
When your client is just an individual person, Customer Due Diligence is demanding but clear: you verify the individual in front of you. When your client is a company or a trust, a question arises, and it’s one that tends to trip up newly regulated firms: ‘Who actually owns or controls this thing?’
From 1 July 2026, identifying beneficial owners is a core part of CDD for every captured practice acting for a corporate or trust client. Where it tends to go wrong is the fact that a company extract or a trust deed rarely hands you the answer directly. With this in mind, this guide explains what a beneficial owner now means under the reformed rules, how to work through a company and a trust, and where the process most often goes awry.

Under the AML/CTF framework, a beneficial owner is the natural person who ultimately owns or controls the legal entity that is the customer. Let’s break it down further.
Firstly, a beneficial owner is always a natural person. If your analysis stops at ‘owned by ABC Holdings Pty Ltd,’ you have not finished. A company cannot be a beneficial owner of another company; it’s simply a link in the ownership chain, not the final destination. You must keep tracing ownership back until you identify the individual or individuals who ultimately own or control the entity.
Additionally, a beneficial owner is someone who ultimately owns or controls an entity. This definition is deliberately broader than the share register. Ownership is one route to beneficial ownership, but control is another, and it does not always require an ownership interest.
AUSTRAC’s reform guidance on determining ownership and control structures sets the threshold and the control test together.
The headline rule is a number: any individual who directly or indirectly owns or controls 25% or more of a customer is a beneficial owner. Twenty-five per cent of the shares, the capital, the profits, or the voting rights, held directly or through a chain of entities, will put that person in the scope.
The mistake is treating 25% as the whole test. AUSTRAC is explicit that even where no individual meets the 25% threshold, you must still identify anyone who exercises effective control of the entity.
For this reason, a company can have four shareholders at 25% each and still have a beneficial owner who owns nothing, if that one individual holds the real decision-making power. A file that simply lists the shareholders and comes to an abrupt stop has answered the easy half of the question.

Here are the layers to trace, broken down simply:
| Layer | Entity | 25%+ holder | Individual? |
|---|---|---|---|
| Customer | Client Co Pty Ltd | Holding Co Pty Ltd (60%) | No, trace up |
| Up one | Holding Co Pty Ltd | The Smith Family Trust (100%) | No, trace up |
| Up two | The Smith Family Trust | Trustee: J Smith; controlling appointor: J Smith | Yes |
You see here there are three layers and the individual only appears at the top. A process that checked the first extract and moved on would have identified an entity, not a beneficial owner.
Trusts are where firms most often go wrong, because there is no share register to fall back on. A trust is a set of relationships, not a thing that is owned. Therefore, in this case, you look to the roles rather than to ownership percentages.
Read the whole deed. This practical instruction is simple to state and easy to underestimate. The appointor clause, in particular, is where control frequently sits, and it is not always near the front. A trust file that names the trustee and lists the beneficiaries but has not identified who can hire and fire the trustee is an incomplete file.
Beneficial ownership is less about knowing the rule and more about applying it all the way down.
Beneficial ownership combines three separate tasks that each have to be done well: analysis (reading structures and deeds correctly), verification (proving the individuals are who they say they are), and screening (checking them against sanctions, PEP and adverse-media lists).
Many AML/CTF tools handle individual compliance tasks well but struggle to connect them into a single workflow. The client details get re-entered, the ownership map lives in one place and the verification in another. Plus, the screening happens on a separate screen if it happens at all.
That is the difference between a compliant file and a defensible one. A compliant file has the boxes ticked. A defensible file shows the reasoning, the verification and the screening as one connected record you can produce on request.
VeriEzi runs verification of identity and AML customer due diligence in a single workflow, including the Know Your Business side for companies and trusts.
For corporate and trust clients, the platform lets you collect beneficial owner information and assess the entity’s risk as part of the same process used to verify individuals. This means the ownership information and identity verification stay together instead of being managed in separate systems.
Each beneficial owner, once identified, is verified and screened for sanctions, politically exposed persons and adverse media as part of the same workflow. Every step is recorded in a tamper-evident audit trail that meets the seven-year record retention requirement, turning a beneficial ownership assessment into a record you can produce years later.
The final analysis and judgment stays with your practice: reading the deed, deciding who controls the entity, and applying the rules to the structure in front of you are your call, not the software’s. What the platform removes is the re-keying and the scattered records, so the individuals you identify flow straight into verification and screening.
To see how a company or trust client runs through beneficial owner collection, verification and screening end to end, book your free demo.
More insights from the same category: Compliance
ComplianceSeptember 22, 2026
Filed an SMR under Tranche 2? See the actual reporting deadlines, what privilege protects, the new tipping-off rule, and what s 235 protection covers.
Read More
ComplianceSeptember 15, 2026
Does remote VOI meet ARNECC’s rules? See how it compares to Australia Post’s in-person process and what the “reasonable steps” pathway actually requires.
Read More
ComplianceAugust 8, 2026
What actually triggers enhanced due diligence under Australia’s Tranche 2 AML reform, and the extra steps AUSTRAC expects, explained in plain English.
Read More