TrustEasy® is a registered trademark of Myna Australia Pty Ltd. Myna Australia Pty ltd complies with ISO/IEC 27001:2022

Why a Simple DVS Check Isn’t Enough: The Critical Role of Secondary Data Sources in AML Compliance

  • By TrustEasy
  • July 20, 2026
  • 2848 Views
AML/CTF Compliance Simple for Australian Accounting Firms

Preparing Australian Accounting Firms for AML/CTF Tranche 2 Compliance from March 2026

For Australian accounting firms navigating Tranche 2 AML/CTF obligations, setting up a digital client onboarding process seems straightforward. You choose a software plug-in, have the client scan their driver’s licence, ping the government’s Document Verification Service (DVS), and mark them as verified.

Job done, right? Not quite.

Relying solely on a primary database like the DVS creates a massive compliance blind spot. If your AML software only checks a single source, your firm is failing to meet AUSTRAC’s strict standards for Electronic Verification (eKYC)—especially when dealing with high-risk customers or complex structures.

Here is why secondary electronic data sources are a regulatory necessity for protecting your practice, and how modern platforms like TrustEasy bridge the compliance gap.

The Problem with Single-Source Verification

The Document Verification Service (DVS) is an incredible tool. It confirms that a specific document number matches a real government record (like a valid passport or driver’s licence). However, a DVS check is a binary match. It answers the question: “Does this specific card exist?”

What it cannot do on its own is satisfy AUSTRAC’s “Safe Harbour” requirements for digital verification. To achieve Safe Harbour status—which legally protects your firm if a client turns out to be using a fraudulent identity—you must verify a client’s identity using a dual-source matching methodology.

What is a Secondary Electronic Source?

Under AUSTRAC guidelines, a secondary electronic source is an independent, reliable database completely separate from the primary government document issuer. Examples include:

  • Credit Bureau Data (e.g., Equifax, Experian, Illion)
  • National Electoral Rolls
  • Comprehensive Utility Registries (telecom and energy data)
  • Public and Commercial Registries

Achieving the “Safe Harbour” Standard

To legally verify an individual electronically in Australia without sighting physical documents, AUSTRAC requires you to match customer data against at least two independent data sources.

The standard digital formula looks like this:

  1. Source 1 (Primary/DVS): Verifies the client’s Full Name and Date of Birth.
  2. Source 2 (Secondary/Bureau/Utility): Verifies the client’s Full Name and Residential Address (or history of activity).

If your onboarding software cannot cross-reference a credit bureau or an electoral roll to confirm that the person actually lives at that address, your electronic verification is incomplete.

Beyond Onboarding: When Secondary Sources Trigger Enhanced Due Diligence (EDD)

Relying on a single source becomes particularly dangerous when your onboarding checks reveal anomalies. As highlighted in AUSTRAC’s educational guidance on Enhanced Customer Due Diligence, firms must escalate their processes when specific risk triggers are met.

If a primary check passes but secondary data is missing, inconsistent, or unmasks a complex layered structure (such as undisclosed corporate layers or foreign trusts), AUSTRAC mandates that you apply Enhanced Customer Due Diligence (EDD) (1:56).

According to AUSTRAC’s operational framework, EDD requires you to take extra risk-based steps to genuinely understand your customer (1:56). In these high-risk scenarios, a basic software platform leaves you completely unequipped, whereas multi-source verification allows you to:

  • Collect and verify additional Know Your Customer (KYC) information to resolve gaps or structural uncertainties (6:13).
  • Establish the customer’s source of funds and source of wealth on reasonable grounds to ensure their financial activity aligns with their profile (6:13).
  • Conduct more detailed transaction monitoring to flag complex patterns with no apparent lawful purpose (6:22).

How TrustEasy Solves the Multi-Source Dilemma

This is precisely where specialized accounting compliance platforms like TrustEasy beat basic, single-source software. TrustEasy was built specifically to absorb the heavy lifting of Tranche 2 compliance within a single, cost-effective workflow.

  • Native Dual-Source Matching: TrustEasy doesn’t just ping the DVS. Its electronic verification framework utilizes a combined broker/bureau verification layer behind the scenes. It cross-references independent databases (including credit bureaus and national registries) to automatically satisfy AUSTRAC’s dual-source safe harbour rules.
  • Built-in EDD Triggers: When a client profile flags an anomaly or a complex structure, TrustEasy transitions your workflow into Enhanced Due Diligence seamlessly, prompting your team to gather and record the necessary source of wealth or source of funds evidence (6:13).
  • Compliant Policy Generation: AUSTRAC explicitly states that your AML/CTF program cannot treat compliance as a static checklist; your internal policies must document exactly how your firm responds to high-risk clients (6:40). TrustEasy bundles automated, compliant AML Policy and Risk Assessment framework generation directly into its software, ensuring your practice guidelines match regulatory expectations from day one (6:52).

Protect Your Firm, Not Just Your Workflow

Efficiency is important, but compliance is non-negotiable. If you outsource your AML setup or rely on a basic plug-in tool that cuts corners on secondary databases, remember that your firm remains legally responsible for ensuring those arrangements meet all AUSTRAC obligations (53:36).

Using a basic single-source verification tool might save a few dollars on monthly software fees, but it leaves your firm exposed to severe regulatory penalties. By leveraging a comprehensive platform like TrustEasy, you ensure your digital onboarding process utilizes the mandatory secondary electronic sources—allowing you to truly know your client, satisfy regulatory expectations, and safeguard your practice (0:10).