AML/CTF obligations for Tranche 2 businesses are now in force. Since 1 July 2026 Get compliant
Beneficial ownership CDD for trusts, SMSFs and companies. The ID check is only the start.

Beneficial ownership CDD for trusts, SMSFs and companies

The ID check is only the start when the customer is a trust, SMSF or company.

AML/CTF Compliance 20 July 2026 8 min read AML Guard

Beneficial ownership CDD is where trusts, SMSFs and companies make the new AML/CTF regime operationally difficult for real-estate agencies. Since 1 July 2026, Australian real-estate businesses providing regulated designated services have had to complete customer due diligence under the reformed regime. For an individual buyer or seller, the identity path is usually more linear: collect the required information, verify it according to risk and keep the record. Then a contract arrives in the name of a family trust, an SMSF with a corporate trustee, or a company owned through another entity. The question changes: who is really behind this customer?

That question has several parts, and AUSTRAC keeps them distinct: who the customer is, who is authorised to act for it, who it receives the service on behalf of, and who ultimately owns or controls it. For an entity, answering that last part, identifying the beneficial owners, is the work individual verification never prepared you for.

Why is entity CDD different from an individual ID check?

When your customer is an individual, due diligence is close to a straight line: establish who they are and verify it to a standard appropriate to the risk. (Where identity verification is used within AML Guard, those services are provided through its verification partner, GlobalData.) Entity customers add layers. AUSTRAC's guidance for a company or trust is that you look through the entity to the individuals behind it, its beneficial owners, and separately establish who is authorised to act for it.

Who is a beneficial owner under Australian AML/CTF law?

A beneficial owner is an individual who ultimately owns 25% or more of a customer, or who controls the customer. Ownership may be direct or indirect. Control is a separate test and can arise through majority voting power, control of the board, or practical influence over the company's financial and operating decisions.

Those are two independent limbs, and a person can be a beneficial owner on either. Ownership is a stake; control is influence, and it can exist with a small holding or none at all. Under the AML/CTF Act, you follow the ownership chain through any holding companies until you reach the natural people, rather than stopping at the first entity in the middle. AUSTRAC's guidance on determining ownership and control structures describes both the formal and the practical forms control can take.

How does CDD work for a trust?

For a trust, beneficial owners may include the individual trustees, the beneficial owners of a corporate trustee, the settlor, the appointor, a guardian or protector, and any other individual who controls the trust. Beneficiaries are not automatically beneficial owners, although a beneficiary may qualify in some structures, including a bare trust.

A trust is not one question but several, and AUSTRAC's initial CDD guidance for a trust keeps them distinct: the customer (the trust itself); the people on whose behalf it receives the service, generally the beneficiaries, or a description of each class of beneficiary where individuals cannot be named; the people acting for it, the trustees and their representatives; and the beneficial owners and controllers above. Collapsing those groups into a single list is the most common way an entity case goes wrong.

How do you complete CDD on an SMSF with a corporate trustee?

CDD on an SMSF means treating the fund as a trust: establish the fund, its members or beneficiaries, the trustee and anyone acting for it. Where the trustee is a company, separately identify the individuals who ultimately own or control that corporate trustee, and keep the supporting evidence.

An SMSF case can involve four different questions: who the trust is, who acts for it, who benefits from it, and who owns or controls its corporate trustee. Being registered with the ATO does not remove any of them. Comparing the trustee company's owners against the fund's members is a good way to surface a discrepancy, provided you do not simply assume the two lists are the same.

Where does entity CDD commonly go wrong?

Entity due diligence rarely fails through laziness. The structures are built for tax and succession, not for transparency, and the failure modes are subtle.

A sole director is not automatically a sole shareholder

It is natural to assume the one director of a small company owns all of it. Ownership is confirmed from the share register, not from the directorship.

Control can exist without 25% ownership

A check that identifies only shareholders at or above 25%, without tracing the ownership chains and testing control separately, can miss a beneficial owner entirely.

Layered ownership must be traced to individuals

A company owned by another company, owned by a trust, is not unusual in property. Each layer is its own look-through down to the natural people. Our guide to tracing beneficial owners (UBOs) under Tranche 2 walks through that look-through step by step.

SMSF members and corporate-trustee owners are different lists

The fund's members are not automatically the trustee company's shareholders. Identify the owners of the trustee company in their own right, then compare.

Any one of these can turn a determination that looked finished into one that would not survive a second look. That second look is the point: the regime is built so that, if AUSTRAC or an independent reviewer later asks how you established the beneficial owners of a particular trust, you can explain it on reasonable grounds and show the evidence.

What should entity CDD software guide and record?

Good beneficial ownership CDD is less about doing more and more about doing the same work in fewer steps, with the error-prone parts surfaced and the evidence produced as you go. An agent does not need to become a corporate lawyer between appointments; they need a process, and ideally software, that asks the right questions in the right order, prevents obvious omissions and preserves the evidence behind the decision. If you are choosing or reviewing a system, these are the capabilities that decide an entity case:

It works down the structure, not just across it. Enter a company or a trust and the system should move you toward the individuals who own or control it, and toward the people authorised to act for it, rather than confirming the entity exists and stopping there.

It treats an SMSF and a corporate trustee as their own case. A system that records the trustee company's directors and shareholders and lays them alongside the fund's members, so a discrepancy is visible rather than assumed away, is handling the part where mistakes happen.

It records each person once, with their several roles. One individual may be a director, a member and a controller; recording them once with each role, rather than as three separate entries, keeps the picture honest.

It guides the determination and records the basis. Good software shows the next relevant question for the case in front of you and, when you reach a judgement, lets you record who the beneficial owners are, on what basis, ownership or control, with the evidence you relied on and who signed it off. Relevant evidence may include a trust deed, a company share register, current or historical ASIC extracts, constitutions, shareholder agreements and trustee resolutions. The determination remains the reporting entity's; the platform's job is to structure it and keep the trail.

It lets you apply your own verification policy. AUSTRAC does not prescribe a paid company report for every entity customer. What the reforms require is a reasonable-grounds determination supported by the right KYC information and, according to the customer's risk and your AML/CTF policies, reliable and independent verification. A good platform lets you rely on solid evidence you already hold where that is appropriate, and escalate to an independent registry or specialist search where the risk, complexity or a discrepancy warrants it, rather than forcing the same paid step onto every deal or leaving you without one.

It keeps a record that can be reviewed. For each determination: the person identified, the ownership or control basis, the evidence relied on, the discrepancies resolved, the decision-maker and any approver, retained for the seven years the regime expects. When the question comes a year later, the answer is already on file, ready for compliance staff, an independent evaluator or AUSTRAC.

Five questions to ask an AML/CTF platform about entity CDD

Public detail on exactly what each AML product does is not easy to come by, so it pays to compare on the capability that decides your hard cases rather than the demo that shows the straightforward one. Verifying a person and identifying the beneficial owners of a corporate trustee are different capabilities, and in our experience fewer tools do that second job well than do the first. These are the five questions an entity case turns on:

  1. Enter a company or a trust: does it work down to the individual beneficial owners and the people who can act for the entity, or does it stop at confirming the entity is real?
  2. Does it handle an SMSF with a corporate trustee as its own case, and lay the members alongside the trustee's owners so a discrepancy shows?
  3. When you reach a judgement, does it guide you and record the basis, the evidence and the decision-maker, or leave you to work it out in a spreadsheet?
  4. Can you make a documented, reasonable-grounds determination when the evidence supports it, and escalate to a paid search only when the case needs it?
  5. If AUSTRAC asks in a year how you determined a beneficial owner, is the answer already recorded, with its basis?

Any product used for Australian property should be able to demonstrate a clear answer to each. This is the ground AML Guard was built for: the trust and SMSF look-through, the corporate-trustee layer, and the recorded determination behind it.

What does compliance-first entity CDD look like?

None of this is a feature list; it is a posture. The reason to look through every layer, to test control as well as ownership, and to record the basis of every determination is not that the software prefers it. It is that the obligation is real, the structures are genuinely complex, and the only position you can explain later is one where the work was done properly and the record shows it.

Compliance-first means the workflow requires the beneficial-owner question to be resolved, by identifying the relevant individuals, recording why no beneficial owner exists, or documenting the applicable risk-based treatment, rather than letting it be quietly skipped. The reporting entity still owns the decision, its risk assessment and its program; software cannot reach the legal conclusion for you. What it can do is guide staff through the required questions, prevent the obvious omissions and preserve the evidence, which is what turns a defensible intention into a defensible file.

The trust, the SMSF and the company are where the reforms ask something real of Australian property, and where the right platform can materially improve the consistency, efficiency and defensibility of your due diligence.

Ready to see AML Guard in action?

Book a demo and see how AML Guard guides beneficial ownership CDD for trusts, SMSFs and corporate trustees, from the look-through to the recorded determination.

Book a Demo

Related Reading

Beneficial Ownership: How to Trace UBOs Under Tranche 2
What Is an AML/CTF Program? A Plain-English Guide for Property Professionals
AML/CTF Compliance Checklist for Real Estate Agents
When Does AML Compliance Actually Start in a Property Transaction?

This article is general information about using the AML Guard platform and reflects AUSTRAC guidance and the AML/CTF legislation current at the time of writing. AUSTRAC guidance is interpretive and general in nature; this article is not legal or compliance advice. For your circumstances, consult your own legal counsel or a suitably qualified AML/CTF adviser. Identity verification services referenced are provided through AML Guard's verification partner, GlobalData.

Last reviewed: July 2026.