Compliance11 min read

Enhanced CDD Is Not a Risk Rating. AUSTRAC Lists Six Triggers, and Five Fire After Onboarding.

Most firms treat enhanced customer due diligence as a label attached to a high risk client on the day the file is opened. AUSTRAC's guidance lists six circumstances that require it, and only one of them is the risk rating. The other five can fire months into a matter, on a client you marked low. Here is each trigger, what the measures actually have to do, and what has to end up in the file.

2026-09-07· AML Mate Team
Enhanced CDD Is Not a Risk Rating. AUSTRAC Lists Six Triggers, and Five Fire After Onboarding.

Ask a firm two months into the regime when it does enhanced customer due diligence and you usually get one answer: when the client is high risk. That answer is not wrong. It is one sixth of the rule.

AUSTRAC's guidance sets out six circumstances in which enhanced CDD must be applied, and it is blunt about the word must: "You must apply enhanced CDD in all circumstances set out in this section." Only the first of the six is the customer's risk rating. The other five are events. They can happen on a Tuesday afternoon, eight months after you opened the file, on a client your matrix scored low. (AUSTRAC, enhanced customer due diligence, updated 15 July 2026)

That is the difference between a rating and a trigger, and it is the difference between a policy that reads well and one that fires.

The Six Circumstances

Straight from the guidance, which points at section 32 of the Act and sections 6-20 of the Rules. You must apply enhanced CDD if:

  1. The customer's ML/TF risk is high. Whether you worked that out during initial CDD or it became high later, during ongoing CDD.
  2. You are required to submit a suspicious matter report about the customer and you intend to keep providing them a designated service.
  3. The service involves unusual, large or complex transactions. Specifically, transactions that are unusually complex or large, transactions with no apparent economic or legal purpose, or an unusual pattern of transactions.
  4. The designated service is or will be part of a nested services relationship.
  5. A foreign politically exposed person is involved. Your customer, any beneficial owner of the customer, any person on whose behalf the customer is receiving the service such as a trust beneficiary, or any person acting on behalf of the customer.
  6. Someone is located or formed in a high-risk jurisdiction that the Financial Action Task Force has called for enhanced CDD to be applied to. Same four categories of person as the PEP trigger.

Read the list again with your own client base in front of you. Numbers 2, 3, 5 and 6 are things you discover. Number 1 is often something you discover too, because AUSTRAC expects your policies to let you detect when a customer's risk becomes high, and gives customer monitoring alerts, changes in KYC information and a change in the kind of service being requested as the ways that happens. (AUSTRAC, enhanced customer due diligence, updated 15 July 2026)

Its own worked example is a client who was medium risk at onboarding and became high risk because they moved countries. Nobody re-scored that client at onboarding. Somebody noticed a change and re-scored them mid-relationship. If you have not read how to rate a client's risk as a thing you redo rather than a thing you did, that is the gap.

Foreign PEP, Not Any PEP

Worth being precise here, because firms get it wrong in both directions.

The automatic enhanced CDD trigger is a foreign PEP. A domestic PEP is not, by itself, an enhanced CDD trigger. AUSTRAC's PEP guidance says you must apply enhanced CDD if your customer, a beneficial owner, a person acting on behalf of the customer or a person on whose behalf the customer receives the service is a foreign PEP, and that you must also apply enhanced CDD to high ML/TF risk customers. (AUSTRAC, politically exposed persons, updated 29 July 2026)

So a domestic PEP reaches enhanced CDD through the risk-rating door, not the PEP door. That matters for a suburban accountant or conveyancer, whose PEP hits are far more likely to be a councillor or a senior public servant than a foreign minister.

The same page adds an initial CDD obligation that is easy to miss: before you provide the service, you must establish source of funds and source of wealth on reasonable grounds where the person is a foreign PEP, or a domestic or international organisation PEP whose ML/TF risk is high. If you are not sure of the difference between the two, we wrote up source of funds versus source of wealth and what to do when a client matches a PEP or sanctions list.

For the country trigger, the reference point is the FATF call to action, not a general feeling that a place is risky. Our FATF grey list explainer walks through which list does what, and AUSTRAC keeps its own guidance on managing risk from foreign jurisdictions. (AUSTRAC, high-risk countries, regions and groups, updated 22 April 2026)

The Trigger Most Small Firms Will Hit First

Number 3. Unusual, large or complex transactions.

