AML Compliance Guide

ML/TF risk assessment for Virtual asset service providerss — 2026 AUSTRAC Guide

If you provide designated virtual asset services in Australia, you must have a written ML/TF risk assessment that is tailored to how your VASP actually operates. This applies because virtual asset businesses can be exploited to move value quickly, across borders, and sometimes with anonymity or pseudo-anonymity. If you do not do this properly, you risk building a non-compliant AML/CTF program, exposing the business to AUSTRAC enforcement, civil penalties of up to $33.5 million per contravention, and criminal penalties for intentional breaches.

Your risk assessment is the foundation of your AML/CTF program. It must be a written document that identifies and assesses the money laundering, terrorism financing and proliferation financing risks in your business before you finalise your AML/CTF program. For a VASP, that means looking closely at the virtual asset services you offer, the customers you onboard, the channels you use, and the countries you deal with. AUSTRAC guidance is clear that this must be tailored to your business and not copied from a template or written as if every service is low risk.

What your VASP risk assessment must cover

  • Services: for example exchange services, transfers into or out of Australia, withdrawals to self-hosted wallets, cash access points, and any product features that create anonymity or speed of movement
  • Customers: retail clients, corporate clients, trusts, high-volume traders, PEPs, customers using nominees, and customers with complex ownership or control structures
  • Delivery channels: app-based onboarding, web onboarding, API access, non-face-to-face verification, agents, introducers, and any outsourced onboarding or transaction monitoring arrangements
  • Geography: customer location, destination countries, exposure to higher-risk jurisdictions, and cross-border value movement

A practical way to do this is in three steps. First, identify your inherent risks before controls are applied. AUSTRAC’s VASP risk assessment framework says to pinpoint where your business could be exposed and focus on weaknesses. Second, assess those risks by asking how a criminal could misuse your services and what the impact would be. Third, evaluate and prioritise the risks so you can decide which ones need stronger controls in your AML/CTF policies. If you allow withdrawals to self-hosted wallets, transmit value into or out of Australia, or offer fast account opening through remote channels, those risks need to be called out directly.

Deadline and sequence

You must complete the ML/TF risk assessment before finalising your AML/CTF program. Your AML/CTF program must be finalised by 31 December 2026, so the risk assessment needs to be done first and kept up to date whenever your VASP changes materially.

Common mistakes for VASPs are predictable. The biggest is using an off-the-shelf risk assessment that barely mentions your actual products, wallet flows, cross-border activity or onboarding model. Another is treating all virtual asset customers as the same risk, instead of separating low-value domestic users from customers using self-hosted wallets, privacy-enhancing tools, foreign IP addresses, or unusual funding patterns. A third is forgetting that a business change triggers an update: launching a new token product, opening to offshore customers, adding fiat ramps, or changing custody arrangements means the assessment must be reviewed. Keep version history, reasons for changes, and records showing who reviewed and approved it.

Practical tips for a small VASP

  • Map the customer journey from onboarding to withdrawal and note where identity, source of funds, sanctions, and transaction monitoring risks arise
  • Separate hosted-wallet activity from withdrawals to self-hosted wallets and assess them differently
  • Document which transaction patterns are higher risk, such as rapid in-and-out movement, use of multiple accounts, large cash-linked activity, or cross-border transfers that do not fit the customer profile
  • Assign an owner for the document, review it when products or customer types change, and make sure senior management approves the final version

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need a separate risk assessment if my VASP only serves Australian customers?
You still need one. A domestic-only model may reduce some cross-border risk, but it does not remove the risks linked to virtual assets, remote onboarding, rapid movement of value, or withdrawals to self-hosted wallets. Your assessment should explain why certain risks are lower and why others still exist.
Can I buy a template risk assessment and use that?
You can use a template as a starting point, but the final document must be tailored to your business. AUSTRAC guidance warns that an off-the-shelf assessment that is not specific to your services will raise questions about whether you understand your ML/TF risks. You need to customise it to your products, customer types, channels and countries.
What counts as a material change that means I must update the assessment?
A material change is any change that alters your risk profile in a real way. For a VASP, that could include launching a new token or exchange service, adding fiat deposits or withdrawals, allowing transfers to self-hosted wallets, onboarding foreign customers, using a new onboarding provider, or changing custody arrangements. Update the document when the change happens, not months later.
How much will it cost to prepare the risk assessment?
The law does not set a fixed cost. If you do it internally, the main cost is management time, mapping your services, documenting risks, and reviewing AUSTRAC guidance. If you engage a consultant, the cost will depend on how complex your VASP is, but paying for a generic template alone will not solve the compliance problem.
We are very small and only offer one virtual asset service. Can our risk assessment be short?
Yes, it can be proportionate to the size and complexity of your business, but it still needs to be complete. A short document is acceptable if it clearly covers your service, customers, delivery channels and geography, identifies the real risks in your model, and is detailed enough to support your AML/CTF policies. Short does not mean vague.