EST · MMXXVI
Home/Jurisdictions/Australia/PSP and acquiring agreement in Australia (AUSTRAC)
Banking, Payments & EMI Onboarding

PSP and acquiring agreement in Australia (AUSTRAC)

Psp and acquiring agreement in Australia (AUSTRAC). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A digital-asset payments business expanding into the Asia-Pacific corridor quickly discovers that Australian fiat rails sit behind a specific regulatory gate. AUSTRAC – the Australian Transaction Reports and Analysis Centre, the country's financial intelligence and anti-money-laundering regulator – controls the registration threshold that every crypto-adjacent payment service provider must clear before touching an Australian bank's acquiring infrastructure. Without that registration, a PSP cannot lawfully process fiat on behalf of digital-asset clients, and the acquiring agreement that underpins the entire revenue model will not survive the bank's compliance review.

The practical question for an inbound operator is therefore two-layered: first, does the business meet the trigger for AUSTRAC registration under the applicable Digital Currency Exchange (DCE) or remittance service provisions; second, does the operator's cross-border structure – entity domicile, user location, settlement currency – satisfy the due-diligence requirements that an Australian acquiring bank will apply before it will execute a PSP agreement. Both questions must be answered before capital is committed to the market.

This page maps the registration basis, the acquiring process, the cross-border tax and banking interaction, and the decision point at which specialist counsel adds the most value.

What triggers AUSTRAC registration for a crypto PSP?

AUSTRAC registration is mandatory for any business that provides a designated service under Australia's Anti-Money Laundering and Counter-Terrorism Financing Act – the AML/CTF Act – and the associated rules. Two categories are directly relevant to digital-asset payment operators. The first is the DCE service: exchanging digital currency for fiat or fiat for digital currency in the course of carrying on a business. The second is a remittance service: transferring value between payers and payees across borders or domestically. A PSP that settles merchant payments in stablecoins and converts to AUD fits squarely within one or both categories. The territorial trigger is functional: if the service is provided to Australian residents or the settlement leg lands in Australia, AUSTRAC's reach applies regardless of where the operator is incorporated.

AUSTRAC registration is not a licence in the sense that Singapore's MAS Payment Services Act licence or MiCA's CASP authorisation are. It is a compliance-and-registration regime. The entity enrols, appoints an AML/CTF compliance officer, lodges an AML/CTF program, and reports threshold transactions and suspicious matters on an ongoing basis. The barrier to entry is lower than in many flagship licensing jurisdictions, but the ongoing compliance burden – transaction monitoring, annual reporting, and increasingly active AUSTRAC enforcement – is real and has caught operators who treated registration as a one-time administrative step.

The Travel Rule obligation – the requirement to pass originator and beneficiary data with a virtual-asset transfer – applies in Australia under FATF Recommendation 15 as transposed into the AML/CTF rules. Any PSP processing transfers above the applicable de-minimis threshold must have the technical and operational infrastructure to collect, verify and transmit that data. Acquiring banks will ask for evidence of that infrastructure before they sign.

How does a PSP secure an acquiring agreement under the AUSTRAC regime?

Obtaining an acquiring agreement from an Australian bank is a commercial negotiation, but the compliance prerequisites determine whether the negotiation reaches a term sheet. Australian acquiring banks – and their card scheme principals – run a tiered due-diligence process on any PSP applicant. For a crypto-adjacent operator, that process has four distinct gates.

The first gate is legal status: the PSP must hold a current AUSTRAC registration and, where applicable, an Australian Financial Services Licence (AFSL) or a relevant authorisation under the payment-system rules. Without current registration, the bank's AML/CTF risk assessment will terminate the process before commercial terms are discussed.

The second gate is AML/CTF program quality. The acquiring bank is itself a regulated entity under AUSTRAC. It faces correspondent liability risk if it provides settlement services to a PSP whose AML/CTF program is inadequate. Banks routinely request the PSP's AML/CTF program, its risk-assessment methodology, its customer due-diligence procedures and its transaction-monitoring logic. A program that reads as a generic template – rather than a document calibrated to the specific risk profile of a crypto-payments business – will not satisfy a major acquirer's credit-and-compliance committee.

