Ongoing Customer Due Diligence: What It Means in Practice for Australian Businesses

Professional header image for step-by-step guide: Ongoing Customer Due Diligence: What It Means in Practice...

Most Australian businesses treat customer verification as a box to tick at onboarding and never revisit. That assumption is not just operationally risky; it is legally wrong.

Under Australia's Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) framework, customer due diligence requirements extend far beyond the initial identity check. Ongoing monitoring is a continuous legal obligation, one that follows every customer relationship from first engagement through to its end. For reporting entities already navigating AUSTRAC compliance, and for the thousands of businesses entering the regulatory perimeter under Tranche 2 reforms in 2026, understanding what "ongoing" actually means in practice is no longer optional.

This guide moves beyond definitions. It explains what triggers a CDD review, how frequently different customer types should be assessed, what records you are required to keep, and how enhanced due diligence applies to higher-risk relationships. It also covers how to bring legacy customers into your compliance framework without disrupting existing relationships, and where automation can make the entire process manageable at scale. Whether you are refining an established program or building one from scratch, this is where to start.

What Ongoing Customer Due Diligence Actually Means Under Australian Law

Many Australian businesses treat customer due diligence as an onboarding formality: verify identity, tick the box, move on. Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), that approach creates a gap in ongoing compliance obligations from the moment the customer relationship begins.

AUSTRAC treats ongoing customer due diligence as a distinct, continuous legal obligation, separate from the initial verification carried out at onboarding. Completing KYC when a customer first engages with your business satisfies one requirement. It does not satisfy the other. Both obligations exist independently under the Act, and both must be met.

The customer relationship lifecycle, for AUSTRAC's purposes, runs from the first point of engagement through to exit. Every stage carries monitoring obligations. A customer's risk profile can shift materially after onboarding, through changes in transaction behaviour, ownership structure, jurisdiction exposure, or politically exposed person (PEP) status. Your program must be capable of detecting and responding to those changes, not just recording what was true on day one.

Who this applies to is any reporting entity with AUSTRAC obligations, including financial services, remittance providers, bullion dealers, and gambling operators currently in scope. From 2026, Tranche 2 reforms extend those obligations to real estate agents, accountants, lawyers, precious metal dealers, and virtual asset service providers. If your business is preparing for registration, the ongoing CDD obligation begins at registration, not after a grace period.

AUSTRAC expects reporting entities to maintain three interacting components across the customer lifecycle:

  • Transaction monitoring: identifying activity that deviates from a customer's expected behaviour or stated purpose

  • Risk profile reviews: reassessing each customer's risk rating when circumstances change or scheduled review intervals are reached

  • Customer identification updates: refreshing identity and verification information when it becomes outdated or when a review surfaces new information

These components do not operate in isolation. A transaction monitoring alert may trigger a risk profile review; a risk profile review may reveal that stored identification records are no longer current and require updating. The three functions feed each other.

If your business is approaching registration or building out its AML program, begin completing Customer Due Diligence as a structured starting point before your first AUSTRAC examination.

What Triggers a Customer Due Diligence Review

Knowing that ongoing CDD is a continuous obligation is one thing; knowing what actually kicks off a review is where compliance programs either hold together or fall apart. Four practical categories of trigger emerge from AUSTRAC's risk-based framework, and your AML/CTF program must account for all of them.

Event-driven triggers arise when a customer's transaction behaviour deviates materially from their stated purpose or expected activity pattern. A retail customer who suddenly processes high-value international transfers, or a business client whose transaction volumes spike without a corresponding change in their operating profile, are textbook AUSTRAC ongoing CDD flags. The deviation itself is the trigger, regardless of whether a scheduled review is due.

Regulatory and intelligence triggers are externally generated. When AUSTRAC issues a financial intelligence alert, when a sanctioned party is added to a relevant watchlist, or when a customer is identified as a politically exposed person (PEP) after onboarding, a review is required immediately. Waiting for a scheduled review cycle in these circumstances is not compliant.

