Identity Verification
Check identity documents against the government's Document Verification Service and personal details against Australian data sources. This page covers what each check does, which documents and fields it covers, and the four products it runs in.
Checks included
Run them together for full KYC, or each on its own where a lighter check is enough.Document verification
Data verification
Pre-screening
Verifying someone remotely? Add face matching and liveness detection to any of these checks.
Document types
All 14 DVS document types. Each result comes from the issuing authority's record.Data verification fields
Each field returns its own match result, so you can see exactly what did and didn't match.| Field | Checked against | Match grades returned |
|---|---|---|
| Full name | Australian data universe | exact · alias · partial · fuzzy |
| Residential address | GNAF + data universe | exact · partial · fuzzy |
| Date of birth | Data universe | match · no match |
| Phone | Connectivity + universe | match · no match |
| Deliverability + universe | match · no match | |
| Deceased status | Australian Death Check | clear · flagged |
Why organisations verify against source records
KYC obligations
The AML/CTF Act requires identity verification against reliable, independent sources. DVS and government-record checks meet that standard.
Fraud prevention
Checking a document against the authority that issued it catches stolen and fabricated identities before an account exists.
Onboarding speed
Checks return in seconds, so legitimate customers finish sign-up in one sitting instead of waiting on manual review.
Audit evidence
Every check records what was checked, when, and the result. When AUSTRAC or an auditor asks, the evidence is already there.
Where the checks run
Pick by how your team works.Verification as part of an AML/CTF program: verify at onboarding, screen against watchlists in the same pass, and keep monitoring the customer after the check.
Run document, data and pre-screening checks one at a time from a browser. Suited to teams that verify customers as they arrive, without an integration project.
arrow_forward mobile_camera_front ID PassCustomer self-verificationSend the customer a link. They photograph their ID and take a selfie on their own phone; OCR, DVS and face matching run automatically and the result comes back to you.
arrow_forward api Global Data APIInside your own systemsEvery check on this page has an endpoint: the 14 DVS document types, Global Data Check for per-field data matching, liveness, and the full ID Pass flow.
arrow_forwardAPI endpoints
Request schemas and example calls are in the API reference. Sandbox available for integration testing.Which identity documents can you verify?
add
All 14 document types available through the government's Document Verification Service. Each check goes to the authority that issued the document and returns a match or no-match against their own record:
- Driver licences — all states and territories
- Australian passports and travel documents — DFAT
- Medicare cards and Centrelink concession cards — Services Australia
- Birth, marriage, death and change-of-name certificates — state Births, Deaths and Marriages registries
- Citizenship certificates, registration by descent, ImmiCards and visas — Home Affairs
- ASIC and MSIC aviation and maritime security cards
The AEC electoral roll is also available as a document-free check, for customers who can't produce an accepted document. Note that the DVS confirms whether the details match the issuer's record; it does not return a photograph or a copy of the record itself.
What's the difference between document and data verification?
add
They answer two different questions, and most KYC programs use both.
Document verification confirms a credential is genuine: the details on the licence or passport are checked against the issuing authority's record through the DVS. It proves the document is real and current.
Data verification confirms the person is real: name, address, date of birth, phone and email are matched field by field against Australian data sources, with a separate result for each field.
The gap each one leaves is the reason to run both. A genuine document can be presented by someone who isn't its holder, and a real set of details won't always come with a document you can check. Together, the document proves the credential and the data check proves the details belong to a real, living person.
What does a data verification result return?
add
A separate, graded result for every field, not a single pass or fail:
- Full name — matched against the Australian data universe, graded exact, alias, partial or fuzzy
- Residential address — matched against GNAF and the data universe, graded exact, partial or fuzzy
- Date of birth — match or no match
- Phone — a live connectivity check plus a match against the universe
- Email — a deliverability check plus a match against the universe
- Deceased status — screened against the Australian Death Check, returned clear or flagged
Grading each field on its own is what lets you tell a customer who mistyped a unit number from one whose identity doesn't resolve at all. You set which combination of grades counts as a pass for each customer type.
Is the customer's consent required?
add
Yes. A DVS check can only be run with the customer's consent, and you confirm that you hold it before the check will run.
Be precise about who holds what. The platform records your confirmation, the check details and the result. Obtaining and retaining the consent evidence itself remains your responsibility, and you may be audited and required to produce evidence of consent for any DVS check you have run.
That means your own onboarding flow needs to capture consent in a durable form and store it against the customer, instead of treating the tick box at check time as the record. The check trail shows a check was authorised; your records show what the customer agreed to.
Do you store the customer's documents?
add
Image retention is configurable, and in ID Pass the default is zero days: captured images are deleted the moment the verification completes. Where you do choose to retain them, sensitive fields are encrypted at rest under a key unique to that single verification.
The evidence record is kept separately and is not the same thing as the images. It records what was checked, against which source, the result, the timestamp and the operator. That is the part an auditor asks for, and it contains no document photographs.
Does this meet AUSTRAC's KYC requirements?
add
The AML/CTF Act requires identity to be verified against reliable and independent sources. DVS checks go to the issuing authority's own record, and data verification runs against independent Australian data sources. Both satisfy that sourcing standard.
What the Act deliberately doesn't do is prescribe one fixed set of checks for everyone. Your AML/CTF program defines your customer types and risk-based procedures, and decides which checks apply to each. What we provide is verification against sources that qualify, plus a complete evidence trail recorded automatically for every check, so you can produce it when you're asked.
How do customers verify remotely?
add
Through ID Pass. You send the customer a secure link and they complete the whole flow on their own phone, with no app to install. They photograph their ID and take a selfie; OCR extracts the document fields, the DVS check runs against the issuing authority, and face matching confirms the selfie belongs to the document.
The result returns to your workflow or webhook, and the customer's part typically takes under two minutes. If someone can't complete the selfie step, the same identity can still be verified through document and data checks, or run by your own team in IDFEX ID Check.
How long does a check take, and what happens when one fails?
add
Document and data checks return in seconds, so a customer who verifies cleanly finishes sign-up in a single sitting instead of waiting on manual review.
A failure isn't a dead end. Because results come back per field, you can see precisely what didn't match (a superseded address, a transposed licence number) instead of an unexplained rejection. Common designs retry with a different document type, escalate to a selfie and liveness check, or route the case to a reviewer in IDFEX. Your policy decides which path applies, and the evidence is recorded either way.
Can we run these checks from our own software?
add
Yes. Every check on this page is available as an API endpoint:
- DVS — 14 document endpoints, one per document type
- Global Data Check — per-field identity matching
- Person — identity and KYC lookups
- ID Pass — create and read a hosted verification flow
- Liveness — liveness and likeness checks
Request schemas and worked examples are in the API reference, and a sandbox is available so your team can build and test the integration before any of it touches a real customer.
Other solutions
Document Verification Service
Authenticate Australian identity documents against the DVS and confirm the details match authoritative sources.
Read morearrow_forward familiar_face_and_zoneBiometrics & liveness
Facial matching, liveness detection and OCR document capture for remote verification.
Read morearrow_forward search_checkKYC due diligence
Verify who an individual customer is, screen them, and keep the evidence for each check.
Read morearrow_forwardRequest a demo of our solutions
Complete the form and our team will be in touch shortly to walk you through how it works.
SOME OF OUR TRUSTED CLIENTS
Request a Demo
"*" indicates required fields
