6 Emporio Place, Maroochydore, QLD 4558

AML/CTF Update 2

Executive Summary

Here’s some of the most frequently asked questions we are receiving.

FAQ’s
Answer

Do I need to keep copies of ID documents?

Not necessarily. Check your AML program.

How do I check if someone is a PEP or sanctioned person?

Ask the client their occupation and consider using some of the open-source searches cited in this alert.

Do I have to verify all my existing customers?

Not necessarily. However, the guidance from AUSTRAC is not very clear. We recommend verifying all customers as new work comes in.

What technology providers or platforms can I use to verify customer’s identities?

We can’t recommend any particular technology providers but do your homework as not all are compliant. Check to see if they confirm that they are reporting entities and that their processes comply with AML laws. 

Do I need a privacy policy?

Yes. All reporting entities need to comply with the Privacy Act so you should immediately prepare or update your privacy policy.

Should I update my terms of engagement?

Yes. You need to notify clients about your obligations under AML laws and that you will deal with their personal information in accordance with your privacy policy.

Customer due diligence

A reporting entity must not commence to provide a designated service to a customer unless the reporting entity has reasonable grounds to confirm:

  • the identity of the customer;
  • the identity of any person on whose behalf the customer is receiving the designated service;
  • the identity of persons acting on behalf of the customer;
  • if the customer is not an individual – the identity of any beneficial owners of the customer;
  • whether the customer, any beneficial owner of the customer, any person on whose behalf the customer is receiving the designated service, or any person acting on behalf of the customer is:

                    a. a politically exposed person; or

                    b. a person designated for targeted financial sanctions;

                    c. the nature and purpose of the business relationship or occasional transaction.

The AML/CTF Rules set out what information must be collected from a customer in order to establish reasonable grounds. This is referred to as know your customer or ‘KYC information’. Your AML/CTF Program should clearly set out what information you need to collect.

The reporting entity must then verify the KYC information, using reliable and independent data, as appropriate having regard to the customer’s money laundering and terrorism financing (ML/TF) risk profile. Reliable and independent data might include government issued identification documents.

Record Keeping

Reporting entities must keep records to confirm that they are complying with their AML/CTF program. 4 In particular, reporting entities make and keep records of the information they collected relating to customer due diligence. The records must clearly show:

  • What customer information you collected;
  • Steps you took to verify the information collected, or to make sure the information was verified by a third party;
  • Analysis, identification or assessment of ML/TF risk, or decision making, that explains why the level of CDD was applied.

 

Many reporting entities are concerned about exposure under the Privacy Act if a data breach occurs that results in personal information being leaked. Neither the AML/CTF Act nor the AML/CTF Rules specifically require reporting entities to retain copies of customer’s personal information, such as copies of driver’s licences or passports. It is acceptable to confirm that certain records were sighted in order to confirm the identity of the client. You should check your AML/CTF Program to confirm what records need to be retained.

Practical steps to confirm that a person is not a PEP or a sanctioned person

Under the AML/CTF Act and Rules in Australia, you must take reasonable steps to establish on reasonable grounds whether a customer, beneficial owner, person acting on their behalf, or person on whose behalf the service is provided is a Politically Exposed Person (PEP) – before providing a designated service.

A PEP is defined as an individual who holds (or held) a prominent public position or function. Examples include politicians, senior government officials, judges and high ranking military officers.

  1. There is no single official register that lists all PEPs. A combination of methods can be used to confirm that a person is not a PEP. The process should be documented in your AML/CTF program.
  2. As a starting point it is recommended that all individuals be required to self-declare their occupation. This should give you some insight into whether the person might be a PEP. If a person is suspected of being a PEP you could run an internet search to confirm their position from a reliable government website.
  3. The Department of Foreign Affairs and Trade keeps a list of sanction persons. It is recommended that all individuals names be searched. There are also commercial databases which offer PEP and sanctioned persons screening searches.

Pre-commencement customers

If you were providing a designated service to a customer before 1 July 2026 you will only have to carry out initial customer due diligence on that customer if:

  • a suspicious matter reporting obligation arises in relation to the customer; or
  • there’s a significant change in the nature and purpose of the business relationship with the client.

 

AUSTRAC has provided the following examples as guidance for those assessing whether they should carry out initial customer due diligence on a pre-commencement customer. AUSTRAC’s guidance states that if a client requests a new service that is different from your existing business relationship, then you will need to carry out initial customer due diligence.

In another example, AUSTRAC states that a customer will be a pre-commencement customer if you created a company for this customer on 20 June 2026 and committed to restructure their family trust, which you started on 20 July 2026.

The examples provided by AUSTRAC are difficult to reconcile. In our view, the safest course is to verify pre-commencement customers at the earliest time practical. Obviously it will be not practically possible to verify all pre-commencement clients in July 2026. However, it should be possible to verify pre-commencement customers as new work comes in.

Using a third party platform to verify customers

It is possible to engage a third party to verify customers on your behalf such as a software provided. The following requirements must be met:

  • the third party must be a reporting entity regulated by AUSTRAC or a foreign equivalent;
  • you must enter into a written agreement with the third party;
  • you must be satisfied that the third party’s customer verification procedures are appropriate having regard to your ML/TF risk profile;
  • you must be able to obtain KYC information and verification information from the third party

 

You must complete an assessment of whether the third party is meeting these requirements. You must record these results and keep them for 7 years after the record is prepared. The record must be prepared within 10 business days after completing the assessment.

Privacy Laws

All reporting entities must comply with the Privacy Act 1988 (including the Australian Privacy Principles or APPs) when handling personal information for AML/CTF purposes.

This applies even to small businesses with annual turnover under $3 million that are normally exempt from the Privacy Act.

You will need to prepare or update your Privacy Policy to deal with how you collect, handle and storage personal information in connection with fulfilling your obligations under the AML/CTF Act.

Terms of Engagement

Reporting entities should update their terms of engagement to deal with the following:

  • Work will not be commenced until the customer has provided the required KYC information and the firm will not be liable for any delays arising as a result of this;
  • At any time during the course of the matter, it may be necessary to conduct further due diligence into the customer or the transaction and the customer agrees to cooperate with the firm by providing any required KYC information;
  • The firm may terminate the engagement if it is not satisfied with the outcome of its KYC investigations;
  • The firm may need to a suspicious matter if a reporting obligation arises;
  • The firm’s privacy policy discloses how the firm deals with personal information.

How can we help your firm?

We can assist firms with ensuring that they are complying with their duties under AML laws. This includes preparing or reviewing AML programs, training staff or undertaking independent reviews of AML compliance.

We can also help update your firm’s privacy policy or terms of engagement.

Service
Price (Inc GST)

Tailored AML Program

$3,990.00

Staff Training – 1 x 1 Hour Session

$1,089.00

Staff Training – 2 x 1 Hour Sessions

$1,749.00

Tailored Program + 3 x 1 Hour Staff Training Sessions

$4,990.00

Registering your business with AUSTRAC

$400.00

Preparation of a privacy policy tailored to your business

$1,990.00

Preparation of an engagement letter tailored to your business

$1,990.00

Disclaimer

This alert is for general information only and is not legal advice. AML/CTF obligations are fact-specific and must be implemented through your own AML/CTF Program. We recommend you seek tailored advice for your practice. New Era Lawyers is not liable for any reliance on this update.

Share the Post:

Related Posts

AML/CTF Update

Executive Summary  AUSTRAC has advised that the following are not regulated designated services:   Conveyancers acting for a seller who receive a deposit from a buyer in their trust

Read More