Sanctions screening is a mandatory, real-time compliance obligation for every digital reporting entity (a business that provides designated services under Australian law) registered with AUSTRAC (the Australian Transaction Reports and Analysis Centre). A crypto exchange, custodian or digital-asset payment provider operating in or into Australia must screen customers and transactions against Australia's autonomous sanctions lists – maintained by the Department of Foreign Affairs and Trade (DFAT) – as well as against applicable United Nations consolidated sanctions schedules. Failure to screen, or to act on a match, exposes the business to civil and criminal enforcement, account freezes by correspondent banks and, ultimately, de-registration. This page explains the regulatory basis, the screening mechanics, the cross-border complications that catch inbound operators, and the decision points that require counsel.
What Does Sanctions Screening Require Under the Australian AML/CTF Regime?
Sanctions screening under the Australian anti-money laundering and counter-terrorism financing regime means checking every customer – and every transaction counterparty – against the DFAT Consolidated List and the UN Security Council sanctions schedules before providing a designated service, and on a continuous basis thereafter. AUSTRAC's registration requirement under the AML/CTF Act (the Anti-Money Laundering and Counter-Terrorism Financing Act) is the entry-point obligation: a business cannot legally provide a designated service involving digital currency exchange or custody without being registered. Screening is not optional once that threshold is crossed; it is a core element of the AML/CTF program every reporting entity must maintain.
The practical architecture of a compliant program has three interlocking components. First, a Part A program document that maps the business's risks and the controls applied to them – including the screening methodology, the lists screened, the match-resolution process and the escalation chain. Second, a Part B component covering customer due diligence: collecting, verifying and updating the identification information used in screening. Third, an ongoing transaction monitoring system that flags anomalous patterns, including transactions that may indicate an attempt to circumvent a sanctions designation – such as structuring payments to stay beneath monitoring thresholds or using privacy-enhancing protocols to obscure wallet provenance.
Regulators in the leading hubs increasingly expect that the screening toolset is integrated directly into the onboarding and transaction-execution workflow – not a manual check run overnight. In our cross-border practice, we have seen enforcement attention focus specifically on the gap between the written program and the operational reality: a policy that says "daily batch screening" against a business that actually processes thousands of transactions per hour is a documented compliance failure waiting for an inspection.
AUSTRAC may share intelligence with DFAT, the Australian Federal Police and ASIO, making a sanctions breach simultaneously a regulatory matter, a potential criminal matter and a national-security referral.Who Must Register With AUSTRAC – and When Does the Obligation Bite?
Any business providing a digital currency exchange service or a digital currency transfer service – as those terms are defined under the AML/CTF Act – to a customer located in Australia must register with AUSTRAC before commencing that service. The obligation attaches to the service, not the entity's corporate seat. A Cayman-incorporated exchange with Australian customers is in scope. A Singapore-licensed custodian that onboards Australian retail or institutional clients is in scope. The territorial reach of the AUSTRAC registration regime is one of the points most commonly underestimated by inbound operators.
The registration process is administrative in the first instance: an application through the AUSTRAC Online portal, nomination of an Anti-Money Laundering / Counter-Terrorism Financing Compliance Officer, and submission of a draft AML/CTF program or a representation that a compliant program is in place. The registration itself does not require prior approval of the program – but AUSTRAC may audit the program at any time after registration, and the absence of a documented, operational program is itself an offense.
For a business with no prior Australian presence, the timeline from decision to live registration is typically a matter of weeks, provided the AML/CTF program is drafted and a local compliance officer is in position. Where the business is already operating – having commenced services before registration – the position is more complicated. AUSTRAC has enforcement tools that include civil penalty orders, enforceable undertakings and, in serious cases, referral for prosecution. Voluntary disclosure and remediation, before an audit commences, materially changes the enforcement calculus.
The Australian VASP registration sits under the AUSTRAC framework and is distinct from any financial-services licence issued by ASIC (the Australian Securities and Investments Commission). A business whose digital-asset product meets the definition of a financial product – a managed investment scheme, a derivative, or a security – will need both AUSTRAC registration and an ASIC Australian Financial Services Licence. Operators we advise routinely underestimate this dual-layer obligation.
To map your entity's specific registration obligations before you commit resources to the Australian market, write to us at info@oboluslaw.com. The registration question and the product-classification question interact, and getting both wrong at the start doubles the remediation cost.
What Must an AML/CTF Program Actually Contain?
A compliant AML/CTF program under the AUSTRAC regime is a living, documented and board-approved risk framework that addresses every designated service the business provides. The core components are well-established in AUSTRAC guidance: a risk assessment updated for material changes in the business; customer due diligence procedures calibrated to risk (enhanced due diligence for higher-risk customers and politically exposed persons); sanctions screening procedures that specify the lists, the frequency, the match-adjudication workflow and the escalation path; transaction monitoring rules; a suspicious matter reporting process; and a record-keeping regime that meets statutory retention requirements.
For a crypto business, the sanctions screening component has particular technical texture. On-chain transactions do not come with names attached. The program must explain how the business maps a wallet address to an identified customer, how it handles transactions from unhosted wallets, and how it responds when a forensic screening tool (such as Chainalysis or TRM Labs) flags a transaction as involving funds with a high-risk provenance. None of these questions have a single prescribed answer – AUSTRAC's approach is principles-based – but the absence of an answer in the written program is a finding waiting to be made.
In our cross-border practice, we have seen program deficiencies cluster around three areas: the treatment of intra-group transfers (which are frequently, and incorrectly, excluded from screening on the assumption that counterparty identity is already known); the handling of smart-contract interactions where the counterparty is a protocol rather than a natural person; and the absence of a documented process for de-listing a customer who was temporarily flagged as a false positive. Each of these is a gap that a well-prepared AUSTRAC audit will surface.
How Does the Travel Rule Apply to Australian Crypto Businesses?
The Travel Rule – the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary identification information alongside a virtual-asset transfer – applies to Australian digital reporting entities under the AML/CTF Act's transaction reporting and record-keeping provisions. The mechanics require that when a VASP sends a virtual-asset transfer, it must transmit the sender's name, account identifier and address (or other prescribed information) to the receiving VASP; when it receives a transfer, it must obtain and verify that information from the sending VASP.
The cross-border dimension is acute. An Australian VASP sending funds to a counterpart VASP in a jurisdiction that has not yet implemented the Travel Rule faces a structural gap: the counterpart cannot receive the data in a standard format, or may refuse to provide it. AUSTRAC's expectation – consistent with FATF guidance – is that the sending VASP has a documented policy for handling these "sunrise problem" transfers, which may include enhanced due diligence on the receiving VASP, a hold on the transfer pending information, or a refusal to process.
For businesses operating across the Asia-Pacific region, the Travel Rule interacts with the requirements of MAS in Singapore, the SFC in Hong Kong and JVCEA standards in Japan – each with its own data-format expectations and de minimis thresholds. A single cross-border transfer may need to satisfy the outbound requirements of the sending jurisdiction and the inbound requirements of the receiving one simultaneously. Operators we advise routinely find that their messaging infrastructure was built for one jurisdiction and cannot carry the data fields required by the others.
What Happens at the Intersection of AUSTRAC, Tax and Banking?
The sanctions and AML obligations imposed by AUSTRAC do not exist in isolation from the tax and banking relationships that underpin a crypto business's operations. For an inbound operator, the three layers interact in ways that can render even a technically compliant AUSTRAC program commercially unworkable if the downstream relationships are not structured correctly.
On the banking side, Australian correspondent banks and domestic deposit-taking institutions apply their own sanctions screening – generally referencing DFAT, UN, OFAC and EU consolidated lists simultaneously – and they apply it to the crypto business as a customer, not just to the crypto business's end users. A documented AUSTRAC program that is silent on how the business handles OFAC-designated counterparties will, in practice, cause a correspondent bank to close or suspend the account. We have seen this dynamic play out for exchanges incorporated in non-OFAC jurisdictions that failed to appreciate that their Australian banking relationship required OFAC compliance as a contractual matter, independent of any Australian legal obligation.
On the tax side, the Australian Taxation Office (ATO) treats digital assets as property for capital-gains purposes. A business that provides exchange or custody services has record-keeping obligations – cost-base tracking, event-level reporting – that interact with the AML/CTF record-keeping regime. The same transaction data that feeds the sanctions screening log is also the source record for tax reporting. Where those two record-keeping systems are not aligned, a tax audit and an AUSTRAC inspection will produce conflicting transaction histories.
For a business sitting between Australia and a hub such as Singapore or the UAE, the legal question turns on which regulatory regime sets the floor for the strictest obligation in each category – AML, sanctions, tax, and custody – and whether the group structure allows those obligations to be met without duplicating cost. That analysis requires coordinated input across jurisdictions, and it is the kind of work we map before a client commits to an Australian launch.
If a prior application stalled or a banking relationship has been suspended, a structured review can surface the reason and the path to reinstatement. Contact us at info@oboluslaw.com.
A Cross-Border Remediation in Practice
In a recent matter, a digital payments company domiciled in Southeast Asia had commenced offering digital-currency exchange services to Australian retail customers – and had been doing so for several months – before registering with AUSTRAC. When a correspondent bank flagged the omission during a routine KYC refresh, the account was suspended pending evidence of registration and a compliant AML/CTF program. We were engaged to manage the remediation. Working with allied counsel in Australia, we conducted a rapid gap analysis of the existing compliance documentation, drafted a Part A and Part B program that addressed the specific on-chain features of the business, and coordinated the AUSTRAC registration filing. We also produced a sanctions screening policy that addressed both the DFAT list and the OFAC obligations required by the correspondent bank. The account was reinstated within the bank's stated review timeline, and the business was able to continue Australian operations without a formal enforcement referral. The engagement turned on the speed of the remediation documentation – the bank's clock, not the regulator's, set the deadline.
What Are the Most Common Compliance Mistakes for Inbound Crypto Operators in Australia?
Inbound operators most commonly encounter four compliance failures when entering the Australian market, each of which creates compounding risk. The first is commencing operations before registration. Unlike some jurisdictions where a transitional period softens the obligation, the AUSTRAC registration requirement attaches at the point of first provision of a designated service. There is no grace period for new market entrants.
The second failure is program-in-a-drawer syndrome: a professionally drafted AML/CTF program that is never operationalized. AUSTRAC's audit methodology focuses on the gap between written policy and actual practice. A program that describes a workflow the business does not actually follow is treated as no program at all for enforcement purposes.
The third failure is treating sanctions screening as a customer-onboarding check only. Ongoing screening – updating the check against the current DFAT and UN lists for every active customer, not just new ones – is required. A designation issued today applies to a customer who passed screening six months ago.
The fourth, and perhaps most consequential, failure is conflating AUSTRAC registration with full regulatory compliance. A business may be validly registered with AUSTRAC and still be in breach of ASIC financial-services obligations, ATO reporting requirements, or the conduct rules that apply to financial promotions. A single offshore VASP registration – the myth that one licence is enough to serve clients globally – provides no shelter from these concurrent obligations.
Who Needs Counsel, and When?
A digital-asset business needs external counsel on its Australian sanctions and AML position at four identifiable decision points. The first is pre-launch: before any Australian customers are onboarded, the product-classification question (AUSTRAC only, or AUSTRAC plus ASIC?) must be resolved, and the AML/CTF program must be in place before the first designated service is provided. The second is on banking engagement: Australian correspondent banks will request the AML/CTF program, a summary of the sanctions screening methodology and evidence of AUSTRAC registration as part of account-opening due diligence. A poorly structured program document will delay or prevent account opening. The third is on an AUSTRAC audit or inquiry: AUSTRAC's auditors are technically sophisticated and familiar with on-chain transaction patterns; a business responding to a formal inquiry without legal support risks making admissions that widen the scope of the inquiry. The fourth is on product change: adding a staking product, a lending product or a derivatives overlay can change the regulatory classification of the business's services under both the AML/CTF Act and the Corporations Act, requiring a fresh product-classification analysis before launch.
A common assumption in the market is that the Australian AML/CTF regime is less demanding than, say, the FCA's regime in the UK or the NYDFS BitLicense in the United States. That assumption is incorrect. AUSTRAC has demonstrated a sustained willingness to impose material civil penalties on major financial institutions – including for AML failures with a digital-asset dimension – and has signalled continued focus on the crypto sector. The compliance floor in Australia is not low.
To pressure-test your Australian compliance structure before you commit, message us via t.me/oboluslaw.
Related at OBOLUS
Related at OBOLUS
- AML, Travel Rule and compliance for digital-asset businesses – end-to-end program design, Travel Rule implementation and cross-border AML counsel
- Custody rules after recent exchange failures – what the regulatory response means for custodians operating across multiple regimes
- Pre-exit tax restructuring: a cross-jurisdiction comparison – structuring considerations for businesses operating across Australia, Singapore and the Gulf
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from FATF Recommendation 15, requires that a virtual asset service provider transmit originator and beneficiary identification information alongside every qualifying virtual-asset transfer to the receiving VASP. The sending VASP must collect and verify that information; the receiving VASP must obtain and retain it. The specific data fields and the de minimis transfer threshold at which the obligation triggers vary by jurisdiction and require verification against current local implementing rules.
Who must act as MLRO for a crypto firm?
Under the AUSTRAC regime, a registered reporting entity must nominate an AML/CTF Compliance Officer – the functional equivalent of a Money Laundering Reporting Officer. That person must be a senior officer of the business with genuine authority over the compliance program. AUSTRAC does not prescribe a minimum qualification, but the officer must be able to demonstrate understanding of the business's risk profile, the AML/CTF obligations applicable to it, and the escalation process for suspicious matter reporting. Allied counsel in the relevant jurisdiction can advise on the practical expectations applied in practice.
How do regulators audit crypto AML programs?
AUSTRAC audits focus on the alignment between the written AML/CTF program and actual operational practice. Auditors typically request the program documentation, transaction-monitoring alert logs, suspicious matter report records, customer due diligence files for a sampled cohort, and evidence of staff training. For crypto businesses, auditors increasingly review the sanctions screening toolset, the methodology for handling unhosted-wallet transactions, and the Travel Rule implementation records. The most common finding is a gap between the policy as written and the process as actually performed.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the whole of our practice. We map the licence, banking and compliance stack across operating, custody and payment layers before you commit – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when recovery is the issue. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CTF program design and sanctions compliance for digital-asset businesses operating across the Asia-Pacific and European regulatory regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.