EST · MMXXVI
Home/Jurisdictions/Australia/Crypto exchange setup in Australia (AUSTRAC)
Licensing & Registration

Crypto exchange setup in Australia (AUSTRAC)

Crypto exchange setup in Australia (AUSTRAC). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Setting up a crypto exchange in Australia requires registration with AUSTRAC (the Australian Transaction Reports and Analysis Centre), the country's financial-intelligence regulator and AML/CTF supervisor for digital-asset businesses. Any business providing a digital currency exchange (DCE) service – converting fiat to crypto or crypto to crypto for customers – must register before it begins operating. Failure to register exposes the business to civil and criminal penalties, forced shutdown and permanent loss of banking relationships. This page sets out the registration basis, the practical process for an inbound operator, the cross-border banking and tax interaction, and the decision points that matter before you commit.

Who needs AUSTRAC registration to run a crypto exchange?

Any business that provides a digital currency exchange service in Australia must register with AUSTRAC under the applicable Anti-Money Laundering and Counter-Terrorism Financing Act provisions. The obligation attaches to the activity, not the corporate seat. A foreign-incorporated entity offering exchange services to Australian customers is caught. So is an Australian company operating offshore rails. The two relevant categories under the AUSTRAC regime are DCE providers and digital currency transfer providers. Most exchange businesses fall within the DCE category; those that also transmit digital currency between parties may carry an additional obligations profile. AUSTRAC registration is not a discretionary step – it is the threshold condition for lawful operation.

The question of which legal entity registers matters for an inbound business. Operators we advise often arrive with an offshore holding structure and a plan to serve Australian users through an agent or white-label arrangement. AUSTRAC's position is that the entity actually providing the designated service must be the registrant. Operating through an intermediary does not transfer the registration obligation. We regularly advise on how to structure the Australian-facing entity so that the registration sits in the right place, the AML/CTF program runs at the right level, and the parent group's banking relationships are not exposed to unintended risk.

The registration obligation also triggers a mandatory AML/CTF program – a written document covering risk assessment, customer due diligence, transaction monitoring, suspicious matter reporting and staff training. That program must be in place before the business accepts its first customer. Many inbound operators underestimate how much substance that requirement demands.

Next step for a business at the threshold: understanding whether registration is required is only the first question. The structure of the Australian entity, its ownership, its product scope and its user base all affect what the program must contain and how banking will respond to it. To map whether your proposed structure triggers registration – and what that means for your build – contact OBOLUS at info@oboluslaw.com.

What does the AUSTRAC registration process involve for an exchange?

AUSTRAC registration for a DCE provider follows a defined administrative process, but it carries substantive compliance obligations that go well beyond filing a form. The regulator reviews ownership, control, beneficial ownership, the business model and the AML/CTF program. Incomplete or inconsistent applications draw requests for information that extend the timeline significantly.

In practice, the process unfolds in three layers. The first is corporate readiness: the Australian entity must exist, its directors and ultimate beneficial owners must be identified, and the ownership chain must be documented to a standard that satisfies both AUSTRAC and, separately, the business's banking partner. The second is program readiness: the AML/CTF program must be drafted, risk-assessed and board-approved before submission. The third is the submission itself, which involves providing detailed information about the services offered, the customer base, the countries of operation, and the transaction monitoring approach.

Timelines vary depending on application completeness and regulatory workload. A well-prepared submission with a complete AML/CTF program and clean ownership documentation typically moves faster than one that triggers back-and-forth. Operators we advise are told to plan for a process measured in weeks rather than days for a straightforward application – and longer where the ownership structure is complex or where the product touches higher-risk categories such as peer-to-peer exchange or privacy-enhanced tokens.

One detail that catches inbound businesses by surprise: AUSTRAC registration does not confer a licence in the financial-services sense. It is an AML/CTF registration. A business also needs to assess whether its exchange activity constitutes a financial service under the Corporations Act, which would require an Australian Financial Services Licence (AFSL) or an exemption. The two regimes run in parallel. Missing the AFSL question while focusing on AUSTRAC is a common structural error.

How does an AML/CTF program work for an Australian crypto exchange?

An AML/CTF program is the operational heart of the AUSTRAC compliance obligation, and its adequacy is the primary basis on which AUSTRAC assesses and, later, supervises a registered DCE. The program must be risk-based, written, and proportionate to the nature of the business. A high-volume retail exchange has a materially different program than a low-volume OTC desk serving institutional clients.

Core elements include a money-laundering and terrorism-financing risk assessment, customer identification and verification procedures (the Australian equivalent of KYC), ongoing customer due diligence for higher-risk relationships, transaction monitoring rules and thresholds, suspicious matter reporting procedures, and an AML/CTF compliance officer designation. AUSTRAC also expects a designated business group (DBG) structure where the exchange is part of a corporate group – meaning the compliance program must align across the group, not just at the Australian entity level.

The Travel Rule – the obligation to pass originator and beneficiary data with a virtual-asset transfer – applies in Australia under the AML/CTF framework. The specific thresholds and technical requirements have evolved with international FATF guidance. Operators building transfer functionality into their exchange need to ensure their systems can capture, transmit and receive the required data. This is an area where technology decisions made early in the build have long compliance tails.

