KYC for Accounting Firms: A Complete Guide to Customer Due Diligence
Planning guide to customer due diligence for accounting practices providing covered professional designated services under Australia's current AML/CTF regime.
KYC accounting firms, customer due diligence accountants, CDD requirements Australia, AML client verification, know your customer accounting
02/04/2026 • 9 min read
# KYC for Accounting Firms: A Complete Guide to Customer Due Diligence
Australia's expanded AML/CTF regime has been in force since 1 July 2026. An accounting practice is in scope when it provides a covered professional designated service with an Australian geographic link. This guide provides planning prompts for common entity types; it is not a universal checklist.
**Source review: 25 August 2026.** Reviewed against AUSTRAC's current reporting-regime, professional designated-services and existing-customer transition guidance. General information only, not legal advice. Determine the measures and timing that apply to each covered service and customer under the current Act, Rules and your program.
## What is KYC/CDD?
**Know Your Customer (KYC)** is the process of verifying the identity of your clients and understanding the nature of their business. **Customer Due Diligence (CDD)** is the broader framework that includes KYC plus ongoing monitoring, risk assessment, and record-keeping.
Depending on the circumstances, a risk-based CDD framework may involve standard measures, simplified measures where permitted, or enhanced measures:
1. **Simplified CDD** -- for low-risk clients where reduced verification is permitted
2. **Standard CDD** -- the measures your current framework applies in ordinary in-scope circumstances
3. **Enhanced Due Diligence (EDD)** -- additional measures for high-risk clients, PEPs, and complex structures
Initial CDD timing is circumstance-specific. For a new customer, apply the rule for the covered service, including any exception or permitted deferred timing. Existing-customer transition rules are conditional and can be affected by risk and specified triggers.
## CDD for Individuals
For an individual customer in scope, information your procedure may require includes:
### Information to Collect
- Full legal name (as it appears on identity documents)
- Date of birth
- Residential address (not a PO Box)
- Occupation and source of income/wealth
- Tax File Number (for ATO-related services)
- Purpose of the business relationship
### Verification Methods
**Primary Photographic ID (at least one):**
- Australian driver's licence
- Australian passport (current or expired within 2 years)
- Foreign passport with Australian visa
- Proof of age card issued by a state or territory
**Secondary Non-Photographic ID (at least one if needed):**
- Medicare card
- Birth certificate or extract
- Citizenship certificate
- Centrelink or Veterans Affairs card
**Electronic Verification:**
The AML/CTF Act permits electronic identity verification (eKYC) using government data sources. This matches the individual's name, date of birth, and address against records held by:
- Document Verification Service (DVS) -- verifies Australian IDs
- Credit bureaus -- confirms address history
- Electoral roll -- confirms address registration
Electronic verification is faster, more reliable, and creates an automatic audit trail -- making it the preferred method for practices handling volume.
### When to Request Additional Information
The following factors may trigger enhanced measures under your current risk framework:
- Client is from a high-risk jurisdiction (FATF grey/black list)
- Source of funds is unclear or inconsistent with occupation
- Client is a Politically Exposed Person (PEP) or associate of a PEP
- Client requests unusual transaction structures
## CDD for Companies
Company procedures commonly include looking through the corporate structure to identify relevant beneficial owners and controllers under the current rules.
### Information to Collect
- Full company name and any trading names
- Australian Company Number (ACN) and ABN
- Registered office address and principal place of business
- Jurisdiction of incorporation
- Nature of business activities
### Identifying Beneficial Owners
Your procedure should identify the individuals who meet the applicable ownership or control tests, which may include a person who:
- **Owns 25% or more** of the company's issued capital (directly or indirectly)
- **Exercises significant control** over the company (even without ownership)
- **Holds senior management positions** if no individual meets the ownership threshold
For each beneficial owner, perform the same individual CDD as described above.
### Verification Methods
- ASIC company extract (confirms registration, directors, shareholders)
- Annual return or current share register
- Trust deeds (if shares are held by trusts)
- Direct confirmation from directors regarding beneficial ownership
### Complex Ownership Structures
Many accounting clients have layered structures -- a family trust holds shares in a company, which holds units in a unit trust. For each layer:
1. Identify all entities in the ownership chain
2. Trace through to the ultimate beneficial owners (individuals)
3. Verify each individual who holds 25% or more at any level
4. Document the entire structure with a diagram
## CDD for Trusts
Trust structures can present additional ownership and control questions. Apply the information and verification measures required by your risk-based procedure and the current Rules.
### Information to Collect
- Full name of the trust
- Type of trust (discretionary, unit, hybrid, testamentary)
- Country of establishment
- ABN/TFN of the trust
- Name and address of all trustees (individual and corporate)
### People to Verify
| Role | Verification Required |
|------|
Ready to transform your practice?
