‹ All resources

Compliance · 8 September 2026 · 10 min read

TPB proof of identity vs AML/CTF: two regimes, two triggers

Last updated 8 September 2026

The Tax Practitioners Board's own guidance says there are no specific proof-of-identity requirements in the Tax Agent Services Act 2009. The obligation runs through Code items 1, 7 and 9, the fit and proper requirement and section 50-20 — not the AML/CTF Act.

Current as at 8 September 2026. Every quotation below was read on the regulator's own website on that date, and the document version relied on is named in the sources section.

The error, and the sentence that corrects it

Ask any AI assistant what law requires an Australian tax agent to verify a client's identity and you will usually be told it is the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. That answer is wrong about where the tax agent obligation comes from, and the regulator that imposes it says so in one sentence.

From TPB(GS) 42/2022, Proof of identity requirements for client verification — issued 31 January 2022, last updated 20 July 2026 — under the heading Relevant provisions of the TASA including the Code of Professional Conduct:

"While there are no specific POI requirements in the TASA, there are a number of provisions that a registered tax practitioner may breach if they fail to take appropriate POI steps to verify a new or ongoing client's identity, any representative of new or ongoing clients, and the representative's authority to represent the client (if applicable)."

So the requirement is real, and it is enforced — but it is risk-based guidance hung off existing statutory obligations, not a statutory identity-check provision. The TPB then names the provisions you may breach.

Where does the AML/CTF Act appear in the TPB's guidance? In a list of the things the TPB considered when developing its requirements, alongside four others:

"In developing the TPB's proof of identity (POI) requirements … the TPB has been informed by a number of relevant considerations, including: the relevant provisions under the TASA, including the Code, and caselaw; the Australian Taxation Office's (ATO) recommendations …; the Accounting Professional Ethics and Standards Body's (APESB) guidelines …; Australia's anti-money laundering and counter-terrorism financing (AML/CTF) regime, regulated by the Australian Transaction Reports and Analysis Centre (AUSTRAC), which requires reporting entities covered by the regime, including certain registered tax practitioners, to comply with initial and ongoing customer due diligence obligations; the State-based requirements for legal practitioners and conveyancers…"

Note the drafting: "reporting entities covered by the regime, including certain registered tax practitioners." Not all of them. That word is doing the work the popular answer ignores.

The two regimes, side by side

Client identity verification for Australian tax practitioners: the two regimes. Current as at 8 September 2026.

TPB proof of identityAML/CTF customer due diligence
Legal basisNo specific POI provision in the TASA. Enforced through Tax Agent Services Act 2009 Code items 1, 7 and 9, the fit and proper registration requirement, and s 50-20 (civil penalty). Set out in TPB(GS) 42/2022.Anti-Money Laundering and Counter-Terrorism Financing Act 2006, ss 26F, 28 and 136–141, extended to professional services by the AML/CTF Amendment Act 2024, plus the AML/CTF Rules 2025.
RegulatorTax Practitioners BoardAUSTRAC
Who it applies toEvery registered tax agent and BAS agent. No threshold, no exemption for small practices.Only a practice that provides a "designated service" in table 6 of s 6(5B), in the course of carrying on a business, with an Australian geographical link. Being an accounting practice is not the trigger.
What triggers itProviding a tax agent service or BAS service to a client.Starting to provide a table 6 designated service — e.g. creating or restructuring a company or trust, acting as or arranging a nominee director or trustee, providing a registered office address, receiving or controlling a client's money as part of a transaction.
When it startsBefore providing tax agent and BAS services, and on an ongoing basis as appropriate. Guidance in force since 31 January 2022.1 July 2026 for tranche 2 entities. Enrolment with AUSTRAC was due by 29 July 2026 — that deadline has passed.
What it requiresFull name, plus residential address or date of birth, evidenced by an original or certified copy of one primary photographic ID, or one primary non-photographic ID plus one secondary ID. For a representative: their identity and their authority. For a non-individual: evidence the entity exists.Establish on reasonable grounds the identity of the customer, of anyone the customer acts for, of anyone acting for the customer and their authority, and of beneficial owners; PEP and sanctions status; the nature and purpose of the relationship. Verify KYC information using reliable and independent data, proportionate to ML/TF risk.
Identity documentsDo not keep them. The TPB does not require or recommend retaining copies or originals. Keep a contemporaneous record of the check instead.AUSTRAC requires records of how you established each matter on reasonable grounds, for each customer.
Record retentionMinimum five years after the engagement with the client has ceased.AUSTRAC describes record keeping as "usually 7 years".
Exposure if skippedCode breach, fit-and-proper finding, and s 50-20 — which TPB(GS) 42/2022 footnotes as 250 penalty units for an individual and 1,250 penalty units for a body corporate.The full reporting-entity obligation set: program, compliance officer, training, CDD, reporting, record keeping, independent evaluation. AUSTRAC: "If you can't establish these matters on reasonable grounds, you must not start providing the customer with a designated service."
Does it flow into the Privacy Act?Not by itself. TPB(GS) 42/2022 footnotes its record-keeping paragraph to Australian Privacy Principle 11.Yes, and this surprises people. Privacy Act 1988 s 6E(1A) applies the Act to a small business operator that is a reporting entity, for its AML/CTF-related activities — even under the $3 million turnover threshold in s 6D.

