Document-based verification
A document-based path uses reliable and independent identification documents to verify the customer's name, date of birth and, where relevant, residential address. For individuals, a current passport, driver's licence or other government-issued identity document is commonly used. For entities, the identity evidence shifts to registration records, trust deeds and ownership documents, with verification of the individuals behind the entity.
The document must be checked for consistency and validity, not simply collected. Compare the document with the customer's stated details, examine it for signs of alteration, and record what was sighted, from which source, on what date and by whom. A scanned copy emailed by a stranger is weaker evidence than a verified original or a secure collection channel.
Electronic identity verification
Electronic paths can reduce fraud and collection friction, but the provider's coverage and the data it checks vary. Confirm what the vendor actually verified: a selfie and a document image is not the same as a DVS match against a government record. Record the provider, session identifier, result and date so the file can be explained later.
- Identity providers that check documents, biometrics and live presence
- Services that cross-check customer data against trusted registers
- The DVS, which matches identity details against Australian government records
- Digital ID services operating under the Digital ID Act 2024 framework
DVS and government-register checks
The DVS matches identity information against participating Australian government records, such as driver licence, passport, visa, citizenship and birth records. It is a verification tool operated by government and accessed through accredited organisations; an AML software provider is not automatically a DVS provider. Some providers brand their checks as 'DVS' when they are only document verification, so verify the claim before you rely on it.
Cassandra AML does not itself provide Australian DVS or official-register verification. Its identity workflow supports user-initiated hosted identity sessions and a documented manual path, and provider boundaries are recorded honestly rather than marketed as DVS.
What a defensible file contains
AUSTRAC's core guidance on customer identification emphasises that a reporting entity must not provide a designated service unless applicable customer identification procedures have been carried out. A file that shows the procedure, the source and the date is the difference between a controlled process and a collection of documents.
- The customer type and the identity elements required for that type
- The verification method and, for electronic checks, the provider and reference
- The date verification was completed and by whom
- The risk-based decision, including any enhanced measures
- Retention of the evidence for the period the program requires
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Does AML/CTF require DVS or biometric identity checks?
No. The regime requires identification and verification on reasonable grounds using reliable and independent sources. DVS and biometric checks are options; a documented document-based path can also satisfy the obligation when performed properly.
What is the difference between DVS and a document scan?
DVS matches identity details against Australian government records. A document scan verifies the document image. They are different controls, and a vendor claim of DVS should be checked against what the provider actually connects to.
Can we verify identity after starting the service?
Initial CDD must be completed before providing the designated service, subject to limited delayed-CDD rules and any transitional provisions that apply. Delayed CDD is not a general convenience; it must be permitted and documented.
Does Cassandra AML provide Australian DVS?
No. Cassandra does not claim Australian DVS or official-register verification. It records hosted identity sessions and a manual verification path with provider boundaries shown in the file.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.