Skip to main content

KYC for Accounting Firms: A Complete Guide to Customer Due Diligence

Planning guide to customer due diligence for accounting practices providing covered professional designated services under Australia's current AML/CTF regime.

KYC accounting firms, customer due diligence accountants, CDD requirements Australia, AML client verification, know your customer accounting

02/04/2026 9 min read

# KYC for Accounting Firms: A Complete Guide to Customer Due Diligence Australia's expanded AML/CTF regime has been in force since 1 July 2026. An accounting practice is in scope when it provides a covered professional designated service with an Australian geographic link. This guide provides planning prompts for common entity types; it is not a universal checklist. **Source review: 25 August 2026.** Reviewed against AUSTRAC's current reporting-regime, professional designated-services and existing-customer transition guidance. General information only, not legal advice. Determine the measures and timing that apply to each covered service and customer under the current Act, Rules and your program. ## What is KYC/CDD? **Know Your Customer (KYC)** is the process of verifying the identity of your clients and understanding the nature of their business. **Customer Due Diligence (CDD)** is the broader framework that includes KYC plus ongoing monitoring, risk assessment, and record-keeping. Depending on the circumstances, a risk-based CDD framework may involve standard measures, simplified measures where permitted, or enhanced measures: 1. **Simplified CDD** -- for low-risk clients where reduced verification is permitted 2. **Standard CDD** -- the measures your current framework applies in ordinary in-scope circumstances 3. **Enhanced Due Diligence (EDD)** -- additional measures for high-risk clients, PEPs, and complex structures Initial CDD timing is circumstance-specific. For a new customer, apply the rule for the covered service, including any exception or permitted deferred timing. Existing-customer transition rules are conditional and can be affected by risk and specified triggers. ## CDD for Individuals For an individual customer in scope, information your procedure may require includes: ### Information to Collect - Full legal name (as it appears on identity documents) - Date of birth - Residential address (not a PO Box) - Occupation and source of income/wealth - Tax File Number (for ATO-related services) - Purpose of the business relationship ### Verification Methods **Primary Photographic ID (at least one):** - Australian driver's licence - Australian passport (current or expired within 2 years) - Foreign passport with Australian visa - Proof of age card issued by a state or territory **Secondary Non-Photographic ID (at least one if needed):** - Medicare card - Birth certificate or extract - Citizenship certificate - Centrelink or Veterans Affairs card **Electronic Verification:** The AML/CTF Act permits electronic identity verification (eKYC) using government data sources. This matches the individual's name, date of birth, and address against records held by: - Document Verification Service (DVS) -- verifies Australian IDs - Credit bureaus -- confirms address history - Electoral roll -- confirms address registration Electronic verification is faster, more reliable, and creates an automatic audit trail -- making it the preferred method for practices handling volume. ### When to Request Additional Information The following factors may trigger enhanced measures under your current risk framework: - Client is from a high-risk jurisdiction (FATF grey/black list) - Source of funds is unclear or inconsistent with occupation - Client is a Politically Exposed Person (PEP) or associate of a PEP - Client requests unusual transaction structures ## CDD for Companies Company procedures commonly include looking through the corporate structure to identify relevant beneficial owners and controllers under the current rules. ### Information to Collect - Full company name and any trading names - Australian Company Number (ACN) and ABN - Registered office address and principal place of business - Jurisdiction of incorporation - Nature of business activities ### Identifying Beneficial Owners Your procedure should identify the individuals who meet the applicable ownership or control tests, which may include a person who: - **Owns 25% or more** of the company's issued capital (directly or indirectly) - **Exercises significant control** over the company (even without ownership) - **Holds senior management positions** if no individual meets the ownership threshold For each beneficial owner, perform the same individual CDD as described above. ### Verification Methods - ASIC company extract (confirms registration, directors, shareholders) - Annual return or current share register - Trust deeds (if shares are held by trusts) - Direct confirmation from directors regarding beneficial ownership ### Complex Ownership Structures Many accounting clients have layered structures -- a family trust holds shares in a company, which holds units in a unit trust. For each layer: 1. Identify all entities in the ownership chain 2. Trace through to the ultimate beneficial owners (individuals) 3. Verify each individual who holds 25% or more at any level 4. Document the entire structure with a diagram ## CDD for Trusts Trust structures can present additional ownership and control questions. Apply the information and verification measures required by your risk-based procedure and the current Rules. ### Information to Collect - Full name of the trust - Type of trust (discretionary, unit, hybrid, testamentary) - Country of establishment - ABN/TFN of the trust - Name and address of all trustees (individual and corporate) ### People to Verify | Role | Verification Required | |------|

Ready to transform your practice?

