For virtual asset services

Counterparty due diligence for the Australian travel rule

The Australian travel rule requires ordering and beneficiary institutions to collect, transmit and receive specified originator and beneficiary information for transfers of value involving virtual assets. That creates a counterparty discipline: a VASP must know who it is exchanging information with, verify that the counterparty is what it claims to be, and handle failures without quietly lowering the standard. This guide sets out the counterparty due diligence a VASP needs around the travel rule, from discovery to failure handling.

See the virtual asset services AML/CTF workspace

Identify the counterparty role

The travel rule attaches to the institution's role: an ordering institution accepts the customer's instruction to transfer, a beneficiary institution makes the transferred value available, and an intermediary institution passes information through. The same business can hold different roles in different transfers, and the obligations differ by role.

Record the role for each transfer and the counterparty institution. A transfer to an unhosted wallet is different from a transfer to another VASP, and the rules treat them differently.

Verify the counterparty

Counterparty verification is a control, not an administrative detail. A VASP that accepts travel-rule data from an unverified 'institution' cannot demonstrate that the information is reliable or protected.

  • Confirm the counterparty's identity, jurisdiction and regulatory status
  • Assess whether it is subject to an equivalent AML/CTF regime
  • Verify the institution's controls for receiving and protecting information
  • Check the counterparty against sanctions and adverse information
  • Document the verification and the basis for reliance on its data

Exchange the required information

The required information is the substance of the travel rule. The VASP's system should validate the fields, preserve them with the transfer record and show the status of each exchange, including partial or withheld data.

  • Collect the required originator and beneficiary fields for the transfer
  • Use a secure channel with the agreed protocol or format
  • Validate the data before transmission
  • Record what was sent, received and withheld, with reasons
  • Apply the exemption and threshold rules only where they apply

Handle failure without lowering the standard

The weakest travel-rule practice is the silent workaround: accepting missing fields because the deal must proceed. The program should define the failure path, and the file should show it was followed.

  • Block or pause transfers where required information is missing
  • Escalate counterparty refusals and repeated failures
  • Assess whether the failure itself is suspicious and warrants an SMR
  • Maintain a manual fallback with evidence when systems fail
  • Review counterparty arrangements on a defined cycle

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

Frequently asked questions

Who must verify the counterparty under the travel rule?

Institutions sending or receiving transfers should establish the counterparty's identity and role and assess its reliability, consistent with AUSTRAC's travel rule guidance and the VASP's program.

What information must travel with a transfer?

The required originator and beneficiary information for the transfer type, as the Act and Rules specify. The exact fields depend on the role and the applicable threshold and exemption rules.

Can we proceed if the counterparty will not send information?

Only within the rules. Missing required information should block or pause the transfer and be escalated, and the failure itself may be a suspicious-matter trigger.

Does the travel rule apply to unhosted wallets?

Transfers involving unhosted wallets are treated under the specific rules and guidance for self-hosted wallets, which differ from institution-to-institution transfers. Apply those rules carefully.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.