Before you provide any designated service under Tranche 2, you must complete customer due diligence on your client. This means verifying their identity using reliable and independent sources — and keeping a record of that verification for 7 years.
This guide explains exactly what AUSTRAC requires you to check, how to check it, and what records you need to keep.
What is Customer Due Diligence?
Customer due diligence (CDD) is the process of identifying your client and verifying that they are who they claim to be. Under the AML/CTF Act, CDD is not optional — it is a legal requirement that must be completed before you start providing any designated service.
AUSTRAC's CDD requirements have three levels: initial CDD (before you start), ongoing CDD (throughout the relationship) and enhanced CDD (for high-risk clients or suspicious matters).
Initial CDD — What You Must Collect
For every individual client, you must collect and verify:
- Full legal name
- Date of birth
- Residential address
- Occupation or business activities
- The nature and purpose of the business relationship
For company clients, you must additionally collect and verify:
- Company name and ACN
- Registered address
- Nature of business activities
- Full list of directors
- All shareholders owning 25% or more
- The beneficial ownership chain — tracing back to the individuals who ultimately own or control the company
For trust clients, you must collect the trust deed and identify all trustees, settlors, appointors and beneficiaries (or the class of beneficiaries if individual beneficiaries are not yet determined).
How to Verify — What AUSTRAC Accepts
Collecting information is not enough. You must verify it using "reliable and independent" sources. This is the key phrase in AUSTRAC's rules — and it is why photocopies of driver licences alone do not satisfy the requirement.
Electronic Verification via DVS (Recommended)
The most reliable and AUSTRAC-preferred method is electronic verification through the Australian Document Verification Service (DVS). This checks the client's details in real time against government databases including driver licence records (all states and territories), passport records (DFAT), Medicare records (Services Australia) and visa records (Department of Home Affairs). An electronic check that returns a match is strong evidence that the identity is genuine. This is what platforms like VerifyID Online use for Australian clients.
Document Capture and Authentication
For international clients or where DVS matching is not available, document capture and authentication is used. The client photographs their ID document, and software checks it against a template database of over 8,500 government-issued document types from 195 countries. This detects forgeries, tampering and inconsistencies invisible to the human eye.
Biometric Face Matching
A complete verification also includes matching the client's live selfie against the photo on their ID document using biometric facial recognition. Liveness detection confirms the person is physically present and not using a photo or deepfake. This step confirms that the document belongs to the person presenting it — not someone else using a stolen or borrowed ID.
PEP and Sanctions Screening
As part of initial CDD, you must screen every client against the DFAT Consolidated List (Australia's sanctions list) and check whether they are a politically exposed person (PEP). This screening must be done before you start providing services and must be repeated whenever client information changes or during periodic reviews.
A PEP is any individual who holds or has held a senior public position — in an Australian, foreign or international government or organisation — that may create vulnerability to corruption or bribery. Foreign PEPs are automatically classified as high-risk and require enhanced CDD.
Risk Rating and Ongoing CDD
After completing initial CDD, you must assign each client a risk rating — Low, Medium or High — based on factors including who they are, what services they need, how they want to receive those services and where they are based. The risk rating determines how closely you monitor them and how often you review their information:
- High-risk clients — periodic review every 12 months
- Medium-risk clients — periodic review every 2 years
- Low-risk clients — periodic review every 3 years
Record Keeping
You must keep all CDD records — verification results, document images, risk ratings, screening results and audit logs — for a minimum of 7 years following the end of the business relationship or the date of the last transaction, whichever is later. Records must be stored securely, in English (or convertible to English), and must be accessible to AUSTRAC on request.
A platform like VerifyID Online handles this automatically — every verification generates a timestamped, encrypted record stored in Australian data centres for the required 7 years.
Ready to Verify Clients the Compliant Way?
VerifyID Online handles your AUSTRAC identity verification obligations. Set up in 10 minutes.
Join the Waitlist →