On 1 July 2026, a conveyancer in Parramatta who has never filed a suspicious matter report in her life becomes a reporting entity. So does the accountant three doors down, the buyer's agent upstairs, and roughly 100,000 other Australian businesses that until that morning had no anti-money-laundering obligations at all. This is the moment Australia's long-delayed "Tranche 2" AML/CTF reforms take effect — extending AUSTRAC's perimeter to lawyers, accountants, real-estate professionals, dealers in precious metals and stones, and trust and company service providers (AUSTRAC; Moody's).
None of these businesses has a KYC operation. All of them now need one. And that is where the cost hides — not in the one-off build, but in the fact that every one of those 100,000 entities will re-verify customers who have already been verified, over and over, by everyone else in the chain.
Two reforms, one underlying problem
Australia is running two changes in parallel, and it pays to see them as a pair.
The first is enforcement. The AML/CTF Amendment Act received Royal Assent in December 2024; existing reporting entities move to the reformed rules on 31 March 2026, and Tranche 2 entities join on 1 July 2026 (Zyphe). The old prescriptive "applicable customer identification procedures" give way to a flexible, risk-based customer due diligence model, with PEP and sanctions screening, suspicious matter reporting, and seven-year record-keeping baked in (Moody's).
The second is infrastructure. The Digital ID Act 2024 commenced on 1 December 2024, replacing the old unlegislated Trusted Digital Identity Framework (TDIF) with a legislated, civil-penalty-backed accreditation scheme — the AGDIS — that holds identity providers to high standards on privacy, security, proofing and authentication (Department of Finance; Herbert Smith Freehills Kramer). Over 15 million Australians now hold a myID credential, and from November 2026 the government begins accrediting private-sector Identity, Attribute and Exchange providers (FrankieOne). Alongside it, the Trust Exchange (TEx) pilot — trialled with Commonwealth Bank through the myGov wallet — lets a person share only the specific, government-verified attributes a business needs, by consent, via QR (Biometric Update).
Read together, the message is unmistakable: the regulator is widening who must verify, while the state builds the plumbing to make verification portable and consent-driven. The heavy, repeated document-capture model is being deprecated in law and in architecture at the same time.
The duplication tax is real, and measurable
This is not an Australian problem. A Fenergo survey found more than half of banks spend between US$1,500 and US$3,000 per client on KYC reviews, with 21% spending over US$3,000 — and 76% of financial firms said KYC/KYB friction had stopped them adding customers or entering markets (reported via evrotrust). A single business banking with three lenders and holding two facilities can be five separate verification events for what is, factually, one legal entity.
India's compliance teams know this shape intimately. CKYC/CERSAI's registry and the emerging CKYCRR 2.0 already remove some individual re-verification, and Aadhaar-based eKYC did enormous work on the retail side. But the residual gap sits squarely in business onboarding — beneficial ownership, directorships, GSTIN and CIN status, board authority — which no single registry resolves end to end, and which every lender still rebuilds from scratch. Australia's reforms are simply a preview of a global pattern: verify once, at source, and let the proof travel under the holder's consent.
What travels across jurisdictions
The specific rules differ — AUSTRAC's DNFBP net, the RBI's KYC Master Direction, the EU's eIDAS 2.0 wallet — but the design principle is identical everywhere: a source-verified, cryptographically provable, holder-consented credential that a receiving institution can check in seconds rather than re-manufacture in days. The Digital ID Act's separation of Identity, Attribute and Exchange roles is exactly the grammar that reusable identity needs to be portable and auditable.
That is the design behind AssureVerifID. DigiKYB verifies a business — its registration, ownership and signatories — against authoritative sources; DigiKYC does the same for the individuals behind it. The result is recorded on tamper-evident registry infrastructure, so a lender receiving a shared credential can prove what was verified, against which source, and when — without re-running the whole file. Crucially, reuse is lender-scoped by default: the holder decides who sees what, and cross-sector portability stays gated on the regulatory harmonisation that frameworks like Australia's are only now putting in place.
A boundary worth stating plainly: AssureLocker does not lend, price, sanction or decide anything. It is a technology provider — pre-revenue, building toward pilots — whose job is to make a lender's own judgement fast and provable. When 100,000 new reporting entities come online in a single morning, that difference between re-verifying and checking a proof is the whole game.
If your onboarding still rebuilds the same business file every time it changes hands, start here: explore AssureVerifID and reusable KYB.
