The Dual-Regime Future: Why Australian VASPs Should Prepare for AUSTRAC and ASIC Together | VASP Australia 2026
Two regulators, one business
A large part of Australia's crypto sector is about to sit under two regulators at once: AUSTRAC for financial crime prevention, and ASIC for financial services conduct, disclosure and consumer protection.
This is not a novel arrangement in Australian financial services. Australian financial services licensees that also provide designated services — FX businesses, payments providers, certain accounting and advisory firms — have operated under both regimes for years, and know exactly how expensive it is to run them as two separate programs. What is new is that the digital asset sector is about to join them, at scale, on a fixed timetable.
The AUSTRAC side is already live — and it commenced in stages, which is the detail most crypto businesses have wrong. The reformed obligations commenced on 31 March 2026 for existing reporting entities, including businesses exchanging virtual assets for money. The newly registrable virtual asset services — crypto-to-crypto exchange, safekeeping, and accepting instructions to transfer virtual assets — are deferred to 1 July 2026, which is also when travel rule obligations commence.
The ASIC side arrives on 9 April 2027.
What the Digital Assets Framework Act actually does
The Corporations Amendment (Digital Assets Framework) Act 2026 passed Parliament on 1 April 2026, received Royal Assent on 8 April 2026, and commences on 9 April 2027. It amends the Corporations Act to create two new categories of financial product:
Digital Asset Platforms (DAPs)
A facility where an operator holds digital tokens — either for themselves or on behalf of another person — and records client interests. In practice this captures exchanges, brokers, custodians and some wallet providers. If your business holds, trades or manages customer crypto, you are likely operating a DAP.
Tokenised Custody Platforms (TCPs)
A facility where an operator identifies and holds assets other than money, issuing a single digital token for each asset, which grants the holder the right to redeem or direct the delivery of that asset. The operator acts on behalf of the token holder, often as trustee or bailee.
This is the real-world asset tokenisation category. It is not about capital raising or token offerings. If you tokenise physical or off-chain assets and hold the underlying, this is your category.
Operators of DAPs and TCPs must hold an Australian Financial Services Licence, unless an exemption applies — and the exemptions matter.
The exemptions — read these properly before you spend money
Low-value exemption — and it is not a single test. This is the one most commonly misreported. Broadly, an AFSL is not required where all of the following hold: the total market value of transactions across the operator's platforms over a 12-month period does not exceed $10 million; the total entry value of underlying assets held for any single client does not exceed $5,000; no financial products are held under the platforms; and the operator has notified ASIC of its intention to rely on the exemption.
Both the transaction threshold and the per-client threshold must be satisfied. A platform doing $6 million in annual transaction volume but holding $40,000 for a single client does not qualify. If you have a small number of substantial clients, check the per-client limb before anything else.
- Custodial staking. Certain custodial staking arrangements will not be treated as separate financial products when offered through a licensed platform, within defined parameters.
- Wrapped tokens. Redemption rights are disregarded when deciding whether a wrapped token is a financial product, unless the holder's rights materially differ from holding the referenced asset directly.
- Incidental arranging. A person primarily engaged in a non-financial-services business does not need an AFSL merely because they arrange for a financial service in the ordinary course of that business. The relief is limited to introductions and incidental arranging.
The timeline — and what it actually is
The Act commences 9 April 2027. A six-month transition period applies after commencement, during which existing operators may continue operating while they apply for a licence or a licence variation. Where an application is lodged in that window, the new requirements do not apply to that service until the day after ASIC decides the application. The Act provides for an 18-month implementation timeline overall.
ASIC has published an implementation roadmap: stakeholder roundtables and an industry advisory group; consultation on standards and guidance; a new regulatory guide for DAPs and TCPs covering how the law operates and who is likely to need a licence; and regulatory instruments setting asset-holding, transactional and settlement standards and financial requirements.
This is not the cliff it is sometimes portrayed as. But AFSL applications are genuinely substantial. ASIC assesses organisational competence, compliance arrangements, financial resources, risk management framework, responsible managers and dispute resolution membership. For a business that has never held a licence, that is not a form-filling exercise. If you are in scope, the preparation window is open now.
Where AUSTRAC and ASIC obligations overlap
The two regimes are not entirely separate. A well-designed program can serve both from a single governance structure.
Governance and board oversight
AUSTRAC requires your governing body to oversee the AML/CTF program, receive compliance reports and approve risk assessments. An AFSL requires adequate compliance arrangements and board oversight of conduct obligations. One governance structure, one board reporting framework, both regimes.
Compliance officer
AUSTRAC requires a fit and proper AML/CTF compliance officer. An AFSL requires adequate compliance arrangements, which typically means a compliance manager or officer. A single person can serve both functions if they have the knowledge, authority and resources for both — and the role description and reporting lines should be designed for that from day one.
Risk management
AUSTRAC requires a documented ML/TF/PF risk assessment. ASIC requires adequate risk management systems as a licence condition. Different risk domains, but the methodology, documentation standards and review cadence can be aligned. Build the AML/CTF risk assessment in a framework that can later absorb AFSL risk categories and you avoid rebuilding it.
Record-keeping and audit trail
Both regulators require records kept for extended periods and expect them accurate, complete and producible on request. One record-keeping system beats two.
Incident and breach reporting
AUSTRAC: SMRs within 24 hours (terrorism financing) or 3 business days. ASIC: reportable situations within 30 calendar days. The triggers differ, but the investigation, documentation and escalation processes are similar enough that a single incident-management workflow can capture both.
Staff training
Both regimes require staff to understand their obligations. One training program with modules covering both.
Where the obligations diverge
AUSTRAC-specific (no AFSL equivalent)
- Suspicious Matter Reports and Threshold Transaction Reports
- The travel rule
- Sanctions screening
- Customer due diligence and beneficial ownership verification
- Transaction monitoring for financial crime patterns
- The annual AUSTRAC compliance report
ASIC/AFSL-specific (no AUSTRAC equivalent)
- Financial Services Guide and product disclosure obligations
- Platform rules and, for DAPs and TCPs, a tailored platform guide for retail clients
- Responsible Manager obligations
- Internal and external dispute resolution (AFCA membership)
- Reportable-situations breach reporting under the Corporations Act
- Conduct obligations — efficiently, honestly and fairly; conflicts management; client money
- Financial requirements and asset-holding standards
- ASIC regulatory returns
The divergence means you cannot copy your AML/CTF program and call it an AFSL compliance plan. But the shared governance, risk management and reporting infrastructure is a genuine foundation for both.
The expensive mistake
Build an AML/CTF program now. Build a separate AFSL framework in 2027. Try to integrate them afterwards.
That is what most businesses will do, largely because most compliance vendors only cover one regime. The result is two governance structures, two reporting frameworks, two sets of board papers, two compliance calendars, two audit trails and two training programs — for the same business, the same customers and the same transactions.
The alternative is to design one framework that accommodates both from the start. The AML/CTF program you build this month should be built with AFSL expansion in mind, even if the licence application is a year away — and even if, after checking the exemptions properly, you conclude you never need one.
What to do now
- Check the exemptions properly. Both the transaction threshold and the per-client threshold, plus the notification requirement. Do not self-assess on the headline number alone.
- Get advice on classification. DAP, TCP, both, or neither. The definitions turn on whether you hold, control or manage client tokens or underlying assets.
- Design your governance for dual-regime from day one if you are likely in scope — one compliance officer scoped for both, one board reporting cadence, one system of record.
- Build your risk assessment on a framework that can absorb AFSL risk domains — conduct, conflicts, client money — rather than one that will need rebuilding.
- Scope the application timeline if you are in scope: responsible manager qualifications, financial resource requirements, AFCA membership, compliance documentation.
The bigger picture
The dual-regime future is a deliberate policy choice: treat digital assets like other financial products, subject to the same conduct standards, consumer protections and crime prevention obligations that apply across the financial system. Australia is aligning with international standards that expect crypto businesses to operate as regulated financial entities.
For operators, that creates both obligation and opportunity. The compliance burden is real. But businesses that build credible dual-regime programs early are positioned as regulated participants — which unlocks banking relationships, institutional capital and consumer trust that unregulated operators cannot access.
Design the two layers together and you build once. Design them separately and you build twice.
About Veriqua
Veriqua is a SaaS compliance platform for Australian regulated entities, supporting AML/CTF and AFSL obligations in a single system — risk assessments, customer due diligence, onboarding and reporting registers, incidents, breaches and complaints, governance and board reporting, and audit trail management, hosted in Australia.
Veriqua is sold as three lines: AML/CTF, AFSL, or a dual plan covering both. For a crypto business heading toward a licence, the dual plan is the point — one compliance officer, one board reporting cadence, one system of record, one audit trail, across both regulators. The dual plans include the full AML and AFSL feature sets, including customer risk ratings, transaction monitoring, the beneficial ownership register and independent review scheduling.
See it in two minutes, no login: demo.veriqua.com.au/start.
Related articles
29 July 2026: The AUSTRAC Deadline Every Crypto Business Needs to Understand
What the deadline actually requires, who it applies to, and where the real exposure sits.
DCE → VASP: What Actually Changed in Your AML/CTF Program
What genuinely shifts for crypto businesses under the reformed Act — and why this is only the first of two regulatory transitions.
Is Your Crypto Business Ready? The VASP Compliance Checklist
A scannable readiness checklist covering AUSTRAC AML/CTF obligations and forward-looking AFSL readiness.
After the Deadline: Ongoing VASP Obligations That Define Your Audit Readiness
The ongoing compliance cadence — and why it needs to be designed for two regulators, not one.
See how Veriqua handles this
Veriqua is an Australian compliance operating system for AFSL holders and AUSTRAC reporting entities — automating AML/CTF programs, customer due diligence, transaction monitoring, SMR lodgement and board reporting.
Disclaimer: This article is general information only and is current as at July 2026. It reflects our understanding of the Digital Assets Framework Act 2026, the AML/CTF Act 2006, and AUSTRAC and ASIC guidance as at that date, all of which may change. It is not legal, financial or compliance advice. The Digital Assets Framework Act 2026 and AFSL requirements carry significant technical and fact-specific nuances. Whether your business requires an AFSL depends on the specific services you provide and how they are classified under the Corporations Act. Please confirm your position against current ASIC and AUSTRAC guidance and the relevant legislation, and seek advice for your specific circumstances.