‹ All resources · Electronic signatures and Australian law
Compliance · 18 August 2026 · 8 min read
How to verify a client's identity online in Australia: the 2026 guide
Last updated 8 September 2026
Manual sighting, video calls, or electronic verification against government records — the three ways Australian practices verify client identity, what the TPB and AUSTRAC expect, and how to do it without storing copies of IDs.
Every Australian accounting, tax and professional practice now has a reason — usually several — to verify who a client actually is. The Tax Practitioners Board expects a proof-of-identity process for every new client (TPB(GS) 42/2022). Since 1 July 2026, accountants providing designated services are AML/CTF reporting entities with customer-due-diligence obligations to AUSTRAC. And identity fraud against practices is rising: stolen identities lodging returns, redirected refunds, and impostors signing engagement letters.
The question is no longer whether to verify, but how — and the three accepted methods differ enormously in effort, evidence and risk.
Method 1: sighting documents in person
The traditional approach: the client brings their driver licence or passport into the office, you sight it, and you note that you did. It works, and for walk-in clients it remains perfectly acceptable — but it doesn't scale to remote clients, it depends entirely on your ability to spot a fake, and the common habit of photocopying the document for the file creates a privacy liability the TPB itself warns against. A filing cabinet of ID copies is a honeypot.
Method 2: video sighting
A video call where the client holds up their ID solves the distance problem and satisfies the guidance when done carefully. But it takes an appointment, the evidence is only as good as your notes, and you are still judging a document's authenticity through a webcam. Most practices treat it as a fallback, not a system.
Method 3: electronic verification against official records
The strongest method checks the document's details against the records of the authority that issued it — the licence against the state registry, the passport against the passport office, the Medicare card against Services Australia — through the Australian Government's identity-verification framework, with the individual's express consent.
Good electronic verification adds a second, independent check: a biometric face match, where the client takes a liveness-checked selfie that is compared to the photo on the document. A stolen licence fails the selfie; a forged document fails the record check. Together they answer both questions that matter: is this document real, and is this person its owner?
The privacy profile is also better than either manual method, done right: the client enters their document details directly with the verification service, so the practice never sees or stores a document number at all. What the practice keeps is the outcome — verified or not — with timestamps and a consent record.
What a defensible process looks like
- Verification happens before you act for the client — anchored to onboarding or the engagement letter.
- The client consents expressly, and the consent is recorded with the time it was given.
- The check uses more than one source — a government-record match plus a biometric match, not a glance at a photo.
- You keep evidence of the check and its outcome, but not copies of the documents themselves.
- Screening for politically exposed persons and sanctions runs where your risk assessment calls for it.
- There's a manual fallback for clients who can't complete an online check — recorded as such, never mixed up with a government-record result.
How it works in Siggy
Siggy Australia — an accredited Australian Identity Service Provider — builds this process into the platform your clients already sign with. You enter the client's name and email; they receive a link branded as your practice; they consent, confirm a photo ID and take a quick selfie on their phone. About two minutes, no account, no app.
Your dashboard shows the outcome — verified, or could not be confirmed — along with the kind of document checked, the consent record and the PEP & sanctions screening status, all in a tamper-evident audit trail. Checks are prepaid, from $6.00 each, with screening included; a credit is only used when the client actually consents and the check starts.
On the record-keeping itself, the TPB's position is that you should not be holding copies of identity documents at all — what it wants is a contemporaneous record of the check, kept for five years after the engagement ends. Which regime asks for what sets that out beside the AML/CTF obligations, which are triggered differently.
Comparing per-check prices between providers? The Siggy vs Annature comparison puts identity-verification costs side by side, with sources and dates.
This article is general information for Australian practices, current at the publication date — it is not legal or compliance advice. Confirm obligations for your circumstances with your professional adviser or the relevant regulator.
See it in practice
Send your first document in minutes. Free to start, no card, and signers never need an account.
Try for free
