Developers

Person AUSTRAC screen

The AUSTRAC screen of a person answers the question an identity-check provider cannot: is this person a listed person under the AML/CTF Act, and what does my AML/CTF program have to do about it? It is sold mainly to integrators, as the sanctions and PEP source inside their own AUSTRAC solutions. An integrator bundles an identity check (a document or biometric check) with this screen; VerityRadar supplies the screening part, and this page documents exactly what that part returns and what it still leaves to you.

The screen is deterministic: it reads the person's date of birth and citizenships from the request, resolves the DFAT and PEP determinations from the structured screening hits, and writes one austrac_compliance module into the investigation response. It never authors the person's adverse-media findings — those come from the standard adverse-media process and are bucketed here.

1. The request

POST /api/ai-investigate (bearer JWT or long-lived API key; rate-limited under ai-investigations-per-ip).

FieldTypeNotes
subjectTypestring"person" to screen a person.
organizationNamestringRequired. Carries the person's name.
countrystringISO 3166-1 alpha-2 country of residence. Never used to filter screening.
dateOfBirthstringISO yyyy-MM-dd. Disambiguates same-name people on the lists.
citizenshipsstring[]ISO 3166-1 alpha-2 codes. At least one is required for an AUSTRAC screen.
additionalIdentifiersobject[]{ "type", "value", "issuingCountry"? } — passport, licence, etc.
austracScreenbooltrue requests the AUSTRAC screen (3 credits).
advancedSearchboolAdds the Advanced research evidence. Included in an AUSTRAC screen.
privacyNoticeAcknowledgedboolRequired (true) for subjectType: "person".

A complete person AUSTRAC request:

{
  "subjectType": "person",
  "organizationName": "Rosa Delgado",
  "country": "VE",
  "dateOfBirth": "1979-03-22",
  "citizenships": ["VE"],
  "additionalIdentifiers": [
    { "type": "passport", "value": "987654321", "issuingCountry": "VE" }
  ],
  "austracScreen": true,
  "privacyNoticeAcknowledged": true
}

A screen costs 1 credit (Basic), 2 (Advanced) or 3 (AUSTRAC). AUSTRAC includes the Advanced research, so advancedSearch adds nothing to an AUSTRAC screen.

400 rules

Every guard below runs ahead of the billing path, so a refused request costs nothing. The person-identifier refusals carry creditsCharged: 0.

ErrorWhenMessage
austrac_person_requires_identifiersAn AUSTRAC screen of a person is requested without a dateOfBirth or with no citizenships.Submit them, or run a Basic or Advanced screen.
person_identifiers_require_persondateOfBirth, citizenships or additionalIdentifiers are sent on a non-person subjectType.Submit them with "person", or leave them out.
invalid_citizenshipA citizenships value is not an ISO 3166-1 alpha-2 code.Resubmit with two-letter codes, for example "AU".
invalid_date_of_birthdateOfBirth is not ISO yyyy-MM-dd, or is in the future or before 1900.Submit the subject's real date of birth as an ISO date.
privacy_notice_requiredAn individual is screened without privacyNoticeAcknowledged: true.Show the collection notice and resubmit with the acknowledgement.
organizationName is requiredThe name is missing or blank.Send the person's name.

A 402 (insufficient credits or an exhausted per-key budget) is a billing failure, not a refusal: the request was valid but could not be paid for.

2. The response

The response is the v2 investigation envelope. The screen is the austrac_compliance module in modules[] (moduleId: "austrac_compliance", category: "compliance", displayOrder: 190, tier: "free"). Its status is one of listed, possible_match, found, not_found or inconclusive; its severity is derived by the same rules as every other module.

The module's data object:

FieldMeaning
sanctionsAuthorityThe list the DFAT determination is read from — always the DFAT Consolidated List.
dfatDeterminationlisted, not_listed, possible_match or inconclusive.
dfatDeterminationReasonWhy the determination is what it is.
dfatListUpdatedThe date the DFAT Consolidated List was last updated, for the CDD record.
subjectCitizenshipsThe screened person's citizenships.
dfatComparisonsPer-record DFAT comparison: recordId, name, recordBirthDates, recordNationalities, listedOn, lastUpdated, outcome.
foreignListingsForeign-regime listings only: authority, program, sourceUrl.
pepDeterminationnone, domestic, foreign or international_organisation.
pepPositionThe PEP office identified.
pepSourceUrlThe source that identifies the PEP.
pepCurrentOrFormercurrent or former.
foreignDobExclusionsSame-name foreign records excluded because their date of birth belongs to someone else.
pepDobExclusionsSame-name PEP records excluded on date of birth.
comparisonsEvery same-name record weighed, in the shared RecordComparison shape.
relativesAlways not_determinable on a public person screen.
reviewRequiredWhether the screen needs manual review (listed, possible_match, inconclusive, or a foreign/international-organisation PEP).
countryRiskMethodHow country risk is assessed (FATF lists + DFAT sanctions; the Basel AML Index is deliberately excluded).
countryRiskOne row per country of residence and citizenship: country, band, reason, callForAction.
riskFactorsThe A1 factors present: id, label, level.
indicativeRatinglow, medium or high, derived from the risk factors.
triggeredObligationsThe AML/CTF obligations triggered: id, label, citation.
adverseMediaThe bucketed adverse-media findings: profitGeneratingOffence, profitGenerating, minor, excluded, namesakes (each item label, url).
cddRecordWhat was screened, when, with which lists and sources, and what is not covered.

3. Mapping to AUSTRAC's Initial CDD form for an individual

The screen is organised to answer the items on AUSTRAC's Initial CDD form for an individual.

Form itemModule field(s) it answers
D1 — SanctionssanctionsAuthority, dfatDetermination, dfatDeterminationReason, dfatListUpdated, dfatComparisons, foreignListings, foreignDobExclusions, comparisons
D3 — PEPpepDetermination, pepPosition, pepSourceUrl, pepCurrentOrFormer, pepDobExclusions, relatives
A1 — Risk factorscountryRiskMethod, countryRisk, riskFactors, indicativeRating, triggeredObligations, adverseMedia
CDD recordcddRecord (screenedAt, inputs, lists, searchTerms, sourcesReviewed, notCovered)
DisambiguationsubjectCitizenships (feeds both D1 and D3), reviewRequired (flags the whole screen for review)

What the screen does not cover

cddRecord.notCovered names what remains the reporting entity's responsibility and is not part of this screen:

4. Sample response and sample report

A fictional sample is published alongside this guide and kept in sync with the live schema by the report-sample tests.

5. Data coverage

What this screen can find is bounded by the data the crawler ingests. The Screening Data Coverage Statement is the authoritative record of that; it is available on request from VerityRadar while its public host is prepared. The screen itself draws on three dated lists, recorded in cddRecord.lists: