Disclaimer: This content is for informational purposes only and does not constitute legal advice. For advice specific to your circumstances, consult a qualified legal professional or contact AUSTRAC directly.

AML/CTF Compliance

Enhanced Due Diligence: When and How to Apply It in Your Remittance Business

Compliance Desk
13 min read
Enhanced Due Diligence: When and How to Apply It in Your Remittance Business

Photo by The Yuri Arcurs Collection

Enhanced due diligence (EDD) is the heightened set of customer checks you must apply when a customer, transaction, or relationship presents a high money laundering or terrorism financing risk. Under section 36 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act) and Part 8.2 of the AML/CTF Rules, EDD is not optional — it is a legal requirement triggered by specific circumstances. Standard KYC verifies who your customer is; EDD asks why the transaction makes sense and whether the funds are legitimate.

For most remittance operators, the confusion is not whether EDD exists — it is knowing exactly when it kicks in, what additional steps satisfy AUSTRAC, and how to document the process so it survives an inspection. This guide walks through the triggers, the required measures, and a practical documentation framework you can apply this week.

Key Takeaways

  • EDD is mandatory, not discretionary, when a customer or transaction meets high-risk criteria under section 36 of the AML/CTF Act and your own risk assessment.
  • The three core triggers are: politically exposed persons (PEPs), high-risk customers/countries, and any transaction that appears suspicious or unusually complex.
  • EDD requires additional verification of identity, source of funds and source of wealth, and senior management approval to continue the business relationship.
  • Documentation is the test — AUSTRAC assesses whether your EDD decisions are recorded, justified, and applied consistently, not whether you reached a particular conclusion.
  • The 2026 AML/CTF reforms sharpen EDD expectations around beneficial ownership and ongoing customer due diligence, making robust EDD processes more important than ever.

What Is Enhanced Due Diligence (EDD)?

Enhanced due diligence is the additional scrutiny you apply on top of your standard customer identification programme when the money laundering/terrorism financing (ML/TF) risk is high. Where ordinary customer due diligence (CDD) confirms identity, EDD builds a fuller picture of the customer's financial behaviour, the purpose of the transfer, and the origin of the money moving through your business.

The AML/CTF Act establishes a risk-based approach. You are not required to treat every customer the same way — you scale your effort to the risk. Low-risk customers receive simplified or standard CDD. High-risk customers receive EDD. The legislation expects you to identify the difference and act accordingly.

AUSTRAC's regulatory guidance is explicit on this point: EDD is a control you design into your AML/CTF program (Part B), not a one-off reaction. Your program must set out the circumstances in which EDD applies and the specific measures your staff will take.

EDD vs Standard CDD: The Core Difference

ElementStandard CDDEnhanced Due Diligence (EDD)
Identity verificationConfirm name, DOB, address via reliable documentsVerify with additional/independent sources
Source of fundsGenerally not required for low-riskRequired — establish where the money came from
Source of wealthNot requiredRequired for PEPs and high-risk customers
Purpose of transactionRecordedScrutinised and corroborated
Ongoing monitoringStandard frequencyIncreased frequency and depth
Approval to proceedFrontline staffSenior management sign-off
Beneficial ownershipIdentifyVerify and scrutinise ownership/control

When Must You Apply EDD? The Mandatory Triggers

EDD is triggered in specific, identifiable circumstances. Your AML/CTF program must document each of these and your staff must recognise them in real time.

1. Politically Exposed Persons (PEPs)

A politically exposed person is an individual who holds, or has held, a prominent public position — heads of state, senior politicians, senior government, judicial or military officials, senior executives of state-owned enterprises, and senior officials of international organisations. The category extends to immediate family members and close associates.

Under the AML/CTF Rules, you must apply EDD to all foreign PEPs as a baseline. For domestic PEPs and international organisation PEPs, you assess the ML/TF risk and apply EDD where that risk is high. A retired local councillor sending AUD 300 to family may be low risk; a foreign minister's spouse transferring AUD 80,000 is not.

When you identify a PEP, EDD requires you to:

  • Obtain senior management approval before establishing or continuing the relationship
  • Take reasonable measures to establish the customer's source of funds and source of wealth
  • Conduct enhanced ongoing monitoring of the relationship

2. High-Risk Countries and Corridors

Transactions involving countries identified by the Financial Action Task Force (FATF) as having strategic AML/CTF deficiencies trigger EDD. FATF maintains two relevant lists — the "black list" (call for action, including Iran, North Korea and Myanmar) and the "grey list" (increased monitoring). You should also factor in DFAT sanctions, corruption indices, and your own corridor risk data.

A remittance business sending to a grey-listed jurisdiction should not stop servicing the corridor automatically — that risks contributing to de-banking and financial exclusion. Instead, you apply proportionate EDD: closer scrutiny of purpose, source of funds, and beneficiary relationships.

3. Suspicious, Complex, or Unusually Large Transactions

Section 36 of the AML/CTF Act requires EDD whenever you have reasonable grounds to suspect that providing a designated service involves ML/TF, or a transaction is complex, unusually large, or follows an unusual pattern with no apparent economic or lawful purpose.

Common remittance red flags include:

  • A customer structuring transfers to stay below the AUD 10,000 threshold transaction reporting trigger
  • Sudden change in transfer volume or destination inconsistent with the customer's profile
  • Third parties funding a transfer the customer cannot adequately explain
  • Reluctance to provide source of funds information or beneficiary details
  • Multiple senders directing money to a single overseas beneficiary

When these arise, EDD runs in parallel with your suspicious matter report (SMR) obligations. EDD informs whether an SMR is warranted, but applying EDD does not satisfy your reporting duty.

4. Your Own Risk Assessment

Beyond the legislated triggers, your ML/TF risk assessment may identify additional high-risk scenarios specific to your business — certain occupations, cash-intensive customers, new payment channels, or crypto-funded transfers. Where your assessment rates a situation high risk, EDD applies.

How to Apply EDD: A Step-by-Step Process

EDD is a layered process. The depth of each step scales with the level of risk you have identified.

Step 1: Verify Identity Using Additional Sources

Go beyond a single ID document. Corroborate the customer's identity using independent, reliable sources — a second government-issued document, electronic verification against multiple databases, or confirmation of address through a recent utility statement or bank record. For non-individual customers, verify beneficial ownership down to individuals owning or controlling 25% or more.

Step 2: Establish Source of Funds

Source of funds answers: where did the money for this specific transaction come from? Acceptable evidence includes recent payslips, a bank statement showing the deposit, a sale contract, or documentation of an inheritance or loan. Record what you obtained and why it satisfied you.

Step 3: Establish Source of Wealth (for PEPs and high-risk customers)

Source of wealth answers a broader question: how did this customer accumulate their overall wealth? This is required for PEPs. Evidence might include employment history, business ownership records, investment portfolios, or property holdings. The goal is to confirm that the customer's wealth is consistent with the transfers they are making.

Step 4: Scrutinise the Purpose and Nature of the Transaction

Understand and corroborate why the transfer is being made. A customer sending regular amounts to a named family member with a consistent stated purpose presents a coherent picture. A customer sending large, irregular amounts to unrelated beneficiaries with vague explanations does not.

Step 5: Obtain Senior Management Approval

For PEPs and other high-risk relationships, a designated senior person — typically your AML/CTF Compliance Officer or a director — must approve establishing or continuing the relationship. Record who approved it, on what date, and on what basis.

Step 6: Apply Enhanced Ongoing Monitoring

High-risk customers require closer, more frequent transaction monitoring. Set lower alert thresholds, review the relationship periodically, and re-verify information when circumstances change. Document the monitoring cadence in your program.

How to Document EDD So It Satisfies AUSTRAC

AUSTRAC does not assess whether you reached the "right" conclusion — it assesses whether your process was reasonable, consistent, and recorded. A defensible EDD file demonstrates that you identified the risk, took proportionate measures, and made a justified decision.

Your EDD record for each high-risk customer should capture:

Documentation ElementWhat to Record
TriggerWhy EDD was applied (PEP, high-risk country, suspicious activity, risk rating)
Risk ratingThe ML/TF risk level assigned and the rationale
Identity verificationDocuments/sources used beyond standard CDD
Source of fundsEvidence obtained and assessment of adequacy
Source of wealthFor PEPs — evidence and consistency assessment
Beneficial ownershipUBO identification and verification (for entities)
Senior approvalName, role, date, and basis of approval
Monitoring planFrequency and scope of ongoing review
OutcomeDecision to proceed, decline, or report (SMR)
ReviewerStaff member who conducted the EDD and date

Keep these records for seven years from the end of the customer relationship, consistent with the AML/CTF Act's record-keeping requirements. Store them so they are retrievable on request — AUSTRAC may ask to see EDD files during a compliance assessment.

A Worked Example

Consider a customer who normally sends AUD 1,500 monthly to a sibling in the Philippines. One month, they request a AUD 45,000 transfer to a new beneficiary in a different country, stating it is a "business payment".

The transaction triggers EDD on two grounds: it is unusually large for this customer and follows an unusual pattern. Your EDD process would:

  1. Re-verify identity and update the customer profile
  2. Request source of funds — the customer provides a sale contract for a vehicle and a matching bank deposit
  3. Scrutinise purpose — confirm the business relationship with the new beneficiary
  4. Escalate to the Compliance Officer for a proceed/decline/report decision
  5. Document every step and the final outcome

If the customer cannot adequately explain the funds, you consider an SMR and apply your tipping-off obligations. If the explanation is corroborated, you proceed, record the decision, and flag the account for closer monitoring.

EDD Under the 2026 AML/CTF Reforms

The AML/CTF Amendment Act 2024, with core reforms commencing 31 March 2026, reshapes the customer due diligence framework. The reforms replace the existing CDD model with new initial and ongoing customer due diligence obligations and sharpen the requirement to understand the nature and purpose of the business relationship.

For EDD, the practical effects are:

  • Beneficial ownership verification becomes more demanding, requiring you to take reasonable steps to verify — not just identify — the individuals behind entity customers
  • Ongoing CDD is recast as a continuous obligation to keep customer information current and to re-assess risk
  • The outcomes-focused drafting expects you to demonstrate that EDD measures actually reduced risk, not just that you ticked boxes

Review your AML/CTF program now to confirm your EDD triggers and procedures align with the reformed obligations. The transition window is the time to update procedures, not after AUSTRAC begins assessing compliance against the new rules.

Common EDD Mistakes MTOs Make

  • Treating EDD as a documents checklist rather than an assessment of risk — collecting a payslip without evaluating whether it explains the transfer
  • Failing to record the rationale — the decision may be sound, but with no written justification it is indefensible in an inspection
  • Inconsistent application — applying EDD to some PEPs but not others, with no documented basis for the difference
  • No senior management sign-off for PEPs and high-risk relationships
  • Stopping at EDD when an SMR is also required — the two obligations are separate
  • Never refreshing EDD information as the relationship continues

Building EDD Into Your Compliance Framework

EDD works best when it is embedded in your AML/CTF program and supported by trained staff and a capable transaction monitoring system. Your frontline team needs to recognise triggers; your Compliance Officer needs authority to approve, decline, or escalate; and your records need to tell a clear story.

If you are revisiting your compliance documents ahead of the 2026 reforms, start with your risk assessment and work outward to your EDD procedures. Our AML/CTF program tool can help you structure the EDD triggers and controls in line with current AUSTRAC expectations, and our corridor guides provide country-level risk context to inform your high-risk determinations.

This information is general in nature and does not constitute legal advice. Consult AUSTRAC or a qualified legal professional for advice specific to your situation.

Frequently Asked Questions

When is enhanced due diligence legally required for a remittance business?

EDD is required under section 36 of the AML/CTF Act and Part 8.2 of the AML/CTF Rules whenever a customer or transaction presents high ML/TF risk. The core mandatory triggers are foreign politically exposed persons (PEPs), customers or transactions connected to FATF high-risk jurisdictions, and any transaction that is suspicious, complex, unusually large, or has no apparent economic purpose. Your own risk assessment may identify additional high-risk scenarios requiring EDD.

What is the difference between source of funds and source of wealth?

Source of funds explains where the money for a specific transaction came from — for example, a payslip, a property sale, or a bank deposit. Source of wealth explains how the customer accumulated their overall financial position — such as their occupation, business interests, or investments. EDD requires source of funds for high-risk transactions and source of wealth for PEPs and high-risk customers.

Does applying EDD satisfy my suspicious matter reporting obligation?

No. EDD and suspicious matter reporting (SMR) are separate obligations. EDD helps you decide whether a transaction is suspicious, but if you form a reasonable suspicion of ML/TF you must still submit an SMR to AUSTRAC within the required timeframe — three business days for most matters, 24 hours for terrorism financing. Proceeding with EDD does not discharge your reporting duty.

How long must I keep EDD records?

You must keep EDD records for seven years from the end of the customer relationship, consistent with the record-keeping requirements of the AML/CTF Act. Records should be retrievable on request, as AUSTRAC may review EDD files during a compliance assessment to confirm your decisions were reasonable, consistent, and properly documented.

Do I need to apply EDD to every PEP?

You must apply EDD to all foreign PEPs as a baseline. For domestic PEPs and international organisation PEPs, you assess the ML/TF risk and apply EDD where that risk is high. In every case, document the basis for your decision — including why you concluded a domestic PEP was lower risk if you did not apply full EDD.

How do the 2026 AML/CTF reforms change EDD?

The reforms commencing 31 March 2026 strengthen beneficial ownership verification, recast ongoing customer due diligence as a continuous obligation, and adopt an outcomes-focused approach that expects EDD to demonstrably reduce risk. Review and update your AML/CTF program during the transition window to ensure your EDD triggers and procedures meet the reformed requirements.

enhanced due diligenceaml-ctf-complianceAUSTRACPEP screeningCustomer Due Diligence
Was this helpful?