
Photo by seanpay52
Every remittance transaction starts with one question: who is this customer, and can you prove it? Under the AML/CTF Act 2006, you must verify a customer's identity before providing a designated service — including sending money overseas. For front desk staff, this means collecting the right documents, checking them properly, and recording what you did, all while keeping the queue moving.
This guide walks you through the practical steps of customer identification at the point of transaction: which documents to accept, how to verify identity electronically, and what to do when a customer walks in without a passport or driver's licence. Get this right and you protect your business from AUSTRAC penalties, fraud, and the reputational damage of onboarding the wrong customer.
Key Takeaways
- You must verify a customer's identity before providing a remittance service — collecting name, date of birth, and residential address is the minimum for most transactions.
- The standard document combination is one primary photographic ID (passport or driver's licence) — or two secondary documents where photo ID is unavailable.
- Electronic verification (eKYC) using two independent data sources is a valid alternative to sighting original documents and speeds up onboarding.
- Customers who cannot provide standard ID — refugees, recent arrivals, the elderly — can be verified using AUSTRAC's flexible verification provisions rather than being turned away.
- Always record what you sighted or matched, keep it for seven years, and escalate anything that doesn't add up to your compliance officer.
What Customer Identification Actually Requires
Customer identification is the process of collecting and verifying a customer's identity information before you provide a designated service. It sits within the broader Customer Due Diligence (CDD) framework and, until the transition to the new 2026 rules is complete, the Applicable Customer Identification Procedure (ACIP) you set out in your AML/CTF program.
For an individual customer, you collect three core pieces of Know Your Customer (KYC) information:
- Full name
- Date of birth
- Residential address (a PO box alone is not enough)
Collecting the information is only half the job. You then verify it — confirming the customer is who they claim to be — using either reliable and independent documents or reliable and independent electronic data. AUSTRAC treats "collect" and "verify" as two distinct obligations, and inspectors check both.
When you must verify identity
You verify identity before the first transaction for a new customer. For occasional (non-account) customers who transact once, verification happens at the point of the transaction. You do not need to re-verify a returning customer at every visit — but you must confirm they are the same person you previously identified, usually by matching them against your records and a photo ID.
Acceptable Identity Documents for Remittance Customers
Australian MTOs typically use a primary and secondary document framework. A primary photographic document proves identity on its own; secondary documents are combined when photo ID is unavailable.
Primary photographic documents
These are your first choice because they carry a photo, name, and date of birth in a single, tamper-resistant document:
| Document | Confirms | Notes |
|---|---|---|
| Australian passport | Name, DOB, photo | Current or expired within 2 years |
| Foreign passport | Name, DOB, photo | Common for remittance customers; check visa status |
| Australian driver's licence | Name, DOB, address, photo | State-issued; verify via DVS where possible |
| Proof of Age / Photo Card | Name, DOB, address, photo | State-issued alternative to a licence |
| Government-issued immigration card | Name, DOB, photo | Useful for recent arrivals |
Secondary documents (combine two)
When a customer has no photo ID, combine one document that confirms name plus another that confirms name and either date of birth or residential address:
- Australian or foreign birth certificate
- Citizenship certificate
- Centrelink or pension card
- Medicare card (confirms name; commonly paired with a rates or utility notice)
- Recent utility bill, bank statement, or council rates notice (confirms address)
- Tax notice from the ATO issued in the past 12 months
A practical secondary combination is a Medicare card plus a recent utility bill — the first confirms name, the second confirms name and address.
What to check on every document
When you sight a document, do more than glance at the photo. Confirm:
- The document is current (or acceptably recent for expired passports).
- The photo matches the person in front of you.
- The name is consistent across all documents presented.
- There are no signs of tampering — mismatched fonts, altered dates, peeling laminate, or a photo that looks stuck on.
- The document number and details are legible and recorded accurately.
If a name differs between documents — a marriage certificate or deed poll explains the change — record the supporting evidence.
Electronic Verification (eKYC): The Faster Alternative
You are not required to sight original paper documents. The electronic verification method lets you confirm identity by matching customer-supplied data against reliable, independent electronic sources. This is faster at the front desk and essential for online remittance channels.
The two-source rule
To verify a customer electronically, you generally match their name and either date of birth or residential address against at least two independent data sources. Acceptable sources include:
- The Document Verification Service (DVS) — a national government system that confirms whether a document (passport, licence, Medicare card) is valid
- Credit header data from a credit bureau
- Electoral roll data
- Utility or telecommunications records via an approved provider
A common compliant setup is a DVS check against a passport plus a credit-header match — two independent sources confirming the same identity.
Biometric and liveness checks
Many eKYC platforms now add a facial biometric match — comparing a selfie against the photo on the ID — with a liveness detection step to defeat photos-of-photos and deepfakes. AUSTRAC expects reporting entities to guard against synthetic identity fraud, and biometric matching is now standard practice for digital onboarding.
For a deeper walk-through of digital identity tools, see our guide on eKYC and digital identity verification.
Step-by-Step: Identifying a Customer at the Front Desk
Here is the operational sequence for a walk-in customer sending money for the first time.
- Greet and explain. Tell the customer you need to verify their identity before you can send the transfer — it's a legal requirement, not a personal barrier.
- Collect KYC data. Record full name, date of birth, and residential address on your onboarding form or system.
- Request identity documents. Ask for a primary photo ID first. If unavailable, request two secondary documents.
- Verify the documents. Check currency, photo match, name consistency, and tampering. Run a DVS or eKYC check where your system supports it.
- Screen against sanctions lists. Match the customer name against the DFAT Consolidated List and relevant international sanctions lists before completing the transaction.
- Record the evidence. Note which documents you sighted or which electronic sources matched, the date, and the staff member who performed the check.
- Assess risk and proceed. If the customer, destination, or amount raises red flags, pause and escalate to your compliance officer. Otherwise, complete the transaction.
This sequence should take a trained staff member a few minutes for a straightforward customer.
Handling Customers Who Cannot Provide Standard ID
Some customers genuinely cannot produce a passport or driver's licence — recent refugees, elderly people who never held a licence, or newly arrived migrants awaiting documents. AUSTRAC does not require you to refuse these customers. Instead, your AML/CTF program should include flexible or alternative verification procedures for exactly this situation.
Practical alternatives
- Referee statements. A statement from an authorised referee — a person of standing in the community (accountant, medical practitioner, JP) — who has known the customer for a defined period.
- Government correspondence. Letters from Centrelink, the Department of Home Affairs, or a settlement service confirming the customer's identity details.
- Immigration documentation. ImmiCards, bridging visa evidence, or refugee travel documents.
- Community organisation verification. For customers connected to a known settlement or community organisation, supporting documentation from that body.
Applying enhanced scrutiny
Where a customer's identity is harder to verify, you generally elevate the risk rating and apply Enhanced Due Diligence (EDD) — asking more questions about the source of funds and purpose of the transfer, and documenting your reasoning. The goal is a reasonable, defensible basis to be satisfied of the customer's identity, not a rigid document checklist that excludes vulnerable people.
Financial inclusion matters here. Turning away every customer without a passport pushes them toward informal channels that carry higher money-laundering risk — the opposite of what the AML/CTF regime intends.
Common Front Desk Scenarios and How to Handle Them
| Scenario | Recommended action |
|---|---|
| Name on ID differs from booking | Request evidence of name change (marriage certificate, deed poll); record it |
| Photo doesn't clearly match | Request a second ID; if doubt remains, decline and escalate |
| Customer sends on behalf of a third party | Identify the customer AND establish the third party; consider EDD |
| Customer refuses to provide ID | You cannot provide the service; consider whether an SMR is warranted |
| Multiple structured transactions under the threshold | Do not process to avoid reporting; escalate as possible structuring |
| Expired passport (over 2 years) | Request an alternative current document |
Red flags that require escalation
Escalate to your compliance officer — and consider filing a Suspicious Matter Report (SMR) — when you see:
- Reluctance to provide identity information
- Documents that appear altered or inconsistent
- A customer who appears to be acting under someone else's direction
- Transactions that seem designed to stay under the AUD 10,000 threshold transaction reporting line
- A customer's stated occupation or income that doesn't match the transaction size
Record-Keeping: What to Save and for How Long
Under the AML/CTF Act, you must keep records of the identification procedure for seven years after the transaction or after the business relationship ends — whichever is later. Your records should show:
- What information you collected
- What documents you sighted or what electronic sources you matched
- The date and the staff member who performed the check
- The outcome of sanctions screening
Electronic systems that timestamp and store this automatically make AUSTRAC assessments far smoother. When an inspector asks how you verified a specific customer three years ago, you should be able to produce the answer in minutes.
How the 2026 AML/CTF Reforms Change Identification
The AML/CTF Amendment Act 2024 reshapes customer due diligence from 31 March 2026, replacing the prescriptive ACIP framework with an outcomes-based CDD model. In practice, front desk identification becomes more risk-driven: you gather enough information to be reasonably satisfied of a customer's identity, calibrated to the money-laundering risk that customer presents.
The core mechanics — collecting name, date of birth, and address, verifying against reliable sources, and screening for sanctions — remain. What changes is the emphasis on proportionate verification tied to your risk assessment rather than a fixed document tick-list. Businesses already applying a risk-based approach will find the transition straightforward.
For the detail, see our breakdown of the 2026 AML/CTF reforms and how to update your program.
Training Your Front Desk Team
Identification is only as strong as the staff performing it. AUSTRAC expects ongoing AML/CTF training for all customer-facing staff, covering document fraud indicators, sanctions screening, and escalation procedures. Refresh this training at least annually and whenever your procedures change.
Give new staff a simple laminated reference: acceptable documents, what to check, and who to escalate to. A confident, well-trained front desk both protects your licence and reassures legitimate customers that you run a professional operation.
This information is general in nature and does not constitute legal advice. Consult AUSTRAC or a qualified legal professional for advice specific to your situation.
Frequently Asked Questions
What is the minimum ID needed to send money overseas from Australia?
At minimum you must collect and verify the customer's full name, date of birth, and residential address. This is typically satisfied with one primary photographic document such as a current passport or Australian driver's licence, or two secondary documents (for example a Medicare card plus a recent utility bill) where photo ID is unavailable.
Can I verify a customer's identity electronically instead of sighting documents?
Yes. Electronic verification (eKYC) is a valid alternative under the AML/CTF regime. You match the customer's details against at least two independent, reliable electronic data sources — such as the Document Verification Service plus credit-header data. Many providers add a biometric selfie match with liveness detection to prevent identity fraud.
What do I do if a customer has no passport or driver's licence?
Don't automatically turn them away. Your AML/CTF program should include flexible verification for customers such as refugees or the elderly — using referee statements, government correspondence, immigration documents, or verification through a known community organisation. Apply enhanced scrutiny and document your reasoning for being satisfied of their identity.
How long must I keep customer identification records?
Seven years after the transaction or after the business relationship ends, whichever is later. Records should show what information you collected, what documents you sighted or electronic sources you matched, the date, the staff member responsible, and the sanctions-screening outcome.
When should front desk staff escalate a customer to the compliance officer?
Escalate when documents appear altered or inconsistent, a photo doesn't match, a customer refuses to provide identity information, transactions appear structured to stay under the AUD 10,000 threshold, or the customer seems to be acting under someone else's direction. These may warrant a Suspicious Matter Report.


