Acceptable identity documents for AML/CTF customer due diligence in Australia fall into three classes: primary photographic (like a passport or driver licence), primary non-photographic paired with a secondary document, and reliable independent electronic data through services such as the Document Verification Service and Face Verification Service. There is no fixed checklist. Your program must leave you reasonably satisfied about identity, using a risk-based mix of documentation and electronic verification that you define yourself.
TL;DR:
- Most verification relies on current primary photographic documents or reliable electronic data, with risk-based policies tailoring acceptable evidence for each customer type.
- Electronic verification services like DVS and FVS provide real-time document matching and biometric confirmation, but require thorough due diligence on data sources and security standards.
- Alternative ID methods, such as referee statements or government correspondence, are acceptable only with proper risk mitigation and detailed documentation.
- Record retention of verification data must last seven years, with ongoing re-verification triggered by significant changes or approaching document expiry.
- Automated, integrated verification systems streamline compliance, ensure consistent documentation, and reduce human error compared to manual checklist approaches.
Table of Contents
- What counts as acceptable documentary evidence for identity verification?
- How do the Document Verification Service and Face Verification Service work?
- What if a customer has no standard ID documents?
- How do you verify companies, trusts and SMSFs?
- How long must you keep verification records, and when do you file an SMR?
- A practical checklist for your AML/CTF policies
- Common pitfalls when handling discrepancies or suspected fraudulent documents
- What does acceptable ID verification look like in practice?
- A compliance officer’s honest take on where firms go wrong
- Get your acceptable ID list and verification workflow sorted properly
- Sources
What counts as acceptable documentary evidence for identity verification?
Compliance officers coming from a 100-point mindset need to unlearn it fast. That framework belongs to the Financial Transaction Reports Act 1988 and has nothing to do with your obligations as a Tranche 2 reporting entity. Under the AML/CTF Act, the test is whether you have reasonable grounds to be satisfied a customer is who they claim to be, verified against reliable and independent documentation, electronic data, or both.
AUSTRAC’s guidance groups documents into three practical categories.
- Primary photographic documents: an original, current passport, an Australian driver licence, or a proof-of-age card issued by a state or territory.
- Primary non-photographic documents: a full birth certificate, citizenship certificate, or pension card issued by Centrelink, usually paired with a secondary document.
- Secondary documents: a Medicare card, a utility bill, or a notice from the Australian Taxation Office confirming name and address.
The strength of any document depends on more than its category. An expired licence carries less weight than a current one. A certified copy presented in person is generally stronger than an emailed scan with no verification trail. Reliable and independent documentary evidence also has to match the customer’s risk profile. A low-risk residential conveyance might need one primary photographic document; a high-value trust settlement warrants more. Your AML/CTF policies set that acceptable-document list yourself, calibrated to your own risk assessment rather than copied from a template.
How do the Document Verification Service and Face Verification Service work?
Electronic verification has become the default for firms processing volume, not the exception. The Document Verification Service matches a customer’s document details against the issuing government agency’s own records in real time, covering passports, driver licences, Medicare cards, and visas. The Face Verification Service adds a biometric layer, comparing a live selfie against the photo on a government-held document to confirm the person presenting the ID is the person it belongs to.
Both qualify as reliable independent electronic data when used properly, but “used properly” carries conditions. AUSTRAC expects you to verify KYC information using sources appropriate to the customer’s ML/TF risk, not simply the cheapest API you can plug in. Before relying on any commercial e-ID provider layered over DVS or FVS, check:
- Who owns and maintains the underlying data, and whether that source is genuinely independent of the customer.
- How frequently the provider’s data feeds are updated against government registers.
- What security certifications and breach history the provider can demonstrate.
- Whether the provider’s outputs are auditable, not just a pass or fail flag.
Pro Tip: Store the full verification output, not just the result. A “verified” tick with no underlying data trail is close to useless if AUSTRAC or an external auditor later asks how you reached that conclusion.
Link every verification output to the customer record it supports, timestamped and retained exactly as you would a certified paper document.
What if a customer has no standard ID documents?
Not every customer walks in with a passport and a Medicare card. Older Australians, recent arrivals, people experiencing homelessness, and customers whose documents were lost or destroyed all need a lawful path through your CDD process. AUSTRAC explicitly recommends alternative identification procedures for exactly this situation, provided you manage and document the ML/TF risk.
