Australian additional identifier inventory: evidence and recommendations
Evidence cut-off: 3 October 2026 (Australia/Sydney)
Scope: identifiers proposed as additions to Groundskeeper
Machine-readable record: data/australian-additional-identifiers.json
Method and evidence rule
This review uses Australian Government, state/territory government, regulator, issuer, or standards-body sources. A format is recorded only when one of those sources publishes it. Examples seen in search results, cards, or third-party guidance were not generalized into formats. null in the inventory therefore means not authoritatively published in the sources reviewed, not that the identifier does not exist.
The inventory separates:
include: sufficiently distinctive syntax and/or a checksum for a generic detector;context_only: useful only beside an issuer-specific label or in a structured field;exclude: no safe generic detector (variable/private format, obsolete, or not an Australian identifier class).
Syntax and checksums establish plausibility, not issuance or current status. Where an official register or service exists, it is the authoritative validation method.
Recommended additions
| Taxonomy ID | Decision | Published format | Validation | Required context |
|---|---|---|---|---|
au.health.hpi_i | Include | 16 digits, prefix 800361 | Luhn, then HI Service | Word boundaries; preserve leading digits |
au.health.hpi_o | Include | 16 digits, prefix 800362 | Luhn, then HI Service | Word boundaries; preserve leading digits |
au.services.centrelink_crn | Include | 9 digits + letter | Services Australia only; no public checksum found | Prefer CRN/Centrelink; bare form has moderate FP risk |
au.immigration.immicard | Include | 3 letters + 6 digits | Home Affairs/VEVO | Require ImmiCard, AMS, or EIS context; do not assume those are the only prefixes |
au.education.usi | Include | 10 chars from A-HJ-NP-Z2-9; not all digits | USI Registry verification | Prefer USI/education context; syntax alone still collides with tokens |
global.vehicle.vin | Include (global taxonomy) | 17 uppercase alphanumerics excluding I/O/Q; official Australian guidance says last 3 are digits | NEVDIS/RAV; no universal Australian checksum published | Vehicle/VIN context strongly recommended |
au.children.nsw_wwcc | Context-only | Begins WWC; complete length/grammar unpublished | NSW OCG online verification | Require WWCC, Working with Children, or WWC prefix |
au.education.vic_vsn | Context-only | 9 digits | Victorian Student Register/VCAA | Require VSN or full label |
au.immigration.visa_grant_number | Context-only | 13 characters (source does not constrain character class) | VEVO | Require exact label |
au.immigration.citizenship_certificate | Context-only | Multiple certificate-era fields; no current unified syntax published | Home Affairs/DVS | Require exact certificate field label |
The complete inventory includes all requested categories and jurisdictions. The table above is intentionally limited to entries that can support implementation work now.
Decisions by requested area
Health, veterans and professional registration
- DVA file/Veteran Card number: include only as context-bound data. HL7 Australia AU Base v6.0.0 publishes a maximum length of 9 and an example, but not a complete grammar or checksum. DVA/Services Australia lookup is authoritative. Do not turn the example into a regex.
- HPI-I/HPI-O: include. The published profiles specify 16 digits, prefixes
800361and800362, and Luhn. A successful Luhn check is not proof that the HI Service issued the number. - Ahpra registration number: context-only. The public register validates a registration number and Ahpra says it remains with a practitioner for life, but Ahpra does not publish a complete syntax/checksum. It is public professional-register information, while still identifying a person.
Worker and child-safety screening
- NDIS worker screening: retain eight jurisdiction-specific taxonomy entries. The NDIS Commission confirms state/territory issuance, national portability, and database validation. It does not publish a national Worker Screening ID grammar. A 2026 Commission guide states that an Application ID is eight digits; that must not be mislabelled as a Worker Screening ID. NT separately publishes the application reference example
7-NDISXXXXXX, which is an application reference, not clearance proof. - WWCC/WWVP: retain eight jurisdiction-specific entries. Names, cards, application references, and verification mechanisms differ. NSW officially says a clearance begins
WWC, but does not publish the remainder. No other complete current syntax was found in authoritative material reviewed. All require jurisdiction + scheme-label context and issuer verification.
Police, immigration and social services
- Police checks: exclude a generic reference detector. AFP, state/territory police, and ACIC-accredited bodies issue separate references. AFP offers status/certificate validation and QR security, but no common syntax is published. A police check is also point-in-time and purpose-specific.
- Visa grant / ImmiCard / citizenship: Home Affairs publishes 13 characters for Visa Grant Number and exactly three letters plus six digits for ImmiCard. Only ImmiCard is distinctive enough for inclusion, and still needs label/prefix context. Citizenship certificates span document generations and field names; no unified syntax was published.
