You can accept customer due diligence (CDD), the identification and verification of who you are dealing with, when another reporting entity has already performed it. You do not have to repeat the checks. A reporting entity is a person or business that provides a designated service, a service the AML/CTF Act 2006 (Cth) lists as carrying AML/CTF obligations. Acceptance is conditional, and the obligation never leaves you.
Accountants hit this question constantly. It usually surfaces three ways: a client tells you another firm set them up, another firm refers a client with the checks already done, or your practice inherits a client file from a predecessor. In each case the verification already exists, and the reliance provisions let you use it. The word to watch is “use”: it is conditional, and the conditions are precise.
From 1 July 2026, accountants providing the listed services are reporting entities, as are the other captured sectors. The Act calls the person seeking the service an applicant for a designated service. Reliance lets you treat CDD performed by another reporting entity as satisfying your own obligation, which means the work travels with the client rather than being repeated at each firm. See customer due diligence for what the checks involve when you run them yourself.
What reliance lets you do
The point of the provisions is practical: clients move between firms, and re-running the same verification every time would be pointless. The provisions let the work travel; they do not let the responsibility travel. Reliance transfers the verification work, not the obligation.
The reliance provisions sit inside the Act’s CDD framework. They were reformed by the AML/CTF Amendment Act 2024, and the detail that used to live in the old AML/CTF Rules now sits in the remade AML/CTF Rules 2025, with new numbering. Two mechanisms sit side by side and are worth keeping apart: s37 covers agent arrangements, where another party carries out the procedure on your behalf, and s38 covers the per-transaction request to verify, where you ask another reporting entity to confirm work it has already done.
The effect of a valid reliance is that the verification counts as done. You collect no identity documents and run no checks: the other entity’s CDD stands in for yours. What you keep is the record of the reliance itself: the agreement, the reviews, and the evidence you can call up when asked.
None of this is automatic. Four conditions have to hold, and each maps to something you can be asked to show:
| Requirement | What you must have | Consequence if missing |
|---|---|---|
| A counterpart you can rely on | Another reporting entity whose checks you can reasonably rely on | The reliance does not exist, and the CDD is treated as not performed |
| A written agreement | The arrangement documented in writing, covering what the other firm did and will do | AUSTRAC does not recognise the reliance; you face a breach for failing to conduct CDD |
| Periodic review | The agreement and the other firm’s reliability reviewed on a cycle you set | You keep relying on a firm that no longer meets the conditions |
| Access to the records | The underlying CDD records obtainable from the other firm on request | You cannot produce the evidence of verification when a reviewer asks |
The counterpart condition does the first part of the work. You rely on a firm you can reasonably rely on: the assessment is yours, and it covers whether the firm is enrolled and regulated, and whether its verification meets the standard you would apply to your own customer. If you know a firm does not run proper checks and you use it anyway, that is not reliance, it is a gap in your program. Record the basis for the assessment: a reviewer who sees “we assumed they were fine” will treat the reliance as unexamined. The foreign question sits here as well, because clients often arrive through an overseas parent or affiliate. Whether an overseas entity’s checks can be relied on is not something we can state confidently, and the answer will turn on the regime that entity operates under. Treat an overseas affiliate’s CDD as unverified until you have advice on the point.
The written agreement does the second part. In practice the document names the parties, the customers or classes of customers it covers, and what the other firm performed, so a reviewer can see the scope at a glance. On the s38 route there is also a clock: the other entity has a set window to return the data once you ask, and the period differs by sector, so confirm which applies to yours before you build a process around it.
The review keeps the arrangement honest. Set a cycle, annually as a starting point, and revisit it whenever the other firm’s circumstances change. The review asks whether the firm still meets the conditions, and whether the records access still works. The records condition makes the whole thing examinable: the access has to be real, so a request produces the underlying material, in a form you can read, within a reasonable time. If the other firm holds records it will not release, the access fails, and so does the reliance.
Reliance is also not outsourcing. The other firm is not your agent and does not act on your instructions: it performed its own CDD for its own purposes, and you are borrowing that work. When something goes wrong, that distinction matters, because you cannot describe the other firm as having acted for you.
Reliance only helps where the other entity actually performed the checks. If the other firm has not done CDD, there is nothing to rely on, and no arrangement changes that. The first question to ask about any candidate arrangement is whether the verification actually exists.
What catches people out
The liability does not transfer with the work. Firms describe reliance as “they did the CDD, so it is their problem”. The reporting entity is you, and AUSTRAC holds the reporting entity responsible. If the other firm verified the wrong person, or accepted a document without checking it, the breach is yours to answer for, and the arrangement does not change that. A referral is the classic case: the referring firm verified the client, you relied on that verification, and a year later it emerges the identity documents were never checked against anything. The failure is yours either way, because you are the reporting entity that provided the service. Your other duties survive as well: if you later form a suspicion about the client, you still lodge a suspicious matter report (SMR) within three business days, under s41(2). Reliance covers identification and verification, and nothing else: not ongoing monitoring of the customer, and not your reporting duties.
A handshake is not an arrangement. Reliance has to be documented in a written agreement, and the arrangement has to be reviewed periodically. Skip the writing and the reliance does not exist for AUSTRAC’s purposes, which leaves you in the position of having performed no CDD at all. Skip the review and you keep relying on a firm long after its circumstances changed, because it merged, or because it stopped providing the service that made it a reporting entity. Review on a cycle, and keep the review on record.
A confirmation is not the records. The condition is that you can obtain the underlying CDD records from the other firm on request. A letter that says “we performed the checks” is not the record: the identity documents and the source checks, with the dates they were done. When a reviewer asks, you hand over the underlying material, promptly. If the other firm will not release it, or has not kept it, the gap is yours, not theirs. Test the access before you need it, not while a review is already running. The record of your decision to rely, and the reasoning behind it, is your own record: it shows a reviewer that you checked the conditions before relying. Records are retained for seven years, and the record of a reliance decision sits inside that obligation: see record-keeping.
What is still unsettled
The reliance provisions were reformed by the AML/CTF Amendment Act 2024, and the rules carrying the detail were remade as the AML/CTF Rules 2025 with new numbering. The old rule numbers no longer exist, so guidance written before the reform cites provisions you cannot find. The exact requirements in their current form are being confirmed against the Act and the remade Rules; until that confirmation lands, treat the specific conditions on this page as provisional and check AUSTRAC’s current guidance before acting on them. If you already rely on another firm today, confirm that the arrangement satisfies the current requirements rather than assuming the old one carries over. When you read AUSTRAC guidance on reliance, check its publication date, because material written before the reform cites provisions that no longer exist.
Where to start
If you have clients whose checks were done elsewhere, three steps do most of the work:
- Find where reliance already happens: go through your live client relationships and mark the ones where another firm performed the verification: companies and trusts established elsewhere, and clients referred by other firms. Each one is a candidate arrangement.
- Put each arrangement in writing: for every candidate, agree the reliance in a written document that covers what the other firm did and the records access, and have your AML/CTF compliance officer (the AMLCO) review it against the conditions above.
- Test the records access: choose one client and ask the other firm for the underlying CDD records. See how long it takes and what you actually receive. If you cannot get the material, do the CDD yourself.
How duely handles this
Reliance partners live in a registry rather than in a folder of PDFs. The agreement has a lifecycle with a generated document, periodic review and expiry jobs, and each matter that relies on a partner’s work records the approval and the reasoning behind it. The s38 route has its own form for asking another reporting entity to verify, with the deadline and the signatures recorded, so the request and the response are both on file rather than in an inbox.