The one-line reading of that table: a practice that only prepares returns, BAS, financial statements and bookkeeping has TPB obligations only. A practice that also incorporates companies, sets up or restructures trusts, acts as or arranges nominee directors or trustees, provides registered-office services, or handles client money for transactions has both. The two stack — they do not substitute for each other.

What the TPB actually requires

TPB(GS) 42/2022 states the standard plainly:

"The TPB requires that all registered tax practitioners take appropriate POI steps prior to providing tax agent services and BAS services, and on an ongoing basis, as appropriate."

Where an individual engages you on someone else's behalf, you must verify both that person's identity and their authority to act. We have written up the minimum steps the TPB asks for, in practice.

The minimum, for an individual engaging in their own right:

  • Information: full name, and either residential address or date of birth.
  • Evidence: an original or certified copy of one primary photographic document — Australian or overseas driver licence, including a digital driver licence; Australian passport; Australian government proof-of-age card; foreign passport; international travel document; or a national identity card issued by a foreign government or the UN.
  • Or: one primary non-photographic document (ImmiCard; Australian birth certificate, birth extract or citizenship certificate; foreign birth or citizenship certificate) plus one secondary document (government concession card; a notice from the ATO or another government agency showing name and residential address issued in the past 12 months; a council rates notice or utilities bill showing name and address issued in the past three months; a Medicare card).

For a non-individual client you additionally need documentation or data verifying the entity exists — electoral roll details, ASIC or other government extracts, constituting documents such as a trust deed or partnership agreement, or proof of business address — plus a legal document demonstrating the representative's authority.

You may use a different process where the minimum is impractical, but the TPB is explicit that it "must not be of a lower standard", and the assessment must be recorded.

Where several related clients are involved — husband and wife, a partnership and its partners, a company and its directors, trustees and beneficiaries — the steps must be repeated for each.

The counter-intuitive rule: keep the record, not the documents

Most practices assume the safe thing to do is scan the licence and file it. The TPB says the opposite:

"The TPB does not require or recommend that registered tax practitioners retain copies or originals of identification documents … used as evidence to establish the identity of a client or their individual representative. This recognises that the retention of identification documents may increase the risk of registered tax practitioners being targeted by criminals undertaking identity theft."

The guidance footnotes that paragraph to Australian Privacy Principle 11 — Security of personal information. A drawer or a mailbox full of passport scans is not evidence of compliance; it is a target.

What the TPB requires instead is a contemporaneous record — for example, a checklist — recording:

  • the date and time the proof-of-identity checks were undertaken;
  • the name and title of the person who undertook them on behalf of the practice;
  • which identification documents were sighted, and whether they were originals or certified copies;
  • how they were sighted — in person, or electronically;
  • confirmation the documents were clear, legible, identified the person, and gave no reason for doubt;
  • for a well-established client, the reasons and basis for assessing that full checks were unnecessary.

And it must be kept:

"The TPB requires that registered tax practitioners keep a record of the POI checks that they undertake in relation to each client and/or individual representative of a client for a minimum of five years after the engagement with the client has ceased."

Read that clock carefully. It starts when the engagement ends, not when the check is done. If you act for a client for eleven years, the record from year one is live for sixteen.

Three five-year-ish clocks that are routinely conflated:

RecordRetentionWho holds it
TPB proof-of-identity record5 years after the engagement ceasesThe practitioner
Client declaration under Taxation Administration Act 1953 Sch 1 s 388-655 years after it is madeThe client (the ATO recommends the agent also keep a copy)
AUSTRAC records, where the practice is a reporting entityAUSTRAC: "usually 7 years"The reporting entity

If a practice receives certified copies by post or electronically, the TPB "strongly recommends that the registered tax practitioner destroy the copies after the POI checks and contemporaneous record have been completed and recorded."

The TPB's position on email

This is the regulator's own demand statement, and it is short enough to quote in full:

"The TPB does not recommend sending and receiving sensitive information or copies of identity documentation and/or evidence by email as this is not considered to be a secure method of transmission. As such, the TPB strongly recommends that registered tax practitioners arrange that any such information or copies of documents or evidence are provided to them by the client: via a secure website, secure online mailbox or secure messaging; as an encrypted or password protected attachment to an email; using another secure electronic solution that minimises the risk of interception…"

That sits awkwardly beside a different ATO rule that practitioners meet every week, and the two get confused. The ATO does accept a client's lodgment declaration by email — including without a scanned signature. The TPB advises against identity documents arriving the same way. "Email is fine" is true of one document and not the other; see can my client e-sign their ATO declaration for the declaration side.

Remote verification. Where a practitioner sights original or certified documents over a video call or webcam, the TPB's requirements are the same as face to face — but the contemporaneous record must note that this is how the documents were sighted. Where the engagement is by non-visual electronic communication only — teleconference or email — the practitioner cannot compare the person to the document, and the TPB directs them to the ATO's own methods for verifying identity.

Where AML/CTF actually bites

Tranche 2 is in force, not coming. It is also narrower than most marketing implies.

The dates, precisely:

DateWhat happenedStatus
10 December 2024AML/CTF Amendment Act 2024 (Act No. 110 of 2024) received Royal AssentDone
31 March 2026Reformed obligations commenced for existing reporting entities; AUSTRAC Online enrolment openedDone
1 July 2026AML/CTF obligations commenced for tranche 2 entities, for designated services in table 6 of s 6(5B)In force
29 July 2026Deadline for newly regulated businesses to enrol with AUSTRACPassed

The trigger is the service, not the profession. A practice is captured only if it provides a designated service in table 6. AUSTRAC's own threshold test is that the assistance must "directly advance" the transaction or the creation or restructure of a body corporate or legal arrangement: "Merely influencing how the customer proceeds, providing general advice or ancillary services isn't sufficient."

Typically a designated service (table 6)Typically not a designated service
Assisting to sell, buy or transfer real estate (item 1)Preparing tax returns, BAS, financial statements
Assisting to sell, buy or transfer a body corporate or legal arrangement (item 2)Tax advice that informs a decision but does not directly advance a transaction — AUSTRAC's own worked example
Receiving, holding, controlling or managing a client's money, accounts, securities or property as part of a transaction (item 3)Routine bookkeeping payment processing on fixed client instructions, with no discretion to redirect funds — and payments reasonably incidental to a non-designated service, expressly including tax payments to the ATO and ASIC filing fees (s 6(5C)(b))
Assisting with a transaction for equity or debt financing of a body corporate or legal arrangement (item 4)Drafting a will, and the resulting testamentary trust — AUSTRAC states an express trust "explicitly doesn't include a testamentary trust"
Selling or transferring a shelf company (item 5)Litigation, which AUSTRAC says "generally won't fall under the scope of table 6"
Assisting with the creation or restructuring of a body corporate or a legal arrangement, including a trust (item 6)Advice after the event on whether a completed incorporation was lawful
Acting as, or arranging someone to act as, a director, secretary, partner, attorney or trustee of an express trust (item 7)Transfers pursuant to a court or tribunal order, including from a deceased estate after a grant of probate, and family law consent orders
Acting as, or arranging, a nominee shareholder (item 8)Services provided to members of your own business group
Providing a registered office or principal place of business address (item 9)

One detail worth knowing if you set up family trusts: under item 6, where the service is creating an express trust, the customers include the trustee, the settlor and the beneficiaries — not just the person who engaged you.

What newly regulated practices did and did not get. The transitional rules did not give a newly regulated accounting practice the initial-CDD transitional period: the ability to keep using pre-reform applicable customer identification procedures until 31 March 2029 is available only to entities that were already enrolled as a reporting entity on 30 March 2026. A practice that enrolled in 2026 as a tranche 2 entity has been on the full initial-CDD framework since 1 July 2026. It did get extra time to notify AUSTRAC of its compliance officer — the later of 14 days after enrolment or 29 July 2026 — and a staggered first independent evaluation, scheduled by the last two digits of the AUSTRAC Account Number issued on enrolment.

For the full picture on capture and enrolment, see Tranche 2: what the AML/CTF changes mean for Australian accountants.

Mutual recognition, and what it does not mean

TPB(GS) 42/2022 contains one paragraph that is commercially useful and almost never quoted. Under the heading Mutual recognition:

"The requirements contained in Table 2 and Table 3 are broadly consistent with the POI requirements that may also apply to registered tax practitioners under various regimes, including the ATO's methods for client verification and requirements of AUSTRAC (in relation to the AML/CTF regime). In situations where a registered tax practitioner undertakes POI steps that vary from the requirements contained in Table 2 and Table 3, however comply with the ATO's methods and/or AUSTRAC's requirements, including by using any electronic/technological solutions accepted by the ATO and/or AUSTRAC, the TPB will generally consider these POI steps to also meet the TPB's requirements."

Read what that says, and what it does not. It says the TPB will generally accept proof-of-identity steps that comply with ATO or AUSTRAC methods, including by electronic means those agencies accept. It is not an endorsement by the TPB of any product, platform or provider — including ours — and no vendor, us included, is entitled to describe itself as TPB-approved. It also does not displace the TPB's separate record-keeping requirement: whatever method you use, you still need the contemporaneous record and the five-year clock.

(Note for the April 2026 PDF readers: that version said "consistent". The 20 July 2026 HTML says "broadly consistent". We quote the current wording.)

Situations the guidance covers that most summaries miss

  • Clients without conventional identification. The TPB expects a flexible approach — "which may be different to, and sometimes less than, the minimum requirements" — for Aboriginal and Torres Strait Islander clients, remote-area clients, disaster-affected clients, refugees, clients affected by family violence or homelessness, and clients with recently expired documents, supported by detailed contemporaneous records.
  • Well-established clients. Full proof of identity may be unnecessary, but the assessment and its basis must be recorded, and a representative's authority must still be evidenced.
  • A referred client is not a verified client. Where an advising practitioner is engaged by a referring practitioner, written confirmation from the referrer that proof of identity was done is sufficient. But a client merely referred to a new practitioner must be verified in full, regardless of what the referrer did.
  • Employer clients representing employee taxpayers. The practitioner must obtain written confirmation that the employer's checks were "either equal to or greater than" the TPB's requirements, and must have a process to escalate discrepancies before lodgment — with s 50-20 exposure if reckless.
  • Buying a practice or a client list. Proof-of-identity records transfer to the buyer, who need not redo the checks on transfer, though ongoing-frequency obligations still apply. The seller must comply with Code item 6 on disclosure to third parties.
  • Discrepancies. Ask probing questions, seek further evidence, try to verify independently, decline the engagement if not satisfied, and consider notifying the TPB, ATO, ASIC or another authority.

What this page does not cover

Stated plainly, because a page that pretends to cover everything is not worth citing.

  • Whether your specific practice is an AUSTRAC reporting entity. That turns on the services you actually provide, and AUSTRAC publishes a self-assessment tool for it. This page describes the trigger; it does not apply it to you.
  • How to build an AML/CTF program. Enrolment, the risk assessment, the compliance officer, training, personnel due diligence, suspicious matter and threshold transaction reporting, and the independent evaluation are all outside this page. No software makes a practice AML compliant.
  • The Code of Professional Conduct itself. We quote the three Code items as the TPB states them in TPB(GS) 42/2022. We have not reproduced s 30-10 of the Tax Agent Services Act 2009 from the Federal Register, and we do not quote the Code verbatim.
  • The dollar value of a penalty unit. TPB(GS) 42/2022 footnotes s 50-20 as 250 penalty units for an individual and 1,250 for a body corporate. We have not verified the current penalty unit amount and deliberately do not convert it.
  • The ATO's client-declaration and lodgment rules. Different statute, different recipient, different retention clock. Covered separately.
  • Tax (financial) advisers. Since 1 January 2022 they are no longer tax practitioners under the TASA, and TPB(GS) 42/2022 does not apply to them in that capacity.
  • Legal practitioners, conveyancers and real estate agents. Also tranche 2 entities, with profession-specific rules not covered here.
  • Case law. This page states what the guidance and the legislation say. It does not analyse how tribunals and courts have applied them.
  • Anything outside Australia.

This page states what the regulators' guidance and the legislation say, with the source for each statement. It is not legal, tax or compliance advice. TPB(GS) 42/2022 was read on tpb.gov.au on 8 September 2026, showing "Issued: 31 January 2022 / Last modified: 20 July 2026"; the AUSTRAC pages were read the same day. TPB Guidance Statements are guidance, not law — TPB(GS) 42/2022 states that it "does not exhaust, prescribe or limit the scope of the TPB's powers" and does not "create additional rights or legal obligations beyond those that are contained in the TASA or which may exist at law". Guidance and legislation change; check the current version before you rely on anything here. Whether your practice provides a designated service, and what your obligations are, is a question for your professional adviser.

Frequently asked questions

Does the AML/CTF Act require tax agents to verify client identity?

Not as the source of the TPB's requirement. TPB(GS) 42/2022, last updated 20 July 2026, states that "there are no specific POI requirements in the TASA" and that the obligation arises from provisions a practitioner may breach by failing to take proof-of-identity steps: Code items 1, 7 and 9, the fit and proper registration requirement, and s 50-20 of the Tax Agent Services Act 2009. The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 is a separate regime that applies to a practice only if it provides a designated service in table 6 of s 6(5B), from 1 July 2026. A practice can be in one regime, both, or only the TPB one.

What law requires a registered tax agent to check a client's identity?

No single section imposes it. The Tax Practitioners Board requires proof-of-identity steps as risk-based guidance and enforces them through the Tax Agent Services Act 2009: Code item 1 (act honestly and with integrity), Code item 7 (provide services competently), Code item 9 (take reasonable care in ascertaining a client's state of affairs), the ongoing fit and proper registration requirement, and s 50-20, the civil penalty provision for false, incorrect or misleading statements to the Commissioner. TPB(GS) 42/2022 sets out the minimum steps.

Should a tax agent keep a copy of a client's driver licence or passport?

The TPB says no. TPB(GS) 42/2022 states the TPB "does not require or recommend that registered tax practitioners retain copies or originals of identification documents", because retaining them "may increase the risk of registered tax practitioners being targeted by criminals undertaking identity theft". What the TPB requires instead is a contemporaneous record — for example a checklist — showing the date and time of the check, who performed it, which documents were sighted, whether they were originals or certified copies, and how they were sighted. The guidance footnotes this to Australian Privacy Principle 11.

How long must a tax practitioner keep proof-of-identity records?

TPB(GS) 42/2022 requires a record of the proof-of-identity checks for each client and each individual representative to be kept for a minimum of five years after the engagement with the client has ceased. The clock starts when the engagement ends, not when the check is done. That is a different clock from the client's own five-year retention of a s 388-65 declaration under the Taxation Administration Act 1953, which runs from when the declaration is made, and different again from AUSTRAC record keeping, which AUSTRAC describes as usually seven years.

Can a client email me their identity documents?

The TPB advises against it. TPB(GS) 42/2022 states the TPB "does not recommend sending and receiving sensitive information or copies of identity documentation and/or evidence by email as this is not considered to be a secure method of transmission", and strongly recommends documents be provided via a secure website, secure online mailbox or secure messaging, as an encrypted or password-protected email attachment, or using another secure electronic solution that minimises the risk of interception.

Is TPB(PN) 5/2022 still current?

No. On 30 April 2026 the TPB renamed its Practice Note series to Guidance Statement and records in the document history that "The TPB Practice Note TPB(PN) 5/2022 Proof of identity requirements for client verification has been archived." The current document is TPB(GS) 42/2022, issued 31 January 2022, last updated 20 July 2026. The July 2026 update aligned the wording with the AML/CTF changes that commenced on 1 July 2026.

Does preparing tax returns make my practice an AUSTRAC reporting entity?

Not on its own. A practice is captured only if it provides a designated service listed in table 6 of s 6(5B) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, in the course of carrying on a business, with a geographical link to Australia. AUSTRAC's guidance uses tax advice as an example of a service that does not directly advance a transaction and so is not designated. Company formation, creating or restructuring a trust, acting as or arranging a nominee director or trustee, providing a registered office address, and receiving or controlling client money as part of a transaction are designated services.

If I meet AUSTRAC's customer due diligence, have I met the TPB's requirements?

Generally, but read the wording. TPB(GS) 42/2022 states that where a practitioner takes proof-of-identity steps that vary from Tables 2 and 3 but comply with the ATO's methods and/or AUSTRAC's requirements, "including by using any electronic/technological solutions accepted by the ATO and/or AUSTRAC, the TPB will generally consider these POI steps to also meet the TPB's requirements." That is recognition of methods accepted by those two agencies. It is not an endorsement by the TPB of any product or provider, and it does not remove the TPB's separate record-keeping requirement.

What happens if a tax practitioner does not verify a client's identity?

There is no standalone penalty, because there is no standalone requirement. The exposure is through the provisions the TPB names: breach of Code items 1, 7 or 9, a finding that the practitioner is no longer fit and proper, and s 50-20 of the Tax Agent Services Act 2009, the civil penalty provision for making or preparing a statement to the Commissioner that the practitioner knows or is reckless as to whether it is false, incorrect or misleading in a material particular. TPB(GS) 42/2022 footnotes that a breach of s 50-20 carries 250 penalty units for an individual and 1,250 penalty units for a body corporate.

Do I need to verify identity again for an existing client?

The TPB requires proof-of-identity steps before providing tax agent and BAS services "and on an ongoing basis, as appropriate". Frequency is a matter of professional judgement, but TPB(GS) 42/2022 requires the practitioner to make and retain a record of their assessment of the appropriate frequency for each ongoing client. For a well-established client, full proof of identity may be unnecessary — but the reasons and basis for that assessment must be recorded, and evidence of a representative's authority must still be sighted.

Sources

  1. TPB(GS) 42/2022, Proof of identity requirements for client verification — issued 31 January 2022, last modified 20 July 2026 (HTML) — as at 8 September 2026
  2. AUSTRAC — Professional designated services (last updated 3 September 2026) — as at 8 September 2026
  3. AUSTRAC — AML/CTF transitional rules 2026 (last updated 2 April 2026) — as at 8 September 2026
  4. Tax Agent Services Act 2009 (Cth) — as at 8 September 2026
  5. Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) — C2026C00274, effective 1 July 2026 — as at 7 September 2026
  6. Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth), Act No. 110 of 2024 — Royal Assent 10 December 2024 — as at 7 September 2026
  7. Privacy Act 1988 (Cth) — C2026C00227, Compilation No. 104, 4 June 2026 — as at 7 September 2026

Siggy is Australian electronic signature software, built and hosted in Australia.

The TPB's position is that identity documents should not arrive by email, and that what you keep is the record of the check — not the documents. Siggy is built that way. Send the engagement letter for signature, run identity verification in the same sitting from a link your client opens on their phone, and file the outcome: a government-records check, a biometric face match and PEP and sanctions screening, from $6.00 a check, alongside a sealed PDF and a Certificate of Completion recording who signed and when. Siggy Australia is an accredited Australian Identity Service Provider. Included from Professional, $15 a month.

One honest limit, stated plainly: nothing in a signing platform decides whether your practice is an AUSTRAC reporting entity, and no product makes a practice AML compliant. The program, the compliance officer, the training and the reporting are yours. What a verification step attached to a signing workflow produces is evidence for the customer due diligence and record-keeping limbs — and the contemporaneous record the TPB asks for.

Start free — 5 envelopes a month, no card