Introduction
Australia’s anti-money laundering and counter-terrorism financing (AML/CTF) regime for the digital asset sector expanded significantly with reforms that commenced in 2026. This expansion means a wider range of virtual asset services are now considered a designated service. VASPs that provide a designated service with the required geographical link to meet stringent compliance obligations, often with guidance from specialist AML/CTF lawyers.
This article outlines the key duties for VASPs, covering the registration process with AUSTRAC, core AML/CTF program requirements like risk assessment and customer due diligence, and the specific obligations for the transfer of virtual assets.
Interactive Tool: Check Your Crypto Business Registration & Compliance Status
VASP AML/CTF Compliance Readiness Checker
Quickly assess your business’s AML/CTF obligations and next steps under Australia’s 2026 VASP reforms.
Does your business provide any of the following virtual asset services in Australia?
Is your business already enrolled and registered with AUSTRAC as a VASP or digital currency exchange?
Have you updated your AML/CTF program and risk assessment to reflect the 2026 reforms?
✅ No AML/CTF Registration Required
Reference: Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Get AML/CTF Legal Advice⚠️ AUSTRAC Registration Required
Reference: Section 6 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Speak to a Lawyer about AUSTRAC Registration⚠️ Update Your AUSTRAC Registration
Reference: Section 51B of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Get Legal Advice on Updating Your AUSTRAC Profile⚠️ Update Your AML/CTF Program
Reference: Section 81 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Speak to a Lawyer about AML/CTF Program Updates✅ AML/CTF Compliance Confirmed
Reference: Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Request a Compliance Health CheckWhat Is a Virtual Asset Service Provider Under Australia’s AML/CTF Regime?
From Digital Currency Exchange to VASP
Australia’s AML/CTF reforms have updated key terminology to align with international standards. The previous terms ‘digital currency’ and ‘digital currency exchange provider’ have been replaced. The regime now uses the broader concepts of ‘virtual asset’ and ‘VASP‘, following the commencement of amended Schedule 6 to the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) on 31 March 2026.
This change expands the scope of AML/CTF regulation. Under Section 5B of the AML/CTF Act, subject to certain exclusions, a ‘virtual asset’ is broadly:
- a digital representation of value that is not issued by or under the authority of a government body;
- can be transferred, stored or traded electronically, and;
- functions as a medium of exchange, store of economic value, unit of account or investment.
This ensures that more types of transactions and asset services are subject to the Australian Transaction Reports and Analysis Centre (AUSTRAC) oversight, consistent with Financial Action Task Force (FATF) recommendations.
Designated Virtual Asset Services
A business may be regulated as a VASP if it provides certain ‘designated services‘ set out in Table 1 in Section 6 of the AML/CTF Act. Key designated services that classify a business as a VASP include:
- Exchanging virtual assets for money: This applies to trading a virtual asset for fiat currency (or vice versa) and is covered by item 50A of Table 1 in Section 6 of the AML/CTF Act.
- Exchanging one virtual asset for another: This includes crypto-to-crypto trades and falls under item 50B.
- Providing virtual asset safekeeping: Item 46A covers services where a business controls or manages virtual assets or private keys on behalf of a customer. This does not capture developers who only provide software for self-hosted wallets.
- Transferring virtual assets: Accepting customer instructions to transfer virtual assets or making them available to a recipient is captured under items 29–30, where the provider acts as an ordering institution or beneficiary institution.
- Offering related financial services: A business participating in the offer or sale of a virtual asset, such as in an initial coin offering, is providing a designated service under item 50C.
Geographical Link to Australia
AML/CTF obligations apply to any business providing one or more of the designated virtual asset services that have a geographical link to Australia under Section 6(6) of the AML/CTF Act.
This means that offshore platforms and businesses incorporated overseas may still be captured by the Australian regime. That said, providing virtual asset services to Australian customers does not, by itself, establish a geographical link. The statutory test generally depends on whether the service is provided at or through a ‘permanent establishment’ in Australia, or whether one of the other circumstances in Section 6(6) applies.
Impact on VASPs That Were Already Regulated
Fiat-to-Virtual-Asset Exchange Services
Under Australia’s AML/CTF regime, certain virtual asset services were regulated before the 2026 reforms. Since 2018, any business involved in exchanging digital currency, now referred to as virtual assets, for money, or vice versa, has been required to comply with AML/CTF obligations, subject to statutory conditions and geographical link requirements.
Under this item 50A designated service, any digital currency exchange providing fiat-to-crypto services had to enrol and register with AUSTRAC under Part 3A and the former Part 6A of the AML/CTF Act. These initial regulations laid the groundwork for the expanded oversight introduced by the subsequent reforms.
Crypto Exchanges
Existing VASPs already registered with AUSTRAC cannot assume their current status covers all their activities under the 2026 reforms.
An existing registered digital currency exchange provider was automatically treated as a registered VASP from 31 March 2026 and did not need to reapply for registration. However, they must review their services to see if any fall under the new designated service categories.
If an existing digital currency exchange also offers services like crypto-to-crypto exchanges or custodial wallets, these activities are now explicitly regulated. Consequently, the VASP must update its registration details with AUSTRAC to reflect these newly regulated asset services. It must also ensure its AML/CTF program covers the associated risks.
Further, AUSTRAC required existing providers to transition their service details to the VASP framework by 29 July 2026.
Core AML/CTF Obligations for VASPs
AML/CTF Program & Risk Assessment
A VASP must develop and maintain an AML/CTF program under Sections 26B-26F of the AML/CTF Act. This program is essential for protecting your business from being exploited for criminal activities and ensuring compliance with Australian law. It must be specifically designed to address the unique risks your business faces.
The foundation of this program is a thorough risk assessment. Under Section 26C(1) of the AML/CTF Act, you are required to identify and evaluate your business’s vulnerabilities to ML/TF/PF. This assessment should consider various factors, including:
- the types of customers you serve;
- the virtual asset services you offer;
- how you deliver these services; and
- the jurisdictions you operate in.
Based on this risk assessment, you must create and implement appropriate policies, procedures, and controls to manage and reduce these identified risks.
Customer Due Diligence & Beneficial Ownership
Subject to the exceptions in Section 29 of the AML/CTF Act, before providing any designated service, a VASP must perform customer due diligence (CDD) under Section 28. This process involves collecting and verifying information to understand who your customers are and the potential money laundering or terrorism financing risk they present. You must identify both individual clients and the beneficial owners of any corporate clients.
The level of due diligence depends on the risk profile of the customer. For customers or transactions that present a higher risk, you are required to apply enhanced customer due diligence (ECDD) under Section 32.
High-risk scenarios can include:
- dealing with politically exposed persons (PEPs); or
- engaging in transactions that have no clear economic or lawful purpose.
Ongoing Monitoring & Suspicious Matter Reporting
VASPs have an obligation to conduct ongoing customer due diligence (OCDD) under Section 30 of the AML/CTF Act. This means you must continuously monitor your customers’ transactions and activities to identify anything that seems unusual or inconsistent with their known profile.
If you identify behaviour or transactions that raise suspicion, you are required to submit a suspicious matter report (SMR) to AUSTRAC under Section 41 of the AML/CTF Act. Most SMRs must be submitted within three business days after the obligation arises, while matters relating to TF must generally be reported within 24 hours. Section 41(4) makes the reporting requirement a civil penalty provision.
Reporting this information is a critical part of protecting the integrity of the financial system. However, an unusual transaction or monitoring alert does not automatically create an SMR obligation; the VASP must assess whether it has formed a suspicion on reasonable grounds under Section 41.
Record-Keeping & Governance
VASPs must adhere to strict record-keeping and governance requirements under Sections 107, 111 and 116 of the AML/CTF Act. You are required to create and maintain accurate records of your AML/CTF program, CDD, and all transactions for a period of seven years, although the point from which the seven-year period runs differs between record types. These records serve as evidence of your compliance efforts.
A strong governance framework is also mandatory under Sections 26H-26P. This structure must include:
- A governing body: This group holds the primary responsibility for overseeing compliance at the highest level of the business.
- A senior manager: This individual is responsible for approving the AML/CTF program and related compliance decisions.
- An AML/CTF compliance officer: This person manages the day-to-day implementation of the program and ensures policies are followed.
Additionally, you must conduct personnel due diligence to assess the integrity and relevant skills, knowledge, and expertise of staff in AML/CTF roles and provide them with regular training. This ensures they understand their obligations and can effectively identify and manage risks.
Travel Rule Obligations for Virtual Asset Transfers
When the Travel Rule Applies
The ‘travel rule’ is a key component of Australia’s AML/CTF framework, consistent with FATF international standards. This rule applies when a VASP facilitates a transfer of virtual assets as an ordering institution or beneficiary institution under items 29 or 30 of Table 1 in Section 6 of the AML/CTF Act. It mandates that prescribed information about the sender (originator) and receiver (beneficiary) must accompany the transfer when it moves between regulated institutions under Sections 64–66A of the AML/CTF Act.
The core purpose is to ensure that financial intelligence units like AUSTRAC have visibility into virtual asset transactions to detect and disrupt money laundering and other financial crimes.
Policies, Procedures & Technology Controls
To comply with the travel rule, a VASP must integrate specific policies and controls into its AML/CTF program. These measures are designed to manage the risks associated with virtual asset transfers.
For ordering institutions sending virtual assets, the AML/CTF program must outline procedures for:
- conducting due diligence on the recipient’s virtual asset wallet to determine if it is a custodial wallet controlled by a regulated entity or a self-hosted wallet under Section 66A(2) of the AML/CTF Act;
- assessing whether a counterparty VASP is appropriately licensed or registered in a jurisdiction that adheres to FATF recommendations under Section 66A(2)–(4);
- managing the risks of transferring to a wallet controlled by an unregulated person under Rule 5-17(6) of the AML/CTF Rules; and
- verifying that the recipient can securely receive and protect the confidentiality of the transfer information under Rule 5-17(6)(b).
Beneficiary institutions receiving virtual assets must have policies to:
- perform due diligence to identify if the transfer is from a custodial or self-hosted wallet under Section 66A(5) of the AML/CTF Act;
- assess whether the sending institution is regulated under laws that align with FATF standards under Section 66A(5) and (7); and
- manage the risks of receiving assets from unverified or unregulated sources under Rule 5-18(3) of the AML/CTF Rules.
Under Section 66A(9) of the AML/CTF Act, the requirement in Section 66A(3) to pass on transfer information does not apply if the ordering institution has reasonable grounds to believe the beneficiary institution cannot receive it securely or protect its confidentiality and the ordering institution makes and keeps a record of its reasons for not passing on the information.
Transfers Involving Self-Hosted Wallets & Offshore Counterparties
The travel rule has specific requirements for transactions involving self-hosted virtual asset wallets and counterparties located overseas. While an exemption under Rule 8-8 of the AML/CTF Rules means a VASP does not need to send the required information to another business when transferring to a self-hosted wallet, other obligations still apply. The ordering institution must collect and verify payer information and also collect payee and tracing information.
When receiving a transfer from a self-hosted wallet, the beneficiary institution must obtain the payer and tracing information before making the virtual assets available to its customer. Furthermore, a new reporting requirement will commence on 31 March 2029, mandating that VASPs report transfers involving unverified self-hosted virtual asset wallets to AUSTRAC.
For transfers involving offshore counterparties, a VASP must conduct due diligence to determine if the other service provider is licensed or registered in a jurisdiction that implements the FATF recommendations. Under Section 66A(4) and (7) of the AML/CTF Act, a VASP is prohibited from processing a transfer to or from a custodial-wallet provider that is required to be licensed or registered under such a law but is not licensed or registered.
Practical AML/CTF Risk Areas for VASPs
Core Financial Crime Risks
Virtual assets create heightened AML/CTF risks due to pseudonymity, rapid cross-border transfers, and layering techniques that obscure fund flows. These risks must be assessed under Section 26C and managed through appropriate controls under Section 26F of the AML/CTF Act, particularly where criminals exploit weaker regulatory jurisdictions.
Monitoring Tools, Wallets & Compliance Controls
VASPs commonly use blockchain analytics and wallet verification methods (such as signed messages or micro-transactions) to assess risk and confirm control of self-hosted wallets. These are best-practice tools, not legal requirements, but must support risk-appropriate systems under Sections 26F and 30. In addition, VASPs must screen for sanctions exposure and monitor for fraud typologies, reporting suspicious activity where the Section 41 threshold is met.
Sanctions & Fraud Detection Obligations
VASPs must ensure they do not deal with sanctioned persons under Australian sanctions laws and must implement screening and monitoring controls under Section 28(2)(e)(ii) and Rule 5-3. Ongoing monitoring is also required to detect scams, ransomware, and other illicit activity, with AUSTRAC reporting obligations triggered only when statutory suspicion thresholds are met.
Conclusion
Australia’s 2026 AML/CTF reforms have expanded the definition of a VASP, capturing a wider range of designated services beyond traditional exchanges. All VASPs must now implement comprehensive compliance frameworks, including detailed risk assessments, CDD, and adherence to virtual asset transfer rules.
Understanding how these changes apply to your specific asset services is essential for maintaining compliance with AUSTRAC. To ensure your AML/CTF program meets the new international standards, contact the AML/CTF compliance lawyers at Click Legal for guidance on navigating the registration process and your ongoing obligations.