Verifying identity remotely under Tranche 2

Verifying identity remotely under Tranche 2

How to verify identity when you never meet the customer: independent data sources, document authenticity, liveness, and when to escalate a file.

AML/CTF Compliance 20 September 2026 9 min read AML Guard

Customer completing remote identity verification

Yes, non face to face verification is permitted in Australia, provided your AML/CTF program makes you reasonably satisfied of the customer’s identity using reliable and independent data appropriate to their ML/TF risk. Remote onboarding does not, by itself, trigger enhanced customer due diligence; the delivery channel is one risk factor among several. The two controls that close the gap remote channels create, which is impersonation, are document authenticity checks and biometric liveness, or a documented video call where liveness isn’t practical.


TL;DR:


AML Guard
Simplify Remote Customer Due Diligence
AML Guard brings identity verification, biometric liveness, screening and linked AML/CTF program artefacts into one Australian compliance platform.
Book a demo

Table of Contents

What the law requires for remote identity verification in Australia

Every Tranche 2 reporting entity must complete initial customer due diligence before providing a designated service. That means establishing, on reasonable grounds, the customer’s identity, their authority to act, relevant beneficial ownership matters, and the nature and purpose of the business relationship. AUSTRAC is explicit that this must rest on reliable and independent data appropriate to the customer’s money laundering and terrorism financing risk, not on whichever document happens to be easiest to obtain.

The AML/CTF Rules 2025 set out the mechanics. Part 4.9 covers verification from electronic data, Division 8 governs reliance on know your customer information collected by another party, and Part 4.15 deals with alternative proof of identity for customers who lack standard documents. These provisions apply whether the customer walks into your office or verifies from a laptop interstate.

Three obligations sit underneath all of this, regardless of channel:

How do you verify identity without meeting someone in person?

Real, secure online verification in Australia rests on three layers working together, not any single check in isolation.

  1. Electronic data verification. Match the customer’s name, date of birth and address against reliable, independent data sources, preferably ones with a government-backed lineage. AUSTRAC’s guidance and the Rules contemplate using multiple independent data sources where a single source doesn’t give you sufficient confidence, particularly for higher risk customers.
  2. Document capture with authenticity checks. Require a quality image or scan of the identity document, check the expiry date, look for tampering indicators, and use a document verification service where your risk assessment calls for it. A blurry phone photo of a driver licence, on its own, tells you almost nothing about whether that licence is genuine.
  3. Biometric liveness. This is what binds the person in front of the camera to the document they’ve submitted. A selfie matched against a photo ID, captured with liveness detection, addresses the specific vulnerability that non in-person verification methods create: someone using a stolen or borrowed identity document without ever being physically present.

A video call is a legitimate alternative control where liveness technology isn’t available or appropriate, and AUSTRAC’s own guidance on remote KYC procedures references video calls, selfies and scanned documents as acceptable measures. A video call is not, however, a substitute for biometric matching. It’s a different control with different evidentiary value, and your program should document why you’ve chosen one over the other for a given customer segment.

Sanctions, PEP and adverse media screening should run at onboarding and again on a scheduled basis afterwards, not as an afterthought once the file is closed.

Pro Tip: Don’t treat “remote” as a single risk category. A returning customer verifying a second property purchase online carries a different risk profile to a first-time overseas buyer paying via an unfamiliar intermediary. Calibrate your controls to the customer, not the channel.

What if a customer doesn’t have standard identification?

Some customers genuinely can’t produce a driver licence or passport, and AUSTRAC’s guidance on assisting customers without standard ID sets out acceptable alternatives rather than leaving you to refuse service outright. These typically include:

Accepting an alternative doesn’t mean accepting it uncritically. Verify the issuer’s reliability where you can. That might mean phoning the referee’s stated employer through an independently sourced number, confirming government correspondence through an official contact channel, or cross-checking details against other records the customer provides. Where a standard document becomes available later, obtain it and update the file.

Document the specific procedure you followed in your AML/CTF program, not just the outcome. A supervisor reviewing the file six months later needs to see why the alternative was accepted, who approved it, and what compensating steps were taken. If the customer’s overall risk profile is elevated for other reasons, layering enhanced due diligence on top of an alternative ID pathway is often the right call.

When should you re-verify identity or escalate a file?

Certain triggers should prompt you to stop, re-verify or escalate rather than proceeding on the original file:

  1. Data mismatches. The name, date of birth or address on a document doesn’t match other records, or electronic verification returns a partial or failed match.
  2. Behavioural red flags. The customer is reluctant to appear on camera, uses a document that looks edited, or provides inconsistent explanations for the source of funds.
  3. Sanctions or PEP hits. A screening match, even a partial one, needs officer review before the relationship proceeds.
  4. Unexplained urgency. Pressure to settle a transaction quickly, especially combined with an unfamiliar payment source, warrants a second look rather than accommodation.

When any of these appear, pause the designated service, escalate to your AML/CTF compliance officer, and seek additional verification before continuing. Where reasonable suspicion exists that a matter may relate to money laundering, terrorism financing or that identity information is false, lodge a suspicious matter report under section 41. Record the rationale, the approvals given and the evidence reviewed. That file needs to survive scrutiny for the full seven year retention period, not just satisfy you on the day.

A practical checklist for remote onboarding controls

Use this to audit your existing procedures or build a new remote verification workflow into your AML/CTF program:

Pro Tip: Build your remote onboarding checklist into the same document as your AML/CTF program, not as a side procedure. A supervisor should be able to trace every remote verification decision back to a documented policy, not an email chain.

Why linked compliance documentation matters for remote verification

Why linked compliance documentation matters for remote verification

The hardest part of non face to face verification usually isn’t the technology. It’s keeping your risk assessment, your policies, your compliance plan and your staff training all saying the same thing. When those four documents are built separately, inconsistencies creep in, and that’s exactly what a supervisor probes first.

An integrated platform that generates document capture, biometric liveness checks, sanctions and PEP screening, and beneficial ownership lookups against a company’s ACN from one linked set of program artefacts removes that inconsistency risk. Trusts and SMSFs are reached through their corporate trustee’s own ACN determination, not a single automated trace across structures. AML Guard retains records in a tamper-evident audit trail, above the statutory seven-year minimum, and firms typically begin with a demo before their tenant is configured to their designated services and risk profile, month-to-month or on a 12-month term.

How AML Guard supports compliant remote onboarding

If your firm is still stitching together spreadsheets, email trails and a manual sanctions check for every remote customer, the real cost isn’t the software you’re not paying for. It’s the hours your compliance officer spends reconstructing a file when AUSTRAC or an external auditor asks how a decision was made. AML Guard runs document capture, biometric liveness, sanctions and PEP screening, and ACN-based beneficial ownership checks through one workflow, with an officer approving each determination before the file proceeds.

Onboarding starts with a demo, after which your tenant is configured to your designated services and risk profile rather than a generic template. Firms choose month-to-month or a 12-month term, and a client-pays option lets the transaction party fund their own verification check, with verification fees credited back against the subscription. See current plans and per-check pricing on the pricing page, or review the full capability set on the features page before you book a time.

This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.

Sources

FAQ

Does remote onboarding automatically require enhanced due diligence?

No. Enhanced due diligence is triggered by elevated ML/TF risk, and the delivery channel is only one factor among several AUSTRAC expects you to weigh, alongside customer type, product and jurisdiction. A low-risk domestic customer verifying remotely doesn’t need the same scrutiny as a high-risk overseas entity doing the same thing.

What counts as reliable and independent data for online verification?

It means data sourced from a party unconnected to the customer, ideally with a government-backed lineage, matched against the identity details provided. AUSTRAC requires this data be appropriate to the customer’s risk, which sometimes means checking more than one source.

How long must we keep remote verification records?

Seven years is the legal minimum under the Act for verification records and the decisions behind them. Some compliance platforms, including AML Guard’s audit trail, retain records for 8 years, but seven years remains the statutory obligation you must meet regardless of what any vendor offers.

Is a video call as good as biometric liveness checking?

They’re both legitimate controls, but they’re not equivalent. Biometric liveness technically binds the live person to their document image, while a video call is a documented alternative that relies more heavily on officer judgement and should carry compensating measures where used in place of liveness.

What should we do if a remote customer’s documents don’t match?

Pause providing the designated service, escalate to your AML/CTF compliance officer, and seek further verification before continuing. If reasonable suspicion arises that the information is false or connected to money laundering, lodge a suspicious matter report under section 41 and retain the full evidence file.

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 20 September 2026.