Relationship-change triggers apply when the nature of the customer relationship itself changes. A change in beneficial ownership, a corporate restructuring, the addition of a new authorised representative, or a customer moving into a higher-risk product or service all require the risk profile to be reassessed. The change is the trigger, not a lapse of time.

Time-based triggers operate differently. AUSTRAC does not prescribe a single universal review frequency; it requires a risk-calibrated schedule tied to each customer's assigned risk rating. High-risk customers are reviewed more frequently than standard-risk customers. The cadence comes from your documented AML/CTF program, not from a one-size-fits-all calendar.

For Tranche 2 businesses, real estate agents, accountants, precious metal dealers, and legal practitioners registering under the 2026 reforms will hold legacy customer bases that were never formally assessed under AML/CTF criteria, and every one of those existing relationships represents a pending trigger to be worked through systematically. The transition section below addresses how to work through that backlog in practice.

Understanding what triggers a review sets the foundation for the next question: once a trigger fires, how often should each customer actually be reviewed?

How Often Should You Review Each Customer

Once you know what triggers a review, the next question is how often reviews should happen in the first place. AUSTRAC does not set a universal calendar cadence. Instead, it requires a risk-based approach, meaning review frequency must be proportionate to each customer's assigned risk rating.

Typical cadences by risk tier:

  • High-risk customers (including those subject to enhanced customer due diligence): high-risk customers typically warrant more frequent review, often within a twelve-month window, with closer transaction monitoring between formal reviews

  • Standard-risk customers: may be reviewed less frequently, depending on the nature of the relationship and product exposure

  • Low-risk customers: reviewed less frequently still, though the rationale for that classification must still be documented

Your documented AML/CTF program should define these intervals explicitly. These are not regulatory mandates for specific timeframes; they reflect what proportionate compliance looks like in practice for most reporting entities.

Risk ratings are not permanent. A customer assessed as standard risk at onboarding can become high risk when their transaction behaviour shifts, a beneficial owner changes, or new adverse information emerges. When that happens, an immediate out-of-cycle review is required. Waiting until the next scheduled review date is not compliant. High-risk client screening should be capable of surfacing those changes as they occur, not only on a schedule.

Your AML/CTF program must codify the schedule. Frequency decisions cannot be left to individual judgement or resolved case by case. Your documented policies must specify exactly how each risk tier maps to a monitoring interval. This gives reviewers clear instructions, creates an auditable standard, and prevents gaps when staff change.

The higher the assessed risk, the more frequently that scrutiny must be applied. Enhanced CDD is covered in detail in the next section, but the key point here is structural: it belongs in your risk-tier-to-frequency mapping as a named category with its own schedule, not treated as an ad hoc escalation.

Enhanced Customer Due Diligence: When and How It Applies

When a customer's risk profile crosses a certain threshold, standard CDD is no longer sufficient. Enhanced customer due diligence is a mandatory escalation under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, not a discretionary step a reporting entity can choose to skip.

What Triggers Enhanced CDD

Four categories consistently require the heightened standard:

  • Politically exposed persons (PEPs) and their close associates. AUSTRAC designates PEPs as a primary trigger given their elevated exposure to bribery and corruption risk.

  • High-risk jurisdictions. Customers with connections to countries identified on FATF grey or black lists, or on Australian autonomous sanctions lists.

  • Complex or opaque ownership structures. Layered corporate arrangements, discretionary trusts, or structures where beneficial ownership is difficult to establish.

  • Unusual or high-value transaction activity. Volumes or patterns that are inconsistent with the customer's stated business purpose or expected profile.

What 'Enhanced' Means in Practice

Enhanced CDD is not simply a more thorough version of the same checklist. Operationally, it requires:

  • Additional identity verification, beyond standard documentation

  • Source-of-funds and source-of-wealth documentation

  • Senior management sign-off before the relationship proceeds or continues

  • Shorter review intervals than standard-risk customers

  • Closer transaction monitoring calibrated to the specific risk indicators present

Every one of these steps must be recorded. A practical starting point for structuring these obligations is the practical guide to CDD, which covers documentation standards alongside verification requirements.

