Free guide: How to use AI in compliance
Back

Australia's IDLock will let customers switch off their own Document Verification Service checks

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published September 2, 2026 Reviewed by Charlene Wang
Editorial illustration for the article "Australia's IDLock will let customers switch off their own Document Verification Service checks".

Australia's IDLock will let people block their own documents in the Document Verification Service. What it changes for KYC onboarding and CDD obligations.

Table of contents

Australia's Attorney-General announced IDLock on 31 August 2026, a myGov service that will let people block, unblock and monitor their identity documents in the Document Verification Service. A limited early access cohort starts in 2026, with national rollout in 2027. Reporting entities should plan for genuine customers who arrive deliberately unverifiable.

  • IDLock was announced on 31 August 2026 and reaches myGov in 2027, after a limited early access cohort in 2026.
  • It is a consumer front end for the Credential Protection Register, a Commonwealth block list that has run since 2022.
  • The Attorney-General's Department reports more than 830,000 blocked verification attempts since 2022, around 18,000 each month.
  • Section 28 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 requires verification using reliable and independent data, so a lock closes one route, never the obligation.
  • Departmental guidance already tells organisations they must hold an alternative method of verification and must not decide on a match result alone.

What did Australia actually announce?

Australia's Attorney-General, Michelle Rowland, published a media release on 31 August 2026 announcing IDLock, a service that will let Australians block, unblock and monitor the use of eligible identity documents through the Document Verification Service. It reaches myGov in 2027. A small cohort gets early access later in 2026.

This is a delivery announcement, not a new law. The release announces no legislation, and the capability already sits under the Identity Verification Services Act 2023: the Attorney-General's Department has operated the Credential Protection Register since 2022, and IDLock is described as a new way for people to reach the protections that register already provides.

Rowland framed it as a shift from remediation to prevention, saying that as data breaches, scams and cyber-enabled crime evolve, "Australia's approach must evolve with them." The department's own materials are blunter about the mechanism: a registered credential is stopped from being verified, while remaining usable for what it was issued to do.

ItemDetail
Announcement date31 August 2026
Announced byAttorney-General Michelle Rowland MP
ServiceIDLock, delivered through myGov
FunctionsBlock, unblock and monitor eligible identity documents
Verification service affectedDocument Verification Service
Underlying registerCredential Protection Register, established 2022

Source: Attorney-General's media release, 31 August 2026.

How does the Credential Protection Register actually block a check?

The register is a central list of identity documents that are prevented from being verified through the Document Verification Service. Entries are stored as hashed, de-identified values rather than document details. When a participating organisation submits a check, the Attorney-General's Department routes it to the issuing agency and returns a result. Registered credentials do not verify.

Two design choices matter for anyone building onboarding against it. First, the department says results "usually" return a yes or a no. Second, the architecture is deliberately double blind: the requesting organisation does not need to store a copy of the document, the issuer does not learn who asked, and the department knows the parties to a transaction but not the content of what it relays.

Access to the Document Verification Service is contractual as well as statutory. Every user signs a participation agreement, must collect the individual's express consent before running a check, and must complete an annual self-audit and compliance statement. The department also states that information supplied for verification cannot be reused for data profiling, online tracking or marketing.

The department publishes the 14 document types the service can verify, from passports and driver licences to Medicare cards and birth certificates, but has not said which of them IDLock will cover. That answer decides how much of your accepted document set a customer can switch off, across the more than 3,500 organisations in Australia and New Zealand approved to use the service.

DateRegister milestoneDetail
4 May 2026Ministerial update on performanceMore than 750,000 attempts blocked
4 May 2026Enhancement programme confirmedMore than 14 million Australian dollars
4 May 2026Issuer web portal liveNear real time blocking by issuers
31 August 2026IDLock announcedMore than 830,000 attempts blocked

Source: Attorney-General's media releases, 4 May and 31 August 2026.

What does a locked credential change for your due diligence duties?

