
Yes, non face to face verification is permitted in Australia, provided your AML/CTF program makes you reasonably satisfied of the customer’s identity using reliable and independent data appropriate to their ML/TF risk. Remote onboarding does not, by itself, trigger enhanced customer due diligence; the delivery channel is one risk factor among several. The two controls that close the gap remote channels create, which is impersonation, are document authenticity checks and biometric liveness, or a documented video call where liveness isn’t practical.
TL;DR:
- Reliable and independent data sources, preferably government-backed, are essential to verify customer identity accurately in remote onboarding processes.
- Biometric liveness checks are the most effective way to prove a person is physically present and bound to submitted documents, especially when digital impersonation risks exist.
- Records of identity verification, screening results, and decisions must be maintained for at least seven years, with some platforms keeping records longer as a best practice.
- Alternative identification methods, such as referee statements or official correspondence, are acceptable but require verification of issuer reliability and thorough documentation of procedures.
- Suspicious signs like data mismatches, behavioral red flags, or sanctions hits should trigger escalation, additional verification, and possible filing of a suspicious matter report.
Table of Contents
- What the law requires for remote identity verification in Australia
- How do you verify identity without meeting someone in person?
- What if a customer doesn’t have standard identification?
- When should you re-verify identity or escalate a file?
- A practical checklist for remote onboarding controls
- Why linked compliance documentation matters for remote verification
- How AML Guard supports compliant remote onboarding
- Sources
- FAQ
What the law requires for remote identity verification in Australia
Every Tranche 2 reporting entity must complete initial customer due diligence before providing a designated service. That means establishing, on reasonable grounds, the customer’s identity, their authority to act, relevant beneficial ownership matters, and the nature and purpose of the business relationship. AUSTRAC is explicit that this must rest on reliable and independent data appropriate to the customer’s money laundering and terrorism financing risk, not on whichever document happens to be easiest to obtain.
The AML/CTF Rules 2025 set out the mechanics. Part 4.9 covers verification from electronic data, Division 8 governs reliance on know your customer information collected by another party, and Part 4.15 deals with alternative proof of identity for customers who lack standard documents. These provisions apply whether the customer walks into your office or verifies from a laptop interstate.
Three obligations sit underneath all of this, regardless of channel:
- Verification decisions and the evidence behind them must be documented at the time, not reconstructed later.
- Records of identity verification, screening outcomes and program decisions must be kept for seven years, which is the Act’s legal minimum.
- Some platforms retain audit trails beyond that statutory floor as a matter of operational practice, but seven years is the obligation you’re legally bound to meet.
How do you verify identity without meeting someone in person?
Real, secure online verification in Australia rests on three layers working together, not any single check in isolation.
- Electronic data verification. Match the customer’s name, date of birth and address against reliable, independent data sources, preferably ones with a government-backed lineage. AUSTRAC’s guidance and the Rules contemplate using multiple independent data sources where a single source doesn’t give you sufficient confidence, particularly for higher risk customers.
- Document capture with authenticity checks. Require a quality image or scan of the identity document, check the expiry date, look for tampering indicators, and use a document verification service where your risk assessment calls for it. A blurry phone photo of a driver licence, on its own, tells you almost nothing about whether that licence is genuine.
- Biometric liveness. This is what binds the person in front of the camera to the document they’ve submitted. A selfie matched against a photo ID, captured with liveness detection, addresses the specific vulnerability that non in-person verification methods create: someone using a stolen or borrowed identity document without ever being physically present.
A video call is a legitimate alternative control where liveness technology isn’t available or appropriate, and AUSTRAC’s own guidance on remote KYC procedures references video calls, selfies and scanned documents as acceptable measures. A video call is not, however, a substitute for biometric matching. It’s a different control with different evidentiary value, and your program should document why you’ve chosen one over the other for a given customer segment.
Sanctions, PEP and adverse media screening should run at onboarding and again on a scheduled basis afterwards, not as an afterthought once the file is closed.
Pro Tip: Don’t treat “remote” as a single risk category. A returning customer verifying a second property purchase online carries a different risk profile to a first-time overseas buyer paying via an unfamiliar intermediary. Calibrate your controls to the customer, not the channel.
What if a customer doesn’t have standard identification?
Some customers genuinely can’t produce a driver licence or passport, and AUSTRAC’s guidance on assisting customers without standard ID sets out acceptable alternatives rather than leaving you to refuse service outright. These typically include:
- Referee statements from a person in an eligible occupation who has known the customer for a reasonable period.
- Official government correspondence, such as a Centrelink or tax office letter, showing name and address.
- Community-issued identification recognised for Aboriginal and Torres Strait Islander customers in remote communities.
- Recently expired identity documents, where the underlying details remain verifiable.
Accepting an alternative doesn’t mean accepting it uncritically. Verify the issuer’s reliability where you can. That might mean phoning the referee’s stated employer through an independently sourced number, confirming government correspondence through an official contact channel, or cross-checking details against other records the customer provides. Where a standard document becomes available later, obtain it and update the file.
Document the specific procedure you followed in your AML/CTF program, not just the outcome. A supervisor reviewing the file six months later needs to see why the alternative was accepted, who approved it, and what compensating steps were taken. If the customer’s overall risk profile is elevated for other reasons, layering enhanced due diligence on top of an alternative ID pathway is often the right call.
When should you re-verify identity or escalate a file?
Certain triggers should prompt you to stop, re-verify or escalate rather than proceeding on the original file:
- Data mismatches. The name, date of birth or address on a document doesn’t match other records, or electronic verification returns a partial or failed match.
- Behavioural red flags. The customer is reluctant to appear on camera, uses a document that looks edited, or provides inconsistent explanations for the source of funds.
- Sanctions or PEP hits. A screening match, even a partial one, needs officer review before the relationship proceeds.
- Unexplained urgency. Pressure to settle a transaction quickly, especially combined with an unfamiliar payment source, warrants a second look rather than accommodation.
When any of these appear, pause the designated service, escalate to your AML/CTF compliance officer, and seek additional verification before continuing. Where reasonable suspicion exists that a matter may relate to money laundering, terrorism financing or that identity information is false, lodge a suspicious matter report under section 41. Record the rationale, the approvals given and the evidence reviewed. That file needs to survive scrutiny for the full seven year retention period, not just satisfy you on the day.
A practical checklist for remote onboarding controls
Use this to audit your existing procedures or build a new remote verification workflow into your AML/CTF program:
- Collect know your customer information and apply a risk rating before verification begins, with clear thresholds for when enhanced due diligence kicks in.
- Maintain a documented list of acceptable ID types and electronic data sources, plus a separate procedure for alternative identification.
- Require a binding control (biometric liveness, or a documented video call where liveness isn’t used) on every remote file, not just high-risk ones.
- Run sanctions and PEP screening at onboarding and on a defined re-screening schedule.
- Keep tamper-evident records of every verification decision for seven years, with staff training refreshed regularly and governance reporting lines that make escalation obvious.
Pro Tip: Build your remote onboarding checklist into the same document as your AML/CTF program, not as a side procedure. A supervisor should be able to trace every remote verification decision back to a documented policy, not an email chain.
Why linked compliance documentation matters for remote verification

The hardest part of non face to face verification usually isn’t the technology. It’s keeping your risk assessment, your policies, your compliance plan and your staff training all saying the same thing. When those four documents are built separately, inconsistencies creep in, and that’s exactly what a supervisor probes first.
An integrated platform that generates document capture, biometric liveness checks, sanctions and PEP screening, and beneficial ownership lookups against a company’s ACN from one linked set of program artefacts removes that inconsistency risk. Trusts and SMSFs are reached through their corporate trustee’s own ACN determination, not a single automated trace across structures. AML Guard retains records in a tamper-evident audit trail, above the statutory seven-year minimum, and firms typically begin with a demo before their tenant is configured to their designated services and risk profile, month-to-month or on a 12-month term.
How AML Guard supports compliant remote onboarding
If your firm is still stitching together spreadsheets, email trails and a manual sanctions check for every remote customer, the real cost isn’t the software you’re not paying for. It’s the hours your compliance officer spends reconstructing a file when AUSTRAC or an external auditor asks how a decision was made. AML Guard runs document capture, biometric liveness, sanctions and PEP screening, and ACN-based beneficial ownership checks through one workflow, with an officer approving each determination before the file proceeds.
Onboarding starts with a demo, after which your tenant is configured to your designated services and risk profile rather than a generic template. Firms choose month-to-month or a 12-month term, and a client-pays option lets the transaction party fund their own verification check, with verification fees credited back against the subscription. See current plans and per-check pricing on the pricing page, or review the full capability set on the features page before you book a time.
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
Sources
- Overview of initial customer due diligence | AUSTRAC
- Anti‑Money Laundering and Counter‑Terrorism Financing Rules 2025
FAQ
Does remote onboarding automatically require enhanced due diligence?
No. Enhanced due diligence is triggered by elevated ML/TF risk, and the delivery channel is only one factor among several AUSTRAC expects you to weigh, alongside customer type, product and jurisdiction. A low-risk domestic customer verifying remotely doesn’t need the same scrutiny as a high-risk overseas entity doing the same thing.
What counts as reliable and independent data for online verification?
It means data sourced from a party unconnected to the customer, ideally with a government-backed lineage, matched against the identity details provided. AUSTRAC requires this data be appropriate to the customer’s risk, which sometimes means checking more than one source.
How long must we keep remote verification records?
Seven years is the legal minimum under the Act for verification records and the decisions behind them. Some compliance platforms, including AML Guard’s audit trail, retain records for 8 years, but seven years remains the statutory obligation you must meet regardless of what any vendor offers.
Is a video call as good as biometric liveness checking?
They’re both legitimate controls, but they’re not equivalent. Biometric liveness technically binds the live person to their document image, while a video call is a documented alternative that relies more heavily on officer judgement and should carry compensating measures where used in place of liveness.
What should we do if a remote customer’s documents don’t match?
Pause providing the designated service, escalate to your AML/CTF compliance officer, and seek further verification before continuing. If reasonable suspicion arises that the information is false or connected to money laundering, lodge a suspicious matter report under section 41 and retain the full evidence file.
Recommended
- Tranche 2 AML Australia: your compliance obligations explained
- Tranche 2 customer due diligence in Australia
- AML/CTF Program Documents for Tranche 2
- Acceptable ID documents for Tranche 2 firms
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.