AU
TransitionSource check: 18 July 2026

Australia KYC requirements

Australia now uses an express initial and ongoing customer due diligence framework. Section 28 requires a reporting entity to establish specified identity and risk matters on reasonable grounds before providing a designated service, subject to limited exceptions.

Primary lawAnti-Money Laundering and Counter-Terrorism Financing Act 2006
Lead sourceAUSTRAC
Baseline retentionUsually 7 years

01 / Scope

Who Australia KYC rules cover

Reporting entities that provide a designated service. The designated-service tables, exemptions, and transitional status determine whether the duties apply to a particular business.

02 / Start the check

When Australia customer due diligence starts

  • Before a reporting entity starts to provide a designated service to a customer, unless a statutory or rules-based exception permits later completion.
  • During the relationship when risk changes, unusual behavior appears, information is doubtful, or the risk-based review cycle calls for reverification.
  • Enhanced due diligence is required in the higher-risk circumstances set by section 32 and the AML/CTF Rules.

03 / Evidence

Identity data required for Australia KYC

  • Identity of the customer and any person for whom the service is received.
  • Identity and authority of a person acting for the customer.
  • For a non-individual customer, the identity of beneficial owners.
  • PEP and targeted-financial-sanctions status for the relevant people.
  • Nature and purpose of the relationship or occasional transaction, plus risk-appropriate KYC information.

Verification methods and evidence

  • Take reasonable steps to establish that an individual is who they claim to be.
  • Use collection and verification controls that are appropriate to the assessed ML/TF risk and satisfy the 2025 Rules.
  • Do not hard-code one document path for every customer; retain escalation routes for missing evidence and elevated risk.

04 / Entity customers

Beneficial-owner and representative checks

Section 28 expressly includes beneficial-owner identity for customers that are not individuals. The Rules govern simplified treatment and the detail of collection and verification.

05 / After onboarding

Ongoing KYC monitoring in Australia

Section 30 requires ongoing monitoring, including unusual-transaction and behavior detection, risk review, KYC updates, and risk-appropriate reverification.

Record retention

AUSTRAC describes retention periods as usually seven years. Identity-verification request records generally run for at least seven years and may run longer while designated services continue.

06 / Build notes

How to implement Australia KYC requirements

  1. Map each product to the current section 6 designated-service table before designing the flow.
  2. Store the reason a low-, standard-, or enhanced-due-diligence path was selected, not only the resulting documents.
  3. Make PEP, sanctions, authority-to-act, and beneficial-owner checks explicit fields in the case model.
  4. Version the policy logic so a reviewer can reconstruct which rules were applied on the decision date.

07 / Related answers

Questions behind international KYC implementation

08 / Source ledger

Primary sources for Australia KYC rules

We use regulator and legislation publishers here, not vendor explainers. Pinpoint citations show where to begin; the linked instrument controls.

01
AML/CTF Act 2006, current compilation

ss 27-32 Initial, ongoing, simplified, and enhanced customer due diligence.

02
AML/CTF Rules 2025

current compilation Operational detail for customer due diligence and beneficial owners.

03
AUSTRAC transitional rules

2026 transition guidance Who may continue former ACIP procedures and until when.

04
AUSTRAC record-keeping overview

record retention Regulator guidance on identity and transaction record periods.

Source review completed 18 July 2026. This page is a structured research summary, not a legal opinion or a substitute for sector-specific advice.