Nothing in IDLock changes the statutory standard. Section 28 of the AML/CTF Act 2006 bars a reporting entity from commencing a designated service until it has established the required matters on reasonable grounds, and section 28(3)(d) requires it to "verify, using reliable and independent data" the KYC information appropriate to the customer's risk. A lock removes one source, not the duty.

There is also a statutory electronic route a lock does not close. Division 5A lets a reporting entity disclose a customer's name, residential address and date of birth to a credit reporting body and request an assessment of whether they match, under section 35A, with section 35B authorising the body to answer. It consumes no document number. Section 35A(2) attaches cumulative conditions: telling the customer first, obtaining their express agreement, and making an alternative means of verification available. Section 35C requires written notice where verification still fails.

Do not reach for the relief in section 6-10 of the AML/CTF Rules 2025 by reflex. It treats a matter as established where an individual is unable to obtain the evidence, or unable to access it "due to circumstances beyond the person's control". A customer who chose to lock a credential and can unlock it in the myGov app does not obviously fit either limb, and the limbs are cumulative: the entity must still take reasonable steps to establish identity and complete the risk assessment.

Suspicious matter reporting is where this most easily goes wrong. The obligation in section 41(1)(d) turns on suspecting on reasonable grounds that the person is not who they claim to be. A voluntary lock, standing alone, is not that. Treating every declined electronic check as a reportable matter would degrade the value of your reporting and burden AUSTRAC, the Australian Transaction Reports and Analysis Centre, with noise.

Three duties are untouched. Sanctions and politically exposed person screening under section 28(2)(e) runs on the name and date of birth you already hold. Record keeping under section 111 still applies, and your AML/CTF program should evidence why the electronic route failed and what you did instead. Enhanced customer due diligence under section 32 triggers on risk, not on a failed check.

The department is also explicit that a match result cannot be the sole deciding factor, and that an organisation "must also have an alternative method of verification". Firms that built onboarding around one electronic check with no documentary path were out of step with that guidance before IDLock existed. That matters now because the AML/CTF Rules 2025 commenced on 31 March 2026, and from 1 July 2026 roughly 80,000 new businesses entered the regime under the tranche 2 reforms.

What is still uncertain about IDLock?

The largest open question is what a blocked credential looks like to the relying party. The department says results "usually" return a yes or a no. Nothing released so far commits to a distinguishable response for a locked document, and without one an onboarding system cannot separate a deliberate lock from a typo or an impersonation attempt.

If locks present as ordinary Document Verification Service failures, false declines rise, manual review queues grow, and the customers most likely to lock, people already harmed by a breach, are pushed into the slowest path. Nobody has published a model of that cost, and the announcement does not address it.

Unlock latency is unresolved too. The May 2026 release describes near real time updates by document issuers through a web portal, but says nothing about how quickly a customer-initiated unlock propagates. An application flow that assumes an instant toggle will break if the answer is minutes or hours.

Coverage is uneven by design. Only participating Commonwealth, state and territory issuers can put documents on the register, and the government said in May that it "continues to work closely with all jurisdictions" on uptake. A licence from a jurisdiction that has not joined cannot be locked, so protection will be patchy well into the rollout.

Two risks run the other way. Control now concentrates in myGov, so whoever compromises that account controls the unlock, which moves the attack surface rather than removing it. And a lock the customer can be talked into lifting invites coercion, whether from a scammer running a script or from someone with control over a vulnerable person's affairs.

The headline number deserves care as well. The 830,000 figure counts blocked verification attempts, not confirmed fraud, and IDLock will add holder-initiated blocks to the same denominator. Treat it as harm contained rather than harm measured, and treat the announced dates as programme commitments rather than statutory deadlines.

How does this compare with the UK and EU approaches?

Three jurisdictions are solving the same problem in three different places in the stack. Australia is adding holder control to a central government matching service. The United Kingdom is certifying the providers who sit between the holder and the relying party. The European Union is moving the credential itself onto the holder's device.

