AML Compliance Guide

Sanctions screening for Virtual asset service providerss — 2026 AUSTRAC Guide

If you run a virtual asset service provider business in Australia, you must screen customers and related parties for targeted financial sanctions before you provide a designated service and keep checking during the relationship. This applies because crypto and wallet-based services can move value offshore quickly, making them attractive for sanctions evasion as well as money laundering. If you provide services to a sanctioned person or deal with frozen assets, you can face serious criminal consequences, and your AML/CTF program must show exactly how you prevent that.

For a virtual asset service provider, sanctions screening is not a one-off name check at onboarding. You must establish on reasonable grounds whether your customer, any beneficial owner, any person on whose behalf the customer is receiving the service, and any person acting on behalf of the customer is designated for targeted financial sanctions before you start providing the designated service. You must also monitor whether any of those people become designated later. In practice, that means screening account holders, controllers of company customers, authorised users, and anyone connected to a hosted wallet, exchange account, or transfer instruction where they are acting for someone else.

What your business needs to do

  • Build sanctions checks into onboarding before a customer can trade, open a wallet service, or send or receive value through your platform.
  • Screen against DFAT’s Consolidated List and use search settings that catch spelling variations, aliases and transliterations.
  • Identify beneficial owners and controllers of company, trust and other entity customers before screening them.
  • Re-screen during the relationship, especially before high-risk activity such as large transfers, offshore activity, wallet changes or unusual transaction patterns.
  • Escalate possible matches immediately, stop the service from proceeding until reviewed, and document the decision.

Do not release frozen assets

If you are, or think you may be, holding assets owned or controlled by a sanctioned person, do not deal with them and do not return them to the customer without a sanctions permit. AUSTRAC expects you to contact the Australian Sanctions Office and report the matter to the Australian Federal Police as soon as practicable.

Virtual asset businesses need a tighter process than many other sectors because sanctions risk can sit behind the visible customer. A clean onboarding ID check does not deal with wallet exposure, foreign counterparties, nested relationships, or complex entity structures. Your AML/CTF policies should cover when to use enhanced due diligence, such as for international customers, customers linked to countries known as intermediaries for sanctioned jurisdictions, complex ownership structures, and customers whose wallet activity suggests exposure to criminal or sanctioned activity. AUSTRAC guidance for crypto ATM providers also points to tailored controls such as ongoing monitoring, customer risk rating methods built for crypto activity, and blockchain tools to understand exposure of customer wallets to criminal activity.

Common mistakes for virtual asset providers

  • Only screening the named account holder and ignoring beneficial owners, authorised operators or the person behind the transaction.
  • Treating sanctions screening as complete once the customer passes onboarding, with no ongoing monitoring.
  • Relying on exact-name matching and missing alternative spellings of non-English names.
  • Letting deposits, swaps, wallet withdrawals or account reactivation proceed while a potential sanctions hit is still under review.
  • Assuming sanctions only matter for fiat transfers, not crypto-to-crypto services or wallet services.

A workable setup for a small or mid-sized provider is to automate list screening at onboarding and on a daily refresh, then add manual review rules for higher-risk alerts. Make sure staff know when to freeze action on an account, who reviews a possible match, how to record the reasoning, and when to escalate outside the business. If you also need to file a suspicious matter report, do not tell the customer you are considering or making that report. Your records of screening results, reviews and decisions must be kept for 7 years after the relationship ends.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I only need to screen the customer named on the account?
No. You must establish on reasonable grounds whether the customer, any beneficial owner, any person on whose behalf the customer receives the service, and any person acting on behalf of the customer is designated for targeted financial sanctions. For entity customers, that means you need ownership and control information before your screening process is complete.
Do I have to screen wallet addresses as well as names?
The core legal obligation is to establish whether relevant persons are designated for targeted financial sanctions. For a virtual asset business, wallet analysis is often a practical part of meeting that obligation, especially for higher-risk customers, foreign connections and unusual wallet activity. AUSTRAC guidance specifically refers to blockchain tools as an example of tailored enhanced due diligence for crypto risks.
What should I do if I get a possible match on the DFAT list?
Stop the service from proceeding until the match is reviewed properly. If the person is designated, you must not deal with the assets or make assets available to them without a sanctions permit, and you should contact the Australian Sanctions Office and report the matter to the Australian Federal Police as soon as practicable. Keep a clear record of the alert, review steps and final decision.
Can I outsource sanctions screening to a software provider and treat that as done?
You can use software, but the obligation stays with your business. You still need AML/CTF policies that explain how screening works, who reviews alerts, how ongoing monitoring happens, and what you do with potential matches or frozen assets. Software that only does exact-name matching is usually not enough for crypto businesses with international exposure.
Is there any exception for low-risk customers or small-value crypto transactions?
You still need to meet your targeted financial sanctions obligations before providing the designated service. AUSTRAC guidance says it may be appropriate to screen low-risk customers as part of delayed initial CDD in some cases, but that does not remove the need to establish on reasonable grounds whether relevant persons are designated for TFS. For virtual asset services, speed and offshore reach usually justify a cautious approach even for smaller transactions.