In a recent licensing matter, a payments technology business expanding its Australian operations engaged us to audit its draft AML/CTF program before submission. The draft was materially incomplete on transaction monitoring logic and lacked a workable suspicious matter reporting escalation path. We rebuilt those components, aligned the program with the group's existing FATF-compliant framework in another jurisdiction, and the submission proceeded without a request for further information. The business was registered within the expected window.

Cross-border banking for an Australian crypto exchange: what operators need to know

Banking is the single most consequential operational variable for an Australian crypto exchange, and it is the area where the gap between legal registration and commercial viability is most starkly visible. AUSTRAC registration is necessary but not sufficient. A registered DCE that cannot open or maintain an Australian bank account cannot operate a meaningful fiat on-ramp.

Australian banks have applied heightened scrutiny to DCE clients for some years. Approval rates, documentation requirements and account conditions vary significantly across institutions. In our cross-border practice, we see a consistent pattern: operators who approach banking after registration, without a prepared banking package, face delays of months and frequent rejections. Operators who prepare their AML/CTF program, their beneficial ownership documentation and their business-plan narrative for a banking audience before they approach the first institution fare considerably better.

The cross-border dimension is particularly acute for an exchange that settles in multiple currencies or routes settlement through an offshore treasury entity. Australian banks conduct their own due diligence on the group structure. A complex offshore holding arrangement – common among exchanges that have licensed in multiple jurisdictions – requires a clear, documented explanation of fund flows, the role of each entity, and the compliance posture at each level. We map that narrative as part of the banking preparation process, because a bank's compliance team and a regulator read the same documents differently.

For businesses that maintain a treasury function outside Australia – common where the group has a MiCA-authorised entity in the EU or a VARA-licensed entity in Dubai – the interaction between the Australian DCE registration and the offshore entity's regulatory obligations adds a layer. Transfer pricing, the allocation of revenue between entities and the currency of settlement all carry both tax and banking implications that must be resolved before go-live. We work through those interactions with allied counsel in the relevant jurisdictions.

If your banking approach has stalled or a previous application was declined, the structural reason is usually identifiable. A second read of the ownership documentation and the AML/CTF program against the bank's published risk appetite can surface it. Contact OBOLUS at info@oboluslaw.com to map the path forward.

Tax and structuring considerations for an inbound exchange setting up in Australia

Tax treatment for digital-asset businesses in Australia is determined primarily by the ATO (Australian Taxation Office) and depends on the characterisation of the exchange's activities and the tokens it handles. The core questions – whether exchange gains are income or capital, how GST applies to crypto transactions, and how the holding entity interacts with the Australian tax residency rules – are each fact-specific and consequential.

The ATO has published guidance on the tax treatment of digital assets for businesses and individuals, but that guidance does not resolve every edge case for a multi-product exchange. Staking rewards, liquidity provision, token issuance, margin products and derivative-like instruments each carry distinct characterisation questions. An exchange that processes a wide product range needs a clear tax analysis at the product level before it prices those products to customers.

For an inbound operator, the Australian entity's tax residency and the characterisation of its relationship with the offshore parent are equally critical. Australia's controlled foreign company rules and transfer pricing regime apply to transactions between related parties. Where the Australian DCE is a subsidiary of a group that holds intellectual property, licenses a brand, or provides settlement services offshore, those intragroup arrangements require documentation at arm's length.

GST treatment of crypto-to-fiat conversion has been clarified over successive ATO guidance cycles. The current position treats digital currency as a form of money for GST purposes in defined circumstances, which affects whether the exchange's margin is GST-exempt or subject to the general rate. That distinction matters materially to the business's cost base and pricing model.

We map the licence, banking and tax stack together because decisions made at the structuring stage – which entity holds the Australian registration, where treasury sits, how IP is licensed – determine the efficiency and the risk profile of the operating model for years.

How does Australia compare for an inbound crypto exchange operator?

Australia is a mature, well-regulated market with a sophisticated retail and institutional crypto user base. AUSTRAC registration is administratively achievable for a well-prepared operator. The regime is principles-based in the AML/CTF sense – it does not prescribe every control – which gives an experienced compliance team room to build a proportionate program. That is a genuine advantage over more prescriptive regimes.

The constraints are real. Banking is harder than in some comparable markets. The parallel AFSL question adds complexity that pure AML/CTF registration regimes in other jurisdictions do not impose. The ATO's approach to digital assets is active and detailed. And the Travel Rule implementation requires technical investment that smaller operators sometimes underestimate.

For a business deciding between Australia and, say, a MiCA-authorised base in the EU or a MAS-licensed operation in Singapore, the decision turns on the target customer base, the product suite and the group's existing regulatory footprint. Australia offers direct access to a large domestic market and a common-law legal environment familiar to international businesses. It does not offer the passporting benefits of MiCA or the reputational signal of an MAS licence in certain institutional contexts.

In our practice, the operators best positioned for Australia are those with genuine Australian market intent – not those seeking a soft-touch entry point. AUSTRAC is an active, well-resourced supervisor. Operators who treat the registration as a compliance checkbox rather than as the beginning of a supervised relationship encounter difficulty. Those who invest in a substantive program from day one build durable regulatory capital.

A profile-based view: a retail exchange targeting the Australian domestic market directly should prioritise the AUSTRAC registration and AFSL analysis in parallel, prepare a bank-ready ownership and compliance package before approaching any institution, and build Travel Rule capability into the platform from the outset. A group that already holds a MiCA CASP authorisation and is adding Australia as a new market should assess whether its existing group AML/CTF framework can be adapted to the AUSTRAC standard or requires a standalone program. An offshore institutional OTC desk considering an Australian presence should resolve the AFSL question first – the DCE registration may be the secondary issue.

Common mistakes when setting up a crypto exchange in Australia

The most consequential mistake is treating AUSTRAC registration as the only compliance question. A surprising number of inbound operators arrive focused entirely on the DCE registration and have not assessed the AFSL issue, the tax residency of the Australian entity, or the banking implications of their offshore group structure. By the time those gaps surface, the entity is registered but commercially stranded.

The second common error is drafting the AML/CTF program in-house without reference to AUSTRAC's current supervisory expectations. AUSTRAC publishes guidance and has taken enforcement action against registered DCEs for inadequate programs. An AML/CTF program that meets the minimum documentary standard but lacks workable transaction monitoring logic or realistic suspicious matter reporting procedures is a compliance liability, not a compliance asset.

The third error is sequencing. Some operators register first and approach banking second. Others negotiate banking terms before they have a finalised AML/CTF program to show the bank's compliance team. The correct sequence – entity formation, program drafting, banking preparation, registration submission, banking approach – is not intuitive, and the costs of getting it wrong are measured in months of delay.

A common assumption we hear is that a single offshore registration – in, say, the BVI or a small EU member state – is sufficient to serve Australian customers without triggering local obligations. That assumption is incorrect. AUSTRAC's reach is activity-based. Where an Australian customer is being served, the registration obligation is engaged regardless of where the entity is incorporated. Operating without registration while relying on an offshore licence is one of the cleaner enforcement risk profiles we see in the market.

Self-assessment checklist for an operator considering Australia

Before engaging counsel, an operator can pressure-test its readiness against the following questions. A "no" or "unsure" on any of these is a flag that the structure needs work before submission.

  • Is the proposed Australian entity properly incorporated and is its ownership chain fully documented to the ultimate beneficial owner level?
  • Has the scope of designated services been clearly defined, and has the AFSL question been assessed independently of the AUSTRAC question?
  • Is there a drafted, risk-assessed AML/CTF program that addresses transaction monitoring, customer due diligence and suspicious matter reporting at the product level?
  • Has a designated AML/CTF compliance officer been identified, and does that person have adequate authority and resource within the business?
  • Have the group's offshore entities and their regulatory status been documented in a form that a bank's compliance team can follow?
  • Has the tax characterisation of the exchange's core products been assessed by reference to current ATO guidance?
  • Has Travel Rule capability been assessed against the technical standard applicable in Australia, and has a compliant implementation been scoped?
  • Has banking been approached with a prepared package, not cold?

Operators who can answer yes to all eight are in a strong position to move. Those who cannot should resolve the gaps before submission – not after.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

For an AUSTRAC DCE registration, a well-prepared application with complete ownership documentation and a finalised AML/CTF program typically resolves in a matter of weeks. Incomplete applications, complex beneficial ownership chains or higher-risk product scopes extend the timeline, sometimes significantly. The parallel AFSL process, where required, runs on a separate timetable and is generally longer. Other jurisdictions – Singapore, Dubai, Malta under MiCA – each carry distinct timelines that depend on application quality and current regulatory workload.

Which jurisdiction is best for licensing my crypto business?

There is no single answer. The right jurisdiction depends on your target market, product suite, existing group structure and banking relationships. Australia offers direct access to a large domestic market under a principles-based AML/CTF regime, but requires careful management of the parallel AFSL question and active banking preparation. MiCA passporting suits a business targeting EU customers. MAS in Singapore offers institutional credibility for Asia-Pacific reach. VARA in Dubai fits a business building a Middle East presence. We map the full licence, banking and tax stack across your operating model before recommending a structure.

Do I need a separate custody licence?

In Australia, the AUSTRAC DCE registration covers the exchange activity. If your exchange also holds client assets – whether fiat or digital – on a custodial basis, the AFSL analysis becomes more pointed: custodying financial products for clients is a regulated financial service in its own right. Whether your custody activity is caught depends on how the assets are characterised under the Corporations Act. In jurisdictions such as Dubai (VARA), the EU (MiCA) and Singapore (MAS), custody is a separately licensed activity. A multi-jurisdictional exchange holding client assets across several markets needs the custody question answered jurisdiction by jurisdiction.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – because the structure you build at the start determines the regulatory and commercial risk you carry for years. To discuss your Australian exchange setup or any cross-border licensing question, contact us at info@oboluslaw.com or via t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialist in inbound exchange registration, multi-jurisdiction licence stacks and AML/CTF program design for digital-asset businesses across the Asia-Pacific and Gulf regions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours