Compliance7 min read

Someone Else's Data Breach Is Your AML Problem Too

The AML/CTF Act tells you to collect identity information and keep the record for seven years, which quietly turns your practice into something worth stealing. AUSTRAC's data breach guidance covers that, and it also covers the case nobody expects: a breach at some other organisation that never touches your systems and still weakens every identity check you run. Here is what it expects you to do about both.

2026-08-07· AML Mate Team
Someone Else's Data Breach Is Your AML Problem Too

Six weeks into the regime, your practice holds something it did not hold in June: names, dates of birth, addresses, document numbers, and a verification record for every client you have onboarded since 1 July. The Act told you to collect it and to keep the record for seven years.

That pile is now an asset to somebody who is not you.

AUSTRAC's guidance covers two situations, and the second one surprises people

The first is obvious: your own systems are breached. The second is not.

This guidance applies to you if your business has been directly affected by a data breach, or impacted by an external data breach that affects your services or customers.

(AUSTRAC, data breaches and AML/CTF considerations, updated 13 April 2026.)

So a breach at an organisation you have never dealt with, that never touches a single one of your systems, can still land in your lap. Not because you did anything, but because of what it does to the reliability of your customer due diligence.

Why a breach somewhere else weakens your CDD

AUSTRAC puts the mechanism plainly: criminals may misuse sensitive or personal information drawn from data breaches to exploit your business and avoid detection, including by using breached information or credentials to gain access to an account, system or network.

Think about what that means for the checks you have been running since July. You collect a name, a date of birth, an address and a document number, and you verify them against a reliable source. That process assumes the person in front of you is the only one who holds that combination.

After a large breach, that assumption is worth less. The details still match, because they are real details. They are simply no longer private.

None of that makes verification pointless. It does mean a clean match is a weaker signal than it was, and that is a risk-assessment fact rather than a philosophical one.

The obligation nobody is doing yet

Here is the part of the guidance that reads oddly the first time, because it asks you to go looking:

We encourage you to proactively identify data breaches that may affect you.

Two suggested ways, both cheap:

That second one takes about a minute and nothing in a small practice is currently doing it. The first is a habit rather than a system: when a breach is in the news and it plausibly covers your client base, that is a trigger to think about the accounts and matters it touches, not a news story to scroll past.

What to watch for, translated

AUSTRAC's indicator list is worth reading, with one caveat. It is written for entities with online accounts, so a good part of it is about IP ranges, device registration, failed security questions and time zones. An accounting or conveyancing practice does not have those signals, and pretending otherwise produces a policy nobody follows.

The ones that do translate to professional services:

  • a client changing phone, email and address all at once, or in quick succession
  • a client asking to change those details immediately before a large or unusual transaction
  • inconsistent or invalid details, such as a mobile number that is disconnected
  • a billing or delivery address in a different region or country to the residential address
  • a client who strongly prefers email or web chat and avoids anything else
  • a new client presenting the same document number, or the same name and date of birth, as an existing client

That last one deserves its own moment. AUSTRAC's suggested control is to allow a given combination of name, document type and document number to be used once to create a customer profile, so a single stolen identity cannot be used to open several. In a firm using spreadsheets, nothing checks that. In a system, it is a uniqueness constraint.

Two controls that suit a small firm

Both are in the guidance, and both cost nothing:

Confirm the person matches the document. Check signatures, photographs and other identifiers, or ask the person to send a photograph of themselves holding their photo identification. It is unglamorous and it defeats the entire class of attack that relies on holding correct details for someone else.

Slow things down when something is off. For clients who remain high risk or suspicious, AUSTRAC suggests measures that let you scrutinise a transaction before it completes rather than after. For a professional practice the equivalent is refusing to progress the matter until the discrepancy is resolved, which is also what the before-you-act rule already requires.

The other half: hold less

Everything above is about detecting misuse of data that leaked from somewhere else. The other side of the problem is the pile in your own office, and the good news is that the Act asks for far less of it than most firms think.

You must keep the record: the information taken from the document, the verification method and its outcome, and your risk decisions, for seven years. You are not required to keep scanned copies or photocopies of the identity documents themselves (AUSTRAC, initial customer due diligence).

So a folder of licence and passport scans kept "just in case" is not a compliance safeguard. It is the most attractive thing in your office to a criminal, held for a reason that does not exist. We went through what to keep and what to destroy in this piece, and if you have been assuming the small business exemption keeps you outside the Privacy Act, that changed too.

A breach you cannot have is better than a breach you handle well.

Where AML Mate fits

Identity images from the hosted verification never reach us at all: they stay with the verification provider and we keep the outcome and a reference. A document you upload to a client file yourself is destroyed automatically 90 days after you complete CDD, while the verification record is kept for the full seven years. Client details are encrypted at the application layer and data stays in Sydney. The detail is on our security page.

That design is not a feature we added for marketing. It is the direct consequence of the point above: the safest way to survive a breach of identity documents is not to be holding any.

The short version

  • AUSTRAC's data breach guidance applies to you even when the breach happened somewhere else entirely.
  • A clean identity match means less after a large public breach, because the details are real but no longer private.
  • You are expected to look for breaches that may affect your clients. Register with the ASD Alert Service, and treat a relevant breach in the news as a trigger.
  • Watch for details changing all at once, changes just before a large transaction, and two clients sharing a document number or a name and date of birth.
  • Ask the person to prove they are the person in the document.
  • Keep the record for seven years. Do not keep the scans. They are a liability the Act never asked for.

The uncomfortable shape of this one is that compliance created the exposure. You built the pile because you were told to. What you get to choose is how big it is.


This article is general information, not legal advice. For advice specific to your circumstances, consult a qualified AML/CTF professional.

data-breachprivacycddidentity-crimerecord-keepingaustractranche-2

Ready to build your AML/CTF program?

AML Mate generates your AML/CTF program in 15 minutes using AUSTRAC's official templates. Start a 14-day free trial, cancel anytime.

This article is based on AUSTRAC's publicly available guidance. It does not constitute legal or compliance advice. Consult a licensed compliance professional for complex situations.

Data Breaches and Your AML/CTF Obligations in Australia