AML/CTF Guide for Virtual Asset Service Providers in Australia
Australian virtual asset businesses may be reporting entities when they provide a listed exchange, transfer, custody or other virtual-asset designated service. Registration may also be required. This guide explains scope, sector risks, practical controls, examples and official sources in plain English.
How this guide was researched and reviewedOn this page
Short answer
Australian virtual asset businesses may be reporting entities when they provide a listed exchange, transfer, custody or other virtual-asset designated service. Registration may also be required.
Scope is based on each designated service, the business test and the geographical link. Check current exemptions and modifications before relying on a result.
At a glance
Start With These Four Checks
Map the service
Write down exactly what is done for the customer and match it to section 6.
Know the customer
Identify the customer, beneficial owners, people acting for them and the purpose of the work.
Follow the sector risk
Build controls around how money, property, structures, products and instructions move in this sector.
Keep the evidence
Scope, CDD, risk, monitoring, reports, training and review should be easy to prove.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- Designated service
- A service listed in section 6 of the Australian AML/CTF Act.
- Reporting entity
- A person or business that must meet AML obligations for the covered service or activity.
- Beneficial owner
- The individual who ultimately owns or controls the customer or on whose behalf the work is done.
- Enhanced CDD
- Extra customer and source checks used when the law or higher risk requires them.
- SMR
- A suspicious matter report submitted to AUSTRAC when reasonable grounds for suspicion exist.
Part 1
When AML/CTF May Apply
The 2026 framework covers a broader range of virtual-asset services. The technology label does not decide scope; the function performed for the customer does.
- Exchanging virtual assets for money or other virtual assets.
- Transferring virtual assets for a customer.
- Safekeeping or administering virtual assets or the means of control.
- Providing specified financial services connected with issuing or selling a virtual asset.
- Operating another designated payment, remittance, custody or financial service.
Software development, validation, self-custody tools and other technical activity are not automatically designated services. Control of assets, customer relationships and the exact function should be examined.
Part 2
Main Risks in This Sector
These are starting points, not a ready-made risk rating. The business still needs to assess its own customers, services, countries, channels, transactions and technology.
- Virtual assets can move across borders quickly and through pseudonymous addresses.
- Mixers, chain hopping, privacy tools and high-risk services can obscure the trail.
- Stolen identity, account takeover and scams can make the apparent customer misleading.
- Hosted and unhosted wallets can create different visibility and counterparty risks.
- Sanctions exposure can arise through addresses, services and countries outside ordinary customer data.
Part 3
A Practical Control Plan
- Step 1
Confirm scope
Map every virtual-asset function, legal entity, wallet model and flow of control.
- Step 2
Build the customer process
Confirm enrolment and registration requirements for each designated service.
- Step 3
Set the risk controls
Connect KYC, wallet screening, sanctions, transaction monitoring and case decisions.
- Step 4
Train and connect people
Set risk rules for products, assets, counterparties, geographies and unhosted wallets.
- Step 5
Test and improve
Test deposits, withdrawals, transfers, account takeover and suspicious reporting end to end.
Part 4
Worked Examples
These examples show how the scope and risk questions can be joined. They do not replace the law or the facts of a real matter.
| Situation | Why it matters | Practical response |
|---|---|---|
| A new customer receives assets from a mixer and withdraws immediately. | The source and purpose may be hidden and the rapid movement may reduce recovery options. | Apply the risk rules, investigate the chain and customer profile, then consider enhanced CDD, restrictions and an SMR. |
| A platform provides software but never controls customer assets. | The business may assume the VASP label decides scope. | Map the actual function, control and customer relationship against each designated service. |
| A customer’s device and wallet behaviour change suddenly. | The account may have been taken over or sold. | Pause where appropriate, re-establish control and identity, review linked activity and assess suspicion. |
Part 5
Evidence That Should Be Easy to Find
- The designated-service and geographical-link analysis.
- The current sector risk assessment and the official sources used.
- A service and wallet-control map tied to the legal designated-service analysis.
- Registration, asset-listing and risk-acceptance decisions.
- Wallet and transaction-screening results linked to customer cases.
- Testing of data coverage, sanctions logic, alert quality and withdrawal controls.
- Customer, beneficial ownership, risk, monitoring and reporting records.
- Training, internal review, independent assurance and remediation records.
Part 6
Common Mistakes
- Using the word exchange or wallet as the scope decision.
- Screening the customer but not the wallet or transaction path.
- Treating blockchain analytics as a decision rather than a source of evidence.
- Ignoring account takeover and scam indicators because they look like fraud.
- Failing to reassess new assets, protocols or services before launch.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Does every business in this sector have AML/CTF duties?
No. The exact service and the other legal tests decide the answer. A business may provide both designated and non-designated services.
What should the business do first?
Map every virtual-asset function, legal entity, wallet model and flow of control.
Can the sector risk assessment replace our own?
No. Official national and sector assessments are important sources, but the reporting entity must assess the risks it reasonably expects to face in its own business.
Can a generic AML/CTF template be used?
A template can help with structure, but it must be matched to the business’s scope, risks, people, systems and evidence. A document that is not implemented is not enough.
Does every crypto software business need VASP registration?
No. Scope depends on the service and legal conditions, including the function, customer and control of value. A careful written analysis is needed.
Is blockchain analytics enough for CDD?
No. It can support risk assessment and monitoring, but customer identity, beneficial ownership, purpose, source and other duties still need to be met.
Reference
Official Sources
This guide cites the following sources.
- Primary lawFederal Register of LegislationAnti-Money Laundering and Counter-Terrorism Financing Act 2006
The current Australian AML/CTF Act, including program, CDD, reporting, governance and record-keeping duties.
- Regulator guidanceAUSTRACVirtual asset service providers
Current AUSTRAC guidance and resources for virtual asset exchanges, transfer, custody and related providers.
- Regulator guidanceAUSTRACWho and what we regulate
The activities-based test for deciding whether a business is a reporting entity.
- Regulator guidanceAUSTRACDevelop your AML/CTF program
The five-part process for governance, risk assessment, policies, review and independent evaluation.
- Regulator guidanceAUSTRACCustomer due diligence
Current guidance on initial, ongoing, simplified and enhanced customer due diligence.