Not because your clients are criminals, but because it is the trigger with the lowest bar and the widest surface. AUSTRAC's ongoing CDD guidance lists what counts as unusual, and several items on the list describe ordinary professional services work seen from a slightly different angle:

  • transactions put through a service provider such as a lawyer or accountant for no apparent commercial or other reason
  • using legal entity structures or corporate vehicles to conduct transactions for no apparent commercial reason, or to obscure ownership
  • using trust funds or structures as a vehicle to move funds
  • registering domestic companies that have no apparent commercial activity
  • transactions involving income or wealth inconsistent with what you know about the client
  • large cash deposits or withdrawals, or activity that appears structured to avoid reporting obligations

(AUSTRAC, what you must monitor, updated 31 March 2026)

Spotting one of those is not an accusation. AUSTRAC says so directly: customers may have unusual transactions or behaviour and that does not always mean they are doing something illegal. What it asks is that you decide, and that the decision has two possible outcomes. Either there is a legitimate explanation, or you take further action such as conducting enhanced CDD or submitting an SMR. (AUSTRAC, responding to unusual transactions and behaviour, updated 27 March 2026)

The failure mode is not choosing wrong. It is a file that shows the firm noticed nothing, on a matter where the file itself shows something worth noticing. That is the same test we pulled out of the MHITS transaction monitoring notice.

Enhanced CDD Is Not "Ask for More Documents"

This is where the guidance is sharper than most firms expect.

AUSTRAC lists the measures you might apply, and they are the familiar ones: collect or verify more KYC information, ask for the reason behind a transaction, establish source of funds or source of wealth, look harder at the background and ownership of the parties, review the relationship more often, update KYC information more frequently, monitor and analyse transactions in more depth.

Then it says this: "when carrying out enhanced CDD, we expect that this will include taking active steps to manage and mitigate any ML/TF risks, not just additional monitoring."

The examples it gives of active steps are the uncomfortable ones. Electing not to provide a designated service where it falls outside your risk appetite. Imposing a transaction limit on physical currency, or requiring the client to pay by bank transfer or EFTPOS. Escalating the matter to senior management so they can decide whether the firm is equipped to manage the risk at all. (AUSTRAC, enhanced customer due diligence, updated 15 July 2026)

Every measure you pick has to clear four tests. It must be targeted to that customer's specific risks, proportionate to the risk level, effective at managing and mitigating the risk, and appropriate to the risk duration, which means ongoing measures where the risk is ongoing behaviour rather than a one-off transaction.

There is a corollary worth saying plainly, because firms panic about it: you can still act for a client who needs enhanced CDD. The guidance says so. What you cannot do is act without policies that manage and mitigate the risk of doing so.

The SMR Trigger Has Its Own Clock

If enhanced CDD is triggered because you have to lodge an SMR, do not sequence them the intuitive way.

AUSTRAC is explicit: you are not required to complete enhanced CDD before you submit the SMR, and the SMR must go in within the required timeframes even if the enhanced CDD is still running. Those timeframes are 24 hours from forming the suspicion where it relates to terrorism financing, and three business days after the day you formed the suspicion for everything else. Where you claim legal professional privilege over information in the report, you have five business days, and that extension does not apply to terrorism financing. (AUSTRAC, suspicious matter reports, updated 8 July 2026)

One more thing about that trigger. An SMR sometimes names a client who is not the subject of the suspicion, a victim of suspected fraud for example. AUSTRAC does not expect enhanced CDD on that person unless it is needed to manage their own risk.

And while you are doing any of this, tipping off is live. The enhanced CDD guidance names it twice, once as a general warning about interacting with the customer, and once as something your policies must address: how you will manage tipping off obligations while conducting enhanced CDD. "Sorry, I have to ask a few more questions for compliance reasons" is a sentence worth agreeing on before somebody improvises it.

Four Things Your Policies Have to Say

Section 26F sits behind this. AUSTRAC expects your AML/CTF policies for enhanced CDD to set out all of:

  • when you will apply which enhanced CDD measures, in response to which specific risks
  • who in the business is responsible for applying enhanced CDD
  • how you will monitor and review whether those measures are working
  • how you will manage tipping off obligations while doing it

Then, separately, how you will respond to what enhanced CDD turns up: escalation, what happens if the measures cannot manage the risk, how the SMR gets lodged, and whether you continue the relationship or end it.

Note the second bullet. In a firm of four people, "who is responsible" is a name, and the honest answer is usually the same name as the compliance officer. That is fine. It just has to be written down, which is the point we made about three governance jobs and probably one head.

What Ends Up in the File

The record-keeping list in the guidance is short enough to use as a template. Document:

  • the circumstances that required enhanced CDD, meaning which of the six triggers fired
  • why you applied the specific measures you chose
  • any additional information you collected
  • how you verified it
  • whether you submitted an SMR
  • any change you made to the customer's risk rating as a result
  • any decision to apply further measures, or to stop providing the service because the risk was unacceptable

Seven lines. Most of them one sentence each. That is the entire evidentiary difference between a firm that did enhanced CDD and a firm that says it did. Keep it with the rest of the client record under your normal record-keeping rules, and remember the amended Act does not want you hoarding copies of ID documents.

The Version of This You Can Actually Run

Three things, and none of them takes a weekend.

Write the six triggers into your procedure verbatim. Not "when a client is high risk". All six, in the order AUSTRAC lists them, with the name of the person who decides next to each one. If your Part A currently mentions only the risk rating, you have five gaps.

Give the triggers somewhere to land. A trigger nobody can raise is decoration. In practice that is one line in your file-opening checklist and one line in whatever monthly review you already do, asking whether anything on the list has happened since last time.

Pick your active steps in advance. Decide now, in calm conditions, what your firm does when enhanced CDD says the risk cannot be managed. Cash limit? Payment by transfer only? Decline the engagement? Senior manager sign-off? Choosing in the moment, with a client in the room and a settlement date approaching, is how firms end up with a file that documents a decision nobody would defend later.

Enhanced CDD is not a tier of client. It is what your program does when something happens. Six things, specifically. And running the program from here on is mostly the business of noticing them.


This article is general information, not legal advice. For advice specific to your circumstances, consult a qualified AML/CTF professional.

enhanced-cddcustomer-due-diligenceongoing-cddaustracrisk-ratingpepsource-of-fundssmrtranche-2accountantslegalreal-estateconveyancersjewellers

Related Articles

Compliance

Another Firm Already Verified Your Client. AUSTRAC Lets You Rely on That in Two Ways, and Both Come With Paperwork.

Ten weeks into the regime, the CDD question that keeps coming up is not how to verify a client. It is whether you have to, when another firm in the same transaction already did. AUSTRAC's answer is yes, in two forms: a case-by-case file note, or a written arrangement a senior manager approves and you reassess at least every two years. Here are the conditions, what the referring firm has to hand over, and why an ID-check vendor never counts.

Compliance

AUSTRAC Is Investigating Western Union. The Test It Named Is 'Known Patterns', and It Has Already Published Yours.

On 1 September 2026 AUSTRAC opened an enforcement investigation into Western Union and, unusually, published both the file behind the decision and the three tests it will run: does the program work, does monitoring catch known patterns, and who really makes the decisions. Here is each test at the scale of a four-person practice, and why the sequence that led here matters more than the name on the release.

Compliance

The Client Wants to Start Today and the Checks Are Not Finished. AUSTRAC Allows That, on Two Conditions and a 20 Day Clock.

Initial CDD comes before the service. There is a narrow exception, and ten weeks into the regime it is the one firms reach for without having read it. You may start before verification is finished, but only if delay is essential to avoid interrupting the ordinary course of business and the added ML/TF risk is low. Here is what you can actually delay, what never moves, and the 20 business day clock that starts the moment you act.

Ready to build your AML/CTF program?

AML Mate generates your AML/CTF program in 15 minutes using AUSTRAC's official templates. Start a 14-day free trial, cancel anytime.

This article is based on AUSTRAC's publicly available guidance. It does not constitute legal or compliance advice. Consult a licensed compliance professional for complex situations.