Groundskeeper

Australian additional identifier inventory: evidence and recommendations

Evidence cut-off: 3 October 2026 (Australia/Sydney) Scope: identifiers proposed as additions to Groundskeeper Machine-readable record: data/australian-additional-identifiers.json

Method and evidence rule

This review uses Australian Government, state/territory government, regulator, issuer, or standards-body sources. A format is recorded only when one of those sources publishes it. Examples seen in search results, cards, or third-party guidance were not generalized into formats. null in the inventory therefore means not authoritatively published in the sources reviewed, not that the identifier does not exist.

The inventory separates:

  • include: sufficiently distinctive syntax and/or a checksum for a generic detector;
  • context_only: useful only beside an issuer-specific label or in a structured field;
  • exclude: no safe generic detector (variable/private format, obsolete, or not an Australian identifier class).

Syntax and checksums establish plausibility, not issuance or current status. Where an official register or service exists, it is the authoritative validation method.

Taxonomy IDDecisionPublished formatValidationRequired context
au.health.hpi_iInclude16 digits, prefix 800361Luhn, then HI ServiceWord boundaries; preserve leading digits
au.health.hpi_oInclude16 digits, prefix 800362Luhn, then HI ServiceWord boundaries; preserve leading digits
au.services.centrelink_crnInclude9 digits + letterServices Australia only; no public checksum foundPrefer CRN/Centrelink; bare form has moderate FP risk
au.immigration.immicardInclude3 letters + 6 digitsHome Affairs/VEVORequire ImmiCard, AMS, or EIS context; do not assume those are the only prefixes
au.education.usiInclude10 chars from A-HJ-NP-Z2-9; not all digitsUSI Registry verificationPrefer USI/education context; syntax alone still collides with tokens
global.vehicle.vinInclude (global taxonomy)17 uppercase alphanumerics excluding I/O/Q; official Australian guidance says last 3 are digitsNEVDIS/RAV; no universal Australian checksum publishedVehicle/VIN context strongly recommended
au.children.nsw_wwccContext-onlyBegins WWC; complete length/grammar unpublishedNSW OCG online verificationRequire WWCC, Working with Children, or WWC prefix
au.education.vic_vsnContext-only9 digitsVictorian Student Register/VCAARequire VSN or full label
au.immigration.visa_grant_numberContext-only13 characters (source does not constrain character class)VEVORequire exact label
au.immigration.citizenship_certificateContext-onlyMultiple certificate-era fields; no current unified syntax publishedHome Affairs/DVSRequire exact certificate field label

The complete inventory includes all requested categories and jurisdictions. The table above is intentionally limited to entries that can support implementation work now.

Decisions by requested area

Health, veterans and professional registration

  • DVA file/Veteran Card number: include only as context-bound data. HL7 Australia AU Base v6.0.0 publishes a maximum length of 9 and an example, but not a complete grammar or checksum. DVA/Services Australia lookup is authoritative. Do not turn the example into a regex.
  • HPI-I/HPI-O: include. The published profiles specify 16 digits, prefixes 800361 and 800362, and Luhn. A successful Luhn check is not proof that the HI Service issued the number.
  • Ahpra registration number: context-only. The public register validates a registration number and Ahpra says it remains with a practitioner for life, but Ahpra does not publish a complete syntax/checksum. It is public professional-register information, while still identifying a person.

Worker and child-safety screening

  • NDIS worker screening: retain eight jurisdiction-specific taxonomy entries. The NDIS Commission confirms state/territory issuance, national portability, and database validation. It does not publish a national Worker Screening ID grammar. A 2026 Commission guide states that an Application ID is eight digits; that must not be mislabelled as a Worker Screening ID. NT separately publishes the application reference example 7-NDISXXXXXX, which is an application reference, not clearance proof.
  • WWCC/WWVP: retain eight jurisdiction-specific entries. Names, cards, application references, and verification mechanisms differ. NSW officially says a clearance begins WWC, but does not publish the remainder. No other complete current syntax was found in authoritative material reviewed. All require jurisdiction + scheme-label context and issuer verification.

