01 / Scope
Who Australia KYC rules cover
Reporting entities that provide a designated service. The designated-service tables, exemptions, and transitional status determine whether the duties apply to a particular business.
02 / Start the check
When Australia customer due diligence starts
- Before a reporting entity starts to provide a designated service to a customer, unless a statutory or rules-based exception permits later completion.
- During the relationship when risk changes, unusual behavior appears, information is doubtful, or the risk-based review cycle calls for reverification.
- Enhanced due diligence is required in the higher-risk circumstances set by section 32 and the AML/CTF Rules.
03 / Evidence
Identity data required for Australia KYC
- Identity of the customer and any person for whom the service is received.
- Identity and authority of a person acting for the customer.
- For a non-individual customer, the identity of beneficial owners.
- PEP and targeted-financial-sanctions status for the relevant people.
- Nature and purpose of the relationship or occasional transaction, plus risk-appropriate KYC information.
Verification methods and evidence
- Take reasonable steps to establish that an individual is who they claim to be.
- Use collection and verification controls that are appropriate to the assessed ML/TF risk and satisfy the 2025 Rules.
- Do not hard-code one document path for every customer; retain escalation routes for missing evidence and elevated risk.
04 / Entity customers
Beneficial-owner and representative checks
Section 28 expressly includes beneficial-owner identity for customers that are not individuals. The Rules govern simplified treatment and the detail of collection and verification.
05 / After onboarding
Ongoing KYC monitoring in Australia
Section 30 requires ongoing monitoring, including unusual-transaction and behavior detection, risk review, KYC updates, and risk-appropriate reverification.
Record retention
AUSTRAC describes retention periods as usually seven years. Identity-verification request records generally run for at least seven years and may run longer while designated services continue.
06 / Build notes
How to implement Australia KYC requirements
- Map each product to the current section 6 designated-service table before designing the flow.
- Store the reason a low-, standard-, or enhanced-due-diligence path was selected, not only the resulting documents.
- Make PEP, sanctions, authority-to-act, and beneficial-owner checks explicit fields in the case model.
- Version the policy logic so a reviewer can reconstruct which rules were applied on the decision date.
07 / Related answers
Questions behind international KYC implementation
08 / Source ledger
Primary sources for Australia KYC rules
We use regulator and legislation publishers here, not vendor explainers. Pinpoint citations show where to begin; the linked instrument controls.
ss 27-32 Initial, ongoing, simplified, and enhanced customer due diligence.
current compilation Operational detail for customer due diligence and beneficial owners.
2026 transition guidance Who may continue former ACIP procedures and until when.
record retention Regulator guidance on identity and transaction record periods.
Source review completed 18 July 2026. This page is a structured research summary, not a legal opinion or a substitute for sector-specific advice.