EST · MMXXVI
Home/Jurisdictions/Australia/EMI licence for crypto firms in Australia (AUSTRAC)
Licensing & Registration

EMI licence for crypto firms in Australia (AUSTRAC)

Emi licence for crypto firms in Australia (AUSTRAC). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS

Operating a crypto exchange, digital-wallet service or payment platform in Australia without the right registration exposes the business to enforcement action from AUSTRAC (the Australian Transaction Reports and Analysis Centre), frozen correspondent-banking rails and the practical impossibility of maintaining domestic bank accounts. The stakes are not theoretical. AUSTRAC has demonstrated a willingness to pursue significant civil penalty proceedings against major financial institutions, and the agency applies the same supervisory posture to digital-currency exchanges registered on its roll.

Australia does not issue a general EMI licence (electronic money institution licence) in the European sense. The correct instrument for a crypto firm operating in Australia is AUSTRAC registration as a Digital Currency Exchange (DCE) provider – a mandatory compliance obligation under the applicable anti-money-laundering and counter-terrorism financing legislation. Firms providing certain payment functions may additionally require an Australian Financial Services Licence (AFSL) or registration under the payments licensing regime administered by the Australian Securities and Investments Commission (ASIC). This page maps both obligations, explains the registration process and its timeline, addresses the cross-border realities a foreign operator faces and identifies the decision point at which legal counsel makes the difference.

The analysis that follows moves from the regulatory perimeter, through the application process and AML/CTF programme requirements, to the banking and tax interaction that frequently catches inbound businesses off-guard.

What regulatory regime governs crypto firms in Australia?

AUSTRAC is the Australian government's financial intelligence agency and AML/CTF supervisor. Under the applicable AML/CTF legislation, any person who carries on a business of providing digital currency exchange services – converting fiat currency to digital currency or vice versa – must register with AUSTRAC before commencing that business. Registration is not optional and not a formality. Providing a DCE service without registration is a criminal offence carrying serious penalties, and operating in breach of ongoing AML/CTF programme obligations compounds that exposure.

The regime defines digital currency broadly to cover cryptocurrencies and similar cryptographic tokens that are not already regulated as fiat currency. This captures Bitcoin, Ether and most fungible utility tokens. Non-fungible tokens and tokenised securities are assessed on their own characteristics, and operators whose model touches securities law will face a parallel ASIC analysis under the Corporations Act framework.

AUSTRAC sits within Tier 1 of the global regulatory hierarchy for crypto supervision. It is an FATF-member body, and its AML/CTF standards reflect the FATF Recommendations – including Recommendation 15 on virtual assets and the Travel Rule obligation to pass originator and beneficiary data with qualifying transfers. Australia's Travel Rule implementation timeline and de-minimis threshold remain subject to current legislative guidance, so operators should treat this requirement qualitatively at the planning stage and confirm current thresholds with counsel.

Who needs an AUSTRAC DCE registration?

Any business – domestic or foreign – that provides a digital currency exchange service to customers located in Australia, or that otherwise carries on that business within Australia's jurisdiction, must register. The nexus test is functional, not formal: a BVI or Cayman entity with Australian users, an Australian-resident customer support team or Australian-domiciled servers may all trigger the obligation. A foreign firm cannot sidestep AUSTRAC by booking trades offshore if the customer relationship and the exchange activity are effectively conducted in Australia.

The registration obligation applies to the entity operating the business, not to a holding company or a technology provider sitting above it. Operators running a multi-entity group structure – a common design for exchanges seeking to separate the operating risk from the intellectual property holding – must identify which entity in the chain is the registered provider and ensure that entity is the one interfacing with Australian customers.

Beyond the DCE obligation, firms that hold or transfer digital assets on behalf of clients may engage the AFSL framework administered by ASIC if those assets constitute financial products. The ASIC analysis turns on the economic substance of the token – its rights, its promise, the expectations it creates – rather than its label. In our practice, we routinely see token issuers and exchange operators underestimate ASIC exposure and then face a parallel remediation process alongside the AUSTRAC registration.

