Skip to content
Case studiesPricingSecurityCompareBlog

Europe

Americas

Oceania

Industry12 min read

Fake ASIC Company Extracts in KYB Onboarding

How fraudsters forge ASIC certificates of registration and company extracts to pass KYB checks in Australia, and how compliance teams detect and stop it.

CheckFile Team
CheckFile Teamยท
Illustration for Fake ASIC Company Extracts in KYB Onboarding โ€” Industry

Summarize this article with

A fake ASIC company extract is a certificate of registration or current company extract that has been edited, fabricated, or presented with a genuine Australian Company Number (ACN) but substituted details, to pass a KYB onboarding check. Because ASIC's register and the Australian Business Register are both searchable online, fraudsters can misrepresent a real filing more cheaply than they can forge a passport or bank statement. This is the fraud-detection companion to our guide on how to verify a company registration certificate online: that article covers the legitimate lookup process, this one covers how the document gets faked and caught.

This article is for informational purposes only and does not constitute legal, tax, or regulatory advice. Consult a solicitor or compliance professional for guidance specific to your organisation. Legislation and guidance referenced are current as of 25 July 2026.

What an ASIC Company Extract Proves โ€” and What It Does Not

A certificate of registration confirms that a company was legally formed on a specific date, under a specific name and Australian Company Number, but it says nothing about who currently runs the business. It is issued once, at incorporation, and never updated โ€” a genuine certificate from 2019 remains genuine even if the company has since changed directors three times, moved its registered office interstate, or entered external administration. KYB (Know Your Business) onboarding should treat the certificate as only a starting point: proof the entity was validly created, not proof it is still trading or controlled by the people a counterparty believes it is dealing with.

A current ASIC company extract is what matters for ongoing risk: it records the company's live status, registered office, current directors, share structure, and any external administration or deregistration action as it happens. A counterparty who presents only the original certificate, without a recently dated extract, is showing a snapshot from formation day rather than the company's current legal state โ€” that gap is where forged documents hide. The linked Australian Business Number (ABN) adds a second, independent data point: ABN Lookup shows whether the ABN and GST registration are still active, awkward to fake consistently across two registers.

Australia's Beneficial Ownership Reform Is Still Taking Shape

Unlike the United Kingdom, which brought mandatory director and PSC identity verification into force through the Economic Crime and Corporate Transparency Act 2023, Australia has no equivalent register yet. Treasury's consultation dates back to November 2022, with updated policy specifications released in December 2024, and the 2025-26 Budget allocated $207 million to stabilise ASIC's ageing companies register โ€” a precondition for integrating beneficial ownership data into it. Government signalling points to a centralised register aligned with ASIC, but full stakeholder consultation on the design is not expected until early 2027 (Treasury Ministers, Improving transparency of the true owners of companies).

This means Australian KYB teams cannot yet rely on a statutory beneficial ownership register the way UK teams increasingly can. Verifying who controls a counterparty still depends on cross-referencing the ASIC officeholder record, share structure on a current extract, and direct enquiry โ€” precisely why register cross-checking matters more here, not less.

How Fraudsters Actually Forge These Documents

Editing a genuine downloaded PDF is the most common method, because ASIC extracts, once purchased, are unwatermarked PDFs like any other. A fraudster buys or reuses a real extract, opens it in a PDF editor, and changes the registered office, director names, or extract date before presenting it as current, relying on the reviewer not cross-checking the live register.

Fabricating a document from scratch is less common but still occurs, usually where the target is a one-off visual check rather than a determined verifier. This means recreating ASIC's extract layout in a design tool or, increasingly, using generative AI to produce a convincing image-based extract with a fabricated ACN that either does not exist or belongs to an unrelated entity.

Corporate identity theft is the more dangerous variant: using a real, active company's genuine ACN and name, but substituting the director names, registered office, or share structure on the document presented. Because the ACN checks out on a cursory glance, this survives a reviewer who confirms "yes, that company exists" without comparing every field against the live extract โ€” the same weakness ASIC has flagged when investigating company details lodged against addresses the occupants never authorised.

A fourth pattern is a stale extract that quietly omits a recent deregistration, appointment of an external administrator (voluntary administration, receivership, or liquidation), or overdue annual review. The certificate and early filings are entirely genuine; missing is the most recent entry showing the company is no longer active, is being wound up, or has lapsed into non-compliance under the Corporations Act 2001 (Cth).

