AML/CTF · VASP

Is Your Crypto Business Ready? The VASP Compliance Checklist | VASP Australia 2026

Published 18 May 2026Last reviewed July 20265 min readBy Paul Wise

Use this checklist to find your gaps, then confirm each item against AUSTRAC guidance and your own risk assessment. It is general information, not legal advice.

The AUSTRAC readiness checklist

Enrolment and registration sorted — and know which case you are in

If you were a registered DCE before 31 March 2026: you were automatically converted to VASP. No re-enrolment, no re-registration. But you must update your enrolment information as a VASP in AUSTRAC Online by 29 July 2026, and update your registration details before your next scheduled renewal.
If you are newly captured: you must apply to enrol and register by 29 July 2026. Importantly — if you apply before that date, the transitional rules let you keep providing the new virtual asset services until AUSTRAC decides your application. You do not have to stop trading while you wait. What you must not do is provide registrable virtual asset services without having applied at all.

AML/CTF Compliance Officer appointed and notified

A fit and proper person, at management level, with the authority and resources to run the program. This is now an explicit statutory requirement.

  • Existing reporting entities: notification was due 30 May 2026. If you missed it, notify now.
  • Newly regulated businesses: the deadline is tied to your enrolment date, not a flat calendar date. Confirm your own date against current AUSTRAC guidance.

Know your actual commencement date — it may be earlier than 1 July

The reformed obligations did not all start on the same day, and this is the most commonly missed point in the sector.

  • Exchanging virtual assets for money, or arranging that exchange (the classic fiat-to-crypto exchange): the transitional deferral does not apply. Your reformed obligations — program, CDD, reporting, record-keeping — commenced 31 March 2026.
  • Newly registrable virtual asset services (crypto-to-crypto exchange, virtual asset safekeeping, accepting instructions to transfer virtual assets): deferred to 1 July 2026.
  • If you provide both, the earlier date applies to your exchange activity and the later date to the rest.

ML/TF/PF risk assessment in place

Your written assessment of money laundering, terrorism financing and proliferation financing risk across your services, customers, channels (including self-hosted wallets) and jurisdictions.

Proliferation financing as a distinct category is new. If your risk assessment only covers ML and TF, it is not built for the current regime — and this is the most common gap in programs that were updated rather than rebuilt.

AML/CTF policies in place

The policies, procedures, systems and controls that manage and mitigate the risks your assessment identified. Note that the old program-structure split was abolished on 31 March 2026 — you now run a single program, organised however suits your business, provided it meets the Act.

Governance and roles documented

Your governing body and senior management have explicit oversight responsibility for ML/TF risk and AML/CTF compliance. Document who does what, and evidence that the oversight is real.

CDD procedures live, including wallet attribution

Risk-based initial and ongoing CDD: identifying and verifying customers and beneficial owners, screening for PEPs, applying enhanced CDD to higher-risk customers.

Newly captured VASPs get no CDD transition — it applies in full from commencement. Existing reporting entities may use the ACIP transitional path for nominated customer classes, but must document which classes and when they transition, and must apply the new ongoing CDD obligations to everyone from 31 March 2026.

Travel rule capability built

Collect, verify and transmit originator and beneficiary information with virtual asset transfers. Conduct due diligence on counterparty VASPs before transacting. Apply risk-based policies to self-hosted wallet transfers — these are not exempt from collection and verification, only from transmission.

Commencement: 1 July 2026. The travel rule attaches to transfers of value involving virtual assets, which sit inside the transitional deferral. It does not attach to exchange services.

This is the single biggest operational lift. Do not leave it to last.

SMR and TTR workflows running

  • Suspicious Matter Reports: 24 hours where it relates to terrorism financing (or a person's physical safety), 3 business days for money laundering or any other offence. The trigger is reasonable grounds to suspect — you do not need proof, and the obligation can arise even where you decline the transaction.
  • Threshold Transaction Reports: physical currency transactions of $10,000 or more.

Sanctions screening active

Screening customers and counterparties against the relevant lists, with a documented process for handling matches. Your policies must ensure you do not contravene targeted financial sanctions obligations.

Staff trained and records kept

  • Personnel who understand their obligations and can escalate.
  • Training records with dates, completion status and certificates.
  • Records retained seven years. An audit-ready trail throughout.

Looking ahead: AFSL readiness (from 9 April 2027)

The checklist above covers AUSTRAC. Separately, the Corporations Amendment (Digital Assets Framework) Act 2026 — Royal Assent 8 April 2026, commencing 9 April 2027 — brings two new financial products into the AFSL regime:

  • Digital Asset Platforms (DAPs): a facility where an operator holds digital tokens, for themselves or on behalf of another person. Exchanges, brokers, custodians, some wallet providers.
  • Tokenised Custody Platforms (TCPs): a facility where an operator identifies and holds assets other than money, issuing a single digital token for each asset, giving the holder a right to redeem or direct delivery of that asset. Real-world asset tokenisation.

Have you checked whether you fall under an exemption — properly?

Start here, before anything else — but do not stop at the headline number.

The low-value exemption is not a single $10 million test. Broadly, it requires all of the following: the total market value of transactions across the operator's platforms over a 12-month period does not exceed $10 million; the value of underlying assets held for any single client does not exceed $5,000; no financial products are held under the platforms; and the operator has notified ASIC of its intention to rely on the exemption.

A platform comfortably under the $10 million transaction threshold can still fall outside the exemption on the per-client limb alone. If you have a small number of substantial clients, this is you. There are also carve-outs for certain custodial staking arrangements and for wrapped tokens.

Establish your actual position with advice — before you spend money preparing an application you may not need, and equally before you conclude you are exempt when you are not.

Have you assessed whether your model is a DAP or a TCP?

If you are in scope, the definitions turn on whether you hold, control or manage client tokens or underlying assets. Get advice on the classification rather than assuming.

Do you understand the actual timeline?

The Act commences 9 April 2027, and a six-month transition period applies after commencement, during which existing operators may keep trading while they apply for a licence or a variation. Where an application is lodged in that window, the new requirements do not apply to that service until ASIC decides. The Act provides an 18-month implementation timeline, and ASIC has published a roadmap covering consultation, new regulatory guidance for DAPs and TCPs, and asset-holding standards.

This is not a cliff. But AFSL applications are substantial — ASIC assesses organisational competence, compliance arrangements, financial resources, risk management, responsible managers and dispute resolution membership — so if you are in scope, start early.

Are your governance structures designed for dual-regime?

If you will hold both AUSTRAC obligations and an AFSL, your compliance officer, board reporting framework and risk management structure should be designed to satisfy both from day one. Building two separate frameworks and merging them later costs more than designing one.

How Veriqua maps to the checklist

Veriqua is an Australian compliance platform for AUSTRAC reporting entities and ASIC licensees. Most of the checklist above maps to modules included on every AML plan: the program documents module for your ML/TF/PF risk assessment and AML/CTF policies; customer onboarding with initial and enhanced due diligence; suspicious matter, threshold transaction and international funds transfer registers; AUSTRAC reporting; staff training records; and board reporting — all on an audit-ready trail hosted in Australia.

Four checklist items map to modules available from the Professional tier: customer risk ratings, the beneficial ownership register, transaction monitoring, and independent review scheduling.

Because Veriqua supports AML/CTF and AFSL obligations in one system, the structure you build today expands into an AFSL framework if the Digital Assets Framework Act applies to you. Run a free readiness assessment in ten minutes, no login: demo.veriqua.com.au/start.

See how Veriqua handles this

Veriqua is an Australian compliance operating system for AFSL holders and AUSTRAC reporting entities — automating AML/CTF programs, customer due diligence, transaction monitoring, SMR lodgement and board reporting.

Disclaimer: A plain-English readiness checklist for Australian crypto businesses. General information only, not legal or compliance advice, and not exhaustive — your obligations depend on the virtual asset services you provide, your risk assessment, and transitional timing. Confirm each item against current AUSTRAC and ASIC guidance and the relevant legislation, and seek advice for your circumstances.