Police, immigration and social services

  • Police checks: exclude a generic reference detector. AFP, state/territory police, and ACIC-accredited bodies issue separate references. AFP offers status/certificate validation and QR security, but no common syntax is published. A police check is also point-in-time and purpose-specific.
  • Visa grant / ImmiCard / citizenship: Home Affairs publishes 13 characters for Visa Grant Number and exactly three letters plus six digits for ImmiCard. Only ImmiCard is distinctive enough for inclusion, and still needs label/prefix context. Citizenship certificates span document generations and field names; no unified syntax was published.
  • Centrelink CAN vs CRN: these are not synonyms. CRN is the durable record identifier and is officially 9 digits plus a letter. CAN is a phone self-service access credential used with a PIN; no current syntax was found. Detect CRN; do not detect CAN generically.
  • Child Support, My Aged Care, PRODA/RAM: the services use customer/reference/account identifiers but publish no stable generic syntax in the reviewed current material. These should be context-only fields. PRODA is also being replaced by Digital ID/myID + RAM in some service journeys; RAM authorisation and machine-credential artefacts are credentials, not public identifiers.
  • NDIA/NDIS provider registration: registered provider status is publicly searchable primarily by name/ABN. The Commission does not publish a safe registration-number grammar in its public register. Use ABN plus Provider Register lookup, not a new generic number detector.

Education and superannuation

  • USI: include with the official 10-character alphabet. Authoritative verification is the USI Registry; the public WSDL constrains syntax but does not expose a locally usable checksum algorithm.
  • CHESSN: mark obsolete/decommissioning. StudyAssist says decommissioning began in 2021 and USI is now primary. Preserve only for historical labelled data.
  • State student IDs: no national detector. Victoria alone clearly publishes VSN as a random 9-digit number. NSW, Queensland, WA, SA and Tasmania are retained as context-only because their reviewed official pages confirm issuer-specific identifiers but do not publish complete syntax. ACT and NT are excluded/unverified because no single territory-wide identifier and format was found; NT students may separately receive a SACE registration number for NTCET.
  • Super member/account numbers: fund-assigned and private; no common syntax. ATO says an account is identified by fund ABN + super-product USI + member account number. Do not confuse a member number with the public organizational Unique Superannuation Identifier, whose format may be a SPIN or ABN plus three digits.

Cards, transport, property, weapons, maritime and aviation

  • Proof-of-age/photo cards, vehicle registrations, firearms licences, marine licences, property titles: all are jurisdiction-variable. Use jurisdiction and exact document label; do not create Australia-wide bare-value detectors. WA publishes a property-title machine representation, but that is not portable to other land registries.
  • VIN: suitable for a global detector with vehicle context. Australia publishes the 17-character alphabet and NEVDIS/RAV validation. Older vehicles/chassis numbers are exceptions. No universal Australian checksum rule was found.
  • AMSA/CASA: AMSA certificate number + Seafarer ID + password/QR can be authoritatively checked, but syntax is unpublished. CASA ARN is the core individual/organisation reference (and an individual's flight-crew licence number), but CASA does not publish a current length/grammar. Both are context-only.

Financial, commercial and crypto identifiers

  • AFSL/credit/authorised-representative numbers: public organizational/professional identifiers and searchable in ASIC's Professional Registers, but ASIC does not publish a complete numeric grammar or checksum. Detect only with explicit AFSL, AFS licence, Australian credit licence, or authorised representative context, then verify against ASIC.
  • Insurance policy, loan, claim, customer/account numbers: issuers define these. APRA reporting standards call policy numbers free text and claim/policy IDs issuer-unique; there is no cross-industry syntax. They can identify a person and financial relationship. Generic detectors are unsuitable; use tenant/issuer-configured labelled-field rules.
  • Crypto wallet addresses: not an Australian identifier and formats/checksums differ by network. Addresses are public/pseudonymous but can become personal information when linked to a person. Implement network-specific global detectors, never one AU crypto wallet regex; validate using the relevant network and, where appropriate, a blockchain explorer.

Privacy and licensing

“Public” means the identifier is intentionally published in an official register (for example ASIC licences), not that all associated data is unrestricted. “Personal” follows the OAIC's contextual test: information that identifies or reasonably identifies an individual. Health, welfare, immigration, child-safety, police, education, financial-account and screening identifiers should be handled as personal; police/health/disability context may also reveal sensitive information.

The inventory records source-level reuse constraints. Most Commonwealth and state web facts can be cited; many pages are CC BY 4.0, but logos, coats of arms, trademarks, images and third-party material are excluded. Services Australia expressly requires attribution. HL7 Australia AU Base is CC0 but protects HL7/FHIR marks and excludes third-party IP. ISO standards are copyrighted: implement only requirements available through licensed standards or independently published regulator guidance. This report records facts and short descriptions rather than reproducing source content.

Approved implementation model

Groundskeeper supports both explicit classes in ADR 0010:

  1. Validated structured detectors implement authoritatively published grammar, checksum, and documented context gates for include records.
  2. Context-bound structured detectors implement context_only records and require a nearby approved exact label/field plus jurisdiction where applicable.

The second class materially increases coverage without treating broad syntax as proof: a label match is evidence, while a broad alphanumeric regex is not. The class name does not grant runtime validated state; checksum/reference evidence and authoritative registry validity remain distinct.

On this page