Financial services and virtual asset screening

KYC and AML Checks for Financial Services and Virtual Asset Providers

Verify individual and business customers, screen relevant people for PEP and sanctions risk, and hand clearer onboarding evidence into your AML/CTF decision workflow.

Financial crime compliance analysts reviewing customer identity and risk information in an Australian fintech office

CDD workflow ready

Tell us your customer types, products, evidence and integration needs so we can help scope the right checks.

Built for your workflow

Risk-based KYC, KYB and screening workflows

01

Individual KYC and business KYB

02

PEP, sanctions and watchlist screening

03

Potential-match review evidence

04

API-ready workflow scoping

Financial and virtual asset customer due diligence

Build a clearer KYC and AML evidence trail without overstating the check

Financial services and virtual asset providers need more than a single identity result. AuthNTick can support the KYC, KYB and screening stages of a risk-based onboarding workflow, helping your team connect verified customer information, relevant-person screening and review evidence to the decision controls it operates under its own AML/CTF program.

Relevant checks

What AuthNTick can support in the onboarding workflow

Configure the checks and review points that match your customer, service and risk-based process.

01

Individual KYC identity verification

Collect and verify the identifying information and identity evidence required by your configured onboarding workflow, then retain a timestamped outcome for the customer file.

02

Business and entity KYB

Check Australian business details and structure the collection of information about relevant directors, officeholders, beneficial owners, controllers and authorised representatives.

03

PEP and sanctions screening

Compare customer and related-person identifiers with politically exposed person, sanctions and agreed watchlist data, with possible similarities routed for review rather than treated as confirmed.

04

Risk-based onboarding inputs

Capture information such as relationship purpose, expected account or service use, occupation or business activity, source information and relevant jurisdictions for assessment under your own risk method.

05

Potential-match review evidence

Support reviewers with available identifiers and a documented status so a possible PEP, sanctions or watchlist match can be cleared, confirmed or escalated under your procedures.

06

Structured evidence and API hand-off

Use the result and available integration options to hand onboarding evidence into your customer, case-management or compliance workflow. Confirm fields and integration scope before implementation.

Workflow

How to structure financial services and VASP onboarding

  1. 01

    Classify the customer and service

    Determine whether you are onboarding an individual, organisation, trustee, authorised representative or related party and identify the designated service, product and channel involved.

  2. 02

    Collect identity and relationship information

    Request the identity evidence, entity details, ownership or control information, purpose of the relationship and risk inputs defined in your AML/CTF program.

  3. 03

    Run KYC or KYB verification

    Verify the individual or business using the configured workflow and identify any missing, inconsistent or higher-risk information that needs additional review.

  4. 04

    Screen and assess possible matches

    Screen relevant customers and related people for PEP, sanctions and watchlist records, compare the available identifiers and document the review outcome.

  5. 05

    Hand evidence into your decision workflow

    Combine the result with your customer risk rating, enhanced due diligence steps, approvals and any product-specific controls before deciding whether and how to provide the service.

  6. 06

    Trigger future review under your program

    Treat onboarding as the starting point. Your own systems should initiate ongoing CDD, screening refreshes or event-driven reviews when risk, ownership, behaviour or customer information changes.

Scope and responsibility

Controls that remain with your reporting entity

  1. 01

    AuthNTick identity, KYB and screening checks can support customer due diligence, but they do not create or operate your AML/CTF program and do not guarantee compliance.

  2. 02

    Transaction monitoring, blockchain or wallet analytics, suspicious matter reporting, threshold transaction reporting and other AUSTRAC reporting are outside a point-in-time identity and name-screening check.

  3. 03

    A Travel Rule workflow may require collection, verification and sharing of transfer information between relevant institutions. Do not assume an onboarding check performs those transaction-level obligations.

  4. 04

    Virtual asset service provider enrolment and registration are obligations managed directly with AUSTRAC. AuthNTick does not register a business or provide approval to commence a designated service.

  5. 05

    A possible PEP, sanctions or watchlist match is not automatically a confirmed match or a failed customer. Your authorised reviewer must assess the identifiers, legal context and required response.