Workable alternatives include:
- A referee statement from a person who has known the customer for a set period, typically containing the referee’s full name, occupation, contact details, relationship to the customer, and a signed statement confirming identity.
- Government correspondence, such as a Centrelink or ATO letter, showing the customer’s name and current address.
- Community identification, including documents issued by community organisations for customers without government-issued ID.
- Recently expired ID, assessed on the balance of remaining reliability rather than rejected outright.
- Self-attestation combined with a secondary corroborating step, reserved for the lowest-risk scenarios only.
Every one of these carries a condition: apply mitigation. That might mean limiting the designated service’s functionality until further verification lands, granting temporary access pending follow-up, or escalating straight to enhanced due diligence if anything about the story doesn’t add up. Document the reasoning at the time you make the decision, not after the fact.
How do you verify companies, trusts and SMSFs?
Non-individual customers demand a different verification path entirely, built around confirming the entity exists and identifying who actually controls it. Start with the minimum fields: full legal name, ABN or ACN, registered address, entity type, and the names of directors, trustees, or partners depending on structure.
Confirm existence against authoritative government sources rather than customer-supplied paperwork alone.
- ASIC registers confirm company registration, director details, and current status for corporate customers.
- ABR (Australian Business Register) searches verify ABN validity and registered business details.
- Trust deeds and SMSF trust deeds, cross-checked against ATO registration where relevant, establish trustee identity and beneficiary structure.
- Beneficial ownership tracing requires looking through the entity to the individuals who ultimately own or control 25% or more, or who exercise effective control by other means.
For layered structures, corporate trustees behind discretionary trusts, or SMSFs with multiple members, expect to work through more than one layer of documentation before you reach a natural person. Where you rely on another party’s verification under a permitted arrangement, that reliance doesn’t remove your own obligation. You remain accountable for the result, so keep your own record of what was relied on and why it was reasonable to do so at the time. Beneficial ownership tracing for trusts and SMSFs deserves its own dedicated workflow rather than an afterthought bolted onto individual CDD.
How long must you keep verification records, and when do you file an SMR?
Retention isn’t optional or negotiable by internal policy. The AML/CTF Rules require you to keep customer identification records for seven years from the date the relevant service ends or the transaction is completed, whichever is later, with a tamper-evident trail showing what you checked, when, and what you concluded.
Ongoing due diligence means re-verification isn’t a one-off event at onboarding. Common triggers include:
- A significant change in transaction pattern or value that doesn’t match the customer’s stated purpose.
- A document nearing or past its expiry date during an active matter.
- A change in beneficial ownership or control structure for a company or trust.
- A jump in the customer’s risk rating following adverse media or a sanctions hit.
Where you cannot establish identity on reasonable grounds, you must not provide the designated service, and you need to consider whether to submit a suspicious matter report. That threshold sits below outright proof of wrongdoing. Reasonable grounds to suspect a document is fraudulent, that a customer is deliberately obstructing verification, or that identity details don’t reconcile across sources is enough to warrant lodging an SMR, regardless of whether the transaction ultimately proceeds.
A practical checklist for your AML/CTF policies
Turning all of this into something usable inside your AML/CTF policies comes down to five decisions, documented once and applied consistently. Since the 2024 amendments there is no Part A and Part B split: your program is a business-wide ML/TF risk assessment under section 26C, and the policies that manage the risks it identifies.
Map each service you provide against a risk category, then attach an acceptable-document list to each category rather than one blanket list for the whole business. Define which electronic sources you’ll rely on, DVS, FVS, or a named commercial provider, and record the vendor due diligence behind that choice. Build a template for alternative ID scenarios before you need it in the field, including the referee statement wording and the follow-up verification you’ll require. Set explicit re-verification triggers tied to risk rating, document expiry, and transaction pattern changes. Confirm your retention system produces a tamper-evident audit trail that survives seven years without gaps.

The consistency problem is where most firms trip up. A risk assessment that says one thing, policies that drift from it, and a training manual nobody’s updated since the last review create exactly the gap a supervisor is trained to find. AML Guard’s guided program wizards generate the business-wide risk assessment and AML/CTF policies as one linked set, so the acceptable-document list in your policies matches the risk categories in your assessment, and the workflow evidence ties back to both automatically.
