Written by
Hadi Hawi, Chief Technology Officer
Reviewed by
Amos Yassa, Onboarding and Compliance Lead
Published 9 May 2026 · Last updated 9 May 2026
Ratified is the only Australian AML CTF platform built for the privacy paradox at the heart of Tranche 2. Identity verification, tokenised. Documents, not retained. Infrastructure, hosted in Australia under Australian privacy law. The architecture is not a marketing claim, it is the only legally defensible answer to two regulators making opposing demands of the same data.
The AML/CTF Act 2006 requires every reporting entity to verify the identity of every customer and to keep a complete audit trail of that verification for seven years. The Privacy Act 1988 requires the same entity to destroy or de-identify personal information once it is no longer needed for the purpose for which it was collected. Australian Privacy Principle 11 carries that destruction obligation as a hard duty.
Most AML platforms ignore one half of the equation. Some store full passport scans and driver licence images on offshore cloud servers and hope the AML obligation neutralises the privacy obligation. Others build for privacy and skip the audit trail the regulator will ask for during inspection. Both fail under the early 2026 OAIC guidance on AML/CTF reporting entities, which made it explicit that the AML/CTF Act does not give a reporting entity authority to retain raw identity documents indefinitely. Verification record yes, raw passport image no.
Ratified is built around the paradox, not in spite of it. The architecture verifies an identity against the source-of-truth government databases through an approved gateway, captures the verification result and the consent record, and discards the raw document. The audit trail survives. The privacy exposure does not. That is what APP 11 compliance for an AML platform actually looks like in 2026.
Australian Privacy Principle 11 sits inside Schedule 1 of the Privacy Act 1988 (Cth) and applies to every entity covered by the Act. The text and the OAIC's interpretation of it are publicly available, and every reporting entity preparing for Tranche 2 needs to read both. The shorthand version is below.
APP 11.2 requires an entity to take reasonable steps to destroy personal information or to ensure it is de-identified once that information is no longer needed for the purpose it was collected for. The trigger is not "when the customer asks us to delete it". The trigger is "when we no longer need it". For an AML/CTF reporting entity that has just verified an identity, the moment the verification result is captured and the audit-trail entry is generated, the underlying passport image is no longer needed. The reasonable step at that point is to destroy it.
The OAIC guidance for reporting entities under the AML/CTF Act, published in early 2026, makes the position explicit. The AML/CTF Act requires identity verification, not the indefinite warehousing of identity documents. Reporting entities are expected to actively destroy or cryptographically de-identify raw personal information once the verification record is generated and the compliance purpose is served.
The AML/CTF Act creates a seven-year record-keeping obligation. APP 11 carves out an exemption where another law requires retention. The exemption covers the verification record, the customer due diligence assessment, the risk rating, the beneficial ownership disclosure, the suspicious matter report, and the audit trail of who verified what when. It does not cover the raw passport image, the high-resolution driver licence scan, the live selfie, or the biometric template captured during liveness checks. Those are the inputs to verification, not the verification record itself.
Reporting entities that conflate the two and store everything are leaning on a retention exemption that does not apply. When an OAIC compliance sweep tests them, the destruction obligation is the one they will fail.
Australian Privacy Principle 8 governs the cross-border disclosure of personal information. An entity that sends personal information to an overseas recipient remains accountable for any act or practice of that recipient that would have breached the Australian Privacy Principles if the recipient had been bound by them. In plain terms, if your AML platform stores Australian customer documents on a US, EU, or Singapore data centre, you carry the legal risk for any breach by that overseas provider. The breach is foreign, the liability is yours.
For Tranche 2 entities the APP 8 dimension matters every time they evaluate a vendor. Onshore Australian hosting is not a nice-to-have, it is the simplest way to remove a category of regulatory exposure from the procurement decision.
Two failure modes show up across the AML SaaS market that fail under the early 2026 OAIC position.
The first is platforms that retain raw identity documents as a default. Marketing copy on these platforms still says things like "secure document storage" and "encrypted document vault". Encryption is a security control, not a destruction. Storing an encrypted passport image in a vault is still storage, and APP 11 requires destruction when the document is no longer needed. A reporting entity that uses such a platform is the entity holding the document, regardless of where the platform's vault sits.
The second is platforms hosted overseas. AML SaaS providers headquartered in the United States, the United Kingdom, the European Union, or Singapore typically store Australian customer data in the same data centres they use for their global customers. The Australian reporting entity inherits the APP 8 exposure of any privacy breach by that overseas provider. The 2024 average total cost of a corporate data breach in Australia reached $4.26 million per incident (Cost of a Data Breach Report 2024, IBM). Inheriting that risk through a vendor selection decision is a financial exposure the principal of the firm signs off on personally.
A reporting entity does not get to delegate the breach away. Under APP 8.1 the Australian entity remains liable. Under APP 11.2 the Australian entity remains responsible for destruction. The only way to remove both exposures at the platform layer is to use an AML platform that does not retain the raw documents at all, hosted on infrastructure governed by Australian law.
Ratified is built on the architecture the OAIC describes as the compliant path. Three properties matter.
First, verification is tokenised. When a customer is verified through the Ratified Network, the platform submits the customer's biographic details to the Australian Government's Document Verification Service through an approved Gateway Service Provider. The DVS returns a match-or-no-match response that confirms the identity document is valid against the issuing agency's records. The verification result, the timestamp, the consent record, and the audit-trail entry are persisted. The raw document image is discarded. What remains in the Ratified Network is a token, a verification confirmation, a record of who consented to what and when. Not a passport image. Not a driver licence scan.
Second, the infrastructure is Australian-hosted. Ratified's data sits in Australian data centres, on infrastructure governed by Australian privacy law, inside the jurisdiction of the OAIC. There is no APP 8 cross-border exposure to manage. The reporting entity using Ratified is not relying on the privacy regime of another country to protect its customers' information.
Third, the architecture is built on top of the Identity Verification Services Act 2023 and the Identity Verification Services Rules 2024. Commercial entities cannot connect directly to the Document Verification Service. The IVS Act requires private-sector access through an approved Gateway Service Provider. Building an in-house verification tool that touches DVS without that approval is not technically difficult, it is legally prohibited. Ratified operates inside that legislated path. Customers using the platform inherit a verification flow that is compliant with the IVS Act, with the AML/CTF Act, and with APP 11.
The 4-pager that explains the underlying product mechanics in detail sits in the Ratified Network architecture. The short version is that the customer scans the Ratified QR code once, completes a verified identity capture against DVS, and from that point forward the verification can be reused across the Ratified Network without the document ever leaving the secure capture surface. Verified Once, Trusted Everywhere. Because the document never settles into a vault, there is nothing to destroy later, and nothing to leak.
Tranche 2 captures more than 100,000 entities across five sectors. The data-handling exposure looks slightly different in each.
A standard real estate agency runs identity verification across vendors, purchasers, tenants, and landlords every week. High volume means high accumulation of raw documents under any platform that retains them. Australian-hosted, no-document-retention architecture is the only model that does not turn an agency's compliance file into a privacy breach risk. More on the real estate AML compliance workflow.
Conveyancers verify identity inside settlement timeframes that can compress to 24 hours. Friction in the verification step is friction in the settlement chain. A platform that destroys the raw document at point of verification removes a future-dated retention liability without slowing the file. More on AML for conveyancers.
Legal practitioners hold trust account funds and operate under professional indemnity cover that prices privacy breach risk as a separate line. APP 11 exposure on retained client identity documents is a direct PI underwriting input. Removing the retention removes the input. More on AML for legal practices.
Accountants verify the natural persons behind companies, trusts, and partnerships. Beneficial ownership disclosure inside Tranche 2 means the volume of personal information passing through the practice is materially higher than at most other DNFBPs. Tokenised verification means the volume of retained personal information stays low even as the verification volume rises. More on AML for accountants.
Every verification, every consent record, every risk rating, and every escalation is captured in the Compliance Officer Dashboard with timestamps, the verifying officer, and the customer's consent. The dashboard exports the AUSTRAC-aligned audit trail that a reporting entity is expected to produce on inspection. Granular, queryable, and date-stamped. The dashboard is the live record. The raw document is not.
The audit trail is only as defensible as the access model behind it. Ratified runs role-based access across every customer file, with the principal, compliance officer, sales agent, and administrative roles each given visibility scoped to what they need. No agent has unilateral access to the full record set. No file is editable after the audit-trail event is logged. The role model is part of the compliance posture, not a UI convenience.
Ratified aligns to the Australian Cyber Security Centre's Essential Eight as the operational security baseline. Penetration testing posture and the AUSTRAC-aligned audit-trail mechanics will be detailed on the dedicated cluster pages (Phase 2 publish). The engineering team behind the platform is led by Caprock and built on the foundation of the three-year, multi-million-dollar Ratified build through the Australian fintech that originally engineered the technology.
If your business is preparing for Tranche 2 obligations for data handling, the architecture decisions you make on hosting, retention, and verification flow are the decisions that determine whether you end up on the right or the wrong side of an OAIC compliance sweep. Ratified is built so that decision is the easy one.
Written by Hadi Hawi, Chief Technology Officer · Reviewed by Amos Yassa, Onboarding and Compliance Lead · Built by the team behind Ratified .
Ratified, AML made simple. See Ratified pricing or register now.