Accounting and advisory client verification

KYC and AML checks for Australian accounting firms

Support risk-based onboarding for covered professional services with individual KYC, business verification, beneficial ownership workflows, PEP and sanctions screening, and documented exceptions.

Australian accountant and business owner reviewing company records and client onboarding documents on a laptop

Accounting onboarding ready

Tell us your customer types, designated services and evidence requirements so we can scope the right verification workflow.

Built for your workflow

Customer verification support for accounting and advisory practices

01

Individual and business verification

02

Beneficial owner and representative checks

03

PEP and sanctions screening

04

Timestamped results and exception evidence

Accounting AML/CTF onboarding

Put reliable verification evidence inside your practice’s risk-based process

Accounting and advisory firms can use AuthNTick to support identity, entity and screening steps when onboarding clients for covered designated services. The workflow can help standardise evidence and exceptions across the practice, while your reporting entity retains responsibility for service scoping, its AML/CTF program, risk decisions, ongoing due diligence and reporting.

Relevant checks

Checks an accounting onboarding workflow can include

Configure the checks and review points that match your customer, service and risk-based process.

01

Individual client KYC

Verify identifying information for individual clients using the evidence and verification method configured for your practice. The result can support initial customer due diligence before a covered designated service begins.

02

Business and entity verification

Check key details for Australian companies and other organisations, then retain the available entity evidence with the engagement file. More complex, foreign or trust structures may require additional documents and manual assessment.

03

Representatives and authority

Build a workflow that identifies the person acting for a client, verifies that person where required and captures evidence of their authority. Your practice decides what authority is sufficient for the customer and service.

04

Beneficial owner verification

Use KYB and individual KYC steps to support identification and verification of relevant beneficial owners. Your AML/CTF policies must determine whose information is required and when the applicable process can stop.

05

PEP and sanctions screening

Compare relevant people against politically exposed person, sanctions and agreed watchlist data. Possible matches are review items, not automatic proof of identity, status, misconduct or a final onboarding outcome.

06

Evidence and exception handling

Record the result available at the time, route failed or inconclusive checks for authorised review and keep the reason for clearance, escalation or a request for further evidence alongside the client file.

Workflow

A practical client verification workflow

  1. 01

    Map the services your practice provides

    Identify whether an engagement includes a covered professional designated service under Table 6 and has the required geographical link to Australia. Do not assume every tax return, audit, bookkeeping or general advisory engagement is regulated in the same way.

  2. 02

    Define the client and related-person requirements

    Use your approved AML/CTF policies to specify the KYC information, entity records, representatives, authority, beneficial owners, screening and other risk information required for each customer type and designated service.

  3. 03

    Collect and verify onboarding information

    Send the configured verification workflow to the client or relevant person. Use reliable and independent data appropriate to the assessed risk, and obtain additional evidence when the standard route cannot establish what your policy requires.

  4. 04

    Review screening results and exceptions

    Assess possible PEP, sanctions or watchlist similarities using the available identifiers. Investigate mismatches, incomplete ownership information and unclear authority instead of treating a system result as the practice’s final decision.

  5. 05

    Make and document the practice’s risk decision

    Combine the verification evidence with the nature and purpose of the relationship, the designated service, delivery channel, jurisdictions, ownership and other relevant indicators. Your authorised personnel determine the risk rating and whether standard, simplified or enhanced CDD is appropriate.

  6. 06

    Retain evidence and continue due diligence

    Keep the check results with the risk assessment, reviewer notes, approvals and engagement decision. Separately operate the ongoing CDD, monitoring, refresh, reporting and record-keeping controls required by your AML/CTF program.

Scope and responsibility

Important compliance and service boundaries

  1. 01

    AuthNTick supports identity, entity and screening checks. It does not supply your complete AML/CTF program or determine whether an engagement is a designated service.

  2. 02

    Your practice remains responsible for its ML/TF risk assessment, customer risk methodology, policies, governance, personnel controls, independent evaluations and legal interpretation.

  3. 03

    AuthNTick does not make your final simplified, standard or enhanced CDD decision and does not determine whether you may start, continue, restrict or end an engagement.

  4. 04

    A one-off KYC, KYB or screening result does not provide transaction monitoring, ongoing CDD, suspicious matter reporting, threshold transaction reporting or annual compliance reporting.

  5. 05

    Outsourcing verification or another AML/CTF function does not transfer the reporting entity’s obligations or general liability for a breach. Provider due diligence and oversight remain important.