Built and run every day by Tax7, an Australian accounting practice. Fedix prepares the work - you review and sign.

Request a Practice Review
----------------------| | **Settlor** | Identify and verify (unless nominal -- e.g. $10 settlement) | | **Trustees** | Full individual CDD for each individual trustee; full company CDD for corporate trustees | | **Beneficiaries** | Identify named beneficiaries; for discretionary trusts, identify classes of beneficiaries | | **Appointor / Guardian** | Identify and verify -- this person has the power to remove and appoint trustees | | **Beneficial owners** | Anyone who holds 25%+ beneficial interest or exercises effective control | ### Key Documents - Trust deed (including any variations or amendments) - Minutes of trustee meetings (to confirm current trustees and appointor) - Financial statements showing distributions (to identify active beneficiaries) ### Discretionary Trusts: Special Considerations Discretionary trusts (family trusts) are common in Australian accounting practices. Because the trustee has discretion over distributions, there are no fixed beneficial owners. In this case: - Identify the **appointor** (who controls the trustee) -- this person is effectively the beneficial owner - Identify all **classes of beneficiaries** described in the trust deed - Monitor annual distributions to see which beneficiaries are actually receiving benefits - Apply enhanced due diligence if the trust structure appears designed to obscure ownership ## CDD for SMSFs Self-Managed Super Funds are a unique Australian structure requiring specific CDD steps. ### Information to Collect - Fund name and ABN - Whether individual or corporate trustee structure - All member names and details - SMSF auditor details - ATO compliance status ### Verification Requirements - Verify all individual trustees (or the corporate trustee entity) - Verify all members of the fund - Confirm the fund is registered with the ATO and not in a compliance breach - For corporate trustee SMSFs, apply the company CDD process to the trustee company ### Red Flags for SMSFs - Related party transactions at non-arm's length terms - Loans to members or related parties (prohibited under SIS Act) - Unusual investment patterns (speculative assets, cryptocurrency without clear strategy) - Late or missing auditor reports ## Risk-Based Approach Not every client presents the same level of risk. The AML/CTF Act requires a risk-based approach to CDD. ### Risk Factors to Assess **Client Risk:** - Type of entity (individual vs complex trust structure) - Country of residence or incorporation - PEP status - Source of funds/wealth clarity - History of compliance issues **Service Risk:** - Managing client money or assets (higher risk) - Creating or managing legal entities (higher risk) - Tax compliance only (lower risk) - Advisory services only (lower risk) **Geographic Risk:** - Client or beneficial owners in FATF grey/black list countries - Cross-border transactions - Connections to high-risk jurisdictions ### Risk Categories and Review Frequency | Risk Level | CDD Level | Review Frequency | Examples | |-----------|-----------|-----------------|---------| | **Lower** | Measures permitted by the current Rules and your program | Set by your risk-based procedure and relevant triggers | A lower-risk profile does not remove all applicable obligations | | **Medium** | Measures set by your program | Review on the cycle and trigger events your program specifies | Straightforward ownership may reduce complexity but does not determine scope by itself | | **Higher** | Enhanced measures where required | More frequent or event-driven review as your program requires | Political exposure, complex structures or higher-risk geographic connections may be relevant | ## Record Retention Many CDD records are subject to a **7-year** retention period, but the starting event depends on the record type. Confirm the current rule before setting disposal dates, including whether it runs from: - The end of the business relationship, OR - The completion of an occasional transaction Records to retain include: - Copies of identity documents collected - Electronic verification results and reports - Risk assessments and rationale - Ongoing monitoring records - Suspicious matter reports (if any) - Correspondence related to CDD Store records securely with appropriate access controls. Electronic storage is permitted and preferred for searchability and audit purposes. ## Automate Your CDD with Fedix Fedix assists with parts of the CDD workflow. It does not perform the practice's statutory CDD or make its compliance decisions: - **One-click identity verification** for individuals against DVS and credit bureau databases - **Company and trust information workflows** to help the practice collect and review ownership information - **Sanctions screening** against the DFAT Consolidated Sanctions List, plus AI-assisted political-exposure indicators that are not a licensed PEP database - **Draft risk ratings** for the practice to review, change and approve - **Review reminders** based on the practice's selected settings - **Secure document storage** with 7-year retention and full audit trail - **$2.90+gst per verification** -- first 10 free, volume tiers down to $1.50, no monthly subscriptions, no minimum commitments [See how Fedix assists KYC workflows for accounting firms](/features/kyc-aml) or [talk to us about onboarding your practice](/contact). Your practice remains responsible for deciding scope, completing CDD and retaining a complete file.

Related Articles

Stay Updated

Get tips, updates, and industry insights