Blog

Tranche 2

How Automated Due Diligence Simplifies Tranche 2 Compliance

Why manual customer due diligence doesn't scale under Tranche 2, and what automated CDD actually needs to cover.

Tranche 2 extends Australia's AML/CTF regime to legal, accounting, and real estate businesses, and customer due diligence sits at the core of what they now have to do — identifying and verifying clients, assessing risk, and monitoring for suspicious behaviour. Manual processes built for occasional compliance checks generally can't keep pace with what Tranche 2 actually expects.

What does CDD require under Tranche 2 specifically?

The same foundation as any effective AML programme: verifying the customer's identity, understanding the purpose and nature of the business relationship, assessing their money-laundering or terrorism-financing risk, and conducting ongoing monitoring and review. The distinction Tranche 2 makes explicit is that these aren't one-off tasks completed at onboarding and then forgotten — they're continuing responsibilities that have to be carried out consistently for the life of the relationship.

Why does manual CDD stop working at this point?

Because consistency and speed both degrade as volume grows. A small legal or accounting practice reviewing a handful of new clients a month can do it carefully by hand; the same practice at ten times the client base, held to the same continuing-review standard, either has to grow its compliance headcount proportionally or start cutting corners. Automated CDD solves this by using technology to verify identity, run risk assessments, and flag inconsistencies in real time rather than in a weekly batch review.

What are the concrete benefits of automating this?

Speed and accuracy — instant identity verification and KYC checks cut onboarding time while improving accuracy over manual review. Consistent risk assessment — standardised workflows mean every client is assessed against the same criteria, not whichever analyst happened to review them. Real-time alerts when a customer's status changes, such as appearing on a sanctions or PEP list after onboarding. Audit readiness, since all activity is logged and retrievable rather than reconstructed from memory when a regulator asks. And scalability — the same system handles everything from basic due diligence to enhanced due diligence for higher-risk clients without needing proportionally more staff.

What should a business actually look for in a CDD automation tool?

Seamless integration with existing systems, rather than a standalone tool that creates its own data silo. Comprehensive KYC data coverage across the jurisdictions the business actually serves. Automated document verification paired with biometric checks. Continuous screening against global watchlists and adverse media, not a point-in-time check. And customisable rules for client risk scoring, since a firm's own risk model — informed by its specific client base and services — should drive the scoring, not a fixed vendor default. Manual processes are no longer sufficient once continuing due diligence is a legal expectation rather than good practice, and CDD automation is the practical foundation the rest of a Tranche 2 compliance programme gets built on top of.

FAQ

Common questions.

What is customer due diligence under Tranche 2?
Verifying a customer's identity, understanding the purpose and nature of the business relationship, assessing money laundering or terrorism financing risk, and conducting ongoing monitoring and review — as a continuing responsibility, not a one-off onboarding step.
Why does manual CDD struggle to meet Tranche 2 expectations?
Manual review doesn't scale consistently across a growing client base, and Tranche 2 treats due diligence as an ongoing responsibility rather than a single onboarding task, which compounds the workload over time.
What should an automated CDD tool actually provide?
Integration with existing systems, comprehensive KYC data coverage, automated document verification and biometric checks, continuous screening against global watchlists and adverse media, and customisable client risk scoring.
Does automating CDD remove the need for compliance staff judgement?
No — automation handles the verification, screening, and consistency work at scale, but risk decisions on genuinely flagged cases still need a trained person to assess them.

See MemberCheck against your own risk data.

Book a walkthrough with our compliance team and screen a real case in the first session.