Custarra is in closed beta testing and currently closed to new sign-ups — email info@custarra.com.au for more information.

How it works

Customer due diligence, step by step

From one SMS link to a filed CDD record — here is the whole journey, exactly as your customer and your team experience it.

The full picture

One guided flow, two points of view

The top lane is you; the bottom lane is your customer — meet Sarah, your buyer. She does the work in one sitting on her phone; Custarra runs the checks; you get the record.

Your agencywith Custarra
Sarahyour buyer

You

generate an SMS link
using Custarra

Risk assessment

scored from her answers
LOWMEDHIGH

ID verified

ID documents
KYC1
independently verified ✓
Automated Custarra IDV check

AML screening

PEP2clear ✓
Sanctions · DFATclear ✓
Automated Custarra AML check

Done

LOW RISK
CDD3 record filed
audit trail complete

SMS link

arrives on her phone
no app · no signup

Onboarding form

her details + declarations
consent gathered

ID check

scans ID + selfie
same link · one sitting
1KYC — Know Your Customer 2PEP — Politically Exposed Person 3CDD — Customer Due Diligence
scroll →

Your client does the work — send them a secure link and they complete onboarding themselves, no forms, no back-and-forth. You get the record.

Every step, in detail

What actually happens at each stage of the flow above — and what it means for your obligations under the AML/CTF Act.

  1. You generate a secure SMS link

    Onboarding starts in Custarra: pick the customer, and the platform generates a secure, single-purpose link and sends it by SMS. There are no forms to prepare and nothing to chase — the link carries everything the flow needs, tailored to your sector and your program.

  2. The link arrives on her phone

    Sarah gets a text. No app to install, no account to create, no password — she taps the link and is straight into onboarding, on the device she already has in her hand.

  3. She completes the onboarding form

    The form gathers her details and the declarations your program requires, and records her consent to electronic verification — a condition of verifying someone against official data sources. Everything she enters lands in the CDD record.

  4. Custarra scores the risk

    Her answers are scored against the risk assessment in your AML/CTF program, and she comes out low, medium or high risk. The rating decides how much checking follows — that is the risk-based approach the Act asks for. Custarra recommends; the decision stays yours.

  5. She verifies her ID in the same sitting

    Still on the same link, Sarah photographs her ID and takes a live selfie. One sitting, no follow-up emails — by the time she puts her phone down, her part is done.

  6. Her identity is verified independently

    Custarra verifies her documents and runs the KYC check against trusted, independent Australian data sources — the same verification technology large financial institutions rely on. You never handle her documents, and the result is recorded with evidence.

  7. AML screening runs automatically

    She is screened for politically exposed persons and against Australian and global sanctions lists, including the DFAT Consolidated List. Higher-risk customers get more — adverse media screening and biometric proof are added when the risk rating calls for them, and skipped (and recorded as such) when it does not.

  8. Done — the CDD record is filed

    Every answer, check result and decision is filed as one CDD record with a complete audit trail, kept for seven years and exportable. If AUSTRAC or an independent auditor asks how you verified Sarah, the answer is one click, not a hunt through shared drives.

See it with your own customers

Start a free trial and run your first customer through the flow today.