How does Australia’s AML/CTF regime regulate virtual assets?

Australia’s anti-money laundering and counter-terrorism financing regime now regulates a broader range of virtual asset services.

The changes extend beyond exchanges between virtual assets and conventional money. They can also cover virtual asset custody, crypto-to-crypto exchange, transfers and financial services connected with an offer or sale.

If your business handles virtual assets for customers, the first question is no longer whether you consider yourself a crypto business. The question is whether any service you provide is a designated service under the AML/CTF regime.

This explainer covers the meaning of virtual asset, the services that are regulated, registration with the Australian Transaction Reports and Analysis Centre (AUSTRAC), and the main compliance steps for virtual asset service providers.

What is a virtual asset?

A virtual asset is a digital representation of value that can be transferred, stored or traded electronically and is not issued by or under the authority of a government body.

A digital representation of value may be a virtual asset if it functions as:

  • a medium of exchange;

  • a store of value;

  • a unit of account;

  • an investment; or

  • a means of voting on the management, administration or governance of an arrangement connected with the digital representation of value.

The definition can therefore extend beyond cryptocurrency. Depending on their characteristics and use, it may capture governance tokens, some non-fungible tokens and other digital assets.

The substance of the asset matters more than its label. Calling something a utility token, digital collectible or membership token does not determine whether it is a virtual asset.

What is not a virtual asset?

Money is not a virtual asset.

Digital items used only within an electronic game are also generally excluded, as are loyalty and reward points that the issuer does not intend to be convertible into money or another digital representation of value.

The distinction can become less clear where an asset has several functions. A token may provide access to a service but also be transferable, traded on a secondary market or held as an investment.

Businesses should assess what the asset does, how holders can use it and whether it can move outside a closed system. Marketing material, contractual rights and technical design may all be relevant.

The AML/CTF Rules may include or exclude additional kinds of digital assets as business models and technologies change.

Why did the law move from digital currency to virtual assets?

The earlier concept of digital currency did not capture every service involving digital representations of value.

The broader virtual asset framework brings virtual asset safekeeping, exchanges between virtual assets, transfers and some services connected with token offerings within the AML/CTF regime. It also aligns Australian terminology more closely with the standards of the Financial Action Task Force (FATF).

The change recognises that money laundering, terrorism financing and proliferation financing risks are not confined to buying or selling cryptocurrency for conventional money.

Which virtual asset services are regulated?

A business may have AML/CTF obligations if it provides one or more designated virtual asset services with the required connection to Australia.

The regulated services include:

  • exchanging virtual assets for money, or money for virtual assets;

  • arranging an exchange between virtual assets and money;

  • exchanging one virtual asset for another;

  • arranging an exchange between virtual assets;

  • providing a virtual asset safekeeping service;

  • accepting instructions to transfer virtual assets on behalf of customers;

  • making transferred virtual assets available to customers; and

  • providing certain financial services connected with an offer or sale of virtual assets.

The exchange services cover arrangements for an exchange as well as the exchange itself. A platform or intermediary may therefore be regulated even if it does not take ownership of the virtual assets.

The scope of the regulated service should be assessed by reference to what the business does in practice, not only how its contracts or website describe the service.

What is a virtual asset safekeeping service?

A virtual asset safekeeping service involves controlling or managing virtual assets or private keys for or on behalf of a customer or another person nominated by the customer.

This can include custodial wallet services and other arrangements under which the provider can control access to, or movement of, a customer’s virtual assets.

The technical design matters. A provider that cannot access or control the customer’s assets may present a different regulatory position from one that holds private keys, approves transactions or can restrict transfers.

Businesses offering wallets, custody technology or key-management services should map precisely:

  • who holds each private key;

  • who can initiate or approve a transaction;

  • whether several parties must approve a transfer;

  • whether the provider can freeze or restrict access; and

  • what happens if the customer loses their credentials.

Those facts will help determine whether the business is providing safekeeping rather than merely supplying software.

Are exchanges between virtual assets regulated?

Yes. Exchanging one virtual asset for another, or arranging that exchange, can be a designated service.

