Skip to content

Enhanced customer due diligence (ECDD) — when and how

When the AML/CTF Act makes enhanced customer due diligence mandatory, which measures the Rules require in particular cases, and when a senior manager must approve.

In short

ECDD is mandatory when any trigger in s 32 of the AML/CTF Act applies: the customer is high risk, a suspicious matter reporting obligation arises and you intend to keep acting, a foreign PEP is involved, someone involved is in or formed in a FATF call-to-action jurisdiction, or the customer asks for unusual services (Rule 6-20). The measures must be appropriate to the customer's risk. Senior-manager approval is mandatory only in the cases Rule 5-5(1) lists, which for an agency means PEPs and s 37A reliance arrangements. It is not required for every high-risk customer.

Standard customer due diligence establishes who the customer is and what they want from you. Enhanced customer due diligence (ECDD) is the extra work the law requires when the risk is higher. Section 32 of the AML/CTF Act 2006 (Cth) says that when you carry out initial CDD (s 28) or ongoing CDD (s 30), you must apply enhanced measures "appropriate to the ML/TF risk of the customer" if one or more triggers apply.

The triggers (Act s 32; Rules s 6-20).

  1. High risk. The customer's ML/TF risk is high (s 32(a)).
  2. A suspicious matter, and you intend to keep acting. A suspicious matter reporting obligation arises for the customer and you propose to continue providing a designated service to them (s 32(b)). Both parts must be present.
  3. A foreign PEP. The customer, a beneficial owner, a person the customer is receiving the service on behalf of, or a person acting on the customer's behalf is a foreign politically exposed person (s 32(c)).
  4. A FATF call-to-action jurisdiction. Any of those same people is an individual physically present in, or a body corporate or legal arrangement formed in, a high-risk jurisdiction for which FATF has called for enhanced due diligence (s 32(d)).
  5. Unusual services. The customer asks for services that have no apparent economic or legal purpose, or would involve unusually complex or large transactions, or would involve an unusual pattern of transactions (s 32(f); Rule 6-20). Any one of these is enough.
  6. Nested services (s 32(e)). By definition (s 5) a nested services relationship exists only where the reporting entity is a remitter, virtual asset service provider or financial institution. It will not arise from an agency's brokering work.

Domestic PEPs and international-organisation PEPs are not triggers in their own right. Their status matters through s 32(a): if it helps make the customer's ML/TF risk high, ECDD applies. Exposure to a grey-listed or otherwise risky country works the same way. It goes into your risk rating, and a high rating triggers ECDD.

FATF revises its call-to-action list after each plenary. Check the current FATF statement each time rather than relying on a list copied into your programme.

What ECDD involves. Neither the Act nor the Rules give a general checklist of ECDD measures. Section 32 requires measures appropriate to the customer's risk, so what you do should follow from why ECDD applies. AUSTRAC's guidance gives examples:

  • collecting and verifying more KYC information;
  • asking the reason for the transaction;
  • collecting or verifying source of funds or source of wealth;
  • reviewing the relationship more often;
  • monitoring more closely.

AUSTRAC also expects active steps, such as declining work outside your risk appetite, and not only extra monitoring.

Some measures are mandatory in particular cases:

  • Source of wealth and source of funds: high risk, SMR or FATF triggers. Where ECDD applies because of s 32(a), (b) or (d), you must establish the customer's source of wealth and source of funds if that is relevant to the nature of the customer's ML/TF risk (Rule 6-21).

  • Source of wealth and source of funds: PEPs. If the customer, a beneficial owner or a person the customer is acting for is a foreign PEP, you must establish that PEP's source of wealth and source of funds. For a domestic or international-organisation PEP, the same applies when the customer's ML/TF risk is high (Rule 6-23).

  • Senior-manager approval: listed cases only. Rule 5-5(1) requires your policies to obtain a senior manager's approval before you start providing a designated service in these cases:

    • a foreign PEP is involved;
    • a domestic or international-organisation PEP is involved and the customer is high risk;
    • the service is part of a nested services relationship.

    It also applies before you enter a written s 37A reliance arrangement as the relying party. If a customer, beneficial owner or person the customer is acting for becomes a foreign PEP during the relationship, or becomes a domestic or international-organisation PEP while the customer is high risk, a senior manager must decide as soon as practicable whether to continue (Rule 5-5(1A)).

