Free guide: How to use AI in compliance
Back

AML/CTF for Digital Currency Exchanges in Australia: AUSTRAC Obligations After the Virtual Asset Reforms

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published September 18, 2026Updated September 18, 2026
An ordering and a beneficiary virtual asset service provider exchanging Bitcoin for Australian dollars with a travel rule envelope carrying payer and payee details

What an Australian crypto exchange must do under the AML/CTF Act after the virtual asset reforms: registration, designated services, CDD and the travel rule.

Table of contents
  • Exchanging digital currency for money has been a designated service in Australia since 2018. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 replaced the terms digital currency and digital currency exchange provider with virtual asset and virtual asset service provider, and widened the regulated services to crypto-to-crypto exchange, safekeeping, transfers and participation in an issuer's offer or sale.
  • Such a provider must both enrol and register with AUSTRAC. Enrolment is the general duty for any designated service; registration is the extra step reserved for remitters and providers of specialised virtual asset services, and operating without it is an offence.
  • Initial customer due diligence must be complete before a customer trades, withdraws or deposits: identity established on reasonable grounds, beneficial owners for company customers, politically exposed person and sanctions checks, and the nature and purpose of the relationship.
  • Separate travel rule obligations apply to transfers of value involving virtual assets. The ordering institution sends and the beneficiary institution receives payer and payee information with the transfer, which is the piece exchanges built for a wallet-to-wallet world find hardest.
  • Suspicious matter reports are due within 3 business days of forming a suspicion, or 24 hours for terrorism financing, and the duty applies even where the exchange declines the transaction. Transaction monitoring is what produces those reports at scale.
  • Below the enterprise tier the Australian market has no free option and no practice-management incumbent for licensed exchanges. A compliance stack that verifies without storing documents, screens every counterparty, monitors every transfer before it settles and drafts the report is the gap.

A virtual asset service provider is a business that exchanges virtual assets for money or for other virtual assets, transfers them on a customer's instruction, safekeeps them or their private keys, or provides financial services in an issuer's offer or sale. In Australia these are designated services under the AML/CTF Act, and the provider must register with AUSTRAC.

TL;DR

An Australian exchange is a virtual asset service provider under the reformed AML/CTF Act. It must enrol and register with AUSTRAC, run an AML/CTF programme built on its own risk assessment, complete customer due diligence before any customer trades, screen every customer and counterparty, apply enhanced measures for foreign PEPs and listed jurisdictions, carry payer and payee information with every transfer of value under the travel rule, monitor transactions for suspicious activity, report suspicious matters within 3 business days, and keep records for seven years. The 2024 reforms widened the perimeter to crypto-to-crypto exchange, custody and transfers, so a business that was only ever a fiat on-ramp may now provide several designated services.

What changed from digital currency exchange to virtual asset service provider?

AUSTRAC's virtual asset designated services guidance states the position plainly: the exchange of virtual assets for money, and vice versa, has been regulated under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 since 2018, and the new terms have replaced digital currency and digital currency exchange provider. The concept of a virtual asset is wider: a digital representation of value that can be transferred, stored or traded electronically, is not issued by or under the authority of a government body, and functions as a medium of exchange, a store of value, a unit of account or an investment, or carries governance rights. Bitcoin, Ether, stablecoins such as USDC and USDT, non-fungible tokens that function as a store of value and governance tokens are inside; central bank digital currencies, in-game currency, loyalty points and purely collectible tokens are outside.

The widening was enacted by the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, Schedule 6 of which is titled services relating to virtual assets, with Schedule 8 covering transfers of value. The same Act rewrote AML/CTF programmes and customer due diligence for every reporting entity, so an exchange that has been registered since 2018 is running under new programme and CDD rules as well as a wider service list; our tranche 2 overview covers what changed for existing entities.

Which virtual asset services are designated services?

The relevant items sit in table 1 of section 6 of the Act. AUSTRAC's guidance lists them and their customers as follows.

ItemDesignated serviceCustomer
50AExchanging, or making arrangements for the exchange of, a virtual asset for money or money for a virtual asset, in the course of carrying on a business as a virtual asset service providerThe person whose virtual asset or money is exchanged
50BExchanging, or making arrangements for the exchange of, a virtual asset for another virtual asset, of the same or a different kind, as a virtual asset service providerThe person whose virtual asset is exchanged
46AProviding a virtual asset safekeeping service, controlling or managing virtual assets or private keys for a customer, as a virtual asset service providerThe customer of the service
29 and 30Accepting instructions to transfer virtual assets on behalf of customers, or making transferred virtual assets available to customers, as ordering or beneficiary institutionThe transferor or the payee
50CFinancial services in connection with an issuer's offer or sale of a virtual asset, where the business participates in the offer or saleThe issuer or the investor

Three interpretive points matter. Making arrangements for an exchange is caught, so a platform that operates peer-to-peer matching, acts as a principal, clears or settles, or otherwise intermediates the trade provides the service even if it does not perform every step. Safekeeping covers control of assets or of the private keys that control them, including inside a multi-signature arrangement, but not a developer who only supplies self-hosted wallet software and never holds the assets. And items 46A, 50A and 50B apply only where the business is carrying on business as a virtual asset service provider, while item 50C applies to any business that participates in an offer or sale, once or repeatedly. Some obligations for the new services other than item 50A are deferred or staged under transitional rules, so an exchange adding custody or crypto-to-crypto pairs should check the transitional position for each.

How does a VASP enrol and register with AUSTRAC?

Under AUSTRAC's enrolment overview, any business providing a designated service with a geographical link to Australia must enrol no later than 28 days after the day it starts, through AUSTRAC Online, and is then placed on the Reporting Entities Roll. A remitter or VASP must also register, which is the additional process that AUSTRAC says typically applies only to money remitters and people providing specialised virtual asset services. Enrolment details must be updated within 14 days of a change, and an enrolled business submits an annual compliance report. AUSTRAC's homepage in September 2026 carried the headline that it had removed 45 businesses from its rolls as scrutiny intensified on high-risk payments, which is the reminder that registration is maintained, not merely obtained.

A business that only incidentally sends or receives virtual assets alongside another service generally does not need to register, but an exchange is the paradigm case of a business that does.

What must the AML/CTF programme cover for an exchange?

The programme has two parts: a money laundering and terrorism financing risk assessment specific to the exchange, and AML/CTF policies that manage the risks it identifies. For an exchange the assessment has to name the risks the sector actually carries: pseudonymous counterparties, self-hosted wallets, cross-border transfers at a speed no correspondent bank matches, mixers and privacy coins, exposure to sanctioned addresses, and the account-takeover and mule patterns that follow any platform where value leaves in minutes. The policies then have to say what KYC information is collected and verified for which customers, when enhanced customer due diligence applies, how the travel rule is met, what the transaction monitoring rules are and how they are tuned, who is responsible, and how tipping off is handled.

The programme is judged on whether it describes the business. A template that could belong to a remitter or a bank reads to AUSTRAC as evidence that no assessment was done. An exchange's version has to be able to explain, for example, why a first deposit from an address linked to a mixer is treated differently from a first deposit from a domestic bank.

What does customer due diligence require before a customer trades?

Initial customer due diligence must be complete before the exchange starts providing the designated service. Under AUSTRAC's initial CDD overview the exchange must establish on reasonable grounds the customer's identity; the identity of anyone acting for the customer and their authority; for company customers, the beneficial owners, meaning individuals owning 25 percent or more or otherwise controlling the customer; whether any of those people is a politically exposed person or designated for targeted financial sanctions; and the nature and purpose of the relationship. Source of funds and wealth are mandatory for foreign PEPs and, under enhanced CDD, for the customer where relevant to the risk.

For individuals that means a government identity document verified against reliable and independent data, with a liveness check so the document belongs to the person present; AUSTRAC accepts third-party digital identity services where their data is independent and reliable. For institutional and corporate customers it means business verification: the register record, directors and the ownership chain to individuals, which our KYB guide sets out. Enhanced customer due diligence is mandatory in the circumstances AUSTRAC's ECDD guidance lists: high customer risk, a suspicious matter report with the relationship continuing, unusually large or complex transactions, nested services, foreign PEPs, and any relevant person located or formed in a FATF call-for-action jurisdiction. Ongoing CDD keeps the picture current: re-screening on list changes, re-rating on behaviour, and refreshing KYC information on a risk-based cycle rather than never.

How does the travel rule apply to virtual asset transfers?

AUSTRAC's virtual asset guidance states that separate travel rule obligations apply to transfers of value involving virtual assets under items 29 to 31, and its travel rule guidance sets out the duties of ordering and beneficiary institutions. The principle is the one the FATF's Recommendation 16 established for wire transfers: the institution that sends a transfer of value passes the payer's and payee's identifying information with it, and the institution that receives it obtains that information, screens it and holds it. For an exchange that means identifying whether a counterparty wallet belongs to another regulated provider or to an individual's self-hosted wallet, transmitting or receiving the required data through a compatible protocol, and applying its policies to transfers where the data is missing or the counterparty cannot be identified.

The travel rule is where verification quality shows. The payer information an ordering institution sends is only as good as the KYC record it was drawn from, and a beneficiary institution screening incoming payee data against a name string will drown in false positives. Our guide to FATF Travel Rule compliance for VASPs covers the protocols and the sequencing.

What does transaction monitoring have to catch?

Ongoing customer due diligence includes monitoring transactions and behaviour for activity that may require a suspicious matter report, and for an exchange the typologies are specific: structuring of fiat deposits below the 10,000 dollar threshold, rapid pass-through of funds bought and withdrawn to a self-hosted wallet within minutes, deposits from addresses associated with mixers, darknet markets or sanctioned entities, chain-hopping through several assets to break the trail, dormant accounts that suddenly receive and forward value, and counterparties shared across apparently unrelated customers, which is how mule networks reveal themselves. The transaction monitoring glossary entry covers the general method; for an exchange the point is that monitoring must run before the withdrawal settles, because once virtual assets leave to a self-hosted wallet there is nothing to freeze.

What must be reported, and by when?

Under AUSTRAC's SMR guidance, a suspicious matter report is due within 3 business days after the day a suspicion is formed on reasonable grounds, or within 24 hours where the suspicion relates to terrorism financing, and the duty applies even where the exchange declines the transaction or the customer never completes onboarding, because criminals test providers. A new report is due each time a new suspicion forms about the same customer. Threshold transaction reports apply where physical currency of 10,000 dollars or more is involved, which for an exchange usually means over-the-counter desks and kiosks. International funds transfer instruction reporting and its virtual asset equivalent under the transfers-of-value provisions apply to cross-border transfers. Records of how each customer due diligence matter was established, of monitoring and of reporting are kept for seven years, and AUSTRAC states that copies of identity documents need not be kept, only their details. AUSTRAC's published enforcement actions, including those against exchanges and remitters, are logged with their findings in our AML enforcement tracker, and the recurring findings are the ones above: CDD not completed before the service, monitoring that did not produce reports, and reports filed late.

How does a licensed exchange run this below the enterprise tier?

The obligations are identical for a two-person exchange and a global one, and the tooling market has been built for the second. Zyphe's stack is priced per verification in credits with a Business tier that is free to start, which is the entry point the Australian segment lacks.

The KYC software runs document and liveness verification against over 4,000 identity document versions from 213 countries and territories, with injection-attack detection for the deepfake and virtual-camera attacks that exchanges see first, and screens every customer against sanctions, PEP, watchlist and adverse media data with a 0 to 100 banded score and a contributing-source count per match. Institutional customers go through KYB with live register purchase and ownership discovery to natural persons. The AML software is a deterministic rules engine: every payment is evaluated synchronously against the exchange's rules, using transaction, list, identity and velocity fields including counterparties shared across identities, and returns Allow, Review or Block with the fired rules attached before funds move; any rule can be backtested for free on stored transactions before it goes live, and the catalogue is jurisdiction-tagged. Agents draft the SMR narrative and evidence pack, and the exchange's own compliance officer files, which is where the Act puts the decision. Exchanges that would rather not staff the alert queue can have it worked as an operated service through the transaction monitoring alert triage desk, with the same human approval boundary.

Documents and biometrics are processed transiently and stored encrypted in each customer's own vault; the exchange keeps verification results, audit logs and proofs, which is the record AUSTRAC asks for and not the honeypot that has made identity vendors the breach story of the last two years. The data residency position, including that EEA, UK and US data stays in region, is on the security and data handling page, and the KYC for crypto page sets out the onboarding flow for exchanges in detail.

The bottom line

The reform did not make Australian exchanges reporting entities; they have been that since 2018. It widened what counts as a regulated service, rewrote the programme and customer due diligence rules underneath, and attached the travel rule to transfers of value. For a VASP the obligations now read like a bank's: enrol and register, assess and programme, verify before trading, screen and monitor before settlement, carry payer and payee data with every transfer, report within 3 business days, retain for seven years. The difference from a bank is speed and irreversibility, which is why the controls have to run before the withdrawal, not after.

This article is general information, not legal advice. Obligations depend on the services a business provides, and firms should take advice on their own circumstances.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

Yes. The 2024 Amendment Act replaced the terms digital currency and digital currency exchange provider with virtual asset and virtual asset service provider. Exchanging virtual assets for money has been a designated service since 2018, and the reforms added crypto-to-crypto exchange, safekeeping, transfers and participation in an issuer's offer or sale as designated services.

Both. Every business providing a designated service must enrol within 28 days of starting. A virtual asset service provider must also register, which is the additional step AUSTRAC applies to remitters and providers of specialised virtual asset services, and which must be maintained through updated details and an annual compliance report.

Yes, under item 50B of table 1: exchanging, or making arrangements for the exchange of, a virtual asset for another virtual asset, of the same or a different kind, in the course of carrying on a business as a virtual asset service provider. Some obligations for the new services other than fiat exchange are staged under transitional rules.

A digital representation of value that can be transferred, stored or traded electronically, is not issued by or under the authority of a government body, and functions as a medium of exchange, a store of value, a unit of account or an investment, or carries governance rights. Cryptocurrencies, stablecoins and value-bearing tokens are inside; central bank digital currencies, in-game currency, loyalty points and purely collectible tokens are outside.

The customer's identity established on reasonable grounds against reliable and independent data, the identity and authority of anyone acting for the customer, the beneficial owners of company customers, checks for politically exposed persons and sanctions designations, and the nature and purpose of the relationship. Enhanced customer due diligence applies for foreign PEPs, listed jurisdictions, high-risk customers and unusually large or complex transactions.

Yes. AUSTRAC's guidance states that separate travel rule obligations apply to transfers of value involving virtual assets. The ordering institution sends payer and payee information with the transfer and the beneficiary institution obtains, screens and retains it, with policies for transfers to and from self-hosted wallets and for missing data.

Within 3 business days after the day the suspicion is formed on reasonable grounds, or within 24 hours where it relates to terrorism financing, through AUSTRAC Online. The duty applies even where the exchange declines the transaction or the customer never completes onboarding.

No. AUSTRAC states that reporting entities are not required to keep copies of identity documents and can record their details instead. Records showing how each matter was established must be kept for seven years, which is met by retaining the verification results and proofs rather than a database of passports and selfies.

AML compliance without the PII liability

Screening, monitoring and reporting built on a privacy-first identity layer.

See Zyphe AML