Trust and company service providers

KYC and AML for Trust and Company Service Providers

Build a risk-based customer due diligence workflow for companies, trusts and layered structures—combining KYB, related-person KYC, PEP and sanctions screening with evidence your reviewers can understand.

Corporate services professional and client reviewing company ownership and trust records in an Australian office

Review-ready customer due diligence

Tell us which professional services you provide, your customer types and expected volume so we can scope the workflow.

Built for your workflow

Tailored business and trust onboarding workflows

01

Company, corporate trustee and trust workflows

02

Ownership, control and authority evidence

03

Related-person identity and AML screening

04

Clear exceptions and manual-review pathways

Australian trust and company services

Understand the customer, structure and people behind it

Trust and company service work can involve companies, corporate trustees, express trusts, partnerships, nominees and multi-layer ownership. AuthNTick helps bring the business record, structure documents, authority, individual identity checks and selected AML screening into a single reviewable case. The workflow is designed to support initial customer due diligence without pretending that software can classify every designated service, resolve every beneficial owner or make the firm’s legal and risk decisions.

Relevant checks

What the trust and company services workflow can cover

Configure the checks and review points that match your customer, service and risk-based process.

01

Business and legal-arrangement KYB

Collect and compare the legal name, entity or arrangement type, registration details, status, address and business activity for Australian companies, corporate trustees, partnerships and other customers in scope. Trusts and foreign structures can be routed for additional documentary review.

02

Trust and structure information

Capture the structure being created, administered or transacted with, together with the role of the trustee, corporate trustee, settlor, beneficiaries, appointor or other controlling parties when those people are relevant under your policy and the applicable designated service.

03

Representatives and authority to act

Identify the individual giving instructions or acting for the customer, record their capacity and collect suitable evidence of authority. The workflow distinguishes an authorised representative from a director, trustee, beneficial owner or other person connected to the structure.

04

Ownership and control mapping

Collect direct and indirect ownership or control information and follow layered structures towards the relevant natural persons. Corporate extracts, constitutions, trust deeds, partnership agreements, ownership charts and customer declarations can be requested when registry data is not enough.

05

Related-person KYC checks

Verify the identity of the customer, representative, beneficial owners and other relevant people selected by your risk-based procedure. Each person receives a clear, linked identity outcome rather than being treated as part of an unexplained business-level pass or fail.

06

PEP and sanctions screening

Screen relevant individuals for politically exposed person and targeted financial sanctions indicators. Potential matches remain review items: identifiers, role, country, date of birth and other context are used to support an informed assessment.

07

Relationship purpose and risk inputs

Record why the customer needs the service, the expected nature of the relationship, countries involved, delivery channel and other agreed risk inputs. These details support the reporting entity’s own customer risk rating and escalation rules.

08

Evidence, exceptions and gaps

Keep the declarations, checks, source evidence, dates, discrepancies and unresolved ownership or identity questions together. Reviewers can request more information, record a decision and retain an auditable explanation rather than relying on a black-box result.

Workflow

How KYC, AML and KYB fit into onboarding

  1. 01

    Classify the service and customer

    Your team first records the professional service, customer type, Australian connection and people potentially in scope. This matters because Table 6 coverage depends on the actual service and facts, not simply on calling a business a trust or company service provider.

  2. 02

    Collect the customer profile

    The customer supplies identifying information, the purpose and expected nature of the engagement, the representative giving instructions, jurisdictions involved and the details relevant to the company, trust or other legal arrangement.

  3. 03

    Verify the entity or arrangement

    Available registry data and suitable independent evidence are compared with the customer’s declarations. Trusts, private arrangements and foreign entities may require deeds, extracts, constitutions, registers or other documents because a standard company search will not explain the whole structure.

  4. 04

    Map ownership, control and authority

    Direct and indirect links are reviewed to identify the relevant natural persons and confirm who can act. Where one company owns or controls another, the workflow follows the chain until the people required by the firm’s procedure can be identified or a gap is escalated.

  5. 05

    Run individual KYC and AML checks

    Selected representatives, beneficial owners and other associated people complete identity verification and, where required, PEP and sanctions screening. Possible screening matches and identity discrepancies are referred for assessment rather than automatically deciding the engagement.

  6. 06

    Apply risk-based follow-up

    Higher-risk countries, opaque layers, unexplained nominees, unusual instructions or inconsistent information can trigger additional evidence and enhanced review under the customer’s own AML/CTF policies. Source of funds or source of wealth may also be required where the law and risk circumstances call for it.

  7. 07

    Review and retain the outcome

    An authorised reviewer sees what was established, how it was verified and what remains unresolved. The firm records its acceptance, escalation or refusal decision and manages recordkeeping and future review under its AML/CTF program.

Scope and responsibility

Regulatory and verification boundaries

Verification and screening support your controls; your organisation remains responsible for its AML/CTF obligations and customer decisions.

  1. 01

    From 1 July 2026, AML/CTF obligations apply to covered Table 6 professional designated services with the required geographical link to Australia. Whether a particular engagement is covered depends on the service and facts; profession or industry label alone is not decisive.

  2. 02

    AuthNTick provides verification, screening and evidence workflows. It does not determine whether every engagement is a designated service and does not replace legal advice, an AML/CTF risk assessment, program governance or the reporting entity’s decision-making.

  3. 03

    KYB verifies an entity or legal arrangement; KYC verifies a natural person; AML screening checks selected risk indicators. Using all three can support customer due diligence, but no single check guarantees AML/CTF compliance.

  4. 04

    Public records do not always reveal the complete ownership and control chain. Trusts, nominee arrangements, foreign entities and layered groups commonly need customer-supplied documents and manual review. AuthNTick does not promise complete automated UBO resolution.

  5. 05

    The people who must be identified can vary by customer type, designated service and risk. Settlors, trustees, beneficiaries, directors, owners, controllers and representatives should only be included as required by the applicable law and your documented policy.

  6. 06

    A PEP or sanctions indicator is not an automatic rejection. Potential matches need contextual assessment, while higher-risk cases may require enhanced customer due diligence, approvals and source-of-funds or source-of-wealth enquiries under your program.

Industry guidance

Build the process around the work.

Open each topic for practical considerations and implementation guidance.

01Which trust and company services are regulated?

AUSTRAC’s professional designated-services guidance describes the services in Table 6 of the AML/CTF Act. Coverage is profession-neutral and focuses on what the provider actually does. From 1 July 2026, a business providing a covered service with the required Australian geographical link has AML/CTF obligations, subject to the legislation and any applicable exemption.

  • Examples include sufficiently connected assistance with buying, selling or transferring a body corporate or legal arrangement, relevant equity or debt financing, and creating or restructuring a body corporate or legal arrangement.
  • Other listed services include selling or transferring a shelf company; acting or arranging for a person to act in certain company or legal-arrangement positions; nominee-shareholder services; and certain registered-office or business-address services.
  • Preliminary or preparatory work can be covered when it directly advances the regulated outcome. General advice, an ancillary task or a merely hypothetical future transaction may fall outside the service, depending on the facts.
  • Classify each service line and engagement rather than applying the same workflow to every customer of the firm. The onboarding record should preserve the service classification used to set the due-diligence scope.
02Customer due diligence before a designated service

AUSTRAC says initial customer due diligence generally must be completed before a reporting entity begins providing a designated service. The objective is to establish required matters on reasonable grounds using information and verification appropriate to the customer’s money laundering, terrorism financing and proliferation financing risk.

  • Establish the customer’s identity and, where relevant, any person acting for the customer, their authority, persons on whose behalf the service is received and the customer’s beneficial owners.
  • Determine whether relevant people are politically exposed persons or designated for targeted financial sanctions, and understand the nature and purpose of the business relationship or occasional transaction.
  • Collect KYC information, assign or inform the customer risk rating and verify appropriate information using reliable, independent data. Higher-risk or unusual circumstances commonly require more evidence.
  • Keep enough evidence to explain how required matters were established. A workflow should surface missing information and conflicting results instead of converting uncertainty into an unsupported pass.
03KYB for companies and corporate trustees

Company onboarding starts by connecting the customer’s declaration to the legal entity that will receive the service. A legal name and ABN or ACN can support that task, but the customer profile also needs to explain the business activity, representative, proposed service and ownership or control relevant to the firm’s risk-based process.

  • Compare declared identifiers with available registration status, registered details, officeholders and other suitable independent information. Record discrepancies and the date of the source.
  • Distinguish the operating company from a corporate trustee and identify the trust or other arrangement for which that company acts. Verifying only the corporate trustee can leave the underlying customer relationship unexplained.
  • Collect evidence of the representative’s role and authority. A person submitting an online form is not necessarily authorised to instruct the firm or bind the customer.
  • Request a current extract, constitution, shareholder information, ownership chart or other supporting material when the available registry information cannot establish the relevant ownership and control chain.
04CDD for trusts and other legal arrangements

Trusts are not verified in exactly the same way as companies. The trust deed or a suitable extract may be needed to understand the trust, its purpose and the parties connected to it. The people in scope should be determined from the applicable service, customer type, legal requirements and the firm’s risk-based policies.

  • Capture the trust name and type, date and jurisdiction of establishment, business or investment purpose, trustee details and the document relied upon to understand the arrangement.
  • Identify and verify trustees, settlors, beneficiaries, appointors, protectors, controllers or persons receiving the service only where those roles are relevant under the applicable law and your procedure.
  • For a corporate trustee, complete the necessary company KYB and then resolve the natural persons who own or control that trustee or otherwise fall within the due-diligence scope.
  • Treat broad beneficiary classes, discretionary powers, foreign trust-like arrangements and documents that are incomplete or inconsistent as structured review cases rather than assuming they can be resolved automatically.
05Layered ownership and beneficial owners

AUSTRAC notes that customers can have complex ownership structures and that beneficial owners may be difficult to identify. The investigation can combine customer declarations with ASIC information, company extracts, constitutions, trust deeds, partnership agreements and other reliable evidence.

