AML Compliance Guide
Deadline: 29 July 2026 — enforcement now active

Compliance officer for Virtual asset service providerss — 2026 AUSTRAC Guide

If you provide a virtual asset designated service with an Australian geographical link from 1 July 2026, you need an AML/CTF compliance officer as part of meeting your AUSTRAC obligations. This role matters because VASPs handle higher-risk services such as virtual asset exchanges, safekeeping and transfers on behalf of customers, and AUSTRAC expects clear accountability from day one. If you operate without proper governance in place, you risk regulatory action, civil penalties of up to $33.5 million per contravention, and criminal penalties for intentional breaches.

For a virtual asset service provider, the compliance officer is the person responsible for overseeing how your business meets its AML/CTF obligations in practice. That includes making sure customer due diligence happens before you provide designated services, sanctions screening is working, suspicious matter decisions are escalated quickly, and reporting to AUSTRAC is not missed. If you exchange virtual assets for money, exchange one virtual asset for another, provide wallet or safekeeping services, accept transfer instructions, or participate in the offer or sale of virtual assets, this role should be in place before you start providing those services.

Deadline you need to work to

Have your compliance officer appointed by 29 July 2026 if you will be providing newly regulated virtual asset designated services from 1 July 2026. If your business starts after 1 July 2026, do this before or as you begin providing the designated service, alongside AUSTRAC enrolment within 28 days. Waiting until your AML/CTF program is finalised on 31 December 2026 is too late for governance.

What a VASP should do now

  • Identify exactly which designated services you provide, such as item 50A exchange services, virtual asset-to-virtual asset exchange, safekeeping, or transfer services.
  • Appoint one person with enough seniority to make decisions, access records, direct staff, and escalate urgent issues like sanctions hits or suspicious matters.
  • Give that person authority over onboarding controls, blockchain or wallet monitoring processes, sanctions screening, AUSTRAC reporting, and staff training.
  • Record the appointment in writing, including the person’s role, reporting line, responsibilities, and authority to stop or delay a transaction.
  • Make sure customer-facing staff, operations staff and anyone handling transfers know when to escalate unusual wallet activity, mixer use, rapid in-and-out transfers, or attempts to avoid identification.
  • If you also provide remittance-style services or other regulated services, make sure the compliance officer covers those obligations too, including any separate registration requirements that apply to remittance or VASP services.

A common mistake in the virtual asset sector is treating the compliance officer as a nominal appointment. AUSTRAC expects a real decision-maker, not just the founder’s name on a document or an outsourced adviser with no operational control. Another mistake is assuming blockchain transparency replaces AML controls. It does not. Your compliance officer must be able to connect wallet activity to verified customers, monitor higher-risk behaviours like use of self-hosted wallets or chain-hopping, and make sure sanctions screening covers both the customer and relevant counterparties where your systems can identify them.

For small VASPs, the founder or operations lead may be the right person if they have enough time, authority and understanding of the business. Practical setup usually means giving the compliance officer direct access to onboarding files, transaction monitoring tools, wallet intelligence outputs, sanctions alerts, and AUSTRAC Online. They should also own the incident process for suspected sanctions breaches, SMRs within 3 business days, or within 24 hours if terrorism financing is suspected. If you use vendors for KYC, wallet screening or transaction monitoring, the compliance officer still remains responsible for making sure those tools are actually working for your business.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Can I appoint myself as the compliance officer if I run a small crypto exchange or wallet business?
Yes, if you genuinely have the seniority, authority and time to do the job. For a small VASP, the founder or director is often the practical choice, but you must be able to oversee onboarding, sanctions screening, reporting and escalation decisions. If you are too operationally stretched to review alerts and make timely decisions, appointing yourself on paper will not be enough.
Do I need a separate compliance officer for each virtual asset service I offer?
No. One compliance officer can cover multiple designated services if they can properly oversee all of them. The key question is whether that person can manage the risks across exchange, custody, transfer and token sale activity without gaps.
Can I outsource the compliance officer role to a consultant?
You can get outside help, but your business still needs a clearly accountable person with real authority over day-to-day compliance. If a consultant cannot direct staff, access systems, stop a transaction or approve escalation steps, they are not a complete substitute for an internal accountable officer. Outsourcing support does not transfer your legal responsibility.
What will this usually cost a VASP?
There is no AUSTRAC fee just for appointing a compliance officer. Your cost is usually internal time, training, governance setup, and possibly external advice or software access. For VASPs, the bigger expense often sits in customer verification, wallet screening, sanctions tools and transaction monitoring rather than the appointment itself.
What if my VASP has not enrolled with AUSTRAC yet but will start operating after 1 July 2026?
You should appoint the compliance officer before or as you begin providing the designated service, not after problems arise. AUSTRAC enrolment must happen within 28 days of first providing the service, but governance needs to be ready from the start because customer due diligence and sanctions screening apply before you provide the service. Leaving the role vacant creates immediate compliance risk.