If your virtual asset business provides designated services in Australia, you must have a written AML/CTF program that matches how your platform, wallet, exchange, brokerage or transfer service is actually used. The program sets out your money laundering, terrorism financing and proliferation financing risks, and the controls you use to manage them, including customer onboarding, transaction monitoring, sanctions screening and suspicious matter escalation. If you do not have a compliant program in place by 31 December 2026, AUSTRAC can take enforcement action and civil penalties can reach $33.5 million per contravention, with criminal penalties for intentional breaches.
Your AML/CTF obligations
For a virtual asset service provider, the AML/CTF program is not a template you file away. It is the written rulebook for how your business accepts customers, verifies identity, screens wallets and users, monitors transfers, handles fiat on-ramp and off-ramp activity, detects unusual blockchain patterns, and decides when to stop a service or report to AUSTRAC. Your program must have two parts: your ML/TF risk assessment and the policies, procedures, systems and controls you use to manage those risks. Senior management must approve it, and it must reflect the real risks of your products, customer base, delivery channels and geographies.
What your business needs to do
Deadline
Your AML/CTF program must be finalised by 31 December 2026. You must complete the ML/TF risk assessment before the program is finalised, and the program must be approved by senior management.
The biggest mistake for virtual asset businesses is relying on a generic finance-sector manual that says nothing useful about blockchain activity. AUSTRAC expects a risk-based program that deals with the way value moves in your business. If you offer instant transfers to self-hosted wallets, allow rapid movement between tokens, onboard foreign customers remotely, or accept customers funded through multiple linked accounts, your controls need to address those features directly. Another common mistake is treating the AML/CTF program as separate from product design. If your platform architecture cannot flag unusual wallet clustering, repeated near-threshold cash behaviour through physical channels, or outbound transfers linked to sanctioned persons, your written program will not match your actual controls.
Practical tips for virtual asset businesses
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.