If your business exchanges digital currency for money — or money for digital currency — in Australia, you are a digital currency exchange (DCE), and AUSTRAC treats you as a reporting entity with the same core obligations as a bank. This guide walks through what that means in practice: registration, the AML/CTF program you must build and run, KYC and enhanced due diligence for crypto customers, on-chain and off-chain transaction monitoring, the Travel Rule, sanctions screening, the reports you must lodge, and the specific ways DCEs fail an AUSTRAC review — with a compliance checklist you can act on.
- What a DCE is and why AUSTRAC regulates you
- Registration and the obligation to have a program
- The AML/CTF program: Part A and Part B
- KYC, CDD and enhanced due diligence for crypto
- On-chain vs off-chain transaction monitoring
- Blockchain analytics and wallet-risk screening
- The Travel Rule and originator/beneficiary information
- Sanctions screening: DFAT and global
- Reporting: SMRs, TTRs and record-keeping
- Independent review
- How DCEs fail an AUSTRAC review — and how to avoid it
- DCE compliance checklist
- Frequently asked questions
What a digital currency exchange is — and why AUSTRAC regulates you
Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (the AML/CTF Act), exchanging digital currency for money, or money for digital currency, in the course of carrying on a business is a designated service. Providing a designated service makes you a reporting entity. The label most people use is digital currency exchange, or DCE — but the obligations attach to the service, not the branding. A retail exchange, an OTC desk, a crypto broker, a payments business with a buy/sell feature, and many custodial platforms can all be caught.
The reason is straightforward. Digital assets move value quickly, across borders, and — depending on the asset and the tooling — with varying degrees of transparency. That combination is attractive to money launderers, scammers, ransomware operators and sanctions evaders. AUSTRAC, Australia's AML/CTF regulator and financial intelligence unit, regulates DCEs so that the on-and-off ramps between the crypto economy and the banking system carry the same controls, reporting and traceability as any other money-moving business.
Registration and the obligation to maintain a program
A DCE has two foundational obligations before it takes its first customer. First, you must register as a digital currency exchange provider with AUSTRAC and enrol on the Reporting Entities Roll. Registration is not a formality you can defer until you have traction — providing DCE services without being registered is an offence, and AUSTRAC has both the powers and the track record to act on it. Registration also has to be kept current: material changes to your business, ownership or key personnel need to be reflected.
Second, you must have a compliant AML/CTF program in place and actually apply it. The program is the operating manual for how you identify customers, monitor activity, report to AUSTRAC and govern the whole thing. It is not a template you file once. It has to reflect your real business, be approved and overseen by your board and senior management, and be kept up to date as your products, customers and risks change.
- Register and enrol with AUSTRAC before providing any designated service.
- Appoint an AML/CTF compliance officer at management level with the authority and resources to do the job.
- Adopt and maintain an AML/CTF program (Part A and Part B) approved by the governing board.
- Keep it live — review it when you launch products, enter new markets or your risk changes.
The AML/CTF program: Part A and Part B
Your program has two parts, and DCEs routinely under-invest in one of them.
Part A — risk-based systems and controls
Part A is the machinery. Its purpose is to identify, mitigate and manage the money-laundering and terrorism-financing (ML/TF) risk your business reasonably faces. At its centre sits your ML/TF risk assessment: a documented analysis of risk across your customer types, the products and services you offer, your delivery channels (app, web, OTC, API), the jurisdictions you touch, and the specific typologies that hit crypto businesses. Everything else in Part A should trace back to that assessment. Part A also covers transaction monitoring, employee due diligence and training, the compliance officer function, ongoing customer due diligence, permissions and reporting to AUSTRAC, and — critically — board and senior-management oversight and the independent review.
Part B — customer identification
Part B is the customer identification and verification procedure you apply before you provide a designated service. It sets out how you collect and verify a customer's identity (and, for non-individuals, beneficial ownership), the electronic and documentary methods you accept, and how you handle discrepancies. Part B is where "know your customer" becomes concrete — but it is only the front door. The ongoing risk management lives in Part A.
KYC, CDD and enhanced due diligence for crypto customers
Customer due diligence (CDD) for a DCE starts with knowing who the customer is, and extends to understanding what they do and whether their activity makes sense. For crypto, three areas deserve particular attention.
- Identity. Collect and verify identity to the standard set in your Part B, using reliable and independent sources. Match the depth of verification to the risk — a low-value retail account and a high-volume OTC counterparty are not the same.
- Source of funds and source of wealth. For higher-risk customers and larger transactions, establishing source of funds (where the money or crypto for this transaction came from) and source of wealth (how the customer accumulated their assets overall) is where crypto compliance is won or lost. On-chain provenance — is the inbound crypto coming from an exchange, a mixer, a sanctioned address, a scam wallet? — is part of this picture, not a separate exercise.
- PEPs and sanctions. Screen customers and, where relevant, beneficial owners against politically exposed person (PEP) lists and sanctions lists at onboarding and on an ongoing basis. A PEP match does not mean you decline — it means you apply enhanced customer due diligence (ECDD), senior sign-off and closer monitoring.
ECDD is triggered when risk is high: high-risk customers, unusual or complex activity, PEPs, high-risk jurisdictions, or any situation where a suspicion is forming. In practice ECDD for a DCE means going deeper on identity and beneficial ownership, corroborating source of funds and wealth with evidence, running enhanced on-chain analysis of the customer's wallet exposure, and escalating for senior decision before you proceed.
On-chain versus off-chain transaction monitoring
A DCE has two ledgers to watch, and a mature program monitors both and joins them together.
Off-chain monitoring looks at activity on your own systems and the fiat rails: deposits and withdrawals via bank transfer or card, account behaviour, velocity, structuring across linked accounts, and mismatches between stated purpose and actual use. This is classic transaction monitoring, tuned for a crypto business.
On-chain monitoring looks at the blockchain itself: the wallets a customer deposits from and withdraws to, and the exposure of those wallets to high-risk sources. On-chain analysis catches risk that never appears in your fiat data. The typologies that matter most for DCEs include:
- Mixers and tumblers — services designed to break the link between source and destination, obscuring provenance.
- Chain-hopping — rapidly moving value across different blockchains and assets to frustrate tracing.
- Structuring — breaking deposits or withdrawals into amounts that sit below reporting or internal thresholds, often across multiple accounts or wallets.
- Scam, fraud and ransomware exposure — funds flowing to or from wallets linked to investment scams, romance scams, ransomware payments or extortion.
- Sanctioned addresses — direct or indirect exposure to wallets associated with sanctioned persons, entities or jurisdictions.
The point is not to run two disconnected systems. It is to let on-chain wallet-risk signals inform the customer's risk rating, ECDD and your decisions to report — and to let off-chain behaviour prompt a closer on-chain look.
Blockchain analytics and wallet-risk screening
Blockchain analytics is the tooling that makes on-chain monitoring practical at scale. Analytics providers cluster addresses, attribute them to known entities (exchanges, services, illicit actors) and score the risk of a given wallet or transaction based on its exposure to high-risk categories. For a DCE, the core uses are:
- Deposit and withdrawal screening — check the counterparty wallet before crediting a deposit or releasing a withdrawal, and hold or escalate where exposure is high.
- Wallet-risk in the customer risk rating — feed on-chain exposure into how you rate and monitor the customer, not just a one-off gate.
- Investigation and tracing — reconstruct the flow of funds when a suspicion forms, to support an SMR or a law-enforcement request.
Analytics is a powerful signal, but it is a signal, not a verdict. Attribution can be incomplete or wrong, and a high score is the start of an investigation, not the end of one. Your program should say how analytics feeds decisions, what thresholds trigger action, and how a human adjudicates the result.
The Travel Rule and originator/beneficiary information
The Travel Rule is the requirement that identifying information about the sender (originator) and recipient (beneficiary) travels with a transfer of value between institutions. It originated in the traditional value-transfer world and has been extended to digital assets internationally. In a crypto context it means that when your DCE sends value to another exchange or institution, prescribed originator and beneficiary information should accompany that transfer — and when you receive a transfer, you should receive and check that information.
Australia's AML/CTF reforms are extending value-transfer and Travel-Rule style obligations to digital currency, closing the gap between crypto and traditional rails. Practically, DCEs should build the capability to collect, hold and transmit the required originator and beneficiary details, handle transfers to and from self-hosted (unhosted) wallets, and manage counterparties who cannot yet exchange this data. Building this into your architecture early is far cheaper than retrofitting it under a deadline.
Sanctions screening: DFAT and global
Sanctions compliance sits alongside — but is legally distinct from — your AML/CTF obligations. Australian sanctions are administered under the regime overseen by the Department of Foreign Affairs and Trade (DFAT), including the Consolidated List. Depending on your customers and corridors, you may also need to account for major international regimes. For a DCE, sanctions screening has to cover both the traditional and the on-chain dimension:
- Name screening of customers and beneficial owners against the DFAT Consolidated List and other applicable lists, at onboarding and on an ongoing basis.
- Address screening of wallet addresses against sanctioned-address data via blockchain analytics.
- Ongoing rescreening so that a customer or wallet newly added to a list is caught — sanctions lists change.
- A defensible process for adjudicating matches, escalating true hits, and documenting the decision.
Reporting: SMRs, TTRs and record-keeping
Reporting is how AUSTRAC gets the financial intelligence the whole system depends on. Three obligations matter most for DCEs.
- Suspicious Matter Reports (SMRs). When you form a suspicion on reasonable grounds — that a customer or transaction may relate to money laundering, terrorism financing, fraud, proceeds of crime or another offence — you must lodge an SMR within the required timeframe. Suspicion can arise at onboarding, during monitoring, or when a customer's explanation does not hold up. The related "tipping off" rules mean you must not disclose that an SMR has been (or may be) made.
- Threshold Transaction Reports (TTRs). Transactions involving physical currency or digital currency at or above the reporting threshold must be reported, regardless of whether anything looks suspicious.
- Record-keeping. You must retain records — customer identification, transactions, your AML/CTF program and the decisions made under it — for the periods set by the Act (generally several years), and be able to produce them.
The theme across all three: reporting is only as good as the monitoring and the people behind it. An SMR obligation you never detect is still an obligation you have breached.
Independent review
Part A of your AML/CTF program must be independently reviewed on a regular basis. The reviewer has to be suitably qualified and genuinely independent of the functions under review — the person who runs monitoring cannot audit their own monitoring. A good review tests three things: that the program meets the legal requirements, that it is current, and that it is actually being applied day to day. The findings should go to the board or senior management with a clear, owned remediation plan — a review that gathers dust is a finding waiting to happen at the next AUSTRAC contact.
How DCEs fail an AUSTRAC review — and how to avoid it
Across the crypto sector, the failures cluster into a familiar set. Knowing them is the fastest way to avoid them.
- Operating before registration. Taking customers while registration is "in progress." Fix: register and enrol first, full stop.
- A generic, off-the-shelf program. A template that does not reflect your actual products, customers and channels. Fix: build the ML/TF risk assessment for your business and let the program flow from it.
- A risk assessment that is a document, not a driver. A risk assessment written once and never connected to monitoring or CDD. Fix: trace every control back to a risk, and revisit when the business changes.
- On-chain and off-chain in silos. Fiat monitoring and blockchain analytics that never talk to each other. Fix: feed wallet-risk into customer ratings, ECDD and reporting.
- Weak source of funds and wealth. Onboarding that verifies identity but never asks where the value came from. Fix: make source of funds and wealth a real, evidenced step for higher-risk activity.
- Under-reporting. Suspicions that are noticed but never escalated, or TTRs missed. Fix: clear escalation paths, trained staff, and monitoring that actually surfaces the events.
- No board oversight. A compliance officer working in isolation with no visible governance. Fix: real board approval, reporting and accountability.
- No independent review, or one that is ignored. Fix: commission a genuine review and close its findings on a tracked plan.
DCE compliance checklist
Use this as a fast self-assessment. If any row lands in the "common gap" column for your business, it is a candidate for your next uplift.
| Obligation | What good looks like | Common gap |
|---|---|---|
| AUSTRAC registration & enrolment | Registered as a DCE and enrolled before any service; details kept current | Trading before registration completes; stale details after changes |
| AML/CTF program (Part A & B) | Board-approved, business-specific, kept up to date | Generic template that does not match the real business |
| ML/TF risk assessment | Documented across customers, products, channels, geographies and typologies; drives the controls | Written once, disconnected from monitoring and CDD |
| KYC / CDD (Part B) | Reliable identity verification proportionate to risk | One-size-fits-all checks regardless of customer risk |
| Enhanced due diligence | Triggered by risk; evidenced source of funds/wealth; PEP and sanctions handling with sign-off | ECDD defined on paper but not applied in practice |
| Transaction monitoring (off-chain) | Rules tuned to crypto typologies; structuring and velocity detection | Untuned rules, alert backlogs, false-positive overload |
| On-chain monitoring & analytics | Deposit/withdrawal wallet screening feeding risk ratings and reporting | Analytics run in isolation, or not at all |
| Travel Rule readiness | Capability to collect, hold and transmit originator/beneficiary data; unhosted-wallet handling | No architecture for value-transfer information |
| Sanctions screening | DFAT and applicable global lists; name and wallet-address screening; ongoing rescreening | One-off screening; no address screening; no rescreening |
| SMRs & TTRs | Timely, complete reporting with clear escalation and tipping-off controls | Missed suspicions; late or omitted threshold reports |
| Record-keeping | Records retained for the required periods and readily producible | Fragmented records that cannot be produced on request |
| Independent review | Qualified, independent, regular; findings reported and remediated | No review, or findings that are never closed out |
DCE compliance, answered
Does my crypto business need to register with AUSTRAC?
If you exchange digital currency for money (or money for digital currency) in the course of a business in Australia, you are providing a designated service as a digital currency exchange and must register with AUSTRAC before you start. Operating an unregistered DCE is an offence. You must also enrol on the Reporting Entities Roll and maintain a compliant AML/CTF program.
What is the difference between Part A and Part B of an AML/CTF program?
Part A is the risk-based systems and controls that identify, mitigate and manage your ML/TF risk — your risk assessment, transaction monitoring, employee due diligence, training, oversight by the board and senior management, and the compliance officer function. Part B sets out the customer identification and verification procedures you apply before providing a designated service.
What is the crypto Travel Rule and does it apply to Australian DCEs?
The Travel Rule requires that originator and beneficiary information travels with a transfer of value between institutions. For digital-asset transfers it means that when a DCE sends value to another exchange, prescribed information about the sender and recipient must accompany the transfer. Australian reforms are extending value-transfer and Travel-Rule style obligations to digital currency, so DCEs should build the capability to collect, hold and transmit this information.
What is the difference between an SMR and a TTR?
A Suspicious Matter Report (SMR) is lodged when you form a suspicion on reasonable grounds about a customer or transaction — for example possible money laundering, fraud or an offence — and it has strict lodgement timeframes. A Threshold Transaction Report (TTR) is lodged for transactions involving physical currency or digital currency at or above the reporting threshold, regardless of suspicion.
How does blockchain analytics support DCE compliance?
Blockchain analytics tools screen wallet addresses and trace the flow of funds on-chain, scoring exposure to high-risk sources such as sanctioned addresses, darknet markets, mixers and tumblers, ransomware and known scams. They complement traditional off-chain monitoring of fiat rails, feeding wallet-risk signals into your customer risk rating, enhanced due diligence and suspicious matter reporting.
How often does a DCE need an independent review of its AML/CTF program?
Part A of your AML/CTF program must be independently reviewed on a regular basis. The reviewer must be suitably qualified and independent of the functions being examined. The review tests whether the program meets legal requirements, is up to date, and is actually being applied in practice — its findings should be reported to the board or senior management with a remediation plan.