Skip to content
In force

Tranche 2 started 1 July — AML/CTF obligations now extend beyond financial services.

See who is coveredarrow_forward
WatchEyeOnboarding & monitoring

Customer onboarding, screening and ongoing monitoring in one system, with real-time KYC and KYB alerts when a customer's risk changes.

Visit WatchEyearrow_forwardcheck_circleIncluded in the Global Data Portal
IDFEX ID CheckIdentity verification

One-to-one identity, document and data checks against the DVS and Australian data sources, run from the Portal or by API.

Visit IDFEX ID Checkarrow_forwardcheck_circleIncluded in the Global Data Portal
ID PassSelf-service verification

Customers verify their own identity and biometrics from a link on their phone. The result comes back to you, and they keep control of their data.

Visit ID Passarrow_forwardcheck_circleIncluded in the Global Data Portal
InsiightData quality

Verifies, corrects and enriches customer records so they stay accurate — one at a time or across your whole database.

Visit Insiightarrow_forwardcheck_circleIncluded in the Global Data Portal
Australian Death CheckDeceased data

The official national death data source. Match your records against it to find and remove deceased individuals.

Visit Australian Death Checkarrow_forwardcheck_circleIncluded in the Global Data Portal
QuesterMarketing lists

Build targeted, privacy-compliant Australian marketing lists with smart filters. Pay only for the records you download.

Visit Questerarrow_forwardcheck_circleIncluded in the Global Data Portal
verified_userVerify identities7 solutions

Confirm a person or business is who they claim to be: government IDs, biometrics, business registries and employment checks against authoritative Australian sources.

All solutionsarrow_forwardcheck_circleAvailable in the Portal and by API
policy_alertStay compliant6 solutions

Meet AUSTRAC obligations and understand customer risk: screening, risk assessment, fraud controls and investigation tools with evidence recorded for each check.

All solutionsarrow_forwardcheck_circleAvailable in the Portal and by API
databaseImprove your data3 solutions

Keep customer records accurate and put them to work: correct and enrich existing data, unify it into a single view, or build compliant marketing lists from opted-in records.

All solutionsarrow_forwardcheck_circleAvailable in the Portal and by API
monitoringWatchEye API14 categories

The WatchEye API gives programmatic access to everything in WatchEye: PEP and sanctions screening, identity checks, IDPass verifications, monitoring programs, events and reports.

View allarrow_forwardcheck_circleSandbox environment for integration testing
policyAML & screening6 use cases

Obligations under the AML/CTF Act, from screening at onboarding through to ongoing monitoring — with the evidence for each check recorded.

All use casesarrow_forwardcheck_circleMapped to the products and data that cover it
how_to_regOnboarding & identity3 use cases

Verifying who a customer, employee or account holder is — at sign-up and during ongoing checks — against authoritative Australian sources.

All use casesarrow_forwardcheck_circleMapped to the products and data that cover it
databaseData & enrichment4 use cases

Keeping customer records accurate, current and complete: validate contact detail, fill the gaps, locate people and remove deceased records.

All use casesarrow_forwardcheck_circleMapped to the products and data that cover it
Global Data
Portalarrow_forward
Productsexpand_more
Solutionsexpand_more
Use casesexpand_more
Dataexpand_more
APIarrow_forwardIndustriesarrow_forwardResourcesarrow_forwardAboutarrow_forwardContactarrow_forward Request a Demo
Talk to the team

9am–5pm AEST, Monday to Friday.

call03 9948 4089
WatchEye · IDPass

Launch an adhoc IDPass

Launching an adhoc IDPass creates a remote identity verification for a person with no entity record. Instead of your system submitting document details, the individual opens a secure hosted link to photograph their documents, complete a liveness check and give consent. The call returns 202 with the link, and the result is collected from Show an IDPass once the individual has finished.

  • Up to three document steps, each DVS-verified, with an optional face liveness check compared against the document photos
  • The link is delivered by SMS or returned for you to send, and stays open for 1 to 14 days
For developers

After the technical detail?

For the technical detail, go to the API documentation. It holds the request and response schema, the integration guides and the error codes for this endpoint.

  • Request and response schema
  • Configuration, document types and delivery
Go to the API docs

New accounts begin with sandbox access.

ISO 27001 certified Handled under Australian privacy law Every API call written to the audit log
What the check gives you

Verifying someone remotely, without adding them to a program

A one-off applicant can be verified without an entity record. They photograph the documents you allow, pass a liveness check if you turn it on, and consent on a page that names your organisation and links your privacy policy. If no date of birth is supplied the documents are still fully DVS-verified and matched to the supplied name only.

What exists at launch

The response carries the IDPass UUID, its configuration and delivery details, the hosted link, when it was sent by SMS, the path to poll and the ID check it belongs to. The outcome, summaries, log and images come from Show an IDPass once the individual has finished.

What the individual is asked for

Each configured step accepts the document types you allow: Australian driver licence, passport, Medicare card, a foreign passport with an Australian visa, Centrelink card, birth certificate or New Zealand driver licence. Liveness, a standalone ID photo with its stated purpose, and a return URL are each optional.

That the account was ready to run it

The account needs the IDPass product and a DVS identity with a privacy policy URL. A launch missing either returns 403, insufficient credit returns 402, and a configuration error such as a step reusing an earlier step's document type returns 400.

That a retry will not create a second link

An optional Idempotency-Key header returns the original response on a retry with the same key and body, so a dropped connection cannot create or charge the IDPass twice.

How a check runs

A link the individual completes, then a result you collect

The launch returns 202 with the hosted link. The individual opens it, consents and submits their documents, and the status moves through new, opened and in progress. Your system polls Show an IDPass until the status is terminal, then reads the verification status.

Poll every few seconds at first, then every 30 to 60 seconds; the link validity of 1 to 14 days is the upper bound. Treat the hosted link as opaque and pass it on exactly as returned.

Reading the result

What each answer means for the record in front of you

The status says where the individual is in the hosted flow. Once it reaches a terminal value, the verification status carries the outcome.

Passed

The identity was verified

The status is complete and the verification status is passed. The validation summary carries the verified identity established across the documents, the per-document results and, where liveness was on, the biometric comparison. The certificate PDF is available.

Review

Verified, but flagged for review

The identity was verified but has been flagged for review in the portal. Treat it as not yet passed until it has been looked at. Manual correction of the result is a portal-only function.

Failed

Not verified, or the link was not completed

The verification status is failed when the identity was not verified, and also when the IDPass expired or was cancelled. The verification description gives the reason, and the activity log shows each step the individual attempted.

What it costs

Charged at creation, by the number of document steps configured

Each IDPass launch is charged to your WatchEye account when it is created. The product billed depends on how many document verification steps are configured, from one to three. If the link is never used and expires, the launch charge is refunded. Rates are set for your account and communicated by your Global Data account manager.

  • Billed at creation
  • Refunded if the link expires unused
How billing works
Credits drawn down against your account balance
  • A launch is charged when the IDPass is created.
  • The product billed follows the number of document steps: one, two or three.
  • A link that lapses unused moves the IDPass to expired and the launch charge is refunded.
  • A 402 response means the account has reached its credit or call limit. Nothing is run and nothing is charged.
Talk to us about rates
Related checks

Others in WatchEye IDPass

Show an IDPass collects the result. List IDPasses finds them. Download an IDPass certificate as PDF and Download an IDPass image produce the evidence. Launch an IDPass against an entity runs the same flow for a person you monitor.

Questions

Questions we get asked about adhoc IDPasses

Do we need a developer to implement this?
Yes. The launch is a REST call that returns the hosted link, and a second call collects the result, so a developer connects the two-step flow and the link delivery to your system. A sandbox account is available for development at no charge. It is a separate account with its own API keys, it returns test data in the same response shapes as live, and the same base URL serves both environments.
What does our system need to send?
A data object with a first name or last name and an optional date of birth in YYYY-MM-DD format, plus a config object: the link validity in days from 1 to 14, whether to check liveness, the allowed document types for step one and optionally steps two and three, whether an ID photo is required and its purpose, an optional return URL, whether to retain verification images, and the delivery method with a mobile number when it is SMS.
Which documents can the individual present?
For each step, any of: Australian driver licence, Australian passport, Medicare card, a foreign passport with an Australian visa, Centrelink card, Australian birth certificate, or New Zealand driver licence. Centrelink cards and birth certificates are typed in rather than photographed. Up to three steps can be configured, and a step cannot reuse a document type consumed by an earlier step.
What comes back?
A 202 with the IDPass shell: its UUID, source, the requester name shown on the consent page, the configuration as applied, the hosted link, the delivery method and when the link was sent, the created at time, the path to poll and the ID check it belongs to.
How long does it take?
As long as the individual takes. Poll Show an IDPass every few seconds at first, then back off to every 30 to 60 seconds, with the link validity of 1 to 14 days as the upper bound. The status moves from new to opened when the link is opened, to in progress once consent is given, and then to complete, expired, failed or cancelled.
What does our account need?
The IDPass product, and a DVS identity, the Originating Agency Code, with a privacy policy URL configured. The OAC supplies the requester name and privacy policy shown to the individual on the consent page. A launch without these returns 403.
What does it cost?
Each launch is charged at creation. The product billed depends on the number of document verification steps configured. A link that lapses unused moves the IDPass to expired and the launch charge is refunded. The PDF and image endpoints are not billed.
How do we test it?
Against a sandbox account. Sandbox calls are not charged and the response shape is identical to live, so your code does not branch on environment. IDPasses work end to end in sandbox. Open the hosted link yourself and upload one of the synthetic test documents listed in the IDPass test documents guide. No SMS is sent in sandbox; the link is still returned in the response.
Getting started

The first step to access is a conversation

Sandbox accounts are provisioned by your Global Data account manager. API keys are created and managed in the WatchEye portal, and the same endpoints serve sandbox and live; the account behind the key decides which environment you are in.

Call 03 9948 4089, 9am–5pm AEST Monday to Friday

ISO 27001 certified
Handled under Australian privacy law
Every API call written to the audit log