EST · MMXXVI
Home/Jurisdictions/Digital-Asset Licensing in Australia (AUSTRAC): What Businesses Need to Know
Licensing & Registration

Digital-Asset Licensing in Australia (AUSTRAC): What Businesses Need to Know

Digital-Asset Licensing in Australia (AUSTRAC): What Businesses Need to Know. Cross-border digital-asset legal counsel for business – licensing, disputes and st

Operating an exchange, a payments platform, or a custody service in Australia without understanding your registration obligations under AUSTRAC (the Australian Transaction Reports and Analysis Centre) is not a calculated risk – it is an enforcement event waiting to happen. Australia's digital-asset regime imposes registration requirements on any business that provides digital-currency exchange or digital-currency transfer services to customers, regardless of where the business entity is incorporated. A foreign operator serving Australian users from a Singapore or BVI structure still falls within scope. The consequence of missing that threshold is not a warning letter: it is civil penalty proceedings, de-banking, and the loss of the local banking relationships that keep a payments business alive.

This page maps the Australian regulatory regime for digital-asset businesses – who must register, what the process involves, how AUSTRAC's regime interacts with the broader licensing stack a global operator needs, and where the structural pressure points sit for an inbound business.

Who Regulates Digital Assets in Australia, and Under What Regime?

AUSTRAC – Australia's financial intelligence agency and anti-money laundering regulator – is the primary regulator for digital-asset businesses operating in Australia. It administers the Anti-Money Laundering and Counter-Terrorism Financing Act (the AML/CTF Act), which defines the regulated population and the compliance obligations that follow. Under the AML/CTF Act, businesses that provide designated services involving digital currency must register as Digital Currency Exchange (DCE) providers on the AUSTRAC Digital Currency Exchange Register before they commence operations.

Registration is not equivalent to authorisation under a financial services licence. Australia operates a two-track regulatory structure for digital-asset businesses. AUSTRAC registration governs AML/CTF obligations: know-your-customer procedures, transaction monitoring, threshold-transaction reporting, and suspicious-matter reporting. A separate track – licensing under the Australian Financial Services Licence (AFSL) regime administered by the Australian Securities and Investments Commission (ASIC) – applies where the digital asset in question constitutes a financial product under the Corporations Act. Whether a token is a financial product turns on its characteristics: does it confer rights analogous to a managed investment scheme, a derivative, or a debenture? That analysis is fact-specific and must be conducted before an operator launches any product.

Operators we advise regularly underestimate this two-track structure. They obtain AUSTRAC registration and assume the box is checked. In practice, a staking product, a yield-bearing token, or a leveraged trading facility may trigger AFSL obligations independently. The first filing does not extinguish the second question.

Who Needs to Register with AUSTRAC?

Any business that exchanges digital currency for fiat currency, or exchanges one digital currency for another, on behalf of customers is a DCE provider and must register with AUSTRAC before providing the service. The trigger is functional, not structural: it attaches to the service, not to where the company is incorporated or where its servers sit.

This has a direct consequence for cross-border operators. A Cayman-incorporated exchange whose mobile application is available in Australian app stores and whose customer-facing website accepts Australian-dollar payment methods will, in most circumstances, be providing a designated service to Australian customers. AUSTRAC's jurisdiction follows the customer. Operators relying on geoblocking alone – without a documented, enforced access-restriction mechanism – are unlikely to satisfy the regulator that the service is genuinely unavailable in Australia.

Beyond DCE providers, the following business types frequently face registration or licensing questions in Australia:

  • Businesses operating digital-currency transfer services (the functional equivalent of remittance for crypto).
  • Custodians holding digital assets on behalf of clients, where the custodial arrangement is structured to avoid AFSL characterisation but the AML/CTF nexus remains.
  • Operators of automated market-maker or liquidity-provision infrastructure that interacts with retail customers.
  • Stablecoin issuers whose product is used for payments within Australia, where the stored-value or payment-facility analysis under the Payment Systems (Regulation) Act may also apply.

The expanding scope of both AUSTRAC and ASIC means that a legal characterisation prepared two years ago may no longer be current. Australia has been actively consulting on reform to bring its digital-asset regime closer to the licensing models seen in Singapore and Hong Kong, and any operator should treat their legal position as requiring periodic review rather than a one-time assessment.

To map whether your business model triggers AUSTRAC registration, AFSL obligations, or both, contact OBOLUS at info@oboluslaw.com. The process above describes the standard registration path. Your facts – the entity structure, the user base, the product type, the banking – change the analysis materially.

What Does AUSTRAC Registration Require in Practice?

AUSTRAC registration for a DCE provider requires the business to enroll on the AUSTRAC Online portal, submit identification details for the business and its beneficial owners, and demonstrate that an AML/CTF program is in place before the service opens to customers. Registration is not a passive filing: it initiates an ongoing compliance relationship with the regulator.

The core obligations that attach on registration include:

  • AML/CTF program: a written, risk-based program covering customer due diligence, enhanced due diligence for higher-risk customers, and an employee training framework.
  • Know-your-customer (KYC) procedures: customer identification and verification at onboarding, with ongoing monitoring obligations.
  • Transaction monitoring: systems capable of identifying unusual or suspicious transactions in real time.
  • Threshold-transaction reports (TTRs): mandatory reporting to AUSTRAC for transactions above the prescribed cash-related threshold (note: the specific current threshold is a [VERIFY] item – confirm from the AUSTRAC website before relying on any figure in market commentary).
  • Suspicious-matter reports (SMRs): obligation to file promptly on formation of suspicion, not on proof.
  • Annual compliance reports: lodged with AUSTRAC confirming the program remains effective.

The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data with digital-asset transfers – applies in principle to Australian DCE providers and is a live area of regulatory development. The de minimis threshold at which Travel Rule obligations attach is a [VERIFY] item that operators must confirm from current AUSTRAC guidance, as Australia has been aligning its implementation with FATF standards on an ongoing basis.

In our cross-border practice, the AML/CTF program is consistently the element that under-resourced operators build too lightly. A program that satisfies a smaller, lower-risk business will not satisfy an exchange processing volume at the level that attracts AUSTRAC supervisory attention. The program must be calibrated to the actual risk profile of the product and the customer base.

How Does the AFSL Regime Apply to Digital Assets?

An Australian Financial Services Licence (AFSL) is required where a business provides financial services in respect of financial products, and the central question for any digital-asset operator is whether its products or services cross that threshold. ASIC administers the AFSL regime and has issued guidance on when digital assets constitute financial products – but the analysis remains intensely fact-specific, and the guidance does not map neatly onto novel product structures.

The following product types carry the highest risk of AFSL characterisation:

  • Tokenised managed funds, yield products, or pooled investment structures.
  • Derivatives referencing digital-asset prices (including synthetic exposure products, prediction markets, or leveraged trading).
  • Digital tokens that confer rights to a share of revenue or profit.
  • Stablecoins structured as stored-value facilities where the redemption mechanism resembles a debenture.

Where AFSL obligations apply, the compliance burden is substantially higher than AUSTRAC registration alone. An AFSL holder must meet conduct obligations under the Corporations Act, maintain adequate financial resources, hold professional indemnity insurance, and comply with ASIC's ongoing disclosure and reporting requirements. The responsible manager framework – under which the licence applicant must nominate individuals with the relevant knowledge and experience – is a material constraint for lean crypto-native teams that lack personnel with recognised Australian financial-services credentials.

A common structural approach is to house the AUSTRAC-registered exchange function in one entity and the managed-investment or derivative-adjacent products in a separate licensed entity. Whether that structure is viable depends on the product design, the group's capital position, and the banking arrangements. We map this analysis before an operator commits to a structure.

What Are the Cross-Border Realities for an Inbound Operator?

For a business already licensed under MiCA in the EU, under the MAS Payment Services Act in Singapore, or under the SFC's VASP regime in Hong Kong, the Australian position requires a separate local analysis. Australian law does not grant mutual recognition to foreign licences. A MiCA CASP authorisation – even one that includes custody and exchange services across the EU/EEA – provides no regulatory coverage in Australia. Each jurisdiction stands alone.

