
Yes, Australian reporting entities can rely on another reporting entity’s customer due diligence under sections 37A and 38 of the AML/CTF Act 2006 (Cth), but only within tight limits. You need a written arrangement in place before you rely on anyone under section 37A, you must remain able to obtain the underlying verification evidence, and you stay legally responsible for that customer’s due diligence regardless of who collected it. AUSTRAC’s reliance guidance sets the procedural bar you’re expected to clear.
TL;DR:
- Reliance on another reporting entity’s customer due diligence requires a written, signed arrangement that clearly allocates responsibilities and guarantees access to verification data.
- Dependence is only appropriate for high-risk customers when the third party is a regulated entity or FATF-compliant foreign business, with extra scrutiny applied to jurisdictional risks.
- Regular reassessments, at least every two years or upon specific triggers, are mandatory to maintain reliance validity and avoid civil penalties.
- Reliance should not be confused with outsourcing, as the latter involves a third-party performing CDD tasks without the reliance legal framework and associated obligations.
- Maintaining a detailed, tamper-evident reliance register linked to specific customer matters is essential for audit readiness and regulatory verification.
Table of Contents
- When is reliance on CDD appropriate under the AML/CTF regime?
- What must a section 37A CDD arrangement include?
- How should you document and approve a reliance arrangement?
- How often must you assess your CDD reliance arrangements?
- Reliance versus outsourcing: which one are you actually doing?
- What does CDD reliance look like in practice?
- Building a reliance register that survives an audit
- A compliance officer’s honest take on reliance risk
- How AML Guard supports your CDD reliance obligations
- Where to verify these obligations directly
- Sources
When is reliance on CDD appropriate under the AML/CTF regime?
Reliance is not a shortcut you can invoke whenever it’s convenient. AUSTRAC expects you to test whether reliance is appropriate to the money laundering and terrorism financing risk of the specific customer and channel in front of you, not just appropriate in the abstract.
That test runs against several factors together, not any single one in isolation:
- The nature and size of your business and the designated services you provide
- The types of products and delivery channels involved in that customer relationship
- The customer types you’re onboarding, including their ownership structure and behaviour
- The jurisdictions connected to the customer, the transaction, or the third party you’re proposing to rely on
Who you can actually rely on is narrower than most compliance teams assume. The third party must be a reporting entity itself, or a foreign business regulated under laws that give effect to FATF recommendations on customer due diligence and record keeping. Being regulated somewhere is not enough on its own. A mortgage broker holding an Australian credit licence, for instance, is not automatically a reporting entity you can rely on for AML/CTF purposes, and a foreign law firm with a strong local reputation is not a substitute for confirming its home jurisdiction actually enforces FATF-equivalent CDD standards.
Foreign third parties demand extra scrutiny. You need to weigh the ML/TF risk of that jurisdiction specifically, drawing on sources such as FATF mutual evaluation reports and independent country assessments, before you treat their CDD as equivalent to your own. Practical red flags that a third party is unsuitable include an inability to produce verification records on request, a program that hasn’t been independently reviewed in years, or a jurisdiction flagged for weak AML supervision.
What must a section 37A CDD arrangement include?
Section 37A doesn’t just require a written arrangement to exist. It requires that arrangement to do specific work before you’re entitled to rely on it. AUSTRAC’s guidance on reliance arrangements sets out what a compliant document needs to cover, and the checklist is more demanding than a one-page letter of comfort.
- Allocate responsibility clearly. State exactly which party collects identification information, which party verifies it, and which party bears record-keeping duties for each customer type covered.
- Guarantee access to underlying data. The arrangement must give you the right to obtain copies of the independent data, documents, or electronic verification results the third party used, not just a summary or a pass/fail confirmation.
- Record senior manager approval and scope. Name the senior manager who approved entering the arrangement, and define precisely which designated services, customer types, and matters it covers.
- Address delayed initial CDD where relevant. If the arrangement anticipates any delay in completing initial CDD before service delivery begins, the permitted circumstances and safeguards need to be spelt out.
Timing matters as much as content. AUSTRAC expects evidence to be produced immediately or as soon as reasonably practicable, and for ordinary, lower-risk services it would not expect more than a short delay between your request and the third party handing over the underlying verification data. An arrangement that lets a third party take a week to respond will not survive scrutiny. Reliance also never removes your obligation to complete initial CDD appropriate to that customer’s risk before you provide a designated service, unless a specific delayed CDD exception genuinely applies.
How should you document and approve a reliance arrangement?
A reliance arrangement can take the form of a formal contract, a memorandum of understanding, or a standard operating procedure agreed between the parties, provided it’s in writing and covers the section 37A elements. What matters to an auditor is not the label on the document but whether it actually records the rationale for relying on this particular third party and captures a named senior manager’s sign off before reliance began.
Per matter, your files need to hold enough to reconstruct the decision years later:
- A copy of the verification data or documents the third party actually used, not just their conclusion
- The provenance of those independent sources, so you can show where the data originated
- The date the evidence was inspected and by whom
- The senior manager approval tied to that specific reliance instance
Retain all of it for seven years, and store it somewhere tamper-evident so a regulator can trust the timestamp on every entry. If AUSTRAC asks why you were reasonably satisfied the third party’s procedures were adequate, “they told us they were compliant” will not hold up. You need your own documented assessment of their program, not just their assurance.
Pro Tip: Keep a one-page reliance summary attached to every matter file that cross-references the register entry, the arrangement clause it sits under, and the date evidence was last sampled. It turns a seven-year audit request from a research project into a five-minute lookup.
How often must you assess your CDD reliance arrangements?
Section 37B requires regular assessments of every arrangement covered by section 37A, and AUSTRAC expects that review at least every two years, more often if the customer’s risk profile or the third party’s circumstances change. Skipping this isn’t a paperwork lapse. Failing to conduct these assessments can expose your entity to civil penalties under the Act, which puts reliance governance on the same footing as any other core AML/CTF obligation.
Document a written record of the outcome within 10 business days of completing each assessment. That record needs to show what you actually checked, not just that a checkbox was ticked.
Several triggers should pull an assessment forward, regardless of where you sit in the two-year cycle:
- Adverse regulatory findings against the third party, in Australia or overseas
- Adverse media reporting connecting the third party to financial crime or sanctions breaches
- A change in the third party’s ownership, control, or senior management
- A failed or qualified independent audit of the third party’s AML/CTF program
Sound assessment methods combine several techniques rather than relying on one. AUSTRAC points to sampling individual verification files, commissioning or reviewing independent evaluations of the third party’s program, and reading their policies and recent audit reports directly rather than accepting a summary letter. A compliance officer who only reads the third party’s marketing material about their own compliance standards hasn’t assessed anything.
Reliance versus outsourcing: which one are you actually doing?
These two terms get used interchangeably in compliance conversations, and that habit creates real exposure. AUSTRAC draws a firm line between them: reliance is a regulatory mechanism that lets you use another reporting entity’s own CDD as if it were yours, invoked under sections 37A or 38. Outsourcing is a commercial arrangement where a third party performs CDD tasks on your behalf, but the CDD remains yours, not theirs.
You remain liable either way. What changes is the evidence standard and the legal test:
- Reliance requires the third party to be an eligible reporting entity or FATF-equivalent foreign business, a written section 37A arrangement, and periodic assessments under section 37B.
- Outsourcing has no equivalent statutory reliance test. You’re simply contracting a supplier, often an identity verification vendor or a document-checking service, and the CDD output is treated as your own work from the start.
A common trap: a real estate agency that pays a third-party verification service to run identity checks is outsourcing, not relying, even if that service is itself AML-regulated for other purposes. Treating that vendor relationship as section 37A reliance when it doesn’t meet the eligibility test leaves a gap in your program that a supervisor will find quickly.
What does CDD reliance look like in practice?
Three scenarios cover most of what compliance officers encounter, and each carries a different documentation burden.
- Domestic ongoing arrangement. Two Australian reporting entities, say a law firm and a conveyancing practice working the same property chain, enter a standing section 37A arrangement covering all shared clients. The relying entity samples a percentage of files each quarter, checks the underlying identity documents against its own risk appetite, and keeps a rolling assessment log rather than reassessing from scratch every time.
- Case-by-case reliance. An accounting practice occasionally receives referred clients from an unrelated firm and wants to rely on section 38 for that specific matter rather than a standing arrangement. Before relying, request the referring firm’s verification file, confirm it meets the identity and beneficial ownership elements your own program requires, and record that single-matter basis in your reliance register.
- Foreign third-party arrangement. A trust and company service provider relies on an overseas law firm’s CDD for a client with cross-border ownership. This demands the extra jurisdictional risk check on top of the standard tests, since you’re relying on a party outside AUSTRAC’s direct supervision.
Getting this wrong carries a real cost: failing to conduct the mandated periodic assessments of these arrangements can expose your entity to civil penalties, which is precisely why the register discipline in the next section matters as much as the initial decision to rely.
Building a reliance register that survives an audit
A reliance register is the single artefact that turns “we rely on several partners” into something AUSTRAC can actually verify. Best practice links every reliance instance to the specific customer matter, not just to the third party generally, and records the exact evidence used for each required element, identity, beneficial ownership, and PEP or sanctions screening, along with where that evidence sits and who approved reliance.
A workable register needs these fields at minimum:
| Field | Purpose |
|---|---|
| Arrangement type | Section 37A standing arrangement or section 38 case-by-case reliance |
| Parties | Your entity and the third party relied upon |
| Scope | Designated services, customer types, and matters covered |
| Evidence location | Where the underlying verification data is stored and how to retrieve it |
| Last assessment date | When the third party’s procedures were last reviewed |
| Next assessment due | Scheduled review date, no later than two years out |
| Senior manager approval | Name and date of sign off |
| Remediation notes | Any issues found and how they were resolved |
Operationally, the controls that reduce supervisory risk are the ones that remove manual gaps: an evidence request that fires automatically the moment reliance is invoked, a sampling dashboard that flags inconsistent verification methods between different third parties, and an assessment calendar that escalates when a review is overdue rather than relying on someone remembering. AML Guard’s platform builds this register logic directly into its CDD workflow, keeping the reliance record, the evidence, and the senior manager approval in one tamper-evident audit trail rather than scattered across email threads and shared drives.
Pro Tip: Schedule your two-year reassessments on a rolling basis across the calendar year rather than all at once. A compliance officer facing forty overdue reliance reviews in the same month is a compliance officer who starts cutting corners.
A compliance officer’s honest take on reliance risk
The mistake I see most often isn’t a missing signature on an arrangement. It’s compliance teams treating a verification vendor relationship as reliance when it’s actually outsourcing, then wondering why their program document doesn’t hold up under review. The paperwork looks similar on the surface, but the legal test underneath is completely different.
Weak access to evidence is the second recurring problem. A written arrangement that promises data “on request” but never gets tested against a real deadline is a liability waiting to surface, usually during an actual AUSTRAC review rather than a friendly internal audit. Senior manager sign off, automated evidence requests, and a sampling schedule you actually stick to do more to reduce your exposure than any amount of extra legal drafting.
If you take one thing from this: build the assessment calendar before you sign the first arrangement, not after the first review is already overdue.
How AML Guard supports your CDD reliance obligations
Running reliance arrangements on spreadsheets and email trails works until the first AUSTRAC review, and then it doesn’t. AML Guard gives Tranche 2 reporting entities a single workflow where the business-wide risk assessment, the AML/CTF policies, and your CDD reliance decisions come from the same linked set of program artefacts, so a reviewer checking one document finds the others consistent with it.

The platform runs end-to-end customer due diligence, including document capture and biometric liveness checks, sanctions and PEP screening with ongoing re-screening, and beneficial ownership determination on a company’s ACN, with trusts and SMSFs reached through their corporate trustee. Every reliance decision, evidence request, and senior manager approval sits inside a seven-year tamper-evident audit trail, built so you can pull the file a regulator asks for in minutes rather than days. If your firm handles referrals from other reporting entities, such as a property advocacy relationship where CDD may be shared between parties, the same evidence-tracking discipline applies regardless of who originated the check.
An officer approves each determination before CDD proceeds, keeping the judgement with your team while the platform automates the lookups and record-keeping around it. If your current reliance register lives in a shared drive and a prayer, book a demo to see how the workflow handles arrangement documentation, scheduled assessments, and audit-ready evidence retrieval in one place.

Where to verify these obligations directly
For the legal text itself, read sections 37A and 38 of the AML/CTF Act 2006 (Cth) on the Federal Register of Legislation. AUSTRAC’s reliance under CDD arrangements guidance and its reform overview page set out current procedural expectations, and the initial CDD overview clarifies where reliance stops and your own obligations begin.
Sources
- Reliance under customer due diligence arrangements | AUSTRAC
- Anti‑Money Laundering and Counter‑Terrorism Financing Act 2006 - Federal Register of Legislation
Recommended
- Tranche 2 customer due diligence in Australia
- Beneficial Ownership CDD for Trusts, SMSFs & Companies
- AML/CTF Program Documents for Tranche 2
- Which AML/CTF program template should you use in 2026?
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.