  6. 06

    Customer risk ratings, enhanced due diligence, source-of-funds or source-of-wealth decisions, product restrictions and final onboarding decisions remain your organisation’s responsibility.

Industry guidance

Build the process around the work.

Open each topic for practical considerations and implementation guidance.

01Apply the 2026 AML/CTF settings to the right service

Australia’s updated AML/CTF obligations for existing reporting entities took effect on 31 March 2026. Expanded virtual asset designated services commenced from 1 July 2026, subject to transitional arrangements. The practical first step is to identify exactly which services your organisation provides, which customers and counterparties are involved, and which commencement or transition provisions apply.

  • Map every product and transaction flow to the applicable designated service rather than assuming one onboarding standard fits the whole business.
  • Document how customer, product, delivery-channel and geographic risks influence the information and verification steps required at onboarding.
  • For a new or expanded virtual asset activity, confirm the current AUSTRAC enrolment and registration position before relying on a general compliance checklist.
  • Keep your legal and compliance interpretation separate from the technical configuration of an identity or screening vendor.
02Design individual and business onboarding as connected journeys

Financial and virtual asset customers do not all arrive as simple individuals. A business relationship may involve an entity, directors, beneficial owners, controllers, trustees and people authorised to act. A strong workflow establishes the entity first, then connects the right individual checks without losing the evidence trail between them.

  • Use a KYC Check for the identity-verification stage of an individual customer or related-person workflow.
  • Use a KYB Check to confirm business information and organise checks on relevant owners, controllers, officeholders and representatives.
  • Use a combined KYC and AML Check when identity verification and PEP, sanctions or watchlist screening form part of the same individual onboarding decision.
  • Define how trusts, foreign entities, complex ownership and information inconsistencies move to document collection or manual review.
03Turn screening results into reviewable decisions

Name screening is most useful when the workflow preserves context. Similar names can produce false positives, and a PEP connection is a risk consideration rather than evidence of wrongdoing. Reviewers need enough identifying information to understand the record, compare it with the customer and record a defensible outcome.

  • Use full names, date of birth, nationality, address or location and other permitted identifiers when they are available and relevant.
  • Distinguish PEP status from sanctions restrictions and other watchlist records because the consequences and required controls are not identical.
  • Route unresolved similarities to an authorised person rather than allowing an automated name match to make the final decision.
  • Retain the screening time, data source context, identifiers considered, reviewer conclusion and any escalation or enhanced due diligence step.
04Keep onboarding, ongoing CDD and transaction controls distinct

An onboarding result is a point-in-time view of identity and the screening data then available. AUSTRAC’s customer due diligence framework also addresses understanding the customer relationship and keeping information current. Financial and virtual asset businesses should therefore connect onboarding evidence to separate ongoing controls rather than describing one check as continuous compliance.

  • Define periodic and event-driven review triggers based on customer risk, material information changes and the services being provided.
  • Reassess entity ownership, control and authorised-person information when relevant changes become known.
  • Operate transaction monitoring, behavioural review and suspicious matter escalation through the systems and procedures established for those purposes.
  • Confirm separately whether recurring screening or adverse media services are available before including them in your control design.
05Plan the Travel Rule as a transaction-data workflow

AUSTRAC explains that financial institutions, remitters and virtual asset service providers may need to collect, verify and share customer information when transferring or receiving funds or virtual assets. This is operationally different from completing KYC at account opening: the relevant transaction information must travel through the payment or virtual asset transfer chain.

  • Identify whether your business acts as an ordering, intermediary or beneficiary institution for each relevant transfer flow.
  • Map which originator and beneficiary information must be collected, verified, transmitted, received, checked and retained.
  • Design exception handling for missing, incomplete or inconsistent transfer information and determine when a transaction should be paused or escalated.
  • Do not represent an identity-verification API as a complete Travel Rule solution unless the required transaction messaging, counterparty exchange and controls are demonstrably in scope.
06Preserve evidence across API and manual review steps

Good integration is not only about returning a pass or fail. The downstream case should retain enough information to show what happened, when it happened and who resolved an exception. Before implementation, agree on the result fields, identifiers, status vocabulary, webhook or API behaviour, retention approach and manual-review hand-off.

