AML Compliance Guide

AML/CTF program for Virtual asset service providerss — 2026 AUSTRAC Guide

If your virtual asset business provides designated services in Australia, you must have a written AML/CTF program that matches how your platform, wallet, exchange, brokerage or transfer service is actually used. The program sets out your money laundering, terrorism financing and proliferation financing risks, and the controls you use to manage them, including customer onboarding, transaction monitoring, sanctions screening and suspicious matter escalation. If you do not have a compliant program in place by 31 December 2026, AUSTRAC can take enforcement action and civil penalties can reach $33.5 million per contravention, with criminal penalties for intentional breaches.

For a virtual asset service provider, the AML/CTF program is not a template you file away. It is the written rulebook for how your business accepts customers, verifies identity, screens wallets and users, monitors transfers, handles fiat on-ramp and off-ramp activity, detects unusual blockchain patterns, and decides when to stop a service or report to AUSTRAC. Your program must have two parts: your ML/TF risk assessment and the policies, procedures, systems and controls you use to manage those risks. Senior management must approve it, and it must reflect the real risks of your products, customer base, delivery channels and geographies.

What your business needs to do

  • Map your designated services first. Work out exactly which parts of your virtual asset business trigger AML/CTF obligations, such as exchange, transfer or custody-related services, rather than assuming every activity is covered in the same way.
  • Complete a written ML/TF risk assessment before you finalise the program. Rate risks across customer types, transaction size and frequency, wallet behaviour, use of mixers or privacy-enhancing tools, cross-border exposure, fiat funding methods and high-risk jurisdictions.
  • Write the operational controls your staff and systems must follow. Include customer due diligence, beneficial owner checks for companies and trusts, sanctions screening, PEP handling, ongoing monitoring, SMR escalation, IFTI reporting and record retention.
  • Get senior management approval and train staff on the final program. Your analysts, onboarding team, customer support staff and anyone handling transactions need documented training on what to do and when to escalate.
  • Review and update the program when your business changes materially, such as listing new tokens, adding wallet products, integrating a new payment rail, outsourcing KYC, or expanding into new countries.

Deadline

Your AML/CTF program must be finalised by 31 December 2026. You must complete the ML/TF risk assessment before the program is finalised, and the program must be approved by senior management.

The biggest mistake for virtual asset businesses is relying on a generic finance-sector manual that says nothing useful about blockchain activity. AUSTRAC expects a risk-based program that deals with the way value moves in your business. If you offer instant transfers to self-hosted wallets, allow rapid movement between tokens, onboard foreign customers remotely, or accept customers funded through multiple linked accounts, your controls need to address those features directly. Another common mistake is treating the AML/CTF program as separate from product design. If your platform architecture cannot flag unusual wallet clustering, repeated near-threshold cash behaviour through physical channels, or outbound transfers linked to sanctioned persons, your written program will not match your actual controls.

Practical tips for virtual asset businesses

  • Build onboarding rules around your actual customer types: retail traders, high-volume corporate users, OTC clients, DAO-related structures or foreign entities all need different levels of scrutiny.
  • Document how blockchain analytics, sanctions screening tools and transaction monitoring alerts fit together, including who reviews alerts and how quickly decisions must be made.
  • Set clear rules for self-hosted wallets, third-party wallet deposits and source-of-funds questions where transaction patterns do not match the customer profile.
  • Keep version control on your program. If you change a token listing policy, wallet product, jurisdiction settings or onboarding vendor, update the program and retrain staff.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need an AML/CTF program if my business is only online and has no shopfront in Australia?
Yes, if you provide a designated service in Australia, being online-only does not remove the obligation. Your program should address remote onboarding, digital identity verification, cross-border customer risk and the way your platform monitors online transactions and wallet activity.
Can I use a generic compliance template bought from a consultant?
You can use a template as a starting point, but it will not be enough unless it is rewritten to fit your virtual asset services. Your program must reflect your own products, customer base, blockchain risks, reporting lines, systems and escalation process.
What if I outsource KYC, sanctions screening or blockchain monitoring to a vendor?
You still remain responsible for compliance. Your program should state what the vendor does, what your business checks, how exceptions are handled, who reviews alerts, and how you make sure outsourced controls are working properly.
How much will it cost to put an AML/CTF program in place?
There is no government fee to create the program itself, but most virtual asset businesses will have internal setup costs and may need spending on ID verification, sanctions screening, blockchain analytics, legal review and staff training. The cost depends on your size, transaction volume, products and whether you build controls in-house or outsource them.
If we add a new token or launch a wallet product after the program is approved, do we need to rewrite it?
You must update the ML/TF risk assessment and the program whenever your business changes materially. A new token, custody feature, transfer tool, payment method or overseas market can change your risk profile, so your controls and staff training need to be updated to match.