Australia's IDLock will let people block their own documents in the Document Verification Service. What it changes for KYC onboarding and CDD obligations.
Table of contents
Australia's Attorney-General announced IDLock on 31 August 2026, a myGov service that will let people block, unblock and monitor their identity documents in the Document Verification Service. A limited early access cohort starts in 2026, with national rollout in 2027. Reporting entities should plan for genuine customers who arrive deliberately unverifiable.
- IDLock was announced on 31 August 2026 and reaches myGov in 2027, after a limited early access cohort in 2026.
- It is a consumer front end for the Credential Protection Register, a Commonwealth block list that has run since 2022.
- The Attorney-General's Department reports more than 830,000 blocked verification attempts since 2022, around 18,000 each month.
- Section 28 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 requires verification using reliable and independent data, so a lock closes one route, never the obligation.
- Departmental guidance already tells organisations they must hold an alternative method of verification and must not decide on a match result alone.
What did Australia actually announce?
Australia's Attorney-General, Michelle Rowland, published a media release on 31 August 2026 announcing IDLock, a service that will let Australians block, unblock and monitor the use of eligible identity documents through the Document Verification Service. It reaches myGov in 2027. A small cohort gets early access later in 2026.
This is a delivery announcement, not a new law. The release announces no legislation, and the capability already sits under the Identity Verification Services Act 2023: the Attorney-General's Department has operated the Credential Protection Register since 2022, and IDLock is described as a new way for people to reach the protections that register already provides.
Rowland framed it as a shift from remediation to prevention, saying that as data breaches, scams and cyber-enabled crime evolve, "Australia's approach must evolve with them." The department's own materials are blunter about the mechanism: a registered credential is stopped from being verified, while remaining usable for what it was issued to do.
| Item | Detail |
|---|---|
| Announcement date | 31 August 2026 |
| Announced by | Attorney-General Michelle Rowland MP |
| Service | IDLock, delivered through myGov |
| Functions | Block, unblock and monitor eligible identity documents |
| Verification service affected | Document Verification Service |
| Underlying register | Credential Protection Register, established 2022 |
Source: Attorney-General's media release, 31 August 2026.
How does the Credential Protection Register actually block a check?
The register is a central list of identity documents that are prevented from being verified through the Document Verification Service. Entries are stored as hashed, de-identified values rather than document details. When a participating organisation submits a check, the Attorney-General's Department routes it to the issuing agency and returns a result. Registered credentials do not verify.
Two design choices matter for anyone building onboarding against it. First, the department says results "usually" return a yes or a no. Second, the architecture is deliberately double blind: the requesting organisation does not need to store a copy of the document, the issuer does not learn who asked, and the department knows the parties to a transaction but not the content of what it relays.
Access to the Document Verification Service is contractual as well as statutory. Every user signs a participation agreement, must collect the individual's express consent before running a check, and must complete an annual self-audit and compliance statement. The department also states that information supplied for verification cannot be reused for data profiling, online tracking or marketing.
The department publishes the 14 document types the service can verify, from passports and driver licences to Medicare cards and birth certificates, but has not said which of them IDLock will cover. That answer decides how much of your accepted document set a customer can switch off, across the more than 3,500 organisations in Australia and New Zealand approved to use the service.
| Date | Register milestone | Detail |
|---|---|---|
| 4 May 2026 | Ministerial update on performance | More than 750,000 attempts blocked |
| 4 May 2026 | Enhancement programme confirmed | More than 14 million Australian dollars |
| 4 May 2026 | Issuer web portal live | Near real time blocking by issuers |
| 31 August 2026 | IDLock announced | More than 830,000 attempts blocked |
Source: Attorney-General's media releases, 4 May and 31 August 2026.
What does a locked credential change for your due diligence duties?
Nothing in IDLock changes the statutory standard. Section 28 of the AML/CTF Act 2006 bars a reporting entity from commencing a designated service until it has established the required matters on reasonable grounds, and section 28(3)(d) requires it to "verify, using reliable and independent data" the KYC information appropriate to the customer's risk. A lock removes one source, not the duty.
There is also a statutory electronic route a lock does not close. Division 5A lets a reporting entity disclose a customer's name, residential address and date of birth to a credit reporting body and request an assessment of whether they match, under section 35A, with section 35B authorising the body to answer. It consumes no document number. Section 35A(2) attaches cumulative conditions: telling the customer first, obtaining their express agreement, and making an alternative means of verification available. Section 35C requires written notice where verification still fails.
Do not reach for the relief in section 6-10 of the AML/CTF Rules 2025 by reflex. It treats a matter as established where an individual is unable to obtain the evidence, or unable to access it "due to circumstances beyond the person's control". A customer who chose to lock a credential and can unlock it in the myGov app does not obviously fit either limb, and the limbs are cumulative: the entity must still take reasonable steps to establish identity and complete the risk assessment.
Suspicious matter reporting is where this most easily goes wrong. The obligation in section 41(1)(d) turns on suspecting on reasonable grounds that the person is not who they claim to be. A voluntary lock, standing alone, is not that. Treating every declined electronic check as a reportable matter would degrade the value of your reporting and burden AUSTRAC, the Australian Transaction Reports and Analysis Centre, with noise.
Three duties are untouched. Sanctions and politically exposed person screening under section 28(2)(e) runs on the name and date of birth you already hold. Record keeping under section 111 still applies, and your AML/CTF program should evidence why the electronic route failed and what you did instead. Enhanced customer due diligence under section 32 triggers on risk, not on a failed check.
The department is also explicit that a match result cannot be the sole deciding factor, and that an organisation "must also have an alternative method of verification". Firms that built onboarding around one electronic check with no documentary path were out of step with that guidance before IDLock existed. That matters now because the AML/CTF Rules 2025 commenced on 31 March 2026, and from 1 July 2026 roughly 80,000 new businesses entered the regime under the tranche 2 reforms.
What is still uncertain about IDLock?
The largest open question is what a blocked credential looks like to the relying party. The department says results "usually" return a yes or a no. Nothing released so far commits to a distinguishable response for a locked document, and without one an onboarding system cannot separate a deliberate lock from a typo or an impersonation attempt.
If locks present as ordinary Document Verification Service failures, false declines rise, manual review queues grow, and the customers most likely to lock, people already harmed by a breach, are pushed into the slowest path. Nobody has published a model of that cost, and the announcement does not address it.
Unlock latency is unresolved too. The May 2026 release describes near real time updates by document issuers through a web portal, but says nothing about how quickly a customer-initiated unlock propagates. An application flow that assumes an instant toggle will break if the answer is minutes or hours.
Coverage is uneven by design. Only participating Commonwealth, state and territory issuers can put documents on the register, and the government said in May that it "continues to work closely with all jurisdictions" on uptake. A licence from a jurisdiction that has not joined cannot be locked, so protection will be patchy well into the rollout.
Two risks run the other way. Control now concentrates in myGov, so whoever compromises that account controls the unlock, which moves the attack surface rather than removing it. And a lock the customer can be talked into lifting invites coercion, whether from a scammer running a script or from someone with control over a vulnerable person's affairs.
The headline number deserves care as well. The 830,000 figure counts blocked verification attempts, not confirmed fraud, and IDLock will add holder-initiated blocks to the same denominator. Treat it as harm contained rather than harm measured, and treat the announced dates as programme commitments rather than statutory deadlines.
How does this compare with the UK and EU approaches?
Three jurisdictions are solving the same problem in three different places in the stack. Australia is adding holder control to a central government matching service. The United Kingdom is certifying the providers who sit between the holder and the relying party. The European Union is moving the credential itself onto the holder's device.
| Approach | Where control sits | What the relying party gets | Status |
|---|---|---|---|
| Australia, register plus IDLock | Central register, holder toggles through myGov | A yes or no from a government service | Register live since 2022, IDLock announced 31 August 2026 |
| United Kingdom, digital verification services (DVS) trust framework 1.0 | Certified providers on a statutory register | Assurance the provider meets a published framework | Not in force; starts when the first conformity assessment body is accredited, no earlier than 1 September 2026 |
| European Union, digital identity wallet | Credential held on the user's own device | Only the attributes the user chooses to release | Article 5a(1) requires each member state to provide a wallet within 24 months of the relevant implementing acts entering into force |
The Australian model is the least disruptive to existing integrations and the least ambitious about data minimisation. Nothing about IDLock changes what an organisation collects or stores. It changes only whether a Document Verification Service check succeeds. The UK framework and the EU wallet both push further, toward assured intermediaries and selective disclosure respectively.
A block list is a strong recovery mechanism after a breach and a weak preventive one before it, because the data that made the credential forgeable is already loose. That is the honest limit of what this design can do, and it is why the other two jurisdictions are working further up the stack.
How should compliance teams respond?
Start with a pipeline test. Pull your last twelve months of failed electronic verifications and separate genuine mismatches from data quality problems, because that base rate is what a wave of customer-initiated locks will sit on top of. If you cannot produce that split, that is the first gap to close.
Then write the fallback down. Your AML/CTF program should name at least one route towards satisfying section 28(3)(d) that does not consume a document number, such as the Division 5A credit reporting body assessment, define who approves it, and set the record you keep when you use it.
Train onboarding and support staff to ask whether the customer has locked a document before escalating, and give them wording for requesting a temporary unlock. Australian firms should review their Document Verification Service participation agreement obligations, since the annual self-audit already requires evidence of how you use the service.
Longer term, the direction of travel is clear enough: holders expect control over how their identity data is used, and regulators are building it for them. Zyphe takes that further down the stack, verifying the NFC chip in a passport or identity card to the ICAO 9303 standard and sharding personal data across many independent nodes, with no master key and no central store to breach, so control sits with the customer by construction rather than by toggle. If that is the model you want under your onboarding, book a demo or read how it works.
The bottom line
IDLock is a small change to a government service with a disproportionate effect on onboarding. It hands the holder a switch on the Document Verification Service route that Australian reporting entities have treated as always available, at exactly the moment tens of thousands of newly regulated firms are standing up their first customer due diligence processes. The statutory duty does not move. What moves is the reliability of the cheapest way of discharging it, and teams that have never written down a fallback will discover that the hard way. Build the alternative path now, teach your staff to recognise a lock rather than assume a fraud, and treat the announced dates as intentions rather than deadlines. Holder control over identity data is not a trend to wait out.
Cited sources
- Attorney-General media release, new identity protection service IDLock, 31 August 2026
- Attorney-General media release, more than 750,000 fraudulent identity verification requests blocked, 4 May 2026
- IDMatch, Credential Protection Register and data breach guidance, Attorney-General's Department
- IDMatch, information for individuals, including alternative verification methods
- IDMatch, about our services, including the 14 verifiable document types
- Identity Verification Services Privacy Statement, Attorney-General's Department
- IDMatch, guidance for users of the identity verification services
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006, compilation in force 1 July 2026
- Anti-Money Laundering and Counter-Terrorism Financing Rules 2025, F2025L01026
- Identity Verification Services Act 2023, Federal Register of Legislation
- UK digital verification services trust framework 1.0, GOV.UK
- Regulation (EU) 2024/1183, Article 5a, European Digital Identity Wallets
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.