A client refuses ID verification. What do you actually do?
A client will not provide ID or will not complete verification. Here is the obligation, the options, and where the line sits between an awkward client and a reportable concern.
A client refuses ID verification. What do you actually do?
A buyer says they will sign whatever you need but will not upload a licence photo. A vendor's "representative" turns up with a signed authority and no ID of their own. Someone tells you, politely or not, that they do not see why an agent needs a copy of their passport to sell a house.
The fastest way to see where you stand
Set up customer due diligence (CDD) in AML Simple and a refusal shows up as an incomplete file, not a mystery:
- Sign up (around 2 minutes). Your ABN pulls your registered business details automatically.
- AUSTRAC Readiness Check (around 5 minutes). Confirms which of your services actually need CDD before you act.
- Client verification link. Send the client a link to complete ID checks on their own phone. The moment they submit it, that is timestamped on the file. If they never submit it, the file simply stays visibly incomplete, no submission timestamp, nothing filled in, instead of living in someone's memory as "they said they'd get to it."
That record matters more than it sounds. If a file is ever reviewed, "verification link sent 14 March, no submission on file" is a defensible answer. "I remember they seemed fine about it" is not.
What the obligation actually is
If your agency provides a designated service under AUSTRAC Tranche 2, you must complete CDD before you can provide that service. That is the rule. It does not say you must convince a reluctant client, and it does not say a refusal must be treated as suspicious. Those are two separate questions, and mixing them up is where agents get into trouble either direction.
The CDD obligation: collect and verify identity, ownership structure, and enough information to assess risk, before you act for the client.
The reporting obligation: if something about a client or transaction gives you an actual suspicion of money laundering, terrorism financing, or another matter listed in the AML/CTF Act, you must consider whether it triggers a suspicious matter report (SMR).
A client who will not provide ID fails the first test. It does not automatically satisfy the second.
Refusing to provide ID is not automatically suspicious
Plenty of reasons a client stalls on verification have nothing to do with concealment. They are travelling and cannot get to a scanner. They are uneasy about handing personal documents to an unfamiliar app, which is a reasonable instinct in 2026. They are older and unfamiliar with digital ID checks. They are busy and it is genuinely not a priority for them yet.
None of that is grounds for a suspicious matter report. Forming a suspicion because someone was slow, private, or irritated about the process is not what the reporting obligation is for, and treating ordinary friction as suspicious activity does two things badly: it wastes AUSTRAC's attention on noise, and it risks unfair treatment of a client who was simply inconvenienced.
What you do while CDD is incomplete
The clean answer is also the boring one: you do not provide the designated service until CDD is complete. Not "provide it and chase the paperwork after." Not "proceed because the deal is time-sensitive." The service and the CDD obligation are tied together, and a signed contract does not retrofit a missing identity check.
In practice that usually means:
When a client stalls on verification
Declining to act is not a punishment and it is not a report. It is simply what happens when a required step cannot be completed. Plenty of legitimate clients will still walk away frustrated, and that is a normal, unremarkable outcome of the rule, not a sign anything went wrong.
Where the line actually is
A suspicion worth reporting is not "this client is difficult." It is a pattern that, taken together, gives you an actual reason to think something is off, not just an inconvenience. Current guidance points to things like these shifting a file from awkward to concerning:
- The client offers several different forms of identification, or documents that appear altered or inconsistent with each other
- Someone actively avoids ever being identified while still trying to direct or benefit from the transaction
- The refusal comes with pressure to complete the transaction unusually fast, or with cash, specifically to avoid the check
- Details volunteered about the client or the source of funds do not add up, and the client becomes evasive when asked to clarify rather than simply declining
One of these on its own is rarely enough. It is the combination, plus your own assessment of the file, that turns "I could not complete CDD" into "I have an actual suspicion." Those two conclusions require different next steps, and it is worth writing down which one you have reached and why, even briefly, on the file.
If you do form a suspicion
If your assessment does cross into suspicion, the obligation is to consider filing an SMR through AUSTRAC's channels. Two things matter here more than anything else:
You do not need certainty. The threshold is a reasonable suspicion, not proof.
You must not tell the client. Disclosing that you have filed, or intend to file, a suspicious matter report is itself a separate offence under the tipping-off provisions, regardless of how justified the suspicion turns out to be. Decline to act because CDD is incomplete, and stop there. Do not explain the real reason.
Our suspicious matter reports guide covers what triggers an SMR and how filing actually works if you get to that point. Verification itself is not a one-off event either; a client who passes CDD today can still trigger a fresh look later, which is covered in our ongoing CDD guide.
Let the file speak for itself
AML Simple's client verification link timestamps every submission, so an incomplete file is documented as incomplete, not just remembered that way. Free to start.
Start your AML program