Step-by-step process
Inventory services and products
Map every exchange, arrangement, custody, transfer and token-offer function to the relevant designated-service test and customer definition.
Confirm registration and governance
Verify enrolment and VASP registration status, registration conditions, accountable roles and the current business details held by AUSTRAC.
Build a VASP-specific program
Assess product, customer, channel and jurisdiction risks and document controls for CDD, monitoring, travel rule, reporting and records.
Connect customers, wallets and transactions
Retain enough structured information to establish the parties, understand expected activity, monitor behaviour and reconstruct every designated service.
Test and improve controls
Review alert coverage, data quality, wallet classification, travel-rule exceptions, reporting timeliness and record retrieval, then document remediation.
Map each product to a designated service
Start with a product-and-activity inventory. Item 50A covers exchanging, or making arrangements to exchange, virtual assets for money and money for virtual assets in the course of carrying on a business as a VASP. Item 50B covers exchanging, or making arrangements to exchange, one virtual asset for another. Making arrangements can capture a platform or intermediary even when it does not perform every step of the exchange.
Item 46A covers virtual asset safekeeping where a VASP controls or manages virtual assets or private keys for a customer or a person nominated by the customer. Multi-signature arrangements can be captured where the provider has the relevant control or management role. A developer that only supplies self-hosted-wallet software, without safekeeping or administration, is not captured on that fact alone.
Items 29 and 30 apply where an ordering institution accepts a customer's instruction to transfer virtual assets or a beneficiary institution makes transferred virtual assets available. Item 50C covers another table 1 financial service provided in connection with an offer or sale of a virtual asset by a business participating in that offer or sale. Record a conclusion for every product, including brokerage, peer-to-peer facilitation, custody, staking-related custody, token distribution and transfer functions; a marketing label is not the legal test.
Confirm the asset and Australian connection
AUSTRAC describes a virtual asset as a non-government-issued digital representation of value that can be transferred, stored or traded electronically and performs at least one specified function, such as acting as a medium of exchange, store of economic value, unit of account, investment or governance right. Cryptocurrency, relevant stablecoins, governance tokens and some NFTs can be included. Central bank digital currency is treated as money, while non-convertible game currency, loyalty points and purely collectible NFTs may be outside the definition.
A designated service must also have the required geographical link to Australia. Document the contracting entity, operating location, customer-facing business, personnel, platform and transfer chain. Do not assume incorporation offshore, use of a decentralised protocol or an overseas wallet removes the Australian analysis.
Establish governance, risk assessment and AML/CTF policies
A generic policy that mentions cryptocurrency is not enough. Controls should explain what data is available, which risks each rule addresses, how alerts are reviewed, who can release a transfer, what happens when required information is missing and how control effectiveness is tested. Outsourcing blockchain analytics, identity checks or travel-rule messaging does not outsource the reporting entity's accountability.
- Identify the governing body, responsible senior manager and AML/CTF compliance officer, and record their decisions and oversight cadence.
- Assess customer, service, delivery-channel and foreign-jurisdiction risks for each designated service, including cash channels, crypto ATMs, custody, cross-chain activity, peer-to-peer trading, offshore VASPs and self-hosted wallets.
- Document policies for initial and ongoing CDD, enhanced CDD, sanctions and PEP responses, transaction monitoring, suspicious-matter escalation, the travel rule, reporting, record keeping, outsourcing, information security and change management.
- Train frontline, operations, engineering, fraud, compliance and customer-support personnel for the decisions they actually make.
- Review the program when products, chains, tokens, providers, customer types, delivery channels, threats or AUSTRAC guidance change, and arrange the required independent evaluation.
Build the customer-to-transaction workflow
Before providing a designated service, establish the customer and the other people required by initial CDD. For non-individual customers, trace beneficial ownership and control to the relevant individuals. Establish representative authority, the nature and purpose of the relationship or occasional transaction, expected activity and customer risk. Apply enhanced measures whenever a current trigger is met and preserve the reason for the measures and the decision.
Connect CDD to the transaction record. At minimum, retain the customer and account identifiers, service type, asset, chain or network, date and time, amount, wallet and transaction references, counterparties where applicable, fiat leg and valuation evidence. That baseline supports monitoring, travel-rule decisions, reporting and reconstruction years later.
Operate travel-rule and wallet controls
For a transfer of value, determine whether the business acts as ordering, intermediary or beneficiary institution. Collect, verify, pass on, receive and monitor payer, payee and tracing information as required for the role and transfer type. For virtual assets, tracing information can include wallet addresses, destination tags or memos and unique transaction references.
Classify the sending and receiving wallets as custodial or self-hosted on reasonable grounds. Where another custodian is involved, assess whether it is required to be, and is, licensed or registered under a law giving effect to FATF recommendations. A transfer to a self-hosted wallet has a limited exemption from passing information to another business, but the ordering institution still collects and verifies payer information and collects the payee and tracing information. Incoming self-hosted transfers also carry specific beneficiary-institution requirements.
Monitor, investigate, report and retain
Monitor both on-chain and off-chain activity throughout an ongoing relationship. Compare activity with the customer's profile, expected purpose, linked accounts and funding sources. Use reliable blockchain analysis where appropriate, but treat a score or label as an input rather than an automatic conclusion. Investigate alerts promptly, document the material considered and update risk or KYC information when the facts require it.
Submit an SMR when the available information creates reasonable grounds for a relevant suspicion; an alert or single risk indicator alone is not necessarily enough. Assess TTR and international-transfer reporting separately because each has its own trigger. Keep sufficient AML/CTF program, CDD, travel-rule and transaction records for the applicable period, usually seven years, with access controls and an audit trail.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
- AUSTRAC - Virtual asset designated services (updated 10 July 2026)
- AUSTRAC - Virtual asset service providers overview (updated 2 April 2026)
- AUSTRAC - Your obligations (updated 10 July 2026)
- AUSTRAC - Initial customer due diligence overview (updated 27 March 2026)
- AUSTRAC - Additional travel rule obligations for virtual assets (updated 31 March 2026)
- AUSTRAC - How to monitor your customers (updated 27 March 2026)
Frequently asked questions
Which virtual asset services are regulated in Australia?
The current framework includes virtual-asset-to-money and money-to-virtual-asset exchange, virtual-asset-to-virtual-asset exchange, virtual asset safekeeping, accepting transfer instructions or making transferred virtual assets available, and specified financial services connected with an offer or sale. Apply the exact item and geographical-link tests to the service facts.
Is a software-only self-hosted wallet provider automatically a VASP?
Not solely because it supplies software. AUSTRAC says the safekeeping definition is intended to exclude a person that only supplies a self-hosted-wallet application and does not safeguard or administer virtual assets. Other services or facts can still bring the business within a designated service.
Does registration replace an AML/CTF program?
No. Registration is an additional gate for VASPs. A registered reporting entity must still meet its applicable governance, risk assessment, program, CDD, travel-rule, monitoring, reporting and record-keeping obligations and any registration conditions.
Can blockchain analytics replace customer due diligence?
No. Blockchain analytics can inform wallet classification, transaction monitoring and investigations. It does not establish every customer's identity, beneficial owners, representative authority, purpose, expected activity or source information required under the applicable CDD rules.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.