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.

Request a free pilot

Real Fraud Schemes This Enables

Invoice fraud and CEO fraud frequently start with a forged registration document used to impersonate a real, trusted supplier, redirecting payment to an account the fraudster controls while the ACN and business name look legitimate on paper. Construction sees fraudulent subcontractor onboarding constantly, where a forged or borrowed extract lets a non-compliant or uninsured subcontractor pass a head contractor's paperwork check before work begins.

Phoenixing is the Australian-specific fraud pattern that dominates this space. A company deliberately accumulates debts โ€” unpaid suppliers, superannuation, PAYG withholding, entitlements โ€” then is liquidated or abandoned to avoid paying them, while a near-identical new entity, often sharing directors, premises, and a similar trading name, is registered to continue unencumbered. ASIC estimates illegal phoenix activity costs employees $31-298 million a year in unpaid entitlements and costs government around $1.66 billion a year in unpaid tax (ASIC, Combating illegal phoenix activity). A KYB check sees only the new entity's clean certificate unless someone checks the directors' history. Synthetic company setups for money laundering similarly pair a lightly-altered registration document with fabricated financial statements, echoing our analysis of fake financial statements in business lending fraud. The registration document is rarely the fraud itself โ€” it is the credential that gets the fraudster past the door.

Detection Techniques That Actually Work

The single most effective control is cross-checking the ACN directly on ASIC Connect rather than trusting the PDF a counterparty has sent. Searching the ASIC company and organisation register takes under a minute and shows whether the company is registered, deregistered, or under external administration โ€” any mismatch with the document is the clearest sign of tampering. Cross-checking the linked ABN on ABN Lookup adds an independent second source: a cancelled ABN or lapsed GST registration, while the extract implies active trading, is a strong red flag on its own.

Requesting a recently dated extract, rather than accepting whatever PDF is on file, closes the stale-document gap โ€” an extract ordered in the last few days cannot omit a deregistration or external administration event from last month. ASIC also requires insolvency notices published on the Published Notices Website, a useful cross-check when a counterparty's history is unclear. PDF metadata is a second layer: creation software and modification timestamps can reveal a "2021 certificate" was actually last saved in an image editor weeks ago.

Red flag Verification method What it reveals
ACN matches, but director or officeholder names differ from the document Search the ACN on ASIC Connect Corporate identity theft โ€” real entity, fabricated control details
ABN shows cancelled or GST registration lapsed while the extract implies active trading Cross-check the ABN on ABN Lookup Entity may no longer be genuinely trading despite a clean-looking certificate
Extract presented as current for a deregistered or externally administered company Check current status on the ASIC register and the Published Notices Website Stale extract concealing deregistration, liquidation, or receivership
New entity with the same directors, premises, or trading name as a recently liquidated company Search the directors' names on ASIC Connect for prior directorships Possible phoenix arrangement avoiding a predecessor's debts
PDF creation date inconsistent with claimed extract date Inspect file metadata (creation software, save history) Document edited or fabricated after the date it claims to represent
Layout, header, or wording differs from the genuine ASIC extract template Compare against an extract ordered directly from ASIC Connect Wholesale fabrication rather than an edited genuine document

What Compliance Teams Are Actually Asking

Compliance and fintech practitioners on Australian industry forums often ask how to tell a slightly outdated but genuine certificate from a deliberately manipulated one. The distinguishing factor is not the age of the certificate โ€” static by design โ€” but whether the current register entry matches what the counterparty claims today; an old certificate paired with a consistent extract is normal, one paired with a contradicting extract is not.

A second recurring question is whether new-entity red flags โ€” registration within the last twelve months, run by directors who also sat on a recently liquidated business in the same industry โ€” are enough to reject a counterparty outright. One flag should trigger a director-history search on ASIC Connect, but two or more overlapping indicators, especially matching premises or trading names alongside common directors, is grounds most compliance teams treat as pausing the relationship, given how squarely that matches known phoenix activity.

