The Broker Times · Compliance Briefing

One Client. Three Identity Checks. One Statutory Duty — And It Probably Isn’t Yours.

The MFAA has asked the statutory review of the Digital ID Act 2024 to make identity information usable across the lending chain. Here is what the chain looks like today.

The same client, verified three ways

CHECK 1

At application

You collect and certify the client’s identity documents to the lender’s standard, then lodge them with the file.

Whose duty: the lender’s, met through its broker requirements — per MFAA member guidance.

CHECK 2

At credit assessment

The lender runs its own customer due diligence and may re-examine ownership structures behind companies and trusts.

Whose duty: the lender’s, as a reporting entity.

CHECK 3

At settlement

Verification of Identity is performed again for electronic conveyancing — in person, against original documents.

Whose duty: the Subscriber’s or the mortgagee’s, under the Model Participation Rules.

The pattern: on the industry guidance and settlement rules reviewed here, the broker is generally not the party holding the statutory obligation — but is the party holding the documents. Whether that holds for your business is a question for your licensee.

Four dates on the identity calendar

31 Mar 2026

Main commencement of the reformed AML/CTF obligations for existing reporting entities.

1 Jul 2026

Obligations extend to real estate professionals, lawyers and accountants.

21 Aug 2026

MFAA announces its submission to the Digital ID Act 2024 statutory review.

31 Mar 2029

End of AUSTRAC’s transitional window for eligible reporting entities still using the older identification procedure — your lenders, not you.

The question nobody has answered

The FBAA has asked AUSTRAC more than once whether commercial asset finance broking falls inside the designated service of “brokering the sale, purchase or transfer of real estate”. As at the reporting reviewed for this article, no public answer has been given.

The takeaway

Until Digital ID is made to work across the chain, the duplicate check stays. Your exposure is not the statutory duty — it is the documents sitting in your system, and how clearly your file shows whose requirement you were meeting.

Compliance · Identity & AML

The MFAA Has Asked Canberra to End Duplicate ID Checks. Until It Does, the Check You’re Doing Is the Lender’s Obligation, Not Yours

Identity is the one part of a loan file that gets done two or three times — and the one part where most brokers cannot say precisely whose rule they are following.

In this article

  1. What the MFAA actually asked for
  2. Whose obligation is the check at application?
  3. The second check nobody talks about: VOI at settlement
  4. The question the FBAA still can’t get answered
  5. The rulebook being redrafted right now
  6. What this means for your file — and your data
  7. What to review this week

Think about the last purchase you settled. Your client proved who they were to you at application. The lender ran its own customer due diligence on the same person behind the scenes. Then, weeks later, a conveyancer or a settlement agent sat that same client down in front of the same passport and did it again, in person, for the electronic conveyancing platform.

Three verifications. One human being. None of them able to see the others.

On 21 August the Mortgage & Finance Association of Australia announced it had put that problem to the statutory review of the Digital ID Act 2024, in a submission reported by The Adviser on 8 September. It is a small item in a busy news week, and it is worth more broker attention than it has had — not because anything changes tomorrow, but because working through what the MFAA is asking for forces a question most brokers have never had to answer: when you verify a client’s identity, whose rule are you actually following?

For a large share of the channel, the honest answer is “the lender’s”. That answer has consequences for how your file should be built.

What the MFAA actually asked for

The submission’s core argument, as reported, is about interoperability rather than technology. The MFAA’s position is that identity information should be able to move securely across the lending and property transaction chain instead of being rebuilt from scratch by each participant.

“Digital ID will only deliver its full benefits if identity information can be used securely and efficiently across the broader lending ecosystem, rather than requiring consumers to repeatedly verify their identity with individual participants.”

— MFAA submission to the statutory review of the Digital ID Act 2024, as reported by The Adviser, 8 September 2026

Alongside that, the association asked for greater regulatory and technical interoperability between Digital ID, anti-money laundering requirements, Verification of Identity for property settlement, verifiable credentials and the Consumer Data Right; for clarity on when an accredited Digital ID result actually satisfies a compliance obligation; and — the line brokers should read twice — that implementation should reduce existing identity verification and document-handling requirements rather than add another step.

That last point is a warning as much as a request. A national Digital ID scheme that sits beside the existing checks rather than replacing any of them would make a broker’s week longer, not shorter.

Whose obligation is the check at application?

Here is where a widespread assumption needs testing. A lot of brokers believe that the anti-money laundering reforms that commenced on 31 March 2026 brought the broker channel into the AML/CTF regime directly. The MFAA’s own member guidance, published on 9 March 2026, says the opposite: the changes do not bring brokers into the regime. What they do is change the obligations of lenders — who then, in many cases, require brokers to perform identification steps on their behalf.

