AML/CTF Compliance
Customer identification, watchlist screening and ongoing due diligence as running capabilities, each leaving the records AUSTRAC expects. For the obligations themselves, start from the AML/CTF compliance use case.
Three capabilities, one program
Each has its own page. This one shows how they fit together.Customer identification
Screening
Ongoing CDD
Problem-first reading: the AML/CTF compliance, watchlist screening and Tranche 2 use cases.
Why the capability has to be running, not written down
A program document describes intent. AUSTRAC audits what ran.AUSTRAC enforcement
Recent penalties have turned on programs that existed on paper but didn't run in practice.
Tranche 2 scope
Tens of thousands of newly regulated firms now carry the same obligations, without compliance departments.
Board accountability
Governing bodies must be able to show oversight. Dashboards and check records are what that looks like.
Evidence on demand
When a notice arrives, the response window is short. Records that already exist are the difference.
Where the checks run
Pick by how your team works; the checks and results are the same.API endpoints
Request schemas and example calls are in the API reference. Sandbox available for integration testing.What does AUSTRAC expect an AML/CTF program to contain?
add
Six things, and AUSTRAC expects each of them to be both documented and demonstrably operating:
- An ML/TF risk assessment covering your designated services, customers, channels and jurisdictions
- Customer identification procedures — how you establish who a customer is before providing a designated service
- Screening against sanctions, PEP and other watchlists
- Ongoing customer due diligence for the life of the relationship
- Reporting processes for suspicious matters, threshold transactions and annual compliance reports
- Governance and oversight, including accountability at board level
The program itself is your document, sized to your business and your risk assessment. What this page covers is the three capabilities that have to run underneath it: identification, screening and ongoing due diligence, plus the record each one leaves behind.
Our program is written and approved. Isn't that the compliance job done?
add
A program document describes intent. AUSTRAC audits what ran.
Recent enforcement action has turned on precisely this gap: programs that existed on paper but were not operating in practice, with screening that was specified but not performed and due diligence that was scheduled but never evidenced. The document is necessary, but on its own it is not enough.
The test is whether you can produce, for any given customer, the record of which checks ran, when, against which source, and with what result. If that record exists as a by-product of the checks themselves, the program is running. If it has to be reconstructed after a notice arrives, it is not, and the response window for a notice is short.
Which checks make up customer identification?
add
Two, and most programs specify both:
- Document verification — an identity document checked against the issuing authority's own record through the government's Document Verification Service, across all 14 accepted document types
- Data verification — name, address, date of birth, phone and email matched field by field against an Australian universe of more than 2 billion records
They are run together because they answer different questions. The document check proves the credential is genuine; the data check proves the details belong to a real, living person. A genuine document presented by someone who is not its holder passes the first and fails the second.
What does the screening cover?
add
Sanctions lists, politically exposed persons, and criminal and regulatory watchlists, with coverage across more than 268 countries and territories, updated in real time as the source lists change.
Screening is not limited to individuals. Companies and vessels are screened through the same endpoint, which matters when you are onboarding a business instead of a person, and adverse media coverage can be added for both people and businesses where your risk assessment calls for enhanced due diligence.
Matching rules are configurable, so you decide how closely a name has to match before an alert is raised. That is the main lever on false positive volume.
How is screening frequency set?
add
Screening at onboarding is standard. After that, re-screening runs on a schedule you set per monitor.
The available schedules are daily, weekdays only, weekends only, a specific weekday, the 1st of the month, the 15th, the 1st and 15th, or quarterly. There is also a run-on-demand option for monitors you would rather trigger yourself. Scheduled monitors run automatically overnight, and you are emailed if new events were raised.
Because each monitor carries its own schedule, you can run the sources that matter most more often than the rest: PEP and sanctions daily, adverse media weekly, court screening quarterly. That avoids paying to run everything at the highest frequency. Your risk tiers decide which cadence applies to whom, and the schedule you chose is itself part of the evidence that the program was operating as designed.
What records are kept for each check?
add
Five fields, on every check: the subject, the source it was checked against, the result, the timestamp, and the operator who ran it. Screening results, events and the review trail are all stored as the check happens.
Retention is a setting, not a default. Each program has its own retention period, from no retention at all up to 84 months (the seven years the AML/CTF Act requires). The default is 12 months. If you are relying on these records to meet the seven-year obligation, the program must be configured that way deliberately; the out-of-the-box setting will not get you there.
Records can be exported at any point, for an internal audit, an external review, or a response to a regulator. Because the record is a by-product of the check itself, there is no separate filing step to be missed.
How is Tranche 2 different?
add
Same Act, same obligations, different scale.
Tranche 2 brought tens of thousands of newly regulated firms into the regime: lawyers, conveyancers, accountants, real estate professionals, dealers in precious metals and stones, and trust and company service providers. They carry the same obligations as long-established reporting entities, generally without a compliance department to run them.
That changes how the capability is delivered, not what it has to achieve. Tranche 2 firms typically run checks from the portal instead of building an integration, and their programs are sized to a handful of designated services. The Tranche 2 use case covers the detail.
Do we need an integration, or can our team run this from a browser?
add
Either. The same checks run and the same records are produced whichever way you work:
- IDFEX ID Check — customer identification one at a time, from the portal
- WatchEye — screening, monitoring, risk tiers and the alert queue in one platform, with per-check records kept automatically
- Caspar — the deeper sources for enhanced due diligence, when a customer's risk rating demands more
- API — PEP and sanction, Global Data Check, DVS and adverse media endpoints inside your own systems
Most organisations start in the portal and integrate later, once the process has settled and the volume justifies it.
Other solutions
Risk assessment
Score customer risk from verified data and set the checks each risk tier requires.
Read morearrow_forward securityFraud prevention
Detect stolen and synthetic identities before an account is opened.
Read morearrow_forward person_searchInvestigation tools
Search tools for locating people and assembling background information on them.
Read morearrow_forwardRequest a demo of our solutions
Complete the form and our team will be in touch shortly to walk you through how it works.
SOME OF OUR TRUSTED CLIENTS
Request a Demo
"*" indicates required fields