- Centrelink CAN vs CRN: these are not synonyms. CRN is the durable record identifier and is officially 9 digits plus a letter. CAN is a phone self-service access credential used with a PIN; no current syntax was found. Detect CRN; do not detect CAN generically.
- Child Support, My Aged Care, PRODA/RAM: the services use customer/reference/account identifiers but publish no stable generic syntax in the reviewed current material. These should be context-only fields. PRODA is also being replaced by Digital ID/myID + RAM in some service journeys; RAM authorisation and machine-credential artefacts are credentials, not public identifiers.
- NDIA/NDIS provider registration: registered provider status is publicly searchable primarily by name/ABN. The Commission does not publish a safe registration-number grammar in its public register. Use ABN plus Provider Register lookup, not a new generic number detector.
Education and superannuation
- USI: include with the official 10-character alphabet. Authoritative verification is the USI Registry; the public WSDL constrains syntax but does not expose a locally usable checksum algorithm.
- CHESSN: mark obsolete/decommissioning. StudyAssist says decommissioning began in 2021 and USI is now primary. Preserve only for historical labelled data.
- State student IDs: no national detector. Victoria alone clearly publishes VSN as a random 9-digit number. NSW, Queensland, WA, SA and Tasmania are retained as context-only because their reviewed official pages confirm issuer-specific identifiers but do not publish complete syntax. ACT and NT are excluded/unverified because no single territory-wide identifier and format was found; NT students may separately receive a SACE registration number for NTCET.
- Super member/account numbers: fund-assigned and private; no common syntax. ATO says an account is identified by fund ABN + super-product USI + member account number. Do not confuse a member number with the public organizational Unique Superannuation Identifier, whose format may be a SPIN or ABN plus three digits.
Cards, transport, property, weapons, maritime and aviation
- Proof-of-age/photo cards, vehicle registrations, firearms licences, marine licences, property titles: all are jurisdiction-variable. Use jurisdiction and exact document label; do not create Australia-wide bare-value detectors. WA publishes a property-title machine representation, but that is not portable to other land registries.
- VIN: suitable for a global detector with vehicle context. Australia publishes the 17-character alphabet and NEVDIS/RAV validation. Older vehicles/chassis numbers are exceptions. No universal Australian checksum rule was found.
- AMSA/CASA: AMSA certificate number + Seafarer ID + password/QR can be authoritatively checked, but syntax is unpublished. CASA ARN is the core individual/organisation reference (and an individual's flight-crew licence number), but CASA does not publish a current length/grammar. Both are context-only.
Financial, commercial and crypto identifiers
- AFSL/credit/authorised-representative numbers: public organizational/professional identifiers and searchable in ASIC's Professional Registers, but ASIC does not publish a complete numeric grammar or checksum. Detect only with explicit
AFSL,AFS licence,Australian credit licence, orauthorised representativecontext, then verify against ASIC. - Insurance policy, loan, claim, customer/account numbers: issuers define these. APRA reporting standards call policy numbers free text and claim/policy IDs issuer-unique; there is no cross-industry syntax. They can identify a person and financial relationship. Generic detectors are unsuitable; use tenant/issuer-configured labelled-field rules.
- Crypto wallet addresses: not an Australian identifier and formats/checksums differ by network. Addresses are public/pseudonymous but can become personal information when linked to a person. Implement network-specific global detectors, never one
AU crypto walletregex; validate using the relevant network and, where appropriate, a blockchain explorer.
Privacy and licensing
“Public” means the identifier is intentionally published in an official register (for example ASIC licences), not that all associated data is unrestricted. “Personal” follows the OAIC's contextual test: information that identifies or reasonably identifies an individual. Health, welfare, immigration, child-safety, police, education, financial-account and screening identifiers should be handled as personal; police/health/disability context may also reveal sensitive information.
The inventory records source-level reuse constraints. Most Commonwealth and state web facts can be cited; many pages are CC BY 4.0, but logos, coats of arms, trademarks, images and third-party material are excluded. Services Australia expressly requires attribution. HL7 Australia AU Base is CC0 but protects HL7/FHIR marks and excludes third-party IP. ISO standards are copyrighted: implement only requirements available through licensed standards or independently published regulator guidance. This report records facts and short descriptions rather than reproducing source content.
Approved implementation model
Groundskeeper supports both explicit classes in ADR 0010:
- Validated structured detectors implement authoritatively published grammar,
checksum, and documented context gates for
includerecords. - Context-bound structured detectors implement
context_onlyrecords and require a nearby approved exact label/field plus jurisdiction where applicable.
The second class materially increases coverage without treating broad syntax as
proof: a label match is evidence, while a broad alphanumeric regex is not. The
class name does not grant runtime validated state; checksum/reference evidence
and authoritative registry validity remain distinct.