The banking dimension compounds the regulatory question. Australian banks have historically applied heightened due diligence to digital-asset businesses, and securing a business transaction account as a DCE provider requires demonstrating to the bank that the AUSTRAC program is in place, that AML/CTF controls meet the bank's own risk appetite, and – in many cases – that the business has engaged external compliance counsel to review the program. Operators who attempt to open banking before the compliance infrastructure is built consistently encounter refusals or account closures.

The Australian dollar payment rail – where most retail crypto-to-fiat conversion occurs – sits outside the crypto layer entirely. Access to the New Payments Platform (NPP) and to direct-entry settlement requires a relationship with an APRA-regulated authorised deposit-taking institution (ADI). Some DCE operators access this indirectly through a payments intermediary. That intermediary has its own risk-appetite constraints, and the operator's AUSTRAC compliance posture is the gating factor.

For an operator with a global user base, the structural question is whether to establish an Australian subsidiary as the AUSTRAC registrant – capturing the local banking relationship and the regulatory status – or to maintain a foreign parent that relies on geographic restrictions. In our practice, operators who choose the latter frequently revisit the decision when their Australian user numbers grow and the bank begins asking questions about the nature of inbound flows.

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw.

How Does Australia Compare for an Inbound Operator Choosing a Licensing Base?

Australia offers a common-law legal environment, a well-developed dispute resolution system, and a large, sophisticated retail and institutional market for digital assets. For an operator whose primary business case is serving Australian customers, the domestic licensing question is not optional. But for an operator assessing Australia as a licensing base from which to serve a broader region, the comparison with Singapore, Hong Kong, and the UAE is important.

Singapore's MAS Payment Services Act offers a tiered licensing structure with a developed institutional market and a well-understood process. Hong Kong's SFC VASP regime is designed explicitly for exchange operators and comes with a detailed regulatory expectation framework. The UAE – through VARA in Dubai or the FSRA within ADGM – provides an activity-based licensing model in a low-tax, free-zone environment with active regulatory engagement. Australia's AUSTRAC regime is primarily AML/CTF-focused rather than a comprehensive financial-services authorisation, which means that an operator who also needs AFSL authorisation faces a two-regulator compliance architecture.

The relevant profiles for the Australian-market decision are broadly as follows.

Profile A – Domestically focused exchange or payments operator: AUSTRAC registration is non-negotiable. The operator should assess AFSL requirements for any product beyond spot exchange. The banking relationship is the critical dependency. Timeline for registration is a [VERIFY] item – AUSTRAC publishes current processing expectations on its website, and operators should confirm before planning a launch date.

Profile B – Global operator entering Australia as one market: The operator should assess the territorial scope of its existing licences and the cost of a standalone Australian registration against the revenue opportunity. A subsidiary structure providing the local regulatory face, with the global group providing technology under a services agreement, is a common architecture. Transfer-pricing and corporate-tax analysis follows.

Profile C – Operator seeking an Asia-Pacific licensing base: Australia is a strong choice if the primary market is Australian customers, but it is not a passporting jurisdiction. An operator seeking regional coverage across APAC will need separate registrations or licences in each of the markets it serves. Singapore remains the more frequently chosen APAC hub for regional-coverage strategies, given the MAS framework's depth and the breadth of institutional relationships accessible from Singapore.

In a recent matter, a digital-payments operator sought to consolidate its APAC licensing footprint before a Series B close. We assessed registration obligations across four jurisdictions simultaneously, identified that the Australian DCE registration was the critical-path item for the operator's existing product, and structured the sequence of applications to avoid a period of non-compliance in the highest-volume market. The banking documentation – prepared alongside the AML/CTF program – was submitted to the operator's target Australian bank before registration was confirmed, reducing the post-registration delay to account opening to a matter of days.

What Are the Most Common Mistakes in the AUSTRAC Registration Process?

Mistakes in AUSTRAC registration cluster around three failure modes that we see with regularity across inbound and domestic operators alike.

The first is commencing operations before registration is confirmed. The registration trigger is commencement of the designated service, not commencement of solicitation. A business that begins onboarding customers – even in a "soft launch" phase – before its AUSTRAC registration is active is operating in breach. Enforcement action has followed from exactly this pattern in the Australian market. The solution is to treat AUSTRAC registration as a go/no-go condition for launch, not a parallel-track administrative task.

