By Fiona Halsey
When the anti-money laundering and counter-terrorism financing (AML CTF) obligations began to apply to law firms, the concept of simplified initial client due diligence (ICDD) was, for many practitioners, largely theoretical. It was part of the legislation as a permitted measure, but it initially appeared to have limited application.
In the period up until 1 July 2026, firms were extremely busy simply implementing systems, appointing people to roles, and organising training.
Our initial thoughts were that the breakdown of clients in terms of the type of ICDD would likely be simplified ICDD 10%, standard ICDD 80%, and enhanced ICDD 10%.
Now that firms have been undertaking ICDD for some time, a clearer picture has emerged. One of the most significant lessons is this: a greater proportion of clients are eligible for simplified ICDD than was previously assumed. It seems likely that for most practices it could be something more in the order of simplified ICDD 80%, standard ICDD 10%, and enhanced ICDD 10%.
Simplified ICDD presents an excellent opportunity to reduce client friction, firm costs, and staff frustration.
The statutory framework
The availability of simplified customer due diligence is governed by section 31 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).
A reporting entity may apply simplified customer due diligence measures if three conditions are satisfied:
- the money laundering or terrorism financing (ML/TF) risk of the customer is low;
- section 32 does not apply to the customer (enhanced CDD); and
- the reporting entity complies with the requirements specified in the AML/CTF Rules.
Section 32, in turn, sets out the circumstances that trigger the enhanced customer due diligence obligation. Enhanced measures must be applied where:
- the ML/TF risk of the customer is high;
- a suspicious matter reporting obligation arises and the firm proposes to continue providing a designated service;
- the customer, a beneficial owner, a person on whose behalf the service is received, or a person acting on the customer’s behalf is a foreign politically exposed person;
- any such person is physically present in, or is a body corporate or legal arrangement formed in, a high-risk jurisdiction for which the Financial Action Task Force has called for enhanced due diligence;
- the designated service is provided as part of a nested services relationship (unlikely for law firms); or
- the customer is of a kind specified in the Rules.
The requirements in the Rules (in summary) are that:
- section 31 of the Act permits ICDD in relation to the customer;
- if the customer is an individual, the firm has taken steps to establish that the customer is who they claim to be;
- the firm has identified the money laundering/terrorism financing risk of the customer based on reasonably available know your client (KYC) information;
- the firm has collected KYC information appropriate to the risk of the customer;
- there are no reasonable grounds for the firm to doubt the adequacy or veracity of that KYC information; and
- the AML/CTF policy of the firm allows simplified ICDD.
The structure of these provisions is instructive. Simplified ICDD is not a narrow exception carved out for a small category of clients. Rather, it is available whenever a client presents a low ML/TF risk after a reasonable amount of information is collected and analysed, none of the enhanced due diligence triggers in section 32 is engaged, and the firm policy allows it.
The threshold, properly understood, is defined as much by the absence of high-risk features as by the presence of positive low-risk indicators.
When is a client low risk?
All reporting entities are required to have a risk assessment for their firm, and carry out a risk assessment for every client who receives a designated service.
AUSTRAC has helpfully created starter packs, and within those starter packs are questionnaires to assess client risk. We acknowledge that not all firms can rely upon the starter packs, however many can, and the starter pack assessment questionnaires are a helpful base. We find in practice that when the questionnaire is completed for a client, the vast majority are low risk. The client risk rating suggested within the starter pack is:
- High – if you’ve answered YES to at least one high risk factor or there are other reasons that suggest the client is high ML/TF risk.
- Medium – if you’ve answered YES to at least two medium risk factors or the information you have otherwise warrants this rating.
- Low – where a high or medium risk rating isn’t warranted.
From this, we conclude that in many situations, where there’s only 1 medium risk rated answer and the remainder of answers are low risk, the client is likely low risk, and simplified ICDD can be used. The position is even clearer when AUSTRAC’s explanatory notes are included.
Indeed, our experience suggests that if the client risk assessment questions in the AUSTRAC starter pack are answered carefully and conscientiously, around 80 to 90 per cent of clients will be assessed as low risk. That is a striking figure, and it reinforces the central point: simplified ICDD is not the exception but, for many firms, the norm.
The critical qualification is that the assessment must be undertaken with genuine care. A rushed or superficial response to the risk assessment questions will not produce a reliable outcome, and firms should ensure that those completing the assessment understand both the questions and their significance.
Reduced friction and reduced verification
The advantages of applying simplified ICDD where it is properly available are not merely theoretical. In a practical sense, simplified measures can dramatically reduce the verification requirements that would otherwise apply.
Rather than gathering and independently verifying an extensive body of identification and supporting material, firms can adopt a proportionate approach commensurate with the low risk presented. This translates directly into time and cost savings for the firm.
Equally important is the reduction in client friction. The commencement of a client relationship is a critical juncture. A client who is met at the outset with burdensome, seemingly disproportionate information demands may form an unfavourable early impression, or may be deterred altogether.
For low-risk clients, an onboarding process that is efficient and unobtrusive supports the commercial relationship without compromising the firm’s compliance obligations. Reducing friction at this early stage, where first impressions are formed, is of particular value. In saying this, we do not suggest in any way that slapdash ICDD should be carried out to please customers.
Applying standard or enhanced measures to clients who properly qualify for simplified ICDD imposes unnecessary cost, delay and friction, both on the firm and on the client, without producing any commensurate improvement in the firm’s control of ML/TF risk. Over-application is not a neutral or conservative choice; it diverts finite compliance resources away from the clients and matters that genuinely warrant closer scrutiny.
A practical caveat: does the software support it?
One practical question that firms should not overlook is whether their chosen compliance software actually accommodates a simplified ICDD workflow. Not all providers’ systems are built to reflect the distinction between simplified, standard and enhanced measures, and some default to a single, more onerous verification pathway regardless of the assessed risk.
If the software does not allow simplified ICDD to be applied where it is available, the firm risks losing the very efficiencies that the legislation permits. Firms would be well advised to interrogate their systems on this point and, where necessary, to raise it with their providers.
We have anecdotally heard that some software suppliers have imposed, without consultation with their firm clients, an amount which they deem to be a high value transaction, and that this amount is imposed upon all transactions as part of the assessment of risk. This seems to us to be questionable practice.
What is high value for one client or sector is not necessarily high value for other clients or sectors, and it could wrongly cause a client to be classified with an incorrect risk classification.
Potential disadvantage of simplified ICDD
The nature of all ICDD is that a base line of information is collected and then a risk assessment is made of the client. At that point, if the client is determined to have for example a medium risk rating such that standard ICDD must be undertaken, it is likely to be necessary to undertake further work, and to ask further questions of the client. This could cause somewhat more back-and-forth interaction with the client.
Some firms may decide it’s best to do all of that up front before the risk assessment (i.e. do more work for all clients based on having a standard process). We think that based upon the likely proportion of clients as low risk it would be better to undertake less work for most clients, but this is genuinely a position where a firm’s own experience will prevail.
A risk-based, evidence-informed approach
None of this is an invitation to relax vigilance. Simplified ICDD remains a form of due diligence, not an absence of it. The assessment of low risk must be genuine, documented and consistent with the firm’s AML/CTF program, and firms must continue to monitor for any change in circumstances that would engage section 32.
Firms would be well served by revisiting their client risk assessment methodologies in light of operational experience.
One possibility could be that where evidence demonstrates that a client category consistently presents low risk and falls outside section 32, the sensible course is to recognise that category as eligible for simplified ICDD. Doing so is not only permissible under the Act; it is the appropriate application of a truly risk-based framework, and it allows firms to focus their resources where the risk genuinely lies.