Legal commentary on the point runs the same way. Bright Law’s published analysis states that finance brokers acting as agents for lenders are not reporting entities under the AML/CTF Act unless they provide one or more designated services outside their agency agreement. The distinction it draws is between acting within an agency relationship and providing a designated service in your own right.

This is general information rather than advice about your business, and the answer genuinely can differ depending on what a brokerage does — the commentary itself flags activity outside the agency arrangement as the trigger. If you have never had this confirmed for your own licence and your own service mix, it is a question for your aggregator’s compliance team or your licensee, not for a blog post or a LinkedIn thread.

But assume for a moment that it holds for your business. What follows is not comfortable. You are performing an identity procedure whose statutory owner is someone else, to a standard set by that someone else, using documents you then store — and if the procedure was performed badly, the party in breach and the party holding the client’s passport scan are two different businesses.

The practical consequence

Your protection is not a statutory defence. It is evidence: a file that shows which lender’s requirement you were meeting, which version of that requirement applied on the day, what you sighted, and what you did when something did not reconcile.

The second check nobody talks about: VOI at settlement

The third verification in that opening scenario is the one furthest from the broker’s desk and the one most brokers have never examined. Electronic conveyancing runs on the Model Participation Rules maintained by the Australian Registrars’ National Electronic Conveyancing Council. Version 7, published in January 2024, remains the current version.

Under those rules and the accompanying guidance note, the parties required to verify identity are Subscribers — the lawyers, conveyancers and others transacting on the electronic lodgement network — and mortgagees. A Subscriber acting for a mortgagee may rely on the mortgagee’s verification where it is reasonably satisfied the mortgagee took reasonable steps. The standard itself, set out in Schedule 8, contemplates a face-to-face interview against original documents, with categories of acceptable identifiers and a requirement to use the highest available category. A Subscriber may appoint an Identity Agent to carry out the verification, subject to written appointment and a certification requirement.

Read that list of obliged parties again. Mortgage brokers are not on it. The most document-intensive, most face-to-face identity procedure in the whole transaction is one you do not perform, cannot rely on, and usually never see the output of — even though your client experiences it as “doing the ID again” and, in many cases, rings you to ask why.

That phone call is the MFAA’s argument in miniature. The duplication is not caused by any one participant being unreasonable. It is caused by three regimes that were built separately and were never required to recognise each other’s work.

The question the FBAA still can’t get answered

If the “brokers aren’t captured” position feels settled, it isn’t — at least not at the edges. In July, the Finance Brokers Association of Australia went public with a request for an urgent meeting with AUSTRAC to clarify whether brokers and intermediaries are captured by the obligations that commenced on 1 July 2026.

The concern is narrow and specific. AUSTRAC’s real estate designated services, effective from 1 July 2026, include brokering the sale, purchase or transfer of real estate on behalf of a buyer, seller, transferee or transferor in the course of carrying on a business. The FBAA’s regulatory compliance specialist, David Carson, said the association’s concern was “because the way their guidance has been drafted would appear that commercial asset finance broking could be defined as a designated service which would bring it under AML/CTF rules”, adding: “We are not convinced it was ever the legislative intent to capture this activity so we remain hopeful that we can obtain clarification that it is not captured.”

FBAA chief executive Leo Gagic described “significant uncertainty and confusion across the broker community regarding whether these changes apply to our sector, and if so, explain the extent of the obligations that may arise”, and noted: “We have contacted AUSTRAC again to seek definitive guidance on these matters, and we note that other industry associations have done so as well.”

No public AUSTRAC response appears in the reporting reviewed for this article. Nothing about the FBAA’s request implies any wrongdoing by anyone; it is a request for interpretive certainty on a boundary question, and it is the sort of question that is cheap to ask now and expensive to get wrong later. If you write commercial or asset finance alongside residential, this is the live one to raise with your licensee.

The rulebook being redrafted right now

There is one more piece of timing worth knowing, because it shapes how quickly the MFAA’s ask could actually land.

ARNECC has published a consultation draft of Version 8 of the Model Participation Rules. On the draft as published, the document header carries no publication date and no effective date — both are marked as to be advised. On the identity provisions, the draft keeps the existing architecture: Schedule 8’s Verification of Identity Standard, or verification “in some other way that constitutes the taking of reasonable steps”, with Identity Agents still permitted and a re-verification window retained. On the face of the consultation draft, there is no accredited Digital ID pathway introduced into the settlement-side rules.

In other words: the rulebook governing the third check is being redrafted, and the redraft does not yet appear to contemplate the thing the MFAA is asking the Digital ID review to enable. Interoperability across three regimes needs all three to move. Right now they are moving on unrelated timetables.

What this means for your file — and your data

Strip away the acronyms and the broker-level position is straightforward, and slightly uncomfortable.

