How to verify every beneficial owner behind a layered trust with offshore owners under Australia's AML/CTF Act: who counts, evidence, ECDD triggers, example.
Table of contents
- Under Australia's AML/CTF Act a beneficial owner is an individual who directly or indirectly owns 25 percent or more of the customer or otherwise controls it. For a trust, AUSTRAC's guidance adds every individual trustee, the beneficial owners of any corporate trustee, and the settlors, appointors, guardians, protectors and other controlling individuals.
- The chain must be followed to the end. Where a trust is controlled by a company owned by another company, the reporting entity keeps going until it reaches the individuals who ultimately own or control the customer, and it records how each identity was established on reasonable grounds.
- Offshore layers change the evidence, not the duty. Foreign registers vary from fully public to closed, a foreign trust may have no register at all, and a person located or formed in a jurisdiction on the FATF's call-for-action list triggers mandatory enhanced customer due diligence.
- AUSTRAC's National Money Laundering Risk Assessment 2024 rated trusts a high national money laundering risk and named their poor transparency as one of Australia's key vulnerabilities, which is why the trust guidance is the most demanding of the customer-type guides.
- Every price list in the Australian market marks a multi-tier structure with offshore owners as bespoke. The worked example in this guide, a discretionary trust with a corporate trustee, two intermediate companies and two offshore individuals, shows the steps, the evidence at each layer and what to document when a branch cannot be resolved.
- The workable model is ownership discovery that runs through every available tier, shows truncated and unresolved branches rather than hiding them, and then verifies each beneficial owner as a person, without keeping a database of their passports.
A beneficial owner is an individual who directly or indirectly owns 25 percent or more of a customer, or who otherwise controls it, and for a trust includes its trustees, settlors, appointors, protectors and other controlling individuals. Australian reporting entities must identify each one on reasonable grounds before the service starts, following ownership through every layer to an individual.
TL;DR
A beneficial owner of a trust is not one person but a set: every trustee, the individuals behind a corporate trustee, the settlor, the appointor and anyone else who controls the trust, plus the beneficiaries as the people on whose behalf the service is received. Australian reporting entities must follow ownership through every company and trust in the chain until they reach individuals, verify at least one piece of information for each, apply enhanced customer due diligence when a layer sits in a listed jurisdiction or the structure is unusually complex, and document every branch they could not finish. The worked example below runs a four-layer structure with two offshore owners through those steps.
What is a beneficial owner under the AML/CTF Act, and why do trusts complicate it?
AUSTRAC's overview of initial customer due diligence gives the working definition: a beneficial owner is an individual who directly or indirectly ultimately owns 25 percent or more of the customer, or otherwise controls the customer. A customer may have more than one, and sometimes has none. The obligation is to establish each beneficial owner's identity on reasonable grounds before the designated service starts, alongside the customer's own identity, any person acting on its behalf, any person on whose behalf it receives the service, whether any of them is a politically exposed person or designated for targeted financial sanctions, and the nature and purpose of the relationship.
Companies make this a calculation. Trusts make it an investigation, for two reasons. First, a trust has no owners in the company sense; control and benefit are split across roles created by the deed, and the deed can be varied. Second, trusts are the vehicle AUSTRAC worries about most. Its trust guidance cites the National Money Laundering Risk Assessment 2024, which rated trusts a high national money laundering risk and identified their poor transparency as one of Australia's key vulnerabilities to criminal exploitation. The regulator is careful to add that a nationally high-risk structure is not automatically a high-risk customer; the reporting entity still rates each trust on its own facts. But the identification duty is wide by design.
This guide sits alongside our general entry on the ultimate beneficial owner and the tranche 2 obligations for trust and company service providers, the firms that build these structures for a living.
Who must be identified when the customer is a trust?
