Your tax file is not customer due diligence. It never was. Under Tranche 2, with obligations running from 1 July 2026, an accountant has to run initial CDD before providing a designated service: collect know your customer information and verify identity on reliable, independent data (AML/CTF Act 2006 ss 26F, 28 and 41). The file you have built over eight years of returns does not satisfy that. One part of it, the tax file number, is the single identifier you are not allowed to reuse. This is about where the tax engagement stops, where the CDD file starts, and which traffic is allowed to move between them.
Two files, one client
Same person, two files, two bodies of law. The tax engagement file exists to run tax administration. It answers to the Tax Agent Services Act, the Taxation Administration Act 1953 and the Privacy (TFN) Rule 2015, and it fills up with the client’s tax file number, prior returns, income, deductions and entity structure. The CDD file exists for a different reason, to manage money laundering and terrorism financing risk. It answers to the AML/CTF Act, and it holds identity verified on reliable independent data, beneficial owners, a documented ML/TF risk rating and a read on the source of funds. They overlap in the client. They do not overlap in purpose, and purpose is what the law cares about.
One client, two files: the information boundary an accountant now has to draw.
The trap is thinking you already have all this
Collection is not verification, and that gap is where the mistake lives. AUSTRAC keeps the two separate: you must collect KYC information, and you must verify it on reliable and independent data appropriate to the client’s risk. Years of tax work hand you a mountain of collected information. Almost none of it was verified to an AML standard, because it never had to be. Knowing a client well is not the same as having established, on reasonable grounds and on independent evidence, that they are who they say they are. Pre-commencement customers get some relief on re-running identity, but the day a client enters a new business relationship for a designated service on or after 1 July 2026, full initial CDD applies. Longevity exempts nobody.
The tax file number trap
Here is the part almost nobody flags. The tax file number is the richest identifier you hold, and it is the one you cannot touch for CDD. The Privacy (TFN) Rule 2015 restricts TFN information to purposes authorised by taxation, superannuation and personal assistance law. AML customer due diligence is not one of them. The Rule goes further and says a TFN must not be used as part of a national identification system, which is precisely what an identity check is. Reuse it as a CDD identifier and you are not saving time, you are committing an offence: unauthorised use or disclosure of a TFN can attract up to 100 penalty units or 2 years imprisonment under sections 8WA and 8WB of the Taxation Administration Act 1953. The tidy idea of lifting the TFN out of the tax file to anchor the AML check is not a shortcut. It is the one move you have to design out of the process.
What is allowed to cross
Not everything is walled off, and it helps to know what travels. Some of what your tax work produces is legitimate reliable and independent data for CDD, and AUSTRAC says so itself. Its guidance on verifying a trust lists business activity statements and letters from the client’s accountant among the evidence you can use to verify the nature and purpose of the customer. An ASIC company extract does the same job for a corporate customer. The line is about what you are verifying. Entity facts, structure, the nature of the business: tax artefacts can carry that. Personal identity of an individual needs its own reliable independent evidence, its own consent basis, and it still cannot lean on the TFN.
The traffic that runs the other way
The boundary is not just a wall around the tax file. CDD pushes information back at you that you then have to act on. Ask the plain source of funds question and the answer might not line up with what the returns have said for years. Under section 41 of the AML/CTF Act, a reasonable suspicion is enough to trigger a suspicious matter report, and the transaction does not have to complete. You do not get to sit on it because the client is old and trusted. Once you are there, section 123 says you must not tip off: you cannot tell the client, in words or in a suddenly stiff manner, that a report is coming. The confidentiality you owe under the tax relationship and the reporting duty you owe under the AML regime meet right here, and the reporting duty wins.
From my desk. A client I had done tax for since 2018 came in one July to set up a discretionary trust and a corporate trustee for a property purchase. My first instinct was that I knew this family cold: eight years of returns, the lot. Then it landed that none of that was CDD. Helping structure that purchase was a designated service, so before I lifted a finger I had to run initial CDD on the trust, identify and verify the beneficial owners, and verify identity on independent evidence, not on the fact that I held their tax file. The tax file number on record was no help, because I am not permitted to use it here. And when I asked the ordinary source of funds question, the answer did not sit with eight years of returns. That is the moment the two files stop being an admin nuisance and become the whole point.
The rule that keeps you clean
Keep two files, two legal bases, two retention clocks, and never let one pretend to be the other. The CDD file stands on its own verified evidence, with the TFN left out of it entirely. Tax artefacts can support entity verification, but they enter the CDD file as verification data, logged as such, not as a photocopy of the tax file. And when CDD surfaces something, it flows to a report, not back into a chat with the client. Draw the line once, build it into onboarding, and you stop having to redraw it under pressure with a client sitting across the desk. If you would rather keep the CDD file, the verification evidence and the review dates in one place built for this, that is what HP-KYC is for.
The detail (current as at July 2026)
Tranche 2 for accountants: designated services from 1 July 2026. The CDD reforms commenced 31 March 2026, replacing applicable customer identification procedures (ACIP) with initial CDD. AML/CTF Act 2006 (Cth); reformed AML/CTF Rules.
Initial CDD: collect and verify KYC information on reliable and independent data before providing a designated service; identify and verify beneficial owners; assess ML/TF risk. AML/CTF Act ss 26F, 28, 41; Rules s 6-10. Collection and verification are separate obligations.
Pre-commencement customers (a business relationship involving a designated service provided on or before 1 July 2026): full initial CDD is not required to be re-run, but ongoing CDD, monitoring and KYC updates still apply. A new business relationship for a designated service on or after 1 July 2026 requires full initial CDD.
Tax file number: use and disclosure restricted to taxation, superannuation and personal assistance law purposes; must not be used as part of a national identification system. Privacy (TFN) Rule 2015, made under Privacy Act 1988 s 17. Unauthorised requirement, request, recording, use or disclosure of a TFN is an offence under Taxation Administration Act 1953 ss 8WA and 8WB, up to 100 penalty units or 2 years imprisonment.
Reliable and independent data for entity verification can include business activity statements, an accountant’s letter and ASIC records (AUSTRAC CDD guidance). Individual identity verification requires its own reliable and independent evidence.
Suspicious matter reports: a reasonable suspicion triggers a report under AML/CTF Act s 41; a completed transaction is not required. Tipping off is prohibited under s 123 (result-based test in force from 31 March 2025).
Penalty unit: $364 for offences on or after 1 July 2026 (Crimes Act 1914 s 4AA).
Frequently asked questions
Can I use my tax file as my CDD file?
No. A tax file is built to support a return. A CDD file has to prove identity, verification, beneficial ownership and a risk assessment for the service you provided.
What does a CDD file need that a tax file does not have?
Identity information collected and verified against a reliable and independent source, the beneficial owners behind the customer, an understanding of the relationship, and a documented risk rating.
Does a TFN declaration verify identity?
No. It establishes a tax file number for withholding. It is not identity verification, and its use is confined by privacy rules.
Can I reuse client information collected for tax work?
Some of it, with care. Information collected for tax purposes may be reusable, but you have to check the privacy limits and fill the gaps the tax file was never designed to cover.