  • Follow ownership through intermediate entities until the relevant natural persons are identified, or document why the applicable rules support another outcome. Do not stop at the first corporate shareholder.
  • Consider control through voting rights, appointment powers, trustee or appointor roles, contractual influence or other means—not only a direct share percentage.
  • Link every person to the entity, arrangement and role that brought them into scope. This makes related-person KYC and screening outcomes intelligible to the reviewer.
  • Where the chain cannot be resolved, state what evidence was reviewed, what remains unknown and which additional document or approval is required. Manual review is a control, not a platform failure.
06PEP, sanctions and higher-risk indicators

Trust and company structures can be legitimate and commercially necessary, but their flexibility can also obscure ownership, control or the movement of value. AUSTRAC’s sector risk material highlights risk factors including unexplained structural changes, high-risk jurisdictions, remote delivery and instructions delivered through intermediaries.

  • Screen the individuals required by your policy for PEP and targeted financial sanctions indicators, then investigate possible matches using additional identifiers and context.
  • Consider jurisdiction, service type, customer type, delivery channel and unusual behaviour as separate inputs. A low-risk company record does not erase a higher-risk service or transaction pattern.
  • Escalate unexplained nominees, rapid or frequent changes in ownership, reluctance to identify controlling people, opaque offshore layers or instructions with no clear commercial rationale.
  • Apply enhanced due diligence and source-of-funds or source-of-wealth enquiries when required by the law and your policies. AuthNTick can collect agreed evidence, but your reporting entity sets the threshold and decides the outcome.
07Build a review-ready evidence trail

Effective onboarding produces more than a green status. It should let an authorised person reconstruct who the customer was, which people and structures were considered, what independent evidence was used and why the firm reached its decision.

  • Retain the customer’s declarations, entity and trust documents, registry information, identity-verification outcomes, screening results, dates and versioned risk inputs according to your recordkeeping policy.
  • Separate confirmed facts, customer-supplied information, possible matches and unresolved gaps so future reviewers can understand the strength of each conclusion.
  • Record manual-review notes, additional evidence requests, approvals and the final onboarding decision. The decision remains with the reporting entity, not the screening tool.
  • Use event-driven or periodic review when ownership, control, authorised people, countries, service use or risk changes. A point-in-time KYC or KYB check is not ongoing customer due diligence by itself.

Practical questions, answered.

Are all trust and company service providers regulated by AUSTRAC?

Not merely because they use that label. From 1 July 2026, AML/CTF obligations apply when a business provides a covered designated service in Table 6 with the required geographical link to Australia, subject to the Act, Rules and applicable exemptions. The specific service and facts determine coverage.

Which trust and company services may be designated services?

Examples include sufficiently connected assistance with creating or restructuring a body corporate or legal arrangement, buying or transferring one, selling a shelf company, acting or arranging for certain officeholder or trustee roles, nominee-shareholder services and certain registered-office or business-address services. Firms should check the current legislation and AUSTRAC guidance for their exact activities.

What is the difference between KYB, KYC and AML screening?

KYB verifies the company, trust or other business customer and helps map authority, ownership and control. KYC verifies a natural person. AML screening checks selected risk indicators such as PEP and targeted financial sanctions information. A customer-due-diligence workflow may combine all three, but they remain distinct controls.

Who may need to be checked when creating a trust?

The relevant people depend on the designated service, customer type, law and the reporting entity’s policy. They can include the trustee, settlor, beneficiaries, appointor or controller, the person giving instructions and beneficial owners of a corporate trustee. Do not assume every role receives the same check in every case.

Can AuthNTick automatically identify every beneficial owner?

No. Available registry information can support ownership enquiries, but private trusts, nominees, foreign entities and layered groups may require deeds, corporate extracts, shareholder information, ownership charts and manual review. AuthNTick does not promise complete automated UBO resolution.

Does a PEP or sanctions match mean the customer must be rejected?

Not automatically. A similar name may not be the same person, so possible matches need assessment using identifiers and context. If a person is confirmed as a PEP or designated for targeted financial sanctions, the reporting entity must apply the legal requirements and its AML/CTF policies to the case.

When might enhanced due diligence or source-of-funds evidence be needed?

The need depends on the customer’s risk and the applicable obligations. Opaque ownership, unusual instructions, high-risk jurisdictions, nominee involvement, significant unexplained changes or certain PEP relationships can justify more information, approvals and source-of-funds or source-of-wealth enquiries under the firm’s program.

Does using AuthNTick make a firm AML/CTF compliant?

No vendor or single check can guarantee compliance. AuthNTick can support identity, business verification, screening and evidence collection, while the reporting entity remains responsible for service classification, enrolment where required, its risk assessment and AML/CTF program, customer decisions, ongoing due diligence, reporting and recordkeeping.

Talk to AuthNTick

Bring complex customer structures into one reviewable workflow.

Tell us about your services, structures, customer types and expected volume.