A common assumption is that AUSTRAC registration covers every regulatory obligation a crypto firm faces in Australia. It does not. ASIC, APRA and the Reserve Bank of Australia each have jurisdiction over defined activities. An operator whose model touches payment services, deposit-taking or financial product distribution needs to scope each layer independently before launch.

For a scoped assessment of your Australian regulatory perimeter, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options

How does the AUSTRAC DCE registration process work?

The AUSTRAC DCE registration process is conducted online through AUSTRAC's regulatory portal and follows a defined sequence of steps that a prepared applicant can complete in a matter of weeks, though the full compliance build typically takes longer.

The first step is confirming the registrable entity. The entity that will hold the registration must be legally constituted – whether as an Australian company registered with ASIC, a registered foreign company or another recognised form. Foreign companies operating through a branch or subsidiary should take legal advice on which structure best serves the banking and liability profile before incorporating.

The second step is preparing the AML/CTF programme. Every registered DCE provider must have a written AML/CTF programme in place before registration is granted. The programme must cover, at minimum: a customer identification and verification framework (the KYC architecture); an ongoing customer due-diligence methodology; transaction monitoring logic; a suspicious matter reporting process; record-keeping procedures; and an employee training scheme. AUSTRAC publishes guidance on programme content, and the agency conducts assessments of programme quality as part of its supervisory cycle. A thin programme filed to meet the deadline and then ignored is a significant compliance risk.

The third step is the registration application itself. Applicants disclose the identity of the beneficial owner, key personnel and the business model. AUSTRAC can refuse registration where it is not satisfied with the fitness of the applicant or the adequacy of the AML/CTF programme. Once the application is accepted and registration granted, the firm's name appears on AUSTRAC's public register. Registration is not a licence to ignore the underlying compliance obligations – it is the gateway to an ongoing supervisory relationship.

In terms of timeline, the registration application itself can be submitted and processed relatively quickly once the programme and supporting materials are ready. The bottleneck is almost always the AML/CTF programme build and the internal compliance infrastructure, not AUSTRAC's processing time. Operators who try to file without a developed programme routinely receive a request for further information that extends the process materially.

What does a compliant AML/CTF programme require?

A compliant AML/CTF programme under the AUSTRAC regime is a substantive operational document, not a boilerplate policy file. AUSTRAC expects the programme to be risk-based, meaning the controls applied to a customer or transaction type should be proportionate to the assessed risk that customer or transaction type presents. A high-volume retail exchange with anonymous on-boarding and minimal transaction monitoring will not satisfy that expectation.

The KYC architecture must support customer identification before a business relationship is established and ongoing due diligence as the relationship continues. For a crypto exchange, this typically means a tiered verification model: a lower tier for small-value or low-risk activity, with enhanced due diligence triggered for higher-risk profiles, large transactions or customers from high-risk jurisdictions. AUSTRAC's published risk guidance and FATF country assessments feed the risk-rating logic.

Transaction monitoring must be capable of identifying patterns consistent with money laundering, terrorism financing or sanctions evasion. On-chain analytics tools – the kind operated by specialist forensics providers – are increasingly integrated into exchange compliance stacks to supplement traditional rule-based monitoring. AUSTRAC has signalled that it expects the monitoring logic to keep pace with the products offered. A firm adding staking, lending or derivatives needs to revisit its monitoring calibration each time the product set expands.

The Travel Rule – the obligation to pass originator and beneficiary data with a virtual-asset transfer – is an area of active development in Australia. Operators should build their technical architecture with Travel Rule capability in mind, even where the domestic threshold has not yet crystallised, because retrofitting a compliant messaging layer into a live system is significantly more expensive than designing for it from the start.

In a recent matter, a payments-adjacent firm had operated for several months before identifying that its transaction monitoring rules had not been calibrated for the specific token pairs it was trading. We worked with the firm to conduct a look-back review, remediate the programme gaps and prepare a voluntary disclosure to AUSTRAC. The outcome was a structured supervisory engagement rather than an enforcement referral – a result that required early action and transparent engagement with the regulator.

How does the cross-border reality affect Australian operations?

Foreign operators entering Australia face a banking problem that predates the licence question. Australian banks apply rigorous correspondent-banking policies to crypto-facing customers. A new DCE registrant without a domestic operating history, local directors or a demonstrated compliance track record will find that major retail banks are reluctant to open or maintain business accounts. This is not unique to Australia – it mirrors the dynamic in Singapore, Hong Kong and the UK – but it is more acute for inbound operators who have no prior relationship with the Australian banking market.

The banking solution typically requires a combination of: a local director or a locally established entity with a credible compliance posture; engagement with a banking partner that has an established crypto-business policy; and, increasingly, a non-bank payment provider as a bridge while the primary banking relationship is developed. Operators who arrive in Australia having already secured banking in a comparable jurisdiction – Singapore or a leading EU hub – are better positioned to demonstrate the compliance baseline that Australian banks expect.

The tax interaction adds a second layer of planning. Australia taxes digital-asset disposals as capital gains events under the tax framework administered by the Australian Taxation Office (ATO). For a business operating an exchange, every crypto-to-fiat trade or crypto-to-crypto swap executed by the platform may have tax characterisation consequences for the firm's own balance sheet – particularly where the firm holds inventory or makes markets. GST treatment of digital currency services has been modified to exempt digital currency from double-taxation, but the boundaries of that exemption are technical. Getting the tax position wrong at the point of structuring the entity and the booking model creates a remediation problem that is expensive to fix retrospectively.

For a business sitting between a Singapore parent and an Australian operating entity, the legal question turns on transfer pricing, the location of the value-generating activity and the interplay between the AUSTRAC registration in Australia and the MAS licence or DPT authorisation in Singapore. These are not separate questions – they are the same question answered by the same structure. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams.

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. For a compliance architecture review or a re-approach to banking, write to info@oboluslaw.com. Map your options

Which operator profile is this regime suited to?

Australia's AUSTRAC regime suits a defined set of operator profiles. Understanding which profile matches your business is the first decision point before committing resources to the application process.

Profile A – The retail crypto exchange targeting Australian consumers. This is the core DCE use case. An operator running a spot exchange for Australian retail customers needs AUSTRAC registration as a minimum. If the product extends to margin trading, staking or tokenised financial products, an ASIC analysis runs in parallel. Timeline to operational compliance is typically measured in weeks for the registration itself, with the programme build and banking engagement taking longer. Key risk: underestimating the AML/CTF programme standard and triggering a remediation cycle post-registration.

Profile B – The institutional platform or OTC desk. An operator providing OTC execution or custody services to professional counterparties still requires AUSTRAC registration if the activity meets the DCE definition. The customer base may be smaller and the due-diligence process more straightforward, but the programme obligations are the same. If the firm also holds assets on behalf of clients, the AFSL custody analysis becomes relevant. Timeline is comparable to Profile A; the banking relationship is often easier to establish at the institutional level.

Profile C – The foreign operator using Australia as a secondary market. A firm already licensed in a comparable jurisdiction – Singapore under the MAS Payment Services Act, or in the EU under MiCA – seeking to add Australian users faces the same AUSTRAC registration requirement as a domestic operator. There is no mutual recognition pathway between AUSTRAC and foreign crypto regulators at this time. The foreign licence demonstrates a compliance baseline but does not substitute for Australian registration. Timeline and process are the same; the advantage is a demonstrated compliance record to support banking conversations.

Profile D – The token issuer or DeFi protocol. Depending on the token structure and the degree of user interaction, a token issuer or protocol operator may fall within the DCE definition, the AFSL framework or both. This profile carries the highest structural uncertainty and benefits most from a pre-launch regulatory scoping exercise. A token that confers financial-product rights – a share in profits, a managed-investment interest – is an ASIC matter regardless of how it is described in the whitepaper.

What are the most common compliance mistakes at this stage?

