Step-by-step process
Build a report decision matrix
Assess SMR, TTR, IFTI, future IVTS and self-hosted-wallet reporting on their separate legal triggers and deadlines.
Capture reconstructable transactions
Link customers, counterparties, asset and chain data, wallet and transaction identifiers, fiat legs, instructions and travel-rule information.
Record each reporting decision
Preserve the evidence, decision time, approver, report type, submission acknowledgement and any correction while restricting SMR information.
Apply retention and security
Use the correct seven-year trigger, role-based access, encryption, immutable audit history, backups and tested retrieval.
Prepare for 2029
Track AUSTRAC specifications and test that historical payer, payee, institution, wallet and asset data can support IVTS and unverified-wallet reports.
Separate the reporting tests
Build a reporting matrix around facts, not product names. A single customer event may require more than one report, while a high-value virtual asset transfer may require no TTR because no physical currency was transferred. Preserve each yes-or-no assessment and its evidence.
- SMR: assess whether there are reasonable grounds for a suspicion covered by the AML/CTF Act, including identity, crime, proceeds, terrorism-financing or other relevant grounds.
- TTR: assess each individual transfer of A$10,000 or more in physical currency or foreign-currency equivalent; a virtual asset transfer by itself is not physical currency.
- IFTI: during the transitional period, continue to assess pre-reform international funds transfer instruction reporting for transfers of money or property into or out of Australia.
- IVTS: prepare for the international value transfer service reporting transition beginning from 31 March 2029 under the applicable transition date.
- Unverified self-hosted-wallet report: beneficiary institutions must prepare for the separate report scheduled to begin on 31 March 2029.
Make suspicious-matter decisions promptly
Investigate unusual activity and decide whether the information creates reasonable grounds for a relevant suspicion. AUSTRAC says certainty is not required and one indicator may or may not be enough. Relevant material can include customer identity and risk, source information, profile consistency, third-party instructions, wallet exposure, transaction-monitoring alerts and prior investigations.
When the threshold is met, lodge within 24 hours for a terrorism-financing suspicion or three business days for other reportable suspicions. Use the current form that applies to the entity's enrolment and transition position. Put virtual asset wallet addresses, transaction identifiers and structured asset details in their correct fields and protect SMR-related information from unauthorised disclosure and tipping-off risk.
Apply the international-reporting transition carefully
AUSTRAC's transitional guidance preserves IFTI reporting until the entity's IVTS reporting transition date. An IFTI into or out of Australia is generally reported within ten business days. The standard transition date is 31 March 2029, with a limited ability for eligible existing reporters to nominate a substitute date no later than 30 September 2029.
A provider that transfers virtual assets internationally before 31 March 2029 cannot choose a later substitute IVTS date. AUSTRAC also says a business only transferring virtual assets under items 29 and 30, without transferring money or property, does not submit IFTIs on those transfers before the IVTS transition. By contrast, using virtual assets merely as settlement with another remitter or financial institution does not remove an otherwise applicable IFTI. Map the complete instruction and settlement arrangement rather than looking only at the asset delivered to the customer.
Create a reconstructable virtual asset transaction record
AUSTRAC requires sufficient records to fully and accurately reconstruct each designated-service transaction. The exact data needed depends on the service, but retaining only an internal order number or a public transaction hash will rarely explain the customer, transfer chain, fiat value, instructions and compliance decisions together.
- Designated service, customer, payer, payee, representatives, relevant accounts and beneficial-owner links.
- Date and time, direction, status, asset or token, contract, chain and network, number of units, fees and valuation source and time where fiat value is used.
- Transaction hash, wallet addresses, destination tag or memo, internal and external references and each institution in the transfer chain.
- Fiat leg, payment method, funding account, recipient details, invoices, instructions, agreements and customer-provided documents.
- Wallet classification, counterparty-VASP registration check, travel-rule message, missing-data alert, security exception and release or rejection decision.
- Monitoring alerts, investigation and reporting decision, with restricted SMR information segregated appropriately.
Apply the correct retention trigger
General transaction records are generally kept for seven years from creation, and customer-provided transaction documents for seven years from receipt. CDD records are generally kept for seven years after the occasional transaction is complete or the business relationship ends. Travel-rule transaction records, applicable policy records and evidence of compliance are also generally kept for seven years under AUSTRAC's guidance.
Make records complete, accurate, retrievable and protected against unauthorised alteration or access. Preserve source, timestamps, version, approver and audit history. Encrypt sensitive records, limit access by role, back them up securely and test retrieval. Do not put seed phrases, private keys or recovery secrets into the compliance record.
Control reporting quality and change
Reconcile eligible transactions and alerts to submitted reports, acknowledgements, corrections and rejected files. Monitor deadlines, missing mandatory fields, duplicate submissions and unresolved report errors. Keep the rule, form and schema version that produced each report and a documented manual fallback for an outage.
The reporting regime is still transitioning. Track AUSTRAC updates for IVTS and unverified-self-hosted-wallet specifications well before March 2029. Test historical data migration and field availability, especially payer, payee, wallet, asset and institution information, instead of assuming current SMR or IFTI data will automatically satisfy future reports.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
- AUSTRAC - Suspicious matter reports (updated 8 July 2026)
- AUSTRAC - International funds transfer reports (updated 22 May 2026)
- AUSTRAC - AML/CTF transitional rules 2026 (updated 2 April 2026)
- AUSTRAC - Additional virtual asset travel-rule obligations (updated 31 March 2026)
- AUSTRAC - Record keeping overview (updated 10 July 2026)
- AUSTRAC - Record keeping checklist (updated 25 March 2026)
Frequently asked questions
Does a A$10,000 virtual asset transfer require a TTR?
Not merely because the virtual asset value is A$10,000. A TTR concerns an individual transfer of A$10,000 or more in physical currency or its foreign-currency equivalent. Assess any physical-currency leg separately and consider SMR, travel-rule and international-reporting obligations on their own tests.
When must a VASP lodge an SMR?
When it forms reasonable grounds for a relevant suspicion. AUSTRAC's deadlines are 24 hours for terrorism-financing suspicions and three business days for other reportable suspicions. The clock follows formation of the suspicion, not completion of an internal convenience cycle.
When does IVTS reporting start?
The standard transition is 31 March 2029. Some eligible existing IFTI reporters may nominate a later date up to 30 September 2029, but a provider conducting international value transfers involving virtual assets before 31 March 2029 cannot choose that later substitute date.
Is a transaction hash enough as the record?
Usually not. The record must be sufficient to reconstruct the designated service. Link the hash to customer and counterparty details, service, asset, chain, amount, timing, fiat leg, instructions, travel-rule data and material compliance decisions.
How long are VASP records kept?
Many AML/CTF records are kept for seven years, but the trigger differs. Transaction records generally run from creation or receipt, while CDD retention generally runs from the end of the relationship or completion of the occasional transaction. Apply the exact record category and current law.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.