Home / Insights / Crypto & Exchanges
Crypto & Exchanges

AUSTRAC AML for Australian crypto exchanges (DCEs): the complete compliance guide

If your business exchanges digital currency for money — or money for digital currency — in Australia, you are a digital currency exchange (DCE), and AUSTRAC treats you as a reporting entity with the same core obligations as a bank. This guide walks through what that means in practice: registration, the AML/CTF program you must build and run, KYC and enhanced due diligence for crypto customers, on-chain and off-chain transaction monitoring, the Travel Rule, sanctions screening, the reports you must lodge, and the specific ways DCEs fail an AUSTRAC review — with a compliance checklist you can act on.

On this page

What a digital currency exchange is — and why AUSTRAC regulates you

Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (the AML/CTF Act), exchanging digital currency for money, or money for digital currency, in the course of carrying on a business is a designated service. Providing a designated service makes you a reporting entity. The label most people use is digital currency exchange, or DCE — but the obligations attach to the service, not the branding. A retail exchange, an OTC desk, a crypto broker, a payments business with a buy/sell feature, and many custodial platforms can all be caught.

The reason is straightforward. Digital assets move value quickly, across borders, and — depending on the asset and the tooling — with varying degrees of transparency. That combination is attractive to money launderers, scammers, ransomware operators and sanctions evaders. AUSTRAC, Australia's AML/CTF regulator and financial intelligence unit, regulates DCEs so that the on-and-off ramps between the crypto economy and the banking system carry the same controls, reporting and traceability as any other money-moving business.

The short version. If money or crypto crosses your platform as part of a business, assume you are a reporting entity until you have confirmed otherwise. The cost of getting this wrong — operating unregistered, or running a program that exists on paper but not in practice — is far higher than the cost of getting it right from the start.

Registration and the obligation to maintain a program

A DCE has two foundational obligations before it takes its first customer. First, you must register as a digital currency exchange provider with AUSTRAC and enrol on the Reporting Entities Roll. Registration is not a formality you can defer until you have traction — providing DCE services without being registered is an offence, and AUSTRAC has both the powers and the track record to act on it. Registration also has to be kept current: material changes to your business, ownership or key personnel need to be reflected.

Second, you must have a compliant AML/CTF program in place and actually apply it. The program is the operating manual for how you identify customers, monitor activity, report to AUSTRAC and govern the whole thing. It is not a template you file once. It has to reflect your real business, be approved and overseen by your board and senior management, and be kept up to date as your products, customers and risks change.

The AML/CTF program: Part A and Part B

Your program has two parts, and DCEs routinely under-invest in one of them.

Part A — risk-based systems and controls

Part A is the machinery. Its purpose is to identify, mitigate and manage the money-laundering and terrorism-financing (ML/TF) risk your business reasonably faces. At its centre sits your ML/TF risk assessment: a documented analysis of risk across your customer types, the products and services you offer, your delivery channels (app, web, OTC, API), the jurisdictions you touch, and the specific typologies that hit crypto businesses. Everything else in Part A should trace back to that assessment. Part A also covers transaction monitoring, employee due diligence and training, the compliance officer function, ongoing customer due diligence, permissions and reporting to AUSTRAC, and — critically — board and senior-management oversight and the independent review.

Part B — customer identification

Part B is the customer identification and verification procedure you apply before you provide a designated service. It sets out how you collect and verify a customer's identity (and, for non-individuals, beneficial ownership), the electronic and documentary methods you accept, and how you handle discrepancies. Part B is where "know your customer" becomes concrete — but it is only the front door. The ongoing risk management lives in Part A.

Common misread. Many DCEs build a strong onboarding flow (Part B) and treat Part A as paperwork. AUSTRAC reviews go the other way: they probe whether your risk assessment is genuine, whether monitoring reflects it, and whether the board actually oversees it. A slick sign-up screen will not save a hollow Part A.

KYC, CDD and enhanced due diligence for crypto customers

Customer due diligence (CDD) for a DCE starts with knowing who the customer is, and extends to understanding what they do and whether their activity makes sense. For crypto, three areas deserve particular attention.