AUSTRAC's initial CDD guide for trusts lists the matters to establish. Translated into people, a trust customer produces four groups.
| Group | Who it includes | Why the Act treats them as relevant |
|---|---|---|
| Beneficial owners | All individual trustees; the beneficial owners of any corporate trustee; settlors; appointors; guardians; protectors; any other individual with control, and in some cases beneficiaries | They own or control the trust, directly or through the roles the deed creates |
| Persons acting on behalf of the customer | Every trustee, and any other representative who deals with the reporting entity | They exercise the trust's powers and must have authority to act |
| Persons on whose behalf the service is received | All beneficiaries, or each class of beneficiaries where they cannot be individually named | They are who the service ultimately benefits |
| Governance individuals | Those with primary responsibility for governance and executive decisions: typically all trustees, appointors, guardians and protectors, the board of a corporate trustee, or the beneficiaries of a bare trust | Their identity is part of the trust's own identity |
Three points from the guidance decide the workload. A corporate trustee is not a beneficial owner; its own beneficial owners are, so the trustee company has to be unwrapped like any other customer. A settlor who contributed the trust property is identified even where they have no ongoing role. And beneficiaries of a discretionary trust are identified as a class where the deed defines them that way, with the reporting entity collecting enough about the class to know who could benefit.
How do you work through layers of companies and trusts?
The guidance's own example is the method: your customer is a trust; a company controls the trust; if the company's owner is an individual, establish their identity; if the owner is not an individual, keep following the chain of ownership until you find the individuals who ultimately own or control the customer. Four rules make that mechanical.
- Multiply along each link. A person holding 50 percent of a company that owns 60 percent of the customer holds 30 percent indirectly and is a beneficial owner. Percentages compound; they do not reset at each layer.
- Aggregate across branches. The same individual can appear at the end of two chains. Their holdings add up before the 25 percent test is applied.
- Apply the control test independently. A person below 25 percent, or with no equity at all, is a beneficial owner if they otherwise control the customer: an appointor who can remove the trustee, a protector with a veto, a director whose consent a corporate trustee needs, a nominee arrangement where the nominee acts on someone else's instructions.
- Look through nominees and trustees. A nominee shareholder of record is not the beneficial owner; the person they hold for is. A corporate trustee's shareholders and controllers are examined as if the trustee were the customer.
Nothing in the chain is taken from the customer's word alone. A customer-supplied ownership chart tells you where to look; register extracts, share registers, trust deeds and constitutions are what establish each link on reasonable grounds.
What changes when an owner or a layer is offshore?
The duty is the same. The evidence, the risk rating and sometimes the mandatory measures change.
Evidence. Australian companies sit on the ASIC register and Australian trusts carrying on business have an ABN on the Australian Business Register, which AUSTRAC names as reliable and independent data. A foreign company sits on its home register, which may be fully public with shareholder data (Singapore's ACRA, the UK's Companies House with its people with significant control register), partially public (many EU registers now restrict beneficial ownership access following the 2022 Court of Justice ruling), or closed (several offshore financial centres keep ownership registers accessible only to authorities). A foreign trust may have no register at all. AUSTRAC's trust guidance accepts information about foreign trusts from a foreign registration body where one exists, and letters from independent professional advisers as an alternative source.
Risk rating. Jurisdiction is a standard risk factor, and a layer in a secrecy jurisdiction with no reason connected to the customer's business pushes the customer's ML/TF risk up. The reporting entity's own policies decide the weighting, but the rating has to be recorded and the file has to show it was applied.
Mandatory enhanced measures. Under AUSTRAC's enhanced customer due diligence guidance, enhanced CDD is compulsory where the customer, any beneficial owner, any person acting for the customer or any person on whose behalf the service is received is physically present in or formed in a jurisdiction the FATF has called for enhanced due diligence on, or is a foreign politically exposed person. An offshore beneficial owner in a listed jurisdiction is not a judgement call; it is a trigger.
What evidence establishes each beneficial owner on reasonable grounds?
Reasonable grounds is an objective test: a reasonable person with the same material, knowledge and training would reach the same conclusion. AUSTRAC expects at least one piece of KYC information to be verified against reliable and independent data for each matter, more for higher-risk customers, and more again for the people associated with a high-risk customer, such as a beneficial owner.
| Layer | What establishes the link | Sources AUSTRAC treats as reliable and independent |
|---|---|---|
| The trust | Existence, kind, governing powers, governance individuals | Trust deed and deeds of variation; ABN on the Australian Business Register; letters from an independent professional adviser to the trust |
| A corporate trustee or intermediate company | Existence, status, directors, shareholders | Company register extract (ASIC or the foreign equivalent), share register, constitution |
| A foreign entity | Existence, status, ownership where the register discloses it | The foreign registration body; where ownership is not public, certified documents from the entity and independent professional letters |
| An individual beneficial owner | Identity | Government identity document with a liveness check, or a digital identity service whose data is independent and reliable |
| Control without ownership | The power itself | The clause of the deed, constitution or agreement that creates the power |
AUSTRAC also notes that copies of documents need not be retained; recording their details satisfies the record keeping duty. That matters more for offshore structures than domestic ones, because the file for a four-layer trust otherwise becomes a repository of passports from three countries.
