Blog
/
"Can't we just use the check the other firm has already done?" What you need to know about reliance!
17 September 2026

"Can't we just use the check the other firm has already done?" What you need to know about reliance!

Two months in, the thing firms tell us about most isn't the program, the enrolment, or the reporting. Those were hard. They were also expected, and they were on the project plan.

What wasn't on the project plan is the impact on the client.

A residential sale now routinely involves a real estate agent, a buyer's agent, a lawyer or conveyancer on each side, and a lender. Most are reporting entities. Each carries its own initial CDD obligation, and each obligation is independent of the others. So one person photographs the same licence three or four times to complete a single transaction, answers the same questions each time, and every firm after the first pays for a check that has, in substance, already been done.

An estimated 90,000 businesses joined the regime on 1 July — the largest single expansion since the Act commenced in 2006. But the duplication didn't scale with that number. It scaled with the connections between them.

Nobody designed this. It is what you get when a regime that quite properly holds each firm responsible for its own decisions meets a transaction in which five firms serve one person.

The question everyone is asking

Almost daily, in one form or another: can't we just use the check the other firm has already done?

The formal answer is reliance. Reliance is real, it is properly drafted, and for most of the duplication you are actually seeing, it is rather less useful than it sounds.

In short: you may treat your initial CDD as satisfied on the basis of KYC information collected and verified by someone else. There are several routes — a standing written arrangement under s 37A, case-by-case reliance under s 38, and a model in Division 9 of the Rules built specifically for property. That last one is aimed squarely at the problem described here and it is genuinely useful: under rule 6-32 an agent may defer initial CDD on the party they are not acting for, completing it 28 days after exchange of contracts or at least three days before the agreed settlement date, whichever comes first. If you have a referral partner you work with every week, formalising the relationship is a sensible thing to do, and some firms are already doing it.

What the routes have in common is the part that attracts the least attention.

Reliance does not transfer accountability. If the other firm's CDD turns out to have been inadequate, you are the one who failed to conduct adequate CDD. There is a limited safe harbour for isolated deficiencies where you had a proper arrangement and did your homework. It is a narrow protection, not a transfer of risk.

And an arrangement is a relationship instrument, not a transaction one. You assess the other firm's programme before you enter it. You hold their verification data. You revisit the whole thing at least every two years. For the partner you work with weekly, that is a reasonable investment. For the agent on the other side of one sale, it is a standing commitment to a firm you may never act as the opposite again — and that long tail is where nearly all the duplication actually lives.

One further trap for lawyers and conveyancers, in particular. AML/CTF reliance is not verification of identity under the ARNECC Model Participation Rules. Your AML onboarding may inform your verification of identity BUT it does not discharge it, and an identity check carried out by an agent is not s 37A reliance. Two obligations, two records, and no credit for confusing them.

There is another path

The debate has settled into two options, but there are actually three. You are not choosing between starting from scratch (option 1) or relying on the other firm (option 2).

Initial CDD requires you to verify your customer's identity against reliable and independent data. It does not require you to be the person holding the phone when the licence is photographed. Banks worked this out years ago. A bank running an electronic verification isn't relying on anybody. It is conducting its own CDD, against a data source, and keeping its own evidence. No arrangement with another reporting entity, no two-yearly assessment, no shared liability — because nothing is shared. The bank made its own decision on its own information.

The same path is open to you, and it turns on a single question: what moves between the firms?

If what moves is the outcome — firm A's verification, accepted by firm B — that is reliance (option 2), whatever anyone calls it, and it needs the machinery to match.

If what moves is the information, with the client's consent, and you verify it yourself against reliable and independent data at the point you take them on, then you have relied on nobody. Your check. Your risk rating. Your file. The same work, done faster, without asking the client to photograph that licence for the fourth time this month. Welcome to option 3!

That distinction is not a technicality and it is not a workaround. It is the difference between two firms sharing responsibility for one decision and two firms each making their own decision from good information.

It is also why consent cannot be an afterthought. Identity information moving between firms engages your Privacy Act obligations quite separately from anything in the AML/CTF Act.

Why we've been building for this

We didn't start this in July 2026.

VerifiMe was built on a premise that looked slightly early at the time: that verification would stop being a one-off event at onboarding and become something a person carries between the businesses they deal with. Hence the accreditation, hence a platform architected around a verified record rather than a stored image of a document, hence consent as a design principle rather than a tick-box added at the end.

For several years that was a conviction with a modest audience. Tranche 2 turned it into a queue.

Firms are also solving it without waiting for us. A mortgage and finance provider we work with recently brought its legal partner onto the platform for precisely this reason — so their shared clients stop uploading the same documents twice in the same transaction, and so neither firm is emailing identity documents to the other. Nobody asked us to build that. Two businesses looked at the duplication in front of them and moved.

When clients start solving your roadmap for you, that is the clearest signal you will get.

VerifiOnce

It has a name, and it goes live in September with a first group of client firms.

VerifiOnce lets a client verified through one firm on the platform pass their verified information to another firm in the same transaction — with their consent, each time, to a named recipient. The receiving firm runs its own check against reliable and independent data and keeps its own evidence pack. No subscription for the receiving firm, no onboarding, no identity documents in anybody's inbox.

We are starting with a small group rather than opening it to everyone at once, and not out of caution for its own sake: the firms in that first group are the ones whose transactions will tell us what needs adjusting before it goes wider. If you would like to be in the next group, reply to hello@verifime.com. If duplicate verification is costing you time you cannot bill and goodwill you cannot recover, we would like to hear how it is landing in your practice.


This article is general information about the AML/CTF framework and is not legal advice. Your obligations depend on your own designated services and risk assessment. Refer to AUSTRAC's guidance on reliance and CDD, and take your own advice.

Read More
Beyond the ID Check
An identity check is where AML/CTF compliance begins, not where it ends. Since 1 July 2026, real estate agents, accountants, lawyers and other Tranche 2 businesses have carried the full weight of Australia's AML/CTF regime. Much current guidance rightly notes that an ID check alone does not cover ongoing monitoring or reporting. The practical question is how those obligations should be met, and what role a platform should play.

28 September 2026

Introducing VerifiOnce: identity verification that travels with your customer
If you verify customers for a living, you already know the pattern. The same person walks into a transaction, gets asked for the same passport and driver's licence, and goes through the same process — for you, and then again for the next business in the chain, and the next. VerifiOnce changes that. This post is an introduction to what it is, what it isn't, and how it fits alongside VerifiMe.

17 September 2026

Tranche 2 for accountants: two identity regimes, one client relationship
From 1 July 2026, accountants join the list of professions captured by Australia's Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act). For most practices, this prompts the same first question: do I now have to re-do identity verification on every client? The honest answer is more nuanced than the headlines suggest — and understanding that nuance is the difference between a calm, proportionate transition and a costly over-correction.

2 May 2026

Ready to meet compliance requirements with VerifiMe®?

Get started
VerifiMe Australia Copyright 2026
VerifiMe acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their Elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.