KYC Due Diligence
KYC establishes who a customer is. Identity verification, screening and enhanced due diligence run here, with the evidence for each check stored as it happens. Business customers are covered on the KYB verification page.
From first check to enhanced due diligence
Start with the check the relationship needs; escalate when risk says so.KYC
Enhanced due diligence
Verifying a business and the people behind it? See KYB verification.
Why due diligence is the core of a compliance program
Customer due diligence is the obligation everything else in the AML/CTF Act hangs off.AML/CTF obligation
CDD before providing a designated service is required for every customer.
Business customers
When the customer is a company, due diligence escalates to KYB verification: the entity, its officers, and who controls it.
Risk-based approach
Low-risk customers get a fast check; high-risk customers get depth. The same tooling covers both ends.
Audit evidence
Each check stores what was checked, the source and the result: the file an auditor asks for first.
Where the checks run
Pick by how your team works; the checks and results are the same.Runs CDD as a program: onboarding checks, risk ratings, ongoing monitoring and the alert queue in one place.
The data behind enhanced due diligence: person history, court records, associates and linked entities.
arrow_forward api Global Data APIIntegrationASIC, Court, PEP/Sanction and company risk endpoints run the same checks from your own systems.
arrow_forwardAPI endpoints
Request schemas and example calls are in the API reference. Sandbox available for integration testing.What is the difference between KYC and KYB?
add
KYC verifies an individual: identity documents, personal details and screening.
KYB verifies a business: registration, officeholders and ownership. It then runs KYC-style checks on the people who control it.
They are not alternatives. Onboarding a company almost always involves both, because verifying that an entity is validly registered tells you nothing about whether the people behind it are sanctioned, disqualified, or the same individuals who appear behind three other entities you have already declined. KYB verification covers the business side in detail.
What counts as a reliable and independent source?
add
Government records and licensed independent data. In practice that means the DVS, ASIC registers, the AEC electoral roll, and licensed reference data.
AUSTRAC's standard is reliable and independent, and the second word is where most of the work is. Self-reported details do not qualify no matter how thoroughly they are collected: a customer confirming their own address is not independent verification of it, and neither is a utility bill they supplied themselves.
Independence means the confirmation comes from a source with no interest in the outcome, which is why the check goes to the issuing authority or to reference data instead of back to the customer.
When does enhanced due diligence apply?
add
When your risk assessment triggers it. The common triggers are:
- Politically exposed persons
- Customers connected to high-risk jurisdictions
- Complex or opaque ownership structures
- Escalations arising from ongoing monitoring
The specific triggers are yours to define; that is what a risk-based program means. What matters for compliance is that the triggers are written down, applied consistently, and evidenced when they fire, instead of being applied case by case according to whoever happened to review the file.
What does enhanced due diligence add?
add
Depth of source. Standard KYC establishes identity and screens against sanctions and PEP lists. EDD adds court records, adverse media coverage and social intelligence, building a picture of the person beyond a confirmation of their details.
Is customer due diligence a point-in-time check or ongoing?
add
Both, and the second half is where programs most often fall short.
Verification happens at onboarding. The obligation to keep customer information current continues for the entire life of the relationship: a customer who was low risk three years ago may since have become a PEP, moved to a high-risk jurisdiction, or appeared on a sanctions list.
Monitors re-check when registers or lists change, so the update is triggered by the event rather than waiting for a scheduled review. The alternative is a file that is accurate on the day it was opened and progressively less accurate every day after.
Which data sources are used?
add
Six, and every result names the source it came from:
- The DVS, for identity documents
- An Australian reference universe of roughly 2 billion records
- ASIC company data
- More than 40 million court records
- Global PEP and sanctions lists, covering 268+ countries
- Adverse media coverage
Naming the source on each result is not a presentational detail. When a finding is disputed, or when an auditor asks why a customer was rated as they were, the answer has to identify what was checked and where it came from.
How does a risk-based approach work in practice?
add
Low-risk customers get a fast check; high-risk customers get depth. The same tooling covers both ends, and the customer's rating decides which applies.
This is not a convenience. AUSTRAC requires a risk-based program, which presumes you have a working method for rating customers and a defined relationship between the rating and the checks that follow.
The practical effect is that depth is allocated where it is warranted. Applying enhanced due diligence to every customer is unaffordable; applying standard checks to every customer is indefensible. The rating is what makes the difference between those two positions.
What evidence is kept for each check?
add
What was checked, the source it was checked against, and the result, all stored as the check happens and not compiled afterwards.
This is the file an auditor asks for first, and the reason it is stored automatically is that retrospective compilation does not really work. Reconstructing a year of due diligence after a notice arrives means reconstructing it under time pressure, from systems that were not designed to be asked the question.
Records are retained to the seven-year requirement in the AML/CTF Act and can be exported at any time.
Other solutions
Document Verification Service
Authenticate Australian identity documents against the DVS and confirm the details match authoritative sources.
Read morearrow_forward account_balance_walletIdentity verification
Verify identity documents against the DVS and personal details against Australian data sources.
Read morearrow_forward familiar_face_and_zoneBiometrics & liveness
Facial matching, liveness detection and OCR document capture for remote verification.
Read morearrow_forwardRequest a demo of our solutions
Complete the form and our team will be in touch shortly to walk you through how it works.
SOME OF OUR TRUSTED CLIENTS
Request a Demo
"*" indicates required fields
