KYC verification in Australia: what small firms actually have to do

Every AML/CTF program in Australia has a customer identification piece — the part where you work out who you're actually dealing with before you take them on. In practice it's called KYC, know your customer, and for most small firms it's the single biggest change coming.
Not because it's complicated. Because it happens on every new client, forever, and it has to be provable years later.
Here's what "verified" actually means, and how to do it without adding twenty minutes to every onboarding.
What you're required to establish
For an individual customer, the baseline is:
Full name
Date of birth
Residential address
And you have to verify those against reliable, independent evidence — not just take their word for it.
For a company, trust or partnership, you need the entity's details and the humans behind it:
The entity's legal name, registration number (ACN/ABN), and registered address
Its structure and who controls it
The beneficial owners — generally the individuals who ultimately own or control 25% or more, or who otherwise control the entity
The person acting for the entity, and their authority to do so
The beneficial owner part is where firms get stuck. A company owned by a trust owned by another company is common and legal, and you still have to get to the natural persons at the end of the chain.
The two ways to verify
Documentary. Government-issued ID. In practice one primary photographic document (passport, driver's licence) or a combination of secondary documents. You keep a copy, or a record of what you saw and when.
Electronic. A verification service checks the details against independent data sources — credit files, electoral roll, government records — and returns a pass or fail with an audit trail.
For most small firms, electronic verification is the better answer for one reason: it produces the record automatically. A licence photo in a Dropbox folder is evidence only if you can find it in 2031 and prove when you collected it. An electronic check timestamps itself.
Risk-based means what it sounds like
You don't treat every client the same. Your risk assessment sets the tiers.
Simplified — lower-risk customers, where the basics are enough. Not "no checks", just proportionate ones.
Standard — the default for most clients.
Enhanced — higher-risk situations, where you go further: source of funds, source of wealth, senior sign-off, closer monitoring. Politically exposed persons, customers in higher-risk jurisdictions, unusual structures, and anything that doesn't add up.
The tiers only work if the rules for landing in each one are written down. "We use judgement" is not a documented policy.
Timing: before, not after
Verification happens before you provide the designated service, with narrow exceptions. This is the part that clashes with how most professional services firms actually work — you want to get moving on day one and sort the paperwork later.
Two fixes, both structural:
Move ID collection to the front of the funnel. Ask for it in the engagement step, not after the first meeting. Clients expect it from banks; they'll accept it from you if it comes at the natural moment.
Make it self-service. A link the client opens on their phone beats "can you email me a scan of your licence" every time, and it removes you from the chase.
Records: seven years, and findable
You keep records of the customer's identity, the documents or checks you relied on, and the decisions you made — for seven years after the relationship ends.
Two failure modes we see constantly:
Records exist but aren't retrievable. Scattered across email attachments, someone's laptop and a shared drive nobody maintains. Technically kept, practically lost.
The decision isn't recorded, only the document. You have the passport scan but no note of why this client was rated standard risk rather than enhanced. The reasoning is part of the record.
One folder structure, one naming convention, one place. Boring beats clever.
What a workable small-firm setup looks like
We build variations of the same thing for accounting, legal and property firms:
Client fills in an onboarding form that captures the entity details and the people involved
Electronic ID verification runs from that form, and the result attaches to the client record
Beneficial ownership is captured as structured data, not a free-text note
Risk rating is calculated from the answers, with an override the compliance officer can apply and must justify
Everything lands in one client file with a date stamp, and a report can list every client verified in a period
No new system to log into. It runs inside the CRM or job software the team already uses.
Cost and effort, honestly
Electronic verification typically runs a few dollars per check. Building the flow into your existing tools is a one-off. Against that: the manual version costs somebody fifteen to twenty minutes per client, forever, and produces worse evidence.
If you onboard two clients a week, the automated version pays for itself inside a quarter on time alone.
Where to start
Get the free AML Compliance Pack — it produces a starting risk assessment and program that includes your customer due diligence approach, so you can see what you're actually committing to.
When you want it built rather than written, our AML/CTF and client onboarding setup wires verification into your onboarding from A$999 fixed price.
AUSTRAC's own guidance on customer identification is at austrac.gov.au.
Common questions
Can I just photocopy a driver's licence?
You can rely on documentary verification, but you need a proper record of what you saw and when, and you need to be able to produce it years later. Electronic verification generally produces a stronger, easier audit trail.
What's a beneficial owner?
The natural person who ultimately owns or controls the customer — generally 25% or more ownership, or control by other means. For layered structures you follow the chain until you reach individuals.
Do I re-verify existing clients?
Not on a fixed schedule, but you monitor the relationship and re-verify when risk or circumstances change materially — new owners, new structure, unusual activity.
Can I outsource verification?
You can use a third-party service or rely on another reporting entity's checks in some circumstances, but the obligation stays with you. Outsource the work, not the responsibility.