  • Keep the customer or entity reference consistent across KYC, KYB, screening and internal case records.
  • Record completed, incomplete, clear, potential-match and review states precisely instead of collapsing them into one generic status.
  • Limit access to identity evidence and sensitive screening information according to role and business need.
  • Test retry, duplicate, timeout, unavailable-source and manual-review paths before relying on the workflow in production.
07Treat VASP enrolment and registration as a separate workstream

AUSTRAC states that a remittance or virtual asset service provider must both enrol and register. Generally, a provider cannot begin the registrable service until registration has been approved, although transitional arrangements may apply to newly regulated virtual asset services where an application was made within the specified period. This is a regulatory process, not an outcome produced by KYC software.

  • Confirm whether the particular virtual asset activity is a designated and registrable service, including its geographical connection to Australia.
  • Use current AUSTRAC guidance for application timing, transitional treatment and information that must be supplied.
  • Maintain evidence that the business is ready to manage ML/TF and proliferation-financing risk independently of vendor selection.
  • Seek appropriately qualified advice for legal classification or transition questions that cannot be resolved from official guidance.

Practical questions, answered.

What checks are commonly used when onboarding a financial services customer?

The workflow may include individual KYC or business KYB, verification of relevant beneficial owners or authorised representatives, PEP and sanctions screening, customer risk information and potential-match review. The precise controls should be based on the designated service, customer type and risk assessment in your AML/CTF program.

Can AuthNTick support virtual asset customer onboarding?

AuthNTick can help with configured identity, business and name-screening stages and provide evidence for a downstream onboarding decision. Confirm the specific data, checks and integration scope with AuthNTick. Transaction monitoring, wallet analytics, Travel Rule messaging, registration and AUSTRAC reporting are not implied.

Does a KYC and AML check make a financial business AML/CTF compliant?

No. A check can support customer due diligence, but the reporting entity remains responsible for its risk assessment, AML/CTF program, governance, customer risk decisions, ongoing CDD, transaction monitoring, record keeping, reporting and other applicable obligations.

What is the difference between onboarding screening and ongoing CDD?

Onboarding screening records an identity and screening result at a point in time. Ongoing CDD is the broader process of keeping customer information current and reassessing the relationship when risk or relevant circumstances change. Recurring screening and event-driven refreshes must be scoped separately.

Does the service include transaction monitoring or wallet analytics?

No such capability should be assumed from an identity and name-screening check. Transaction monitoring examines activity after or during the relationship, while wallet analytics analyses virtual asset addresses and flows. Ask AuthNTick to confirm any separately available integrations, but plan those controls independently.

Does AuthNTick complete the Travel Rule for a VASP?

No. The Travel Rule can require relevant institutions to collect, verify and share originator or beneficiary information for transfers. Identity evidence may be one input, but the transaction messaging, counterparty exchange, exception handling and record-keeping workflow are separate responsibilities.

Must an Australian virtual asset service provider register with AUSTRAC?

AUSTRAC states that virtual asset service providers must both enrol and apply for registration. Generally, a provider cannot start the registrable service before approval, although transitional rules may apply to newly regulated services. Check the current AUSTRAC guidance for your activity and timing; AuthNTick does not provide registration approval.

How should a possible PEP or sanctions match be handled?

A possible match should be compared with all available identifiers and reviewed under your procedures. PEP status is a risk factor, not proof of wrongdoing, while a sanctions record may have different legal consequences. Document whether the similarity was cleared, confirmed or escalated and why.

When should a KYB Check be used?

Use KYB when the customer is a company or another organisation and you need to verify entity information and structure checks for relevant owners, controllers, officeholders or representatives. Individual KYC and AML screening may then be linked to those people according to your program.

Can results be connected to an internal compliance system?

AuthNTick can discuss available evidence and integration options for handing results into customer, case-management or compliance workflows. Confirm field availability, statuses, API or webhook behaviour, error handling, reviewer steps and data-retention responsibilities before implementation.

Talk to AuthNTick

Scope a customer verification workflow around your risk controls.

Tell us about your customers, products, review process and integration requirements.