5 mistakes almost every business has made since 1 July
Since 1 July, almost every firm has made at least one of these. None of them are your fault.
·28 August 2026·About 4 minutes
Something has probably slipped since July. Not through carelessness, and not because anyone stopped paying attention. The paperwork side of AML/CTF came with guidance, templates and advisers to walk a firm through it. What happens to client identity documents inside your systems came with none of that, and that is where all five below happened.
Here are the five, in the order they tend to happen. Each one takes under a minute to check.
1. The licence was scanned, and the picture was kept
The instinct is the right one. Verify the identity, keep the record. So the details went into the system, and the image went in beside them, filed exactly the way the one before it was.
The OAIC has since put it plainly. "The AML/CTF Act does not require you to keep scanned copies or photocopies of identity documents themselves for record keeping purposes." The record is the information taken from the document and the fact that somebody checked it. The photograph was never what the Act asked for, and once it is no longer needed there is an obligation to take reasonable steps to destroy or de-identify it.
In an accounting practice this looks like a client onboarded in July, with the scan still sitting beside the details.
2. The program was written, and that felt like the finish
Writing an AML/CTF program is real work. It takes weeks, it usually takes an adviser, and at the end of it there is a document. What there is not is any change to where client identity documents are stored, who can open them, or what removes them when they are no longer needed. The document sets out the intention, but it is the systems that decide whether it happens. Anyone who finished the first half had every reason to think that was the job completed. Unfortunately it wasn't.
3. Identity documents arrived in a shared inbox, and stayed there
Clients send things to the email address on the website. That is what the address is for.
The OAIC's first published example of a reasonable step is knowing what personal information you hold and where it is stored, and knowing what systems you use, who has access to them, and what those people can do. A general inbox tends to fall down on the last two. It is open to whoever answers enquiries, which is a sensible arrangement for enquiries and an accidental one for drivers licences.
In a real estate agency this looks like a general enquiries address that four people can open, with licence photographs in it going back to July.
4. There is a record of who opened a client file, but there is nothing for email
Practice and matter systems keep a log of who opened what. It is one of the reasons firms buy them.
Mailboxes generally do not, unless somebody turned it on. The OAIC's fourth published example asks for "audit logs and access monitoring for all your systems, including email accounts", and those last three words are doing deliberate work, because email is where identity documents actually arrive and where most of them stay.
In a law firm this looks like a conveyancing matter that settled months ago, whose identity verification came in by email and is still sitting in it.
5. Turnover still felt like the line
For twenty years it was. A business turning over $3 million or less sat outside the Privacy Act, and a great many firms in these three industries did.
That has changed for the AML/CTF work, and only for that work. The OAIC lists the businesses covered whatever their turnover, and reporting entities under the AML/CTF Act are on that list. Client identity documents sit inside that. Staff records and marketing lists sit outside it.
This one has an article of its own: The Privacy Act exemption your business just lost.
Which of these apply to you
None of the five needs a project to fix. Each of them needs somebody to find out whether it applies, and that is the part nobody has time for.
Fixing them is ordinary work. Tightening who can open a shared inbox, turning on logging where it is off, and keeping the systems that hold identity documents configured to keep people out and monitored for the times somebody tries to get in. That is the part we do at efex.
Our AML/CTF technology and data checklist asks thirteen questions and takes about three minutes to complete. No client files are opened and nothing is uploaded. At the end you get a written findings report that says which of these are already handled and which are not. Start the checklist.
Thirteen questions. About three minutes. No client files.
Or talk it through first. Thirty minutes, no obligation, with somebody who does this work every day.
These articles explain what the regulators have published and what it commonly means in practice. General information only, not legal or compliance advice.