Enhanced CDD Is Not Permanent

If the circumstances that triggered enhanced CDD change, a reporting entity can step a customer back to standard CDD. Risk reduction must be genuine and evidenced; the decision to downgrade must be documented with the same rigour as the original escalation decision, including the rationale, the reviewer's name, and the date.

The Link to Suspicious Matter Reporting

Enhanced scrutiny sometimes surfaces information that goes beyond a risk rating adjustment. If the review uncovers indicators of money laundering or terrorism financing, the reporting entity has an independent legal obligation to lodge a Suspicious Matter Report with AUSTRAC. That obligation exists regardless of whether the business chooses to continue or exit the customer relationship.

What Records You Must Keep and How to Structure Them

Whether you are running standard CDD or enhanced scrutiny, every review decision needs to live somewhere retrievable, attributable, and self-explanatory.

Best practice, consistent with AUSTRAC's risk-based approach, is to record the reasoning behind each decision, not just the outcome. A note that reads "customer reviewed, no issues" does not meet this standard. The record must explain what information was examined, what risk indicators were considered, and why the conclusion was reached.

Every ongoing CDD file should contain, at minimum:

  • The date the review was conducted

  • The customer's risk rating at the time of review

  • What information was collected or verified during the review

  • Any changes made to the risk profile, and the basis for those changes

  • The full name of the person who conducted the review

Retention period

Records must be kept for the statutory retention period prescribed under the AML/CTF Act and Rules. Verify the applicable retention period against the AML/CTF Act and Rules, as the period may vary by record type. This applies to customer identification records, transaction records, and the documentation of each ongoing CDD review.

The audit trail standard

AUSTRAC examiners apply a practical test: can a reviewer reconstruct the compliance decision without asking anyone? If the answer requires a staff member to explain what they meant or recall context from memory, the documentation has failed. Records must be self-contained. Each CDD file should read as a standalone account of the compliance decision made at that point in time.

This matters beyond examinations. If you are ever required to file a suspicious matter report and need to act quickly, a well-structured CDD file enables faster, more accurate reporting.

Common documentation weaknesses that examinations tend to surface include:

  • Generic review notes with no customer-specific detail

  • Missing or inconsistent dates on review records

  • Records stored across disconnected systems, making retrieval slow under examination pressure

  • Review decisions that cannot be attributed to a named individual

Each of these is avoidable. The practical fix is a standardised review template applied consistently across every customer file, stored in a single location where records can be retrieved by customer, date, or reviewer without manual searching.

Bringing Legacy Customers into Your CDD Framework

Bringing Legacy Customers into Your CDD Framework

Good documentation tells you what was decided. A transition plan tells you what still needs to be done. For businesses with established customer bases, those are two separate problems.

AUSTRAC's transitional framework acknowledges the practical reality: no reporting entity can instantly bring every existing customer into full CDD compliance. The AML/CTF Transitional Rules, in effect from 31 March 2026, provide structured timeframes for initial CDD obligations, giving existing entities until 30 March 2029 to complete that transition. Critically, ongoing CDD is not deferred. It applies immediately from 31 March 2026, regardless of where a customer sits in your transition queue.

That distinction shapes how you prioritise.

Sequence by Risk, Not by Convenience

The operationally sound approach, and the one consistent with AUSTRAC's risk-based framework, is to sequence your legacy customer reviews from highest estimated risk downward. Start with customers who have PEP indicators, complex ownership structures, high transaction volumes, or connections to higher-risk jurisdictions. Work toward lower-risk, straightforward relationships last.

This is not just regulatory best practice. For businesses managing hundreds of existing customers, it ensures the relationships that pose the greatest ML/TF exposure are addressed first, regardless of how long the full transition takes.

Four Steps for a Legacy Transition Program

  1. Segment your existing customer base by estimated risk tier, using the information you already hold. Account for transaction history, customer type, jurisdiction, and any earlier risk flags.

  2. Assign a target review date to each segment, not each individual customer. This makes the workload schedulable and auditable.

  3. Document the segmentation methodology in writing. AUSTRAC examiners need to see how you made prioritisation decisions, not just that you made them.

