CDD reliance checklist for Tranche 2 firms

CDD reliance checklist for Tranche 2 firms

What a section 37A reliance arrangement actually requires, how often section 37B makes you reassess it, and how to keep records audit ready.

AML/CTF Compliance 10 September 2026 12 min read AML Guard

Officer cross-referencing CDD reliance records

Yes, Australian reporting entities can rely on another reporting entity’s customer due diligence under sections 37A and 38 of the AML/CTF Act 2006 (Cth), but only within tight limits. You need a written arrangement in place before you rely on anyone under section 37A, you must remain able to obtain the underlying verification evidence, and you stay legally responsible for that customer’s due diligence regardless of who collected it. AUSTRAC’s reliance guidance sets the procedural bar you’re expected to clear.


TL;DR:


AML Guard
Keep CDD Reliance Records Connected
AML Guard records CDD, approvals, reporting workflows and a tamper-evident audit trail across your Australian compliance processes.
Book a demo

Table of Contents

When is reliance on CDD appropriate under the AML/CTF regime?

Reliance is not a shortcut you can invoke whenever it’s convenient. AUSTRAC expects you to test whether reliance is appropriate to the money laundering and terrorism financing risk of the specific customer and channel in front of you, not just appropriate in the abstract.

That test runs against several factors together, not any single one in isolation:

Who you can actually rely on is narrower than most compliance teams assume. The third party must be a reporting entity itself, or a foreign business regulated under laws that give effect to FATF recommendations on customer due diligence and record keeping. Being regulated somewhere is not enough on its own. A mortgage broker holding an Australian credit licence, for instance, is not automatically a reporting entity you can rely on for AML/CTF purposes, and a foreign law firm with a strong local reputation is not a substitute for confirming its home jurisdiction actually enforces FATF-equivalent CDD standards.

Foreign third parties demand extra scrutiny. You need to weigh the ML/TF risk of that jurisdiction specifically, drawing on sources such as FATF mutual evaluation reports and independent country assessments, before you treat their CDD as equivalent to your own. Practical red flags that a third party is unsuitable include an inability to produce verification records on request, a program that hasn’t been independently reviewed in years, or a jurisdiction flagged for weak AML supervision.

What must a section 37A CDD arrangement include?

Section 37A doesn’t just require a written arrangement to exist. It requires that arrangement to do specific work before you’re entitled to rely on it. AUSTRAC’s guidance on reliance arrangements sets out what a compliant document needs to cover, and the checklist is more demanding than a one-page letter of comfort.

  1. Allocate responsibility clearly. State exactly which party collects identification information, which party verifies it, and which party bears record-keeping duties for each customer type covered.
  2. Guarantee access to underlying data. The arrangement must give you the right to obtain copies of the independent data, documents, or electronic verification results the third party used, not just a summary or a pass/fail confirmation.
  3. Record senior manager approval and scope. Name the senior manager who approved entering the arrangement, and define precisely which designated services, customer types, and matters it covers.
  4. Address delayed initial CDD where relevant. If the arrangement anticipates any delay in completing initial CDD before service delivery begins, the permitted circumstances and safeguards need to be spelt out.

Timing matters as much as content. AUSTRAC expects evidence to be produced immediately or as soon as reasonably practicable, and for ordinary, lower-risk services it would not expect more than a short delay between your request and the third party handing over the underlying verification data. An arrangement that lets a third party take a week to respond will not survive scrutiny. Reliance also never removes your obligation to complete initial CDD appropriate to that customer’s risk before you provide a designated service, unless a specific delayed CDD exception genuinely applies.

How should you document and approve a reliance arrangement?

A reliance arrangement can take the form of a formal contract, a memorandum of understanding, or a standard operating procedure agreed between the parties, provided it’s in writing and covers the section 37A elements. What matters to an auditor is not the label on the document but whether it actually records the rationale for relying on this particular third party and captures a named senior manager’s sign off before reliance began.

Per matter, your files need to hold enough to reconstruct the decision years later:

Retain all of it for seven years, and store it somewhere tamper-evident so a regulator can trust the timestamp on every entry. If AUSTRAC asks why you were reasonably satisfied the third party’s procedures were adequate, “they told us they were compliant” will not hold up. You need your own documented assessment of their program, not just their assurance.

Pro Tip: Keep a one-page reliance summary attached to every matter file that cross-references the register entry, the arrangement clause it sits under, and the date evidence was last sampled. It turns a seven-year audit request from a research project into a five-minute lookup.

How often must you assess your CDD reliance arrangements?

Section 37B requires regular assessments of every arrangement covered by section 37A, and AUSTRAC expects that review at least every two years, more often if the customer’s risk profile or the third party’s circumstances change. Skipping this isn’t a paperwork lapse. Failing to conduct these assessments can expose your entity to civil penalties under the Act, which puts reliance governance on the same footing as any other core AML/CTF obligation.

Document a written record of the outcome within 10 business days of completing each assessment. That record needs to show what you actually checked, not just that a checkbox was ticked.

Several triggers should pull an assessment forward, regardless of where you sit in the two-year cycle:

Sound assessment methods combine several techniques rather than relying on one. AUSTRAC points to sampling individual verification files, commissioning or reviewing independent evaluations of the third party’s program, and reading their policies and recent audit reports directly rather than accepting a summary letter. A compliance officer who only reads the third party’s marketing material about their own compliance standards hasn’t assessed anything.

Reliance versus outsourcing: which one are you actually doing?

These two terms get used interchangeably in compliance conversations, and that habit creates real exposure. AUSTRAC draws a firm line between them: reliance is a regulatory mechanism that lets you use another reporting entity’s own CDD as if it were yours, invoked under sections 37A or 38. Outsourcing is a commercial arrangement where a third party performs CDD tasks on your behalf, but the CDD remains yours, not theirs.

You remain liable either way. What changes is the evidence standard and the legal test:

A common trap: a real estate agency that pays a third-party verification service to run identity checks is outsourcing, not relying, even if that service is itself AML-regulated for other purposes. Treating that vendor relationship as section 37A reliance when it doesn’t meet the eligibility test leaves a gap in your program that a supervisor will find quickly.

What does CDD reliance look like in practice?

Three scenarios cover most of what compliance officers encounter, and each carries a different documentation burden.

  1. Domestic ongoing arrangement. Two Australian reporting entities, say a law firm and a conveyancing practice working the same property chain, enter a standing section 37A arrangement covering all shared clients. The relying entity samples a percentage of files each quarter, checks the underlying identity documents against its own risk appetite, and keeps a rolling assessment log rather than reassessing from scratch every time.
  2. Case-by-case reliance. An accounting practice occasionally receives referred clients from an unrelated firm and wants to rely on section 38 for that specific matter rather than a standing arrangement. Before relying, request the referring firm’s verification file, confirm it meets the identity and beneficial ownership elements your own program requires, and record that single-matter basis in your reliance register.
  3. Foreign third-party arrangement. A trust and company service provider relies on an overseas law firm’s CDD for a client with cross-border ownership. This demands the extra jurisdictional risk check on top of the standard tests, since you’re relying on a party outside AUSTRAC’s direct supervision.

Getting this wrong carries a real cost: failing to conduct the mandated periodic assessments of these arrangements can expose your entity to civil penalties, which is precisely why the register discipline in the next section matters as much as the initial decision to rely.

Building a reliance register that survives an audit

A reliance register is the single artefact that turns “we rely on several partners” into something AUSTRAC can actually verify. Best practice links every reliance instance to the specific customer matter, not just to the third party generally, and records the exact evidence used for each required element, identity, beneficial ownership, and PEP or sanctions screening, along with where that evidence sits and who approved reliance.

A workable register needs these fields at minimum:

Field Purpose
Arrangement type Section 37A standing arrangement or section 38 case-by-case reliance
Parties Your entity and the third party relied upon
Scope Designated services, customer types, and matters covered
Evidence location Where the underlying verification data is stored and how to retrieve it
Last assessment date When the third party’s procedures were last reviewed
Next assessment due Scheduled review date, no later than two years out
Senior manager approval Name and date of sign off
Remediation notes Any issues found and how they were resolved

Operationally, the controls that reduce supervisory risk are the ones that remove manual gaps: an evidence request that fires automatically the moment reliance is invoked, a sampling dashboard that flags inconsistent verification methods between different third parties, and an assessment calendar that escalates when a review is overdue rather than relying on someone remembering. AML Guard’s platform builds this register logic directly into its CDD workflow, keeping the reliance record, the evidence, and the senior manager approval in one tamper-evident audit trail rather than scattered across email threads and shared drives.

Pro Tip: Schedule your two-year reassessments on a rolling basis across the calendar year rather than all at once. A compliance officer facing forty overdue reliance reviews in the same month is a compliance officer who starts cutting corners.

A compliance officer’s honest take on reliance risk

The mistake I see most often isn’t a missing signature on an arrangement. It’s compliance teams treating a verification vendor relationship as reliance when it’s actually outsourcing, then wondering why their program document doesn’t hold up under review. The paperwork looks similar on the surface, but the legal test underneath is completely different.

Weak access to evidence is the second recurring problem. A written arrangement that promises data “on request” but never gets tested against a real deadline is a liability waiting to surface, usually during an actual AUSTRAC review rather than a friendly internal audit. Senior manager sign off, automated evidence requests, and a sampling schedule you actually stick to do more to reduce your exposure than any amount of extra legal drafting.

If you take one thing from this: build the assessment calendar before you sign the first arrangement, not after the first review is already overdue.

How AML Guard supports your CDD reliance obligations

Running reliance arrangements on spreadsheets and email trails works until the first AUSTRAC review, and then it doesn’t. AML Guard gives Tranche 2 reporting entities a single workflow where the business-wide risk assessment, the AML/CTF policies, and your CDD reliance decisions come from the same linked set of program artefacts, so a reviewer checking one document finds the others consistent with it.

AML Guard reliance register showing arrangement status and next review date

The platform runs end-to-end customer due diligence, including document capture and biometric liveness checks, sanctions and PEP screening with ongoing re-screening, and beneficial ownership determination on a company’s ACN, with trusts and SMSFs reached through their corporate trustee. Every reliance decision, evidence request, and senior manager approval sits inside a seven-year tamper-evident audit trail, built so you can pull the file a regulator asks for in minutes rather than days. If your firm handles referrals from other reporting entities, such as a property advocacy relationship where CDD may be shared between parties, the same evidence-tracking discipline applies regardless of who originated the check.

An officer approves each determination before CDD proceeds, keeping the judgement with your team while the platform automates the lookups and record-keeping around it. If your current reliance register lives in a shared drive and a prayer, book a demo to see how the workflow handles arrangement documentation, scheduled assessments, and audit-ready evidence retrieval in one place.

How AML Guard supports your CDD reliance obligations — overview diagram

Where to verify these obligations directly

For the legal text itself, read sections 37A and 38 of the AML/CTF Act 2006 (Cth) on the Federal Register of Legislation. AUSTRAC’s reliance under CDD arrangements guidance and its reform overview page set out current procedural expectations, and the initial CDD overview clarifies where reliance stops and your own obligations begin.

Sources

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 10 September 2026.