VASP licensing in Australia (AUSTRAC): Legal Requirements for Businesses
Operating a digital asset exchange, custody platform or payment service in Australia without registering as a digital currency exchange (DCE) provider under the AUSTRAC regime exposes the business to civil penalties, forced closure of banking relationships and potential criminal referral. The answer for most inbound operators is straightforward in principle: any business that exchanges digital currency for fiat, or exchanges one form of digital currency for another, in Australia or for Australian users, must register with the Australian Transaction Reports and Analysis Centre (AUSTRAC) before commencing operations. Registration is not optional, and AUSTRAC has demonstrated willingness to pursue unregistered operators. This page sets out the regulated perimeter, the registration process, the cross-border reality for non-resident businesses, and the decision points that determine whether Australia belongs in your licence stack.
What does the AUSTRAC regime actually regulate?
AUSTRAC supervises digital-asset businesses as designated services under the Australian anti-money-laundering and counter-terrorism-financing framework, and the DCE registration obligation sits within that AML/CFT architecture. The obligation turns on activity, not on where the corporate entity is incorporated. An operator registered in the BVI, Singapore or Estonia that accepts Australian residents as customers and provides exchange or peer-to-peer transfer services is, in the view of the regulator, carrying on a designated service in Australia and must register accordingly.
The core categories that trigger registration are the exchange of digital currency for fiat money, the exchange of one digital currency for another, and, importantly, the provision of digital-currency transfer services. AUSTRAC does not use the term VASP in its primary legislation – the operative concept is the designated service – but the functional coverage aligns closely with the FATF definition of a virtual asset service provider. Custodians that hold digital assets on behalf of clients may also fall within scope depending on whether their activity constitutes a designated service; this requires a case-by-case analysis of the precise rights and obligations involved.
Businesses that are already regulated by the Australian Securities and Investments Commission (ASIC) for financial services activities may have overlapping obligations. Tokens that constitute financial products under Australian law attract ASIC licensing requirements in addition to, not instead of, the AUSTRAC registration. The two regimes sit in parallel, and operators with a mixed service offering must satisfy both.
Who must register with AUSTRAC?
Any business providing a designated service involving digital currency must register with AUSTRAC before providing that service to any person in Australia. The threshold is not turnover-based and there is no de-minimis carve-out for small operators. A startup processing a handful of trades per day faces the same registration obligation as an established exchange handling institutional volume.
Notably, the obligation extends to foreign entities. A non-Australian company that provides DCE services to Australian residents is within scope. In our cross-border practice, we regularly advise operators who assumed that incorporation offshore and no physical presence in Australia was sufficient insulation. It is not. AUSTRAC applies a nexus test that focuses on where the customer is located and where the service is delivered, not on where the corporate vehicle sits.
Businesses that are part of a group should consider each legal entity separately. A group structure that channels Australian customer activity through a non-Australian entity does not eliminate the registration requirement if that non-Australian entity is itself providing the designated service. Group-wide compliance mapping – covering every entity that touches the Australian customer relationship – is essential before the first trade executes.
The AUSTRAC registration requirement applies to both new entrants and to businesses that were providing DCE services before the registration obligation came into force. Operators who were providing services and have not yet registered are already in breach.
How does the AUSTRAC registration process work?
The AUSTRAC registration process for DCE providers involves a formal online application through the AUSTRAC Business Portal, supported by an AML/CTF program that the business must have in place before applying. The process is administrative in character but substantive in its compliance demands: AUSTRAC expects a documented, risk-based AML/CTF program that covers customer due diligence, enhanced due diligence for higher-risk customers, ongoing transaction monitoring, and the designation of an AML/CTF compliance officer.
There are two parts to a compliant AML/CTF program. Part A covers the risk assessment, governance, internal controls and compliance officer appointment. Part B covers the customer identification program. Both must be complete and operational, not aspirational, at the time of registration. AUSTRAC has historically declined registrations where the program exists as a document but lacks operational substance – trained staff, working systems, tested procedures.
The timeline for AUSTRAC registration, once the application is properly submitted with a complete program, is generally measured in weeks rather than months. However, if AUSTRAC requests additional information or assurance that the AML/CTF program meets the standard, that period extends. We have seen AUSTRAC seek clarification on the beneficial ownership structure of the applicant entity, particularly where there are intermediate holding layers or non-resident directors. Preparing a clean corporate structure disclosure at the outset shortens the process materially.