  6. 06

    This page is general product information, not legal advice. Accountants and advisers should use current AUSTRAC guidance and obtain professional advice for their own facts.

Industry guidance

Build the process around the work.

Open each topic for practical considerations and implementation guidance.

01Start with designated-service scope, not the client’s industry label

From 1 July 2026, AML/CTF obligations apply when an accounting or professional-services business provides one or more covered Table 6 designated services with a geographical link to Australia. The rules are profession neutral and service based. A client being a company, investor or property owner does not by itself establish that your engagement is regulated.

  • Map each service line against the current Table 6 descriptions and document how you reached the scope decision.
  • Covered activities can include actively advancing certain real-estate or entity transactions, creating or restructuring entities or arrangements, handling property for a transaction, arranging specified roles, and providing certain addresses.
  • General advice or an ancillary service may fall outside Table 6 where it merely influences an outcome rather than directly advancing the covered transaction, creation or restructure.
  • Revisit scope when the engagement changes. A matter that begins as general advice may later include instructions that trigger a designated service.
02Design onboarding for the actual customer type

Initial CDD is not a single universal identity check. The information needed depends on whether the customer is an individual, body corporate, partnership, unincorporated association, trust, government body or another structure, as well as the customer’s ML/TF risk. Build separate paths so staff collect the right evidence without forcing every client through the same form.

  • For an individual, collect and verify the KYC information required by your policies using reliable and independent data appropriate to risk.
  • For a company or other organisation, verify the entity and identify the natural people who own or control it where required.
  • For a trust, identify the trust and the relevant parties specified by your policies; complex ownership or foreign arrangements may need deeds, extracts or further evidence.
  • Collect the nature and purpose of the relationship and enough service, delivery-channel and jurisdiction information to inform the practice’s risk assessment.
03Treat representatives and authority as separate questions

The person communicating with the practice may not be the customer. A director, employee, trustee, attorney, agent or adviser may act for another individual or entity. Your workflow should distinguish who the customer is, who is acting for them, whether that representative must be identified and verified, and what demonstrates their authority.

  • Record the capacity in which the representative acts and the customer they represent.
  • Verify the representative when required by your policies rather than relying only on an email address or introduction.
  • Check authority using appropriate evidence, such as current entity records, an appointment, resolution, trust documentation or another source accepted by your practice.
  • Escalate conflicting instructions, unexpected account details or authority that cannot be established instead of working around the exception.
04Connect beneficial ownership checks to current CDD measures

Beneficial ownership work often requires more than confirming an ABN or ACN. Accountants may need to trace ownership or control through intermediate entities and verify relevant natural persons. AUSTRAC’s accountant starter-kit update released on 10 June 2026 changed ownership terminology and clarified when checks can stop for certain customer types under the new CDD measures.

  • Use current customer-type forms and processes rather than copying an older ownership threshold or stopping rule into a new workflow.
  • Keep the sources used to understand the structure and record why the practice concluded that the required beneficial owners were identified.
  • Route nominee arrangements, layered ownership, foreign entities, trusts and inconsistencies for further evidence or manual review.
  • Apply individual KYC and relevant screening to the people identified by your policies; an entity registry result alone does not verify those people.
05Use PEP and targeted financial sanctions screening carefully

Screening can help identify possible politically exposed person connections and similarities to sanctions or other agreed watchlist data. It is one input to due diligence. A similar name is not a confirmed match, and a PEP connection is a risk factor rather than evidence of criminal conduct.

  • Use full and accurate identifying information where available so reviewers can distinguish people with similar names.
  • Check relevant customers, beneficial owners and other associated people in accordance with your policies and the circumstances of the engagement.
  • Document whether a possible match was cleared, confirmed or remains unresolved, including the identifiers and source context considered.
  • Escalate the outcome under your own sanctions and enhanced CDD procedures; AuthNTick does not make the legal or engagement decision for the practice.
06Build a controlled exception path for real client files

Accounting clients do not always fit a straight-through digital process. Historic entities, name changes, overseas documents, layered groups, executors and older trusts can create incomplete or conflicting evidence. A defensible workflow explains what staff do when an automated check cannot establish the required information.

