AUSTRAC expects AFS licensees to conduct ongoing customer due diligence by monitoring customer behaviour, updating customer information, and reassessing risk over time using transaction, device, and behavioural signals. Effective OCDD ensures customer activity remains consistent with the expected risk profile and triggers escalation where anomalies arise.
Expanded Answer
AUSTRAC expects reporting entities to maintain ongoing customer due diligence processes that keep customer information up to date and monitor for changes in risk. This includes periodic review of customer details and continuous monitoring of transactions and behaviour. ASIC similarly expects AFS licensees to maintain systems that detect misconduct and respond to emerging risks, including those that develop after onboarding.
In practice, OCDD combines periodic KYC refresh (based on risk rating), transaction monitoring, and behavioural monitoring. These controls should be informed by fraud signals such as sudden changes in device or geographic location, multiple accounts accessed from the same device, velocity anomalies (such as rapid spikes in activity), and unusual session behaviour. These indicators may suggest account takeover, identity misuse, or emerging fraud patterns that were not evident at onboarding.
Risk increases where customer behaviour diverges from the established profile without explanation, particularly when multiple signals occur together. AFS licensees should escalate these cases through enhanced due diligence, account restrictions, or suspicious matter reporting where appropriate. A signals-based monitoring approach aligns with ASIC expectations for continuous surveillance and is explored in From samples to signals: a smarter approach to AFSL surveillance and broader data-driven compliance practices in The role of data in improving compliance and business performance.
Why it matters
Failure to monitor ongoing customer behaviour increases exposure to account takeover, fraud, and AML/CTF breaches. Regulators assess whether AFS licensees can detect changes in risk over time, not just at onboarding, and whether monitoring systems respond appropriately to anomalies.
Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call.
Practical guidance
- Implement risk-based KYC refresh cycles aligned to customer risk ratings
- Monitor behavioural and transaction signals continuously to detect deviations from expected activity
- Escalate anomalies where multiple signals indicate increased risk or potential fraud
Further reading