AML Compliance Guide
← Back to compliance toolkit

Free AML/CTF Tranche 2 Compliance Toolkit

Customer Due Diligence

Send a secure link to your customer. They complete identity verification — you get a confirmed name, a sanctions screening result, and a timestamped audit trail in your dashboard. Only takes minutes end-to-end.

Why this is required: All Tranche 2 reporting entities must verify the identity of customers before providing a designated service, and keep those records for at least 7 years. AML/CTF Act 2006 (Cth) Pt 2 Div 2 ↗

See the customer experience before you buy

CDD check links are a paid feature, but you can send a free test link to your own inbox to try the full customer flow first.

Create a free account to try it →

What's checked

Identity verification

  • Passport (MRZ checksum-validated, any issuing country) or Australian driver licence
  • Live selfie matched to document photo, with a manual-review fallback for lower-confidence matches
  • Basic in-browser liveness check (blink detection) to catch a static printed photo
  • Legal name and date of birth extracted and returned
  • Document images discarded after processing — only the extracted result is kept

Sanctions & PEP screening

  • DFAT Consolidated List — Australia's autonomous sanctions regime
  • OpenSanctions' global Politically Exposed Persons (PEP) database
  • Checked live at submission time against current OpenSanctions data
  • Every named director, beneficial owner, or trustee screened individually, not just the primary applicant

Business verification

  • ASIC company extract parsed for company name, ACN, status, officeholders, and shareholders
  • Company name cross-checked against the ABN Lookup government registry
  • Beneficial owners (25%+ shareholding) automatically flagged
  • Deregistered or inactive companies flagged for review
  • ABN and ACN checksums validated
  • Trust deeds, partnership agreements, and association constitutions can be uploaded as supporting evidence of ownership/control structure

See it in action

Swipe through the actual screens — from generating the link to seeing the screening result.

Ready to run your first CDD check?

Generate a link, share it with your customer — verified and screened in minutes. Not sure yet? Send a free test link to your own inbox first.

Free account · No credit card required · Try it with a free test link first

Frequently asked questions

What is Customer Due Diligence (CDD) and why is it required?
CDD is the process of verifying a customer's identity before providing a designated service. Under the AML/CTF Act 2006 (Cth) Part 2 Division 2, all reporting entities must collect and verify identifying information for individual customers before or as soon as practicable after the commencement of a business relationship. Tranche 2 businesses (accountants, lawyers, conveyancers, real estate agents) are required to implement CDD from 29 July 2026.
What does the identity verification actually check?
Our verification checks a government-issued passport or Australian driver licence and confirms that the person presenting it matches the document via a live selfie, backed by a basic in-browser liveness check (blink detection). Passport data is checksum-validated against the MRZ; driver licence extraction is lower-confidence and flagged for manual confirmation. This is a screening aid, not a certified anti-spoofing product — genuine matches should still be treated as a starting point for your own review, not standalone proof of identity.
Which sanctions lists does the screening cover?
Screening is performed live against OpenSanctions at submission time, covering the DFAT Consolidated List (Australia's autonomous sanctions regime) and OpenSanctions' global Politically Exposed Persons (PEP) database. Every named director, beneficial owner, or trustee is screened individually, not just the primary applicant.
Does the customer's ID document get stored on your servers?
Identity document images are captured and processed entirely within our platform. Only the verified legal name and, where available, date of birth are stored in your account — the raw document image is not retained after verification completes.
Is this sufficient for all CDD obligations?
This tool covers individual identity verification, DFAT and PEP screening, and business verification (ASIC extract cross-checked against the ABN Lookup registry, with beneficial owners at 25%+ shareholding automatically flagged) — the core CDD requirements for most standard-risk customers. However, your AML/CTF program may still require additional steps for higher-risk customers (enhanced CDD) or source-of-funds/source-of-wealth checks. The result here is one input into your overall CDD assessment, not a substitute for your program.
Which customer types does this support?
Individual, Sole trader, Company, Trust, Partnership, Unincorporated association, and Government body — each with its own tailored data-collection and verification flow. Trusts capture trustee/controller and beneficiary details plus a trust deed upload; Partnerships capture each partner's name, address, and ownership share (validated to sum to 100%) plus a partnership agreement upload; Sole traders get an ABN lookup alongside personal ID verification; Unincorporated associations and Companies can upload their governing constitution.
What happens if there is a sanctions match?
The result will show "review required" in your dashboard. You will need to manually review the match — many hits are false positives (common names). If you believe a match is genuine, you must not proceed with the transaction and should consider your SMR obligations under s 41 of the AML/CTF Act. Do not tip off the customer that a report may be made.
How long are CDD records retained?
Under the AML/CTF Act, CDD records must be retained for at least 7 years from the date the business relationship ends or the transaction is completed. Records are stored in your account and can be exported at any time.