ApproachWhere control sitsWhat the relying party getsStatus
Australia, register plus IDLockCentral register, holder toggles through myGovA yes or no from a government serviceRegister live since 2022, IDLock announced 31 August 2026
United Kingdom, digital verification services (DVS) trust framework 1.0Certified providers on a statutory registerAssurance the provider meets a published frameworkNot in force; starts when the first conformity assessment body is accredited, no earlier than 1 September 2026
European Union, digital identity walletCredential held on the user's own deviceOnly the attributes the user chooses to releaseArticle 5a(1) requires each member state to provide a wallet within 24 months of the relevant implementing acts entering into force

The Australian model is the least disruptive to existing integrations and the least ambitious about data minimisation. Nothing about IDLock changes what an organisation collects or stores. It changes only whether a Document Verification Service check succeeds. The UK framework and the EU wallet both push further, toward assured intermediaries and selective disclosure respectively.

A block list is a strong recovery mechanism after a breach and a weak preventive one before it, because the data that made the credential forgeable is already loose. That is the honest limit of what this design can do, and it is why the other two jurisdictions are working further up the stack.

How should compliance teams respond?

Start with a pipeline test. Pull your last twelve months of failed electronic verifications and separate genuine mismatches from data quality problems, because that base rate is what a wave of customer-initiated locks will sit on top of. If you cannot produce that split, that is the first gap to close.

Then write the fallback down. Your AML/CTF program should name at least one route towards satisfying section 28(3)(d) that does not consume a document number, such as the Division 5A credit reporting body assessment, define who approves it, and set the record you keep when you use it.

Train onboarding and support staff to ask whether the customer has locked a document before escalating, and give them wording for requesting a temporary unlock. Australian firms should review their Document Verification Service participation agreement obligations, since the annual self-audit already requires evidence of how you use the service.

Longer term, the direction of travel is clear enough: holders expect control over how their identity data is used, and regulators are building it for them. Zyphe takes that further down the stack, verifying the NFC chip in a passport or identity card to the ICAO 9303 standard and sharding personal data across many independent nodes, with no master key and no central store to breach, so control sits with the customer by construction rather than by toggle. If that is the model you want under your onboarding, book a demo or read how it works.

The bottom line

IDLock is a small change to a government service with a disproportionate effect on onboarding. It hands the holder a switch on the Document Verification Service route that Australian reporting entities have treated as always available, at exactly the moment tens of thousands of newly regulated firms are standing up their first customer due diligence processes. The statutory duty does not move. What moves is the reliability of the cheapest way of discharging it, and teams that have never written down a fallback will discover that the hard way. Build the alternative path now, teach your staff to recognise a lock rather than assume a fraud, and treat the announced dates as intentions rather than deadlines. Holder control over identity data is not a trend to wait out.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

IDLock is an Australian government service announced on 31 August 2026 that will let people block, unblock and monitor the use of their identity documents through the Document Verification Service. It will be delivered through myGov, with a small early access cohort later in 2026 and a broader national rollout in 2027.

No. A document on the Credential Protection Register is blocked from electronic verification but remains usable for its primary purpose. The Attorney-General's Department gives the example of a blocked passport, which can still be used to travel overseas. Only the verification pathway is closed, not the document itself.

Yes. Section 28 of the AML/CTF Act 2006 requires you to verify KYC information using reliable and independent data before providing a designated service. A locked credential removes one route to that standard. You can use documentary verification, the Division 5A credit reporting body assessment, or ask the customer to unlock the document.

Not by itself. The obligation in section 41(1)(d) of the AML/CTF Act 2006 arises where there is a suspicion on reasonable grounds, including a suspicion that the person is not who they claim to be. A customer exercising a published government control does not meet that test without something more.

The Attorney-General's media release of 31 August 2026 reports more than 830,000 blocked identity verification attempts since late 2022, averaging around 18,000 each month. An earlier release on 4 May 2026 put the figure above 750,000 and confirmed more than 14 million Australian dollars of investment in register enhancements.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo