If you run a virtual asset service provider business in Australia, you must screen customers and related parties for targeted financial sanctions before you provide a designated service and keep checking during the relationship. This applies because crypto and wallet-based services can move value offshore quickly, making them attractive for sanctions evasion as well as money laundering. If you provide services to a sanctioned person or deal with frozen assets, you can face serious criminal consequences, and your AML/CTF program must show exactly how you prevent that.
Your AML/CTF obligations
For a virtual asset service provider, sanctions screening is not a one-off name check at onboarding. You must establish on reasonable grounds whether your customer, any beneficial owner, any person on whose behalf the customer is receiving the service, and any person acting on behalf of the customer is designated for targeted financial sanctions before you start providing the designated service. You must also monitor whether any of those people become designated later. In practice, that means screening account holders, controllers of company customers, authorised users, and anyone connected to a hosted wallet, exchange account, or transfer instruction where they are acting for someone else.
What your business needs to do
Do not release frozen assets
If you are, or think you may be, holding assets owned or controlled by a sanctioned person, do not deal with them and do not return them to the customer without a sanctions permit. AUSTRAC expects you to contact the Australian Sanctions Office and report the matter to the Australian Federal Police as soon as practicable.
Virtual asset businesses need a tighter process than many other sectors because sanctions risk can sit behind the visible customer. A clean onboarding ID check does not deal with wallet exposure, foreign counterparties, nested relationships, or complex entity structures. Your AML/CTF policies should cover when to use enhanced due diligence, such as for international customers, customers linked to countries known as intermediaries for sanctioned jurisdictions, complex ownership structures, and customers whose wallet activity suggests exposure to criminal or sanctioned activity. AUSTRAC guidance for crypto ATM providers also points to tailored controls such as ongoing monitoring, customer risk rating methods built for crypto activity, and blockchain tools to understand exposure of customer wallets to criminal activity.
Common mistakes for virtual asset providers
A workable setup for a small or mid-sized provider is to automate list screening at onboarding and on a daily refresh, then add manual review rules for higher-risk alerts. Make sure staff know when to freeze action on an account, who reviews a possible match, how to record the reasoning, and when to escalate outside the business. If you also need to file a suspicious matter report, do not tell the customer you are considering or making that report. Your records of screening results, reviews and decisions must be kept for 7 years after the relationship ends.
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.