Ask a firm two months into the regime when it does enhanced customer due diligence and you usually get one answer: when the client is high risk. That answer is not wrong. It is one sixth of the rule.
AUSTRAC's guidance sets out six circumstances in which enhanced CDD must be applied, and it is blunt about the word must: "You must apply enhanced CDD in all circumstances set out in this section." Only the first of the six is the customer's risk rating. The other five are events. They can happen on a Tuesday afternoon, eight months after you opened the file, on a client your matrix scored low. (AUSTRAC, enhanced customer due diligence, updated 15 July 2026)
That is the difference between a rating and a trigger, and it is the difference between a policy that reads well and one that fires.
The Six Circumstances
Straight from the guidance, which points at section 32 of the Act and sections 6-20 of the Rules. You must apply enhanced CDD if:
- The customer's ML/TF risk is high. Whether you worked that out during initial CDD or it became high later, during ongoing CDD.
- You are required to submit a suspicious matter report about the customer and you intend to keep providing them a designated service.
- The service involves unusual, large or complex transactions. Specifically, transactions that are unusually complex or large, transactions with no apparent economic or legal purpose, or an unusual pattern of transactions.
- The designated service is or will be part of a nested services relationship.
- A foreign politically exposed person is involved. Your customer, any beneficial owner of the customer, any person on whose behalf the customer is receiving the service such as a trust beneficiary, or any person acting on behalf of the customer.
- Someone is located or formed in a high-risk jurisdiction that the Financial Action Task Force has called for enhanced CDD to be applied to. Same four categories of person as the PEP trigger.
Read the list again with your own client base in front of you. Numbers 2, 3, 5 and 6 are things you discover. Number 1 is often something you discover too, because AUSTRAC expects your policies to let you detect when a customer's risk becomes high, and gives customer monitoring alerts, changes in KYC information and a change in the kind of service being requested as the ways that happens. (AUSTRAC, enhanced customer due diligence, updated 15 July 2026)
Its own worked example is a client who was medium risk at onboarding and became high risk because they moved countries. Nobody re-scored that client at onboarding. Somebody noticed a change and re-scored them mid-relationship. If you have not read how to rate a client's risk as a thing you redo rather than a thing you did, that is the gap.
Foreign PEP, Not Any PEP
Worth being precise here, because firms get it wrong in both directions.
The automatic enhanced CDD trigger is a foreign PEP. A domestic PEP is not, by itself, an enhanced CDD trigger. AUSTRAC's PEP guidance says you must apply enhanced CDD if your customer, a beneficial owner, a person acting on behalf of the customer or a person on whose behalf the customer receives the service is a foreign PEP, and that you must also apply enhanced CDD to high ML/TF risk customers. (AUSTRAC, politically exposed persons, updated 29 July 2026)
So a domestic PEP reaches enhanced CDD through the risk-rating door, not the PEP door. That matters for a suburban accountant or conveyancer, whose PEP hits are far more likely to be a councillor or a senior public servant than a foreign minister.
The same page adds an initial CDD obligation that is easy to miss: before you provide the service, you must establish source of funds and source of wealth on reasonable grounds where the person is a foreign PEP, or a domestic or international organisation PEP whose ML/TF risk is high. If you are not sure of the difference between the two, we wrote up source of funds versus source of wealth and what to do when a client matches a PEP or sanctions list.
For the country trigger, the reference point is the FATF call to action, not a general feeling that a place is risky. Our FATF grey list explainer walks through which list does what, and AUSTRAC keeps its own guidance on managing risk from foreign jurisdictions. (AUSTRAC, high-risk countries, regions and groups, updated 22 April 2026)
The Trigger Most Small Firms Will Hit First
Number 3. Unusual, large or complex transactions.
Not because your clients are criminals, but because it is the trigger with the lowest bar and the widest surface. AUSTRAC's ongoing CDD guidance lists what counts as unusual, and several items on the list describe ordinary professional services work seen from a slightly different angle:
- transactions put through a service provider such as a lawyer or accountant for no apparent commercial or other reason
- using legal entity structures or corporate vehicles to conduct transactions for no apparent commercial reason, or to obscure ownership
- using trust funds or structures as a vehicle to move funds
- registering domestic companies that have no apparent commercial activity
- transactions involving income or wealth inconsistent with what you know about the client
- large cash deposits or withdrawals, or activity that appears structured to avoid reporting obligations
(AUSTRAC, what you must monitor, updated 31 March 2026)
Spotting one of those is not an accusation. AUSTRAC says so directly: customers may have unusual transactions or behaviour and that does not always mean they are doing something illegal. What it asks is that you decide, and that the decision has two possible outcomes. Either there is a legitimate explanation, or you take further action such as conducting enhanced CDD or submitting an SMR. (AUSTRAC, responding to unusual transactions and behaviour, updated 27 March 2026)
The failure mode is not choosing wrong. It is a file that shows the firm noticed nothing, on a matter where the file itself shows something worth noticing. That is the same test we pulled out of the MHITS transaction monitoring notice.
