The key obligation is to meet the legal requirements for customer identification, verification, and due diligence under the relevant Australian AML and compliance framework. Teams should also account for non-face-to-face onboarding rules and keep evidence that their controls are applied consistently. Good programmes align policy, operational checks, and audit trails so decisions are defensible.
Why This Matters for Security Teams
In Australia, customer due diligence is not just a compliance checkbox. It is the control that proves an organisation knows who it is onboarding, why the relationship is acceptable, and whether the evidence supports a defensible decision. That matters most where onboarding is digital, high volume, or partially automated, because weak identity proofing and poor recordkeeping become audit findings quickly. The regulatory expectation is to show consistent application, not ad hoc judgment, and to retain evidence that can survive challenge under AML and KYC review.
For security and risk teams, the practical issue is that due diligence spans policy, verification tooling, escalation paths, and exception handling. The strongest programmes map operational controls to the obligations described in the NIST Cybersecurity Framework 2.0 while keeping a clear regulatory narrative for auditors. NHIMG’s Ultimate Guide to NHIs, Regulatory and Audit Perspectives is especially relevant because it shows how evidence, lifecycle discipline, and governance need to line up when controls are reviewed after the fact. In practice, many security teams discover due diligence gaps only after a remediation request or audit query has already exposed inconsistent onboarding decisions.
How It Works in Practice
Customer due diligence in Australia typically means the organisation must identify the customer, verify that identity using acceptable evidence, understand the nature and purpose of the relationship, and apply enhanced checks when risk is higher. The exact legal tests depend on the applicable AML regime and the customer type, but the operational pattern is consistent: risk-based intake, evidence capture, screening, decisioning, and retention. Current guidance suggests that teams should treat this as a controlled workflow rather than a one-time form submission.
A practical implementation usually includes:
- Identity proofing rules for individuals and entities, including beneficial ownership where relevant.
- Non-face-to-face onboarding controls, such as document verification, liveness checks, or trusted data-source validation.
- Risk scoring that determines when standard due diligence is enough and when enhanced due diligence is required.
- Immutable audit trails showing what was checked, when, by whom, and under which policy version.
- Exception handling for failed verification, mismatched data, sanctions hits, or manual approval.
For control design, the FATF Recommendations remain the clearest international reference point for risk-based AML expectations, while NIST SP 800-53 Rev. 5 is useful for translating those expectations into access, logging, integrity, and accountability controls. NHIMG’s Lifecycle Processes for Managing NHIs is also helpful because due diligence programmes fail in the same way many identity programmes fail: controls exist, but lifecycle ownership, review cadence, and evidence retention are weak. These controls tend to break down when onboarding is outsourced across multiple systems because the organisation cannot prove a single, consistent due diligence decision path.
Common Variations and Edge Cases
Tighter due diligence often increases friction and manual review cost, so organisations must balance customer experience against the regulatory risk of getting identity wrong. That tradeoff is especially visible in higher-risk customers, foreign documents, and complex corporate structures, where automated verification alone may not be sufficient. There is no universal standard for every scenario, so best practice is evolving toward risk-based rules that are documented, repeatable, and easy to evidence.
One common edge case is non-face-to-face onboarding, where the organisation cannot rely on physical presence or in-person checks. Another is beneficial ownership, where the customer may be a legal entity but the real risk sits behind layered control or nominee arrangements. A third is periodic review, where initial acceptance is not enough and the risk profile can change over time. NHIMG’s Top 10 NHI Issues reinforces a broader lesson that applies here too: governance fails when evidence, ownership, and review are not maintained as an operating discipline. Teams should also note that regulatory obligations can differ by product, sector, and customer geography, so legal interpretation should be maintained alongside the control framework rather than bolted on later.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | Identity proofing and access assurance support defensible customer due diligence. |
| NIST SP 800-63 | IAL2 | Customer verification strength maps to digital identity assurance requirements. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Poor lifecycle governance causes weak evidence and inconsistent due diligence controls. |
| NIST AI RMF | Risk governance is central where automated due diligence decisions affect compliance. |
Tie onboarding checks to PR.AA-01 and document how identity evidence is verified before account activation.
Related resources from NHI Mgmt Group
- What breaks when customer due diligence is too light for South African regulatory obligations?
- Who is accountable when customer verification and due diligence controls are not aligned to local law?
- What breaks when customer verification and due diligence are not aligned to Thailand regulatory expectations?
- Who is accountable when non face to face customer due diligence does not meet regulatory requirements?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org