Compliance9 min read

The Client Won't Hand Over ID. The Act Has Already Decided What Happens Next.

If you cannot establish who your customer is on reasonable grounds, you must not provide the designated service. That is the whole rule, and it is short. What it does not tell you is the difference between a client who will not prove who they are and one who cannot, which are two different situations that look identical from your side of the desk. Here is how to tell them apart, and what has to be in the file either way.

2026-08-02· AML Mate Team
The Client Won't Hand Over ID. The Act Has Already Decided What Happens Next.

A new client sits down. You ask for a driver licence and one other document. They say no.

Maybe they say it politely. Maybe they say the last three accountants never asked. Maybe they hand over the licence quite happily and then go quiet when you ask who actually controls the trust. However it arrives, you are now standing in the one part of Tranche 2 where you have no discretion at all.

The line that decides it

AUSTRAC's initial customer due diligence guidance settles it in a single sentence:

If you can't establish a matter on reasonable grounds, you must not provide the designated service.

(AUSTRAC, overview of initial customer due diligence, updated 27 March 2026.)

Read what it does not say. It does not say weigh it up, or consider how long they have been a client, or judge how likely this particular person is to be laundering anything. Once you cannot establish the matter, the service is off the table. The same page adds the other half: you must submit a suspicious matter report if you reasonably suspect the customer is not who they claim to be.

One moment, two obligations. Neither of them is optional, and the second one survives even after the client walks out.

"Won't" and "can't" look identical and are not

From your side of the desk, a client who refuses and a client who is unable produce exactly the same silence. The Act treats them very differently, and getting it wrong costs you in both directions.

Turn away someone who genuinely could not produce documents and you have lost a legitimate client for no reason, which is a commercial problem and, in some cases, a fairness one. Wave through someone who would not produce them and you have provided a designated service you were prohibited from providing, which is a different kind of problem entirely.

So the first question is not "do I trust this person". It is "is this refusal, or is this incapacity".

When it is "can't", there is a documented path

AUSTRAC carves out the case where an individual cannot obtain identity evidence, or cannot access it, for reasons beyond their control. You are considered compliant with your obligation to establish that person's identity if you have done all of the following:

  • implemented AML/CTF policies that mitigate and manage the additional ML/TF risk these situations create
  • taken reasonable steps to establish the individual is who they claim to be, such as applying alternative identification procedures
  • identified the customer's ML/TF risk from the KYC information reasonably available to you, before you start providing the service
  • collected KYC information appropriate to that risk
  • taken reasonable steps to verify it using data reasonably available to you, in a manner appropriate to that risk

(AUSTRAC, overview of initial customer due diligence.) AUSTRAC publishes worked examples of alternative identification procedures, a page on identifying individuals who do not have standard ID, and specific guidance on alternative ID for First Nations peoples.

Who this actually covers, in a normal suburban practice: someone who arrived in Australia recently, someone who left a violent household without their paperwork, an older client in residential care whose licence lapsed years ago, someone from a remote community. None of that is exotic. If you act for the general public you will meet it this year.

The thing to notice is that every one of those five conditions is something you have to do, and therefore something you can be asked to show. "They didn't have a licence so we went ahead" is not this carve-out. It is the absence of one.

When it is "won't", the refusal may itself be the report

The other branch is colder. AUSTRAC is explicit that people trying to exploit your services will try to evade identification, and that you are expected to watch for it throughout the CDD process.

A person may commit a criminal offence if they start to receive a designated service from you and they use a false name, receive it on the basis of anonymity, are commonly known by two or more names and use one without disclosing the other, or knowingly give you false or misleading information or documents. If you have reasonable grounds to suspect any of that, you must report it (AUSTRAC, overview of initial customer due diligence).

There is a sting in the tail of that section as well: you may commit a criminal offence if you start providing a designated service to a person using a false customer name, or on the basis of anonymity. The client's evasion does not stay the client's problem once you proceed anyway.

If you form a suspicion, the clock is short. An SMR is due within 3 business days after the day you formed the suspicion, or 24 hours if it relates to terrorism financing. If you are claiming legal professional privilege over information in the report, you get up to 5 business days, and that extension does not apply to terrorism financing (AUSTRAC, suspicious matter reports, updated 8 July 2026). Our SMR guide with worked examples walks through what "reasonable grounds" looks like in practice.

Nobody emails you to start that clock. It starts when you notice.

