Country-specific guidance Current

Verifying an identity document came from a reliable, independent source

Collecting a document and verifying it are two different steps.

Asking for an identity document is only the first step. Verifying it meets the reliable, independent source standard is a separate step your firm needs to actually do. It is general information, not legal or compliance advice.

Action plan

1 Confirm the document itself is a reliable, independent source The standard is about where the information comes from, not just how the document looks.

The customer due diligence standard reflected in HKICPA's AML/CTF Guidelines requires identifying and verifying a client's identity to a level that gives reasonable assurance the information is an appropriate and sufficient indication of their true identity, using reliable, independent documents. A current, government-issued Hong Kong identity card or passport meets this standard; a self-declared or unverifiable document does not.

  • Treat a current, government-issued document as the baseline for reliability
  • Don't accept a self-declared or informally issued document as sufficient on its own
  • Apply the same reliable, independent source standard to every individual client

Done when: The identity document relied on meets the reliable, independent source standard, not just a visual check

HKICPA: AML/CTF Guidelines for Professional Accountants
2 Check the document is current and consistent with other details A verification step should catch a document that's expired or doesn't match what else you know.

Confirm the document hasn't expired, and cross-check the name, date of birth, and other identifying details against any other information the client has provided. An inconsistency between the document and the client's other details is a reason to ask further questions, not to note and move on.

  • Confirm the document's expiry date before relying on it
  • Cross-check the name and date of birth against other information already held
  • Follow up on any inconsistency rather than proceeding regardless

Done when: The document was confirmed current and consistent with other information held about the client

3 Keep evidence of what was checked, not just the conclusion A file note saying "identity verified" isn't the same as evidence of how.

Retain a record of what was actually checked, such as a copy of the document and a note of the cross-checks performed, rather than only a conclusion that verification was completed. This is what makes the step reviewable later, including by your own firm's quality reviewers.

  • Keep a copy of the document itself, not only a summary
  • Note the specific cross-checks performed, not just the outcome
  • Store this evidence securely, consistent with your firm's data-security obligations

Done when: Evidence of the verification steps performed, not just the conclusion, is kept on file

See storing client identity evidence securely