This means that a platform is not outside the AML/CTF regime merely because no Australian dollars or other conventional currency enter the transaction.

The exchange may involve virtual assets of different kinds or assets of the same kind. Businesses should therefore review swaps, conversions, brokerage functions, order matching and other arrangements that allow customers to move between virtual assets.

Are virtual asset transfers regulated?

The AML/CTF regime regulates certain roles in a transfer of value involving virtual assets.

A business may provide a designated service if it:

  • accepts an instruction to transfer a virtual asset on behalf of a payer;

  • makes a transferred virtual asset available to a payee; or

  • passes a transfer message through a value-transfer chain.

These roles are commonly described as the ordering institution, beneficiary institution and intermediary institution.

The regime focuses on the function performed in the transfer. A business may therefore have obligations even if it does not describe itself as a remitter or payment provider.

Separate travel rule requirements can apply to transfers of value involving virtual assets. These requirements concern information that must accompany or be associated with a transfer.

Are services connected with virtual asset offerings regulated?

Some financial services provided in connection with an offer or sale of a virtual asset are designated services where the provider participates in the offer or sale.

This may capture activities such as underwriting, market making and acting as a placement agent.

The rule is broader than the services provided by a conventional virtual asset exchange. Advisers, intermediaries and financial service providers involved in a token offering may need to consider whether their role is regulated even if they do not provide custody or exchange services.

A one-off or free service may still be provided in the course of carrying on a business if it helps further that business. The absence of a separate fee does not necessarily place the activity outside the AML/CTF regime.

What is a virtual asset service provider?

A virtual asset service provider, or VASP, is a business that provides specified virtual asset services.

Whether a business is a VASP depends on the activities it carries out. It does not depend on whether the business uses that term to describe itself.

A software business, payment provider, token issuer, marketplace or financial intermediary may fall within the regime if its actual functions amount to a designated virtual asset service.

The analysis may be difficult where several entities contribute to one service. A group might separate customer onboarding, wallet infrastructure, transaction approval and asset custody across different companies.

Each entity’s role should be assessed separately.

Must a VASP register with AUSTRAC?

A business providing a registrable virtual asset service must generally enrol with AUSTRAC and register as a VASP.

Enrolment and registration are separate processes:

  • Enrolment places the business on AUSTRAC’s reporting entities roll and allows it to interact with AUSTRAC.

  • Registration authorises it to provide registrable virtual asset services.

A provider cannot assume that enrolment alone allows it to start providing those services.

Registration typically applies to virtual asset safekeeping, exchanges, relevant virtual asset transfers and financial services connected with offers or sales. Exceptions can apply, including for some services provided by financial institutions or licensed casinos.

AUSTRAC maintains a public VASP register that can be used to check whether a provider is registered.

What information is required for registration?

A VASP registration application requires detailed information about the business, the services it proposes to provide and the people who own or control it.

The information may include:

  • the entity’s legal structure, names, addresses and registration details;

  • beneficial owners, directors and key personnel;

  • relevant foreign registrations and licences;

  • criminal, civil and regulatory history;

  • the types of virtual assets the business handles;

  • expected transaction volumes and values;

  • delivery channels and methods of exchange;

  • transaction limits;

  • wallet addresses and wallet capabilities;

  • bank or financial institution accounts used for the services;

  • the business’s ML/TF risk assessment and AML/CTF policies; and

  • third parties that assist with compliance functions.

This is not an administrative formality. AUSTRAC considers the risk that the applicant may be involved in, or exposed to, money laundering, terrorism financing or other serious crime.

A business preparing an application should confirm that its ownership records, key-person disclosures and AML/CTF documents are complete and consistent before submission.

What happens after registration?

VASP registration is not permanent. It generally needs to be renewed every three years.

AUSTRAC may impose conditions on a registration. Conditions may restrict transaction values or volumes or require the provider to notify AUSTRAC about specified matters.

A registered VASP must keep its information current and notify AUSTRAC of relevant changes. AUSTRAC may also suspend, cancel or refuse to renew a registration where the legal grounds for doing so are met.

Registration does not replace the provider’s other AML/CTF obligations. A registered VASP must still develop and maintain an AML/CTF program, conduct customer due diligence, monitor transactions, keep records and submit required reports.

What AML/CTF obligations apply to VASPs?

A VASP that provides designated services is a reporting entity for those services.

Its principal obligations may include:

  • developing and maintaining an AML/CTF program;

  • assessing its money laundering, terrorism financing and proliferation financing risks;

  • conducting initial and ongoing customer due diligence;

  • identifying beneficial owners and politically exposed persons;

  • screening for targeted financial sanctions;

  • monitoring customers and transactions;

  • conducting enhanced customer due diligence where required;

  • reporting suspicious matters and other reportable transactions;

  • complying with applicable travel rule requirements;

  • training staff;

  • keeping required records; and

  • arranging independent evaluations of its AML/CTF program.

These controls must reflect the actual risks of the service. A risk assessment for a custodial wallet provider should not simply reproduce one prepared for a conventional currency exchange.

When is enhanced customer due diligence required?

Enhanced customer due diligence applies when higher-risk circumstances arise.

Specific requirements apply where a customer deposits or receives physical currency as part of an exchange between virtual assets and money. These services present heightened money laundering and terrorism financing risks, particularly where crypto ATMs or similar physical cash channels are involved.

The reporting entity may need to collect and verify information about the customer’s source of funds. Where enhanced measures apply, it may also need information about the customer’s source of wealth.

The point is to understand where the physical currency came from and whether the explanation is consistent with the customer’s profile and activity.

Collecting an answer is not enough. The business must assess it.

What should you do?

  • Map every virtual asset service. Identify exchange, custody, transfer, wallet, brokerage and token-offering activities across the business and its related entities.

  • Assess the function, not the label. Review who controls assets and private keys, arranges exchanges, accepts transfer instructions and makes assets available to recipients.

  • Confirm whether registration is required. Determine whether each activity is a registrable virtual asset service and whether an exception applies.

  • Prepare registration material carefully. Check ownership, key-person, wallet, transaction and compliance information before making an application.

  • Update your ML/TF risk assessment. Address the particular assets, customers, countries, delivery channels and technologies involved in your services.

  • Connect custody design to your controls. Document who can access keys, approve transactions, restrict withdrawals and respond to compromised wallets.

  • Review customer due diligence. Make sure onboarding and monitoring address beneficial ownership, sanctions, source of funds, source of wealth and higher-risk activity.

  • Assess transfer obligations. Identify when your business acts as an ordering, beneficiary or intermediary institution and whether the travel rule applies.

  • Test the program after implementation. Review customer files, transaction alerts, transfer information and escalation decisions to check whether the controls work in practice.

The bottom line

Virtual asset regulation is based on services and functions, not business labels.

A business does not avoid the AML/CTF regime because it operates through software, deals only in virtual assets or does not hold itself out as an exchange. Custody, arrangement, transfer and token-offering functions can each bring a business within the regime.

Start with a detailed map of what the business actually does. Registration and compliance decisions should follow from that map.

Need help with AML/CTF regulation of virtual assets?

Dwyer Harris assists reporting entities and virtual asset businesses to identify, assess and meet their AML/CTF obligations.

We can help you:

  • determine whether your activities are designated or registrable virtual asset services;

  • assess whether you must enrol and register with AUSTRAC;

  • prepare or review a VASP registration application;

  • draft or review your ML/TF risk assessment;

  • develop AML/CTF policies for exchange, custody and transfer services;

  • review customer due diligence and transaction-monitoring controls;

  • assess virtual asset transfer and travel rule requirements;

  • review outsourcing, wallet and key-management arrangements;

  • conduct a post-implementation review of your AML/CTF controls; and

  • update your program following a new service, technology or regulatory change.

Our focus is on controls that meet the legal requirements, explain clearly what staff must do and reflect how the service works in practice.

Get in touch with Dwyer Harris if you need help assessing, registering or managing the AML/CTF obligations that apply to your virtual asset services.

Information only. Not legal advice.

Next
Next

AML/CTF customer due diligence (CDD) explained