Person AUSTRAC screen
The AUSTRAC screen of a person answers the question an identity-check provider cannot: is this person a listed person under the AML/CTF Act, and what does my AML/CTF program have to do about it? It is sold mainly to integrators, as the sanctions and PEP source inside their own AUSTRAC solutions. An integrator bundles an identity check (a document or biometric check) with this screen; VerityRadar supplies the screening part, and this page documents exactly what that part returns and what it still leaves to you.
The screen is deterministic: it reads the person's date of birth and citizenships from the request, resolves the DFAT and PEP determinations from the structured screening hits, and writes one austrac_compliance module into the investigation response. It never authors the person's adverse-media findings — those come from the standard adverse-media process and are bucketed here.
1. The request
POST /api/ai-investigate (bearer JWT or long-lived API key; rate-limited under ai-investigations-per-ip).
| Field | Type | Notes |
|---|---|---|
subjectType | string | "person" to screen a person. |
organizationName | string | Required. Carries the person's name. |
country | string | ISO 3166-1 alpha-2 country of residence. Never used to filter screening. |
dateOfBirth | string | ISO yyyy-MM-dd. Disambiguates same-name people on the lists. |
citizenships | string[] | ISO 3166-1 alpha-2 codes. At least one is required for an AUSTRAC screen. |
additionalIdentifiers | object[] | { "type", "value", "issuingCountry"? } — passport, licence, etc. |
austracScreen | bool | true requests the AUSTRAC screen (3 credits). |
advancedSearch | bool | Adds the Advanced research evidence. Included in an AUSTRAC screen. |
privacyNoticeAcknowledged | bool | Required (true) for subjectType: "person". |
A complete person AUSTRAC request:
{
"subjectType": "person",
"organizationName": "Rosa Delgado",
"country": "VE",
"dateOfBirth": "1979-03-22",
"citizenships": ["VE"],
"additionalIdentifiers": [
{ "type": "passport", "value": "987654321", "issuingCountry": "VE" }
],
"austracScreen": true,
"privacyNoticeAcknowledged": true
}
A screen costs 1 credit (Basic), 2 (Advanced) or 3 (AUSTRAC). AUSTRAC includes the Advanced research, so advancedSearch adds nothing to an AUSTRAC screen.
400 rules
Every guard below runs ahead of the billing path, so a refused request costs nothing. The person-identifier refusals carry creditsCharged: 0.
| Error | When | Message |
|---|---|---|
austrac_person_requires_identifiers | An AUSTRAC screen of a person is requested without a dateOfBirth or with no citizenships. | Submit them, or run a Basic or Advanced screen. |
person_identifiers_require_person | dateOfBirth, citizenships or additionalIdentifiers are sent on a non-person subjectType. | Submit them with "person", or leave them out. |
invalid_citizenship | A citizenships value is not an ISO 3166-1 alpha-2 code. | Resubmit with two-letter codes, for example "AU". |
invalid_date_of_birth | dateOfBirth is not ISO yyyy-MM-dd, or is in the future or before 1900. | Submit the subject's real date of birth as an ISO date. |
privacy_notice_required | An individual is screened without privacyNoticeAcknowledged: true. | Show the collection notice and resubmit with the acknowledgement. |
organizationName is required | The name is missing or blank. | Send the person's name. |
A 402 (insufficient credits or an exhausted per-key budget) is a billing failure, not a refusal: the request was valid but could not be paid for.
2. The response
The response is the v2 investigation envelope. The screen is the austrac_compliance module in modules[] (moduleId: "austrac_compliance", category: "compliance", displayOrder: 190, tier: "free"). Its status is one of listed, possible_match, found, not_found or inconclusive; its severity is derived by the same rules as every other module.
