
Photo by goffkein
Electronic KYC (eKYC) is now the standard way Australian remittance operators verify customer identity — and under the 2026 AML/CTF reforms, it carries the same legal weight as a face-to-face document check. If your onboarding flow still leans on manual passport photocopies and utility bills, you are working harder than you need to and creating friction that costs you customers.
This guide explains which digital identity services are approved for AML/CTF purposes, how to build eKYC into your customer onboarding, and the specific scenarios where a physical or enhanced verification step is still required. Under section 32 of the AML/CTF Act 2006 and the reformed AML/CTF Rules, you must verify a customer's identity using reliable and independent documentation or electronic data before providing a designated service — but the reforms give you far more flexibility in how you meet that standard.
Key Takeaways
- eKYC is legally equivalent to face-to-face verification under AUSTRAC rules — you can onboard customers entirely online provided your process uses reliable, independent electronic data sources.
- The Government's Digital ID system (accredited under the Digital ID Act 2024) gives MTOs access to government-grade identity verification through accredited providers.
- The Document Verification Service (DVS) and Face Verification Service (FVS) remain the backbone of most commercial eKYC platforms in Australia.
- Physical or enhanced verification is still required for high-risk customers, PEPs, discrepancies in electronic data, and where you cannot achieve a reliable electronic match.
- Your AML/CTF program must document your eKYC methodology — including data sources, matching thresholds, and fallback procedures — or you risk an AUSTRAC finding.
What eKYC Means Under the 2026 AML/CTF Reforms
eKYC, or electronic Know Your Customer, is the process of verifying a customer's identity using digital data sources rather than physically inspecting original documents. For Australian MTOs, this typically means matching a customer's name, date of birth, and address against authoritative electronic records — government databases, credit bureau files, and biometric checks.
The 2026 AML/CTF reforms (which commenced on 31 March 2026) did not invent eKYC, but they clarified and strengthened its footing. The reforms moved Australia from a prescriptive "Applicable Customer Identification Procedure" (ACIP) model toward an outcomes-based customer due diligence (CDD) framework. You are now judged on whether you have satisfied yourself, on reasonable grounds, that a customer is who they claim to be — not on whether you ticked a specific list of document boxes.
This matters because it removes the old ambiguity about whether online-only verification was "good enough". Provided your electronic process draws on reliable and independent sources and produces a defensible match, it meets the legal standard. AUSTRAC has repeatedly confirmed that electronic verification is acceptable across its regulatory guidance.
The practical effect: you can onboard a customer in Sydney sending money to Manila without ever meeting them, seeing a physical passport, or receiving a certified copy — as long as your eKYC stack is properly designed and documented.
Which Digital Identity Services Are Approved in Australia
There is no single AUSTRAC "approved list" of eKYC vendors. Instead, the law requires that the data sources your provider relies on are reliable and independent. In practice, Australian eKYC platforms are built on a handful of authoritative infrastructure services.
Government Digital ID (Accredited under the Digital ID Act 2024)
The Australian Government Digital ID system — governed by the Digital ID Act 2024 and regulated by the ACCC and the Office of the Australian Information Commissioner — is the newest and most significant development. It allows accredited identity providers (such as myID, formerly myGovID) to verify a person's identity to a government-assured level.
For MTOs, the value is a reusable, high-assurance identity credential. Once a customer has established a Digital ID at the appropriate level of assurance, you can rely on that verification rather than re-collecting documents. As more accredited private-sector providers join the Australian Government Digital ID System (AGDIS), expect this to become a mainstream onboarding option.
Document Verification Service (DVS)
The DVS is a national, real-time system that checks whether an identity document is valid and matches the issuing agency's records. It confirms — with a yes/no response — that a driver licence, passport, Medicare card, or visa is genuine and current.
The DVS is the single most widely used data source in Australian commercial eKYC. Nearly every reputable identity verification platform (Frankie, GBG/GreenID, ZipID, Sumsub, Onfido, and others) queries the DVS behind the scenes. Access is provided through Attorney-General's Department-authorised gateway service providers.
Face Verification Service (FVS) and Biometric Matching
The FVS allows a one-to-one match between a customer's live selfie and their passport or citizenship photograph held by government. Combined with liveness detection — technology that confirms the person is physically present and not a photo, mask, or deepfake — biometric matching has become the gold standard for remote onboarding.
Biometric verification is particularly valuable for remittance because it directly addresses impersonation fraud and the account-takeover risks flagged in recent AUSTRAC and scam-loss reporting.
Credit Bureau and Commercial Data Sources
Providers also match customer details against credit-header data from bureaus (Equifax, illion, Experian) and against electoral, telco, and utility records. These are used to satisfy the "two source" verification model many MTOs adopt — for example, one government document plus one independent data match.
How to Integrate eKYC Into Your Onboarding Flow
A well-designed eKYC flow verifies most customers in under two minutes while routing higher-risk cases to manual review. Here is a practical sequence for a remittance onboarding journey.
- Collect core identity data. Capture full name, date of birth, and residential address at sign-up. Keep the form short — every extra field increases drop-off.
- Run electronic verification. Pass the data to your eKYC provider, which queries the DVS and other reliable sources in real time. A successful two-source match completes standard verification.
- Add document capture and biometric check. For document-based verification, the customer photographs their ID and takes a selfie. Optical character recognition extracts the data, liveness detection confirms presence, and biometric matching compares the selfie to the document photo.
- Screen against sanctions and PEP lists. Before providing any designated service, screen the verified identity against consolidated sanctions lists (DFAT) and PEP/adverse-media databases. This is a separate legal obligation from identity verification.
- Assess risk and apply the outcome. Assign an ML/TF risk rating. Low and medium-risk customers proceed; high-risk customers trigger enhanced due diligence (EDD) before onboarding completes.
- Store the evidence. Retain the verification result, data sources used, timestamps, and any documents for seven years after the customer relationship ends, as required under the Act.
Matching Thresholds and Data Quality
Your AML/CTF program should specify the matching threshold your provider applies — for example, how much tolerance is allowed for name variations, transposed characters, or address formatting. Set this too loose and you onboard fraudulent identities; set it too tight and you reject legitimate customers with minor data mismatches.
Document the logic. When AUSTRAC reviews your eKYC process, it wants to see that your matching rules are deliberate, risk-based, and consistently applied — not a black box you switched on and forgot.
When a Physical ID Check Is Still Required
eKYC covers the majority of onboarding, but the reforms do not eliminate the need for stronger verification in defined scenarios. A purely electronic check is not sufficient when any of the following apply.
| Scenario | Why eKYC alone is insufficient | Required response |
|---|---|---|
| Electronic data cannot be matched | No reliable source confirms the identity (e.g. recent arrival, no credit footprint) | Collect and verify original or certified documents |
| Discrepancy in electronic results | Name, DOB, or address returns conflicting matches | Resolve the discrepancy before onboarding; may require documents |
| High ML/TF risk rating | Customer, product, or corridor is high-risk | Apply enhanced due diligence, including additional identity evidence |
| Politically exposed persons (PEPs) | Elevated risk under the Act | Senior management approval plus EDD and source-of-funds checks |
| Suspected impersonation or fraud | Liveness or biometric check fails or is inconclusive | Manual review; face-to-face or supervised verification |
| Beneficial ownership of a company/trust | Layered structures obscure control | Verify each beneficial owner; documentary evidence often needed |
The underlying principle from the reforms: your obligation is to be satisfied on reasonable grounds of a customer's identity. When electronic verification cannot deliver that confidence, you must escalate — whether to certified documents, video verification, or an in-person check.
The Fallback Procedure You Must Document
Every eKYC-based MTO needs a written fallback (or exception) procedure in its AML/CTF program. This describes exactly what happens when electronic verification fails or is inconclusive: which additional documents you accept, who reviews exceptions, and the point at which you decline to onboard.
AUSTRAC treats the absence of a documented fallback as a control gap. If your automated flow rejects a legitimate customer and your staff have no defined path to verify them another way, you lose the customer and fail the compliance test.
eKYC Provider Comparison for Australian MTOs
The table below summarises the categories of eKYC capability most relevant to remittance onboarding. Feature availability varies by plan and provider.
| Capability | What it does | Why it matters for MTOs |
|---|---|---|
| DVS integration | Real-time document validity check | Core requirement for reliable, independent verification |
| Biometric + liveness | Selfie-to-document face match | Prevents impersonation and account takeover |
| Sanctions & PEP screening | Screens against DFAT and global lists | Separate legal obligation; often bundled |
| Digital ID acceptance | Reuses government-assured identity | Faster onboarding, higher assurance |
| AML risk scoring | Assigns ML/TF risk rating | Feeds your CDD and EDD decisions |
| Audit trail & retention | Logs sources, results, timestamps | Meets 7-year record-keeping requirement |
When selecting a provider, prioritise those with direct DVS gateway access, transparent matching logic, and Australian data residency. Confirm the vendor's screening data is updated frequently — a sanctions list that refreshes weekly is not fit for purpose.
Privacy, Consent, and Data Security Obligations
eKYC creates a large store of sensitive personal and biometric data, which brings Privacy Act 1988 obligations alongside your AML/CTF duties. You must obtain informed consent before verifying a customer's identity electronically, particularly for DVS and biometric checks, and disclose how the data will be used and retained.
Biometric information is classified as sensitive information under the Privacy Act and attracts higher protection. If you collect selfies and facial templates, your privacy policy and collection notices must specifically address biometric handling, storage, and deletion.
Balance two competing timelines: the AML/CTF Act requires seven-year retention of verification records, while privacy principles require you not to keep personal data longer than necessary. The practical reconciliation is that AML retention is a lawful basis to hold the data for the mandated period — but you should still minimise what you collect and secure it appropriately.
Common eKYC Mistakes That Trigger AUSTRAC Findings
- Treating eKYC as "set and forget". Your provider's data sources, matching thresholds, and screening lists need periodic review, and your AML/CTF program must reflect the current setup.
- No documented fallback procedure. Automated rejection with no manual verification path is a control gap.
- Weak or absent liveness detection. Static selfie matching without liveness invites deepfake and photo-of-a-photo fraud.
- Skipping ongoing CDD. Identity verification at onboarding is not the end — you must keep customer information current and monitor for changes.
- Failing to link eKYC results to risk ratings. Verification and risk assessment are connected; a verified identity in a high-risk corridor still needs EDD.
The 2026 Outlook: Reusable Identity and Reduced Friction
The direction of travel is clear. The Australian Government Digital ID System is expanding to admit accredited private-sector providers, which will let customers reuse a single high-assurance identity across multiple financial services — including remittance. For MTOs, this promises faster onboarding, lower per-check costs, and stronger fraud resistance.
Expect biometric verification with liveness detection to become the default for remote onboarding, driven by rising impersonation fraud and deepfake risk. The MTOs that win will pair robust automated eKYC with a disciplined, well-documented exception process — capturing legitimate customers quickly while catching the ones who should not pass.
This information is general in nature and does not constitute legal advice. Consult AUSTRAC or a qualified legal professional for advice specific to your situation.
Frequently Asked Questions
Is electronic KYC legally acceptable for AML/CTF in Australia?
Yes. Under section 32 of the AML/CTF Act 2006 and the reformed AML/CTF Rules, you may verify customer identity using reliable and independent electronic data. AUSTRAC treats a properly designed eKYC process as equivalent to face-to-face verification, provided it produces a defensible identity match and is documented in your AML/CTF program.
What is the difference between DVS and Digital ID?
The Document Verification Service (DVS) confirms whether a specific document — such as a passport or driver licence — is valid and matches government records. The Government Digital ID (under the Digital ID Act 2024) is a reusable, government-assured identity credential a customer establishes once and can present to multiple services. DVS verifies a document; Digital ID verifies a person to an assured level.
Do I still need to see a physical ID document if I use eKYC?
Not in most cases. A compliant eKYC flow can onboard standard-risk customers entirely online. You must escalate to documentary or enhanced verification when electronic data cannot be matched, returns discrepancies, or the customer is high-risk, a PEP, or shows signs of impersonation. Your AML/CTF program must document these fallback triggers.
How long must I keep eKYC verification records?
Seven years after the customer relationship ends, as required under the AML/CTF Act. Retain the verification result, the data sources used, timestamps, and any documents collected. This retention obligation is a lawful basis for holding the data despite Privacy Act minimisation principles.
Does eKYC replace sanctions and PEP screening?
No. Identity verification and sanctions/PEP screening are separate legal obligations. Even after a customer's identity is verified electronically, you must screen them against DFAT consolidated sanctions lists and PEP/adverse-media databases before providing a designated service, and on an ongoing basis.
Building or reviewing your onboarding controls? Use our AML/CTF Program tool to document your eKYC methodology, matching thresholds, and fallback procedures, and explore our corridor guides to align verification with your highest-risk destinations. Subscribe to our newsletter for ongoing updates on the 2026 reforms.

