VOI vs AML customer due diligence: what's the difference for conveyancers?
They're two different obligations that happen to use the same documents. Verifying identity for electronic lodgment is required of you by the ARNECC Participation Rules (rule 6.5.1); the Schedule 8 Verification of Identity Standard is the safe-harbour way of doing it, enforced through the land registries. AML customer due diligence is AUSTRAC's separate, broader money-laundering check. You may do both; satisfying one doesn't satisfy the other.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
Why do conveyancers now have two separate checks?
Conveyancers have verified client identity for years, for electronic lodgment. From 1 July 2026 there's a second, separate check for AML/CTF (customer due diligence) that starts with identity but goes further. Because both ask for the same kinds of documents (passport, driver licence, Medicare), it's easy to assume they're one job. They aren't: they're two separate obligations, under different regulators and for different purposes, and doing one doesn't discharge the other.
What is VOI (the ARNECC standard)?
Verification of Identity (VOI) is part of the electronic conveyancing framework. The Australian Registrars' National Electronic Conveyancing Council (ARNECC) publishes the Model Participation Rules (Version 7, January 2024), and the Verification of Identity Standard is in Schedule 8. Each Registrar determines them as the Participation Rules for its jurisdiction, and rule 6.5.1 requires a subscriber (a conveyancer or lawyer lodging electronically) to take reasonable steps to verify the identity of each client or their client agent.
Two things are worth being precise about. First, verifying identity is required; it is the Standard that is the safe harbour. Rule 6.5.2 lets you either apply the Schedule 8 Standard or verify identity some other way that constitutes reasonable steps, and rule 6.5.6 deems compliance with the Standard to be the taking of reasonable steps. Second, it's enforced through the land-registry participation rules, not by AUSTRAC, and rule 6.6 requires you to retain the evidence supporting verification of identity for at least seven years from lodgment.
What is AML customer due diligence?
AML customer due diligence (CDD) is an obligation under the AML/CTF regime, overseen by AUSTRAC. It's broader than confirming who someone is. Section 28(2) sets out what you must establish on reasonable grounds before you start: the customer's identity, the identity of anyone the customer acts for and of anyone acting for the customer, beneficial owners where the customer is not an individual (an individual who ultimately owns 25% or more of it, or controls it), whether any of them is a politically exposed person or designated for targeted financial sanctions, and the nature and purpose of the relationship or transaction. For higher risk, s 32 requires enhanced due diligence, which the Rules extend to source of wealth and source of funds.
Unlike VOI, there's no safe-harbour procedure tied to lodgment: s 28(1) says a reporting entity must not commence to provide the designated service until it has established those matters on reasonable grounds, and the regime carries its own record-keeping and reporting duties.
At a glance
| Aspect | VOI (ARNECC) | AML CDD (AUSTRAC) |
|---|---|---|
| Purpose | Confirm identity for electronic lodgment | Manage money-laundering / terrorism-financing risk |
| Legal source | ARNECC Model Participation Rules v7, Schedule 8 | AML/CTF Act and AML/CTF Rules 2025 |
| Regulator | State land registries (participation rules) | AUSTRAC |
| Nature | Verification required (rule 6.5.1); the Schedule 8 Standard is the safe harbour | Statutory obligation for reporting entities |
| Scope | Identity of the signatory / party | Identity + beneficial owners + PEP/sanctions + (for higher risk) source of funds |
Where does privacy come in?
Here's the point both regimes share: each one makes you collect and hold identity documents and government related identifiers (licence and Medicare numbers), and how you handle them is governed by the Privacy Act. Section 6E(1A) is activity-scoped, not data-scoped: where you are a reporting entity it applies the Act to the activities you carry on "for the purposes of, or in connection with, activities relating to" the AML/CTF Act, whatever your turnover (see Does becoming an AUSTRAC reporting entity trigger the Privacy Act?). So a third obligation sits on top: a privacy policy, a collection notice when you take the documents, secure retention, and APP 9.1, which bars adopting a government related identifier as your own identifier of the individual unless an Australian law authorises it. (For the full picture of the data involved, see what personal information you now collect for AML.)
Can VOI and AML CDD be treated as one?
The practical mistake to avoid is assuming your existing VOI process "covers" AML, or that an AML KYC check satisfies your lodgment VOI. They overlap in the documents collected but are separate obligations you have to evidence separately. The electronic match makes the point: where the request goes to a credit reporting body to verify identity for AML/CTF purposes, s 35A(2) says a reporting entity must not make it unless, first, the individual was given five prescribed items of information, "expressly agreed to the making of the request and the disclosure of the personal information", and "an alternative means of verifying the identity of the individual was made available". A breach is an interference with privacy (s 35L). Does your consent wording name the credit reporting body disclosure, record express agreement, and set out the alternative?
Common questions
Does my VOI process satisfy my AML customer due diligence?
Not on its own. VOI is the ARNECC safe-harbour identity standard for lodgment; AML CDD is a broader AUSTRAC obligation that also covers beneficial owners, PEP/sanctions screening and (for higher risk) source of funds. Doing one doesn't discharge the other.
Is VOI mandatory?
Verifying identity is mandatory; the Schedule 8 Standard is not the only route to it. Rule 6.5.1 requires the subscriber to take reasonable steps to verify the identity of each client or their client agent. Rule 6.5.6 deems compliance with the Standard to be the taking of reasonable steps, and rule 6.5.2 lets you verify identity some other way that constitutes reasonable steps. It's enforced through the land-registry participation rules.
Who regulates each one?
VOI sits under the ARNECC Model Participation Rules and the state land registries; AML customer due diligence sits under the AML/CTF Act and is overseen by AUSTRAC. Privaproof does not assess AML/CTF obligations. That's AUSTRAC's domain.
Does the Privacy Act apply to the identity data?
Yes. Section 6E(1A) is activity-scoped: if you are a reporting entity it applies the Act to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, whatever your turnover. That's why the identity documents you take now need a collection notice and secure handling.
Do I need consent to run an electronic identity check?
For an AML verification request to a credit reporting body, yes: s 35A(2) requires prescribed information first, the individual's express agreement to the request and the disclosure, and an alternative means of verification made available. A breach is an interference with privacy (s 35L).
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: ARNECC, Model Participation Rules v7; AUSTRAC, professional designated services; AML/CTF Act 2006 (Cth) ss 28, 32, 35A; OAIC, guidance for reporting entities under the AML/CTF Act.