Risk & Compliance
Last updated: 28 July 2026
How we think about risk
Senly ID operates in a regulated, high-trust space. We take a risk-based approach: we identify the ways things can go wrong for the people and businesses who rely on us, put controls in place proportionate to each risk, and review them as the platform and the regulatory landscape change. The main risk areas are set out below.
1. Regulatory risk: AML/CTF and identity
Senly ID supports businesses with their customer due diligence, including identity (KYC), business (KYB) and AML/sanctions/PEP screening. Senly provides evidence that a verification occurred; it does not discharge a business’s own obligations under the AML/CTF Act. The business remains the reporting entity responsible for its own customer due diligence, record-keeping and any suspicious-matter reporting. We design our checks and evidence records to align with AUSTRAC requirements, including the seven-year retention of verification evidence.
Ongoing monitoring. Every AML check includes ongoing monitoring, and we take a risk-based, event-driven approach consistent with AUSTRAC’s ongoing customer due diligence guidance. Rather than re-screening on a fixed daily cycle, we re-screen when sanctions, politically-exposed-person or watchlist sources change, and we monitor both the business entity and its key people (its beneficial owners and controllers). A material change, such as a change in ownership or control, should prompt the business to run a fresh check. AUSTRAC does not mandate a fixed monitoring interval; it requires a documented, risk-based approach, which this reflects.
2. Fraud and impersonation risk
Identity fraud is the core threat we defend against. Verifications include presentation-attack detection (liveness) independently tested to iBeta Level 1 (ISO/IEC 30107-3), document authenticity checks, and, for Australian documents, matching against the official Document Verification Service. Signed, tamper-evident results mean a verification cannot be silently altered after the fact, and a superseded result can be revoked.
3. Privacy and data-protection risk
We handle sensitive personal information under the Privacy Act 1988 and the Australian Privacy Principles. We reduce this risk by collecting only what a check requires, deleting raw identity documents after processing, encrypting sensitive data at rest, enforcing strict access controls, and giving individuals control over their own vault copy and what they disclose. See our Privacy Policy and Information Security pages.
4. Data-breach risk
We maintain a response process aligned to the Australian Notifiable Data Breaches scheme. We contain and assess the breach and, where an eligible breach is likely to cause serious harm, notify affected individuals and the OAIC, then remediate to prevent recurrence.
5. Vendor and supply-chain risk
We rely on a small number of specialist providers (identity verification, cloud infrastructure, payments). We select providers with recognised independent certifications (including SOC 2, ISO/IEC 27001 and government-approved gateway status for Australian document checks) and bind them with appropriate data-processing terms. Our own software dependencies are version-pinned and security-audited before release, and we do not adopt new versions without review.
6. Operational and availability risk
Verification results can be time-sensitive for the businesses that receive them. We run on managed Australian cloud infrastructure with automated health checks that roll back a release that does not start cleanly, controlled database migrations, and monitoring, so that a change cannot quietly take the service down.
7. Consumer-protection risk
Our billing is pay-as-you-go with no lock-in, prices are shown GST-inclusive, and nothing in our terms limits rights that cannot be excluded under the Australian Consumer Law. Where a person is declined and eligible, we offer a review/appeal path.
Governance and review
These controls are owned by Senly management and reviewed periodically and when circumstances change (new features, new regulation, or a material incident).