Customer Due Diligence
Customer due diligence is the obligation to know who you are dealing with before you provide a designated service to them. It is the obligation most of the daily work in Duely exists to satisfy.
The core rule sits in s 28(1) of the AML/CTF Act 2006: a reporting entity must not commence to provide a designated service until it has established, on reasonable grounds, each of the matters in s 28(2).
What must be established
Section 28(2) lists the matters. For most engagements they are:
- the identity of the customer
- the identity of anyone on whose behalf the customer is receiving the service
- the identity of anyone acting on behalf of the customer, and their authority to act
- where the customer is not an individual, the identity of its beneficial owners
- whether any of those people is a politically exposed person or a person designated for targeted financial sanctions
- the nature and purpose of the business relationship or occasional transaction
Because of that last item, due diligence covers more than identity. Understanding why the customer is engaging you, and what the engagement is for, is part of the obligation.
Two limbs for an individual customer
For an individual customer, s 28(3) splits the work into two limbs. Keep them separate in your own records, because one limb can be satisfied while the other is not.
| Limb | What it asks | Provision |
|---|---|---|
| Verify the information | Do the customer's details check out against reliable sources? | s 28(3)(d), all customers |
| Confirm the person | Are they the person they claim to be? | s 28(3)(a) |
The first limb is data matching. The second is identity binding, and matching a name and date of birth against a database does not, by itself, establish it. A record that a person's details were found in a reliable source is not the same record as one showing the human was confirmed to be that person.
Where the customer is not an individual, there is no person to bind in that sense, and the work shifts to verifying the entity and the individuals behind it. Entity structures need their beneficial owners and controllers recorded, as well as the company or trust itself.


Doing it before the service starts
The prohibition in s 28(1) is a timing rule: due diligence is completed before the service commences.
There is a limited exception. Section 29 allows a reporting entity to commence before completing initial due diligence, but only where all the conditions in s 29 are met. They include determining on reasonable grounds that delaying is essential to avoid interrupting the ordinary course of business, and that the additional risk from the delay is low. The firm must also already have policies that complete due diligence as soon as reasonably practicable and mitigate the risk the delay creates. The specifics are on Delayed CDD below.
Ongoing monitoring
Due diligence continues after the service starts. Under s 30(1) a reporting entity must monitor its customers to identify, assess, manage and mitigate its risks.
Two parts of s 30(2) apply day to day. The firm must:
- monitor for unusual transactions and behaviours that may give rise to a suspicious matter reporting obligation
- review and, where appropriate, update its identification and assessment of a customer's risk where there has been a significant change, where unusual transactions or behaviours appear, or in circumstances the Rules specify
This is ongoing customer monitoring: reviewing what you know about a customer, not watching a feed of payment transactions.
Enhanced due diligence
Some situations require more than the baseline. Section 32 sets out enhanced customer due diligence, which applies where the risk is assessed as high. It also applies where the firm has given a suspicious matter report and continues the service, where the customer is a foreign politically exposed person, where a high risk jurisdiction subject to a FATF call for action is involved, for nested services, and in other circumstances the Rules require.
Enhanced due diligence adds measures on top of the initial due diligence already completed, such as establishing source of funds or source of wealth and obtaining senior approval. The underlying identification and verification work does not need to be repeated.
In Duely, a high risk rating can trigger an enhanced due diligence case on the matter. The added measures and the approval behind them are recorded against it, which makes the escalation defensible.
Delayed CDD: when the law allows it
Delayed initial due diligence is available under s 29, on routes set out in the AML/CTF Rules 2025. Two routes are most relevant to the firms this knowledge base covers:
| Route | Rule | Deadline |
|---|---|---|
| Designated service at or through an Australian permanent establishment (general) | Rules s 6-12 | As soon as reasonably practicable, and no later than 20 business days, and always before money or property is transferred or made available |
| Real estate transaction | Rules s 6-32 | As soon as reasonably practicable, and no later than 28 days after exchange of contracts, or 3 days before the initially agreed settlement day, whichever is earliest |
Three points about the real estate route are commonly misunderstood:
- One window covers both roles. A real estate agent delaying due diligence on the party they are not acting for, and a legal practitioner or conveyancer acting for a buyer or transferee, are on the same rule.
- The settlement limb is anchored to the initially agreed settlement day. A settlement that slips does not extend the deadline, and one brought forward does not pull it in.
- The two gateway determinations in s 29, that the delay is essential and the additional risk is low, must be made before the service starts, and recorded.
What this means in Duely
Duely makes this obligation executable: scoping each engagement, capturing customers and their beneficial owners, recording the verification and the basis for it, assessing risk, and escalating to enhanced due diligence where the rating requires it.
Those mechanics are covered in Using Duely, which has task-level guides for each step.
AUSTRAC's published guidance for this obligation is Delayed initial customer due diligence, and for entity customers Initial CDD: body corporate, partnership or unincorporated association.
Related pages
- Obligations overview, for the designated service test that decides whether due diligence is required at all.
- Record keeping, for how long due diligence records must be kept.
- Reporting, because monitoring under s 30 feeds suspicious matter reporting.
- Onboarding a customer and Verifying identity, for the product steps.