Australia requires digital-asset businesses to register with AUSTRAC before they process a single Australian dollar
Operating an Australian digital currency exchange (DCE) – or any business that exchanges digital assets for fiat or transfers value on behalf of clients – without completing AUSTRAC registration is a criminal offence under the Anti-Money Laundering and Counter-Terrorism Financing Act (the AML/CTF Act). That is the direct answer. The regime is not discretionary, and the regulator, AUSTRAC (the Australian Transaction Reports and Analysis Centre), has demonstrated a willingness to pursue civil penalty proceedings carrying liabilities that can threaten the viability of a business. For an inbound operator considering Australian rails, the question is not whether to register – it is how to build a compliant structure that survives regulatory scrutiny, bank onboarding and cross-border payment flows simultaneously.
This page sets out the regulated perimeter, the registration process, the practical interaction with banking and tax, and the decision points a general counsel or founder should work through before committing to an Australian operating entity.
What activities trigger the AUSTRAC registration obligation?
Any business that provides a digital currency exchange service or a remittance service in Australia – or to Australian residents from offshore – must register as a reporting entity under the AML/CTF Act. The obligation bites on substance, not label. A foreign company routed through a BVI holding vehicle that actively onboards Australian users and converts their assets into Australian dollars is providing a DCE service in Australia for regulatory purposes.
The two primary triggered activity types are: first, exchanging digital currency for fiat or fiat for digital currency (the DCE category); and second, moving value – including digital-asset value – on behalf of a third party (the remittance category). Businesses that provide only technology infrastructure, with no client-facing custody or conversion function, may fall outside the perimeter – but that analysis is fact-specific and the line is narrower than many operators assume.
Custody of digital assets on behalf of clients is an adjacent issue. AUSTRAC registration covers the AML/CTF dimension only. Custody and financial services obligations sit under the Corporations Act and may require an Australian Financial Services Licence (AFSL) from ASIC – the Australian Securities and Investments Commission – where the digital assets in question are classified as financial products. The two regimes are independent; satisfying one does not satisfy the other. Operators we advise frequently underestimate the AFSL layer until a bank due-diligence request surfaces the gap.
How does the AUSTRAC registration process work in practice?
AUSTRAC registration is a formal application submitted through the regulator's online portal, and approval is required before commencing business – not within a grace period after launch. The process involves five core steps that a well-prepared applicant can work through in a structured sequence.
Step 1 – Entity establishment. The applicant must be a legal entity incorporated in Australia or a foreign company registered with ASIC. Branch registration of a foreign company is permissible. The choice of structure – proprietary limited company versus a registered foreign company – has downstream consequences for tax residency, thin capitalisation and the permanent-establishment analysis that governs whether Australian-source income is assessable in Australia.
Step 2 – AML/CTF program preparation. An AML/CTF program is a mandatory precondition to registration. It must be a written document addressing customer due diligence, transaction monitoring, suspicious matter reporting and employee training. AUSTRAC expects the program to reflect the specific risk profile of the business – a generic template will not withstand supervisory review. For a digital-asset business with high-velocity on-chain flows and cross-border counterparties, the program must address blockchain analytics, Travel Rule data capture and correspondent-bank chain risks.
The Travel Rule (the obligation to pass originator and beneficiary data with a qualifying value transfer) applies to Australian reporting entities under the AML/CTF Act, consistent with FATF Recommendation 15. The threshold at which data must accompany a transfer is set in the applicable legislation and regulatory guidance – consult current AUSTRAC guidance, as the precise threshold has been subject to alignment with FATF standards.
Step 3 – Submission and fit-and-proper assessment. The application captures information about the business, its beneficial owners, key personnel and the nature of services. AUSTRAC conducts a fit-and-proper assessment of controllers and senior managers. Adverse regulatory history, unspent criminal convictions and undisclosed cross-border regulatory footprints are common causes of delay or refusal.
Step 4 – Registration confirmation and ongoing obligations. Once registered, the entity's name appears on AUSTRAC's public Digital Currency Exchange Register. Ongoing obligations include suspicious matter reporting, threshold transaction reporting, international funds transfer instruction reporting, and annual compliance reporting. Failure to file on time or to maintain an adequate AML/CTF program is the most frequent enforcement trigger.
Step 5 – Renewal and change notifications. Registration must be renewed, and material changes to the business – new services, new beneficial owners, new operating jurisdictions – must be notified to AUSTRAC within prescribed timeframes. Cross-border operators who add new product lines without updating their registration profile accumulate latent enforcement risk.
Timeline: A well-prepared application with a complete AML/CTF program and clean fit-and-proper profiles typically completes registration within a matter of weeks. Applications with missing information, complex ownership structures or prior regulatory flags take materially longer. In our practice, we have seen applications stall for months where the beneficial-ownership chain was multi-layered and inadequately documented at the outset.
For a scoped assessment of your Australian registration exposure and program requirements, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base geography and the banking relationships – change the analysis materially.
Why does AUSTRAC registration alone not solve the banking problem?
AUSTRAC registration is a necessary condition for operating in Australia. It is not a sufficient condition for maintaining a bank account. Australian banks apply their own risk appetite frameworks to digital-asset businesses, and those frameworks are conservative. A registered DCE without a strong AML/CTF program, a credible compliance officer and a clean ownership chain will find account openings difficult regardless of its AUSTRAC status.
The de-risking pattern is well-documented. Banks in Australia – as in most developed markets – have exited or restricted relationships with digital-asset businesses citing correspondent-bank pressure, reputational risk and the cost of transaction monitoring. An operator that obtains AUSTRAC registration without a parallel banking strategy risks having a compliant licence and no rails.
The practical path combines registration with pre-application engagement with prospective banking partners. That means providing the AML/CTF program, a business-model narrative, source-of-funds documentation and evidence of on-chain transaction monitoring capability to the bank's financial crime team before the formal account application. In our cross-border practice, we regularly advise on the sequencing – establishing credibility with the compliance function before the relationship-management team submits the file for credit and onboarding approval.
Payment institution alternatives – including authorised deposit-taking institutions (ADIs), licensed payment service providers and, for certain flows, non-bank lenders – may offer narrower but more accessible rails for specific payment corridors. The AFSL question resurfaces here: a business that holds client money in the course of providing a payment service may need to satisfy the client-money safeguarding requirements that sit under the Corporations Act, requiring that client funds be held in a dedicated trust account separate from the firm's own assets.
How does the Australia-AUSTRAC regime interact with cross-border structures?
For a business that holds a licence in another jurisdiction – MiCA/ESMA authorisation in the EU, a VARA licence in Dubai or a MAS Payment Services Act licence in Singapore – AUSTRAC registration is an additive obligation, not an alternative one. The offshore licence does not passport into Australia. An operator serving Australian users from a licensed EU entity is providing services in Australia and triggering the AUSTRAC perimeter from day one of that user relationship.
This is the point at which the myth of the single offshore licence causes the most damage. We regularly encounter businesses that obtained an EU or Singaporean licence under the correct assumption that it satisfied local requirements in those jurisdictions, and then expanded to Australian users without a parallel registration – only to discover the exposure when a banking partner or an institutional counterparty ran a regulatory due-diligence check.
The cross-border tax interaction is equally material. An Australian-incorporated entity operating a DCE is subject to Australian corporate income tax on its worldwide income. A foreign company registered with ASIC may be subject to Australian tax only on Australian-source income, but the permanent-establishment analysis is sensitive to where key decisions are made and where the servers processing client orders are hosted. The goods-and-services tax (GST) treatment of digital-currency supplies has been the subject of specific legislative intervention in Australia – digital currency is treated as money for GST purposes under the amended legislation, removing the prior double-taxation issue. The practical scope of that treatment, particularly for novel token types, requires current legal advice.
For operators running a multi-hub structure – for example, an AIFC/AFSA-licensed entity in Kazakhstan handling Central Asian flows, an MFSA-licensed entity in Malta serving EU users, and an Australian DCE for Asia-Pacific – the licensing, banking, tax and AML stacks must be mapped together. Gaps in one jurisdiction create systemic risk across the whole structure.
What does a practical AUSTRAC registration engagement look like?
In a recent matter, a payments company headquartered in a leading Asian financial hub sought to extend its service offering to Australian business clients. The company held an existing payment licence in its home jurisdiction and assumed that a light-touch registration process would follow. On review, we identified that three of its five proposed Australian-facing services fell within the DCE or remittance categories under the AML/CTF Act, that its existing AML/CTF program was not calibrated to Australian reporting standards, and that its beneficial-ownership structure – a chain running through two intermediate holding companies – would require enhanced documentation for the fit-and-proper assessment. We restructured the entity layer, prepared an Australia-specific AML/CTF program incorporating AUSTRAC's guidance on digital-asset risk indicators and Travel Rule data flows, and coordinated pre-application engagement with the prospective banking partner. The business obtained registration and opened its primary operating account within the same quarter.
What errors do operators make when entering the Australian market?
The most frequent mistakes cluster around four themes. Each one is avoidable with proper preparation.
Launching before registering. The obligation attaches to the provision of services, not to the formal commencement of a marketing campaign. A private beta with Australian users that involves real-value transfers is a registrable activity. AUSTRAC's enforcement record includes penalties against operators who treated the registration as a formality to complete after the product was live.
Treating AUSTRAC registration as a complete compliance solution. Registration is the AML/CTF foundation. It does not address AFSL obligations, ASIC's responsible lending rules, the Privacy Act requirements for customer data, or the Australian Consumer Law obligations that apply to terms of service. Operators who build only to the AUSTRAC standard discover the other obligations when an incident or a regulatory inquiry surfaces them.
Under-specifying the AML/CTF program. A program that addresses generic risks without tailoring to blockchain-specific risk indicators – such as high-risk wallet addresses, chain-hopping, cross-chain bridge transactions and mixer exposure – will not satisfy a supervisory review. AUSTRAC has published guidance on digital-asset specific risks; that guidance should be the baseline, not the ceiling.
Failing to update on material change. Adding a new token type, launching a staking product, onboarding a new institutional counterparty or changing a beneficial owner are all events that may require notification to AUSTRAC. The change-notification obligation is ongoing and operationally demanding for fast-growing businesses.
Which operator profile should prioritise Australian registration?
The decision to establish an Australian presence is not the same for every business. The following profile analysis – drawn from the patterns we see in our cross-border practice – offers a practical starting point.
Profile A – The inbound Asian-hub operator. A business already licensed in Singapore or Hong Kong, with existing Asia-Pacific distribution, seeking to add Australian retail or institutional clients. This profile benefits most from Australian registration because the incremental compliance cost is low relative to the revenue opportunity, and the MAS or SFC licence provides a credible compliance baseline that AUSTRAC's fit-and-proper assessment responds to positively. The primary risk is the AFSL gap – many products licensed under a Singaporean framework do not map cleanly to the Australian financial-product taxonomy.
Profile B – The EU-licensed exchange seeking global footprint. A business holding a MiCA CASP authorisation, looking to extend reach into Australia as part of a global expansion. This profile must build an Australian entity from the AUSTRAC layer up, with no passporting benefit from the EU authorisation. The compliance overhead is meaningful. The business should assess whether Australian user acquisition justifies a full operational entity or whether a distribution arrangement with an Australian-licensed counterparty offers a lower-cost initial entry point.
Profile C – The pure-offshore structure with Australian user leakage. A business licensed offshore – BVI FSC, Cayman CIMA or VARA – that has accumulated Australian users without a specific strategy. This is the highest-risk profile. The business is already in scope of the AUSTRAC perimeter and may be in breach. The priority is a rapid legal assessment of the scope of the exposure, a decision on voluntary engagement with AUSTRAC, and an entity-establishment plan to regularise the position before the regulator or a banking partner identifies the gap.
If a regulatory clock is already running on your Australian exposure, write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw. If a prior application stalled or an account was closed, a second structural review can surface the reason and the route to regularisation.
A common assumption is that AUSTRAC compliance is simpler than EU or MAS licensing
That assumption is partially correct and significantly misleading. AUSTRAC registration is procedurally less complex than a MiCA CASP authorisation or a MAS Major Payment Institution licence – there is no minimum capital requirement in the same sense, no detailed prudential supervision of the kind ESMA coordinates, and the authorisation process is a registration rather than a merit-based licensing review.
But the compliance obligations that attach post-registration are substantively demanding. Suspicious matter reporting in Australia requires real-time decision-making; the threshold for filing is based on reasonable grounds to suspect, not on certainty. Threshold transaction reporting is automated and leaves no discretion. The AML/CTF program must be subject to independent review every three years at a minimum, and AUSTRAC has broad audit powers. Civil penalties under the AML/CTF Act are among the most significant in the Asia-Pacific region for financial crime failures – the regime's track record of enforcement against major financial institutions, not just crypto businesses, demonstrates that the regulator uses those powers.
The practical compliance burden for a digital-asset business with significant Australian-dollar volume and cross-border flows is comparable to what an operator faces under the FCA's MLR registration regime in the UK. Both regimes are AML/CTF-first, both require ongoing program maintenance, and both have regulators that respond negatively to operators who treat registration as a box-ticking exercise.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – structuring fiat rails, EMI relationships and client-money frameworks for regulated operators.
- De-risking and Account Closure Defence in Turkey – managing bank withdrawal risk and account defence strategy across emerging-market payment corridors.
- Cross-Chain Bridge Legal Risk: A Cross-Jurisdiction Comparison – the regulatory and liability exposure where on-chain infrastructure crosses multiple legal systems.
FAQ
Why do banks close crypto company accounts?
Banks close or restrict accounts for digital-asset businesses primarily because of correspondent-bank pressure, high transaction-monitoring costs and uncertainty about the AML/CTF risk profile of the business. An operator that cannot demonstrate a credible compliance program, a clean beneficial-ownership chain and a clear source-of-funds narrative is a risk the bank's financial crime team will typically decline. AUSTRAC registration helps but does not itself resolve a bank's internal risk-appetite decision.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) seeking to onboard with an EMI (electronic money institution) must typically provide its regulatory registration or licence documentation, a current AML/CTF or AML policy, a business-model narrative that explains the transaction flows and counterparty types, and evidence of its transaction-monitoring capability. EMIs conduct their own due diligence on VASPs as business clients; the quality of that package determines the outcome more than the identity of the VASP's home regulator.
What does client-money safeguarding require?
Client-money safeguarding requires that funds held on behalf of clients are kept in a designated account – typically a statutory trust account – that is legally separate from the firm's own assets and cannot be used for the firm's operational purposes. In Australia, the Corporations Act imposes these obligations on financial services licensees that hold client money. The practical requirement is a separate bank account, a reconciliation process and, in most cases, an annual audit of the safeguarding arrangements.
About OBOLUS. OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence, banking and tax stack across operating, custody and payment layers before you commit – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when things go wrong. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in AML/CTF frameworks, VASP registration strategy and cross-border regulatory compliance for digital-asset businesses across the Asia-Pacific and EU regulatory environments.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.