AML Compliance Guide

Staff training for Virtual asset service providerss — 2026 AUSTRAC Guide

If your virtual asset business provides a designated service in Australia, staff training is a mandatory AML/CTF obligation from 1 July 2026. It applies because VASPs face higher money laundering and terrorism financing risks around fast transfers, cross-border activity, pseudo-anonymous transactions, withdrawals to self-hosted wallets and customer onboarding at scale. If your training is missing, generic or not matched to staff roles, AUSTRAC can treat that as a failure in your AML/CTF program, with civil penalties up to $33.5 million per contravention and criminal penalties for intentional breaches.

For a VASP, staff training is not just a one-off induction module. Your AML/CTF program must include documented training for all staff who deal with customers or handle relevant transactions, and it needs to reflect how your platform actually works. That means training should cover wallet onboarding, source-of-funds questions, blockchain tracing alerts, sanctions screening, suspicious matter escalation, transaction monitoring triggers, fiat on-ramps and off-ramps, and when enhanced due diligence is required for higher-risk customers such as PEPs or customers linked to high-risk countries.

What your VASP needs to do

  • Map which roles have AML/CTF responsibilities: onboarding teams, customer support, fraud and risk staff, transaction monitoring analysts, payments staff, compliance staff, senior management and relevant engineers or product staff.
  • Build training content around your ML/TF risk assessment and AML/CTF policies, not a generic crypto course. Staff should be trained on the risks tied to your own products, customer types, jurisdictions and transaction flows.
  • Deliver training at the right time: general awareness at onboarding for other personnel, role-specific training before staff perform AML/CTF functions, and refresher training on the schedule AUSTRAC expects.
  • Keep records of who was trained, when, what content was covered, how it was delivered and any assessment or sign-off completed.
  • Repeat and update training when your AML/CTF program changes, new risks emerge, AUSTRAC issues guidance, or internal reviews show gaps.

Training frequency AUSTRAC expects

AML/CTF compliance officers and senior management: every 6–12 months. Customer-facing personnel: every 12 months. Personnel responsible for onboarding, transaction monitoring or other enhanced CDD roles: every 12 months. Third-party vendors: when onboarded, and when the contract is renewed or changed. All other personnel not in AML/CTF-relevant roles: general awareness training at onboarding.

Common mistakes for VASPs are using an off-the-shelf training package, treating engineers and product staff as outside scope, and relying only on AUSTRAC e-learning. AUSTRAC says its modules can help, but they cannot be your sole training response because training must be tailored to the person, their AML/CTF functions, the risks relevant to that function and their responsibilities under your policies. If your support team can freeze an account, unblock a withdrawal, override a monitoring alert or communicate with a customer after a suspicious matter is escalated, they need training that matches those tasks.

Practical tips for virtual asset businesses

  • Use real internal case studies: structuring through multiple deposits, rapid movement from fiat to virtual assets, chain-hopping, mixers, privacy tools, withdrawals to self-hosted wallets and sanctions exposure.
  • Train staff on escalation lines so they know exactly when to stop processing, when to refer to compliance and how to avoid tipping off a customer if an SMR is being considered.
  • Include sanctions screening in every relevant workflow. Providing services to a sanctioned person is a strict-liability criminal offence.
  • If you outsource support, KYC review or monitoring, do due diligence on the provider and make sure their training is specific to your business, not just generic crypto compliance content.
  • Test understanding with short scenario-based assessments and retrain quickly where mistakes appear.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do our software developers need AML/CTF training if they never speak to customers?
If they are not in AML/CTF-relevant roles, they still need general awareness training at onboarding. If developers design or maintain controls that affect onboarding, sanctions screening, transaction monitoring, wallet withdrawals, alert handling or record keeping, they should receive role-specific training because their work directly affects compliance.
Can we just use AUSTRAC’s e-learning modules and treat that as done?
No. AUSTRAC says its modules can be used as part of your training, but not relied on solely to meet your obligation. Your training must be tailored to your staff roles, your products and services, your ML/TF risks and your own AML/CTF policies.
We outsource customer support and parts of KYC review overseas. Do those staff need training too?
Yes, if they perform AML/CTF-related functions for your business. AUSTRAC expects third-party vendors to be trained when onboarded and when the contract is renewed or changed, and you remain responsible for making sure the training is appropriate, understandable and aligned with your AML/CTF program.
How much will AML/CTF training cost a small VASP?
There is no government fee for the training obligation itself, but your costs will come from preparing tailored materials, staff time, learning systems, external providers and refresher sessions. A small VASP can control costs by using AUSTRAC guidance as a base, then adding short role-specific modules for onboarding, support, monitoring and management.
What evidence should we keep to prove training happened?
Keep training logs, attendance records, copies of course content, dates delivered, staff assessments, completion certificates and records showing updates after program changes or new risks. You should retain AML/CTF program documents and related records for 7 years after the relationship ends, and training records should be kept as part of that compliance file.