AML/CTF · VASP

DCE → VASP: What Actually Changed in Your AML/CTF Program | VASP Australia 2026

Published 5 May 2026Last reviewed July 20266 min readBy Paul Wise

This is only the AUSTRAC side

Before the detail: the AML/CTF changes below are significant, but they are only the AUSTRAC half of what is coming.

The Corporations Amendment (Digital Assets Framework) Act 2026 received Royal Assent on 8 April 2026 and commences on 9 April 2027. It brings digital asset platforms and tokenised custody platforms into the AFSL regime. Crypto businesses meeting those definitions — and falling outside the exemptions — will hold an AFSL alongside their AUSTRAC obligations.

That means the AML/CTF program you build now needs to account for a second regulator: governance structures, compliance officer responsibilities, board reporting and risk frameworks should be designed to serve both. That is covered in our companion article, The Dual-Regime Future.

Your commencement date is probably earlier than you think

Before anything else, work out which limb you are on — because the reformed obligations did not all start on the same day.

Exchanging virtual assets for money, or arranging that exchange. This is the classic fiat-to-crypto exchange business. The transitional deferral does not apply to you. Your reformed obligations — the rebuilt program, customer due diligence, reporting, record-keeping — commenced on 31 March 2026.

The newly registrable virtual asset services — crypto-to-crypto exchange, virtual asset safekeeping, and accepting instructions to transfer virtual assets — are deferred to 1 July 2026.

If you run a fiat-to-crypto exchange and have been working to a 1 July date, you have been working to the wrong one. A great deal of commentary aimed at the crypto sector flattens this to a single date and loses the distinction entirely.

The program structure changed — and it is not "two parts"

The biggest under-the-hood change applies to every reporting entity, VASPs included: the old program-structure split was abolished on 31 March 2026.

It is tempting to describe what replaced it as "two new parts." Resist that. AUSTRAC's position is that you no longer need to separate your program at all — you can organise it in whatever way meets your needs, provided it meets the requirements of the Act. Rebuilding a two-part mental model with new labels is precisely the habit the reform was designed to break.

What your program must now contain:

  • A documented ML/TF/PF risk assessment. Note the third letter. Proliferation financing is now assessed as a distinct category alongside money laundering and terrorism financing. This is new, and it is the most commonly missing element in programs that were merely 'updated' rather than rebuilt. The assessment must cover your virtual asset services, your customers, your channels (including self-hosted wallets and cross-chain activity), and the jurisdictions you touch.
  • AML/CTF policies, procedures, systems and controls that manage and mitigate the risks you identified. If your proliferation financing risk is low and is adequately addressed by your ML and TF policies, you are not required to write separate counter-proliferation policies — but you must have assessed it.
  • Roles and responsibilities. The reformed framework puts explicit weight on your governing body and senior management overseeing ML/TF risk and AML/CTF compliance. Appointing a fit and proper AML/CTF Compliance Officer responsible for implementing the program is now an explicit statutory requirement, not a matter of good practice.

For a crypto business this is more than a documentation exercise. Proliferation financing risk, counterparty risk and self-hosted wallet risk are exactly the areas a generic, recycled program will not address.

The Travel Rule — the operational headline

The change with the most operational weight is the travel rule, which applies from 1 July 2026. It attaches to transfers of value involving virtual assets — which sit inside the transitional deferral — rather than to exchange services.

When value moves, you must collect, verify and transmit the originator and beneficiary information that travels with the transfer, and conduct due diligence on counterparty VASPs before transacting with them.

Transfers involving self-hosted (unhosted) wallets are not outside the framework. There is no obligation to transmit travel rule information to a self-hosted wallet, but collection and verification obligations still apply: an ordering institution must collect and verify payer information and collect payee and tracing information, and a beneficiary institution receiving from a self-hosted wallet must obtain payer and tracing information before making the asset available.

In practice this changes the customer experience. A transfer that once needed only a wallet address may now require additional data, screening, holds or manual review.

CDD becomes risk-based — and the runway differs

The reformed customer due diligence framework is risk-based and outcomes-focused, split into initial CDD (before you act) and ongoing CDD (monitoring over time), with enhanced CDD for higher-risk customers and specified circumstances — a politically exposed person, for example, or where a suspicious matter reporting obligation arises. Beneficial ownership and PEP screening are squarely in scope.

The old safe-harbour approach is gone. The depth of verification must now match the actual risk of the customer.

The runway is not the same for everyone:

  • Existing reporting entities — including DCEs that converted to VASP — may continue using their existing applicable customer identification procedures (ACIP) for nominated classes of customers during a transitional period. To rely on this you had to be enrolled as a reporting entity before the reform commenced, and you must document in your policies which customer classes ACIP applies to and when each class transitions. You cannot run both approaches for the same class at the same time. The new ongoing CDD obligations apply to everyone from 31 March 2026.
  • Newly captured VASPs get no transitional relief. Full reformed CDD — including beneficial ownership and PEP screening — applies from the moment your obligations commence.

Where Veriqua fits

The shift from "we have a DCE program" to "we run a VASP program" is where a manual setup quietly falls behind.

Veriqua's program documents module — included on every AML plan — drafts your ML/TF/PF risk assessment and your AML/CTF policies from your own business data, structured the way the reformed regime expects, with proliferation financing as a distinct risk category rather than a paragraph inside an ML/TF section. Customer onboarding, initial and enhanced due diligence records, and the reporting registers are included as standard, all logged on an audit-ready trail hosted in Australia.

The pieces that answer the risk-based CDD shift specifically — customer risk ratings, the beneficial ownership register, and transaction monitoring — are available from the Professional tier.

Because Veriqua supports AUSTRAC and ASIC obligations together, the program structure you build now extends into an AFSL framework if the Digital Assets Framework Act applies to your business. See it in two minutes, no login: demo.veriqua.com.au/start.

See how Veriqua handles this

Veriqua is an Australian compliance operating system for AFSL holders and AUSTRAC reporting entities — automating AML/CTF programs, customer due diligence, transaction monitoring, SMR lodgement and board reporting.

Disclaimer: Plain-English information for Australian crypto businesses. General information only — not legal or compliance advice. Travel rule scope, CDD timing and self-hosted-wallet obligations carry transitional and fact-specific nuances. Confirm your position against current AUSTRAC guidance and the relevant legislation, and seek advice for your circumstances.