Your policies must also say when you collect, or collect and verify, source of wealth and source of funds (Rule 5-2(2)–(3)).

Senior-manager approval is not universal. A high-risk customer who is not a PEP does not need senior-manager approval under Rule 5-5(1). Your policies must still say what other decisions need approval and who can give it (Rule 5-5(4)). A "senior manager" is an individual who makes, or takes part in making, decisions affecting the whole or a substantial part of the business (s 5). In a small agency that is usually the principal or a director. Sending every high-risk customer to the principal is a choice your policies can make, and AUSTRAC's guidance encourages escalation to senior management. It is not a requirement of Rule 5-5(1).

Suspicious matters and tipping off. Do not hold back a suspicious matter report to finish ECDD. AUSTRAC's guidance is that you are not required to complete enhanced CDD before you submit an SMR. If an SMR obligation has arisen and you reasonably believe that continuing CDD would or could reasonably be expected to alert the customer to your suspicion, s 39D says ss 28, 30 and 26G do not apply to that extent.

Records. Your CDD records must include any analysis, risk assessment or decision-making you did for the customer (s 111(3)(b)). AUSTRAC suggests an ECDD record covering:

  • what triggered ECDD;
  • which measures you applied and why;
  • what you collected and how you verified it;
  • any approval;
  • any change to the customer's risk rating.

Keep CDD records for 7 years from the end of the business relationship, or from when you finish providing an occasional transaction (s 111(2)).

What to do next. Check your programme's ECDD section against the triggers above, and check that your approval step matches Rule 5-5(1) for PEPs. Then write down who approves other high-risk customers. If your current policy says every ECDD customer needs principal sign-off, that is allowed, but describe it as your own rule rather than a legal requirement.

Frequently asked questions

Do domestic PEPs always trigger ECDD?
No. A foreign PEP is a trigger on its own (s 32(c)). A domestic or international-organisation PEP is not named in s 32, so ECDD applies only if the customer's ML/TF risk is high (s 32(a)). When it is, you must also establish the PEP's source of wealth and source of funds (Rule 6-23(1)) and get a senior manager's approval before you start acting (Rule 5-5(1)(b)–(c)).
Is FATF grey-listed jurisdiction exposure enough to trigger ECDD?
Not on its own. The s 32(d) trigger covers only high-risk jurisdictions for which FATF has called for enhanced due diligence, its call-to-action list. It applies where the customer, a beneficial owner, a person the customer is acting for, or a person acting for the customer is physically present in such a jurisdiction or, for an entity, was formed there. Other country exposure feeds your customer risk rating; if that rating is high, ECDD applies under s 32(a). FATF updates its list after each plenary, so check the current statement.
Who has to approve an ECDD customer?
It depends on the trigger. Rule 5-5(1) requires your policies to get a senior manager's approval before you start providing a designated service where the customer, a beneficial owner or a person the customer is acting for is a foreign PEP, or is a domestic or international-organisation PEP and the customer is high risk. It also covers starting a nested services relationship and entering a written s 37A reliance arrangement as the relying party. If someone becomes a foreign PEP during the relationship, or a domestic or international-organisation PEP while the customer is high risk, a senior manager must decide whether to continue (Rule 5-5(1A)). For other customers, your policies must say when approval is needed and who gives it (Rule 5-5(4)).
Do I have to finish ECDD before lodging a suspicious matter report?
No. AUSTRAC's guidance is that you are not required to complete enhanced CDD before you submit an SMR, and the SMR deadline runs regardless. If continuing CDD would or could reasonably be expected to alert the customer to your suspicion, s 39D switches off ss 28, 30 and 26G to that extent.

Sources

  1. AML/CTF Act 2006 (Cth) s 32 — when enhanced CDD is mandatory
  2. AML/CTF Act 2006 (Cth) s 39D — CDD where it would tip off the customer
  3. AML/CTF Act 2006 (Cth) s 111 — CDD records
  4. AML/CTF Rules 2025 s 6-20 — unusual services
  5. AML/CTF Rules 2025 ss 6-21, 6-23 — source of wealth and source of funds
  6. AML/CTF Rules 2025 s 5-5 — senior-manager approval
  7. AUSTRAC, Enhanced customer due diligence

This is general guidance for Australian real estate professionals. It does not constitute legal advice. Consult a qualified AML/CTF practitioner before relying on it for your agency.