  4. Track completion against those target dates. A simple register showing segment, target date, and completion status satisfies the audit trail requirement for the transition process itself.

Existing Relationships Do Not Need to Be Paused

A common concern among businesses, particularly those in professional services with long-standing client relationships, is that compliance obligations will force them to pause or exit those relationships during transition. The transitional rules are designed to prevent exactly that. Phased, proportionate compliance is the intent.

Tranche 2 Businesses: Plan From Day One

For real estate agents, accountants, lawyers, and precious metal dealers registering from 1 July 2026, there is no grace period on planning. The transition obligation is immediate upon registration. Before you onboard your first customer under AUSTRAC obligations, you need a documented methodology for reviewing the clients you already have. The Tranche 2 compliance checklist is a practical starting point for building that plan.

Making Ongoing CDD Scalable: Where Automation Fits In

Manual processes can hold together for a small customer base, but as customer numbers grow, the structural limitations of spreadsheets and calendar reminders become apparent: reviews slip, documentation varies by staff member, and undocumented context disappears when people leave. Compliance gaps at that scale are not a sign of bad intentions; they are a structural feature of manual processes applied to volumes they were never designed to handle.

What automation replaces, specifically:

  • Continuous sanctions screening runs against updated watchlists in real time, rather than waiting for a scheduled manual check

  • Automated PEP re-checks trigger whenever a monitored watchlist is updated, not just at annual review

  • Transaction pattern alerts are calibrated against each customer's individual baseline, so a deviation flags against their expected activity, not a generic threshold that misses nuanced risk

The distinction between generic and baseline-specific alerting matters for AUSTRAC customer due diligence compliance. A business customer who regularly transacts at $80,000 should not trigger the same alert profile as one whose stated purpose implies $8,000 transactions.

A centralised platform changes the audit trail problem. When KYC, KYB, sanctions screening, and ongoing monitoring records sit in separate systems, compiling documentation for an AUSTRAC examination means cross-referencing multiple sources under time pressure. A platform like Personr consolidates these into a single, audit-ready record per customer, where every review, screening result, and risk rating change is logged against a timestamp and a user. To monitor ongoing risks effectively at scale, that consolidated record is the operational foundation, not a reporting convenience.

Automated review scheduling closes the cadence gap. Rather than managing a flat calendar, systems assign review intervals based on the risk tier set at onboarding or last review. A high-risk customer triggers a review at six months; a standard-risk customer at twelve or twenty-four. The schedule adjusts when the risk rating changes, not on the next calendar cycle.

AUSTRAC's risk-based compliance framework is clear that proportionate, structured tools are expected of all reporting entities, including SMBs, and automation is the practical mechanism for meeting that expectation at scale.

Sector-Specific Considerations for Tranche 2 Businesses

Automation addresses how you monitor. Sector context determines what you are actually watching for, and that distinction matters when configuring any CDD program.

Real estate agents face some of the most structurally complex ongoing CDD obligations under Tranche 2. High-value property transactions frequently involve trusts, companies, and layered ownership arrangements, making beneficial ownership verification the centrepiece of every review. The monitoring obligation does not end at settlement. Repeat clients whose purchasing frequency, transaction size, or ownership structures shift over time can trigger a full CDD review even when their identity has already been verified. Each new engagement is a potential trigger, not a continuation of a prior clearance.

Accountants and legal practitioners are navigating what the Law Society of NSW has acknowledged as triggering substantive operational change for legal practices. The critical distinction for professional services is that ongoing CDD attaches to the engagement, not just the client. A long-standing client who instructs their accountant or solicitor to facilitate a new type of transaction, or whose instructions change in character, requires fresh scrutiny. Identity is already known; the monitoring focus is on the nature of the instructions received and whether they remain consistent with the client's stated purpose. Firms building their AML/CTF programs should note that Personr's integration with legal services providers reflects precisely this engagement-level monitoring need.

Precious metals and virtual asset dealers operate in sectors where anonymity risk is structurally higher than in most other designated service categories. Transaction-level monitoring is not supplementary here; it is the core mechanism. A single transaction that exceeds the relevant threshold or deviates from a customer's documented purpose may itself constitute a CDD trigger requiring immediate review and documentation, independent of any scheduled periodic review cycle.

Across all four Tranche 2 sectors, the legal requirements share the same statutory foundation. What diverges is the practical focus: beneficial ownership in real estate, instruction monitoring in professional services, and transaction deviation in high-anonymity sectors. Sector-specific AML/CTF program templates must reflect these differences explicitly; a generic template will satisfy none of them adequately.

Businesses with exposure across multiple Tranche 2 designations face compounded obligations. The efficient response is a unified CDD framework configured by service line rather than a separate program for each regulated activity. This structure reduces duplication, maintains consistent documentation standards, and allows trigger logic to be calibrated to each service type without building and maintaining entirely separate compliance architectures.

Turning an Ongoing Obligation into a Manageable Process

Regardless of sector, the compliance challenge ultimately comes down to operationalisation: building a process that runs consistently, documents itself, and holds up under scrutiny.

Ongoing CDD is not a box you tick at onboarding and revisit only when something goes wrong. It is a continuous operational commitment requiring documented triggers, risk-calibrated review schedules, and an audit-ready record for every customer in scope. AUSTRAC examiners do not want to see that you completed reviews; they want to see that you completed the right reviews, at the right frequency, with reasoning recorded for each decision.

Three practical steps to start now:

  1. Formalise your trigger list. Document every event that requires a CDD review, covering transaction anomalies, beneficial ownership changes, PEP identification, sanctions updates, and time-based intervals tied to risk tier. If it is not written into your AML/CTF programme, it is not a reliable process.

  2. Assign risk tiers to your existing customer base. Segment customers using a consistent, documented methodology. Each tier must map to a defined review frequency. Leaving this to case-by-case judgement creates gaps that are difficult to defend during an examination.

  3. Set review schedules in writing before your next AUSTRAC examination. A written schedule transforms an intention into an obligation that can be tracked, evidenced, and audited.

For Tranche 2 businesses entering the framework from 2026, the transition period is a genuine opportunity to build scalable CDD infrastructure from the outset rather than retrofitting manual processes across a mature customer base later.

A centralised platform that handles continuous sanctions screening, automated PEP re-checks, and risk-tier-based review scheduling removes the reliance on staff memory and manual calendars, making every decision part of an automatically recorded audit trail. To see how a structured, end-to-end approach supports this, let your compliance process flow from onboarding through to ongoing monitoring in a single system.

Conclusion

Ongoing customer due diligence is not a one-time exercise. It is a living obligation that runs for the entire life of every customer relationship. Managing it well requires documented triggers and review schedules, consistent risk-tier segmentation, and tools that make the process repeatable rather than reliant on individual effort.

The goal is a CDD framework that runs continuously, produces auditable records, and scales as your customer base grows. Start with your written programme, assign your risk tiers, and let the system carry the process forward from there.

Get started with Personr in three easy steps

1

Book a call

Book a call with our compliance experts. We’ll set you up with a free account ready to suit your team’s needs.

2

Add your people

From new clients to your existing ones, onboard effortlessly with our self-serve platform.

3

Dedicated onboarding

From navigating local laws to support for your team members, our dedicated team will help you get set up seamlessly.

Get started with Personr in three easy steps

1

Book a call

Book a call with our compliance experts. We’ll set you up with a free account ready to suit your team’s needs.

2

Add your people

From new clients to your existing ones, onboard effortlessly with our self-serve platform.

3

Dedicated onboarding

From navigating local laws to support for your team members, our dedicated team will help you get set up seamlessly.

Get started with Personr in three easy steps

1

Book a call

Book a call with our compliance experts. We’ll set you up with a free account ready to suit your team’s needs.

2

Add your people

From new clients to your existing ones, onboard effortlessly with our self-serve platform.

3

Dedicated onboarding

From navigating local laws to support for your team members, our dedicated team will help you get set up seamlessly.