If you provide a virtual asset designated service with an Australian geographical link from 1 July 2026, you need an AML/CTF compliance officer as part of meeting your AUSTRAC obligations. This role matters because VASPs handle higher-risk services such as virtual asset exchanges, safekeeping and transfers on behalf of customers, and AUSTRAC expects clear accountability from day one. If you operate without proper governance in place, you risk regulatory action, civil penalties of up to $33.5 million per contravention, and criminal penalties for intentional breaches.
Your AML/CTF obligations
For a virtual asset service provider, the compliance officer is the person responsible for overseeing how your business meets its AML/CTF obligations in practice. That includes making sure customer due diligence happens before you provide designated services, sanctions screening is working, suspicious matter decisions are escalated quickly, and reporting to AUSTRAC is not missed. If you exchange virtual assets for money, exchange one virtual asset for another, provide wallet or safekeeping services, accept transfer instructions, or participate in the offer or sale of virtual assets, this role should be in place before you start providing those services.
Deadline you need to work to
Have your compliance officer appointed by 29 July 2026 if you will be providing newly regulated virtual asset designated services from 1 July 2026. If your business starts after 1 July 2026, do this before or as you begin providing the designated service, alongside AUSTRAC enrolment within 28 days. Waiting until your AML/CTF program is finalised on 31 December 2026 is too late for governance.
What a VASP should do now
A common mistake in the virtual asset sector is treating the compliance officer as a nominal appointment. AUSTRAC expects a real decision-maker, not just the founder’s name on a document or an outsourced adviser with no operational control. Another mistake is assuming blockchain transparency replaces AML controls. It does not. Your compliance officer must be able to connect wallet activity to verified customers, monitor higher-risk behaviours like use of self-hosted wallets or chain-hopping, and make sure sanctions screening covers both the customer and relevant counterparties where your systems can identify them.
For small VASPs, the founder or operations lead may be the right person if they have enough time, authority and understanding of the business. Practical setup usually means giving the compliance officer direct access to onboarding files, transaction monitoring tools, wallet intelligence outputs, sanctions alerts, and AUSTRAC Online. They should also own the incident process for suspected sanctions breaches, SMRs within 3 business days, or within 24 hours if terrorism financing is suspected. If you use vendors for KYC, wallet screening or transaction monitoring, the compliance officer still remains responsible for making sure those tools are actually working for your business.
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.