Common pitfalls when handling discrepancies or suspected fraudulent documents
The most frequent error isn’t a missing document. It’s a name that’s spelled slightly differently across two documents, an address that’s a year out of date, or a date of birth transposed on one form and not another. Treat these as discrepancies requiring resolution, not as automatic red flags demanding rejection, but don’t wave them through either.
Start by asking the customer to explain the inconsistency and provide a third source that resolves it. A married name change, a recent house move, or a simple data entry error on an old document are common, benign explanations. What you cannot do is accept an explanation without corroboration and move on.
Genuine signs of a fraudulent document look different: photo substitution visible under magnification, fonts or security features inconsistent with the issuing authority’s known standards, or a DVS response that returns no match against the claimed document number. Any of these should stop the transaction and prompt escalation, not just a note in the file.
A frequent operational mistake is verifying the document but never verifying the person against the document. A passport can be entirely genuine and still not belong to the person standing in front of you. This is exactly the gap the Face Verification Service closes, biometric matching against a live capture rather than relying on a static photo comparison by eye. Where FVS isn’t available or the risk warrants it, a second independent check, such as a referee statement or a video call comparing the customer against the document photo, closes the same gap manually.

What does acceptable ID verification look like in practice?
Consider a suburban conveyancing firm settling a $650,000 residential purchase. The purchaser presents a current Australian passport. The firm runs it through DVS, gets a match, and records the verification output alongside a certified copy. Low risk, one primary photographic document, one electronic check, done. That’s the routine case, and it should stay routine.
Now consider a law firm engaged by a discretionary trust purchasing a commercial property through a corporate trustee. The trustee director presents a driver licence, verified through DVS and FVS. The firm then pulls an ASIC extract confirming the trustee company’s registration and directors, reviews the trust deed to confirm named beneficiaries, and traces beneficial ownership to two individuals holding effective control. Each layer gets documented, with the reasoning for accepting each source recorded against the transaction file.
A third scenario: an elderly customer at a regional accounting practice has no current photographic ID after a house fire destroyed her documents. The practice accepts a referee statement from a long-standing neighbour, corroborated by a Centrelink letter confirming her name and address, and applies a temporary restriction on the designated service pending replacement documents. The file records the risk assessment, the mitigation applied, and a follow-up date. None of these three scenarios uses the same document mix, and none of them should. That’s the risk-based standard working as intended, not a shortcut around it.
A compliance officer’s honest take on where firms go wrong
The biggest recurring mistake isn’t accepting a bad document. It’s building a rigid checklist that can’t flex for the customer in front of you, then failing to document why an alternative was reasonable when one was genuinely needed. Automating re-verification triggers and audit trails removes the human tendency to let a file go stale until an auditor asks the awkward question.
Get your acceptable ID list and verification workflow sorted properly
Building a defensible acceptable-document list by hand, then keeping it consistent across every file your firm touches, is where most Tranche 2 practices lose hours they don’t have. AML Guard runs identity verification with document capture and biometric liveness checked against Australian government sources, tied directly to the ML/TF risk assessment and AML/CTF policies your program already documents. An officer reviews each outcome; the platform automates the checks and the record, not the judgement.

That means every DVS or FVS result, every alternative ID decision, and every re-verification trigger lands in the same seven-year tamper-evident audit trail, evidenced against the workflow that produced it rather than sitting in a separate spreadsheet somewhere. For real estate agencies, conveyancers, law firms, and accounting practices juggling Tranche 2 obligations alongside client work, that consistency is what a supervisor actually checks. If your current process still relies on a static document list and manual file notes, it’s worth seeing how a purpose-built compliance platform handles the same problem end to end. Book a demo to see how AML Guard configures to your designated services and risk profile before your next file lands.
Sources
- Overview of initial customer due diligence (Reform) | AUSTRAC
- AML/CTF Rules 2025 | Federal Register of Legislation
Recommended
- AML/CTF Program Documents for Tranche 2
- AML/CTF Compliance Checklist for Real Estate Agents: What You Need Before 1 July 2026
- The Client Intake Portal: How Smart Agencies Onboard Clients for AML
- Beneficial Ownership CDD for Trusts, SMSFs & Companies
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.