The module's data object:
| Field | Meaning |
|---|---|
sanctionsAuthority | The list the DFAT determination is read from — always the DFAT Consolidated List. |
dfatDetermination | listed, not_listed, possible_match or inconclusive. |
dfatDeterminationReason | Why the determination is what it is. |
dfatListUpdated | The date the DFAT Consolidated List was last updated, for the CDD record. |
subjectCitizenships | The screened person's citizenships. |
dfatComparisons | Per-record DFAT comparison: recordId, name, recordBirthDates, recordNationalities, listedOn, lastUpdated, outcome. |
foreignListings | Foreign-regime listings only: authority, program, sourceUrl. |
pepDetermination | none, domestic, foreign or international_organisation. |
pepPosition | The PEP office identified. |
pepSourceUrl | The source that identifies the PEP. |
pepCurrentOrFormer | current or former. |
foreignDobExclusions | Same-name foreign records excluded because their date of birth belongs to someone else. |
pepDobExclusions | Same-name PEP records excluded on date of birth. |
comparisons | Every same-name record weighed, in the shared RecordComparison shape. |
relatives | Always not_determinable on a public person screen. |
reviewRequired | Whether the screen needs manual review (listed, possible_match, inconclusive, or a foreign/international-organisation PEP). |
countryRiskMethod | How country risk is assessed (FATF lists + DFAT sanctions; the Basel AML Index is deliberately excluded). |
countryRisk | One row per country of residence and citizenship: country, band, reason, callForAction. |
riskFactors | The A1 factors present: id, label, level. |
indicativeRating | low, medium or high, derived from the risk factors. |
triggeredObligations | The AML/CTF obligations triggered: id, label, citation. |
adverseMedia | The bucketed adverse-media findings: profitGeneratingOffence, profitGenerating, minor, excluded, namesakes (each item label, url). |
cddRecord | What was screened, when, with which lists and sources, and what is not covered. |
3. Mapping to AUSTRAC's Initial CDD form for an individual
The screen is organised to answer the items on AUSTRAC's Initial CDD form for an individual.
| Form item | Module field(s) it answers |
|---|---|
| D1 — Sanctions | sanctionsAuthority, dfatDetermination, dfatDeterminationReason, dfatListUpdated, dfatComparisons, foreignListings, foreignDobExclusions, comparisons |
| D3 — PEP | pepDetermination, pepPosition, pepSourceUrl, pepCurrentOrFormer, pepDobExclusions, relatives |
| A1 — Risk factors | countryRiskMethod, countryRisk, riskFactors, indicativeRating, triggeredObligations, adverseMedia |
| CDD record | cddRecord (screenedAt, inputs, lists, searchTerms, sourcesReviewed, notCovered) |
| Disambiguation | subjectCitizenships (feeds both D1 and D3), reviewRequired (flags the whole screen for review) |
What the screen does not cover
cddRecord.notCovered names what remains the reporting entity's responsibility and is not part of this screen:
- Identity verification — that the person is who they claim to be. This is the identity-check provider's job, not the screen's.
- A representative's authority — that a person acting for a customer has authority to act.
- The nature and purpose of the business relationship.
- Source-of-funds or source-of-wealth evidence — the screen can trigger the obligation (
source_of_funds_wealth) but does not collect the evidence.
4. Sample response and sample report
A fictional sample is published alongside this guide and kept in sync with the live schema by the report-sample tests.
- Sample response — verityradar-sample-individual-austrac.json, a fictional person whose
austrac_compliancemodule carries the full field set above. - Sample report — Individual, AUSTRAC, the same subject rendered through the product's own PDF renderer.
5. Data coverage
What this screen can find is bounded by the data the crawler ingests. The Screening Data Coverage Statement is the authoritative record of that; it is available on request from VerityRadar while its public host is prepared. The screen itself draws on three dated lists, recorded in cddRecord.lists:
- the DFAT Consolidated List (dated in
dfatListUpdated), - the FATF high-risk and other monitored jurisdictions (the
countryRiskband source), - the DFAT sanctioned countries (the country-specific regimes Australia implements).