Skip to content
In force

Tranche 2 started 1 July — AML/CTF obligations now extend beyond financial services.

See who is coveredarrow_forward
WatchEyeOnboarding & monitoring

Customer onboarding, screening and ongoing monitoring in one system, with real-time KYC and KYB alerts when a customer's risk changes.

Visit WatchEyearrow_forwardcheck_circleIncluded in the Global Data Portal
IDFEX ID CheckIdentity verification

One-to-one identity, document and data checks against the DVS and Australian data sources, run from the Portal or by API.

Visit IDFEX ID Checkarrow_forwardcheck_circleIncluded in the Global Data Portal
ID PassSelf-service verification

Customers verify their own identity and biometrics from a link on their phone. The result comes back to you, and they keep control of their data.

Visit ID Passarrow_forwardcheck_circleIncluded in the Global Data Portal
InsiightData quality

Verifies, corrects and enriches customer records so they stay accurate — one at a time or across your whole database.

Visit Insiightarrow_forwardcheck_circleIncluded in the Global Data Portal
Australian Death CheckDeceased data

The official national death data source. Match your records against it to find and remove deceased individuals.

Visit Australian Death Checkarrow_forwardcheck_circleIncluded in the Global Data Portal
QuesterMarketing lists

Build targeted, privacy-compliant Australian marketing lists with smart filters. Pay only for the records you download.

Visit Questerarrow_forwardcheck_circleIncluded in the Global Data Portal
verified_userVerify identities6 solutions

Confirm a person or business is who they claim to be: government IDs, biometrics, business registries and employment checks against authoritative Australian sources.

All solutionsarrow_forwardcheck_circleAvailable in the Portal and by API
policy_alertStay compliant6 solutions

Meet AUSTRAC obligations and understand customer risk: screening, risk assessment, fraud controls and investigation tools with evidence recorded for each check.

All solutionsarrow_forwardcheck_circleAvailable in the Portal and by API
databaseImprove your data3 solutions

Keep customer records accurate and put them to work: correct and enrich existing data, unify it into a single view, or build compliant marketing lists from opted-in records.

All solutionsarrow_forwardcheck_circleAvailable in the Portal and by API
policyAML & screening6 use cases

Obligations under the AML/CTF Act, from screening at onboarding through to ongoing monitoring — with the evidence for each check recorded.

All use casesarrow_forwardcheck_circleMapped to the products and data that cover it
how_to_regOnboarding & identity3 use cases

Verifying who a customer, employee or account holder is — at sign-up and during ongoing checks — against authoritative Australian sources.

All use casesarrow_forwardcheck_circleMapped to the products and data that cover it
databaseData & enrichment4 use cases

Keeping customer records accurate, current and complete: validate contact detail, fill the gaps, locate people and remove deceased records.

All use casesarrow_forwardcheck_circleMapped to the products and data that cover it
Global Data
Portalarrow_forward
Productsexpand_more
Solutionsexpand_more
Use casesexpand_more
Dataexpand_more
APIarrow_forwardIndustriesarrow_forwardResourcesarrow_forwardAboutarrow_forwardContactarrow_forward Request a Demo
Talk to the team

9am–5pm AEST, Monday to Friday.

call03 9948 4089
Solution datasheet

AML/CTF Compliance

Customer identification, watchlist screening and ongoing due diligence as running capabilities, each leaving the records AUSTRAC expects. For the obligations themselves, start from the AML/CTF compliance use case.

Data universe
2BN+ records
Watchlists
Real-time updates
Screening
268+ countries
Records kept
7 years

Three capabilities, one program

Each has its own page. This one shows how they fit together.
badge

Customer identification

Who the customer is, against source records
KYC against government sources: DVS documents and per-field data verification.
14 DVS document typesData checks vs 2BN+ recordsSee Identity verification
policy

Screening

The customer isn't on a watchlist
Watchlist checks at onboarding, and again whenever the lists change.
Sanctions, PEP & criminal listsConfigurable matching rulesSee Watchlist screening
autorenew

Ongoing CDD

The relationship stays within risk appetite
Monitors and re-screening for the life of the customer relationship.
Re-checks on data changeRisk tiers set review depthAlerts queue with evidence

Problem-first reading: the AML/CTF compliance, watchlist screening and Tranche 2 use cases.

Why the capability has to be running, not written down

A program document describes intent. AUSTRAC audits what ran.
gavel

AUSTRAC enforcement

Recent penalties have turned on programs that existed on paper but didn't run in practice.

assured_workload

Tranche 2 scope

Tens of thousands of newly regulated firms now carry the same obligations, without compliance departments.

groups

Board accountability

Governing bodies must be able to show oversight. Dashboards and check records are what that looks like.

history_edu

Evidence on demand

When a notice arrives, the response window is short. Records that already exist are the difference.

API endpoints

Request schemas and example calls are in the API reference. Sandbox available for integration testing.
helpFAQ

Common questions

Something not covered? Ask our team.

What does AUSTRAC expect an AML/CTF program to contain?

add

Six things, and AUSTRAC expects each of them to be both documented and demonstrably operating:

  • An ML/TF risk assessment covering your designated services, customers, channels and jurisdictions
  • Customer identification procedures — how you establish who a customer is before providing a designated service
  • Screening against sanctions, PEP and other watchlists
  • Ongoing customer due diligence for the life of the relationship
  • Reporting processes for suspicious matters, threshold transactions and annual compliance reports
  • Governance and oversight, including accountability at board level

The program itself is your document, sized to your business and your risk assessment. What this page covers is the three capabilities that have to run underneath it: identification, screening and ongoing due diligence, plus the record each one leaves behind.

Our program is written and approved. Isn't that the compliance job done?

add

A program document describes intent. AUSTRAC audits what ran.

Recent enforcement action has turned on precisely this gap: programs that existed on paper but were not operating in practice, with screening that was specified but not performed and due diligence that was scheduled but never evidenced. The document is necessary, but on its own it is not enough.

The test is whether you can produce, for any given customer, the record of which checks ran, when, against which source, and with what result. If that record exists as a by-product of the checks themselves, the program is running. If it has to be reconstructed after a notice arrives, it is not, and the response window for a notice is short.

Which checks make up customer identification?

add

Two, and most programs specify both:

  • Document verification — an identity document checked against the issuing authority's own record through the government's Document Verification Service, across all 14 accepted document types
  • Data verification — name, address, date of birth, phone and email matched field by field against an Australian universe of more than 2 billion records

They are run together because they answer different questions. The document check proves the credential is genuine; the data check proves the details belong to a real, living person. A genuine document presented by someone who is not its holder passes the first and fails the second.

What does the screening cover?

add

Sanctions lists, politically exposed persons, and criminal and regulatory watchlists, with coverage across more than 268 countries and territories, updated in real time as the source lists change.

Screening is not limited to individuals. Companies and vessels are screened through the same endpoint, which matters when you are onboarding a business instead of a person, and adverse media coverage can be added for both people and businesses where your risk assessment calls for enhanced due diligence.

Matching rules are configurable, so you decide how closely a name has to match before an alert is raised. That is the main lever on false positive volume.

How is screening frequency set?

add

Screening at onboarding is standard. After that, re-screening runs on a schedule you set per monitor.

The available schedules are daily, weekdays only, weekends only, a specific weekday, the 1st of the month, the 15th, the 1st and 15th, or quarterly. There is also a run-on-demand option for monitors you would rather trigger yourself. Scheduled monitors run automatically overnight, and you are emailed if new events were raised.

Because each monitor carries its own schedule, you can run the sources that matter most more often than the rest: PEP and sanctions daily, adverse media weekly, court screening quarterly. That avoids paying to run everything at the highest frequency. Your risk tiers decide which cadence applies to whom, and the schedule you chose is itself part of the evidence that the program was operating as designed.

What records are kept for each check?

add

Five fields, on every check: the subject, the source it was checked against, the result, the timestamp, and the operator who ran it. Screening results, events and the review trail are all stored as the check happens.

Retention is a setting, not a default. Each program has its own retention period, from no retention at all up to 84 months (the seven years the AML/CTF Act requires). The default is 12 months. If you are relying on these records to meet the seven-year obligation, the program must be configured that way deliberately; the out-of-the-box setting will not get you there.

Records can be exported at any point, for an internal audit, an external review, or a response to a regulator. Because the record is a by-product of the check itself, there is no separate filing step to be missed.

How is Tranche 2 different?

add

Same Act, same obligations, different scale.

Tranche 2 brought tens of thousands of newly regulated firms into the regime: lawyers, conveyancers, accountants, real estate professionals, dealers in precious metals and stones, and trust and company service providers. They carry the same obligations as long-established reporting entities, generally without a compliance department to run them.

That changes how the capability is delivered, not what it has to achieve. Tranche 2 firms typically run checks from the portal instead of building an integration, and their programs are sized to a handful of designated services. The Tranche 2 use case covers the detail.

Do we need an integration, or can our team run this from a browser?

add

Either. The same checks run and the same records are produced whichever way you work:

  • IDFEX ID Check — customer identification one at a time, from the portal
  • WatchEye — screening, monitoring, risk tiers and the alert queue in one platform, with per-check records kept automatically
  • Caspar — the deeper sources for enhanced due diligence, when a customer's risk rating demands more
  • API — PEP and sanction, Global Data Check, DVS and adverse media endpoints inside your own systems

Most organisations start in the portal and integrate later, once the process has settled and the volume justifies it.

Request a demo

Request a demo of our solutions

Complete the form and our team will be in touch shortly to walk you through how it works.

SOME OF OUR TRUSTED CLIENTS

Request a Demo

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Full Name*