You have to know who you are dealing with before you deal with them, and the record of how you found out is part of the obligation. From 1 July 2026 your firm became a reporting entity, a business that provides a designated service and so carries AML/CTF obligations, and you must establish the identity of your customer before you provide that service. The Act puts it in those words at s28.
If you have read older guidance, put one term aside. Safe harbour is gone. It was the prescriptive verification procedure in Chapter 4 of the previous AML/CTF Rules, and it stopped applying on 30 June 2026, the day before Tranche 2 commenced. What replaced it is risk-based: you decide how far to verify by reference to the customer’s money laundering and terrorism financing risk, and you carry the judgement rather than a checklist.
A designated service is a service the Act lists in its tables, set out in s6. The person who requests or initiates one is your customer for these purposes, which matters because the obligation attaches to them rather than to whoever happens to be in the room.
Customer due diligence is the whole of that work: collecting identity information, verifying it against a source you can point to, and recording how you did it. The point of the exercise is that the person you think you are dealing with is the person you are actually dealing with, and that you can show how you know. Collection is where most firms are comfortable. The other two parts are where compliance actually happens, and where the rest of this page spends its time.
What you collect, how you verify it, what you keep
For an individual, collect full name, any other name they are commonly known by such as a former or anglicised name, date of birth, residential address, and a unique identifier if they have one: a passport number, driver licence number or foreign national identity number. The point of that list is to tell your customer apart from someone else with a similar name.
What you then have to verify is narrower. The baseline target is full name and date of birth, because those are the details that stay with a person across a lifetime. Two routes get you there:
| Route | Documents required |
|---|---|
| A government-issued primary photographic document, such as a current driver licence, passport, proof-of-age card or foreign national identity card | One is enough |
| A primary non-photographic document, such as a birth certificate, citizenship certificate or concession card | Two: that document, plus a secondary one showing name and address, such as a utility bill or a notice from a government body |
An electronic check that confirms name and date of birth against a primary photographic document does the same job as sighting it. For a low-risk individual, one photographic document, or its electronic equivalent, meets the baseline. Higher risk means going further, and that judgement is yours to make and to record.
For a company, a trust or a partnership, identification extends past the entity to its beneficial owners, the natural persons who ultimately own or control it. Where you can stop digging into a structure is the question on the beneficial ownership page.
| Customer type | What identification reaches |
|---|---|
| Individual | The person |
| Company | The company’s name and registration details, plus each beneficial owner as an individual |
| Trust | The trust, the trustee, and the beneficial owners as individuals |
| Partnership | The partnership, the partners, and the beneficial owners as individuals |
All of it has to be done before the service is provided. In practice that means before you act on the customer’s instructions, not before you finish the paperwork on the day. Identification is a condition of providing the service at all, not an admin step you can catch up on later. A narrow, conditional allowance for conveyancing buyers, where verification can finish after settlement begins, is covered on the delayed CDD page; treat it as an exception to plan around, not a reason to defer.
Collecting a document is not verifying it. Verification means checking the identity information against a reliable, independent source and satisfying yourself that the document is authentic and belongs to the applicant. A photocopy in the file does none of that by itself: the document has to be inspected, matched to the person presenting it, and the match recorded. Most firms verify electronically, because the source is independent of the customer; a document the customer hands you is only as good as your check of it.
Because the standard is risk-based rather than prescriptive, there is no procedure you can follow to the letter and stop thinking. The obligation is an outcome: establish who the customer is. A low-risk individual with a current passport is quick. A customer with a layered corporate structure, or one who trips a risk factor, is not, and the file has to show you went further because you decided the risk called for it.
That cuts both ways. Nothing certifies your method in advance, so the burden of showing it was adequate sits with you. But nothing confines you to a fixed document count either, which is what the old safe harbour did. Whichever route you take, the record must show which one it was and why, because the method is the first thing a reviewer looks for.
Identification is also only the start. The relationship needs attention while it is live, and some customers trigger enhanced customer due diligence (ECDD), a deeper set of checks covered on the enhanced due diligence page.
What you record matters as much as what you verify. For every customer the file should hold the identity information collected, the evidence it was checked against, the route you took and why, the source reference IDs such as document numbers, who did the work and when, and the outcome. The decision about which method to use, and why, is itself a record. The file has to be reconstructable by someone who was not there, which is why the evidence itself matters, not just a tick next to the customer’s name. All of it is retained for seven years, and the full shape of that obligation is on the record-keeping page.
One shortcut exists, with conditions attached. Where another reporting entity has already verified the customer, you can rely on that work instead of repeating it; what the arrangement requires, and what liability stays with you, is on the reliance page.
What catches people out
Three failures keep repeating across Tranche 2 firms.
-
A label is not a method: firms record that a customer was “verified” without recording what was actually done, often carrying the habit over from the old safe harbour tick-box. Under a risk-based standard the label carries nothing on its own. If the file does not show the check, the source and why it was proportionate to the risk, AUSTRAC reads the customer as unverified. The consequence lands at review, not at the time.
-
Collecting a document is not verifying it: the classic failure is a file full of passport copies that were received but never inspected, never matched to the applicant, never checked against the source that issued them. When a reviewer looks, every one of those customers is unverified, and you cannot show you took reasonable steps at the time.
-
The record of how you verified matters as much as the outcome: two firms can verify the same customer to the same standard. The firm whose record shows the method, the sources and the evidence gets credit for it; the firm whose file is bare does not. Seven years is a long time for a record to survive, and if the person who ran the checks leaves, the evidence goes with them unless the file stands alone.
What is still unsettled
Two things are still settling, and both are worth watching.
The exact data fields per entity type are not settled practice yet. The Rules were remade in 2025, and precisely what each customer type requires under the new structure is still being worked through by firms and advisers. Build your collection workflow against the reform guidance and expect to adjust it.
How far is far enough is the second, and it is the cost of a risk-based standard. The old regime told you to sight two documents and stop; this one asks you to establish identity and leaves the sufficiency to your judgement. AUSTRAC has not published worked examples of what an adequate record looks like at each risk level. Until it does, the safest record is the one that would convince a reviewer who was not there: what you checked, against what source, why that was proportionate to the risk you assessed, by whom and when.
Where to start
If you have not stood up customer due diligence yet, three things do most of the work:
- Map your applicants: work out which of your services are designated services and who requests them. Each of those people and entities is an applicant for a designated service and needs a file before you serve them.
- Choose the method path first: decide how you will verify, electronically against an independent source or manually against documents you inspect, and at which risk levels each applies. Write the decision down before the first customer. The choice cannot be reconstructed after the work.
- Record at the point of verification: capture the method path, the source reference IDs and the evidence while you do the check. Make the seven-year retention the named responsibility of your AML/CTF compliance officer (the AMLCO).
How duely handles this
The verification gate is the part worth knowing about. A check that has not actually been satisfied can never be marked as verified in duely: the status is derived from the evidence on the record rather than set by hand, so a matter cannot proceed on someone’s assurance that the ID was fine. Verification runs either as a link you send the customer, which they complete themselves, or as a structured manual check your staff record with the evidence attached. Either way the method, the source references and the person who did the work are all part of the record.