For virtual asset services

Australia's travel rule for virtual asset transfers

Australia's travel rule follows the transfer, not the technology brand used to send it. A VASP may act as an ordering institution when it accepts a payer's instruction, an intermediary when it passes a transfer message through the chain, or a beneficiary institution when it makes value available to the payee. Each role has different collection, verification, monitoring, passing-on and decision requirements. There is generally no minimum transfer amount. This guide reflects AUSTRAC travel-rule guidance available on 5 August 2026, including the virtual asset changes effective for newly regulated services from 1 July 2026.

See the virtual asset services AML/CTF workspace

Step-by-step process

  1. Identify the role and transfer type

    Map payer, payee, ordering, intermediary and beneficiary institutions and determine which transfer-specific rules apply before release.

  2. Collect and verify information

    Collect payer, payee and tracing information and verify the fields required for the institution's role.

  3. Classify each wallet and institution

    Determine custodial or self-hosted status, controller and required licensing or registration on reasonable grounds.

  4. Send or receive securely

    Use a secure transfer-message channel, monitor missing or inaccurate fields and prevent release until required decisions are complete.

  5. Retain the transfer record

    Keep the message, tracing information, classifications, checks, exceptions, decisions and transaction evidence for the applicable period.

Identify the transfer and your role before execution

A transfer of value can include money, virtual assets or property, but excludes physical currency and tangible property. For a virtual asset transfer, map the payer, payee, ordering institution, each intermediary and beneficiary institution. The same business can hold more than one role, and the payer and payee can be the same person.

Do this before the on-chain transaction is released. The distributed ledger may not carry the required personal information, so a separate transfer message may need to be sent before or at the same time as the blockchain transaction. Product design should prevent release when a required classification, identity field, message or counterparty decision remains unresolved.

Collect the required information

An ordering institution can use information already collected through CDD or an earlier transfer when it has no reason to doubt its adequacy or truth. If new transfer information conflicts with KYC information, review, update and reverify as required rather than passing the inconsistency downstream.

  • Payer information: the payer's full name plus one or more prescribed identifiers, which can include date and place of birth, full business or residential address, an ordering-institution customer number or another unique identifier.
  • Payee information: typically the payee's full name, subject to the transfer-specific rules and temporary verification provisions.
  • Payer tracing information: an account identifier, custodial-wallet address and tag or memo, self-hosted-wallet address, or required transaction reference depending on the transfer.
  • Payee tracing information: the destination account, custodial-wallet address and tag or memo, self-hosted-wallet address, or transaction reference required for the transfer type.

Apply the ordering, intermediary and beneficiary controls

The ordering institution collects the payer and payee information, verifies the payer information and sends the required transfer message and tracing information to the next institution. The intermediary takes reasonable steps to monitor that required information was received, passes it on without stripping material fields and keeps the required records.

The beneficiary institution monitors for missing required information and, where required, inaccurate payee information before making value available. For a virtual asset transfer, it generally must receive or otherwise obtain payer information, tracing information and the payee's full name before release. Document how missing, inaccurate or technically incompatible messages are held, investigated, corrected, rejected or escalated.

Classify custodial and self-hosted wallets

Before sending or making virtual assets available, determine on reasonable grounds whether the relevant wallet is custodial or self-hosted and who controls it. For a custodial wallet, determine whether the controller is required to be licensed or registered under laws that give effect to FATF recommendations and whether it has the required status. Reliable public registers, counterparty information and high-confidence blockchain or wallet data can support the conclusion.

An ordering institution must not accept an instruction to transfer to a beneficiary institution that is required to be licensed or registered but is operating without that status. A beneficiary institution must not make the transfer available where the sending wallet is controlled by an institution that is required to be licensed or registered but is not. Preserve the source, date and confidence of the classification.

Understand the self-hosted-wallet exemption

A transfer to a self-hosted wallet is exempt from passing travel-rule information to another business in the transfer chain because there is no beneficiary institution to receive it. The exemption is not a blanket CDD or information exemption. The ordering institution still collects and verifies payer information and collects the payee's full name and tracing information.

For an incoming transfer from a self-hosted wallet, the beneficiary institution obtains the payer information and tracing information and, if it does not already hold it, the payee's full name before making the virtual assets available. Its policies must identify the payer and describe the steps used to verify who controls the sending wallet. Separate AUSTRAC reporting for transfers involving unverified self-hosted wallets is scheduled to begin on 31 March 2029; it is distinct from SMRs and TTRs.

Protect messages and retain evidence

Assess whether the next institution can receive the message securely and protect its confidentiality. An ordering institution may have a basis not to pass specified information where the statutory security conditions are met, but it must keep the reasons. Do not send travel-rule personal information in an uncontrolled blockchain memo, support ticket or public transaction field.

Keep transaction records, payer, payee and tracing information, wallet classifications, licensing checks, missing-information alerts, security decisions, release or rejection decisions and applicable policies. AUSTRAC says travel-rule transaction and compliance records are generally retained for seven years and must be sufficient to reconstruct the transfer.

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

Frequently asked questions

Is there a minimum amount for Australia's travel rule?

AUSTRAC says the travel rule applies to domestic or international value transfers of any amount unless an exemption or transfer-specific rule applies. Do not set a monetary threshold as the only trigger for collecting travel-rule information.

Must travel-rule data be written onto the blockchain?

No. Where the ledger cannot carry the required information simultaneously, AUSTRAC says the transfer message must be sent before or at the same time as the on-chain transfer. Use a secure channel designed to protect the information.

Does a self-hosted wallet remove travel-rule obligations?

No. An outgoing transfer to a self-hosted wallet is exempt from passing information to another business, but payer information must still be collected and verified and payee and tracing information collected. Incoming self-hosted transfers also have beneficiary-institution information and wallet-control requirements.

What if the counterparty VASP is unregistered?

Determine whether it is required to be licensed or registered under a law giving effect to FATF recommendations. AUSTRAC prohibits sending to, or making value available from, an institution that is required to hold that status but is operating without it.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.