Customer due diligence means knowing who your customer is before you let them use your virtual asset service. It applies to virtual asset service providers because you are accepting instructions, exchanging virtual assets, providing safekeeping, or participating in offers or sales of virtual assets that are designated services under the AML/CTF Act. If you provide a designated service without completing customer due diligence when required, you risk AUSTRAC enforcement, civil penalties of up to $33.5 million per contravention, and criminal penalties for intentional breaches.
Your AML/CTF obligations
From 1 July 2026, customer due diligence applies to virtual asset service providers that provide designated services with an Australian geographical link. In practice, that means you must collect and verify the customer's identity before you start providing the designated service. For an individual, verify their full name, date of birth and residential address against government-issued ID. For a company, verify its ABN or ACN, legal name and company type through ASIC. For a trust, identify the trustee, review the trust deed and identify the beneficial owners. A beneficial owner is the natural person who owns 25% or more, or who exercises effective control.
CDD starts before the service starts
You must complete necessary steps to know your customer before you start to provide them with a designated service. For most virtual asset service providers, this means before you activate trading, execute a transfer, open a hosted wallet or custody account, or let the customer participate in a token offer or sale you are involved in.
What a virtual asset service provider should do
The biggest mistake for this sector is treating wallet addresses as if they are the customer. They are not. A blockchain address, device fingerprint or email address does not replace identity verification of the person or entity behind the service use. Another common error is onboarding first and planning to verify later. That does not meet the requirement. If you use app-based onboarding, outsourced KYC vendors or offshore operations, you still remain responsible for making sure the checks are done properly and that your records can be produced to AUSTRAC.
Set your process up around risk. Low-friction onboarding may be appropriate for lower-risk retail customers, but you need stronger checks where the risk is higher. For example, if a customer wants rapid movement of value in and out of Australia, uses privacy-enhancing tools, is linked to high-risk geographies, or is using a company or trust with layered ownership, step up your scrutiny. Ask for source-of-funds information, confirm control of the entity, and review whether the activity fits the customer's profile. Your CDD process should connect to your suspicious matter reporting workflow so staff know when identity issues, sanctions matches or unusual transfer patterns need escalation.
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.