EST · MMXXVI
Home/Jurisdictions/Australia/VASP licence application in Australia (AUSTRAC)
Licensing & Registration

VASP licence application in Australia (AUSTRAC)

Vasp licence application in Australia (AUSTRAC). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a digital-asset business that touches Australian users without the correct registration exposes the business to enforcement action by AUSTRAC (the Australian Transaction Reports and Analysis Centre), the country's anti-money-laundering regulator and the body that oversees digital currency exchange (DCE) providers – the registration category that captures most crypto-asset businesses serving Australian customers. A business discovered operating while unregistered risks account closures, mandatory remediation programs and, in serious cases, civil penalty proceedings. The registration path itself is not opaque, but the surrounding compliance architecture – AML/CTF program, ongoing reporting, token classification, banking access and the cross-border interaction with tax – is where operators routinely underestimate their obligations.

This page sets out the AUSTRAC registration regime for digital currency exchange providers, the practical application process, the cross-border considerations that affect inbound operators, and the decision points every business should resolve before submitting. References to specific fees, capital thresholds and statutory timelines remain qualitative where current figures have not been confirmed against official AUSTRAC guidance, consistent with our anti-hallucination discipline.

Who Needs AUSTRAC Registration – and What Does It Cover?

Any business that exchanges digital currency for money, or money for digital currency, and provides that service in Australia or to Australian customers must register with AUSTRAC as a digital currency exchange (DCE) provider before commencing operations. The obligation applies regardless of where the corporate entity is incorporated. An operator domiciled in Singapore, the BVI or the Cayman Islands that actively markets to, or accepts funds from, Australian users falls squarely within the AUSTRAC registration regime. Regulators look at the geographic reach of the service, not the address on the certificate of incorporation.

The AUSTRAC regime is grounded in Australia's Anti-Money Laundering and Counter-Terrorism Financing Act (the AML/CTF Act) and associated rules. It is, at its core, an AML/CFT registration rather than a prudential licence – AUSTRAC is not a conduct or consumer-protection regulator in the way that ASIC is. That distinction matters operationally: AUSTRAC's focus is on transaction monitoring, suspicious-matter reporting, and the integrity of the financial system. Prudential expectations – capital adequacy, segregation of client funds – are addressed elsewhere, principally under ASIC's jurisdiction if the business also issues financial products. An operator running a crypto exchange that does not issue securities or derivatives may interact with AUSTRAC alone for the registration layer, while still needing to consider ASIC's financial-services regime for any product or advice component.

The definition of digital currency for AUSTRAC purposes is broad. It captures Bitcoin, Ether and functionally similar convertible virtual assets. Stablecoins pegged to fiat currency sit in a contested area; operators should obtain a classification opinion before assuming they fall outside the DCE definition. The Travel Rule (the obligation to pass originator and beneficiary data alongside a transfer) applies in principle under FATF Recommendation 15, and Australia is progressively implementing the standard. Current compliance expectations should be confirmed against the latest AUSTRAC guidance at the time of application.

CTA #1

The registration process above is the standard path. Your facts – the entity structure, the user base, the product mix, the banking – change the analysis materially. For a scoped assessment of whether your business needs AUSTRAC registration and what the compliance architecture requires, contact OBOLUS at info@oboluslaw.com or map your options now.

How Does the AUSTRAC Registration Process Work?

The AUSTRAC DCE registration process proceeds through a defined sequence of steps, and a business must be registered before it starts providing the designated service – there is no provisional operating period while an application pends.

The process runs broadly as follows:

  • Pre-application AML/CTF program development. AUSTRAC requires an applicant to have an AML/CTF program in place, or at a minimum in a state ready for adoption, at the time of registration. The program must identify, assess and mitigate the money-laundering and terrorism-financing risks specific to the business. A generic template does not satisfy the obligation. The program must reflect the actual customer base, product types, geographic reach and delivery channels of the specific operator.
  • Beneficial ownership and key-personnel disclosure. AUSTRAC requires full disclosure of beneficial owners and controlling persons. All key individuals – typically directors, senior managers and significant shareholders – must be identified. AUSTRAC will assess whether any individual has a disqualifying history. The threshold for "significant" ownership follows AML/CTF Act definitions; confirm the current threshold with AUSTRAC guidance at the time of application.
  • Online registration submission. The registration is submitted through AUSTRAC Online, the regulator's portal. Supporting documentation accompanies the application: entity formation documents, the AML/CTF program, beneficial ownership chart and key-personnel declarations.
  • AUSTRAC assessment. AUSTRAC reviews the application against the registration criteria. The regulator may issue a request for further information, which pauses the assessment clock. Where the application is complete and the AML/CTF program is adequate, registration is generally granted within a matter of weeks; operators should not plan around a specific fixed timeline, as complexity and completeness of the submission drive the actual duration.
  • Ongoing obligations on registration. Registration is not a one-time event. Once registered, the DCE provider must report suspicious matters in real time, submit annual compliance reports, maintain transaction records for the required retention period, and keep the AML/CTF program current as the business evolves. Failure to do so can trigger enforcement even where the original registration was obtained correctly.

In our licensing practice, we have seen applications stall at two points consistently: an underdeveloped AML/CTF program that does not map to the actual risk profile of the business, and incomplete beneficial ownership documentation for entities with multi-layer holding structures. Both are curable before submission and neither should delay a well-prepared applicant.

What Does the AML/CTF Program Need to Contain?

The AML/CTF program is the central compliance document for an AUSTRAC-registered DCE, and the standard it must meet is materially higher than a procedural checklist. AUSTRAC expects a risk-based approach: the program must begin with a documented risk assessment that identifies the specific ML/TF risks the business faces and calibrates the controls to those risks.

A compliant program typically addresses customer due diligence (CDD) and enhanced due diligence (EDD) for higher-risk customers; politically exposed persons (PEPs); transaction monitoring rules calibrated to the business's product types and customer segments; suspicious matter reporting procedures; employee training; and a program for ongoing review. For a DCE serving institutional clients, the risk weighting differs from one serving retail customers predominantly through peer-to-peer channels.

The Travel Rule component is increasingly material. AUSTRAC has been aligning with the FATF Virtual Assets standard, which requires DCE providers to collect, verify and transmit originator and beneficiary information above the applicable threshold. Operators building the AML/CTF program should build the Travel Rule architecture at the same time, not as a retrofit. The precise current threshold should be confirmed against AUSTRAC's published rules at the point of build.

We regularly advise businesses on program construction from the ground up. The risk assessment that anchors the program is also, strategically, the most useful document for a subsequent AUSTRAC examination – it demonstrates that the business understands its own risk environment, not merely that it has copied a regulatory form. A well-constructed program is therefore both a compliance obligation and a defence asset.

How Does AUSTRAC Registration Interact with ASIC and the Rest of the Regulatory Stack?

AUSTRAC registration addresses only the AML/CTF layer of operating a digital-asset business in Australia; it does not address all regulatory obligations a DCE may face. The Australian Securities and Investments Commission (ASIC) regulates the conduct of financial services, and a crypto-asset product that constitutes a financial product under the Corporations Act triggers an Australian Financial Services Licence (AFSL) requirement, entirely separately from AUSTRAC registration.

The question of whether a particular token constitutes a financial product – a managed investment scheme interest, a derivative, a non-cash payment facility or another regulated instrument – is a classification question that must be resolved on the facts of each token. ASIC has published guidance on the digital-assets perimeter, and enforcement history confirms that exchanges offering derivatives or leveraged products require AFSL authorisation. An operator that assumes AUSTRAC registration is sufficient, without analysing the product mix against ASIC's regime, is exposed.

The Reserve Bank of Australia (RBA) is relevant for stablecoin and payment-system considerations, particularly as Australia moves toward a payments-system modernisation framework. Operators issuing instruments that could be classified as payment facilities should monitor developments in that area.

Australian tax treatment adds a further layer. The Australian Taxation Office (ATO) treats most crypto-asset disposals as taxable events under capital gains tax rules; staking rewards and DeFi income have their own treatment. For a business operating a DCE, the GST treatment of digital currency exchange services has been specifically addressed by the ATO. Any cross-border operator must also consider whether Australian-sourced income is subject to withholding obligations and whether a double-tax treaty applies to the corporate structure.

What Are the Cross-Border Challenges for Inbound Operators?

For a business incorporated outside Australia, the AUSTRAC registration question arises as soon as the service is directed at Australian customers – and several structural realities make the cross-border position more complex than a domestic application.

First, banking access for a foreign-incorporated DCE seeking to settle AUD transactions is difficult. Australian ADIs (authorised deposit-taking institutions) have been cautious about crypto-business banking, and a foreign entity with no Australian presence faces additional scrutiny. Operators we advise routinely find that the banking question must be resolved in parallel with, or prior to, the AUSTRAC application – not as an afterthought. Solutions vary: an Australian subsidiary with local directors may improve banking prospects, but it also brings full tax-residency implications that must be modelled before the structure is committed.

Second, the AUSTRAC AML/CTF program must reflect the real operating reality, including the overseas entity's processes. AUSTRAC has extraterritorial reach over the Australian operations of a foreign-group entity. If a parent company in another jurisdiction handles KYC centrally, the program must document how that function meets Australian standards. A program that simply defers to group policy, without demonstrating alignment with the AML/CTF Act requirements, will not satisfy AUSTRAC.

Third, the token classification question under ASIC's regime can produce a different answer in Australia than in the operator's home jurisdiction. A token that is a utility token under the MiCA framework, or registered as a payment token under a Singapore Payment Services Act licence, may nonetheless be a financial product in Australia based on the rights it confers and the way it is marketed. The classification must be assessed on Australian law, independently of how other regulators have treated it.

A practical point on timing: an operator with an active EU MiCA CASP authorisation or a Singapore DPT licence gains regulatory credibility in an AUSTRAC application but gains no automatic passporting. Australia has no mutual recognition arrangements with other crypto-licensing regimes. The overseas licence demonstrates governance maturity; it does not replace the AUSTRAC registration process.

Micro-matter: In a recent licensing matter, an Asia-Pacific payments business had been operating a peer-to-peer exchange product for Australian users without AUSTRAC registration, having incorrectly assumed its Hong Kong SFC registration covered the position. We identified the gap during a pre-launch compliance review, restructured the product delivery so that Australian activity was clearly ring-fenced within a locally registered entity, developed the AML/CTF program to AUSTRAC's standard and submitted the registration application. The business obtained its DCE registration and relaunched the Australian product in the same quarter – avoiding what would otherwise have been a serious enforcement exposure.

CTA #2: If a prior application stalled, a banking relationship was closed or an AUSTRAC examination has been flagged, a second review can surface the structural cause and the route forward. Write to us at info@oboluslaw.com or map your options with our licensing team.

Who Should Register in Australia Versus Another Jurisdiction First?

The decision matrix for Australia versus another hub first turns on several operator-profile variables, and there is no universal answer.

Profile A – Australia-primary operator (domestic market focus). A business whose primary user base is Australian, whose banking is in AUD, and whose token product does not constitute a financial product needs AUSTRAC DCE registration as its first and foundational compliance layer. An offshore holding structure may still be optimal for tax and investment reasons, but the Australian operating entity must be registered. Indicative timeline from a clean, well-prepared submission: a matter of weeks, longer if AUSTRAC raises queries or the AML/CTF program requires revision. Key risk: underestimating the program development burden and submitting an underprepared application.

Profile B – Inbound global operator (Australia is one market of several). A business with an existing EU MiCA CASP authorisation or Singapore DPT licence that is adding Australia to its geographic reach should treat AUSTRAC registration as an add-on compliance project to its existing program infrastructure. The core governance, KYC/AML architecture and corporate structure are already built; the Australia application layer involves adapting those to meet AUSTRAC's specific requirements. Key risk: assuming the existing program is sufficient without adapting it explicitly to AUSTRAC standards – AUSTRAC examines for compliance with Australian requirements, not the standards of another regulator.

Profile C – Token issuer or DeFi operator. A business that does not operate a fiat-to-crypto exchange but does issue tokens or operates protocol infrastructure needs a two-step analysis: first, whether the DCE definition is triggered at all; second, whether the ASIC financial-product perimeter is triggered. Operators in this profile often engage ASIC before AUSTRAC. Key risk: a classification error that leaves the business regulated by both bodies without having applied to either.

A common assumption we encounter is that a single offshore licence – typically from a well-regarded hub such as Estonia (pre-MiCA), the BVI or Cayman – is sufficient to serve Australian clients without additional registration. That assumption is incorrect. AUSTRAC's registration obligation is triggered by the geographic reach of the service. Allied counsel in the relevant offshore jurisdiction can confirm the foreign licence position, but the AUSTRAC obligation stands independently.

Self-Assessment: Are You Ready to File with AUSTRAC?

Before submitting a DCE registration application, a business should be able to confirm the following without qualification:

  • The business has conducted a documented ML/TF risk assessment specific to its own product, customer and channel profile – not a generic template.
  • An AML/CTF program is drafted, board-approved and ready for adoption on registration.
  • All beneficial owners and controlling persons have been identified and their backgrounds assessed for disqualifying factors.
  • The business has legal advice confirming that its token product does not constitute a financial product requiring an AFSL, or has separately commenced the AFSL process.
  • The business has a banking solution – or a credible plan for one – that can operate from registration date.
  • The business has mapped its Travel Rule obligations and has a solution in place or under active development.
  • The business has assessed whether any Australian-sourced income triggers withholding or reporting obligations under ATO rules.
  • Ongoing reporting obligations – suspicious matter reporting, annual compliance report – have been assigned to a named responsible person within the business.

If any item above is unresolved at the point of submission, the application is likely to attract an information request, delay the process or, in the worst case, produce a registration that later becomes a liability when the gap surfaces in an AUSTRAC examination. Preparation is, practically, the timeline.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

For AUSTRAC DCE registration in Australia, the timeline depends on the completeness of the application and the adequacy of the AML/CTF program submitted. A well-prepared application – with a risk-based AML/CTF program, complete beneficial ownership documentation and no disqualifying history – is generally processed within a matter of weeks. Applications that prompt an information request from AUSTRAC will take longer. Building the program correctly before submission is the single most reliable way to control the timeline.

Which jurisdiction is best for licensing my crypto business?

There is no universally optimal jurisdiction; the right answer depends on where your users are, where your banking sits, what products you offer and what holding structure is most tax-efficient. Australia is a significant and well-regulated market worth registering for directly if you have material Australian exposure. For a business serving multiple markets, Australia typically sits alongside – not instead of – registrations in the EU (MiCA CASP), Singapore (MAS DPT) or another leading hub. We map the full multi-jurisdiction stack as a single mandate.

Do I need a separate custody licence?

In Australia, custody of crypto assets sits in a regulatory grey area that is actively evolving. AUSTRAC DCE registration covers exchange activity. If the custody function involves holding financial products on behalf of clients, ASIC's financial-services regime may be triggered separately, requiring AFSL authorisation with a custody condition. An operator holding crypto assets that are not financial products – the majority of exchange operators – does not currently require a specific custody licence beyond the AUSTRAC registration, but this position should be confirmed against current ASIC guidance and, critically, reviewed as the Australian regime continues to develop.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – mapping the licence stack across operating, custody and payment layers before you commit. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-hub VASP registration strategy and inbound market-entry compliance for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours