Blog
/
Beyond the ID Check
28 September 2026

Beyond the ID Check

What does a compliant reporting entity need to do?

The obligations are real, and broader than identity verification. A compliant reporting entity needs to:

  • identify and verify its customers, assess their risk, and screen for politically exposed persons (PEPs) and targeted financial sanctions;
  • identify companies and trusts, and trace ownership and control through to the individuals behind them;
  • apply enhanced due diligence, including source of funds and source of wealth, where the risk warrants it;
  • monitor for activity inconsistent with what it knows about the customer, and record the outcome;
  • lodge suspicious matter and threshold transaction reports within the legislated timeframes; and
  • maintain enrolment, an AML/CTF program, a compliance officer, trained staff, records, reviews and independent evaluations.

The question is how a busy agency or practice meets those obligations consistently, at volume, with evidence to show for it. That is the problem a well-designed platform exists to solve.

How VerifiMe supports each obligation

One distinction runs through what follows. Ongoing screening asks whether the people you deal with have changed: have they become politically exposed or sanctioned? Monitoring asks whether what they are doing fits what you know about them. The two are often blurred, but VerifiMe supports them in different ways.

Customer due diligence for individuals

Customers verify on their own device with government database and authenticity checks and biometric matching. PEP and sanctions screening runs in the same process and feeds their risk assessment. Because VerifiMe is built on a reusable digital identity, a verified customer can share that credential with another reporting entity rather than starting again.

Companies and trusts

VerifiMe's container structure mirrors real ownership: the entity sits as a parent, with its directors, beneficial owners, trustees and authorised representatives linked beneath it. Each person is verified and screened in their own right, so the chain is traced through to whoever ultimately owns or controls the entity.

Enhanced due diligence

Where risk is elevated, VerifiMe captures source of funds and source of wealth declarations on the file. These checks are triggered by the risk settings in each client's own AML/CTF program, not demanded of every customer by default.

Ongoing PEP and sanctions screening

While a customer or entity remains active, VerifiMe keeps screening the relevant individuals, including directors, beneficial owners and trustees, against PEP and sanctions data. Any change in status is surfaced for review, rather than waiting for the next transaction to reveal it.

Transaction and behaviour monitoring

Unlike screening, monitoring concerns what customers do rather than who they are, and that activity lives in the reporting entity's own systems: its trust account, practice management software and settlement records.

What VerifiMe provides is a place on each customer file to record the transaction and the reasoning around it: funding arrangements, deposits, third-party payments, a change of purchaser, and the entity's assessment of each. When a red flag is raised and resolved, the decision and its rationale sit alongside the identity evidence.

That gives staff the full picture when a concern arises, and produces the record AUSTRAC and independent evaluators will ask to see.

Reporting

VerifiMe does not decide whether a matter is suspicious; that judgement belongs to the reporting entity and its compliance officer. The platform provides the assembled evidence, risk history and assessment notes that make a suspicious matter report faster and better founded.

Annual compliance reporting

For the annual compliance report to AUSTRAC, VerifiMe can supply some of the underlying data: records of the due diligence, screening and enhanced checks completed over the period.

The report itself is the entity's own account of its compliance. Be wary of any provider offering to assemble and lodge it for you: no platform can see everything the report covers, from staff training to program reviews, and outsourcing the lodgement does not outsource the accountability.

Two very different relationships

The tools are the same whoever the client is, but how they apply depends on the shape of the relationship. Two examples show the contrast.

The real estate agent: a transaction with a clear sunset

A property sale has a beginning, a middle and an end. The agency identifies the vendor and purchaser, assesses risk, then watches a defined window: contract, deposit, any change of purchaser or nominee, funding and settlement. The red flags, and the monitoring effort, are concentrated there.

After settlement, the relationship usually ends and the obligation shifts to record-keeping: evidence of what was checked, noticed and decided. If the customer returns for a new transaction, the agency takes a fresh view of the risk, ideally without making them repeat the whole process.

The accountant or adviser: a relationship with no clear end

An accountant, lawyer or trust and company service provider may act for a client for twenty years, with no settlement date. Circumstances change: the client takes public office, restructures a trust, adds a director. A sanctions list may change years after onboarding.

Here, screening and monitoring both become continuous. Screening runs for as long as the relationship lasts, and each new engagement or change is a prompt to revisit the client's risk.

The obligations are the same in law, but they apply differently in practice. That is why VerifiMe's rules engine is configured to each client's own AML/CTF program rather than imposing one fixed workflow.

Responsibility stays with the reporting entity

Under the AML/CTF Act, the obligations belong to the reporting entity. No platform, VerifiMe included, can take them over, and any provider claiming to make a business "fully compliant" out of the box should be treated with caution.

What technology can do is make those obligations easier to meet well. It applies your program the same way on every file. It removes manual re-keying and the errors that come with it. It keeps screening running when staff are busy with settlements or year-end. And it builds the audit trail as the work is done, not afterwards.

The agency or practice still owns its program, its risk appetite, its escalation decisions and its reports. VerifiMe's role is to make sure the tools behind those decisions are reliable, consistent and evidenced.

Choosing a platform: privacy, security and certification

AML/CTF compliance means holding some of the most sensitive information a business will ever collect: identity documents, biometrics, ownership structures and financial details. Your Privacy Act obligations sit alongside your AML/CTF ones, and a poorly secured platform can turn one compliance duty into a breach of another.

Before choosing any provider, ask:

  • What independent certification does it hold? Look for standards such as ISO 9001, ISO/IEC 27001 or a SOC 2 report, and check the scope.
  • Where is the data held, and who can access it? Understand data residency, encryption and access controls.
  • What identity checks do they do? Direct access to government database checks is a meaningful indicator of platform maturity.
  • Can it evidence its own controls? A provider that audits its own processes is better placed to support yours.

Put these questions to any provider you are considering.

The bottom line

An ID check alone does not meet your AML/CTF obligations. But a modern compliance platform is not an ID check alone. It verifies individuals and entities, traces ownership, supports enhanced due diligence and keeps screening for the life of the relationship. It also gives your transaction monitoring a home for the decisions that form your audit trail.

Whether your relationships end at settlement or run for decades, the right technology makes your obligations more efficient and more effective to meet. The responsibility remains yours; the burden need not.

To see how VerifiMe maps to your AML/CTF program, get in touch at support@verifime.com.

Ready to meet compliance requirements with VerifiMe®?

Get started
VerifiMe Australia Copyright 2026
VerifiMe acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their Elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.