As an accountant providing designated services, you must verify your clients before you start work — not after. This practical checklist covers exactly what you need to collect, verify and store for every client under AUSTRAC's rules from 1 July 2026.

Use this checklist for every new client engagement where you are providing a designated service: company registrations via ASIC, trust formations, business sales, equity or debt financing, or any trust and company service provider function.

Reminder: regular tax returns, BAS lodgements and general bookkeeping do not trigger these requirements. This checklist applies only to your designated services.

Before You Start: Determine the Client Type

The checks you need to perform depend on who your client is. Identify which of these applies:

  • Individual or sole trader
  • Company (proprietary limited, public, etc.)
  • Trust (family trust, unit trust, SMSF, etc.)
  • Partnership
  • Association (incorporated or unincorporated)

Checklist A — Individual Clients

  • ☐ Collect full legal name, date of birth and residential address
  • ☐ Collect occupation and the nature and purpose of the engagement
  • ☐ Verify name and date of birth via electronic DVS check (driver licence, passport or Medicare)
  • ☐ Capture and authenticate ID document (if electronic check is not available or as additional verification)
  • ☐ Complete biometric face match (selfie matched to ID document photo)
  • ☐ Screen against DFAT Consolidated List (sanctions)
  • ☐ Check if client is a PEP (domestic, foreign or international organisation)
  • ☐ Assign risk rating: Low, Medium or High
  • ☐ If High risk — escalate to compliance officer before proceeding
  • ☐ Record all results and store for 7 years

Checklist B — Company Clients

  • ☐ Collect company name, ACN and registered address
  • ☐ Obtain current ASIC company extract (no more than 6 months old)
  • ☐ Identify all directors
  • ☐ Identify all shareholders with 25% or more ownership
  • ☐ Map the full beneficial ownership chain back to the individuals who ultimately own or control the company
  • ☐ Complete Individual Checklist A for each director and each 25%+ shareholder
  • ☐ Note any nominee arrangements and verify the underlying beneficial owner
  • ☐ Collect company constitution if available
  • ☐ Verify nature of business activities
  • ☐ Screen company name and all individuals against DFAT Consolidated List
  • ☐ Check all individuals for PEP status
  • ☐ Assign risk rating to the client as a whole
  • ☐ Record all results and store for 7 years

Checklist C — Trust Clients

  • ☐ Obtain a copy of the trust deed (or relevant extracts) and any deeds of variation
  • ☐ Identify the trustee (individual or corporate)
  • ☐ If corporate trustee — complete Company Checklist B for the trustee company
  • ☐ If individual trustee — complete Individual Checklist A
  • ☐ Identify the settlor
  • ☐ Identify all appointors and protectors
  • ☐ Identify all beneficiaries (or the class of beneficiaries if not yet determined)
  • ☐ For discretionary trusts — identify beneficiaries entitled to 25% or more of distributions if determinable
  • ☐ For unit trusts — identify unit holders with 25% or more of units
  • ☐ Complete Individual Checklist A for all identified individual beneficial owners
  • ☐ Screen all individuals and entities against DFAT Consolidated List
  • ☐ Check all individuals for PEP status
  • ☐ Assign risk rating to the client as a whole
  • ☐ Record all results and store for 7 years

After Completing CDD

  • ☐ Record the date initial CDD was completed — this starts your periodic review clock
  • ☐ Set a calendar reminder for the next periodic review (12 months for High, 2 years for Medium, 3 years for Low)
  • ☐ Monitor the client for unusual activity throughout the engagement
  • ☐ If anything suspicious arises — escalate to your AML/CTF compliance officer immediately

Storing Your CDD Records

All records from the checklists above must be stored for a minimum of 7 years. This includes the verification results, document images, screening results, risk ratings and any notes about the engagement. Records must be stored securely, accessible to AUSTRAC on request, and in English or convertible to English.

A purpose-built platform like VerifyID Online handles the collection, verification and 7-year storage automatically — generating a complete PDF certificate for each client that you can add to your file.

Ready to Verify Clients the Compliant Way?

VerifyID Online handles your AUSTRAC identity verification obligations. Set up in 10 minutes.

Join the Waitlist →