Pull up your client list. If you are an accountant or a lawyer in Australia, a big slice of it is trusts, mostly family discretionary trusts sitting behind small businesses and investment portfolios. They are completely routine to you.
They are not routine to AUSTRAC. The National Money Laundering Risk Assessment 2024 rated trusts a high national money laundering risk and called the poor transparency of trusts one of Australia's key vulnerabilities to criminal exploitation. That rating is baked into the CDD rules you now operate under: for a trust customer, the list of people you must identify is longer than for any other customer type, and it is longer than most firms expect.
To be clear on the flip side, AUSTRAC says it plainly: a high national risk rating does not make every trust a high risk customer. Your ordinary client with a vanilla family trust can still come out low risk. But you only get there by working through the file properly first. (Initial CDD for a trust, AUSTRAC reforms guidance)
First question: is what you are doing for the trust even captured?
Before any of the identification work below, check the trigger. CDD obligations arise when you provide a designated service, and for accountants and lawyers the professional services table captures things like creating or restructuring a trust, acting as trustee of one (or arranging for someone to), receiving, holding or managing the trust's money and property as part of planning or executing a transaction, and assisting with its real estate transactions. (Professional services, AUSTRAC reforms guidance)
Preparing the trust's annual accounts and lodging its tax returns, on its own, is generally not a designated service. If tax compliance is truly all you do for a trust, the CDD machinery below may never switch on for that client. The moment the engagement widens (the deed gets varied on your advice, you handle settlement funds for a property the trust is buying, a new trust gets set up), you are in, and the clock starts before you provide the service.
The full cast of characters
For a trust customer, AUSTRAC's reforms guidance says you must establish, on reasonable grounds:
- The identity of the trust itself. Full name, kind of trust, any business names, its ABN if it has one, where it operates from, and evidence it exists at all. That evidence is generally the trust deed (or a will or letters of administration for an estate). You also need to understand the powers that bind and govern the trust, which again lives in the deed.
- The beneficiaries. Every beneficiary, identified individually. Where the nature of the trust makes that impossible, a description of each class of beneficiaries instead. More on this below, because for discretionary trusts this is the wrinkle that matters.
- The trustees and anyone acting for the trust. Each trustee, and any other representative who deals with you, plus their authority to act.
- The beneficial owners. This is the long one. It includes all individual trustees, the beneficial owners of any corporate trustee, and the settlor, appointor, guardian and protector of the trust, plus any other individual who controls the trust. In some cases it includes beneficiaries too.
- Whether any of those people are PEPs or sanctioned. Politically exposed person and targeted financial sanctions checks run across the people you have just identified, not only the person sitting in your meeting room.
- The nature and purpose of the business relationship. Why this trust is engaging you, recorded in the file.
A beneficial owner, under the amended Act, is an individual who owns 25% or more of the customer or who controls it, and control includes practical influence, not just formal voting rights. (Determining ownership and control structures, AUSTRAC)
There are narrow carve-outs from the beneficial owner step: a low risk trust that is (or is controlled by) a prudentially regulated entity or a strata corporation, and customers that are (or are controlled by) listed public companies or government bodies. Your average family trust is none of these, so assume the full list applies.
What that looks like on a real file
Take a setup you have seen a hundred times. The Harper Family Trust, a discretionary trust. Corporate trustee Harper Nominees Pty Ltd, with Kate and David Harper as directors and equal shareholders. Kate and David are the primary beneficiaries, with the usual class of secondary beneficiaries: children and future descendants. Kate is the appointor. The settlor was the family's previous accountant, who contributed the customary $10 twenty years ago.
The engagement that triggers everything: the Harpers have asked your firm to restructure the trust, updating the deed and the trustee arrangements. Assisting in the restructure of a legal arrangement is a designated service, so before you act, CDD.
Working the list:
- The trust: name, type (discretionary), ABN, and the deed as evidence it exists, including any deeds of variation. If there have been three variations since 2006, you want those too, because the current appointor may not be the one on page one.
- Beneficiaries: Kate and David identified by name. The children and future descendants recorded as a class, straight from the deed.
- Trustee: Harper Nominees Pty Ltd, identified as a company, which means its own beneficial owners get identified: Kate and David again, as 50/50 shareholders.
- Beneficial owners of the trust: Kate and David (through the corporate trustee), Kate again as appointor, because the power to appoint and remove trustees is control. And the settlor's identity information collected, yes, even for the $10 accountant. The reforms guidance lists settlors alongside appointors, guardians and protectors as identities you must collect.
- Screening: PEP and sanctions checks across Kate, David and the settlor.
- Purpose: restructure of the trust, recorded.
One ordinary family trust file, five distinct identification jobs and three people screened. Nobody exotic, nothing suspicious, and the risk rating at the end may well be low. But every step needs to be in the file, because "we have acted for the Harpers for fifteen years" is not a CDD record.
The discretionary trust wrinkle: classes of beneficiaries
The rule that saves the family trust file from absurdity: where you cannot identify each beneficiary because of the nature of the trust, you collect a description of each class instead. A discretionary trust whose secondary beneficiaries are "the children and remoter issue of the primary beneficiaries" does not require you to identify people who have not been born.
You verify the class description against the trust deed, or against evidence of actual trust activity such as distribution statements. For named beneficiaries, you identify them the same way you would if they were the customer, an individual as an individual, a corporate beneficiary as a company.
The trap runs the other way: treating everything as a class. If the deed names specific primary beneficiaries, they are identifiable, so identify them.
What verifies what
The good news is that the verification sources for a trust are documents you probably already hold or can get in one email:
- The trust deed, with amendments. Verifies existence, powers, trustees, appointor, named beneficiaries and classes.
- ABN Lookup. Verifies the trust's ABN details against the Australian Business Register, free.
- Letters from the trust's independent professional advisers. AUSTRAC specifically notes these should come from someone who does not hold a role in the trust. The trust's lawyer, not the trustee.
- Trustee resolutions and the memorandum of trust. Useful for verifying how control and decisions actually work.
And the individuals you surface (trustees, appointor, settlor, beneficial owners of a corporate trustee) get verified the way any individual does.
One more thing worth knowing: you are not required to keep copies of these documents. AUSTRAC's guidance says you can record the details instead, which matters more than it sounds, because a drawer full of certified deed copies and licence scans is a data breach waiting to happen. We have written before about what to keep and what to destroy.
The honest part
None of this requires software. AUSTRAC's accountant starter kit even ships a paper initial CDD form for trusts, and if your trust clients number in the single digits, a disciplined form-and-folder system will hold up.
Where it breaks down is volume and repetition. Thirty trust files means thirty deeds, ninety-odd individuals, PEP and sanctions screening on each of them, and a record of all of it that you can produce when asked. That is the part AML Mate systematises: a trust client type that prompts for trustees, beneficiaries and controllers, ABN verification against the ABR in one click, beneficial owner records with per-person PEP and sanctions screening, and a verification trail kept for the seven years the Act demands. The thinking is still yours. The filing is not.
If you are mid-way through your first trust files this month, two other pieces pair well with this one: beneficial ownership and UBO verification in Australia and what to do when a screening check comes back with a match.
Not sure where your gaps are? The free compliance check takes two minutes, no signup, and shows you where your current setup stands against the new obligations.
This is general information drawn from AUSTRAC's reforms guidance as at July 2026, not legal advice. Trust structures vary; confirm how the rules apply to your specific clients with a qualified adviser.