After registration, AUSTRAC-registered businesses must report. Threshold transaction reports are required for cash transactions above the applicable threshold. International funds transfer instructions must be reported. Suspicious matter reports must be filed promptly when a business has grounds for suspicion. Failure to report is an independent basis for regulatory action, separate from any question of underlying criminal activity.
The AML/CTF program must be reviewed and kept current as the business's services and risk profile change. A program written for a spot-exchange service does not automatically cover a lending or staking product added later. Each new designated service requires its own risk assessment and program adjustment.
Contextual bridge: The registration process itself is manageable. The compliance architecture required to sustain it is ongoing and substantive. If you are mapping the AUSTRAC process for the first time or redesigning a program that has grown stale, the structure of your entity and your service mix determines where the complexity lies.
To map your entity's AUSTRAC obligations before you apply, contact OBOLUS at Map your options.
What ongoing AML/CFT obligations apply after registration?
Registration is the entry point, not the endpoint. AUSTRAC-registered DCE providers carry a continuing set of AML/CTF obligations that run for the life of the registration and must be resourced accordingly. These obligations track the FATF Recommendation 15 standard for virtual-asset service providers, adapted to the Australian legislative architecture.
Customer due diligence – the process of verifying the identity of customers and understanding the nature of the business relationship – is mandatory at onboarding and must be refreshed when the customer's risk profile changes. For business customers, this extends to identifying beneficial owners behind the entity. The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) is increasingly part of the compliance conversation for Australian operators, as AUSTRAC aligns its expectations with the FATF standard on virtual-asset transfers.
Transaction monitoring must be risk-based and genuinely operational. A static rule set that was calibrated at launch and never updated does not satisfy the standard. Operators we advise routinely underestimate the resource required to keep monitoring rules current as transaction patterns evolve.
AUSTRAC conducts compliance assessments. It can examine an operator's AML/CTF program, request records, and – where it identifies material deficiencies – impose enforceable undertakings, civil penalties or refer the matter for criminal investigation. The enforcement history in Australia includes significant penalty outcomes against large financial institutions; AUSTRAC has shown it applies the same framework to digital-asset businesses.
How does the AUSTRAC requirement interact with offshore structures?
For an inbound operator, the interaction between AUSTRAC registration and an existing offshore licence is one of the most consequential structural questions. AUSTRAC registration does not substitute for, or replace, any other jurisdiction's licence requirement – and conversely, an offshore licence does not satisfy the Australian obligation. The two run in parallel.
A business licensed in Singapore under the Payment Services Act, or authorised as a CASP under the EU MiCA regime, must still register with AUSTRAC if it serves Australian customers. There is no mutual recognition arrangement between AUSTRAC and the major VASP regimes. This is a material cost point: the compliance program, the reporting infrastructure and the officer appointment must all be maintained independently for Australia.
The banking dimension is closely connected. Australian banks have taken a cautious posture toward digital-asset businesses. An AUSTRAC-registered entity is not guaranteed access to banking, but an unregistered entity will find banking essentially unavailable. In our practice, we map the licence, banking and compliance stack together, because a registration that cannot be banked is commercially inert.
Tax is a separate but related axis. The Australian Taxation Office (ATO) treats digital assets as property for capital gains tax purposes. For an inbound operator structuring Australian operations, the interaction between the corporate structure, the AUSTRAC registration entity, and the applicable tax treaty (if any) is a live issue that should be addressed at the structuring stage, not after banking is in place.
A micro-matter from our recent practice illustrates the point. An exchange operator headquartered in a European jurisdiction had been accepting Australian customer registrations through its main entity for several months before engaging counsel. The entity had no AUSTRAC registration and no AML/CTF program adapted to Australian requirements. We structured a compliant Australian-nexus entity, prepared the required program, and managed the AUSTRAC registration process, bringing the operator into compliance before regulatory attention crystallised. The business was able to retain its existing Australian customer book and re-establish banking relationships within the same quarter.
Does ASIC licensing apply alongside AUSTRAC registration?
For businesses offering products that qualify as financial products under Australian law, the ASIC licensing layer sits alongside the AUSTRAC registration and cannot be avoided by structuring the product as a "utility" token or a "non-financial" service. The classification question turns on the rights the product confers, not on what the issuer calls it.
Stablecoins, derivatives over digital assets, managed investment products and certain tokenised debt instruments are likely to be financial products for Australian purposes. An exchange or platform that offers these alongside spot trading will need to assess both the Australian Financial Services Licence (AFSL) requirement (administered by ASIC) and the AUSTRAC registration. Failing to obtain an AFSL while offering a regulated financial product is a separate and serious breach, independent of the AUSTRAC position.
