
Standard Customer Due Diligence is not so difficult to picture. Collect the ID, verify it, note the risk rating, open the file. A month or two into Tranche 2, most newly regulated firms have some version of that routine running.
Enhanced Due Diligence, though, is the part some struggle to visualise. It’s the moment a normal-looking matter stops being routine: the trust with a beneficiary offshore, the purchaser whose company is registered somewhere you had to look up, the client whose settlement funds don’t match anything you know about them. Suddenly the file demands more attention. The two questions every firm quietly asks are: when exactly does that switch flip from standard to enhanced and what am I actually required to do once it does?
The good news is that AUSTRAC has answers to both of these questions and in plain terms. The triggers are a short, specific list and the extra steps are explicit.
This article walks you through both, explaining the jargon on the way to make the process clear.

Customer Due Diligence (CDD) answers one question: do I know who I’m dealing with, and does anything about them worry me? You do it at the start of the relationship (initial CDD) and you keep half an eye on it as the relationship progresses over months and years (ongoing CDD).
Enhanced CDD is the same question with the stakes raised, in that something about the customer, the transaction or the people behind it puts the matter into higher-risk territory. In such cases, the law requires you to gather more evidence, perform more comprehensive checks, get the right people to sign off, watch the file more closely, and keep records that show the above was actioned.
That’s the whole concept. The rest is knowing exactly when you’re entering the ‘higher-risk territory’.

AUSTRAC’s guidance on when you must apply enhanced CDD lists six circumstances. You may come across them during onboarding, partway through a matter, or both.
| # | Trigger | What it looks like in a real file |
|---|---|---|
| 1 | The customer’s ML/TF risk is high | Your own risk assessment rates the customer as high, at onboarding or later, after a monitoring alert or a change in their details. |
| 2 | Unusual, large or complex transactions | A transaction, or transactions, that are unusually complex or large, have no apparent economic or legal purpose, or form an odd pattern. |
| 3 | A foreign PEP is involved | The purchaser, a beneficial owner, a trust beneficiary or someone acting for the customer holds a prominent public position overseas. |
| 4 | A high-risk jurisdiction is involved | Someone in the matter is physically in, or the entity was formed in, a country on the FATF’s call-for-action list. |
| 5 | You’re required to submit an SMR | You’ve formed a suspicion, you’re lodging a suspicious matter report, and you intend to keep providing the service. |
| 6 | Nested services relationship | This occurs when a financial institution provides services to another financial institution, which then uses those services for its own customers. (This mainly arises in financial-sector arrangements and is unlikely to be seen on a typical professional-practice file.) |
Three of these deserve a closer look, because they’re where newly regulated firms get caught out.
Trigger 1 is your own risk assessment doing its job. If your framework rates a customer high, enhanced CDD will follow automatically, as a result. This means your customer risk ratings aren’t a paperwork exercise; they are the action that switches from standard to enhanced CDD. And remember, ratings can change throughout the relationship. A high rating after many months, that might be triggered by a customer moving to a higher-risk country, for example, is just as valid as a high rating given during onboarding.
For triggers 3 and 4, the net is wider than ‘is my client a foreign official’. You must apply enhanced CDD if any of the following is a foreign PEP, or is located or formed in a listed high-risk jurisdiction:
This is why investigating who actually owns and controls an entity is so important. You can’t know whether the trigger fires until you know who the humans behind the structure are.
In terms of trigger 4, the country list itself is short and specific: it’s the jurisdictions the Financial Action Task Force (FATF) makes public. The list changes after each FATF plenary, so check the current statement regularly for updates.
If you’re required to lodge a suspicious matter report and you intend to keep acting, enhanced CDD applies. But AUSTRAC is explicit about the order: the SMR is submitted by the deadline even if your enhanced CDD is still underway. There’s no need to wait for the latter to submit the former.
Enhanced CDD doesn’t mean simply repeating the same checks more carefully. AUSTRAC expects the measures you apply to be targeted to the specific risk, proportionate to it, and genuinely capable of managing it. In practice, the toolkit looks like this.
For a foreign PEP (or a domestic or international organisation PEP where the customer is high risk), a senior manager must approve providing the designated service, and must approve continuing the relationship if the customer, a beneficial owner, or the person the service is really for becomes a PEP mid-matter. Your AML/CTF policies have to say who holds that authority. The same senior-approval requirement applies where one of those people was previously a PEP.
Outside the PEP scenarios, AUSTRAC expects your policies to require escalation to senior management whenever enhanced CDD findings need a decision. In any case, the person who opened the file shouldn’t be the only person deciding whether it can proceed.
These are two different questions, and the distinction matters:
For foreign PEPs (and high-risk domestic or international organisation PEPs), establishing both on reasonable grounds is a mandatory part of initial CDD, before the service is provided.
Beyond PEPs, you must establish them whenever they’re relevant to the nature of the customer’s high risk. AUSTRAC’s guidance on the scenarios where this applies reads like a checklist of the files that already make practitioners uneasy:
‘Reasonable grounds’ means evidence, not assertion. Bank records, sale contracts, business ownership records, dividend statements, probate documents. Collect it, verify what needs verifying and store it appropriately.
Gather additional KYC information and verify more of it, possibly from different sources than the first time. That can mean a second identity document, a photo of the customer holding their ID, information about counterparties and why the customer wants this particular service, or re-verifying details if doubts have arisen.
Enhanced CDD continues for as long as the risk does. That means more frequent reviews of the relationship, closer analysis of transactions, manual eyes on anything unusual or high-value, and updating the customer’s KYC information more often than you would for the rest of your book.
AUSTRAC is explicit that enhanced CDD must include active steps, not just being more vigilant. You can still act for a customer who requires enhanced CDD, and most of the time you will. But your policies need to cover what happens when the measures can’t reduce the risk to an acceptable level, and ending or declining the engagement has to be one of the available options.
Sections 32 and 111 of the Act require records of the enhanced CDD you applied: what triggered it, which measures you chose and why, what you collected, how you verified it, whether an SMR was submitted and what decisions followed. Up to seven years after the relationship has closed, AUSTRAC still expects to see your working out.
While following the 6 steps above, there’s something vital that needs to remain at the forefront of your process: tipping off. If an SMR is involved, you can’t reveal that to the customer. Requests for extra documents need framing as routine compliance, because for you, they now are.
The table below brings together the key terms used throughout the guidance and explains what each one means.
| Term | Plain English |
|---|---|
| ML/TF | Money laundering/terrorism financing (AUSTRAC’s shorthand also covers proliferation financing). The risks this whole regime exists to manage. |
| Reporting entity | Any business with obligations under the AML/CTF Act. Since 1 July 2026, that includes most legal, conveyancing, accounting, real estate and trust-and-company-services practices. |
| Designated service | The specific services that attract obligations (property transactions, entity structuring, trust account handling and others). Obligations attach to services, not to firms as a whole. |
| CDD | Customer Due Diligence. Knowing who you’re dealing with. Initial CDD happens before you provide the service; ongoing CDD continues while you act. |
| Enhanced CDD / ECDD | The stepped-up version of CDD described in this article. Mandatory in the six trigger circumstances. |
| KYC | Know Your Customer. The identity and background information you collect and verify about a person. |
| KYB | Know Your Business. The same discipline applied to companies and trusts, including working out who owns and controls them. |
| Beneficial owner | The human being who ultimately owns or controls a customer, no matter how many companies or trusts sit in between. |
| PEP | Politically exposed person. Someone holding a prominent public position, plus their close family and associates. Foreign PEPs (overseas positions) always trigger enhanced CDD; domestic and international organisation PEPs trigger the strict extras only when the customer is high risk. |
| SMR | Suspicious matter report. What you lodge with AUSTRAC when you form a suspicion on reasonable grounds. |
| Source of funds | Where the money for this transaction came from. |
| Source of wealth | How the customer built their overall financial position. |
| FATF | Financial Action Task Force, the global AML standards body. Its ‘call for action’ list names the jurisdictions that trigger enhanced CDD. |
| Senior manager | A person with authority in your governance framework to approve high-risk relationships. Your AML/CTF policies must name who this is. |
| Tipping off | The offence of alerting a customer that they’re the subject of an SMR or related suspicion. |
Let’s take a look at a real-world example. A buyer’s agent introduces a purchaser for a $4.2 million commercial property. The purchaser is a company registered in Australia, but KYB checks show one of its two beneficial owners lives overseas and, per screening, holds a senior government position in their home country.
That single fact does four things. The foreign PEP trigger fires (a beneficial owner counts). Senior manager approval is now required before the firm provides the service. Source of funds and source of wealth for that beneficial owner must be established on reasonable grounds, with documents, before things proceed. And the file goes onto a closer monitoring footing for as long as the relationship lasts, with every step recorded.
None of that means the deal is illegitimate or the client is lost. Handled well, it’s a few extra days of evidence-gathering and one approval. Handled without a process, it’s exactly the kind of file that stalls for weeks.
Here’s the honest operational read: no single enhanced CDD file is unmanageable. The strain comes from the fact that you can’t know in advance which files will trigger it. Every new matter needs enough screening to find out, which means PEP checks, sanctions checks and beneficial-owner mapping on routine work, so on the rare occasion that a file does need escalating, it gets treated as such.
Firms doing this by hand often spend many, what feel like unbillable, hours chasing documents by email, running names through search engines, re-keying details, and hoping the file note is good enough if AUSTRAC ever asks.
VeriEzi is Australian verification software built to make the screening layer routine, so enhanced CDD triggers surface early instead of mid-settlement.
The judgement calls stay where the law puts them: your risk assessment, your senior manager’s approval, your decision to act or decline. VeriEzi’s job is to make sure those calls are made early, with the evidence already in hand.
Claim your 5 free verifications and run your next new matter through it, or book a free demo and we’ll walk your team through the screening workflow.
VeriEzi provides identity-verification software to support firms preparing for AUSTRAC Tranche 2 reporting obligations. The information in this article is general in nature and does not constitute legal or compliance advice. Firms remain responsible for their own AML/CTF Program and reporting-entity obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). For advice specific to your firm’s obligations, consult AUSTRAC guidance materials or a qualified compliance adviser.
More insights from the same category: Compliance
ComplianceSeptember 22, 2026
Filed an SMR under Tranche 2? See the actual reporting deadlines, what privilege protects, the new tipping-off rule, and what s 235 protection covers.
Read More
ComplianceSeptember 15, 2026
Does remote VOI meet ARNECC’s rules? See how it compares to Australia Post’s in-person process and what the “reasonable steps” pathway actually requires.
Read More
ComplianceAugust 5, 2026
How to identify and verify who really owns a trust or company under Tranche 2, the 25% threshold, control test, and AUSTRAC’s trace-through rules.
Read More