Skip to content

VOI vs AML customer due diligence: what's the difference for conveyancers?

They're two different obligations that happen to use the same documents. VOI is the ARNECC identity-verification standard for electronic conveyancing: a safe-harbour "reasonable steps" test enforced through the land registries. AML customer due diligence is AUSTRAC's separate, broader money-laundering check. You may do both; satisfying one doesn't satisfy the other.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

Why do conveyancers now have two separate checks?

Conveyancers have verified client identity for years, for electronic lodgment. From 1 July 2026 there's a second, separate check for AML/CTF (customer due diligence) that starts with identity but goes further. Because both ask for the same kinds of documents (passport, driver licence, Medicare), it's easy to assume they're one job. They aren't: they're two separate obligations, under different regulators and for different purposes, and doing one doesn't discharge the other.

What is VOI (the ARNECC standard)?

Verification of Identity (VOI) is part of the electronic conveyancing framework. The Australian Registrars' National Electronic Conveyancing Council (ARNECC) publishes the Model Participation Rules (Version 7), and the Verification of Identity Standard is in Schedule 8. A subscriber (a conveyancer or lawyer lodging electronically) must take reasonable steps to verify the identity of the people they act for.

Two things are worth being precise about. First, the Standard is a safe harbour, not a mandatory procedure. If you carry it out properly (yourself or through an identity agent), you're deemed to have taken reasonable steps; you may instead take other reasonable steps. Second, it's enforced through the land-registry participation rules, not by AUSTRAC. You're also expected to retain evidence that you took reasonable steps.

What is AML customer due diligence?

AML customer due diligence (CDD) is an obligation under the AML/CTF regime, overseen by AUSTRAC. It's broader than confirming who someone is. Initial CDD generally involves verifying the customer's identity (KYC), understanding who they act for, identifying beneficial owners (an individual who ultimately owns or controls 25% or more, or otherwise controls the customer), PEP and sanctions screening, and understanding the nature and purpose of the transaction. For higher-risk matters, enhanced due diligence can extend to source of funds and source of wealth.

Unlike VOI, this isn't a "reasonable steps" safe harbour tied to lodgment; it's a distinct statutory obligation with its own record-keeping and reporting duties.

At a glance

AspectVOI (ARNECC)AML CDD (AUSTRAC)
PurposeConfirm identity for electronic lodgmentManage money-laundering / terrorism-financing risk
Legal sourceARNECC Model Participation Rules v7, Schedule 8AML/CTF Act and AML/CTF Rules 2025
RegulatorState land registries (participation rules)AUSTRAC
NatureSafe-harbour "reasonable steps", not mandatoryStatutory obligation for reporting entities
ScopeIdentity of the signatory / partyIdentity + beneficial owners + PEP/sanctions + (for higher risk) source of funds

Where does privacy come in?

Here's the point both regimes share: each one makes you collect and hold sensitive identity information, and that data is now regulated by the Privacy Act. Because you gather it in connection with your AML/CTF obligations, Privacy Act s 6E(1A) applies the APPs to the AML side regardless of your turnover (see Does becoming an AUSTRAC reporting entity trigger the Privacy Act?). So a third obligation sits on top of the two checks: handling that data properly (a privacy policy, a collection notice at the point you take the documents, and secure retention). (For the full picture of the data involved, see what personal information you now collect for AML.)

Can VOI and AML CDD be treated as one?

The practical mistake to avoid is assuming your existing VOI process "covers" AML, or that an AML KYC check satisfies your lodgment VOI. They overlap in the documents collected but are separate obligations you have to be able to evidence separately. When in doubt, treat them as two boxes to tick, not one.

Common questions

Does my VOI process satisfy my AML customer due diligence?

Not on its own. VOI is the ARNECC safe-harbour identity standard for lodgment; AML CDD is a broader AUSTRAC obligation that also covers beneficial owners, PEP/sanctions screening and (for higher risk) source of funds. Doing one doesn't discharge the other.

Is VOI mandatory?

VOI is a safe-harbour standard, not a mandatory procedure; carrying out the Schedule 8 Standard means you're deemed to have taken reasonable steps, but you can take other reasonable steps instead. It's enforced through the land-registry participation rules.

Who regulates each one?

VOI sits under the ARNECC Model Participation Rules and the state land registries; AML customer due diligence sits under the AML/CTF Act and is overseen by AUSTRAC. Privaproof does not assess AML/CTF obligations. That's AUSTRAC's domain.

Does the Privacy Act apply to the identity data?

Yes, to the data you collect for AML/CTF: s 6E(1A) applies the Privacy Act to it regardless of turnover. That's why the identity documents you take now need a collection notice and secure handling.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor. Sources: ARNECC, Model Participation Rules; AUSTRAC, professional designated services; Privacy Act 1988 (Cth) s 6E(1A).