
Document capture for KYC is the controlled collection of identity evidence that becomes defensible initial customer due diligence only once it is linked to independent verification and an officer’s decision. A stored image or PDF proves nothing on its own. A defensible record shows the document type and number, the issuing authority, its expiry, the verification method used and its result, a timestamp, and the name of the officer responsible. Capture is an input to initial CDD, not the decision itself, and binding the document to the person in front of you is a separate step again.
TL;DR:
- Document storage should include metadata such as document type, issuer, expiry, verification method, and timestamps, so an auditor can reconstruct each decision.
- Results from DVS, FVS and biometric checks should feed human review, not stand alone as proof that a document is genuine or that it belongs to the person presenting it.
- Higher-risk customers warrant layered evidence and a closer look at beneficial owners and anyone acting for them, and any lower-friction method used for them needs a documented rationale.
- Data privacy safeguards include limiting access, encrypting stored evidence, and keeping verification details rather than document images where the rules allow, to reduce breach risk.
- Effective workflows link capture results to overall risk assessment and ongoing monitoring, enabling a complete customer history for audits and regulatory reports.
Table of Contents
- What counts as a KYC document for individuals, companies and beneficial owners
- A step-by-step capture workflow that holds up under audit
- OCR, DVS, FVS and biometrics: what each one actually proves
- Person-binding is not the same job as authenticity checking
- What the audit trail needs to store, and for how long
- Risk-based choices and a short exceptions policy
- How document capture fits into the wider compliance system
- Data privacy and security when handling identity documents
- Where document capture technology is heading
- Regulatory variations across jurisdictions
- Practitioner checklist: eight checks before you accept a captured document
- How AML Guard builds a defensible capture record
- Sources
- FAQ
What counts as a KYC document for individuals, companies and beneficial owners
Acceptable evidence depends on who you’re identifying and how much risk they carry. For individuals, AUSTRAC’s initial CDD guidance for individuals points to primary photographic identification such as:
- A passport
- A driver licence
- A proof of age card
- A foreign national identity card
Where a customer relies on a non-photographic document instead, such as a birth certificate or citizenship certificate, the same guidance pairs it with a secondary document showing their name and address, such as a utility bill or a notice issued by a Commonwealth, state, territory or local government body. Entity customers need a different evidence set entirely: a certificate of registration, an ASIC company extract, constituent documents, and whatever paperwork establishes who actually owns or controls the entity. Beneficial ownership capture under the AML/CTF Act and the 2025 AML/CTF Rules requires identifying the individuals who ultimately own or control the entity, not just its registered details.
One operational nuance trips up a lot of reporting entities: AUSTRAC does not require a stored copy. Its guidance says you are not required to keep identity documents under your record-keeping obligations and can record their details instead. Verification still has to run against a reliable and independent source either way. That distinction matters when you’re designing storage policy, because minimising copies held is a genuine privacy safeguard, not a compliance shortcut.
A step-by-step capture workflow that holds up under audit
A capture workflow only becomes defensible when every step leaves a trace. The sequence below reflects how experienced compliance teams structure the process from first contact to locked record.
- Identify the customer and the people connected to it. For entities, this means beneficial owners and anyone acting on the customer’s behalf, such as authorised signatories, not just the company itself.
- Request evidence matched to customer type and risk. A low-risk individual might need one photo ID; a high-risk entity might need layered evidence across several documents.
- Capture the image and its metadata together. Document ID, issuer, expiry, the context of submission, and a timestamp all need to sit alongside the image, not in a separate system nobody checks.
- Check completeness and internal consistency before verification. Does the name match across documents? Has the document actually expired? These are cheap checks that catch a surprising share of errors.
- Verify against an independent government or electronic source where one exists, and log the method and the result, not just “verified.”
- Route anything that fails or looks inconsistent to human review, with the reviewing officer’s rationale and outcome recorded against the file.
- Lock the capture to the customer record and the verification decision so nobody can later separate the evidence from the judgement that was made about it.
Pro Tip: Build your metadata fields before you build your document upload screen. Teams that design the record structure first rarely end up retrofitting fields under audit pressure later.
OCR, DVS, FVS and biometrics: what each one actually proves
Automated tools speed up capture enormously, but each does a narrower job than the marketing around it suggests. Understanding the boundaries between them is what stops a capture workflow from quietly becoming a rubber stamp.
- OCR and intelligent document processing (IDP) extract text into structured fields quickly and accurately, which cuts manual entry errors. Extraction is not an authenticity check. A well-formed field pulled from a convincing forgery is still a forgery.
- The Document Verification Service (DVS) and Face Verification Service (FVS), administered under Attorney-General’s Department identity verification services arrangements, check biographic data and facial images against the records held by the issuing government body. Access requires a participation agreement and carries privacy obligations that govern how results can be stored and used.
- Biometric liveness checks confirm that a live person, not a photo of a photo or a static image, is presenting in real time. This is where person-binding starts, though liveness alone doesn’t finish the job.
None of these technologies should run in isolation from human judgement. Design your workflow so unusual results, mismatches, or failed checks route automatically to officer review rather than getting waved through because the system returned a “pass” on one dimension.
Person-binding is not the same job as authenticity checking
Two separate questions sit underneath every document capture, and conflating them is one of the more common compliance failures. The first question is whether the document is authentic. The second is whether the person holding it is actually who the document says they are. AUSTRAC’s guidance for individuals deals with the second question as its own matter under section 28(3)(a) of the Act: making sure the customer is the person they claim to be. Each check needs its own recorded result, not one combined pass/fail.
Practical binding controls include liveness detection, face match against the document photo, in-person sighting by a staff member, or independent corroboration through another verified channel. Whichever control you use, the record needs to show which one, the result, the timestamp, and the reviewing officer. A failed DVS or biometric check is not automatically fraud: government verification failures sometimes reflect an entry on the Credential Protection Register, which blocks compromised credentials from online verification, or a temporary service outage. Treat these as investigatory exceptions and record the steps taken to resolve them, not as automatic rejections.

What the audit trail needs to store, and for how long
Auditors reconstruct decisions from records, not memories, which means the fields you capture matter more than the storage system you use to hold them. A defensible audit trail should carry:
- The document identifier and issuing authority
- The verification channel used and the exact response received
- The operator or officer who actioned the check
- Timestamps for capture, verification, and any escalation
- The disposition of the file, including the reason for any exception
Images need to stay linked to their verification results and to the customer record, because provenance breaks the moment a file gets separated from the decision it supported.
The AML/CTF Act 2006 sets a seven-year minimum for record-keeping. What matters is that the trail stays usable for the whole period: an auditor reconstructing a decision in year six needs the same fields as one reading it the day after it was made.
On privacy, the principle is simple even where the practice takes discipline: minimise the copies you hold where the rules allow it, and restrict access to captured evidence to the people who actually need it for verification or review.
Risk-based choices and a short exceptions policy
Certified copies and electronic verification are both legitimate ways to satisfy initial CDD. Neither is inherently superior. The choice is risk-based, the same approach the Attorney-General’s Department takes in its voluntary National Identity Proofing Guidelines: the method should scale with the risk the customer presents, not with convenience.
A few exceptions come up often enough to warrant a standard response. A document nearing expiry might warrant a request for a second form of evidence rather than outright rejection. A facial match that returns borderline confidence should escalate to manual review rather than an automatic fail. For a higher-risk entity customer, go deeper on its beneficial owners and anyone acting on its behalf, even if that slows onboarding. Whenever you use a lower-friction method for a case that’s actually higher-risk, record why. That rationale is what a supervisor looks for when a file gets pulled for review.
How document capture fits into the wider compliance system
Capture rarely operates as a standalone task. It sits inside a chain that runs from onboarding through screening, risk scoring, and ongoing monitoring, and a capture record that isn’t connected to that chain loses most of its value. If a customer’s risk rating changes six months after onboarding, the original capture evidence needs to be retrievable alongside the updated risk assessment, not filed away in a system nobody revisits.
Integration matters in three practical ways. First, capture results should feed the customer’s risk profile directly, since a document that failed an authenticity check or triggered a manual review is itself a risk signal worth recording against the file. Second, sanctions and politically exposed person (PEP) screening usually rely on the same biographic details pulled during capture, so a clean handoff between capture and screening avoids re-entering data and the errors that come with it. Third, suspicious matter reporting obligations under the AML/CTF regime depend on being able to reconstruct what was known about a customer at a given point, which is only possible if capture records, verification results, and screening outcomes live in a connected system rather than scattered across spreadsheets and inboxes.
Firms that treat document capture as an isolated intake step, disconnected from risk assessment and reporting workflows, tend to discover the gap at the worst possible time: during an AUSTRAC review or a suspicious matter investigation, when reconstructing the full customer history becomes a manual reconstruction project rather than a database query.
Data privacy and security when handling identity documents
Identity documents are some of the most sensitive data a business holds, and the obligation to verify customers sits alongside a separate obligation to protect what you collect in the process. Passport numbers, driver licence details, and biometric templates all carry privacy risk that persists long after the onboarding conversation ends.
Practical safeguards start with access control. Not every staff member needs to see raw document images; many workflows only require confirmation that a check passed or failed. Encryption at rest and in transit is standard practice for any system holding this kind of evidence, and role-based access limits exposure if credentials are compromised. Retention discipline matters just as much as security controls: keeping documents well beyond their legally required retention period increases the exposure surface without adding any compliance benefit.
Where AUSTRAC guidance permits retaining verification details rather than a document copy, that option is worth taking seriously as a privacy safeguard rather than treating it purely as a storage-cost decision. Fewer stored images mean less to protect and less to lose in a breach. Firms should also be deliberate about what gets shared with third-party systems: a CRM or case-management tool generally needs to know that a check passed, not the underlying document image or extracted biometric data itself.

Where document capture technology is heading
Artificial intelligence is changing what automated capture tools can catch, particularly around document tampering that used to require a trained eye to spot. Pattern-recognition models can now flag inconsistencies in font, microprint, or security features that a rushed manual review might miss, and they do it in seconds rather than minutes.
The more significant shift is in how liveness and face-match technology is maturing to resist increasingly sophisticated presentation attacks, including deepfake-style spoofing attempts. As that arms race continues, expect biometric binding controls to keep tightening, with vendors building in checks for injection attacks and synthetic media that simply weren’t a serious threat a few years ago.
None of this removes the need for officer review. If anything, better detection tools generate more edge cases worth a human look, not fewer. The trend worth watching isn’t full automation; it’s automation that gets better at deciding what to escalate.
Regulatory variations across jurisdictions
Document capture requirements are not uniform globally, and firms operating across borders need to treat each jurisdiction’s rules as its own regime rather than assuming one policy travels cleanly everywhere. What counts as acceptable identity evidence, how long records must be kept, and which government verification channels are even available differ by country and sometimes by state or territory within a country.
For businesses operating under Australia’s AML/CTF regime, the framework runs through the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and the AML/CTF Rules, with AUSTRAC as the regulator and government verification services like DVS and FVS available through participation agreements. Other jurisdictions run entirely different identity infrastructure, different acceptable-document lists, and different retention periods. A firm building a capture workflow for multiple markets needs to design for that variation from the start, rather than exporting an Australian template and hoping it fits elsewhere.
Practitioner checklist: eight checks before you accept a captured document
Before a captured document goes into the file, run it against these eight checks.
- Confirm the document type suits the customer type.
- Check the expiry date, and collect more evidence if the document has expired.
- Scan for obvious authenticity red flags.
- Check that names and details match across every document you hold.
- Verify it through DVS or FVS, or against an original or certified copy where that’s the chosen route.
- Confirm a person-binding control was actually performed, not just assumed.
- Log the officer who made the decision, and the timestamp.
- Record how any exception was resolved before you consider the record closed.
How AML Guard builds a defensible capture record
AML Guard links document capture, government-source checks, and biometric liveness into a single record, with an officer reviewing the outcome. That structure means the platform’s features for identity verification, beneficial ownership handling, and risk assessment all draw from the same underlying evidence rather than separate, disconnected systems.
The same guided approach generates your risk assessment, AML/CTF policies, compliance action plan, and training manual from one linked set of answers, so the documents a supervisor checks actually match each other. On retention, AML Guard’s audit trail holds records for 8 years, above the Act’s seven-year minimum. Integration with REX CRM pushes status only, never the underlying CDD data, and AML Guard offers a client-pays option where a transaction party can fund their own check, with the fee credited against that month’s subscription. AML Guard is not self-service: firms start with a demo, after which the platform is configured to their designated services and risk profile. Review the Platform subscription options or book a demo to see how a linked capture record would work against your own onboarding flow.
Sources
- Initial CDD for individuals | AUSTRAC
- Identity verification services | Attorney-General’s Department
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- AML/CTF Rules 2025 | Federal Register of Legislation
- National Identity Proofing Guidelines | Attorney-General’s Department
FAQ
What Is a KYC Document?
A KYC document is any piece of identity evidence, such as a passport, driver licence, or company registration extract, used to establish who a customer is during initial due diligence. On its own it’s just evidence; it only becomes meaningful once checked against an independent source and tied to a verification decision, as AUSTRAC’s CDD guidance sets out.
What Documents Are Typically Required for KYC?
For individuals, primary photographic identification such as a passport, driver licence, proof of age card or foreign national identity card is standard, and a non-photographic document such as a birth certificate is paired with a secondary document showing name and address. Entities need registration documents, an ASIC company extract, and evidence identifying beneficial owners, following the customer-type distinctions in the 2025 AML/CTF Rules.
Is KYC Mandatory?
Yes. Any business providing a designated service under the AML/CTF regime must complete initial customer due diligence before providing that service, under the AML/CTF Act 2006 (Cth). In some circumstances verification can be delayed, where carrying it out would interrupt the ordinary course of business and other conditions are met. This isn’t optional or discretionary once a business falls within scope as a reporting entity.
What Are the Stages of KYC?
Most frameworks describe KYC as running through identification, document capture and verification, person-binding, risk assessment, and ongoing monitoring. Definitions of the exact stage count vary between guidance documents and vendors, but the sequence from evidence collection through to an officer’s decision and continued oversight holds across most models.
How Does AML Guard Support Document Capture?
AML Guard combines document capture, government-source verification, and biometric liveness checks into one linked record, with an officer reviewing the outcome. Current pricing details for the Platform subscription and per-check services are available on the pricing page.
Recommended
- Acceptable ID documents for Tranche 2 firms
- Tranche 2 customer due diligence in Australia
- Tranche 2 AML Australia: your compliance obligations explained
- AML/CTF Program Documents for Tranche 2
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.