Regulatory explainer · Identity across time

Customer due diligence verifies who someone is. Caller verification confirms who you're talking to now.

Documents and databases establish identity. Possession of a trusted channel authenticates a later interaction. Firms need both controls in their proper place.

Two layers of assurance

One-off identity is not permanent trust.

CDD and KYC tools answer foundational questions. They gather evidence about a person or entity, establish ownership and authority, support screening and help the firm assess customer risk. Under an AML/CTF program, ongoing CDD keeps that assessment current as the relationship changes.

A later call or email creates a different problem. The real customer may exist and have passed every onboarding check while a criminal controls their mailbox, knows the matter and presents a fraudulent instruction. Re-running a document check can confirm the real customer exists without identifying who controls today's interaction.

Side-by-side

CDD/KYC and caller verification solve different problems.

QuestionCDD / KYCCaller verification
When it happensBefore a designated service begins in most cases, then throughout the relationship as risk and information change.At a consequential interaction: a changed payment destination, sensitive request, new representative or other high-risk trigger.
What it asksWho is the customer, beneficial owner or representative, and what risk does the relationship create?Does the person in this call or email interaction control the trusted contact point already held for the authorised person?
Typical methodsIdentity documents, biometrics, reliable databases, ownership information, screening and risk assessment, depending on the program and provider.A possession challenge sent independently to a verified phone number that predates the instruction under review.
Evidence producedCustomer identification and verification material, risk profile, ownership and authority records, monitoring decisions and review history.A timestamped record of the requester, masked trusted target, method and outcome for the authorised-contact check.
What it does not proveA correct onboarding result does not prove every future caller, mailbox or payment instruction is genuine.Possession of a known phone does not verify an identity document, screen sanctions, establish source of funds or prove payment details are correct.
The day-1 / day-41 frame

Trust has to survive the time between onboarding and action.

  1. 01

    Day 1

    Establish identity and risk

    The firm performs the CDD, KYC or professional identity process appropriate to the engagement, confirms authority and records trusted contact details from an independent source.

  2. 02

    Days 2–40

    Keep the relationship current

    Work proceeds. Ongoing CDD responds to changes in ownership, purpose, behaviour and risk. A mailbox or account can still be compromised after a valid onboarding check.

  3. 03

    Day 41

    A high-risk instruction arrives

    A caller, email or message changes a bank account, requests a release, seeks confidential information or introduces an unexpected representative. Familiar matter details make it sound credible.

  4. 04

    Before action

    Authenticate the interaction

    Return to the trusted contact point established earlier, challenge possession, compare the complete instruction, apply approvals and document the outcome before acting.

“Day 41” is a memorable risk frame, not a claim about average matter length. The second check belongs at any later moment when the channel, authority or instruction carries enough consequence to justify independent verification.

Five professional workflows

The same interaction gap, expressed differently.

01

Legal and conveyancing

VOI and CDD can correctly establish a client at engagement. Weeks later, a compromised mailbox requests that settlement proceeds go to a new account. The live control returns to the trusted client number, verifies possession and reads the full instruction out and back before funds move.

Explore the workflow
02

Accounting

The practice knows the director and has completed its onboarding controls. An urgent caller then asks staff to release a tax refund, payroll file or portal credential. Caller verification tests the current interaction; it does not replace the practice’s authority, privacy or payment-approval checks.

Explore the workflow
03

Real estate

An agency has identified the vendor and assessed customer risk. Near settlement, an email supplies a replacement account for sale proceeds. The agency uses the vendor number already in its records, verifies the authorised contact and confirms the complete account details through the approved workflow.

Explore the workflow
04

Mortgage broking

A broker collected identity evidence for the application, but a later caller seeks the client file or asks to redirect correspondence. Possession-based verification checks whether the person controls the known client phone before staff disclose information or accept the change.

Explore the workflow
05

Financial advice

An adviser has an established client profile and investment authority. A polished call requests a withdrawal to an unfamiliar account. The firm pauses, verifies the authorised contact through a pre-existing number and applies its withdrawal, escalation and record-keeping controls.

Explore the workflow
Possession, not documents

Test the known channel, then verify the instruction.

Vericode uses possession-based verification. A code goes to the verified phone number held for the real person, not to the contact details supplied in the suspicious request. Australian SMS providers MobileMessage or ClickSend using the ACMA-registered sender ID VERICODE.

Each authorised-contact check creates a timestamped, hash-chained record: who requested it, the masked target, method and outcome. Compliance-authorised users can export the record as PDF or CSV. The record belongs beside the firm's instruction, approval and escalation evidence; it does not replace those records.

Verification evidence, not client files. Customer and verification data — recipient details, messages and verification records — is hosted in Australia. Staff sign-in is handled by our identity provider, WorkOS, in the United States; see the subprocessor information.

The practical question

Do I need caller verification if I already do KYC?

Guidance and context

Public guidance is cited for context only. No AUSTRAC endorsement of Vericode is implied.

Add the transaction-time layer

Keep identity assurance connected to the live decision.

Keep CDD and KYC in their proper place, then verify the authorised contact again when a high-risk interaction could change where money, information or authority goes.

General information only. This explainer is not legal, financial, AML/CTF compliance or incident-response advice. Confirm obligations with current AUSTRAC and AFCA guidance and seek professional advice for your circumstances.