Built and run every day by Tax7, an Australian accounting practice. Fedix prepares the work - you review and sign.
----------------------|
| **Settlor** | Identify and verify (unless nominal -- e.g. $10 settlement) |
| **Trustees** | Full individual CDD for each individual trustee; full company CDD for corporate trustees |
| **Beneficiaries** | Identify named beneficiaries; for discretionary trusts, identify classes of beneficiaries |
| **Appointor / Guardian** | Identify and verify -- this person has the power to remove and appoint trustees |
| **Beneficial owners** | Anyone who holds 25%+ beneficial interest or exercises effective control |
### Key Documents
- Trust deed (including any variations or amendments)
- Minutes of trustee meetings (to confirm current trustees and appointor)
- Financial statements showing distributions (to identify active beneficiaries)
### Discretionary Trusts: Special Considerations
Discretionary trusts (family trusts) are common in Australian accounting practices. Because the trustee has discretion over distributions, there are no fixed beneficial owners. In this case:
- Identify the **appointor** (who controls the trustee) -- this person is effectively the beneficial owner
- Identify all **classes of beneficiaries** described in the trust deed
- Monitor annual distributions to see which beneficiaries are actually receiving benefits
- Apply enhanced due diligence if the trust structure appears designed to obscure ownership
## CDD for SMSFs
Self-Managed Super Funds are a unique Australian structure requiring specific CDD steps.
### Information to Collect
- Fund name and ABN
- Whether individual or corporate trustee structure
- All member names and details
- SMSF auditor details
- ATO compliance status
### Verification Requirements
- Verify all individual trustees (or the corporate trustee entity)
- Verify all members of the fund
- Confirm the fund is registered with the ATO and not in a compliance breach
- For corporate trustee SMSFs, apply the company CDD process to the trustee company
### Red Flags for SMSFs
- Related party transactions at non-arm's length terms
- Loans to members or related parties (prohibited under SIS Act)
- Unusual investment patterns (speculative assets, cryptocurrency without clear strategy)
- Late or missing auditor reports
## Risk-Based Approach
Not every client presents the same level of risk. The AML/CTF Act requires a risk-based approach to CDD.
### Risk Factors to Assess
**Client Risk:**
- Type of entity (individual vs complex trust structure)
- Country of residence or incorporation
- PEP status
- Source of funds/wealth clarity
- History of compliance issues
**Service Risk:**
- Managing client money or assets (higher risk)
- Creating or managing legal entities (higher risk)
- Tax compliance only (lower risk)
- Advisory services only (lower risk)
**Geographic Risk:**
- Client or beneficial owners in FATF grey/black list countries
- Cross-border transactions
- Connections to high-risk jurisdictions
### Risk Categories and Review Frequency
| Risk Level | CDD Level | Review Frequency | Examples |
|-----------|-----------|-----------------|---------|
| **Lower** | Measures permitted by the current Rules and your program | Set by your risk-based procedure and relevant triggers | A lower-risk profile does not remove all applicable obligations |
| **Medium** | Measures set by your program | Review on the cycle and trigger events your program specifies | Straightforward ownership may reduce complexity but does not determine scope by itself |
| **Higher** | Enhanced measures where required | More frequent or event-driven review as your program requires | Political exposure, complex structures or higher-risk geographic connections may be relevant |
## Record Retention
Many CDD records are subject to a **7-year** retention period, but the starting event depends on the record type. Confirm the current rule before setting disposal dates, including whether it runs from:
- The end of the business relationship, OR
- The completion of an occasional transaction
Records to retain include:
- Copies of identity documents collected
- Electronic verification results and reports
- Risk assessments and rationale
- Ongoing monitoring records
- Suspicious matter reports (if any)
- Correspondence related to CDD
Store records securely with appropriate access controls. Electronic storage is permitted and preferred for searchability and audit purposes.
## Automate Your CDD with Fedix
Fedix assists with parts of the CDD workflow. It does not perform the practice's statutory CDD or make its compliance decisions:
- **One-click identity verification** for individuals against DVS and credit bureau databases
- **Company and trust information workflows** to help the practice collect and review ownership information
- **Sanctions screening** against the DFAT Consolidated Sanctions List, plus AI-assisted political-exposure indicators that are not a licensed PEP database
- **Draft risk ratings** for the practice to review, change and approve
- **Review reminders** based on the practice's selected settings
- **Secure document storage** with 7-year retention and full audit trail
- **$2.90+gst per verification** -- first 10 free, volume tiers down to $1.50, no monthly subscriptions, no minimum commitments
[See how Fedix assists KYC workflows for accounting firms](/features/kyc-aml) or [talk to us about onboarding your practice](/contact). Your practice remains responsible for deciding scope, completing CDD and retaining a complete file.