The third gate is technology attestation. The card schemes and major banks require evidence of PCI-DSS compliance, data-residency arrangements, and – for crypto-to-fiat settlement – a clear account of how conversion risk is managed and who holds the digital assets between transaction initiation and AUD settlement. This is the point at which the acquiring bank's technology and legal teams overlap, and it is frequently where deals stall.

The fourth gate is commercial-risk appetite. Even a compliant, well-documented PSP may encounter a bank whose current policy excludes crypto-adjacent merchants. Banking access for digital-asset businesses in Australia has been constrained, and the Australian Competition and Consumer Commission (ACCC) and Treasury have both noted the issue publicly. Operators who understand which banks have active acquiring programs for their category – and which have quietly withdrawn – avoid wasted due-diligence cycles.

Acquiring timelines in Australia vary considerably. A well-prepared operator, with registration in hand and a clean AML/CTF program, can expect the bank's due-diligence review to run for a period that is typically measured in weeks to a small number of months. Operators who commence the bank conversation before registration is lodged, or before the AML/CTF program is finalized, extend that timeline materially.

For a scoped assessment of your AUSTRAC registration and acquiring-readiness position, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, user base geography, and the payment flows you process change the risk analysis – and the bank's read of your file.

How does entity domicile affect the acquiring conversation?

The entity that holds the AUSTRAC registration should, in most structures, be the entity that is party to the acquiring agreement. This sounds obvious, but operators entering Australia from offshore frequently run their global payment flows through a single entity – incorporated in a low-friction jurisdiction such as the BVI, Cayman or a European EMI – and seek to add Australian acquiring to that entity's capabilities without establishing a local presence. That approach creates structural friction at multiple levels.

Australian acquiring banks are more comfortable with an Australian-registered entity or, at minimum, a foreign company registered with ASIC (the Australian Securities and Investments Commission). An offshore entity without a registered Australian presence is not legally barred from holding AUSTRAC registration – the regime does not require local incorporation – but in practice the bank's credit-and-compliance team will apply a higher-scrutiny standard, and the AML/CTF compliance-officer requirement effectively demands someone accountable under Australian law.

The interaction with tax is equally material. An Australian-registered subsidiary or foreign-registered branch triggers Australian income-tax obligations on Australian-source income. GST applies to supplies made to Australian consumers, though the treatment of digital-currency supplies involves specific AUSTRAC and ATO (Australian Taxation Office) guidance that has evolved alongside the industry. Operating through a foreign entity that receives Australian-sourced payment-processing fees without a local presence does not eliminate the tax exposure; it creates transfer-pricing and permanent-establishment questions that must be resolved before the structure is committed.

In our practice, operators who design the Australian entity structure at the outset – choosing between a subsidiary, a branch or a managed-service arrangement with an Australian licensee – close their acquiring agreements faster and face fewer re-papering events than those who try to retrofit compliance onto an existing offshore structure after the bank conversation has begun.

What must an AML/CTF program cover for a crypto PSP?

An AML/CTF program under the Australian regime is a living compliance document, not a one-time filing. It must address, at minimum, the identification and assessment of the ML/TF risks inherent in the business; the policies, procedures and controls that the operator applies to manage those risks; the employee due-diligence and training requirements; and the transaction-monitoring and reporting obligations that apply to designated services.

For a crypto-adjacent PSP, the risk assessment must grapple directly with the characteristics of digital-asset payments: pseudonymity of wallet addresses, the speed and finality of on-chain transfers, the absence of a central counterparty to verify identity, and the cross-border nature of most transaction flows. AUSTRAC's published guidance on DCEs – which has been updated as the industry has grown – sets out the regulator's expectations on customer identification procedures, enhanced due diligence for high-risk customers, and the monitoring of transactions for structuring and layering indicators.

The Travel Rule data-transfer requirements sit on top of the AML/CTF program. A PSP that transfers virtual assets on behalf of clients must implement a solution for transmitting originator and beneficiary information to counterpart VASPs and financial institutions. AUSTRAC has aligned with the FATF standard on this obligation, and major Australian banks will ask to see evidence of a live Travel Rule implementation – not just a policy statement – before they proceed with an acquiring relationship.

Operators we advise typically build their AML/CTF program in three phases: a risk-assessment workshop that maps their specific product, customer and geographic risk profile; a controls-design phase that translates the risk assessment into workable policies; and a testing phase before the bank due-diligence process begins. Banks can and do ask follow-up questions after an initial program submission; a program that has already been stress-tested is far better positioned to survive that scrutiny.

How does EMI onboarding interact with the Australian PSP structure?

Many digital-asset businesses enter Australia holding a European EMI authorisation – typically issued under the EU's Payment Services Directive framework or under an equivalent UK FCA registration – and seek to use that authorisation as the foundation for their Australian-facing payment services. The MiCA regime, which governs crypto-asset service providers (CASPs) across the EU and EEA, provides its own passporting mechanism but does not extend its reach to Australia. AUSTRAC registration is a parallel and independent obligation.

Where the operator holds both a European EMI authorisation and AUSTRAC registration, the structure can be efficient: the EMI entity handles EUR/GBP settlement and European card acquiring, while a separate Australian entity – or a foreign-registered branch of the EMI – handles AUD acquiring and AUSTRAC reporting. The practical challenge is the banking layer between the two entities. Intra-group transfers that cross the Australian AUSTRAC perimeter are subject to threshold transaction reporting and may trigger Travel Rule obligations depending on the amount and the nature of the transfer. This is not a theoretical risk; AUSTRAC has focused enforcement attention on intra-group structures that it regards as obscuring the beneficial flow of funds.

For operators holding a MAS Digital Payment Token licence in Singapore, the cross-border interaction with Australia is a common structural question. Singapore and Australia have a high degree of regulatory coordination, and MAS has published guidance acknowledging the FATF Travel Rule in terms similar to AUSTRAC's. A PSP licensed under the Payment Services Act in Singapore that also registers with AUSTRAC can present a coherent compliance story to an Australian acquiring bank – provided the AML/CTF program addresses both regimes and the transaction-monitoring infrastructure covers flows between the two jurisdictions.

If you are mapping the licence, banking and tax stack for an Australia-plus-offshore build, write to info@oboluslaw.com. The interaction between a prior-held EMI authorisation and AUSTRAC requirements determines whether a single entity or a purpose-built Australian vehicle is the right entry point.

A recent matter: acquiring stall resolved through program redesign

In a recent matter, a payments company operating in the Asia-Pacific region held a current AUSTRAC registration but had stalled in acquiring negotiations for several months. The bank's compliance team had raised concerns about the adequacy of the operator's customer risk-classification methodology and the absence of a documented Travel Rule implementation. We reviewed the AML/CTF program, identified three specific gaps against AUSTRAC's current DCE guidance, and drafted a remediated program that addressed the bank's questions directly. We also assisted the operator in completing a formal Travel Rule implementation with documented testing evidence. The acquiring relationship was agreed within weeks of the remediated program being submitted. No structural change to the entity was required.

Which operator profile should establish a local Australian presence?

Not every operator that serves Australian users needs a locally incorporated entity. The decision turns on three variables: the volume and nature of Australian-facing activity, the acquiring bank's appetite for the operator's category, and the long-term strategic weight of the Australian market in the operator's plans.

Profile A – an operator for whom Australia is a primary market, with significant AUD payment volumes and a recurring acquiring relationship – should establish a local subsidiary or registered foreign company, hold AUSTRAC registration in that entity, and build a standalone AML/CTF program calibrated to Australian risk. The operational overhead is higher, but the bank relationship is more durable and the regulatory risk is better contained.

Profile B – an operator testing the Australian market through a limited product, with modest AUD volumes and an offshore principal entity – may be able to register with AUSTRAC as a foreign entity, use a managed-service arrangement with an Australian payment facilitator, or rely on a local acquiring partner who holds the primary relationship with the bank. This path is faster to implement, but it introduces counterparty dependency and limits the operator's direct relationship with the acquirer.

