposes and AML/CTF customer due diligence includes broader financial crime risk requirements.

Often the same documents can support both processes where they meet the relevant requirements. The firm still needs to complete the additional steps required for each regime. See our customer due diligence checklist for accounting firms.

Not simply because they are a tax client. AML/CTF obligations depend on whether the firm is a reporting entity providing a designated service and on the rules applying to the customer relationship.

No. Taxpartna can assist with AML/KYC screening and risk information. The firm remains responsible for its identity verification and customer due diligence procedures.

Important information. This page provides general information only. It is not legal advice and does not replace the TPB's or AUSTRAC's current requirements. Firms should design procedures that reflect the services they provide and obtain advice where necessary. Taxpartna is a quality assurance assistance platform and does not provide legal advice, tax agent services or AML/CTF compliance certification.