The standard
Thirteen rules
These thirteen rules define how a PROOF form should be completed, certified and used. They are intentionally simple: the aim is to keep every PROOF record consistent, clear and reliable without dictating the underlying compliance decision.
- 01
Pick one core form
Use PROOF One-Time where the matter is assessed once. Use PROOF Ongoing where the relationship continues and requires future review.
The details may vary, but the choice of core form does not.
- 02
Complete PROOF Entity for every relevant entity or trust
PROOF Entity is an additional form used whenever a party is an entity or trust. It records who owns and controls that entity, including the ownership chain where relevant.
Complete a separate PROOF Entity form for each entity or trust, and use it alongside either PROOF One-Time or PROOF Ongoing.
- 03
The certification is fixed
Part 6 contains the standard PROOF certification and must not be changed.
If a recipient requires additional wording, conditions or representations, these should be added separately rather than altering the PROOF form.
Once the certification is changed, it is no longer a standard PROOF form.
- 04
Enter the data
Outside the fixed certification, the form is a record of facts, evidence and conclusions.
Complete every applicable field. If something does not apply, say why. A blank field leaves the record incomplete.
- 05
“Not required” needs a reason
If you considered a report, check or piece of evidence and decided it was not required, record the reason.
“Not required” means a decision was made. A blank field does not. The record should make that distinction clear.
- 06
Screen first, decide after
Screening must be completed before the decision. The record should clearly show:
- When the screening was completed
- What was checked
- Which provider was used
- The result
- The date of the decision
- 07
Explain every cleared match
Screening matches are common. What matters is how they are resolved. For every match, record:
- What matched
- Who reviewed it
- When it was reviewed
- The outcome
- Why that outcome was reached
A match marked “cleared” without a reason is not a complete record.
- 08
Keep the evidence
PROOF can reference supporting documents without requiring every document to be sent to every recipient. The Certifying Party remains responsible for retaining the evidence it relied on.
This keeps the record auditable without unnecessarily circulating sensitive documents.
- 09
Name who is signing
Every PROOF record must identify the person signing and the organisation they represent.
By signing, they confirm that they are authorised to certify the record on that organisation’s behalf.
- 10
Define who can rely on it, and for how long
A PROOF record should clearly state who it is delivered to and how long it may be relied on. Reliance should end when the earliest relevant limit is reached, such as:
- The effective date for a one-time matter
- The next review date
- The end of the permitted reliance period
- Notice that the information has changed
A PROOF record should never create unlimited reliance for unidentified parties.
- 11
The recipient still makes the decision
PROOF records the diligence that was carried out. It does not transfer responsibility for the decision. The recipient must still decide:
- Whether the information is sufficient
- Whether further diligence is required
- Whether the risk is acceptable
- Whether the relationship or transaction should proceed
The certification supports the decision. It does not replace it.
- 12
Keep it current
If material information changes, update the record and notify anyone relying on it.
For ongoing relationships, refresh PROOF at each review or sooner if something material changes.
- 13
Keep PROOF standard
PROOF only works if everyone uses the same form.
If a recipient needs something extra, add it separately. Do not rewrite the PROOF certification. Change the certification, and it is no longer PROOF.