Separate the evidence from the image
A stored identity image and a complete customer due diligence record are different things. AUSTRAC explains that the record must show the relevant information and decisions, but that the AML/CTF Act does not generally require a scanned or photocopied identity document. An image alone may not explain what staff verified or how they resolved a difference. Start with the evidence needed to demonstrate the check. Consider other legal obligations separately before deciding what copies to collect or keep.
- Identity image
Shows the document that was copied. It does not by itself explain the check.
- CDD record
Shows the information used, the verification result and how differences were resolved.
An image and a CDD record answer different questions
The AML/CTF Act does not generally require a scanned identity document. Check other applicable duties before deciding what copies to retain.
Separate evidence questions. An answer to one does not settle the others.
Record what the check established
A suggested CDD record identifies the information used, the verification step, the result and the person or process responsible. Where a difference arises, explain how it was resolved or escalated. Avoid a note that says ID checked without showing what that means. Equally, avoid collecting extra images simply because storage is available. The process should connect the information retained with the purpose of the check. Staff need clear instructions so similar cases do not produce inconsistent or incomplete evidence.
Example: an unclear name difference
Imagine a document and the customer’s supplied details use different forms of a name. Saving both files does not explain the decision. A useful record notes the difference, the additional information considered and the conclusion or escalation. This example does not prescribe a particular verification method. It illustrates the value of recording the reasoning. A later reviewer should be able to understand the work without asking the original staff member to reconstruct the event from memory or infer it from filenames.
Design for privacy and retrieval
Review the record fields with the person responsible for privacy and security. Identify which information is necessary, who can access it and how the record can be retrieved. Keep the relevant retention event linked to the customer record. If a supplier performs a check, confirm what supporting evidence remains available to your business. A reduced number of document copies can lower unnecessary exposure, but only when the remaining record still supports the applicable obligations. Do not delete existing material without checking retention and other requirements.
Check supplier terminology
If a supplier says verified, ask what that status establishes and which data supports it. Record the meaning used in your procedure. The business should be able to explain the check without assuming the label covers every identification question. Keep unresolved mismatches visible until the relevant process reaches a supported decision.