If your virtual asset service provider business provides a designated service in Australia, you must keep AML/CTF records for 7 years. For a VASP, that means records that show who your customer was, what service you provided, and enough transaction detail to reconstruct crypto-to-fiat, crypto-to-crypto, custody, transfer or other relevant activity. If you cannot produce those records when AUSTRAC asks, you may be treated as non-compliant with the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth), with civil penalties of up to $33.5 million per contravention and criminal penalties for intentional breaches.
Your AML/CTF obligations
Record keeping is not just saving a few screenshots from your platform. You must make and keep records that are reasonably necessary to show you are meeting your AML/CTF obligations, and records that are sufficient to reconstruct each designated service transaction. For a VASP, that usually includes customer onboarding records, wallet and account identifiers, blockchain transaction hashes, fiat funding details, timestamps, asset type and amount, recipient details where available, internal approval records, sanctions screening results, and any customer-provided transaction documents such as signed instructions, order forms or transfer requests.
What your VASP should do in practice
Format and storage matter
AUSTRAC expects records to be kept in their original format or the format you usually use. If your exchange data sits in CSV, database tables, wallet logs, API logs or chat-based support records, keep them in a form that preserves structure and usability. Records should be in English, or easily translated into English, securely stored, backed up, and accessible quickly if AUSTRAC requests them.
A common mistake for VASPs is assuming the blockchain is the record, so the business does not need to keep its own files. On-chain data alone is not enough because it usually does not show the customer behind the wallet, the reason for the transfer, internal risk decisions, linked fiat movement, or documents the customer provided. Another mistake is keeping only front-end transaction summaries and not preserving raw system logs, support tickets, sanctions alerts, or manual review notes that explain how a suspicious transfer, unusual wallet pattern or PEP escalation was handled.
Practical controls that work for VASPs
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.