If you provide designated virtual asset services in Australia, you must have a written ML/TF risk assessment that is tailored to how your VASP actually operates. This applies because virtual asset businesses can be exploited to move value quickly, across borders, and sometimes with anonymity or pseudo-anonymity. If you do not do this properly, you risk building a non-compliant AML/CTF program, exposing the business to AUSTRAC enforcement, civil penalties of up to $33.5 million per contravention, and criminal penalties for intentional breaches.
Your AML/CTF obligations
Your risk assessment is the foundation of your AML/CTF program. It must be a written document that identifies and assesses the money laundering, terrorism financing and proliferation financing risks in your business before you finalise your AML/CTF program. For a VASP, that means looking closely at the virtual asset services you offer, the customers you onboard, the channels you use, and the countries you deal with. AUSTRAC guidance is clear that this must be tailored to your business and not copied from a template or written as if every service is low risk.
What your VASP risk assessment must cover
A practical way to do this is in three steps. First, identify your inherent risks before controls are applied. AUSTRAC’s VASP risk assessment framework says to pinpoint where your business could be exposed and focus on weaknesses. Second, assess those risks by asking how a criminal could misuse your services and what the impact would be. Third, evaluate and prioritise the risks so you can decide which ones need stronger controls in your AML/CTF policies. If you allow withdrawals to self-hosted wallets, transmit value into or out of Australia, or offer fast account opening through remote channels, those risks need to be called out directly.
Deadline and sequence
You must complete the ML/TF risk assessment before finalising your AML/CTF program. Your AML/CTF program must be finalised by 31 December 2026, so the risk assessment needs to be done first and kept up to date whenever your VASP changes materially.
Common mistakes for VASPs are predictable. The biggest is using an off-the-shelf risk assessment that barely mentions your actual products, wallet flows, cross-border activity or onboarding model. Another is treating all virtual asset customers as the same risk, instead of separating low-value domestic users from customers using self-hosted wallets, privacy-enhancing tools, foreign IP addresses, or unusual funding patterns. A third is forgetting that a business change triggers an update: launching a new token product, opening to offshore customers, adding fiat ramps, or changing custody arrangements means the assessment must be reviewed. Keep version history, reasons for changes, and records showing who reviewed and approved it.
Practical tips for a small VASP
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.