Fake ASIC Company Extracts: Detecting KYB Fraud in Australia
How fraudsters forge Australian company constitutions and ASIC extracts to pass KYB checks, and how compliance teams detect and stop it before onboarding.

Summarize this article with
A fake company constitution or ASIC extract is a fabricated, tampered, or fraudulently obtained version of the documents an Australian counterparty relies on to prove who controls a company โ its constitution, or the replaceable rules it defaults to under the Corporations Act 2001, and the ASIC extract that banks, equipment lessors, and vendor risk teams pull to confirm officeholders and status. Because Australia does not require every company to file or publicly disclose a full constitution, fraudsters increasingly target the extract itself, presenting a manipulated or lookalike version to pass a KYB (Know Your Business) check.
This article is provided for informational purposes only and does not constitute legal, financial, or regulatory advice. Regulatory references are accurate as of the publication date. Consult a qualified professional for guidance specific to your situation.
Why the Constitution โ and the ASIC Extract โ Are High-Value Fraud Targets
Under section 134 of the Corporations Act 2001 (Cth), a company's internal management is governed by the replaceable rules in the Act itself, by a constitution it adopts, or by a combination of both. This is a genuine structural difference from jurisdictions where every company files a constitutional document at formation: many Australian proprietary companies never adopt one at all, relying on default replaceable rules for director appointment, share transfers, and meetings, with no governance page ever lodged with ASIC. Where a company does adopt a constitution, section 136 requires the special resolution to be lodged, but the document itself is not always retrievable in full through a standard public search.
That gap is precisely why the ASIC extract, not the constitution, is the more common attack surface in Australian KYB fraud: it is the document most onboarding teams actually pull, drawn from a register that held more than 3.5 million active companies as of 2024 (LegalVision, How Do I Obtain an ASIC Company Extract?). A convincing fake, or a genuine extract obtained against a fraudulent change, misrepresents who a bank, lessor, or supplier believes is authorised to sign.
The Director ID Reform Narrowed One Fraud Path, Not All of Them
Since 1 November 2021, the Corporations Act has required every company director to hold a director identification number (director ID), issued by the Australian Business Registry Services and verified through myGovID, with the final transitional cohort required to comply by 30 November 2022 (ASIC, New ID requirement for directors). This closes the loophole of appointing a wholly fabricated person as director, since every director is now traceable to a verified identity across every company they hold โ but it does not stop forgery of documents for a company that already exists, or a fraudulent lodgement against a real director ID obtained by impersonation. A fraudster who cannot invent a director can still take a genuine company's real extract and misrepresent who controls it, which is why independent verification remains necessary regardless.
Four Ways Fraudsters Fake These Documents
Fabrication From Scratch
A fraudster with no genuine document to start from recreates the ASIC extract layout โ name, ACN, registered office, officeholder table, share structure โ in a design tool, inventing an Australian Company Number that either does not exist or belongs to an unrelated entity. This is the crudest method and easiest to catch, since it fails the moment anyone searches the fabricated ACN, but it still passes reviewers who accept a document that "looks official" without checking the source.
Registry-Level Identity Hijack
This variant is more dangerous because the resulting extract is entirely genuine. A fraudster lodges a fraudulent Form 484 change of company details โ a new officeholder, a changed registered address, or an amended share structure โ against a real, active company, waits for ASIC to process it, then pulls the now-updated but illegitimately altered extract as if legitimate. ASIC does not independently verify the truth of every change at the point of submission, which is the structural gap this fraud exploits; ASIC's own alerts about correspondence mimicking its branding show how routinely fraudsters trade on the register's credibility (ASIC, Warning: websites displaying fake ASIC endorsements).
Partial Field Tampering on a Real Document
A genuine extract, purchased cheaply through ASIC Connect, is edited to change one or two fields โ an officeholder name, the registered office, or the share structure โ while the ACN is left untouched. This survives a reviewer who confirms the company number resolves but never compares every field against the live register entry.
Full Generative-AI Synthesis
Document-generation models can now produce a complete, plausible ASIC extract or constitution from a short prompt, matching ASIC typography and layout without touching a real filing. The output typically carries a fabricated ACN and invented officeholder names with no counterpart on the register โ but because the formatting is convincing, it defeats a purely visual check as effectively as a tampered genuine document, and more efficiently, since no source document is needed to start from.
Ready to automate your checks?
Free pilot with your own documents. Results in 48h.
Request a free pilotWhat This Fraud Enables
A forged or hijacked extract is rarely the fraud itself โ it is the credential that gets a fraudster through a door that would otherwise stay shut:
- Shell companies for money laundering. A plausible extract and clean-seeming change history clear an initial KYB threshold, after which the entity moves funds through accounts that appear legitimate on paper.
- Supplier and vendor impersonation. A forged or tampered extract lets a fraudster present as a trusted supplier's representative and redirect payment. Payment redirection scams cost Australian businesses $166.8 million in 2025, the second-largest scam category by loss after investment fraud (ACCC, Continued action critical to combat fraud as annual scam losses exceed $2 billion).
- Equipment financing and leasing fraud. Lessors relying on an extract to confirm signing authority before releasing high-value equipment are exposed when the named officeholder is fabricated or substituted โ a pattern that recurs in equipment financing and leasing onboarding.
- Hostile business bank account takeover. A registry-level hijack that changes the officeholder on file can convince a bank that new signatories have authority over an existing account, particularly where bank KYC onboarding relies on the extract rather than an independent identity check.
Detecting Fake Constitutions and ASIC Extracts
The single most effective control is pulling a fresh extract from ASIC's company and organisation registers and comparing every material field โ ACN, officeholders, registered office, share structure โ against the document received, rather than trusting a PDF a counterparty has sent. This catches fabrication, tampering, and most AI-synthesised documents, since none can produce a matching entry unless the lodgement was itself fraudulent.
Change history review is the second layer: a registry-level hijack leaves a trace, such as an unusual officeholder change filed shortly before the document was presented. PDF metadata โ creation software, author field, last-modified timestamp โ can reveal an extract dated months ago was edited weeks ago. For AI-generated documents, look for an ACN with no register match, inconsistent typography against a genuine template, and missing authentication elements.
| Fraud method | Primary red flag | How to verify |
|---|---|---|
| Fabrication from scratch | ACN does not resolve, or resolves to an unrelated entity | Search the ACN on ASIC's live company register |
| Registry-level identity hijack | Recent, unexplained officeholder or address change just before the document was presented | Pull the current extract and compare change dates |
| Partial field tampering | One field (officeholder, address, share structure) mismatches the register while the ACN checks out | Compare every field individually, not just the ACN |
| Full generative-AI synthesis | Typography or layout subtly differs from a genuine ASIC template; no matching register entry | Purchase a fresh extract directly through ASIC Connect for comparison |
| Any method | PDF creation or modification date inconsistent with the claimed extract date | Inspect file metadata (creation software, save history) |
Legal Framework and Liability
Lodging a document with ASIC known to be false or misleading is a criminal offence under section 1308 of the Corporations Act 2001 (Cth); ASIC has prosecuted directors under this provision (ASIC, Company director convicted for making a false statement to ASIC). Presenting a forged extract to induce a business decision separately exposes the fraudster to fraud offences under state and territory criminal law.
For regulated businesses, customer due diligence sits within the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, enforced by AUSTRAC, requiring verification of a corporate customer's structure and beneficial owners proportionate to risk. From 1 July 2026 these obligations extend to "tranche 2" entities โ lawyers, accountants, real estate professionals, and trust and company service providers โ who must enrol with AUSTRAC and run the same checks banks already perform (AUSTRAC, Newly regulated businesses: get ready for the reforms). Reporting entities must also observe the Australian Privacy Principles under the Privacy Act 1988, per OAIC guidance for AML/CTF reporting entities. A business onboarding on an unchecked, forged extract does not just carry the underlying fraud exposure โ it risks its own position under this regime.
A Layered Approach to Detection
Manual document review catches only around 37% of occupational fraud cases, with a median detection delay of 87 days, which is why a single visual pass on a company extract is not a sufficient control on its own (ACFE, 2024 Report to the Nations). CheckFile's approach combines structural checks, metadata analysis, and cross-validation against official registries as one layer among several, not a replacement for a live ASIC search. That includes an AI-generation detection layer deployed as a complementary signal, not a standalone verdict โ a hijacked lodgement that is technically genuine still needs a change-history and outreach check no document-level analysis alone can replace.
For teams building a full onboarding workflow, our complete guide to business entity verification covers the wider process, and our industry verification guide breaks down sector checks across financing, construction, and regulated services. This is the companion piece to our analysis of forged certificates of incorporation, covering the formation document rather than officeholder data. See CheckFile's security page, pricing, and homepage for more.
If your review process still relies on a visual read of a PDF a counterparty has sent, CheckFile's AI-generated document detection adds AI-generation signals as a complement to your existing controls โ not a guarantee of catching every forgery, but a meaningful layer alongside register cross-checks and change-history review.
Frequently Asked Questions
Can a genuine ASIC extract still be fraudulent?
Yes, when it results from a registry-level identity hijack โ a fraudulent officeholder or address change lodged against a real company. The extract is technically authentic, so catching this means reviewing the change history for unexplained recent updates, not just checking the extract looks correct.
What is the fastest way to check if an ASIC extract is genuine?
Purchase a fresh extract through ASIC Connect and compare every material field โ ACN, officeholders, registered office, share structure โ against the document received. This takes only a few minutes and catches fabricated, tampered, and most AI-generated documents.
Do all Australian companies have a written constitution?
No. Many proprietary companies rely entirely on the replaceable rules in the Corporations Act 2001 rather than adopting a written constitution, and where one exists it is not always fully retrievable through a standard search. This makes the ASIC extract, not the constitution, the document most KYB checks rely on.
Does the director ID requirement stop this fraud?
It reduces one risk โ appointing a wholly fabricated person as director โ but not fraudulent lodgements against existing companies or document-level tampering. Independent register checks and change-history review remain necessary regardless of a director's verified ID.
Is presenting a forged ASIC extract a criminal offence in Australia?
Yes. Lodging a document with ASIC known to be false or misleading is an offence under section 1308 of the Corporations Act 2001 (Cth), and using a forged document to induce a business decision separately exposes the fraudster to fraud offences under state and territory law.
Stay informed
Get our compliance insights and practical guides delivered to your inbox.