When does the structure trigger enhanced customer due diligence?
Beyond the two mandatory offshore triggers above, a layered trust meets the enhanced CDD conditions in AUSTRAC's guidance in three other ways that are common in practice: the customer's ML/TF risk is assessed as high, the requested service involves transactions that are unusually complex or have no apparent economic or legal purpose, or the reporting entity forms a suspicion and must submit a suspicious matter report while intending to continue the relationship.
The measures must fit the reason. For a structure whose complexity is the concern, AUSTRAC's list points to obtaining the reason for the structure and for particular transactions, collecting and verifying the source of funds and source of wealth of the customer and its beneficial owners, taking additional steps to understand the background and financial situation of the parties, monitoring more closely, reviewing more often, and escalating to senior management. It also states that enhanced CDD includes taking active steps, up to declining the service where it falls outside the firm's risk appetite, rather than monitoring alone. Our general guide to enhanced due diligence covers the CDD-to-EDD boundary in more depth.
Worked example: a four-layer trust with two offshore owners
The customer is the Harbourline Discretionary Trust, an Australian trust seeking a designated service. Its trustee is Harbourline Nominees Pty Ltd, an Australian company. Harbourline Nominees is owned 60 percent by Meridian Holdings Pte Ltd, a Singapore company, and 40 percent by Coral Reef Ventures Ltd, a company in the British Virgin Islands. Meridian Holdings is wholly owned by an individual, A, resident in Singapore. Coral Reef Ventures is owned equally by two individuals, B and C, both resident in a third country. The deed names an Australian resident, D, as appointor with power to remove and replace the trustee, and defines the beneficiaries as D's spouse, children and remoter issue. The names are fictional; the structure is ordinary.
Step 1: identify the trust. Collect the deed and any variations, the kind of trust, its ABN if it carries on business, its principal place of operation and its governance individuals. Verify against the deed and the Australian Business Register.
Step 2: identify the persons acting for the trust. The trustee company and whichever of its directors deal with you. Verify Harbourline Nominees against the ASIC register: status, directors, shareholders.
Step 3: identify the beneficiaries. The class as defined by the deed, recorded as the persons on whose behalf the service is received, and screened for sanctions and PEP status to the extent they are named.
Step 4: unwrap the corporate trustee. Harbourline Nominees is not a beneficial owner; its owners are. Follow both shareholders.
Step 5: follow the Singapore branch. Meridian Holdings' ACRA extract shows A as sole shareholder. A holds 100 percent of 60 percent, so 60 percent of the trustee company. A is a beneficial owner by ownership, resident abroad but not in a listed jurisdiction. Verify A's identity as an individual with a government document and liveness, and screen for PEP status and sanctions.
Step 6: follow the BVI branch. The BVI register does not disclose shareholders to the public. Coral Reef Ventures' ownership has to be established from certified constitutional documents and a letter from an independent professional adviser, and recorded as such. B and C each hold 50 percent of 40 percent, so 20 percent each of the trustee company. Neither meets the 25 percent ownership test on their own. The file records the calculation and turns to control: do B or C hold any power under the deed or the trustee's constitution? If not, they are not beneficial owners by the ownership route, and the record says why.
Step 7: apply the control test to the deed. D, the appointor, can remove and replace the trustee. That is control by other means, and D is a beneficial owner regardless of holding no units or shares. Verify D's identity and screen.
Step 8: decide on enhanced measures. If the third country where B and C reside is on the FATF's call-for-action list, enhanced CDD is mandatory for the customer, and source of funds and wealth for the trust and its beneficial owners must be established. If it is not listed, the reporting entity still rates the structure: two intermediate companies in two foreign jurisdictions, one of them with a closed register, for an Australian family trust, is a complexity that needs a documented business rationale, and most policies will rate it high and apply enhanced CDD on that ground.
Step 9: record the outcome. Beneficial owners identified: A (60 percent, ownership) and D (control as appointor). B and C recorded with their 20 percent calculations and the reason they fall outside the test. Evidence listed per layer, with the BVI branch flagged as established from certified documents rather than a public register. Risk rating recorded, enhanced measures recorded, senior management approval recorded where the policy requires it.
Done by hand, steps 4 to 7 are where the days go: two foreign registers, one closed, three individuals in two countries, a deed to read for control powers. Done with ownership discovery software, the register pulls and the percentage arithmetic are automatic, the closed register surfaces as an unresolved branch that a reviewer decides how to evidence, and the individuals receive linked identity checks in parallel rather than in sequence.
What do you record, and what happens when a branch cannot be resolved?
The record has to let a supervisor reconstruct the reasoning: which matters were established, from which sources, with what calculation, and why the reporting entity was satisfied on reasonable grounds. AUSTRAC accepts that some customers have no beneficial owner; it does not accept a blank. Where no individual meets the ownership test, the file records the analysis and identifies who controls the entity by other means. Where a branch cannot be resolved because a jurisdiction discloses nothing and the customer cannot evidence it, the honest record is that the branch is unresolved, what was attempted, and what the reporting entity decided to do about it: apply enhanced measures, obtain a declaration from the customer marked as declared rather than verified, or decline the service.
That last point is the difference between a defensible file and an exposed one. A platform that quietly promotes a corporate entity into the beneficial owner field to make the output look complete has manufactured a finding for the next review. A platform that shows the unresolved branch has given the reporting entity a risk decision to make and record.
How does ownership discovery run this with an agent?
Zyphe's KYB software runs steps 2 through 6 as ownership discovery. The authoritative register record for each company in the chain is purchased live, across more than 240 registries in three published latency tiers, and the submission is graded against it. Discovery follows corporate shareholders through every available tier until it reaches natural persons, with stakes multiplied along each chain and the 25 percent test applied to the aggregate, configurable per flow. There is no fixed layer limit; the bound is a credit budget the reporting entity sets, and branches the budget cuts stay visible as truncated, extendable node by node behind a cost preview.
Where a branch reaches a jurisdiction with no register coverage, as the BVI branch does, it stays visible as unresolved and the entity is held as a proxy, never reported as a natural person. Where discovery cannot complete, the customer is asked to declare the owners and the declaration is marked as declared. Each individual found, A and D in the example, receives a linked KYC flow with a document check, liveness and screening, and the business verification cannot be approved until those complete; sanctions, PEP and adverse media screening runs on every entity and person in the chain.
For the enhanced due diligence decision itself, the UBO and EDD review desk assembles the trace, the screening results and a draft rationale for the reporting entity's own responsible person to approve, which is where the Act leaves the decision. Documents and biometrics collected along the way are processed transiently and stored encrypted in each individual's own vault; the reporting entity keeps the verification results, logs and proofs, which is the record AUSTRAC asks for and not the passport archive it says you do not need. The data residency position is written down on the security and data handling page.
The bottom line
A multi-layer trust with offshore owners is not a special case under Australia's AML/CTF Act; it is the ordinary case applied to its limit. Every trustee, controller and settlor is identified, every corporate layer is followed until an individual appears, every percentage is multiplied and aggregated, every offshore link is evidenced from what the jurisdiction discloses and rated for what it does not, and every branch that cannot be finished is written down as unfinished. The firms that do this well have stopped treating it as bespoke and started treating it as a workflow, with the unresolved branches shown rather than hidden.
This article is general information, not legal advice. Obligations depend on the services a business provides and the structure in front of it, and firms should take advice on their own circumstances.
Related resources
- AML/CTF for trust and company service providers in Australia
- AUSTRAC tranche 2: enrolment, obligations and deadlines
- Ultimate beneficial owner (UBO)
- What is KYB (Know Your Business)?
- Enhanced due diligence: when and how to apply it
- KYB software
- UBO screening software
- KYC software
- UBO and EDD review desk
Cited sources
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006, Federal Register of Legislation
- Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (No. 110, 2024), Federal Register of Legislation
- AUSTRAC, Overview of initial customer due diligence
- AUSTRAC, Initial CDD for trust
- AUSTRAC, Enhanced customer due diligence
- FATF, Recommendations 24 and 25 on beneficial ownership of legal persons and arrangements
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.