The distinction between a DCE and a financial product provider also determines which consumer-protection, disclosure and conduct obligations apply. AUSTRAC is primarily an AML/CTF regulator; ASIC is the conduct and market-integrity regulator. Operators in the grey zone – platforms offering both spot crypto and derivative products – should expect to be examined by both.
For businesses sitting at the AUSTRAC/ASIC intersection, a legal mapping of the product suite against both regulatory perimeters is the right starting point. If your product set has grown beyond simple spot exchange, the analysis may have shifted. Contact OBOLUS at Map your options.
Is Australia the right jurisdiction for your digital-asset business?
Australia is a well-regulated, English-language, common-law market with a significant retail and institutional digital-asset user base – and AUSTRAC registration is the minimum compliance cost of serving it. The decision of whether to establish an Australian-registered operating entity, versus serving Australian customers through a foreign-registered entity with a standalone AUSTRAC registration, turns on commercial scale, banking access, and the risk tolerance of the founding entity.
For operators whose primary market is the Asia-Pacific region, Australia is often part of a multi-jurisdictional stack that may also include Singapore (MAS Payment Services Act), Hong Kong (SFC VASP licensing), and one or more offshore centres for holding and treasury. AUSTRAC registration handles the Australian customer layer; it does not itself provide a passport into those other regimes.
A practical decision matrix for inbound operators:
An operator whose Australian user base is small relative to total book but growing should consider a standalone AUSTRAC registration held by the main entity, with a compliant AML/CTF program scoped to Australian-nexus transactions. The compliance overhead is manageable; the risk of operating without registration is disproportionate.
An operator building primarily for the Australian market, or seeking Australian institutional relationships, should assess whether a locally incorporated entity – with its own AUSTRAC registration, its own banking, and potentially an AFSL where products require it – is the stronger foundation. This adds incorporation and governance costs but simplifies banking discussions and positions the business as a local operator rather than an offshore one.
An operator with a complex product suite spanning spot, custody and derivatives must run all three regulatory layers – AUSTRAC, ASIC and, where applicable, the AFSL framework – simultaneously. Sequencing these incorrectly is a common and costly mistake. We have seen operators launch a derivatives product on the assumption that spot-exchange registration covered it; it does not.
A common assumption is that a single offshore licence – a well-regarded registration in a major VASP hub – is sufficient to serve customers in markets like Australia. It is not. Australia applies its own nexus test, its own reporting obligations and its own enforcement framework. The offshore licence may support the commercial proposition and the banking relationship, but it does not satisfy the AUSTRAC requirement and cannot substitute for it.
Related at OBOLUS
- Digital Asset Licensing and Registration – cross-jurisdictional licensing strategy and execution for exchanges, custodians and issuers
- Licence Renewal and Variation in the Czech Republic – managing licence changes and renewals under the Czech VASP and MiCA transition regime
- Fund Domicile Selection for Digital Asset Firms – legal counsel on domicile, structure and regulatory positioning for digital-asset funds
FAQ
How long does a crypto licence take to obtain?
For AUSTRAC DCE registration in Australia, the process typically takes several weeks once a complete application and a compliant AML/CTF program are submitted. Where AUSTRAC requests further information – most commonly on beneficial ownership structure or program adequacy – the timeline extends. In other jurisdictions, registration or authorisation timelines range from a matter of weeks to many months depending on the regime, the licence category and the completeness of the application package.
Which jurisdiction is best for licensing my crypto business?
There is no single answer. The right jurisdiction depends on where your customers are located, what services you provide, where your banking sits, and your appetite for ongoing compliance cost. For businesses serving Australian users, AUSTRAC registration is non-negotiable regardless of where the corporate entity is incorporated. Broader licence strategy – whether to add Singapore, the EU, or an offshore centre – turns on the full commercial and regulatory picture. We map that stack before you commit.
Do I need a separate custody licence?
In Australia, custody of digital assets may or may not constitute a regulated designated service depending on the precise nature of the arrangement and whether it involves a financial product. Where custody involves holding assets that are financial products, an AFSL may be required in addition to AUSTRAC registration. Many other jurisdictions regulate custody as a distinct licensed activity. The answer is always fact-specific, and the cost of getting it wrong – operating without the required authorisation – outweighs the cost of the analysis.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit, so that the compliance architecture is built for the business you are building, not the one you started with. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in APAC and cross-border VASP registration strategy, including AUSTRAC compliance architecture for inbound operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.