The part firms get wrong: you cannot explain yourself

Here is where good instincts do damage. Having decided to walk away, the decent human response is to be straight with the client. "Sorry, I can't act for you, it's the AML rules."

That sentence is a problem, and not for the reason most people assume.

AUSTRAC's guidance to financial institutions on declining higher-risk customers is worth reading even though you are not a bank, because the reasoning carries over. Where possible, give a genuine reason that does not indicate you are suspicious. Telling someone the relationship is ending because their activity falls outside your risk appetite will generally not be tipping off. But citing vague "AML/CTF obligations", or saying you are not permitted to say why, "may, itself, increase the risk of tipping off" (AUSTRAC, financial institution customers assessed as higher risk, updated 23 April 2026).

Read that twice. The evasive non-answer people reach for as the safe option is the one AUSTRAC names as raising the risk. You are also required to manage tipping off while you are still in the room, during enhanced CDD, not only afterwards (AUSTRAC, enhanced customer due diligence, updated 15 July 2026).

The practical version: decide your decline wording before you ever need it, keep it commercial and true, and never make the AML rules the stated reason. We covered the boundaries in the tipping off rules explained.

"But I have already started acting for them"

There is a delayed CDD path, and it is narrower than people hope. It applies only to certain services, including a service provided at or through a permanent establishment in Australia, account opening and deposits by a financial institution, certain financial market transactions that must be performed rapidly, real estate transactions, and services provided in a foreign country.

Even then, before you start you must determine on reasonable grounds that delaying is essential to avoid interrupting the ordinary course of business and that there is a low additional ML/TF risk in delaying. You must already have AML/CTF policies that complete initial CDD as soon as reasonably practicable and no later than the timeframes in the Rules. Civil penalties apply if you do not verify KYC information inside those timeframes (AUSTRAC, delayed initial customer due diligence, updated 22 April 2026).

Real estate agents in particular should note their transactions are on that list, and then note that the conditions still bind and the policies have to exist in advance. Delayed CDD is a timing concession granted to firms that planned for it. It is not a retrospective excuse.

What goes in the file either way

You must keep records showing how you complied with initial CDD for each customer: the type and content of the data you collected, and your identification of ML/TF risk and the other decisions you made as part of initial CDD. Seven years from the end of the business relationship, or from the last occasional transaction (AUSTRAC, overview of initial customer due diligence, referring to Act section 111).

That middle clause is the one firms skip. The decision is the record. If you walked away, the file should show what you asked for, what came back, what you could not establish, and what you decided to do. If you proceeded on the beyond-their-control path, the file should show all five conditions being met, not just a note that the client seemed fine.

Worth knowing while you are in there: you are not required to keep scanned copies or photocopies of the identity documents themselves. A lot of firms are sitting on folders of licence scans they were never obliged to collect, and every one of them is a privacy liability rather than a compliance asset. See what to keep and what to destroy and, if you have been assuming the small business exemption covers you, the Privacy Act change.

The short version

  • Cannot establish the matter on reasonable grounds, do not provide the service. There is no judgement call left at that point.
  • Suspect they are not who they claim, that is an SMR. Three business days, 24 hours for terrorism financing, five if you are claiming privilege.
  • "Can't" has a documented path with five conditions. "Won't" does not, and may be an offence in its own right.
  • Do not decline with a vague AML excuse. That is the version AUSTRAC warns about.
  • Write down the decision, not just the documents. The decision is what an examiner asks to see.

The uncomfortable part of all this is that the moment arrives with no warning and no deadline attached to it. A client says no, and by the time you have finished the conversation you are already either compliant or not. Decide how that conversation goes before you have it. It is the only preparation that helps once you are in it.

If you want the trail built as you go rather than reconstructed later, that is the part AML Mate handles: the CDD workflow will not let a client be signed off with the matter unestablished, and what you decided is captured with the date on it. See customer due diligence before you act for where this sits in the wider sequence, and family trust CDD for the structure that most often stalls at "who actually controls this".


This article is general information, not legal advice. For advice specific to your circumstances, consult a qualified AML/CTF professional.

cddcustomer-identificationsmrtipping-offrecord-keepingaustractranche-2

Ready to build your AML/CTF program?

AML Mate generates your AML/CTF program in 15 minutes using AUSTRAC's official templates. Start a 14-day free trial, cancel anytime.

This article is based on AUSTRAC's publicly available guidance. It does not constitute legal or compliance advice. Consult a licensed compliance professional for complex situations.

Client Won't Provide ID? What AUSTRAC Requires You To Do