The most consequential compliance mistake is launching before registration is in place, on the assumption that the registration is a formality or that Australian users can be served from an offshore entity without triggering the domestic obligation. AUSTRAC takes the position that the functional connection to Australia – the customer relationship, the marketing activity, the fiat on-ramp – is the relevant test. Operating unregistered is a criminal exposure, not a regulatory grey area.

The second common mistake is filing a boilerplate AML/CTF programme. AUSTRAC publishes its supervisory expectations and conducts compliance assessments. A programme that does not reflect the actual risk profile of the business – the specific token types offered, the customer demographics, the transaction volumes, the on-chain mechanics – will not survive supervisory scrutiny. The programme must be a working operational document, reviewed and updated as the business evolves.

The third mistake is treating the AUSTRAC registration as the end of the compliance build. Ongoing obligations include annual compliance reports, suspicious matter reporting, record-keeping and the Travel Rule as it is implemented. Firms that register and then allow the programme to stagnate face enforcement risk the moment AUSTRAC conducts a supervisory assessment or receives a referral.

A fourth mistake, specific to foreign operators, is underestimating the banking timeline. The banking conversation should begin in parallel with, or before, the registration application – not after the registration is granted. Arriving with a registration certificate but no bank account means the business cannot operate. In our cross-border practice, we routinely advise clients to run the banking engagement and the regulatory application as concurrent workstreams, each informed by the other.

A common assumption: one offshore licence covers global operations

A common assumption among crypto founders is that a single offshore licence – whether in the BVI, Cayman Islands or a smaller EU member state – is sufficient to serve customers globally, including in Australia. This assumption is incorrect and, in the Australian context, potentially criminal.

Australia's AUSTRAC regime applies to any entity providing DCE services to Australian customers, regardless of where the entity is incorporated or where it holds a licence. The same principle applies in Singapore under the MAS Payment Services Act, in Hong Kong under the SFC VASP regime and under MiCA for EU customers. A BVI or Cayman registration addresses the offshore holding structure; it does not address the regulatory obligation in the jurisdictions where the customers are located.

The practical consequence is that a multi-market crypto business needs a licence stack – a map of each jurisdiction where it has customers or conducts regulated activity, with the corresponding regulatory obligation addressed. That map changes as the product evolves, as the user base grows and as regulators update their perimeter rules. Operators we advise regularly discover mid-build that a product they planned to launch in one jurisdiction requires a separate registration or authorisation in another. Catching this early is far less costly than remediating post-launch.

We map the licence stack across operating, custody and payment layers before you commit to the build – which means the banking, tax and registration timelines are aligned from the start rather than discovered sequentially.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

In Australia, AUSTRAC DCE registration can be processed relatively quickly once the application and AML/CTF programme are complete – often a matter of weeks for AUSTRAC's own processing time. The realistic timeline from scoping to operational compliance, including the programme build, entity structuring and banking engagement, is typically several months. Complexity increases where an AFSL or ASIC authorisation runs in parallel. Timelines vary by applicant readiness and the completeness of supporting materials.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction. The right answer depends on your customer base, the products you offer, your capital position, your banking relationships and your tax structure. Australia suits operators with a genuine Australian user base or strategic reasons to operate in a FATF-member, English-law environment. Many international operators combine an Australian AUSTRAC registration with a Singapore MAS licence or an EU MiCA CASP authorisation to address multiple markets. OBOLUS maps the full stack before recommending a structure.

Do I need a separate custody licence?

In Australia, holding digital assets on behalf of customers may engage the AFSL framework administered by ASIC, particularly where the assets constitute financial products. AUSTRAC DCE registration addresses the exchange and AML/CTF layer, not the custody layer. Whether a separate AFSL authorisation is required depends on the nature of the assets held, the client relationship and the structure of the service. This question should be resolved during the pre-launch regulatory scoping exercise, not after the custody product is live.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – which means the AUSTRAC registration, the banking conversation and the Australian tax position are addressed together, before you commit. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in inbound licensing strategy for digital-asset operators entering the Asia-Pacific and MENA regulatory environment.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours