Skip to main content
AUSTRAC Registration Checklist for Remitters and VASPsVirtual Assets & RegTech
5 min readFor AML Compliance Officers

AUSTRAC Registration Checklist for Remitters and VASPs

AUSTRAC has cancelled, suspended, or refused renewal of 45 remittance and VASP registrations over the past year. If you're operating in Australia's cross-border payments or virtual asset space, this is a direct signal that your registration status depends on demonstrable operational capacity and AML/CTF controls.

This checklist outlines the specific requirements AUSTRAC expects you to maintain. Each item maps to a regulatory obligation under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act). Use it to audit your current state and identify gaps before the regulator does.

Prerequisites

Before you work through this checklist, confirm you have:

  • Current AUSTRAC registration as a remittance network provider or digital currency exchange provider.
  • Access to your AML/CTF program documentation, including your Part A program and any applicable Part B programs.
  • Authority to review operational records, including transaction volumes, customer onboarding files, and reporting submissions.
  • Contact details for your designated AML/CTF Compliance Officer (required under Section 84 of the AML/CTF Act).

If you don't have these four elements documented and accessible, stop here. You're already exposed.

Registration and Operational Capacity Requirements

1. Active Service Delivery Verification

You've provided designated services within the past 12 months

Check your transaction logs. If you've gone dormant or stopped offering remittance or VASP services for extended periods, AUSTRAC considers this grounds for cancellation. Ensure you have documented evidence of active customer transactions, even if volumes are low, with clear records showing continuous service availability.

2. Solvency and Financial Viability

Your business meets minimum capital requirements and you can demonstrate financial stability

Review your latest financial statements. AUSTRAC's actions targeted insolvent entities. Ensure your audited financials show positive working capital, no outstanding insolvency proceedings, and sufficient reserves to meet customer obligations and operational costs for at least six months.

3. Registration Details Currency

Your AUSTRAC registration reflects current business structure, directors, and contact information

Log into your AUSTRAC Online account and verify every field. Changes to directors, business addresses, or service offerings require notification within 14 days under Section 75 of the AML/CTF Act. Ensure your registration record matches your current ASIC company extract exactly, with no pending notifications.

AML/CTF Framework Controls

4. Part A Program Documentation

Your AML/CTF program is documented, board-approved, and covers all designated services you offer

Pull your Part A program document. It must address customer due diligence, ongoing monitoring, and reporting procedures specific to your business model. Ensure your program document is dated within the past two years, signed by your board or senior management, with service-specific risk assessments for each product line.

5. Customer Due Diligence Procedures

You collect and verify customer identification before providing services

Review a sample of recent customer onboarding files. You need name, date of birth, and residential address verified through reliable and independent documentation. For entities, you need beneficial ownership down to individuals holding 25% or more. Ensure 100% of active customers have complete, verified CDD records with clear audit trails showing document types and verification dates.

6. Enhanced Due Diligence for High-Risk Customers

You've identified high-risk customer segments and applied enhanced measures

Check your risk assessment methodology. Cross-border remitters to high-risk jurisdictions and VASPs handling large volumes need enhanced scrutiny. The BA Digital Ventures case, where AUSTRAC alleged exploitation by organized cryptocurrency investment scams, shows what happens when you miss this. Ensure you have documented risk ratings for every customer, with enhanced CDD triggers based on jurisdiction, transaction patterns, and service type, plus evidence of additional verification steps for high-risk accounts.

7. Transaction Monitoring and Suspicious Matter Reporting

You have documented transaction monitoring rules and you've filed Suspicious Matter Reports (SMRs) when required

Review your Transaction Monitoring Rules and SMR submission history. Silence isn't compliance; it's a red flag. Ensure you have documented monitoring rules calibrated to your risk profile, evidence of alert review and disposition, and a pattern of SMR filings that reflects genuine risk detection.

8. Threshold Transaction Reporting

You submit Threshold Transaction Reports (TTRs) for all transactions of AUD 10,000 or more within 10 business days

Run a report of transactions at or above AUD 10,000 and cross-reference against your TTR submissions. Ensure a 100% submission rate within the regulatory timeframe, with no backlog or unexplained gaps in reporting periods.

Technology and Operational Controls

9. Record Retention and Audit Trail

You retain transaction records and CDD documentation for seven years and can produce them on request

Test your document retrieval process. AUSTRAC can request records during supervision or investigation. Ensure indexed, searchable records stored securely with version control, accessible within 24 hours of a regulator request.

10. AML/CTF Compliance Officer Authority and Resources

Your designated Compliance Officer has sufficient authority, resources, and independence to perform their role

Interview your Compliance Officer. They need direct board access and the ability to halt transactions or reject customers. Ensure your Compliance Officer has a defined budget, authority to escalate concerns to senior management without intermediaries, and documented evidence of compliance-driven decisions that override commercial pressure.

Common Mistakes

Treating registration as a one-time event. AUSTRAC registration requires continuous compliance. If your operational capacity changes or you stop trading, you must notify the regulator or surrender your registration.

Underestimating scam exploitation risk. The GetCoins cancellation shows how quickly organized fraud can compromise a VASP. If you're seeing unusual investment-related inflows, especially involving cryptocurrency, you need enhanced monitoring and likely an SMR.

Copying another firm's AML/CTF program. Your Part A program must reflect your specific business model, customer base, and risk profile. Generic templates don't meet the standard.

Assuming low volume equals low risk. AUSTRAC's enforcement actions included dormant and low-activity entities. Even if you process minimal transactions, you're still required to maintain full compliance infrastructure.

Next Steps

If you've identified gaps in this checklist:

  1. Document the gap with specificity. Note which requirement you're failing, the evidence of non-compliance, and the potential regulatory consequence.

  2. Assign remediation ownership. Your Compliance Officer should own the remediation plan, but operational fixes often require IT, finance, or customer operations support.

  3. Set a remediation deadline based on risk severity. Missing CDD records or unreported suspicious activity require immediate action. Documentation updates can follow a longer timeline.

  4. Consider voluntary disclosure to AUSTRAC if you've identified significant breaches. Section 41 of the AML/CTF Act requires reporting of non-compliance that's significant in nature, number, or frequency.

AUSTRAC CEO Brendan Thomas emphasized that effective risk management and reporting are essential for continued operation. The 45 cancelled registrations prove it. Use this checklist to verify you're meeting the standard before the regulator asks the question.

You Might Also Like