What do we need to do about our existing clients on 1 July 2026?
Consider if any current active clients/matters require a new CDD.
Practically, how do I handle existing clients after 1 July?
The short answer is you generally don’t have an immediate need to re-verify or conduct new customer due diligence on your existing clients.
Existing clients are known as pre-commencement customers, do not have to be automatically re-verified (conduct CDD), particularly if you have a transactional relationship with the client such as real estate agents or conveyancers/property lawyers.
If you have begun providing a transactional service and you have completed your client onboarding process prior to 1 July 2026 however the service is being delivered/completed/settled after 1 July you generally don't have to do anything further eg a property settling after 1 July when the contract of sale or settlement process started prior to 1 July.
For ongoing relational services such as with accounting or legal firms where you have completed your client onboarding process prior to 1 July 2026, you generally don't have an immediate need to re-verify (conduct CDD) however you can have ongoing CDD obligations over time, which are covered below.
In all cases, you have immediate CDD obligations if a suspicion is formed or the business relationship or service you're providing changes after 1 July. These are covered in detail below.
What is a pre-commencement customer?
Anyone the firm was in a business relationship with on 1 July 2026 for a designated service.
What's NOT required
Firms do not have to perform initial CDD on every existing client on 1 July 2026. They can continue providing services to pre-commencement customers without doing initial CDD, subject to the obligations below.
"Pre-commencement" is not a "do nothing" status - and this is the single biggest source of confusion about meeting your AML obligations.
What IS still required - ongoing obligations
Even for pre-commencement customers, the firm must:
- Monitor for unusual activity - transactional and behavioural monitoring still applies.
- Keep KYC information current - existing identity, ownership and risk data must be maintained.
- Watch for changes in the customer's risk profile - new PEP exposure, sanctions hits, beneficial ownership changes, jurisdictional shifts.
- Review customers on an ongoing basis. AUSTRAC prescribes (as per starter kits) a risk-tiered 1 - 3 year periodic review cadence.
- The pre-commencement carve-out removes the initial CDD obligation; it does not remove the obligation to keep reviewing each customer over the life of the relationship.
The two triggers that end pre-commencement status
In practice this means a customer must stop being treated as "pre-commencement" - and full initial CDD becomes mandatory - the moment one of these fires:
- A suspicion is formed about the customer (an SMR obligation arises), OR
- The business relationship significantly changes or the client asks for a different designated service and/or ML/TF risk becomes medium or high.
A firm can only rely on the carve-out if it is doing enough monitoring and periodic review to know whether one of those triggers has fired. Your business will need to build processes to manage this risk if you don't fully onboard a customer through a proper initial CDD process.
Related articles
- Pre-commencement customers - what CDD obligations apply, and the risks of not completing initial CDD
- What additional AML readiness considerations apply to medium and large firms?
- What operational tasks does my business need to do beyond setting up easyAML?
- Who in my business needs to make decisions before we can start preparing for AML/CTF?
- What external parties do we need to engage for AML/CTF readiness?