For virtual asset services

Australian AML/CTF guide for virtual asset service providers

Australia now regulates a wider group of virtual asset services than the former digital-currency-exchange framework. As at 5 August 2026, the regulated activities include exchanging virtual assets for money, virtual-asset-to-virtual-asset exchange, virtual asset safekeeping, customer transfers and specified financial services connected with an offer or sale. A business must classify what it actually does, identify the customer for each service and build controls around that service rather than treating every blockchain activity as equivalent. This guide brings together AUSTRAC guidance available on 5 August 2026. It is a compliance-planning resource, not legal advice, and the exact Act, Rules, registration conditions and facts of a service remain decisive.

See the virtual asset services AML/CTF workspace

Step-by-step process

  1. Inventory services and products

    Map every exchange, arrangement, custody, transfer and token-offer function to the relevant designated-service test and customer definition.

  2. Confirm registration and governance

    Verify enrolment and VASP registration status, registration conditions, accountable roles and the current business details held by AUSTRAC.

  3. Build a VASP-specific program

    Assess product, customer, channel and jurisdiction risks and document controls for CDD, monitoring, travel rule, reporting and records.

  4. Connect customers, wallets and transactions

    Retain enough structured information to establish the parties, understand expected activity, monitor behaviour and reconstruct every designated service.

  5. Test and improve controls

    Review alert coverage, data quality, wallet classification, travel-rule exceptions, reporting timeliness and record retrieval, then document remediation.

Map each product to a designated service

Start with a product-and-activity inventory. Item 50A covers exchanging, or making arrangements to exchange, virtual assets for money and money for virtual assets in the course of carrying on a business as a VASP. Item 50B covers exchanging, or making arrangements to exchange, one virtual asset for another. Making arrangements can capture a platform or intermediary even when it does not perform every step of the exchange.

Item 46A covers virtual asset safekeeping where a VASP controls or manages virtual assets or private keys for a customer or a person nominated by the customer. Multi-signature arrangements can be captured where the provider has the relevant control or management role. A developer that only supplies self-hosted-wallet software, without safekeeping or administration, is not captured on that fact alone.

Items 29 and 30 apply where an ordering institution accepts a customer's instruction to transfer virtual assets or a beneficiary institution makes transferred virtual assets available. Item 50C covers another table 1 financial service provided in connection with an offer or sale of a virtual asset by a business participating in that offer or sale. Record a conclusion for every product, including brokerage, peer-to-peer facilitation, custody, staking-related custody, token distribution and transfer functions; a marketing label is not the legal test.

Confirm the asset and Australian connection

AUSTRAC describes a virtual asset as a non-government-issued digital representation of value that can be transferred, stored or traded electronically and performs at least one specified function, such as acting as a medium of exchange, store of economic value, unit of account, investment or governance right. Cryptocurrency, relevant stablecoins, governance tokens and some NFTs can be included. Central bank digital currency is treated as money, while non-convertible game currency, loyalty points and purely collectible NFTs may be outside the definition.

A designated service must also have the required geographical link to Australia. Document the contracting entity, operating location, customer-facing business, personnel, platform and transfer chain. Do not assume incorporation offshore, use of a decentralised protocol or an overseas wallet removes the Australian analysis.

Establish governance, risk assessment and AML/CTF policies

A generic policy that mentions cryptocurrency is not enough. Controls should explain what data is available, which risks each rule addresses, how alerts are reviewed, who can release a transfer, what happens when required information is missing and how control effectiveness is tested. Outsourcing blockchain analytics, identity checks or travel-rule messaging does not outsource the reporting entity's accountability.

  • Identify the governing body, responsible senior manager and AML/CTF compliance officer, and record their decisions and oversight cadence.
  • Assess customer, service, delivery-channel and foreign-jurisdiction risks for each designated service, including cash channels, crypto ATMs, custody, cross-chain activity, peer-to-peer trading, offshore VASPs and self-hosted wallets.
  • Document policies for initial and ongoing CDD, enhanced CDD, sanctions and PEP responses, transaction monitoring, suspicious-matter escalation, the travel rule, reporting, record keeping, outsourcing, information security and change management.
  • Train frontline, operations, engineering, fraud, compliance and customer-support personnel for the decisions they actually make.
  • Review the program when products, chains, tokens, providers, customer types, delivery channels, threats or AUSTRAC guidance change, and arrange the required independent evaluation.

Build the customer-to-transaction workflow

Before providing a designated service, establish the customer and the other people required by initial CDD. For non-individual customers, trace beneficial ownership and control to the relevant individuals. Establish representative authority, the nature and purpose of the relationship or occasional transaction, expected activity and customer risk. Apply enhanced measures whenever a current trigger is met and preserve the reason for the measures and the decision.

Connect CDD to the transaction record. At minimum, retain the customer and account identifiers, service type, asset, chain or network, date and time, amount, wallet and transaction references, counterparties where applicable, fiat leg and valuation evidence. That baseline supports monitoring, travel-rule decisions, reporting and reconstruction years later.

Operate travel-rule and wallet controls

For a transfer of value, determine whether the business acts as ordering, intermediary or beneficiary institution. Collect, verify, pass on, receive and monitor payer, payee and tracing information as required for the role and transfer type. For virtual assets, tracing information can include wallet addresses, destination tags or memos and unique transaction references.

Classify the sending and receiving wallets as custodial or self-hosted on reasonable grounds. Where another custodian is involved, assess whether it is required to be, and is, licensed or registered under a law giving effect to FATF recommendations. A transfer to a self-hosted wallet has a limited exemption from passing information to another business, but the ordering institution still collects and verifies payer information and collects the payee and tracing information. Incoming self-hosted transfers also carry specific beneficiary-institution requirements.

Monitor, investigate, report and retain

Monitor both on-chain and off-chain activity throughout an ongoing relationship. Compare activity with the customer's profile, expected purpose, linked accounts and funding sources. Use reliable blockchain analysis where appropriate, but treat a score or label as an input rather than an automatic conclusion. Investigate alerts promptly, document the material considered and update risk or KYC information when the facts require it.

Submit an SMR when the available information creates reasonable grounds for a relevant suspicion; an alert or single risk indicator alone is not necessarily enough. Assess TTR and international-transfer reporting separately because each has its own trigger. Keep sufficient AML/CTF program, CDD, travel-rule and transaction records for the applicable period, usually seven years, with access controls and an audit trail.

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

Frequently asked questions

Which virtual asset services are regulated in Australia?

The current framework includes virtual-asset-to-money and money-to-virtual-asset exchange, virtual-asset-to-virtual-asset exchange, virtual asset safekeeping, accepting transfer instructions or making transferred virtual assets available, and specified financial services connected with an offer or sale. Apply the exact item and geographical-link tests to the service facts.

Is a software-only self-hosted wallet provider automatically a VASP?

Not solely because it supplies software. AUSTRAC says the safekeeping definition is intended to exclude a person that only supplies a self-hosted-wallet application and does not safeguard or administer virtual assets. Other services or facts can still bring the business within a designated service.

Does registration replace an AML/CTF program?

No. Registration is an additional gate for VASPs. A registered reporting entity must still meet its applicable governance, risk assessment, program, CDD, travel-rule, monitoring, reporting and record-keeping obligations and any registration conditions.

Can blockchain analytics replace customer due diligence?

No. Blockchain analytics can inform wallet classification, transaction monitoring and investigations. It does not establish every customer's identity, beneficial owners, representative authority, purpose, expected activity or source information required under the applicable CDD rules.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.