Customer due diligence — what you collect and verify
Plain-English breakdown of CDD obligations for real estate agencies: who, what, when, and the delayed-CDD window under the amended Rules.
In short
Before you start providing a designated service, s 28 of the AML/CTF Act requires you to establish several matters on reasonable grounds. They are who the customer is, who they act for, who acts for them and with what authority, any beneficial owners, whether anyone involved is a PEP or sanctioned, and the nature and purpose of the deal. You collect the information appropriate to the customer's ML/TF risk and verify as much as that risk requires with reliable and independent data. For the party you don't act for, Rule 6-32 lets CDD finish later, by the earlier of 28 days after exchange of contracts and 3 days before the initially agreed settlement day.
Customer due diligence (CDD) is how you know who you are dealing with. For a real estate agency, both sides of a sale are your customers. Section 6, table 5, item 1 of the AML/CTF Act 2006 (Cth) names the seller and the buyer as customers of the brokering service.
What you must establish (Act s 28(2)). Before you start providing the service, you must establish on reasonable grounds:
- the customer's identity;
- the identity of anyone the customer is receiving the service on behalf of;
- the identity of anyone acting for the customer, and their authority to act;
- for a customer that is not an individual, the identity of its beneficial owners;
- whether the customer, a beneficial owner, a person the customer is acting for or a person acting for the customer is a politically exposed person or designated for targeted financial sanctions;
- the nature and purpose of the business relationship or transaction.
Section 28(3) says how. For an individual customer, take reasonable steps to establish that they are who they claim to be. Identify the customer's ML/TF risk. Collect KYC information appropriate to that risk. Then verify, using reliable and independent data, as much of it as that risk requires. CDD is risk-based: a higher-risk customer needs more.
Individuals. The Rules do not set a fixed list for an individual customer who is not a sole trader. AUSTRAC's baseline examples are:
- full name and any other names;
- date of birth;
- residential address;
- a unique identifier, such as a licence or passport number.
AUSTRAC suggests verifying at least the full name and date of birth. You can use a government-issued photographic ID document, or a primary non-photographic document together with a secondary document showing name and address. Then confirm the person is who they claim to be. For example, compare them with their photo in person, on a video call, or through a biometric check. AUSTRAC also notes that the Act does not require you to keep copies of identity documents; you can record their details instead.
Sole traders. Rule 6-1 requires at least:
- full name, any business name and other names;
- any unique identifier for the business, such as an ABN, or failing that one for the customer;
- the principal place of business;
- information about the nature of the business.
Companies, partnerships and unincorporated associations. Rule 6-2(2) requires at least:
- full name, business names and other names;
- any unique identifier, such as an ACN;
- the principal place of business and any registered office;
- evidence that the customer exists;
- information about the powers that bind and govern it;
- the full name, and any director identification number, of each person with primary responsibility for its governance and executive decisions.
You must also collect information about its ownership and control structure (Rule 6-2(3)) and the nature of its business (Rule 6-2(4)). No rule requires you to verify every director's identity. How much you verify follows the customer's risk (s 28(3)(d)).
Trusts. Rule 6-3 requires at least:
- full name and the kind of trust, such as discretionary, bare or unit trust;
- business names, other names, any unique identifier and the principal place of business;
- evidence that the trust exists, and information about the powers that bind and govern it;
- the names of the individuals with primary responsibility for its governance and executive decisions;
- the identity of the trustees (Rule 6-3(4));
- the identity of each beneficiary, or a description of each class only where the nature of the trust means it is not possible to identify each one (Rule 6-3(3));
- the control structure, and the identity of any settlor, appointor, guardian or protector (Rule 6-3(5)).
Beneficial owners. A beneficial owner is an individual who ultimately owns 25% or more of the customer, directly or indirectly, or who controls it (s 5). Control is a parallel test, not a fallback.
- Listed companies and government bodies. If the customer is a listed public company subject to disclosure requirements, a government body, or an entity they control, Rule 6-7 treats the beneficial-owner matter as established.
- Owners you cannot identify. If you cannot identify the beneficial owners of a company, partnership or unincorporated association after all reasonable steps, Rule 6-8(1) lets you rely on the chief executive officer's identity instead. You must collect that identity, verify it as far as the risk requires, and record the steps you took and the difficulties you met.
- No beneficial owners. If a company has none, you collect the chief executive officer's identity instead (Rule 6-8(2)–(3)).
Timing. The default is that CDD is complete before you start providing the service (s 28(1)). Section 29 allows a later finish only if all of its conditions are met. These include a reasonable-grounds determination that delay is essential to avoid interrupting the ordinary course of business, and that the extra risk is low.
For real estate, Rule 6-32 covers the party you don't act for. That is the buyer once you have started acting for the seller (Rule 6-32(1)), or the seller once you have started acting for the buyer (Rule 6-32(2)). Rule 6-32(4), as amended by F2026L00353, sets the deadline. It is the earlier of 28 days after exchange of contracts and 3 days before the initially agreed settlement day, and you must still finish as soon as reasonably practicable. AUSTRAC's guidance warns that civil penalties may apply if KYC information is not verified within the required timeframes.
AUSTRAC's guidance on when the service starts:
- Seller's agent. The service to the seller starts when the agreement to broker the sale is signed. The service to the buyer starts when it is reasonably expected the sale will proceed, typically when the offer is accepted and the contract signed.
- Buyer's agent. The service to the buyer starts when the agreement to find a property is signed. The service to the seller starts at the same point in the sale.
Simplified and enhanced CDD. Simplified CDD (s 31) is available only where three things are true:
- the customer's ML/TF risk is low;
- s 32 does not apply;
- your policies deal with simplified measures (Rule 6-16).
It is not tied to a customer category. Enhanced CDD is mandatory when any s 32 trigger applies; see Enhanced customer due diligence. Two ECDD rules to note:
- Source of wealth and funds. You must establish source of wealth and source of funds in the cases set by Rules 6-21 and 6-23.
- Senior-manager approval. You need a senior manager's approval before acting where a foreign PEP is involved, or where a domestic or international-organisation PEP is involved and the customer is high risk (Rule 5-5(1)). It is not required for every high-risk customer.
Records. Keep records that show what information you collected, how you verified it, and the risk analysis and decisions behind the level of CDD you applied (s 111(3)). Retain them for 7 years from the end of the business relationship, or from when you finish providing an occasional transaction (s 111(2)).
What to do next. Build a checklist for each customer type (individual, sole trader, company, trust) from the lists above. Make it a gate in your listing and offer-acceptance workflow. When contracts are exchanged, diarise the Rule 6-32(4) deadline for the other side of the sale.
Frequently asked questions
- When does CDD apply to buyers?
- AUSTRAC's guidance is that a seller's agent starts providing the designated service to the buyer when it is reasonably expected that the sale will proceed, typically when the offer has been accepted and the contract signed. If the conditions in s 29 of the Act are met, Rule 6-32 lets you finish the buyer's CDD after that. The deadline is the earlier of 28 days after exchange and 3 days before the initially agreed settlement day. Your own client must be through CDD before you start acting for them.
- What triggers ECDD?
- Any trigger in s 32 of the Act. The customer is high risk. A suspicious matter reporting obligation arises and you propose to keep acting. The customer, a beneficial owner, a person the customer is acting for or a person acting for the customer is a foreign PEP. Any of them is physically present in, or was formed in, a FATF call-to-action jurisdiction. Or the customer asks for unusual services under Rule 6-20: no apparent economic or legal purpose, unusually complex or large transactions, or an unusual pattern of transactions. The nested services trigger cannot arise from an agency's brokering work.
- Do we need to identify every beneficiary of a discretionary trust?
- You must collect information about the identity of each beneficiary. Only if the nature of the trust means it is not possible to identify each one can you instead describe each class of beneficiary (Rule 6-3(3)). You also collect the identity of the trustees (Rule 6-3(4)), and the trust's control structure and any settlor, appointor, guardian or protector (Rule 6-3(5)).
- What is the beneficial ownership threshold?
- A beneficial owner is an individual who ultimately owns, directly or indirectly, 25% or more of the customer, or who controls it directly or indirectly (Act s 5). Control is a separate test, not a fallback: someone can be a beneficial owner through control with no shareholding at all. Suppose you take all reasonable steps and still cannot identify the beneficial owners of a company, partnership or unincorporated association. Rule 6-8(1) then treats the matter as established once you record the steps and difficulties and collect the chief executive officer's identity, verified as far as the risk requires.