AML/CTF Compliance Is Now Available in VeriEzi. Mobile App Coming Soon.
Manage AML reviews, monitor alerts, and streamline your compliance workflow today. Secure mobile access is coming soon.
BlogCompliance

Enhanced Due Diligence Under Tranche 2: What Actually Triggers It, and What You Have to Do Differently

Admin August 8, 2026Compliance
Enhanced Due Diligence Under Tranche 2: What Actually Triggers It, and What You Have to Do Differently

Standard Customer Due Diligence is not so difficult to picture. Collect the ID, verify it, note the risk rating, open the file. A month or two into Tranche 2, most newly regulated firms have some version of that routine running.

Enhanced Due Diligence, though, is the part some struggle to visualise. It’s the moment a normal-looking matter stops being routine: the trust with a beneficiary offshore, the purchaser whose company is registered somewhere you had to look up, the client whose settlement funds don’t match anything you know about them. Suddenly the file demands more attention. The two questions every firm quietly asks are: when exactly does that switch flip from standard to enhanced and what am I actually required to do once it does?

The good news is that AUSTRAC has answers to both of these questions and in plain terms. The triggers are a short, specific list and the extra steps are explicit.

This article walks you through both, explaining the jargon on the way to make the process clear.

The Essentials:
  • Enhanced customer due diligence (enhanced CDD, or ECDD) is mandatory in specific circumstances, set out in section 32 of the AML/CTF Act and section 6-20 of the Rules. It is not a judgement call you can opt out of.
  • The six triggers: (1) the customer’s risk rating is high; (2) you’re required to submit a suspicious matter report and continue to act; (3) the transaction is unusually large, complex or has no apparent economic or legal purpose; (4) the service is part of a nested services relationship; (5) a foreign politically exposed person (PEP) is involved; or, finally, (6) someone involved is located or formed in a high-risk jurisdiction on the FATF’s call-for-action list.
  • The PEP and country triggers extend beyond your client. They cover your customer, any beneficial owner, anyone the service is for (such as a trust beneficiary), and anyone acting on the customer’s behalf.
  • What changes in practice: senior manager sign-off (mandatory for foreign PEPs), establishing source of funds and source of wealth, collecting and verifying more KYC information, closer ongoing monitoring and strengthened documentation of the above.
  • You can still act for the client. Enhanced CDD is a ‘look harder’ obligation, not a ‘walk away’ instruction, although declining the matter has to be a live option for your practice.

First, the plain-English version

The plain-English version of enhanced due diligence

Customer Due Diligence (CDD) answers one question: do I know who I’m dealing with, and does anything about them worry me? You do it at the start of the relationship (initial CDD) and you keep half an eye on it as the relationship progresses over months and years (ongoing CDD).

Enhanced CDD is the same question with the stakes raised, in that something about the customer, the transaction or the people behind it puts the matter into higher-risk territory. In such cases, the law requires you to gather more evidence, perform more comprehensive checks, get the right people to sign off, watch the file more closely, and keep records that show the above was actioned.

That’s the whole concept. The rest is knowing exactly when you’re entering the ‘higher-risk territory’.

The six triggers, in order of how likely you are to meet them

What you actually have to do differently under enhanced CDD

AUSTRAC’s guidance on when you must apply enhanced CDD lists six circumstances. You may come across them during onboarding, partway through a matter, or both.

#TriggerWhat it looks like in a real file
1The customer’s ML/TF risk is highYour own risk assessment rates the customer as high, at onboarding or later, after a monitoring alert or a change in their details.
2Unusual, large or complex transactionsA transaction, or transactions, that are unusually complex or large, have no apparent economic or legal purpose, or form an odd pattern.
3A foreign PEP is involvedThe purchaser, a beneficial owner, a trust beneficiary or someone acting for the customer holds a prominent public position overseas.
4A high-risk jurisdiction is involvedSomeone in the matter is physically in, or the entity was formed in, a country on the FATF’s call-for-action list.
5You’re required to submit an SMRYou’ve formed a suspicion, you’re lodging a suspicious matter report, and you intend to keep providing the service.
6Nested services relationshipThis occurs when a financial institution provides services to another financial institution, which then uses those services for its own customers. (This mainly arises in financial-sector arrangements and is unlikely to be seen on a typical professional-practice file.)

Three of these deserve a closer look, because they’re where newly regulated firms get caught out.

The high risk rating is a trigger you control

Trigger 1 is your own risk assessment doing its job. If your framework rates a customer high, enhanced CDD will follow automatically, as a result. This means your customer risk ratings aren’t a paperwork exercise; they are the action that switches from standard to enhanced CDD. And remember, ratings can change throughout the relationship. A high rating after many months, that might be triggered by a customer moving to a higher-risk country, for example, is just as valid as a high rating given during onboarding.

The PEP and country triggers reach four kinds of people

For triggers 3 and 4, the net is wider than ‘is my client a foreign official’. You must apply enhanced CDD if any of the following is a foreign PEP, or is located or formed in a listed high-risk jurisdiction:

Who counts for the PEP and country triggers:
  • your customer
  • any beneficial owner of the customer
  • any person on whose behalf the customer is receiving the service, such as a beneficiary of a trust or foreign equivalent
  • any person acting on behalf of the customer.

This is why investigating who actually owns and controls an entity is so important. You can’t know whether the trigger fires until you know who the humans behind the structure are.

In terms of trigger 4, the country list itself is short and specific: it’s the jurisdictions the Financial Action Task Force (FATF) makes public. The list changes after each FATF plenary, so check the current statement regularly for updates.

The SMR trigger has a sequencing rule

If you’re required to lodge a suspicious matter report and you intend to keep acting, enhanced CDD applies. But AUSTRAC is explicit about the order: the SMR is submitted by the deadline even if your enhanced CDD is still underway. There’s no need to wait for the latter to submit the former.

What you actually have to do differently

Enhanced CDD doesn’t mean simply repeating the same checks more carefully. AUSTRAC expects the measures you apply to be targeted to the specific risk, proportionate to it, and genuinely capable of managing it. In practice, the toolkit looks like this.

1. Get senior sign-off where the law requires it

For a foreign PEP (or a domestic or international organisation PEP where the customer is high risk), a senior manager must approve providing the designated service, and must approve continuing the relationship if the customer, a beneficial owner, or the person the service is really for becomes a PEP mid-matter. Your AML/CTF policies have to say who holds that authority. The same senior-approval requirement applies where one of those people was previously a PEP.

Outside the PEP scenarios, AUSTRAC expects your policies to require escalation to senior management whenever enhanced CDD findings need a decision. In any case, the person who opened the file shouldn’t be the only person deciding whether it can proceed.

2. Establish source of funds and source of wealth

These are two different questions, and the distinction matters:

Source of funds vs source of wealth:
  • Source of funds: where did the money for this transaction come from? A sale, a loan, savings, an inheritance?
  • Source of wealth: how did this person arrive at their overall financial position? What’s the story of the asset base?

For foreign PEPs (and high-risk domestic or international organisation PEPs), establishing both on reasonable grounds is a mandatory part of initial CDD, before the service is provided.

Beyond PEPs, you must establish them whenever they’re relevant to the nature of the customer’s high risk. AUSTRAC’s guidance on the scenarios where this applies reads like a checklist of the files that already make practitioners uneasy:

Scenarios where source of funds and wealth matter:
  • opaque corporate or trust structures
  • high-net-worth clients whose income sources are unclear
  • wealth spread across multiple jurisdictions
  • large cash holdings
  • adverse media
  • numbers that don’t match what the customer told you.

‘Reasonable grounds’ means evidence, not assertion. Bank records, sale contracts, business ownership records, dividend statements, probate documents. Collect it, verify what needs verifying and store it appropriately.

3. Collect more KYC information and perform more rigorous checks

Gather additional KYC information and verify more of it, possibly from different sources than the first time. That can mean a second identity document, a photo of the customer holding their ID, information about counterparties and why the customer wants this particular service, or re-verifying details if doubts have arisen.

4. Watch the file more closely

Enhanced CDD continues for as long as the risk does. That means more frequent reviews of the relationship, closer analysis of transactions, manual eyes on anything unusual or high-value, and updating the customer’s KYC information more often than you would for the rest of your book.

5. Actively manage the risk, up to and including declining

AUSTRAC is explicit that enhanced CDD must include active steps, not just being more vigilant. You can still act for a customer who requires enhanced CDD, and most of the time you will. But your policies need to cover what happens when the measures can’t reduce the risk to an acceptable level, and ending or declining the engagement has to be one of the available options.

6. Write everything down

Sections 32 and 111 of the Act require records of the enhanced CDD you applied: what triggered it, which measures you chose and why, what you collected, how you verified it, whether an SMR was submitted and what decisions followed. Up to seven years after the relationship has closed, AUSTRAC still expects to see your working out.

While following the 6 steps above, there’s something vital that needs to remain at the forefront of your process: tipping off. If an SMR is involved, you can’t reveal that to the customer. Requests for extra documents need framing as routine compliance, because for you, they now are.

The jargon, translated

The table below brings together the key terms used throughout the guidance and explains what each one means.

TermPlain English
ML/TFMoney laundering/terrorism financing (AUSTRAC’s shorthand also covers proliferation financing). The risks this whole regime exists to manage.
Reporting entityAny business with obligations under the AML/CTF Act. Since 1 July 2026, that includes most legal, conveyancing, accounting, real estate and trust-and-company-services practices.
Designated serviceThe specific services that attract obligations (property transactions, entity structuring, trust account handling and others). Obligations attach to services, not to firms as a whole.
CDDCustomer Due Diligence. Knowing who you’re dealing with. Initial CDD happens before you provide the service; ongoing CDD continues while you act.
Enhanced CDD / ECDDThe stepped-up version of CDD described in this article. Mandatory in the six trigger circumstances.
KYCKnow Your Customer. The identity and background information you collect and verify about a person.
KYBKnow Your Business. The same discipline applied to companies and trusts, including working out who owns and controls them.
Beneficial ownerThe human being who ultimately owns or controls a customer, no matter how many companies or trusts sit in between.
PEPPolitically exposed person. Someone holding a prominent public position, plus their close family and associates. Foreign PEPs (overseas positions) always trigger enhanced CDD; domestic and international organisation PEPs trigger the strict extras only when the customer is high risk.
SMRSuspicious matter report. What you lodge with AUSTRAC when you form a suspicion on reasonable grounds.
Source of fundsWhere the money for this transaction came from.
Source of wealthHow the customer built their overall financial position.
FATFFinancial Action Task Force, the global AML standards body. Its ‘call for action’ list names the jurisdictions that trigger enhanced CDD.
Senior managerA person with authority in your governance framework to approve high-risk relationships. Your AML/CTF policies must name who this is.
Tipping offThe offence of alerting a customer that they’re the subject of an SMR or related suspicion.

What this looks like on a real file

Let’s take a look at a real-world example. A buyer’s agent introduces a purchaser for a $4.2 million commercial property. The purchaser is a company registered in Australia, but KYB checks show one of its two beneficial owners lives overseas and, per screening, holds a senior government position in their home country.

That single fact does four things. The foreign PEP trigger fires (a beneficial owner counts). Senior manager approval is now required before the firm provides the service. Source of funds and source of wealth for that beneficial owner must be established on reasonable grounds, with documents, before things proceed. And the file goes onto a closer monitoring footing for as long as the relationship lasts, with every step recorded.

None of that means the deal is illegitimate or the client is lost. Handled well, it’s a few extra days of evidence-gathering and one approval. Handled without a process, it’s exactly the kind of file that stalls for weeks.

The real problem is doing this at volume

Here’s the honest operational read: no single enhanced CDD file is unmanageable. The strain comes from the fact that you can’t know in advance which files will trigger it. Every new matter needs enough screening to find out, which means PEP checks, sanctions checks and beneficial-owner mapping on routine work, so on the rare occasion that a file does need escalating, it gets treated as such.

Firms doing this by hand often spend many, what feel like unbillable, hours chasing documents by email, running names through search engines, re-keying details, and hoping the file note is good enough if AUSTRAC ever asks.

Where VeriEzi comes in

VeriEzi is Australian verification software built to make the screening layer routine, so enhanced CDD triggers surface early instead of mid-settlement.

What VeriEzi does at the screening layer:
  • KYC for individuals with PEP, sanctions and adverse-media screening in the same pass, so the foreign-PEP question is answered at onboarding, not discovered later
  • KYB for companies and trusts, including beneficial-owner collection, so you know who the humans are before deciding whether a trigger fires
  • Risk scoring with ongoing monitoring, so a rating that drifts towards high gets flagged rather than randomly discovered
  • Overseas and multi-language workflows for verifying the offshore parties these files so often involve
  • A 7-year audit trail and AUSTRAC-ready reporting exports, so the audit trail builds itself as you work rather than being a separate, burdensome task

The judgement calls stay where the law puts them: your risk assessment, your senior manager’s approval, your decision to act or decline. VeriEzi’s job is to make sure those calls are made early, with the evidence already in hand.

Claim your 5 free verifications and run your next new matter through it, or book a free demo and we’ll walk your team through the screening workflow.

VeriEzi provides identity-verification software to support firms preparing for AUSTRAC Tranche 2 reporting obligations. The information in this article is general in nature and does not constitute legal or compliance advice. Firms remain responsible for their own AML/CTF Program and reporting-entity obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). For advice specific to your firm’s obligations, consult AUSTRAC guidance materials or a qualified compliance adviser.

Ready to Modernize Your VOI Process?