Country-specific guidance Current

Verifying an individual client's identity documents against a reliable source

A practical approach to checking evidence, not just collecting it.

Collecting a client's identity documents is only the first step; New Zealand's AML/CFT Act separately requires you to verify that evidence against a reliable and independent source. This guide sets out a practical approach to that verification step. It is general information, not legal or compliance advice.

Action plan

1 Understand what counts as reliable and independent The source needs to be independent of the client, not just look official.

DIA's guidance for AML/CFT reporting entities describes verifying identity information using documents, data, or information from reliable and independent sources. A source is independent when it comes from somewhere other than the client themselves, such as a government-issued document or an independent data source, rather than something the client has produced or asserted on their own.

  • Check the source of the document or data is independent of the client, not self-supplied
  • Prefer a government-issued document or an independently held data source
  • Don't treat a document the client has produced themselves as independent evidence on its own

Done when: The source used to verify identity has been confirmed as independent of the client, not just official-looking

DIA: AML/CFT FAQ for reporting entities
2 Check the document is current and internally consistent An expired or inconsistent document is weaker evidence, even if it looks genuine.

Once you've confirmed a document's source is reliable and independent, check the document itself: whether it's still current, and whether the details on it (name, date of birth, photo) are consistent with what the client has told you and with any other document provided. A mismatch is worth resolving before treating verification as complete.

  • Confirm the document hasn't expired
  • Cross-check the name, date of birth, and other details against what the client has told you
  • Cross-check details against any second document provided

Done when: The document has been confirmed current and its details cross-checked for consistency

3 Record what you used to verify, and when The verification step itself needs to be evidenced, not just the outcome.

Keep a record of exactly which document, data source, or combination was used to verify each piece of customer information, and when the verification took place. This record is what shows the due diligence step actually happened, separately from the documents themselves.

  • Record which specific source verified each piece of information
  • Record the date verification was carried out
  • Keep this record alongside the underlying documents, not as a separate afterthought

Done when: A record exists of what was used to verify each piece of customer information and when

See storing client identity evidence securely