Profile C – an operator whose Australian-facing activity consists solely of accepting AUD from Australian customers via a third-party payment gateway, without providing a designated service directly – may fall outside the AUSTRAC registration trigger. However, this analysis depends on the precise payment-flow structure, and AUSTRAC has historically taken a broad view of what constitutes providing a designated service. A legal opinion on trigger status, rather than an internal assumption, is the appropriate basis for a decision in this profile.

A common assumption in the market is that a single offshore licence – often a BVI or Cayman registration – is sufficient infrastructure to serve customers globally, including in Australia. That assumption is incorrect for any operator that processes fiat or provides a designated service to Australian residents. AUSTRAC registration is an independent, mandatory obligation, and the acquiring bank's due-diligence process will surface the gap regardless of what the operator's terms of service say about applicable law.

When should an operator engage specialist counsel?

The optimal engagement point is before AUSTRAC registration is lodged, not after the acquiring bank has raised concerns. The registration itself is a relatively straightforward administrative process. The documents that follow from it – the AML/CTF program, the risk assessment, the Travel Rule implementation plan – are the documents that determine whether the bank relationship progresses.

Operators who engage counsel at the registration stage can design an AML/CTF program that anticipates the bank's due-diligence questions, rather than responding to them after the fact. They can also resolve the entity-structure question – local subsidiary versus foreign registration versus managed-service arrangement – before capital is allocated. In our cross-border practice, the cost of restructuring after an acquiring stall is materially higher than the cost of designing the structure correctly at the outset.

We have also seen situations where an operator's AUSTRAC registration was current but its AML/CTF program had not been updated to reflect changes in the regulator's published guidance on DCEs, Travel Rule obligations, or enhanced customer due-diligence expectations. AUSTRAC's guidance evolves, and a program that was adequate at registration may not satisfy a bank's current compliance requirements or withstand an AUSTRAC audit. An annual program review is a material risk-management step, not an administrative formality.

For operators already in a stalled acquiring process – where the bank has raised compliance concerns or where a prior banking relationship was closed – a focused legal review can surface the specific gap and the route back. The review is most effective when it covers the AML/CTF program, the Travel Rule implementation, the entity structure, and the acquiring bank's specific information requests simultaneously, rather than addressing each in isolation.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Australian banks close or decline accounts for crypto businesses primarily on AML/CTF risk grounds. A bank that onboards a digital-asset operator becomes a correspondent counterparty subject to AUSTRAC obligations itself. If the operator's AML/CTF program is inadequate, outdated or poorly evidenced, the bank's own compliance exposure rises. Banks also apply commercial-risk-appetite policies that may exclude entire digital-asset categories, regardless of individual compliance quality. Operators with strong, auditable programs and a well-documented Travel Rule implementation materially reduce the risk of account closure.

How can a VASP onboard with an EMI?

A VASP (virtual asset service provider) seeking to onboard with a European EMI must typically satisfy the EMI's internal AML/CTF due diligence, demonstrate FATF-aligned customer screening and transaction monitoring, and provide evidence of local regulatory registration in its operating jurisdictions – including AUSTRAC registration for Australian activity. The EMI will assess the VASP's risk profile against its own regulatory obligations under the applicable Payment Services Directive or equivalent regime. A well-structured VASP compliance package, addressing each of these elements, accelerates the onboarding process considerably.

What does client-money safeguarding require?

Client-money safeguarding under Australian law requires that funds received from payment-service customers are held in a designated account, segregated from the operator's own funds, with a licensed Australian financial institution or equivalent. The specific obligations vary depending on whether the operator holds an AFSL and the nature of the designated service. Safeguarding requirements interact with the acquiring bank's settlement mechanics: the bank will want to confirm that the PSP's AUD settlement account structure complies with applicable client-money rules before executing the acquiring agreement.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so that AUSTRAC registration, acquiring agreements and cross-border EMI onboarding are addressed as a coordinated structure, not a series of separate fires. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when recovery is needed. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AUSTRAC registration, AML/CTF program design, and cross-border PSP compliance for digital-asset payment operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours