
Trust KYC in Australia requires reporting entities to establish the identity of the trust, identify every person who controls or benefits from it, and apply enhanced measures where the Act requires them. Under AUSTRAC’s guidance and the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025, that means identifying the trustee, settlor, appointor, any guardian or protector, the beneficiaries or their classes, and anyone else with control, then verifying as the trust’s risk requires, screening for PEP and sanctions exposure, and keeping records for at least seven years.
TL;DR:
- Verifying the trust’s governance structure and identifying all control persons, including appointors and beneficiaries, is essential before providing designated services.
- The full set of persons to identify includes trustees, settlors, appointors, guardians, protectors, beneficiaries or classes of beneficiary, and anyone else with control.
- Enhanced customer due diligence is required where the trust’s ML/TF risk is high, a suspicious matter reporting obligation has arisen and you continue the service, a relevant person is a foreign PEP, a relevant person is in or formed in a jurisdiction the FATF has called for enhanced due diligence on, or the service sought is unusual (section 32 of the Act and section 6-20 of the Rules).
- The trust deed is the evidence of control. AUSTRAC does not require stored copies, but keeping the pages you relied on (the appointment clause, trustee powers, beneficiaries and distribution rules) makes the determination easier to follow.
- Records of the risk assessment and decisions, including why enhanced CDD applied, must be kept for seven years after the relationship ends or the transaction is completed (section 111).
Table of Contents
- What matters you must establish for a trust
- Who to identify: trustees, settlors, appointors, beneficiaries and persons with control
- What KYC information to collect and how to verify it
- When to apply enhanced customer due diligence
- Reading the trust deed and recording officer determinations
- Ongoing CDD, monitoring and record-keeping
- Common pitfalls, red flags and how to avoid them
- Practical checklist and onboarding items for trust CDD
- Why deed-first, officer-documented decisions reduce audit friction
- Book a demo to see trust CDD handled end to end
- Sources
- FAQ
What matters you must establish for a trust
Verifying the trustee’s identity is only the starting point. AUSTRAC’s initial CDD guidance makes clear that a reporting entity must collect information about the trust’s control structure and the powers that govern it, not just confirm who signed the engagement.
The matters you need to establish on reasonable grounds include:
- The identity of the trust itself: full name, kind of trust, and any unique identifiers such as an ABN.
- The persons on whose behalf the trust receives the service, including beneficiaries or defined classes of beneficiary.
- Anyone acting as a representative, and the authority under which they act.
- Beneficial owners and any person with effective control, which for trusts often extends beyond the trustee.
- Politically exposed person (PEP) status and targeted financial sanctions (TFS) exposure for relevant individuals.
- The nature and purpose of the business relationship the trust is entering into.
Identifying named beneficiaries is straightforward: you collect and verify their details the same way you would for any individual. Identifying a class of beneficiary, such as “the children and grandchildren of the settlor”, is different. Where the nature of the trust means each beneficiary cannot be identified, the Rules require a description of each class instead (section 6-3(3)), which you can check against the deed or evidence of distributions.
The depth of verification scales with ML/TF risk. A discretionary family trust running a suburban rental portfolio warrants a lighter touch than a trust structure layered through offshore entities or linked to a foreign PEP.
Who to identify: trustees, settlors, appointors, beneficiaries and persons with control
Verifying a trust means verifying more than the trustee. The full set of persons to identify typically includes the trustee, the settlor, the appointor, the beneficiaries or their classes, and anyone else who exercises control over the trust’s assets or decisions.
- Identify the trustee. For an individual trustee, verify identity the same way you would for any natural person customer. For a corporate trustee, the company resolves on its own ACN through ASIC registry data, which confirms the company’s registration, status and officeholders.
- Identify the settlor. The settlor established the trust and, while often a minor player in an operating trust, their identity still needs to be recorded and assessed against PEP and sanctions lists.
- Identify the appointor. This is frequently the person with the most practical power in a discretionary trust: the ability to appoint or remove the trustee. AUSTRAC’s trust guidance lists appointors, with settlors, guardians and protectors, among the people who may be a trust’s beneficial owners, whoever signs as trustee.
- Identify beneficiaries or classes of beneficiary. Named beneficiaries get verified individually. Where they cannot be named, each class is recorded as a description taken from the deed’s own wording.
- Identify any other person with control. Some deeds create a protector or guardian role with veto rights over trustee decisions. The Rules require you to collect the identity of any guardian or protector, as well as the settlor and appointor (section 6-3(5)).
The control test matters most for discretionary trusts, where beneficiaries hold no fixed entitlement and the ownership limb of “beneficial owner” simply does not resolve. Control is the operative test there: who can direct or influence the trustee, not who holds a percentage, with that reasoning written down against each person’s name. Our guide to trust beneficial ownership covers the tests in more detail.
What KYC information to collect and how to verify it
Trust-level and person-level KYC information sit side by side in the file. Both are verified against reliable and independent data to the extent the trust’s risk requires. Some matters, such as the identity of the beneficiaries or of a representative, can be taken as established without verification where the trust’s risk is low, enhanced CDD does not apply, you have collected KYC information about the matter, and there are no reasonable grounds to doubt it (section 31 of the Act and section 6-17 of the Rules).
At the trust level, collect:
- Full name of the trust, any business names, and any other names it is commonly known by.
- The kind of trust (discretionary, unit, fixed, testamentary, or bare trust).
- ABN or other unique identifier, and the trustee’s ACN where the trustee is a company.
- The address of the trust’s principal place of business or operations.
- Evidence the trust exists, and information about the powers that bind and govern it, usually from the trust deed and any deeds of variation.
- The full name of each individual with primary responsibility for the trust’s governance and executive decisions.
At the person level, collect standard identity information for individuals and consider biometric liveness checks where remote onboarding raises impersonation risk. For entities acting as trustee or beneficiary, check ABN Lookup on the Australian Business Register, ASIC for a corporate trustee, and the ACNC register for a charitable trust.
PEP and targeted financial sanctions screening applies to the trustee, the settlor, the appointor, and any identified beneficiary or controller, not just the person who walks in the door. Screen at onboarding and again whenever a new person takes on a controlling role, such as a change of appointor. A foreign PEP always means enhanced customer due diligence; a domestic or international organisation PEP does only where the risk is high. A confirmed sanctions match is different again: do not deal with the person’s assets without a permit from the Australian Sanctions Office.
When to apply enhanced customer due diligence
Enhanced customer due diligence (ECDD) is not optional once certain triggers are met. Section 32 of the Act, and section 6-20 of the Rules, set out when it is required rather than a matter of internal risk appetite:
- The trust’s ML/TF risk is high, based on your own risk assessment.
- The trust, any of its beneficial owners (which can include a settlor, appointor, guardian or protector with control), anyone acting on its behalf such as a trustee, or anyone on whose behalf it receives the service is a foreign PEP.
- The trust, a beneficial owner, or anyone acting for it or receiving the service through it is physically present in, or was formed in, a high-risk jurisdiction the Financial Action Task Force has called for enhanced due diligence on.
- A suspicious matter reporting obligation has arisen and you propose to keep providing the service.
- The trust asks for services with no apparent economic or legal purpose, or involving unusually complex or large transactions or an unusual pattern of them (Rules section 6-20).
Once ECDD is triggered, the measures must be appropriate to the trust’s ML/TF risk. They can include obtaining more documentary evidence than standard CDD needed and re-verifying identity where earlier checks now look unreliable. Where enhanced CDD applies because the risk is high, an SMR has arisen and you are continuing, or a FATF call-for-action jurisdiction is involved, the trust’s source of wealth and source of funds are matters to establish if they are relevant to the nature of its risk (Rules section 6-21). Where a foreign PEP is involved, or a domestic or international organisation PEP and the risk is high, establish the source of that PEP’s wealth and funds (Rules section 6-23).
Pro Tip: Write the trigger and the response as two separate lines in the file: “ECDD triggered because [specific fact]” followed by “Measures applied: [specific steps].” A file that jumps straight to “enhanced checks completed” does not show why.
Section 111 of the Act requires CDD records to include records of any analysis, risk assessment or decision-making about the customer. So the file should state the circumstances that required ECDD, the measures chosen and why, and any resulting change to the customer’s risk rating.
Reading the trust deed and recording officer determinations
Corporate trustees resolve neatly: run the ACN through ASIC, confirm the company’s status and officeholders, and you have a verified corporate identity. What ASIC data cannot tell you is who controls the trust itself, and that is where officer judgement takes over.
Deed review is manual work. AUSTRAC does not require you to keep copies of the documents you verify against, and you can record their details instead, but keeping the specific pages you relied on, not a paraphrased summary, makes the determination easier to follow later. Those pages usually cover:
- The appointment clause, which usually names or defines the appointor and their power to hire or fire the trustee.
- The trustee’s powers, particularly around distribution discretion and asset management.
- The description of beneficiaries or beneficiary classes, exactly as worded in the deed.
- Vesting date and distribution rules, which determine when and how the trust winds up.
- Any deed variations executed after the original document, since these can shift control entirely.
For a corporate trustee, the practical sequence is: resolve the company on its ACN through ASIC registry data first, then read the deed to determine who controls the trustee’s decisions. A platform can capture ACN lookups and store deed images alongside the file, but it cannot read the deed for you.
A workable determination entry records four things: the facts extracted from the deed (with page references), the legal inference drawn (who satisfies the control test and why), the conclusion reached about beneficial ownership or control, and a signed officer approval with a date. Imaging and storage can be automated; the inference and the approval cannot.

Ongoing CDD, monitoring and record-keeping
Trust KYC does not end at onboarding. Transaction monitoring should flag activity that sits outside what you would expect from the trust’s stated purpose, such as a family discretionary trust suddenly moving funds through a jurisdiction it has no prior connection to. Periodic risk reviews apply to the whole relationship, and specific triggers, such as a change of appointor or trustee, should prompt re-verification rather than waiting for the next scheduled review.
Record-keeping has one governing number. Section 111 of the AML/CTF Act sets the minimum at seven years after the business relationship ends, or after the occasional transaction is completed. What must be retained:
- Identification records for the trust and every person identified against it.
- The ML/TF risk assessment and any updates made to it over the life of the relationship.
- Officer decisions, including ECDD determinations and control test reasoning.
If activity or information raises reasonable suspicion, section 41 of the AML/CTF Act requires a suspicious matter report (SMR). An SMR obligation and a decision to continue or exit the relationship are separate questions, and the file should record both decisions independently. If you continue, enhanced CDD applies (section 32).
Common pitfalls, red flags and how to avoid them
A frequent gap in trust files is identifying the trustee and stopping there, leaving the appointor, settlor and beneficiary classes unaddressed. Close behind it: deed pages go missing from the file, beneficial ownership reasoning is thin or absent, ECDD gets applied inconsistently across similar files, and PEP or TFS screening only covers the trustee rather than every controlling party.
Fixes are straightforward to implement. Standardise which deed pages must be extracted for every trust file. Require a signed officer determination before any trust CDD is marked complete. Use independent registry checks rather than relying on customer-supplied company details. Where doubt exists, escalate to ECDD and write down why.
Pro Tip: Keep deed-page snapshots filed against the specific clause they support, and cross-reference each one to the line in the risk assessment it justifies. A reviewer should be able to trace “appointor identified” straight back to the exact deed clause without asking you.
Practical checklist and onboarding items for trust CDD
- Collect the trust’s full name, kind of trust, and ABN or other identifier.
- Copy the relevant deed pages: appointment clause, trustee powers, beneficiary descriptions, vesting rules.
- Run ABN Lookup, ASIC and, for a charity, ACNC checks on any corporate trustee or entity beneficiary.
- Identify the trustee, settlor, appointor, any guardian or protector, and the beneficiaries or a description of each class, verifying as the trust’s risk requires.
- Screen every identified person for PEP status and targeted financial sanctions.
- Decide whether ECDD applies, and if so, document the trigger and the measures taken.
- Record the officer’s determination on control and beneficial ownership, signed and dated.
- File everything with a retention marker showing the seven-year minimum from relationship end.
File deed scans, the officer determination, and registry screenshots together under one customer reference, not scattered across separate systems. A checklist built around this sequence turns a vague “we did CDD on the trust” into a file an auditor can actually follow.
Why deed-first, officer-documented decisions reduce audit friction
A trust file is easiest to follow when the deed reasoning sits next to the risk assessment, not buried in a separate folder. Tie your policy to that risk assessment explicitly, and keep the specific deed pages and the officer’s own reasoning in the file, not a summary written after the fact. That discipline serves compliance and day-to-day operations equally well.
Book a demo to see trust CDD handled end to end
The platform is built specifically for Australian Tranche 2 reporting entities, with a workflow that follows the same deed-first logic this guide sets out. It captures and stores specific deed pages an officer relies on, runs ACN lookups against ASIC registry data for corporate trustees, screens trustees, settlors, appointors and beneficiaries for PEP and sanctions exposure, and records the officer’s reasoning against each determination.
Every determination still needs an officer’s sign-off before CDD proceeds. The platform automates the lookups, the screening and the record-keeping, storing everything in an 8-year tamper-evident audit trail, above the statutory seven-year minimum. See how the platform’s features map to a trust file, check current subscription plans, or book a demo to walk through a live trust CDD file with your own deed as the example.
Sources
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) | Federal Register of Legislation
- Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 | Federal Register of Legislation
- Initial CDD for trust | AUSTRAC
FAQ
Is KYC a legal requirement in Australia?
Yes. Reporting entities under the AML/CTF Act must complete initial customer due diligence before providing a designated service, including to trusts, unless the Act and Rules allow it to be delayed. That means establishing each required matter on reasonable grounds, verifying as appropriate to the customer’s risk, and applying enhanced measures where section 32 of the Act requires them. This flows directly from the AML/CTF Act and the Rules 2025; it is not a discretionary internal policy.
What documents are needed for trust KYC?
Usually the trust deed and any deeds of variation, the trust’s name and unique identifier such as an ABN, and identity information for the trustee, settlor, appointor and any guardian or protector. For a corporate trustee, ASIC registry data covers the company’s ACN and officeholder details. Collect identity information for each beneficiary; where the nature of the trust means you cannot identify each one, record a description of each class from the deed’s own wording.
What are the new trust rules in Australia?
Section 6-3 of the AML/CTF Rules 2025 sets the minimum information to collect when the customer is a trust: its name, kind, business and other names, any unique identifier such as an ABN, its principal place of business or operations, evidence of its existence, the powers that govern it and who makes its decisions; the beneficiaries or a description of each class; the trustees; and the control structure and the identity of any settlor, appointor, guardian or protector. Tranche 2 obligations for sectors including real estate, legal, accounting, and trust and company service providers commenced on 1 July 2026.
Is it compulsory to do KYC every year?
There is no fixed annual re-verification rule; instead, ongoing CDD requires periodic risk reviews and re-verification whenever a trigger occurs, such as a change of trustee or appointor, or unusual transaction activity. Records supporting these decisions must be retained for a minimum of seven years after the relationship ends or after the last occasional transaction.
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.