The second is building an AML/CTF program that is generic rather than calibrated. A template program downloaded from a compliance vendor may satisfy the literal requirement to have a written program without satisfying AUSTRAC's substantive expectation that the program reflects the actual risk profile of the business. An exchange serving high-net-worth customers in jurisdictions with elevated FATF risk ratings requires a materially different program from a low-volume retail peer-to-peer platform. AUSTRAC's supervisory focus has moved consistently toward quality of implementation, not just existence of documentation.

The third is treating the AUSTRAC registration as the end of the compliance analysis. As discussed above, the AFSL question, the Payment Systems (Regulation) Act question, and – for certain stablecoin and lending products – the National Consumer Credit Protection Act question are all independent triggers that registration does not address. A common assumption is that AML/CTF registration provides regulatory cover for all digital-asset activities in Australia. It does not. The AUSTRAC register establishes that the operator is a known and supervised entity for AML/CTF purposes; it says nothing about whether the products and services are lawfully offered under financial services or consumer credit law.

Self-Assessment: Key Questions Before You Launch in Australia

Before committing to an Australian market entry or a product launch, the following questions establish whether the legal architecture is sound.

  • Does the business provide digital-currency exchange or transfer services to Australian customers? If yes, AUSTRAC registration is required before launch.
  • Is any product offered – staking, yield, leveraged trading, tokenised fund interests – likely to constitute a financial product under the Corporations Act? If yes, AFSL analysis is required independently.
  • Is the AML/CTF program written, risk-calibrated to the actual product and customer base, and operationally ready before day one?
  • Have beneficial ownership details for all relevant persons been prepared and verified, ready for the AUSTRAC enrollment process?
  • Has the banking relationship been initiated in parallel with registration preparation, with the AML/CTF program available for bank due diligence?
  • If the operator is a foreign entity, has the territorial scope of existing foreign licences been confirmed as not extending to Australia?
  • Has the Travel Rule implementation position been documented and aligned with current AUSTRAC guidance?

We map the licence stack across operating, custody, and payment layers before a client commits to an Australian launch. The cost of a pre-launch structural review is a fraction of the cost of an enforcement inquiry or a de-banking event after operations have commenced.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline varies by jurisdiction and by the completeness of the application at submission. AUSTRAC DCE registration in Australia can be completed in a matter of weeks where the AML/CTF program, beneficial-ownership documentation, and entity details are prepared before lodgment. Regulatory authorisations under other regimes – such as an AFSL with ASIC, or a VASP licence under the MAS or SFC frameworks – typically take longer and involve substantive regulatory review. Confirm current processing expectations directly with the relevant regulator before planning a launch date.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction. The right choice depends on where your customers are, the nature of your products, your capital position, your banking requirements, and your tax structure. Australia is the right answer if your primary market is Australian users: the AUSTRAC registration is non-negotiable in that case. For businesses seeking a regional hub, Singapore, Hong Kong, and the UAE each offer distinct advantages. A multi-jurisdiction licensing strategy – with each entity holding the licence relevant to its market – is the standard approach for global operators at scale.

Do I need a separate custody licence?

In Australia, custody of digital assets may engage either the AFSL regime (if the assets are financial products), the AUSTRAC AML/CTF obligations (if the custodian exchanges or transfers digital currency), or both. Whether a standalone custody licence is required depends on the asset types held, the client base, and whether discretionary management or financial product dealing is involved. In other jurisdictions – Singapore, Hong Kong, the UAE – custody is a separately regulated activity with its own licence category. The answer is fact-specific and should be confirmed with counsel before structuring a custody offering.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions – including AUSTRAC registration, AFSL analysis, and the banking infrastructure that surrounds them. We map the licence stack across operating, custody, and payment layers before you commit. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums, including Australia's federal courts. Digital assets are the whole of our practice. To discuss your Australian market entry or licensing position, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialises in AUSTRAC registration, AFSL analysis, and multi-jurisdiction licensing strategy for digital-asset businesses entering the Asia-Pacific region.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours