AML/CTF · VASP

After the Deadline: The Ongoing VASP Obligations That Define Your Audit Readiness | VASP Australia 2026

Published 14 April 2026Last reviewed July 20265 min readBy Paul Wise

Enrolment is the start line. The ongoing compliance cadence — and why it should be designed for two regulators, not one.

Keep the program alive — the review rhythm

The fastest way to fail an inspection is to treat your AML/CTF program as a document you finished in July. The reformed regime expects it to stay current, with a real cadence rather than a single annual tick.

  • Keep it current as risks change. Your ML/TF/PF risk assessment must be reviewed to remain up to date. The obligation is trigger-based: new services, new delivery channels, new AUSTRAC guidance, material change to your business, or a change in your risk profile all require you to revisit it. A senior manager approves updates, and the governing body is notified of changes to the risk assessment. Your own policies set the review frequency between triggers — so set one, document it, and keep to it.
  • Your Compliance Officer reports to the governing body on how the program is performing. Your policies set the cadence. Whatever you choose, the records need to show the reporting actually happened.
  • You lodge an annual AUSTRAC compliance report each year, covering the prior calendar year. This obligation continues for as long as you remain on the Reporting Entities Roll.
The compliance report, the governing-body report, and the program review are three separate recurring obligations. Missing any of them is the kind of gap that surfaces in a compliance assessment.

Suspicious Matter Reports — know the two clocks

Once you are operating, SMRs are live. When you form a suspicion on reasonable grounds, the deadline depends on what you suspect:

  • 24 hours if it relates to terrorism financing, or a person's physical safety.
  • 3 business days for money laundering or any other offence.

The trigger is reasonable grounds to suspect — you do not need proof — and the obligation can arise even where you decline the transaction. Note these are three business days, not 72 hours.

Cross-border transfers — the travel rule, not "IFTI for crypto"

This is where crypto businesses most often get the wrong end of the stick.

For virtual asset transfers, your cross-border obligation is the travel rule, which applies from 1 July 2026: originator and beneficiary information must travel with the transfer, and you must conduct counterparty-VASP due diligence before transacting.

The separate international value transfer service (IVTS) reporting obligation — the framework that will eventually replace the old IFTI reports — is deferred. Until your IVTS transition date, you continue reporting IFTIs under the pre-reform rules and exemptions. Confirm your own transition date against current AUSTRAC guidance.

So: a pure virtual asset transfer does not automatically carry the old IFTI reporting obligation. But if you also move money or property across borders, those reporting duties can apply to that activity. Build travel rule capability now, and get advice on whether any value-transfer reporting applies to your specific model.

One corollary worth stating plainly: the travel rule attaches to transfers, not to exchange. But if you provide exchange services — the classic fiat-to-crypto business — your other reformed obligations (program, CDD, reporting, record-keeping) commenced on 31 March 2026, not 1 July. The travel rule is the one obligation where the later date is the right one for you.

Independent evaluation

The reforms replaced the old independent review with an independent evaluation of your entire program — your risk assessment, your policies, and how they work in practice. It must be conducted by someone genuinely independent of the program's design and operation, and the written report goes to your governing body and senior management.

AUSTRAC's position is that your AML/CTF policies set the frequency of these evaluations. The transitional rules then give staggered deadlines for your first post-reform evaluation, keyed to your AUSTRAC Account Number, which you receive when you enrol. Find your own deadline rather than assuming a standard interval — the staggering is deliberate, and yours will not be the same as the business next door.

"Independent" means genuinely outside the program's design and operation. Plan for the cost and lead time of an external evaluation from the start, not when the clock has nearly run.

Governance and board oversight

The program has to be governed. The reformed framework puts explicit emphasis on the governing body and senior management: they hold ongoing oversight, receive the compliance reports and independent evaluation, and are expected to question adverse findings. Your records need to show that oversight is real, not symbolic.

Board-ready reporting is what turns "we did the work" into "we can evidence it."

Governance designed for two regulators

This cadence intensifies if the Digital Assets Framework Act 2026 applies to your business. From 9 April 2027, operators of digital asset platforms and tokenised custody platforms will need an AFSL — subject to exemptions, which have several limbs and should be assessed with advice rather than against a headline threshold.

A VASP holding an AFSL faces parallel governance obligations under both regulators: separate compliance reporting, breach reporting under the Corporations Act (the reportable-situations regime, with a 30-calendar-day timeframe), responsible manager obligations, and conduct monitoring.

If that is your trajectory, the board oversight structure you build now should accommodate it from day one:

  • Your compliance officer should be scoped to cover both AML/CTF and AFSL functions, with the authority and resources for both.
  • Your board reporting framework should carry AML/CTF performance (SMRs, alerts, risk assessment updates) and AFSL performance (breaches, complaints, conduct monitoring) in a single cadence.
  • Your risk management methodology should be expandable to incorporate AFSL risk domains — conduct risk, conflicts risk, client money risk — alongside ML/TF/PF risk.
  • Your audit trail should capture compliance actions across both regimes in one system of record.

Building two separate governance frameworks and merging them after the fact costs more and is more disruptive than designing a unified structure from the start.

Worth saying plainly: crypto is not the first sector to live under both AUSTRAC and ASIC. Australian financial services licensees that provide designated services — FX and payments businesses, some accounting and advisory firms — have run both regimes for years. What is new is that a large part of the digital asset sector is about to join them.

Where Veriqua fits

Ongoing cadence is exactly where things slip manually. Veriqua holds the rhythm.

On every AML plan: suspicious matter, threshold transaction and international funds transfer registers with the statutory clocks built in; risk assessment reviews with approval and sign-off; AUSTRAC reporting; the annual report to your governing body; and board packs compiled from live compliance data rather than assembled by hand. Every action sits on an audit-ready trail hosted in Australia — so audit readiness is a continuous state, not a scramble.

From the Professional tier: independent review scheduling with reviewer sign-off, transaction monitoring, customer risk ratings and the beneficial ownership register.

Because Veriqua supports AUSTRAC and ASIC obligations in one system, your ongoing cadence — board reports, breach registers, complaints tracking, obligations monitoring — can run from a single platform, producing one board pack covering both regimes rather than two disconnected reports from two disconnected systems. See the ongoing-compliance tools in two minutes, no login: demo.veriqua.com.au/start.

See how Veriqua handles this

Veriqua is an Australian compliance operating system for AFSL holders and AUSTRAC reporting entities — automating AML/CTF programs, customer due diligence, transaction monitoring, SMR lodgement and board reporting.

Disclaimer: Plain-English information for Australian crypto businesses. General information only — not legal or compliance advice. Reporting obligations (including the travel rule and any value-transfer reporting), evaluation timing and governance duties are technical and carry transitional nuances. Confirm your position against current AUSTRAC and ASIC guidance and the relevant legislation, and seek advice for your circumstances.