Enhanced CDD Is Not "Ask for More Documents"
This is where the guidance is sharper than most firms expect.
AUSTRAC lists the measures you might apply, and they are the familiar ones: collect or verify more KYC information, ask for the reason behind a transaction, establish source of funds or source of wealth, look harder at the background and ownership of the parties, review the relationship more often, update KYC information more frequently, monitor and analyse transactions in more depth.
Then it says this: "when carrying out enhanced CDD, we expect that this will include taking active steps to manage and mitigate any ML/TF risks, not just additional monitoring."
The examples it gives of active steps are the uncomfortable ones. Electing not to provide a designated service where it falls outside your risk appetite. Imposing a transaction limit on physical currency, or requiring the client to pay by bank transfer or EFTPOS. Escalating the matter to senior management so they can decide whether the firm is equipped to manage the risk at all. (AUSTRAC, enhanced customer due diligence, updated 15 July 2026)
Every measure you pick has to clear four tests. It must be targeted to that customer's specific risks, proportionate to the risk level, effective at managing and mitigating the risk, and appropriate to the risk duration, which means ongoing measures where the risk is ongoing behaviour rather than a one-off transaction.
There is a corollary worth saying plainly, because firms panic about it: you can still act for a client who needs enhanced CDD. The guidance says so. What you cannot do is act without policies that manage and mitigate the risk of doing so.
The SMR Trigger Has Its Own Clock
If enhanced CDD is triggered because you have to lodge an SMR, do not sequence them the intuitive way.
AUSTRAC is explicit: you are not required to complete enhanced CDD before you submit the SMR, and the SMR must go in within the required timeframes even if the enhanced CDD is still running. Those timeframes are 24 hours from forming the suspicion where it relates to terrorism financing, and three business days after the day you formed the suspicion for everything else. Where you claim legal professional privilege over information in the report, you have five business days, and that extension does not apply to terrorism financing. (AUSTRAC, suspicious matter reports, updated 8 July 2026)
One more thing about that trigger. An SMR sometimes names a client who is not the subject of the suspicion, a victim of suspected fraud for example. AUSTRAC does not expect enhanced CDD on that person unless it is needed to manage their own risk.
And while you are doing any of this, tipping off is live. The enhanced CDD guidance names it twice, once as a general warning about interacting with the customer, and once as something your policies must address: how you will manage tipping off obligations while conducting enhanced CDD. "Sorry, I have to ask a few more questions for compliance reasons" is a sentence worth agreeing on before somebody improvises it.
Four Things Your Policies Have to Say
Section 26F sits behind this. AUSTRAC expects your AML/CTF policies for enhanced CDD to set out all of:
- when you will apply which enhanced CDD measures, in response to which specific risks
- who in the business is responsible for applying enhanced CDD
- how you will monitor and review whether those measures are working
- how you will manage tipping off obligations while doing it
Then, separately, how you will respond to what enhanced CDD turns up: escalation, what happens if the measures cannot manage the risk, how the SMR gets lodged, and whether you continue the relationship or end it.
Note the second bullet. In a firm of four people, "who is responsible" is a name, and the honest answer is usually the same name as the compliance officer. That is fine. It just has to be written down, which is the point we made about three governance jobs and probably one head.
What Ends Up in the File
The record-keeping list in the guidance is short enough to use as a template. Document:
- the circumstances that required enhanced CDD, meaning which of the six triggers fired
- why you applied the specific measures you chose
- any additional information you collected
- how you verified it
- whether you submitted an SMR
- any change you made to the customer's risk rating as a result
- any decision to apply further measures, or to stop providing the service because the risk was unacceptable
Seven lines. Most of them one sentence each. That is the entire evidentiary difference between a firm that did enhanced CDD and a firm that says it did. Keep it with the rest of the client record under your normal record-keeping rules, and remember the amended Act does not want you hoarding copies of ID documents.
The Version of This You Can Actually Run
Three things, and none of them takes a weekend.
Write the six triggers into your procedure verbatim. Not "when a client is high risk". All six, in the order AUSTRAC lists them, with the name of the person who decides next to each one. If your Part A currently mentions only the risk rating, you have five gaps.
Give the triggers somewhere to land. A trigger nobody can raise is decoration. In practice that is one line in your file-opening checklist and one line in whatever monthly review you already do, asking whether anything on the list has happened since last time.
Pick your active steps in advance. Decide now, in calm conditions, what your firm does when enhanced CDD says the risk cannot be managed. Cash limit? Payment by transfer only? Decline the engagement? Senior manager sign-off? Choosing in the moment, with a client in the room and a settlement date approaching, is how firms end up with a file that documents a decision nobody would defend later.
Enhanced CDD is not a tier of client. It is what your program does when something happens. Six things, specifically. And running the program from here on is mostly the business of noticing them.
This article is general information, not legal advice. For advice specific to your circumstances, consult a qualified AML/CTF professional.
