days leftTranche 2 is live — Compliance Kickstart: 20% off for 6 months. Ends 30 September 2026.
AMLify logoAMLify
Compliance Guides

Customer Due Diligence Obligations for TCSPs

11 August 20264 min readAMLify Team
Customer Due Diligence Obligations for TCSPs

What customer due diligence involves for trust and company service providers under the AML/CTF Act 2006, from beneficial ownership to EDD triggers.

Trust and company service providers (TCSPs) must apply customer due diligence (CDD) to every client relationship before providing a designated service -- verifying who the client is, who ultimately owns or controls them, and why the trust or company structure is being used. Under the AML/CTF Act 2006, this has applied in full since Tranche 2 commenced, and it doesn't stop at onboarding: CDD is an ongoing duty for as long as the relationship lasts.

Who counts as a trust and company service provider under Tranche 2?

A TCSP is any business that, as a service to a client, forms companies or trusts, acts (or arranges for someone else to act) as a director, secretary, trustee, or nominee shareholder, provides a registered office, or otherwise acts as a formation or registered agent. Tranche 2 brought these services within the AML/CTF Act 2006's definition of a designated service for the first time, so TCSPs now carry the same CDD obligations that have long applied to banks.

What does customer due diligence involve for TCSP clients?

For every new client, a TCSP must: 1. Identify and verify the client's identity using reliable, independent documentation 2. Identify beneficial owners -- anyone with 25% or more ownership or effective control of the entity behind the structure 3. Understand the purpose of the trust or company arrangement, including why a particular jurisdiction or structure was chosen 4. Screen for sanctions and PEP exposure among the client and its beneficial owners 5. Apply ongoing monitoring, refreshing CDD whenever circumstances change AUSTRAC expects these records to stay current -- particularly when a trust's beneficiaries change or a company's directors or shareholders are replaced.

When must a TCSP apply enhanced due diligence?

Enhanced due diligence (EDD) applies wherever a relationship presents higher money laundering or terrorism financing risk. For TCSPs, that typically means nominee director or shareholder arrangements that obscure the real controller, multi-layered structures spanning several jurisdictions, a politically exposed person among the owners, or a structure with no clear commercial rationale beyond privacy. Where EDD applies, gather source-of-wealth information, verify the ownership chain back to the natural persons in control, and monitor the relationship more frequently.

How can AMLify help TCSPs meet CDD obligations?

Manually tracing beneficial ownership through layered trust and company structures is where most TCSPs lose time -- and where gaps hide. AMLify for trust and company service providers builds a TCSP-specific CDD workflow that captures beneficial ownership, screens for sanctions and PEP exposure, and flags when a structure needs EDD, all inside one audit-ready record. See pricing to start a free trial.

Key Takeaways

  • CDD is a designated service obligation for TCSPs under the AML/CTF Act 2006, not just best practice
  • Beneficial ownership must be traced to natural persons holding 25% or more ownership or control, however many layers a structure has
  • CDD is ongoing -- records need refreshing when trustees, directors, or shareholders change
  • Nominee arrangements and multi-jurisdictional structures are the clearest EDD triggers
  • Documentation is the difference between a defensible position and an AUSTRAC finding

Frequently Asked Questions

Q: Do all TCSPs need to perform CDD, or only those with high-risk clients?

All TCSPs must perform CDD on every client relationship before providing a designated service, regardless of perceived risk. Risk level determines whether standard or enhanced due diligence applies, not whether CDD is required at all.

Q: How deep does beneficial ownership tracing need to go?

Tracing must continue until it reaches natural persons -- not other companies or trusts -- who hold 25% or more ownership or effective control. Where a structure uses nominee shareholders, a TCSP needs to look through each layer rather than stopping at the first corporate owner.

Q: What triggers enhanced due diligence for a TCSP client?

Common triggers include nominee director or shareholder arrangements, structures spanning multiple jurisdictions, a politically exposed person among the beneficial owners, and any arrangement without a clear commercial reason beyond privacy or asset protection.

Q: How often should a TCSP refresh CDD on an existing client?

Refresh CDD whenever there's a material change -- a new trustee, director, or shareholder, or a shift in the client's business or risk profile -- and periodically even without a trigger event, based on the client's assessed risk level.

This is general information only and not a substitute for legal advice.