AML/CTF Guide for Virtual Asset Service Providers in Australia

Australian virtual asset businesses may be reporting entities when they provide a listed exchange, transfer, custody or other virtual-asset designated service. Registration may also be required. This guide explains scope, sector risks, practical controls, examples and official sources in plain English.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. Start With These Four Checks
  3. Key words explained
  4. Part 1: When AML/CTF May Apply
  5. Part 2: Main Risks in This Sector
  6. Part 3: A Practical Control Plan
  7. Part 4: Worked Examples
  8. Part 5: Evidence That Should Be Easy to Find
  9. Part 6: Common Mistakes
  10. Common questions
  11. Official sources

Short answer

Australian virtual asset businesses may be reporting entities when they provide a listed exchange, transfer, custody or other virtual-asset designated service. Registration may also be required.

Scope is based on each designated service, the business test and the geographical link. Check current exemptions and modifications before relying on a result.

At a glance

Start With These Four Checks

  • Map the service

    Write down exactly what is done for the customer and match it to section 6.

  • Know the customer

    Identify the customer, beneficial owners, people acting for them and the purpose of the work.

  • Follow the sector risk

    Build controls around how money, property, structures, products and instructions move in this sector.

  • Keep the evidence

    Scope, CDD, risk, monitoring, reports, training and review should be easy to prove.

Plain English

Key Words Explained

These words are used in the law and official guidance. This is what they mean on this page.

Designated service
A service listed in section 6 of the Australian AML/CTF Act.
Reporting entity
A person or business that must meet AML obligations for the covered service or activity.
Beneficial owner
The individual who ultimately owns or controls the customer or on whose behalf the work is done.
Enhanced CDD
Extra customer and source checks used when the law or higher risk requires them.
SMR
A suspicious matter report submitted to AUSTRAC when reasonable grounds for suspicion exist.

When AML/CTF May Apply

The 2026 framework covers a broader range of virtual-asset services. The technology label does not decide scope; the function performed for the customer does.

  • Exchanging virtual assets for money or other virtual assets.
  • Transferring virtual assets for a customer.
  • Safekeeping or administering virtual assets or the means of control.
  • Providing specified financial services connected with issuing or selling a virtual asset.
  • Operating another designated payment, remittance, custody or financial service.
Check the boundary

Software development, validation, self-custody tools and other technical activity are not automatically designated services. Control of assets, customer relationships and the exact function should be examined.

Main Risks in This Sector

These are starting points, not a ready-made risk rating. The business still needs to assess its own customers, services, countries, channels, transactions and technology.

  • Virtual assets can move across borders quickly and through pseudonymous addresses.
  • Mixers, chain hopping, privacy tools and high-risk services can obscure the trail.
  • Stolen identity, account takeover and scams can make the apparent customer misleading.
  • Hosted and unhosted wallets can create different visibility and counterparty risks.
  • Sanctions exposure can arise through addresses, services and countries outside ordinary customer data.

A Practical Control Plan

  1. Step 1

    Confirm scope

    Map every virtual-asset function, legal entity, wallet model and flow of control.

  2. Step 2

    Build the customer process

    Confirm enrolment and registration requirements for each designated service.

  3. Step 3

    Set the risk controls

    Connect KYC, wallet screening, sanctions, transaction monitoring and case decisions.

  4. Step 4

    Train and connect people

    Set risk rules for products, assets, counterparties, geographies and unhosted wallets.

  5. Step 5

    Test and improve

    Test deposits, withdrawals, transfers, account takeover and suspicious reporting end to end.

Worked Examples

These examples show how the scope and risk questions can be joined. They do not replace the law or the facts of a real matter.

Virtual Asset Service Providers: common situations and responses
SituationWhy it mattersPractical response
A new customer receives assets from a mixer and withdraws immediately.The source and purpose may be hidden and the rapid movement may reduce recovery options.Apply the risk rules, investigate the chain and customer profile, then consider enhanced CDD, restrictions and an SMR.
A platform provides software but never controls customer assets.The business may assume the VASP label decides scope.Map the actual function, control and customer relationship against each designated service.
A customer’s device and wallet behaviour change suddenly.The account may have been taken over or sold.Pause where appropriate, re-establish control and identity, review linked activity and assess suspicion.

Evidence That Should Be Easy to Find

  • The designated-service and geographical-link analysis.
  • The current sector risk assessment and the official sources used.
  • A service and wallet-control map tied to the legal designated-service analysis.
  • Registration, asset-listing and risk-acceptance decisions.
  • Wallet and transaction-screening results linked to customer cases.
  • Testing of data coverage, sanctions logic, alert quality and withdrawal controls.
  • Customer, beneficial ownership, risk, monitoring and reporting records.
  • Training, internal review, independent assurance and remediation records.

Common Mistakes

  • Using the word exchange or wallet as the scope decision.
  • Screening the customer but not the wallet or transaction path.
  • Treating blockchain analytics as a decision rather than a source of evidence.
  • Ignoring account takeover and scam indicators because they look like fraud.
  • Failing to reassess new assets, protocols or services before launch.

Common Questions

Short answers to the questions businesses ask most often.

Does every business in this sector have AML/CTF duties?

No. The exact service and the other legal tests decide the answer. A business may provide both designated and non-designated services.

What should the business do first?

Map every virtual-asset function, legal entity, wallet model and flow of control.

Can the sector risk assessment replace our own?

No. Official national and sector assessments are important sources, but the reporting entity must assess the risks it reasonably expects to face in its own business.

Can a generic AML/CTF template be used?

A template can help with structure, but it must be matched to the business’s scope, risks, people, systems and evidence. A document that is not implemented is not enough.

Does every crypto software business need VASP registration?

No. Scope depends on the service and legal conditions, including the function, customer and control of value. A careful written analysis is needed.

Is blockchain analytics enough for CDD?

No. It can support risk assessment and monitoring, but customer identity, beneficial ownership, purpose, source and other duties still need to be met.

Official Sources

This guide cites the following sources.

  1. Primary lawFederal Register of Legislation
    Anti-Money Laundering and Counter-Terrorism Financing Act 2006

    The current Australian AML/CTF Act, including program, CDD, reporting, governance and record-keeping duties.

  2. Regulator guidanceAUSTRAC
    Virtual asset service providers

    Current AUSTRAC guidance and resources for virtual asset exchanges, transfer, custody and related providers.

  3. Regulator guidanceAUSTRAC
    Who and what we regulate

    The activities-based test for deciding whether a business is a reporting entity.

  4. Regulator guidanceAUSTRAC
    Develop your AML/CTF program

    The five-part process for governance, risk assessment, policies, review and independent evaluation.

  5. Regulator guidanceAUSTRAC
    Customer due diligence

    Current guidance on initial, ongoing, simplified and enhanced customer due diligence.

This guide provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Need advice for your situation?

Turn the Guidance Into a Clear Next Step.

Tell us what your Australia business does and where the uncertainty sits. We will help you work out the practical AML/CTF response.

Tell us about your situation