AML/CTF News and Insights | AMLHUB

What is Customer Due Diligence (CDD)

Written by Dylan Gallagher | 24/07/2026 1:40:11 AM

What Is CDD? A Practical Guide for Australian Real Estate Agents

A new vendor wants to list a $3 million property. They’re friendly. They’re organised. And they want the property on the market yesterday.

Before you act, however, there’s a question your agency needs to answer: Do we really know who this customer is? That’s where Customer Due Diligence (CDD) comes in.

From 1 July 2026, Australian real estate businesses providing designated services became subject to the expanded Anti-Money Laundering and Counter-Terrorism Financing regime. CDD is now part of everyday client onboarding.

At first glance, CDD can sound complicated. In reality, it is built around one simple idea: knowing who you are dealing with before providing a designated service.

CDD means identifying your customer, verifying appropriate information, understanding who ultimately owns or controls them, and assessing their money laundering, terrorism financing and proliferation financing risk, collectively referred to as ML/TF risk. You may also hear it called Know Your Customer, or (KYC). Although the terms are often used interchangeably, KYC information forms part of the broader CDD process.

CDD does not mean interrogating every vendor like you are starring in a crime drama. It means following a consistent process so criminals cannot easily hide behind false identities, nominees, companies, trusts or complicated ownership structures.

 

What Does CDD Involve?

For most real estate agents, CDD involves:

• identifying the customer and relevant connected parties;

• collecting and verifying appropriate CDD information;

• identifying and verifying beneficial owners;

• understanding the nature and purpose of the relationship; and

• assessing ML/TF risk and completing relevant PEP and targeted financial sanctions checks.

 

Who Is the Customer?

When brokering a real estate transaction, both the seller and buyer are customers for AML/CTF purposes, even if your agency acts for only one party. The designated service doesn't always begin at the same time for both customers. For the seller, it generally starts when the agency agreement is signed. For the buyer, it generally starts once the sale is reasonably expected to proceed, typically after the offer has been accepted and the contract signed.

Who must be identified and verified then depends on whether the customer is an individual, company, trust or another type of entity.


Individuals

For an individual, you will generally collect and verify information such as their full legal name, date of birth and residential address. Verification must use reliable and independent documents, information or data.

A straightforward individual with a current Australian passport or driver licence will usually be easier to onboard than someone acting through three companies and a family trust. The more complex the ownership structure, the more work is typically required.

Electronic identity verification can make the process faster, but clicking “verified” is not the entire job. Your agency must still assess the customer’s circumstances and risk, then decide whether further enquiries are required.

Beneficial Owners and Effective Control

A beneficial owner is an individual who directly or indirectly owns 25% or more of a customer, or otherwise controls them. Ownership may be held through another company or a chain of entities. Ownership and control are not always the same. Someone may own relatively few shares—or none at all—but still control voting rights, appoint or remove directors, direct major decisions or exercise significant influence.

Companies and Trusts

For a company, you generally need its registration details, directors, ownership structure, beneficial owners, effective controllers and anyone acting on its behalf.

The difficult part is rarely confirming that the company exists. The real work is following the ownership trail until you reach the individuals who ultimately own or control it. A company owned equally by two people may be simple. A company owned by a holding company controlled through a trust may require more digging.

Trusts may involve the trust itself, individual or corporate trustees, beneficial owners, appointors, other controlling parties and people acting on the trust’s behalf. Where a corporate trustee is involved, you may also need to examine that company’s ownership and control.

When Must CDD Be Completed?

As a general rule, CDD must be completed before you begin providing the designated service, although limited delayed-CDD exceptions may apply. Identity verification should not become a settlement-day clean-up job. Starting early helps identify ownership issues, higher-risk circumstances or missing information before the transaction gathers momentum.

If you cannot complete the required CDD, you generally must not begin providing the designated service. Build the process into onboarding from the start.

What If the Customer Has No Photo ID?

No passport? No driver licence? Not necessarily the end of the road.

A person without conventional photo identification may still be verified using alternative reliable and independent documents, information or data permitted by your agency’s procedures. It is essential that you follow your verification procedures and record how you became reasonably satisfied of their identity.

Do Pre-Commencement Customers Need CDD?

You do not need to complete initial CDD on every pre-commencement customer immediately. Initial CDD is generally triggered if a Suspicious Matter Report obligation arises, or there is a significant change in the nature and purpose of the business relationship that results in the customer’s ML/TF risk being medium or high.

However ongoing CDD still applies, including monitoring unusual transactions and behaviour, reviewing and updating relevant CDD information, and watching for significant changes in the relationship.

 

Your Quick CDD Checklist: Before providing a designated service, ask:


• Do we know who the customer is?

• Have we verified the required CDD information?

• Do we know who ultimately owns or controls them?

• Do we understand the nature and purpose of the relationship?

• Have we assessed their ML/TF risk?

• Have we completed relevant PEP and sanctions checks?

• Are enhanced checks required?


Exactly what you check will depend on the designated service, the customer’s risk and the procedures in your AML/CTF program. Higher-risk customers may require enhanced CDD, including additional CDD information and, where relevant to the risk, enquiries into source of funds and source of wealth. The goal is not to apply maximum friction to every customer. It is to apply the right checks to the risk in front of you.

 

Contact AMLHUB today to book a demo or discuss how we can help your organisation transition seamlessly into the new regime.