Transaction monitoring for digital-asset businesses in Australia is a regulated obligation under the AUSTRAC (Australian Transaction Reports and Analysis Centre) regime, not a best-practice option. Any business that provides a designated service – including digital currency exchange and non-cash payment products – must register with AUSTRAC, build a compliant AML/CTF program, and operate transaction monitoring that is fit for the volume and risk profile of that business. The applicable framework is the Anti-Money Laundering and Counter-Terrorism Financing Act, enforced by AUSTRAC. Failure to establish adequate transaction monitoring before commencing operations exposes the business to civil penalty proceedings, supervisory remediation orders, and – in serious cases – suspension of the right to operate.
This page sets out the regulatory basis, the practical build sequence for transaction monitoring, the cross-border considerations that catch inbound operators off guard, and the decision points a general counsel should resolve before going live in Australia.
Why transaction monitoring is mandatory under the AUSTRAC regime
Transaction monitoring is a statutory component of the AML/CTF program every reporting entity (a person or business providing a designated service) must maintain under the AUSTRAC regime. AUSTRAC registration is a precondition to providing digital currency exchange services commercially in Australia. Operating without it is not a licensing gap – it is a criminal and civil compliance failure.
The monitoring obligation is not narrowly defined. AUSTRAC expects a reporting entity to identify, assess and respond to money laundering, terrorism financing and other financial crime risks in real time or near-real time. That means automated rule-sets, threshold alerts, and documented escalation paths, all calibrated to the entity's customer types and product suite.
The regime covers a wide perimeter. Digital currency exchanges, peer-to-peer platforms, custodians, payment processors and certain DeFi-adjacent operators can all fall within the designated-service categories. The classification turns on the actual service rendered – AUSTRAC has issued guidance making clear that substance over label applies, and that businesses should not assume an offshore wrapper shields the activity if Australian customers are being served.
Who is caught: the AUSTRAC perimeter for crypto businesses
A business is caught by the AUSTRAC regime if it provides a designated service in Australia or to Australian customers, regardless of where it is incorporated. The designated-service categories expressly include digital currency exchange – the conversion of fiat currency to digital currency and vice versa.
Inbound operators frequently underestimate the reach. A business incorporated in the Cayman Islands, licensed under a MiCA (Markets in Crypto-Assets Regulation) passport in the EU, and serving Australian retail or institutional clients is not automatically excluded from AUSTRAC's registration obligation. The question AUSTRAC asks is whether a designated service is being provided in Australia or to persons in Australia – not where the server is located or where the entity was formed.
Custodians, staking service providers and businesses offering crypto-to-crypto exchange services must also assess their position carefully. The designated-service list has expanded as the industry has evolved, and AUSTRAC actively updates its guidance on which product structures are caught. We regularly advise inbound operators who discover, well into their build phase, that their Australian customer base triggers a registration obligation they had not anticipated.
For a scoped assessment of your AUSTRAC registration position, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity type, the service, the user base, the banking arrangement – change the analysis materially.
Building the AML/CTF program: what transaction monitoring requires in practice
An AUSTRAC-compliant AML/CTF program has two parts: Part A (the governance, risk assessment and employee due diligence framework) and Part B (the customer due diligence framework). Transaction monitoring sits within both, as the operational engine that gives effect to the risk-based rules. The program must be documented, board-approved, and kept current.
In our practice, the build sequence follows a consistent logic. First, the entity defines its customer risk segmentation – by product, geography, transaction volume and counterparty type. That segmentation drives the rule-set. Low-risk, low-volume domestic transfers attract lighter monitoring rules; cross-border transfers, high-value conversions and transactions involving jurisdictions identified as higher-risk by FATF attract enhanced scrutiny.
Second, the entity maps its transaction data flows. This is often where the cross-border complexity surfaces. A business with a wallet infrastructure provider in Singapore, a banking relationship in the EU and an Australian customer base must ensure its monitoring system can consolidate data across those rails and apply AUSTRAC-specific rules, not just the rules of the home jurisdiction. Transaction monitoring that passes FINMA review or satisfies MAS requirements is not automatically AUSTRAC-compliant.
Third, the rule-set is implemented and tested. AUSTRAC expects monitoring rules to be calibrated to the entity's actual risk assessment, not simply copied from a template. Generic threshold alerts that have not been tuned to the business's volume, customer profile and product type will not survive supervisory scrutiny.
Fourth, the escalation and reporting framework is built. Suspicious matter reports (SMRs) and threshold transaction reports (TTRs) must be filed with AUSTRAC within prescribed timeframes. The internal escalation path from alert to investigation to reporting decision must be documented and tested before go-live.
How the Travel Rule interacts with AUSTRAC transaction monitoring
The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary information with a virtual-asset transfer – applies to Australian reporting entities. AUSTRAC has issued guidance adopting the FATF Travel Rule standard for digital currency exchanges and other covered VASPs. The obligation means that when a business sends or receives a transfer above the applicable threshold, it must collect, verify and transmit prescribed information about the originator and beneficiary.
Integration of the Travel Rule into transaction monitoring is an area where businesses regularly underinvest. The two obligations are operationally linked: a transaction monitoring system that flags a transfer for suspicious activity review cannot complete that review without the originator data the Travel Rule requires. A gap in Travel Rule compliance therefore becomes a gap in transaction monitoring, and AUSTRAC's supervisory examinations test both together.
The cross-border dimension is significant. Australian operators transacting with counterparties in jurisdictions that have not yet implemented the Travel Rule must still comply with their own obligations. Where the counterparty VASP cannot provide compliant data, the Australian entity must assess whether to complete the transaction and document that decision. Operators we advise build a counterparty VASP due-diligence layer directly into their transaction monitoring workflow to manage this.
KYC and customer due diligence: the foundation beneath the monitoring
Transaction monitoring without a sound KYC (know your customer) framework is structurally defective. AUSTRAC's customer identification and verification rules require reporting entities to identify customers at onboarding and to apply enhanced due diligence for higher-risk customers, politically exposed persons and transactions above defined thresholds. The quality of transaction monitoring output is directly proportional to the quality of the underlying customer data.
In practice, this means the customer risk profile – established at onboarding – must be accessible to the monitoring system. An alert generated on a transaction that cannot be linked to a verified customer profile cannot be investigated or reported effectively. Businesses that build transaction monitoring as a standalone system, disconnected from their KYC database, find themselves unable to meet AUSTRAC's reporting obligations in practice even if the monitoring rules are technically correct.
For businesses with an international customer base, the complexity compounds. A customer onboarded in another jurisdiction under that jurisdiction's KYC rules may not meet AUSTRAC's verification standards. We regularly advise operators to map their existing customer due diligence standards against AUSTRAC requirements before porting a customer book into an Australian-registered entity.
Cross-border banking, tax and the AUSTRAC compliance stack
A business operating under AUSTRAC supervision typically has banking relationships that cross at least one other jurisdiction. That is not unusual – Australian dollar rails for a crypto business commonly run through correspondent banking arrangements that require the business to demonstrate compliance with both the Australian AML regime and the AML framework of the bank's home jurisdiction. Banks frequently conduct their own AML due diligence on crypto clients in addition to any AUSTRAC registration, and a reporting entity that cannot produce its AML/CTF program documentation on request will lose its banking relationship.
The tax interaction is equally concrete. Australia's domestic tax authority treats digital currency transactions as having tax consequences at each disposal event. A transaction monitoring system that records every transaction for AML purposes simultaneously generates the audit trail needed for tax reporting. Businesses that build these systems in silos – one for AUSTRAC, one for tax – create reconciliation problems that are expensive to resolve. We recommend integrating the data architecture from the outset.
The cross-border structuring question – where to hold the entity, where to hold the assets, where to bank – also intersects with AUSTRAC's registration requirement. A foreign entity providing a designated service in Australia cannot avoid registration by routing transactions through an affiliated entity in another jurisdiction. AUSTRAC looks at the substance of the service, and affiliated-entity structuring that is designed to circumvent registration triggers its own supervisory risk.
To map the licence, banking and compliance stack for your Australian build, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or a banking relationship closed, a structural review can identify the underlying compliance gap and the path to resolution.
A practical illustration: the inbound operator monitoring gap
In a recent matter, a payments group with a MiCA authorisation in an EU member state expanded its service offering to Australian customers without separately registering with AUSTRAC, on the assumption that its EU compliance program satisfied any Australian AML obligations. AUSTRAC's registration obligation was triggered when the group began converting Australian dollars to digital currency for Australian-based clients. We were engaged after the group's Australian banking partner requested sight of its AUSTRAC registration certificate and AML/CTF program documentation. Working through allied counsel in Australia, we supported the group's registration process, mapped its existing EU monitoring rules against AUSTRAC's requirements, and identified several gaps in its Travel Rule workflow that required remediation before the registration could be completed. The registration was finalised without formal enforcement action, and the banking relationship was preserved. The episode turned on moving quickly once the gap was identified – the window between a bank's compliance inquiry and a formal de-risking decision can be narrow.
Decision matrix: which compliance profile applies to your business
The appropriate transaction monitoring architecture depends on the entity's profile, product and customer base. Three situations recur in our practice.
A domestic startup launching a digital currency exchange in Australia with a purely local customer base and low transaction volumes needs AUSTRAC registration, a documented AML/CTF program, and a monitoring system calibrated to its actual risk profile. The build is straightforward relative to the compliance overhead of a global operator, but the documentation and governance obligations are identical. The common mistake is deprioritising the formal board-approval of the AML/CTF program and treating AUSTRAC registration as an administrative step rather than a foundational compliance commitment.
An inbound operator already licensed in Singapore under the Payment Services Act or in Dubai under the VARA regime and expanding into Australia faces a regime-mapping exercise. The MAS or VARA compliance program provides a starting structure, but AUSTRAC's specific requirements – particularly around the customer due diligence and suspicious matter reporting obligations – require local adaptation. The monitoring rules calibrated for a Singapore or UAE customer base may not be correctly tuned for Australian risk typologies or threshold reporting obligations.
A large-scale exchange with customers across multiple jurisdictions, banking in several currencies and a complex product suite faces the most demanding monitoring build. Transaction monitoring must operate across jurisdictions in real time, must integrate the Travel Rule workflow, and must produce reports that satisfy AUSTRAC without compromising compliance in other regulated jurisdictions. The architecture decision – centralised monitoring with jurisdiction-specific rule layers, or separate systems per jurisdiction – has significant cost and operational implications and requires legal input before the technical build begins.
A common assumption this analysis corrects
A common assumption among operators entering Australia is that an offshore licence – whether a MiCA passport, a VARA authorisation or a Singapore MAS licence – satisfies the Australian compliance obligation and that no separate AUSTRAC engagement is needed. This is incorrect. AUSTRAC registration is a standalone Australian obligation that no foreign licence satisfies. The offshore licence may demonstrate governance maturity and may support the entity's AML/CTF program documentation, but it does not replace the requirement to register with AUSTRAC, to build an AUSTRAC-compliant program and to file Australian reports. Operating in reliance on a foreign licence without AUSTRAC registration exposes the business to the full range of AUSTRAC's enforcement powers, including civil penalties and the potential suspension of the right to carry on the designated service.
Related to this myth is the assumption that low transaction volumes exempt a business from the full monitoring obligation. AUSTRAC's regime is activity-based, not volume-based. The obligation to have a compliant AML/CTF program and to monitor transactions arises from the nature of the service, not its scale.
Related at OBOLUS
- AML/CTF and Travel Rule compliance for digital-asset businesses – our full practice coverage across the major regulatory regimes and jurisdictions
- VASP business risk assessment in France under the AMF/PSAN regime – how risk assessment obligations apply in another major jurisdiction transitioning to MiCA
- PSP and acquiring agreement structuring in the Czech Republic – cross-border payment and acquiring considerations for digital-asset operators in Europe
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a virtual asset service provider to collect, verify and transmit prescribed information about the originator and beneficiary of a virtual-asset transfer when the transfer exceeds the applicable threshold. This includes names, account identifiers and, in many jurisdictions, address data. The obligation applies to both the sending and receiving VASP, and both must have systems capable of processing and retaining the data. AUSTRAC has adopted the FATF Travel Rule standard for Australian reporting entities. Gaps in Travel Rule compliance directly impair the quality of transaction monitoring and SMR investigations.
Who must act as MLRO for a crypto firm?
An MLRO (money laundering reporting officer) is the nominated individual responsible for receiving internal suspicious matter disclosures, making the filing decision, and acting as the primary point of contact with the regulator. Under the AUSTRAC regime, reporting entities are required to designate a compliance officer with board-level access and sufficient authority to act independently. The MLRO must understand both the AML/CTF program and the specific risk typologies of the business. For inbound operators, the MLRO is commonly based in Australia or must have documented authority to meet Australian regulatory expectations. The competence and seniority of the MLRO is an explicit area of supervisory focus.
How do regulators audit crypto AML programs?
AUSTRAC conducts both desk-based and on-site supervisory reviews. Reviewers typically examine the documented AML/CTF program, the risk assessment methodology, transaction monitoring rule documentation and testing records, SMR and TTR filing histories, customer due diligence samples, and staff training records. The review assesses whether the program reflects the entity's actual risk profile or is a generic document that has not been tailored. Regulators in other leading hubs – including the FCA, MAS and VARA – follow comparable examination approaches. Businesses that have not tested their monitoring rules against real transaction data before a review consistently fare worse than those that can demonstrate a live, calibrated program.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the entirety of our practice. We map the licence, monitoring and compliance stack across operating, custody and payment layers before our clients commit – because operating without the right compliance architecture risks enforcement, frozen banking rails and lost market access. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CTF program design and AUSTRAC compliance for inbound digital-asset operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.