What Personnel Due Diligence actually requires under Tranche 2 – and why most businesses haven't done it yet
This content is general in nature and provided for educational purposes only. It is not legal or compliance advice and does not take into account your organisation's specific circumstances. It does not certify compliance with any law or regulation. Before acting on this information, you should seek advice from a qualified professional.
Last updated 18 September 2026
Most newly regulated businesses that enrolled with AUSTRAC this year have done the hard work. They've mapped their designated services, appointed a Compliance Officer, rolled out training, and documented their AML/CTF program.
Then they stopped.
Not because they're careless. Because training feels like the finish line. It's the most visible obligation, the one with the clearest deliverable. Complete it, record it, done.
But AUSTRAC's guidance makes clear that training and Personnel Due Diligence are two separate components of your program. Completing one does not satisfy the other.
So what does Personnel Due Diligence actually require?
In practice, PDD means identifying the roles that require due diligence, assessing whether the people performing those roles have the skills, knowledge, expertise and integrity required, applying checks proportionate to the role and its risk, and keeping records of the assessments and decisions.
It starts with your roles, not your people
The first step isn't running checks on anyone. It's working out which roles in your business carry AML/CTF functions, and therefore require due diligence.
AUSTRAC's guidance describes this as mapping the roles in your business that perform AML/CTF-related work, then identifying which of those carry higher risk. A partner managing trust structures carries different risk to a receptionist. A Compliance Officer carries different risk again. Your PDD process needs to reflect that distinction.
For many newly regulated businesses, this is where the gap sits. They've trained everyone and assumed that's enough. It isn't.
It applies to everyone in those roles - not just new hires
This is the part that catches most businesses off guard.
AUSTRAC's guidance is explicit on this point. For newly regulated entities, the expectation is that due diligence checks are conducted on current personnel in designated roles, not just new hires going forward. That means reviewing what checks have already been conducted, identifying gaps, and updating or completing checks where needed.
If your business enrolled earlier this year and hasn't yet assessed the people already sitting in those roles, it's worth addressing that gap now.
Personnel Due Diligence also applies when someone is promoted into a higher-risk position, or when a role changes in a way that increases exposure. It's an ongoing obligation, not a one-time exercise.
The checks need to be proportionate to the risk
AUSTRAC's guidance doesn't prescribe a single list of checks that applies to every role in every business. It expects a risk-based approach, which means the depth of your due diligence should reflect the risk level of the role.
For standard roles, that might mean reference checks, a self-disclosure declaration, and verification of relevant qualifications. For higher-risk roles (those managing trust structures, handling high-value transactions, or interacting with international clients), AUSTRAC's good practice examples include police checks, adverse media screening, bankruptcy checks, and ASIC directorship searches.
The key point: your policies need to define what applies to which roles, and why.
"We ran a reference check" is not a PDD framework. It's one check, applied without a documented rationale.
Records matter as much as the checks themselves
AUSTRAC's published examples of good practice are specific on this point. A well-run PDD process includes clear records of the checks conducted, any adverse findings, and an audit trail of the decisions made for each person.
That last part is important. If a check comes back with something concerning and you make a decision to proceed, the reasoning behind that decision needs to be documented.
Not because AUSTRAC expects perfection (their published regulatory expectations are explicit that they don't), but because an undocumented decision is indistinguishable from no decision at all.
What poor practice looks like in the real world
AUSTRAC's guidance includes a case study of a business that had AML/CTF personnel due diligence and training policies in place, but applied a generic process regardless of the risks and responsibilities associated with individual roles.
The business mapped the roles requiring due diligence but didn't identify higher-risk roles or tailor its checks accordingly. As a result, it relied on interviews, reference checks and a standard self-attestation for all new hires, without conducting additional background or criminal history checks for higher-risk personnel.
The business subsequently discovered that a personnel member with previous adverse media links to a criminal organisation had been hired. That person had processed a series of suspicious transactions linked to suspected money laundering activity.
The business had policies. It just hadn't built a functioning, risk-based process behind them.
The gap most businesses have
Training helps your people understand their AML/CTF responsibilities. Personnel Due Diligence is about making sure the people carrying them out are suitable to do so.
Many businesses have completed training without yet building the second into a documented, repeatable, risk-based process with records that would hold up under scrutiny.
That's not a criticism. The obligation is new, the guidance is detailed, and the operational reality of turning a regulatory requirement into a day-to-day business process is harder than it looks on paper.
But the gap is real, and AUSTRAC has been clear that, during the implementation of the reforms, it will consider whether businesses have made genuine efforts to meet their obligations, not simply whether the training register is complete.
If you're not sure where your business sits on this, that's the right question to be asking.
Want to see what a proportionate, risk-based PDD process looks like for your business?
See how Clearhouse approaches Personnel Due Diligence →
Or skip straight to a conversation.
Book a complimentary 15-minute conversation →