Step-by-step process
Connect the data
Join customer, ownership, fiat, device, wallet, chain, counterparty and external-risk data with reproducible lineage.
Design risk-based scenarios
Translate business and AUSTRAC risk indicators into rules tailored by service, customer, asset, chain, direction, confidence and pattern.
Investigate alerts
Review the full customer and transaction context, corroborate explanations and record evidence, limitations and disposition.
Make the reporting decision
Escalate promptly and lodge an SMR within the applicable deadline when reasonable grounds for a relevant suspicion arise.
Test and tune
Replay cases, measure timeliness and false positives, inspect missed detections and document approved rule and provider changes.
Build a complete monitoring data set
Normalise identifiers across chains and systems so a rule can see linked accounts, wallets and transfers. Preserve the raw source and transformation lineage needed to reproduce an alert. A monitoring rule built on partial data should document the blind spot instead of implying complete coverage.
- Customer, beneficial owner, risk rating, purpose, expected assets, expected value and frequency, source information and jurisdiction profile.
- Fiat deposits and withdrawals, payment instruments, bank-account holder, cash or crypto-ATM events, chargebacks and third-party funding.
- Wallet address, chain, token, contract, transaction hash, direction, timestamp, amount, fees, counterparties, destination tag or memo and cross-chain bridge activity.
- Device, IP, geolocation, session, account linking, authentication changes, API keys, withdrawal-address changes and failed verification events.
- Reliable sanctions, adverse intelligence, VASP registration and blockchain attribution with provider, version, time and confidence preserved.
Monitor customer and transaction behaviour
Compare current activity with the customer's history, stated purpose and similar customers using the same services. Monitor rapid movement after fiat funding, immediate withdrawals, velocity and value changes, chains of asset conversions without apparent rationale, pass-through wallets, unusual third-party funders, multiple linked accounts and sudden changes to devices or withdrawal destinations.
Apply risk-based intensity. Higher-risk customers and services may require more alerts or more frequent manual review. AUSTRAC expects monitoring measures to be checked regularly so the business can show that relevant activity is identified, alerts arrive in time and investigators respond appropriately.
Use virtual-asset-specific indicators
These are indicators, not automatic SMR conclusions. Tune them by asset, chain, service, customer segment, direction, proximity, attribution confidence, value and pattern. A broad rule that generates unmanageable false positives can obscure serious activity just as surely as a rule that never fires.
- Transfers involving wallets associated with unregistered or unregulated VASPs, OTC brokers, peer-to-peer platforms, mixers or higher-risk decentralised exchanges.
- Rapid virtual-asset-to-virtual-asset chains or rapid fiat and stablecoin conversions without a reasonable economic explanation.
- High-confidence blockchain exposure to scam receipts, ransomware, darknet markets, child exploitation, terrorism financing, sanctions or proliferation-financing concerns.
- Privacy-coin or anonymity-enhancing activity inconsistent with the customer's known profile and purpose.
- Multiple bank deposits in different names, rapid clearing to an intermediary wallet, apparent coaching, limited virtual-asset knowledge followed by a large outbound transfer, or a customer reporting they are sending funds for an investment opportunity.
- Account, identity, device or network features consistent with a mule, synthetic identity, account takeover or multiple accounts controlled by the same person.
Investigate and disposition alerts consistently
Give the investigator the relevant transaction path, customer profile, KYC and ownership information, fiat funding, device and account links, prior alerts, blockchain evidence and open-source or sanctions results. Record the question examined, material considered, limitations, customer contact where appropriate, conclusion and approver.
Use controlled dispositions such as explained activity, false positive, monitoring adjustment, KYC refresh, customer-risk update, enhanced CDD, restriction, exit or SMR review. Do not close an alert only because a customer supplied a plausible sentence; corroborate material facts proportionately. Restrict suspicious-matter information to authorised personnel and avoid customer contact that creates a tipping-off risk.
Move from indicators to an SMR decision
Review the whole matter to decide whether there are reasonable grounds for a relevant suspicion. AUSTRAC says one indicator may have a legitimate explanation and multiple indicators may be needed. Certainty that a crime occurred is not required. If reasonable grounds arise, submit the SMR within the applicable deadline: 24 hours for a terrorism-financing suspicion and three business days for other reportable suspicions.
An SMR can be required when a service is requested, started, completed, declined or attempted, depending on the facts. A transfer hold, account closure, law-enforcement referral, TTR or future self-hosted-wallet report does not replace the SMR analysis. Put wallet addresses and structured virtual-asset fields in the correct report fields rather than burying them only in narrative grounds.
Test monitoring effectiveness
Test data completeness, alert logic, thresholds, attribution freshness, scenario coverage, investigation quality, timeliness and reporting hand-off. Replay known typologies and synthetic cases across supported products and chains. Track alert volumes, aging, false-positive reasons, missed detections, model or vendor changes and overrides.
Update scenarios when AUSTRAC publishes new indicators, the business launches a product or chain, customer behaviour changes or an incident reveals a gap. Senior managers should approve material changes, and the business should retain the rule version and evidence that monitoring continued to operate during deployments and migrations.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
- AUSTRAC - VASP suspicious activity indicators (updated 25 March 2026)
- AUSTRAC - VASP ML/TF risk-indicator poster (updated 12 June 2026)
- AUSTRAC - VASP risk insights (updated 3 February 2026)
- AUSTRAC - How to monitor your customers (updated 27 March 2026)
- AUSTRAC - Suspicious matter reports (updated 8 July 2026)
- AUSTRAC - Enhanced customer due diligence (updated 15 July 2026)
Frequently asked questions
Does a high blockchain-risk score automatically require an SMR?
No. It is relevant evidence to investigate. Consider attribution confidence, transaction path, customer information, purpose, source, other indicators and legitimate explanations. Submit an SMR when the combined facts establish reasonable grounds for a relevant suspicion.
Can a small VASP monitor transactions manually?
Manual monitoring can be suitable only where it is genuinely effective for the volume and risk. AUSTRAC expects an automated transaction monitoring system when transactions cannot be monitored effectively by hand. The business must still demonstrate timely alerts, review and response.
Should all mixer or privacy-coin activity be rejected?
AUSTRAC identifies mixers and privacy-enhancing activity as risk indicators. The response should follow the VASP's documented risk appetite, legal obligations and assessment of the actual customer and transaction; the indicator alone is not proof of unlawful activity.
What should an alert record contain?
Retain the triggering rule and version, relevant customer and transaction data, evidence and limitations, investigation steps, conclusion, approvals, resulting CDD or risk changes and whether an SMR review occurred. Protect restricted suspicious-matter information.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.