  • Classify outcomes consistently—for example, verified, further evidence required, possible match, escalated or unable to verify.
  • Define who can clear each exception and when senior, compliance or legal review is required.
  • Keep supplemental documents and reviewer reasoning with the original result so the decision can be reconstructed later.
  • Do not weaken controls simply to meet an engagement deadline; use the delayed initial CDD rules only where they genuinely apply and your policies manage the risk.
07Keep verification evidence inside the wider AML/CTF program

A clear onboarding result helps, but compliance continues after identity verification. Reporting entities need an approved and maintained AML/CTF program, initial and ongoing CDD, record keeping, reporting, governance, personnel due diligence and training, and independent evaluation controls that match their designated services and ML/TF risks.

  • Combine check results with the practice’s documented customer risk assessment rather than treating a clear KYC result as a low-risk classification.
  • Define events that trigger updated KYC, ownership review, rescreening or enhanced CDD during the relationship.
  • Keep transaction and behavioural monitoring separate from identity and name screening, and ensure reporting decisions reach authorised personnel.
  • Review AUSTRAC starter-kit changes and retire superseded forms so teams do not apply outdated onboarding, beneficial ownership or reporting processes.
08Manage AuthNTick as a supporting provider, not the accountable entity

A practice may use a technology or outsourced provider to help perform verification and screening. AUSTRAC distinguishes outsourcing from permitted reliance on CDD performed by another regulated entity. A KYC provider does not become responsible for the accounting practice’s obligations merely because it supplies a check.

  • Define the data, customer types, jurisdictions, result fields and exception-handling service your practice expects.
  • Conduct appropriate provider due diligence and document responsibilities, performance expectations, privacy and information-sharing controls.
  • Monitor the service and sample outcomes in proportion to your compliance and ML/TF risks.
  • Maintain senior-management oversight and a practical route to remediate problems; your practice generally remains legally liable for its obligations.

Practical questions, answered.

Do all accounting and tax services require KYC and AML checks from 1 July 2026?

No. The new obligations are service based. They apply where a business provides a covered designated service, including relevant Table 6 professional services, with the required geographical link to Australia. A practice should map its actual services and obtain advice on ambiguous engagements rather than assume every tax, audit, bookkeeping or advisory task is covered.

Which accounting and advisory activities can be designated services?

Table 6 includes specified services connected with real-estate and entity transactions, handling property for a transaction, equity or debt financing, shelf companies, creating or restructuring bodies corporate or legal arrangements, arranging specified roles and providing certain registered-office or business addresses. Exact scope depends on the facts and current law.

What checks can AuthNTick support for an individual accounting client?

AuthNTick can support configured KYC identity verification and, where selected, PEP, sanctions and relevant watchlist screening. The practice remains responsible for collecting any additional KYC and relationship information, assessing risk, resolving exceptions and deciding whether its initial CDD requirements are met.

How should an accounting firm onboard a company, partnership or trust?

The practice should follow the customer-type process in its current AML/CTF policies. This commonly involves identifying and verifying the entity, relevant representatives and their authority, and beneficial owners or other associated people as required, then combining that evidence with relationship purpose and ML/TF risk information.

Does a KYB result identify every beneficial owner?

Not necessarily. Registry and entity data can support the ownership and control inquiry, but layered, trust, nominee, foreign or complex structures may require further documents and manual tracing. The practice must apply the beneficial ownership process and stopping rules required by its current policies.

Does a PEP or sanctions screening result decide whether the firm can accept a client?

No. A possible match needs review against available identifiers. PEP status is a risk factor rather than proof of wrongdoing, while a confirmed sanctions result may have different legal consequences. The accounting practice must follow its own escalation, sanctions and enhanced CDD procedures and make the final decision.

Can an accounting practice outsource KYC and transfer its AML/CTF obligations?

It may use providers to support certain AML/CTF functions, but outsourcing does not transfer the reporting entity’s responsibility. AUSTRAC states that the business generally remains legally liable for breaches and expects appropriate provider due diligence, written arrangements, oversight, monitoring and documented controls.

Does AuthNTick provide an AML/CTF program, monitoring and AUSTRAC reporting?

No. AuthNTick provides scoped identity, entity and screening checks. The service does not replace the practice’s AML/CTF program, ML/TF or customer risk assessment, ongoing CDD, transaction monitoring, suspicious matter or other regulatory reporting, governance, independent evaluation or legal advice.

What should the practice keep with an AuthNTick check result?

Keep the result with the customer identifiers, entity and authority evidence, ownership analysis, screening review notes, relationship purpose, risk assessment, approvals, exceptions and final engagement decision required by your policies. Retain records under the current AML/CTF requirements and your practice’s information-governance controls.

Talk to AuthNTick

Build the right verification workflow for your accounting practice.

Tell us about your designated services, customer types and evidence requirements.