Ongoing customer due diligence: why CDD in real estate doesn't end at settlement
CDD is not a one-off form you complete at the start of a transaction. Here's what triggers a re-check under AML/CTF Tranche 2, how often to review a client file, and what a working ongoing CDD process looks like for a small agency.
Ongoing customer due diligence: why CDD in real estate doesn't end at settlement
You verified the client at the start of the transaction. Identity checked, ownership structure confirmed, file closed. Six months later the same client is back with a different property, a different structure behind it, or a name that's now showing up somewhere it shouldn't. Is your file still current, or did it stop being current the day it was created?
Under AML/CTF Tranche 2, customer due diligence is not a task you complete once per client and file away. Current guidance points to CDD as an ongoing obligation, and a repeat client, a changed structure, or a new red flag can all trigger a re-check.
What "ongoing" actually covers
CDD has two halves. Initial CDD happens before you provide your designated service. Ongoing CDD is what current guidance points to as the obligation to keep monitoring the relationship and the transactions within it for as long as you're acting for that client, and to update the file when something material changes.
For a real estate agency that mostly deals with one-off transactions, that second half is easy to underweight. But "one-off" transaction doesn't mean the file is frozen the day it's opened. A transaction can take months from listing to settlement, and a client relationship can span multiple transactions over years, especially with investors, developers, and repeat sellers.
What actually triggers a re-check
Current guidance points to a re-check being warranted when:
- A client comes back for a new transaction. The identity check from two years ago may still be valid, but the ownership structure, source of funds, or risk profile behind this deal could be completely different from the last one.
- The transaction itself changes materially. A larger price than expected for the property, an unusual payment structure, a buyer who suddenly wants a third party to pay on their behalf. Current guidance treats a material change in the nature of the transaction as a trigger to revisit the risk assessment, not just note it and move on.
- You learn something new about beneficial ownership. A company client restructures. A trust adds a beneficiary. The person who was the sole director last time isn't this time. Beneficial ownership is a point-in-time fact until it isn't, and a changed structure generally means updating who you've identified as standing behind the entity.
- A sanctions or PEP match appears that wasn't there before. Screening lists change. Someone can become a politically exposed person, or be added to a sanctions list, well after you completed their original file. Current guidance points to periodic re-screening, not a one-time check at onboarding, as the expected practice for managing this risk.
- Something about the client or the deal doesn't add up. Documents that look inconsistent, a source of funds explanation that's changed since the last file, a level of urgency that doesn't match the transaction. These are the kind of observations that would normally sit behind a suspicious matter report consideration, and current guidance points to them also being a trigger to look again at the CDD you already hold.
- Time has simply passed. Even with no obvious trigger, current guidance points to a periodic review being appropriate for higher-risk clients in particular, so identity documents and risk ratings don't quietly go stale.
How often, in practice
There's no single fixed interval written into how most small agencies should run this. What current guidance points to instead is a risk-based rhythm: higher-risk clients (foreign buyers, complex structures, cash-heavy transactions, PEPs) reviewed more frequently, standard-risk clients reviewed at longer intervals or simply re-checked whenever they transact again.
For a small agency, the practical version of this is usually simpler than it sounds. A returning client gets their record pulled up and reviewed rather than treated as brand new. A file that's been open and inactive for an extended period gets a second look before it's finally closed. Screening gets re-run rather than assumed to still hold from the original check.
What to record when you do a re-check
A re-check that isn't documented doesn't hold up as evidence you did it. Current guidance points to a re-check file note including:
- The date of the review and what triggered it
- What was checked (identity documents refreshed, ownership structure confirmed, screening re-run)
- What, if anything, changed since the last review
- The updated risk rating, if it changed
- Who did the review
This is the same record-keeping discipline that applies to the initial CDD file, just applied again at the point of re-check rather than only at onboarding.
What this looks like without a tool tracking it
Without something surfacing the trigger for you, ongoing CDD tends to rely on someone remembering. A principal recognising a returning client's name. A quick manual check against a sanctions list, run inconsistently because there's no prompt to do it. A spreadsheet column for "last reviewed" that nobody updates once the deal closes.
That's not a failure of understanding the rule. It's what happens when the tracking has to live in someone's memory across a busy week of listings, opens, and settlements. The obligation doesn't go away because nobody's watching for the trigger. It just goes unmet quietly, until a file gets pulled and the gap is visible.
How AML Simple handles re-checks, by plan
Every client you've verified in AML Simple stays in your client list with their verification date, risk rating, and screening history attached, so a returning client's record is there to pull up rather than buried in a closed folder. What happens next depends on your plan, and it's worth being specific about that rather than vague:
- Professional and Agency run automated re-screening on a schedule. You don't have to remember to re-run a sanctions or PEP check on an existing client. These tiers also include a higher monthly PEP check allowance (20 and 50 checks respectively) for new clients and re-checks alike.
- Starter re-screening is manual. Open the client record and there's a re-run button, plus a staleness prompt once a screening is more than 90 days old, telling you it's time to check again. Starter includes DFAT sanctions screening and 5 PEP checks a month included, with additional PEP checks at A$2 each.
- Foundation (free) includes DFAT sanctions screening for up to 5 clients, with no PEP screening at all. Ongoing monitoring is preview-only.
If you're on Starter and want re-checks to happen without a reminder rather than because of one, that's what Professional's automated re-screening is for. See plan details.
Ongoing CDD is the part of the AML/CTF Act 2006 regime that's easy to satisfy at the start and easy to lose track of afterward. Start your program with AML Simple and client records, including re-check triggers appropriate to your plan, stay live for as long as you're acting for that client, not just for the day you opened the file.