Customer due diligence checklist for Australian accounting firms
Customer due diligence is one of the core practical obligations for accounting firms that provide designated services under the AML/CTF regime.
It is not simply an identity check. The purpose is to know who the customer is, understand who is behind the customer, identify relevant financial crime risk and establish enough information to decide whether the service can be provided and what controls are required.
This checklist is designed as a working prompt for accounting firms. It should be adapted to the firm's AML/CTF program and used with AUSTRAC's current guidance.
Published 23 August 2026. Last reviewed 23 August 2026. Technically reviewed by the Taxpartna tax team.
Before starting the checklist
First confirm that the engagement involves a designated service.
If the service is not designated, the AML/CTF customer due diligence obligations may not apply to that work, although the firm may still have TPB, professional, privacy and ordinary client acceptance requirements. Our page on which accounting services are designated services can help with that step.
If the service is designated, identify the customer and the relevant customer type before selecting the evidence to collect.
Core CDD checklist
1. Identify the customer
- Record the customer's full legal name.
- Record any trading or business names relevant to the engagement.
- Record the customer's entity type.
- Record the ABN, ACN or other registration details where applicable.
- Confirm the address and other identifying information required by the firm's procedure.
- Identify whether the customer is new or a pre-commencement customer.
2. Identify any person acting on behalf of the customer
- Record the person's identity.
- Establish their authority to act for the customer.
- Verify the authority using the evidence required by the firm's program.
- Consider whether the person's role is consistent with the customer structure and the service requested.
3. Identify beneficial owners where required
For non-individual customers:
- identify the natural persons who meet the relevant beneficial ownership or control tests
- trace ownership through intermediate entities where required
- record the basis on which each beneficial owner was identified
- resolve unexplained differences between the structure chart, ASIC information, trust documents and client instructions
- escalate structures where ownership or control cannot be satisfactorily established
4. Establish PEP status
Consider the customer and other persons who must be checked under the firm's AML/CTF procedure.
- Has the relevant person been identified as a politically exposed person?
- Is the PEP foreign, domestic or connected with an international organisation?
- Is a family member or close associate relevant?
- Does the result change the customer's risk rating?
- Is senior management approval required?
- Are source of funds and source of wealth checks required?
Keep a record of how the PEP conclusion was reached.
5. Check targeted financial sanctions
- Complete the required sanctions screening.
- Confirm the name and identifying information used in the search.
- Review potential matches rather than relying on name similarity alone.
- Escalate a possible true match immediately under the firm's procedure.
- Keep evidence of the search and the conclusion.
6. Understand the nature and purpose of the relationship
Record why the customer is engaging the firm and what the designated service is intended to achieve.
Questions may include:
- What transaction or structure is proposed?
- Why is it being undertaken now?
- Who are the other parties?
- What jurisdictions are involved?
- How will the transaction be funded?
- Is the requested service consistent with what the firm knows about the customer?
A short, specific note is more useful than a generic statement such as "tax and accounting services".
7. Assess customer risk
Apply the firm's documented risk methodology.
Relevant factors may include:
- customer type
- service type
- ownership complexity
- foreign jurisdictions
- PEP status
- sanctions exposure
- unusual or opaque funding
- delivery channel
- use of intermediaries
- adverse information that is relevant and reliable
- behaviour inconsistent with the stated purpose of the engagement
Record the risk rating and why it was assigned.
8. Complete enhanced due diligence where required
If the risk or circumstances require enhanced CDD:
- identify the specific risk that triggered the enhanced process
- collect the additional information required by the firm's policy
- verify additional information using reliable and independent material where required
- consider source of funds and source of wealth
- obtain required senior approval
- document the final decision to commence or continue the relationship
9. Decide whether the customer can be onboarded
The onboarding decision should be clear.
Record whether the customer is:
- approved
- approved subject to additional controls
- referred for senior review
- declined
If the decision is conditional, record the condition and who is responsible for it.
10. Set the ongoing monitoring requirement
For ongoing relationships, record:
- the review frequency or trigger events
- which changes require refreshed information
- how transaction or activity monitoring will occur where relevant
- how staff should escalate unusual activity
Customer-specific prompts
Individuals
Consider:
- full name and date of birth
- residential address
- reliable identity documents or data
- citizenship or jurisdictional factors where relevant
- person acting on behalf of the individual
- PEP and sanctions status
- purpose of the designated service
- source of funds or wealth where required
Companies
Consider:
- registered company details
- directors and relevant officeholders
- ownership chain
- ultimate beneficial owners
- persons authorised to instruct the firm
- business activities
- registered office and principal place of business
- PEP and sanctions status of relevant persons
- consistency between ASIC records, group charts and client instructions
Trusts
Trusts often require more care because legal ownership, control and beneficial interests are spread across different roles.
Consider:
- trust name and type
- trust deed and amendments
- trustee identity
- corporate trustee ownership and directors
- appointor or principal roles where relevant
- beneficiaries or classes of beneficiaries relevant to the CDD rules
- persons exercising practical control
- purpose of the trust and the proposed transaction
- PEP and sanctions status of relevant persons
Do not rely on the trust name alone as evidence of who controls the arrangement.
Partnerships
Consider:
- partnership agreement or other evidence of the arrangement
- partners and ownership interests
- persons authorised to act
- beneficial owners where required
- business activities and purpose of the service
- PEP and sanctions status of relevant persons
Foreign entities
Foreign entities can require additional work simply because Australian databases may not provide enough evidence.
Consider:
- country of formation
- foreign registry records
- ownership chain
- beneficial owners
- local identification documents
- translations where required
- higher-risk jurisdictions
- sanctions exposure
- whether independent verification is reasonably available
What good CDD documentation looks like
A good CDD file lets another experienced person understand the process without having to recreate it.
It should show:
- 1who was identified
- 2what evidence was used
- 3what screening was completed
- 4what risk factors were identified
- 5how the risk rating was reached
- 6what extra work was completed for higher-risk matters
- 7who approved the relationship
- 8what ongoing monitoring was set
The record should also make missing information visible. If a required fact could not be established, that should not disappear into an unchecked box.
Where Taxpartna fits
Taxpartna can assist the CDD and risk assessment process by organising information relevant to beneficial ownership, PEPs, sanctions, industry risk and adverse media.
The value is not simply producing more information. It is helping the practitioner see the information in a structured form so it can be assessed consistently.
Taxpartna does not verify every element of customer identity, replace the firm's AML/CTF program or decide whether a customer should be accepted.
The firm remains responsible for applying its procedures and reaching the final decision. See also our AML/CTF obligations guide for accountants and AML/KYC vs TPB client verification.
Authoritative sources
Customer due diligence requirements depend on the AML/CTF Act, Rules and AUSTRAC guidance. The following primary sources should be checked when this page is technically reviewed or materially updated.
- AUSTRAC - Initial customer due diligence
- AUSTRAC - Politically exposed persons (PEPs)
- AUSTRAC - Accountants
Frequently asked questions
The terms are often used together. Under the AML/CTF framework, customer due diligence is the broader process of identifying the customer, understanding relevant ownership and control, assessing risk and completing additional checks where required.
Important information. This checklist is general information and is not a substitute for the AML/CTF Act, Rules or AUSTRAC guidance. Firms should tailor their CDD procedure to their own services, customers and risk profile. Taxpartna is a quality assurance assistance platform and does not provide legal advice, tax agent services or AML/CTF compliance certification.
