‹ All resources · Electronic signatures and Australian law

Compliance · 7 July 2026 · 6 min read

TPB proof-of-identity requirements: a practical guide for tax practitioners

Last updated 8 September 2026

The Tax Practitioners Board expects registered tax practitioners to verify client identity — through the Code of Professional Conduct rather than a standalone rule. What TPB(GS) 42/2022 asks for, which documents count, and how to meet it without keeping copies of client IDs.

Since the Tax Practitioners Board issued TPB(GS) 42/2022, registered tax and BAS agents have been expected to verify the identity of new clients — and their representatives — before providing services. The ATO's own agent-linking steps lean on the same expectation.

This article is the how-to. If you are working out which regime applies to your practice, and why most answers get it wrong, start there instead — the TPB obligation and the AML/CTF one have different legal bases, different triggers and different record clocks.

The goal is fraud prevention: stolen identities lodging returns, redirected refunds, and fake authorisations are real and rising. The TPB's answer is a proof-of-identity process every practice must be able to demonstrate.

What the guidance expects

  • Verify each new individual client's identity using original or certified documents, or a suitable electronic verification process.
  • One primary photographic document (passport, driver licence), or combinations of primary non-photographic and secondary documents (birth certificate, Medicare card, bank statement).
  • For entities: verify the entity (ABN/ACN records) and the individuals acting for it.
  • Keep a record that verification happened — but the TPB specifically cautions against retaining copies of identity documents unless necessary, because holding them creates a honeypot.

Remote verification is fine — done properly

Most practices now onboard clients they never meet. The guidance contemplates this: video calls where documents are sighted, or electronic verification services that check document details against the issuing authority's records.

The second path is stronger and faster: no appointment, no sighting, no photocopy. The client consents, their details are checked at the source, and the practice records the outcome — verified or not — rather than the document itself.

A workflow that satisfies the record-keeping without the risk

The pattern we recommend: anchor verification to the engagement letter. Send the letter for electronic signature, verify identity in the same sitting, and file the signing certificate — which already records the signer's email, timestamps and the tamper-evident document hash — alongside the verification outcome.

That gives you a complete, dated evidence trail for every client file, with nothing sensitive to shred later. Siggy produces the signing certificate today, and identity verification is now live too: an electronic check against the issuing authority's records, with a biometric face match, run with your client's consent from a link you send — from $6.00 per check.

Keep the retention clocks apart: the TPB record runs for five years after the engagement ceases, while the client's own declaration under s 388-65 runs for five years after it is made, and it is the client who must keep that one.

Running a practice? Here is how accountants use Siggy ›

This article is general information for Australian practices, current at the publication date — it is not legal or compliance advice. Confirm obligations for your circumstances with your professional adviser or the relevant regulator.

See it in practice

Send your first document in minutes. Free to start, no card, and signers never need an account.

Try for free