What ongoing CDD covers
A customer file is a starting point, not a permanent description of the relationship. AUSTRAC separates ongoing customer due diligence from the initial checks. Its guidance covers what to monitor, how to monitor, unusual transactions and behaviour, and updates to customer information. Transaction monitoring is one part of that work. Monitor changes in the relationship as well as transactions. An identity check alone does not perform that work. The detailed requirements depend on the services, risks and circumstances covered by the business program.
- Expected activity
Describe what the available customer information supports.
- Observed change
Identify the specific difference.
- Review
Check the explanation and evidence.
- Decision
Record the result and any next action.
From expected activity to a recorded decision
Illustrative workflow. Read the page and current primary guidance for conditions and exceptions.
Follow the process from top to bottom.
Three parts of ongoing CDD
Ongoing CDD has three connected parts: monitoring activity, reviewing customer risk, and reviewing customer information. For a continuing business relationship, AUSTRAC requires risk and KYC information to be reviewed and, where appropriate, updated or reverified. The work should reflect the business risk assessment, the customer risk found at intake and later changes. This means transaction alerts alone are not the whole process. A new controller or a changed business purpose can matter even when the amounts moving through an account look familiar.
Write down what ordinary activity looks like
Monitoring needs a useful starting description. In a suggested customer record, state the purpose of the service, expected parties, payment arrangements and any other relevant activity. Use information the business can reasonably obtain. A record saying business customer provides little help when staff later decide whether new instructions fit the relationship.
AUSTRAC requires monitoring of transactions and behaviour, including for customers using services occasionally. Review and update duties for risk and KYC information apply to business relationships. Keep that distinction visible in the procedure. A change of controller or unexplained representative can matter even when the transaction value has not changed.
Assess a change in trading activity
A fictional customer normally receives payments from Australian retailers. The next matter includes three payments from an overseas distributor. A staff member notes the difference and checks the stated purpose of the work. The customer says it has signed a distribution agreement. The reviewer compares that explanation with the agreement, parties and payment references that are available.
If the evidence supports a new trading arrangement, the record can explain why the expected activity changes. If the names or terms conflict, the remaining gap needs a further decision. Merely rewriting the expected profile to match the payments would remove the alert without explaining it.
The reviewer makes separate decisions about the alert, customer information, customer risk and any reporting obligation. A supported commercial explanation may resolve one question while another remains open. The workflow records who owns each follow-up so an unresolved matter is not lost when the first alert is closed.
- Ongoing customer due diligence: Ongoing CDD topic index
- Overview of ongoing customer due diligence: Ongoing CDD obligations overview; AML/CTF policies and ongoing CDD; What you must monitor for; Responding to unusual transactions and behaviour; Review and update information and customer ML/TF risk; Check your ongoing CDD; Record keeping
- New activity
A fictional customer starts activity that differs from the existing file.
- Customer information
Check whether the customer’s circumstances or explanation have changed.
- Response
Assess the risk and applicable actions. Keep the reason for the decision.
A changed customer needs a connected review
Read this visual with the source conditions and explanation in this section.
Follow the process from top to bottom.
- Alert outcome
Explain whether the unusual activity is resolved.
- Customer information
Decide whether relevant KYC information needs review or update.
- Customer risk
Record whether the change affects the risk assessment.
- Reporting decision
Assess the reporting test separately; closing an alert does not settle it.
One change can require four separate decisions
Illustrative review for a business relationship. These decisions can overlap; this is not a fixed order.
Separate evidence questions. An answer to one does not settle the others.
Separate the decisions
In this example, closing an alert and deciding whether to submit a suspicious matter report are different decisions. The record should make that distinction visible. It should show what was reviewed, who reviewed it and what remains uncertain. If the business changes its expected customer profile, it should explain why the new profile is supported. Merely increasing an expected transaction amount to stop future alerts would hide the original question. A reviewer also needs a way to return to unresolved information.
Check whether the process works
An illustrative quality check selects a small set of closed and open reviews. Ask whether another trained person can understand each decision without speaking to its author. Look for missing evidence, unexplained delays and repeat alerts that were assessed in isolation. Use those findings to improve instructions and escalation paths. This is a proposed operating check, not a claim that a particular sample size satisfies the law. Consult the detailed AUSTRAC monitoring guidance before setting the business process or changing its controls.
Test manual and automated monitoring the same way
A small business can ask whether its process detects relevant changes, directs them to a responsible person and records the outcome. For a manual process, check how staff identify cases that need review. For software, check which data and behaviours it can actually observe. Neither a spreadsheet nor an alert engine can review information that never enters the process.
A suggested quality check follows one case from the original change through the evidence, decision and follow-up. Check that staff can distinguish alert arrival from suspicion formation. Review repeated low-value events together where relevant, rather than assuming each isolated event explains the pattern. This is an operating example; it does not prescribe a legal review frequency or sample size.