Presenting a forged or manipulated ASIC extract to induce a business decision can constitute obtaining a financial advantage by deception under Divisions 134 and 135 of the Criminal Code Act 1995 (Cth), while a physically altered or fabricated document falls under the forgery offences in Divisions 144 and 145 of the same Code, both carrying up to ten years' imprisonment. Delivering a false document to ASIC is a separate offence under section 1308 of the Corporations Act 2001 (Cth). Phoenixing is targeted by the creditor-defeating disposition provisions the 2020 anti-phoenixing reforms inserted into the Corporations Act, imposing a duty on officers to prevent asset transfers that defeat creditors' recovery, backed by up to fifteen years' imprisonment for the most serious contraventions (ASIC, Combating illegal phoenix activity).

For regulated businesses, scrutinising business documentation as part of KYB sits within the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), which requires reporting entities supervised by AUSTRAC to conduct customer due diligence proportionate to risk, including verifying a corporate customer's identity and controlling persons before providing a designated service (AUSTRAC, Overview of customer due diligence). A reporting entity onboarding on an unchecked, forged extract risks its own compliance position under the AML/CTF Act, and proceeds of the fraud remain subject to restraint under the Proceeds of Crime Act 2002 (Cth).

A Layered Approach to Detection

Manual detection methods, including routine visual review of documents, catch only around 37% of occupational fraud cases, with a median delay of 87 days before detection (ACFE, 2024 Report to the Nations). That gap exists because a well-edited PDF passes a five-second glance every time; it only fails when checked against an independent source, which is why ASIC and ABN Lookup cross-checking has to be a standing step in onboarding, not a discretionary one applied only when something already looks wrong.

CheckFile's approach layers structural analysis, metadata checks, and cross-document validation, built to cover 3,200+ document types and 32 jurisdictions. CheckFile also deploys an AI-generation detection layer as a complementary signal, not a replacement for cross-checking the official register. A forged ASIC extract still has to be checked against ASIC Connect and ABN Lookup to confirm the company's actual status, directors, and ABN standing โ€” no document-level analysis alone substitutes for that step.

For teams refining a full KYB workflow, our complete guide to business entity verification covers the wider process, and our industry verification guide sets out sector-specific checks across financing, construction, and regulated services. CheckFile's platform is also used in equipment financing and leasing, where forged registration documents paired with fabricated financials recur โ€” see our security page, pricing, and homepage for more.

If your onboarding process still relies on a visual read of a PDF a counterparty has sent, CheckFile's AI-generated document detection adds AI-generation signals as a complement to your existing controls โ€” not a guarantee of catching every forgery, but a useful layer alongside ASIC and ABN Lookup cross-checks.

Frequently Asked Questions

Can a fake ASIC extract use a real Australian Company Number?

Yes โ€” this is corporate identity theft. The ACN and company name are genuine and pass a superficial check, but the director names, registered office, or share structure have been substituted. Catching it means comparing every field against a current extract from ASIC Connect, not just confirming the ACN exists.

Does Australia have an identity verification requirement for directors like the UK's?

Not yet. Directors need a Director Identification Number (DIN) before appointment, but Australia has no equivalent to the UK's 2025 mandatory ongoing director and PSC verification regime. A public beneficial ownership register has been in Treasury consultation since 2022, with full stakeholder consultation not expected until early 2027.

What is the fastest way to check if an ASIC extract is genuine?

Search the ACN on ASIC Connect and compare the name, status, registered office, and officeholders against the document, then cross-check the linked ABN on ABN Lookup. This takes minutes and beats any visual inspection of the PDF.

What is phoenixing and why does it matter for KYB checks?

Phoenixing is when a company is deliberately liquidated to avoid paying its debts, taxes, or employee entitlements, and a near-identical new entity โ€” often sharing directors, premises, or a similar trading name โ€” is registered to continue unencumbered. A KYB check that only looks at the new entity's clean certificate will miss this; searching directors' names for prior directorships on ASIC Connect surfaces it.

Is presenting a forged ASIC extract a criminal offence in Australia?

Yes. Using a forged or manipulated extract to induce a business decision can fall under the forgery and dishonesty offences in the Criminal Code Act 1995 (Cth), carrying up to ten years' imprisonment. Delivering false information to ASIC is a separate offence under section 1308 of the Corporations Act 2001 (Cth), and phoenixing carries up to fifteen years' imprisonment under the Act's anti-phoenixing provisions.

Stay informed

Get our compliance insights and practical guides delivered to your inbox.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.