You hold the most sensitive identity data in the transaction. You are very likely not the party the identity rules are written for. Your obligations in this area arrive contractually — through lender accreditation terms and aggregator policy — rather than directly from a statute you can read and point to. And contractual obligations change without a transition period, a consultation paper or a press release.

That has three implications worth acting on.

First, source discipline. If your identity process is “what we’ve always done” rather than “what lender X’s current requirements say”, you are running an undocumented standard. When a lender updates its broker identification requirements, that update is the trigger to change your process — and the file should be able to show which version you applied.

Second, data minimisation. The duplication the MFAA is complaining about means copies of the same identity documents now exist in your CRM, the aggregator’s platform, the lender’s system and the conveyancer’s file. You control one of those. Holding identity documents longer than your licensee’s retention policy requires, in systems with loose access, is a risk you are carrying on someone else’s behalf — and it is the kind of exposure that does not appear on a commission statement until it goes wrong.

Third, client communication. Under the Best Interests Duty, brokers are used to explaining lender choice and cost. Almost nobody explains the identity sequence. A client who is told at the outset that they will verify their identity more than once, by different parties, for different reasons, does not experience the settlement-stage VOI as incompetence on your part. That is a two-sentence conversation that protects the relationship at the exact point in the file where goodwill is thinnest.

What to review this week

None of this requires a project. It requires about ninety minutes.

  1. Name the source. For your top five lenders by volume, find the current broker identification requirement document. If you cannot locate it for a lender you use weekly, that is the finding.
  2. Check the version. Confirm your internal process reflects the current version, not the one you were trained on. Note the date you checked.
  3. Ask the boundary question. If you write commercial or asset finance, ask your licensee in writing whether they consider any part of your service mix captured by the obligations that commenced on 1 July 2026, and keep the answer.
  4. Audit the storage. Identify every place a client’s identity documents sit in your systems, including email attachments and phone photo libraries. Apply your licensee’s retention rules to all of them.
  5. Check access. List who in your business can open an identity document, and confirm each of them still needs to.
  6. Script the conversation. Add two sentences to your first-appointment process setting the client’s expectation that identity will be verified more than once.

What to watch next

Three things, in order of how much they would change your week. Whether the Digital ID Act review recommends any form of cross-regime recognition of identity results. Whether ARNECC’s Version 8 rules, when they are finalised, open any door to accredited Digital ID at settlement. And whether AUSTRAC gives the FBAA — and the rest of the channel — a definitive answer on where the perimeter of the 1 July designated services actually sits.

If all three move together, the duplicate check genuinely disappears and brokers get time back. If only one moves, the most likely outcome is the one the MFAA explicitly warned against: another verification step layered on top of the ones already there.

Key takeaways

  • The MFAA’s submission to the Digital ID Act 2024 statutory review, announced 21 August and reported 8 September, asks that identity information be usable across the lending chain rather than rebuilt by each participant.
  • The MFAA’s own member guidance says the AML/CTF changes that commenced 31 March 2026 do not bring brokers into the regime — they change lenders’ obligations, which lenders then pass to brokers through their requirements.
  • Verification of Identity for electronic conveyancing sits with Subscribers and mortgagees under ARNECC’s Model Participation Rules. Brokers are not among the obliged parties.
  • The FBAA has asked AUSTRAC more than once to confirm whether commercial asset finance broking is captured by the services that commenced 1 July 2026. No public answer appears in the reporting reviewed here.
  • Because the broker’s identity obligations are largely contractual, the protection is evidentiary: show which lender requirement you applied, which version, and what you sighted.

Frequently asked

Breaking news for modern brokers

Policy shifts, lender moves and compliance changes, read through what they actually do to your files.

More at The Broker Times →

Interactive · Broker Tool

Whose Check Is It? — and Is Your File Ready?

Pick a stage to see who holds the obligation and what your file should show. Then work the audit below.



Obligation holder

The lender — discharged through its broker identification requirements.

The MFAA’s member guidance states the AML/CTF changes that commenced on 31 March 2026 did not bring brokers into the regime. They changed lenders’ obligations; lenders then set the identification steps they need brokers to perform.

Your file should show

  • Which lender requirement you applied, and its current version or date.
  • What you sighted, and how (in person, certified copy, electronic).
  • What you did when a detail did not reconcile, and who you escalated it to.

Your 90-minute identity audit

Tick each item as you complete it. Nothing is stored or sent anywhere — this resets when you reload the page.

0 of 6 done

Anything in this audit that turns up a gap is a conversation for your aggregator’s compliance team, not a fix to improvise.

More broker briefings →

Disclaimer: This article is for general information and professional development purposes only. It does not constitute legal, compliance, or financial advice. Brokers should consult their aggregator's compliance team and, where required, seek independent legal advice regarding their obligations under the National Consumer Credit Protection Act 2009 and ASIC's responsible lending guidelines.