ECDD is triggered when risk is high: high-risk customers, unusual or complex activity, PEPs, high-risk jurisdictions, or any situation where a suspicion is forming. In practice ECDD for a DCE means going deeper on identity and beneficial ownership, corroborating source of funds and wealth with evidence, running enhanced on-chain analysis of the customer's wallet exposure, and escalating for senior decision before you proceed.

On-chain versus off-chain transaction monitoring

A DCE has two ledgers to watch, and a mature program monitors both and joins them together.

Off-chain monitoring looks at activity on your own systems and the fiat rails: deposits and withdrawals via bank transfer or card, account behaviour, velocity, structuring across linked accounts, and mismatches between stated purpose and actual use. This is classic transaction monitoring, tuned for a crypto business.

On-chain monitoring looks at the blockchain itself: the wallets a customer deposits from and withdraws to, and the exposure of those wallets to high-risk sources. On-chain analysis catches risk that never appears in your fiat data. The typologies that matter most for DCEs include:

The point is not to run two disconnected systems. It is to let on-chain wallet-risk signals inform the customer's risk rating, ECDD and your decisions to report — and to let off-chain behaviour prompt a closer on-chain look.

Blockchain analytics and wallet-risk screening

Blockchain analytics is the tooling that makes on-chain monitoring practical at scale. Analytics providers cluster addresses, attribute them to known entities (exchanges, services, illicit actors) and score the risk of a given wallet or transaction based on its exposure to high-risk categories. For a DCE, the core uses are:

Analytics is a powerful signal, but it is a signal, not a verdict. Attribution can be incomplete or wrong, and a high score is the start of an investigation, not the end of one. Your program should say how analytics feeds decisions, what thresholds trigger action, and how a human adjudicates the result.

The Travel Rule and originator/beneficiary information

The Travel Rule is the requirement that identifying information about the sender (originator) and recipient (beneficiary) travels with a transfer of value between institutions. It originated in the traditional value-transfer world and has been extended to digital assets internationally. In a crypto context it means that when your DCE sends value to another exchange or institution, prescribed originator and beneficiary information should accompany that transfer — and when you receive a transfer, you should receive and check that information.

Australia's AML/CTF reforms are extending value-transfer and Travel-Rule style obligations to digital currency, closing the gap between crypto and traditional rails. Practically, DCEs should build the capability to collect, hold and transmit the required originator and beneficiary details, handle transfers to and from self-hosted (unhosted) wallets, and manage counterparties who cannot yet exchange this data. Building this into your architecture early is far cheaper than retrofitting it under a deadline.

Sanctions screening: DFAT and global

Sanctions compliance sits alongside — but is legally distinct from — your AML/CTF obligations. Australian sanctions are administered under the regime overseen by the Department of Foreign Affairs and Trade (DFAT), including the Consolidated List. Depending on your customers and corridors, you may also need to account for major international regimes. For a DCE, sanctions screening has to cover both the traditional and the on-chain dimension:

Reporting: SMRs, TTRs and record-keeping

Reporting is how AUSTRAC gets the financial intelligence the whole system depends on. Three obligations matter most for DCEs.

The theme across all three: reporting is only as good as the monitoring and the people behind it. An SMR obligation you never detect is still an obligation you have breached.

Independent review

Part A of your AML/CTF program must be independently reviewed on a regular basis. The reviewer has to be suitably qualified and genuinely independent of the functions under review — the person who runs monitoring cannot audit their own monitoring. A good review tests three things: that the program meets the legal requirements, that it is current, and that it is actually being applied day to day. The findings should go to the board or senior management with a clear, owned remediation plan — a review that gathers dust is a finding waiting to happen at the next AUSTRAC contact.

How DCEs fail an AUSTRAC review — and how to avoid it

Across the crypto sector, the failures cluster into a familiar set. Knowing them is the fastest way to avoid them.

DCE compliance checklist

Use this as a fast self-assessment. If any row lands in the "common gap" column for your business, it is a candidate for your next uplift.

ObligationWhat good looks likeCommon gap
AUSTRAC registration & enrolmentRegistered as a DCE and enrolled before any service; details kept currentTrading before registration completes; stale details after changes
AML/CTF program (Part A & B)Board-approved, business-specific, kept up to dateGeneric template that does not match the real business
ML/TF risk assessmentDocumented across customers, products, channels, geographies and typologies; drives the controlsWritten once, disconnected from monitoring and CDD
KYC / CDD (Part B)Reliable identity verification proportionate to riskOne-size-fits-all checks regardless of customer risk
Enhanced due diligenceTriggered by risk; evidenced source of funds/wealth; PEP and sanctions handling with sign-offECDD defined on paper but not applied in practice
Transaction monitoring (off-chain)Rules tuned to crypto typologies; structuring and velocity detectionUntuned rules, alert backlogs, false-positive overload
On-chain monitoring & analyticsDeposit/withdrawal wallet screening feeding risk ratings and reportingAnalytics run in isolation, or not at all
Travel Rule readinessCapability to collect, hold and transmit originator/beneficiary data; unhosted-wallet handlingNo architecture for value-transfer information
Sanctions screeningDFAT and applicable global lists; name and wallet-address screening; ongoing rescreeningOne-off screening; no address screening; no rescreening
SMRs & TTRsTimely, complete reporting with clear escalation and tipping-off controlsMissed suspicions; late or omitted threshold reports
Record-keepingRecords retained for the required periods and readily producibleFragmented records that cannot be produced on request
Independent reviewQualified, independent, regular; findings reported and remediatedNo review, or findings that are never closed out
Where to start. If you are standing up a DCE, register first and build the ML/TF risk assessment before anything else — it is the spine everything attaches to. If you are already live, a targeted gap assessment against the checklist above will usually surface two or three fixes that matter far more than the rest. Our AML/CTF and digital-asset services cover both.
Common questions

DCE compliance, answered

Does my crypto business need to register with AUSTRAC?

If you exchange digital currency for money (or money for digital currency) in the course of a business in Australia, you are providing a designated service as a digital currency exchange and must register with AUSTRAC before you start. Operating an unregistered DCE is an offence. You must also enrol on the Reporting Entities Roll and maintain a compliant AML/CTF program.

What is the difference between Part A and Part B of an AML/CTF program?

Part A is the risk-based systems and controls that identify, mitigate and manage your ML/TF risk — your risk assessment, transaction monitoring, employee due diligence, training, oversight by the board and senior management, and the compliance officer function. Part B sets out the customer identification and verification procedures you apply before providing a designated service.

What is the crypto Travel Rule and does it apply to Australian DCEs?

The Travel Rule requires that originator and beneficiary information travels with a transfer of value between institutions. For digital-asset transfers it means that when a DCE sends value to another exchange, prescribed information about the sender and recipient must accompany the transfer. Australian reforms are extending value-transfer and Travel-Rule style obligations to digital currency, so DCEs should build the capability to collect, hold and transmit this information.

What is the difference between an SMR and a TTR?

A Suspicious Matter Report (SMR) is lodged when you form a suspicion on reasonable grounds about a customer or transaction — for example possible money laundering, fraud or an offence — and it has strict lodgement timeframes. A Threshold Transaction Report (TTR) is lodged for transactions involving physical currency or digital currency at or above the reporting threshold, regardless of suspicion.

How does blockchain analytics support DCE compliance?

Blockchain analytics tools screen wallet addresses and trace the flow of funds on-chain, scoring exposure to high-risk sources such as sanctioned addresses, darknet markets, mixers and tumblers, ransomware and known scams. They complement traditional off-chain monitoring of fiat rails, feeding wallet-risk signals into your customer risk rating, enhanced due diligence and suspicious matter reporting.

How often does a DCE need an independent review of its AML/CTF program?

Part A of your AML/CTF program must be independently reviewed on a regular basis. The reviewer must be suitably qualified and independent of the functions being examined. The review tests whether the program meets legal requirements, is up to date, and is actually being applied in practice — its findings should be reported to the board or senior management with a remediation plan.

Financial Crime Advisory

Australia's specialist fraud, AML and loss-prevention consultancy. We help digital currency exchanges and digital-asset businesses register, build compliant AML/CTF programs, stand up on-chain and off-chain monitoring, and stay audit-ready for AUSTRAC. This article is general information, not legal or compliance advice — talk to us about your specific circumstances.

Running a DCE and want it audit-ready?

Whether you are registering, uplifting a program, or preparing for an AUSTRAC review, we'll tell you where you stand and what to fix first. No jargon, no lock-in.