AUSTRAC VASP vs Remittance Registration: One Clause Decides Which Register

AUSTRAC VASP vs Remittance Registration: One Clause Decides Which Register
Table of contents
    • A registrable remittance service is an item 29 or 30 value transfer that does not involve a transfer of virtual assets, so the same designated service sends you to a different register depending only on what moved, and a business doing both flows sits on both registers.
    • The DCE-to-VASP change took the regulated set from one service to five and deleted the requirement that a digital currency be generally available to the public without restriction, so the rename was the smallest part of it.
    • The value transfer chain that commenced on 31 March 2026 put remitters and VASPs under one travel rule covering money, virtual assets and property, domestic transfers included, which erased the biggest operational gap between the two sectors.
    • Threshold reporting keys off physical currency at A$10,000, so a A$250,000 crypto trade is not a threshold transaction while a A$10,000 banknote deposit at a crypto ATM is, which is exactly where AUSTRAC’s enforcement has landed.
    • AUSTRAC registration authorizes nothing under the Corporations Act, and ASIC’s sector-wide no-action position for digital asset businesses ran out on 30 June 2026.

    austrac vasp

    The whole boundary between Australia’s two AML/CTF registers now sits in a single exclusion. A registrable remittance service is a value transfer under item 29 or 30, provided by someone other than a financial institution or casino, through an Australian permanent establishment, that does not involve a transfer of virtual assets. That last clause is the dividing line, and every other element of the definition is shared with the register next door. Accepting a customer’s instruction to move value is item 29 whether the value is Australian dollars headed to Manila or USDT headed to a wallet in Dubai, so the only thing deciding which register you belong on is the asset class.

    An operator running both kinds of flow therefore lands on both registers, because the remittance definition carves virtual asset transfers out while the virtual asset definitions carve them in, and neither approval does any work for the other. That is a different failure mode from the one most compliance functions are built to catch. Nobody misses the exchange sitting inside a payments company. What gets missed is the remittance business that added a stablecoin settlement leg and assumed its registration stretched, or the exchange that started paying fiat out to overseas beneficiaries and assumed the VASP register covered it.

    The DCE-to-VASP change was a perimeter expansion wearing a rename

    Before 31 March 2026 the regulated crypto perimeter in Australia was essentially the on-ramp and the off-ramp, and a business that only swapped one token for another, or only held keys, or only moved assets on a customer’s instruction, sat outside the register entirely. The Amendment Act took that single service and turned it into five, covering fiat-to-virtual-asset exchange, virtual-asset-to-virtual-asset exchange, transfers on behalf of customers, safekeeping and administration, and participation in or provision of financial services connected with an issuer’s offer or sale.

    Home Affairs also removed the requirement that a digital currency be generally available to members of the public without restriction, which had been the gap stablecoin issuers could stand in. A permissioned token with a whitelist was arguably outside the old definition on its face, and it is inside the new one. Anyone who built a structure around that carve-out has been operating on borrowed time since March.

    In AUSTRAC’s own mapping the five services land at items 50A, 50B, 46A, 29 and 30, and 50C, and the two that generate the most argument are 50A and 50B, because both extend to making arrangements for an exchange rather than performing one. A platform that matches counterparties, or routes an order, or handles settlement without ever taking the other side, is squarely in the frame. Custody at 46A turns on whether the business controls or manages assets or private keys for another person, which is the line that separates a genuine non-custodial wallet developer from a business telling itself it is one because the marketing says self-custody.

    Existing registrants did not have to start over. Digital currency exchange registrations transitioned automatically into VASP status from 31 March 2026, and businesses newly caught by the expanded perimeter could keep trading while their application was assessed only if they filed by 29 July 2026. That window is shut. AUSTRAC’s ordinary position is that you cannot start providing registrable remittance or virtual asset services before it approves the registration, it may take up to 90 days to assess, the clock restarts when it asks for more information, and the registration runs for three years, so a launch plan that assumes ninety days from filing has no slack in it.

    The geographic test cuts differently for an offshore exchange than an offshore remitter

    Both registers depend on the designated service having a geographical link to Australia, and the routes to one are common to both, with a permanent establishment in Australia, an Australian resident providing the service through a foreign permanent establishment, or a foreign subsidiary of an Australian-resident company doing the same. The regimes part company because the remittance definition builds the Australian permanent establishment into the definition itself, while virtual asset services run off the general framework, so an identical offshore fact pattern resolves differently depending on which side of the exclusion the flow sits.

    AUSTRAC is direct that serving Australian customers through a website does not by itself create the link, and points instead at Australian servers the business owns and operates, business conducted at an Australian office, and payments processed through an Australian bank account, each assessed on the facts rather than on the presence of an address. An offshore exchange with local banking and a local support entity is a much closer call than its counsel usually concedes, and one with none of those sits outside the perimeter regardless of how many Australians hold accounts with it.

    Remittance networks are the place the framework abandons that logic entirely, because an RNP operating an affiliate network in Australia is a reporting entity whether or not it meets the geographical link requirement, which is a deliberate override built around how remittance businesses are structured internationally. Nothing comparable exists for virtual assets, and offshore exchanges reaching Australians through domestic intermediaries look structurally close enough to an offshore network with local affiliates that the asymmetry is worth watching.

    The travel rule erased the biggest operational difference between the two sectors

    For years the honest distinction between a remitter and a DCE was that one of them lived inside funds-transfer message discipline and the other did not. Remitters dealt in payer and payee data quality, correspondent expectations and international transfer reporting as routine operational work, while an exchange could treat blockchain settlement as a separate universe from its AML message controls, and that distinction has now gone.

    The reforms replaced the old funds-transfer architecture with a value transfer chain running from ordering institution to intermediary to beneficiary, and the chain applies to money, virtual assets and property, across domestic transfers as well as cross-border ones. Each participant carries a piece of it, with the ordering institution collecting and verifying payer details, everyone in the middle transmitting the required information onward, and all of them retaining records, screening for missing data and taking action when it is absent. The intermediary role is genuinely new as a named designated service, sitting at item 31 between the ordering leg at 29 and the beneficiary leg at 30, and it formalizes obligations for institutions that previously thought of themselves as passing messages rather than providing a service.

    For a VASP the practical consequence is that a transfer is not compliant merely because the value arrived. The required information has to move with it, or be handled consistently with the framework, and deficient data has to trigger something. Bolting on a travel rule module that talks to a counterparty VASP directory and treating it as a separate system from wallet risk scoring leaves a seam running through the middle of the controls architecture, and that seam is where an AUSTRAC information request lands.

    The reallocation buried in the reporting change deserves more attention than it has had. When international funds transfer instruction reporting gives way to international value transfer service reporting, the obligation shifts to the reporting entity closest to the Australian customer rather than the institution sending or receiving the cross-border instruction. Some entities that report today will stop. Others that have never filed an IFTI in their lives will start, and they will discover it during a build rather than during a policy review, because nothing about their customer-facing product will have changed.

    Remittance networks carry a structure the VASP register has no version of

    Architecture is where the two regimes still genuinely diverge, because remittance registration splits three ways, between an independent dealer using its own products, platforms or systems, a remittance network provider whose brand and infrastructure other businesses trade on, and an affiliate operating under that network by agreement. AUSTRAC puts the registration of affiliates on the network, along with responsibility for their compliance obligations, which is a materially different posture from any part of the VASP framework, where every registrant answers for itself.

    That structure is usually sold internally as compliance economics, and the economics are real, since shared monitoring, shared training and shared reporting across a few hundred shopfronts costs less than each of them building it. What comes with it is a legal exposure to data you do not generate. A network that cannot pull complete, timely, accurate transaction and customer records out of its affiliates is answerable for reports it has no reliable way to produce, and no contractual language fixes that if the underlying data feed is broken. Affiliate onboarding is the point of control, because a network’s assessment of a prospective affiliate’s risk is doing the work that a regulator would otherwise do at registration.

    Nothing equivalent exists for virtual assets, and it is worth asking whether that holds. White-label exchange infrastructure, embedded crypto rails inside consumer apps, and brokerage arrangements where one registered entity provides the pipes for a dozen unregistered front-ends replicate the remittance network shape almost exactly. The Act has no VASP network provider category, so each of those front-ends has to test its own perimeter, and a fair number of them will conclude they are making arrangements for an exchange under 50A or 50B and are registrable in their own right.

    The threshold report is about banknotes, which is why crypto ATMs are where enforcement landed

    A misconception survives in both sectors that a large transaction is a reportable one. Threshold transaction reporting keys off the presence of physical currency at or above A$10,000, so a A$250,000 electronic remittance falls outside it, a A$250,000 virtual asset trade falls outside it, and a A$10,000 stack of banknotes fed into a machine to buy Bitcoin sits squarely inside. Suspicious matter reporting has no floor at all, which means the vast majority of what a reporting entity should be sending AUSTRAC has nothing to do with A$10,000.

    That statutory shape explains the enforcement map better than any risk narrative. Crypto ATMs sit at the one point in the virtual asset economy where cash meets a virtual asset service, which puts them inside the threshold reporting regime in a way an exchange is not, and Australia has a lot of them. AUSTRAC counted a jump from 23 machines in 2019 to roughly 1,800 by the time it announced a dedicated task force, moving something like 150,000 transactions and A$275 million a year, with about 99% of that being cash going in to buy crypto rather than crypto being sold for cash. A one-way cash funnel with fast settlement and thin face-to-face intervention is close to a purpose-built structuring and scam vector, and the numbers said so.

    AUSTRAC’s response was to use registration conditions rather than wait for a penalty, imposing a A$5,000 cap on cash deposits and withdrawals, enhanced customer due diligence and mandatory scam warnings across the sector. Conditions attach to the registration, breach of a condition is itself an offense, and the whole thing took effect without a court. For anyone modeling regulatory risk in this space, that mechanism is more consequential than the civil penalty maximums, because it operates on a supervisory timetable rather than a litigation one.

    Registration is the leverage, and AUSTRAC has been pulling it

    Cryptolink is the clearest demonstration of how that plays out end to end. AUSTRAC issued the company a A$56,340 infringement notice and accepted a court-enforceable undertaking in October 2025 over late reporting of large cash transactions and weaknesses in its money laundering and terrorism financing risk assessments, with third-party reviewers brought in to validate transaction reporting and reassess the risk assessment. When threshold transaction reports still did not arrive and an AUSTRAC information request went unanswered, the regulator suspended the VASP registration on 9 August 2026 for three months and took all 96 of the company’s ATMs offline. A business with no valid registration cannot lawfully provide the service, so the practical effect was a shutdown, delivered faster than any penalty proceeding would have reached a first case management hearing.

    The remittance side has been getting the same treatment with less coverage. AUSTRAC suspended four remittance registrations across 2025 and refused to renew another, and its public record of registration actions reads as a steady drumbeat rather than a campaign. The campaign came in February 2025, when AUSTRAC disclosed action against 13 remittance and digital currency exchange providers with more than 50 others under review, citing systemic non-reporting and under-reporting across both sectors, having already cancelled, suspended or refused renewal for nine providers late the previous year. The context those figures sit in is a population of 417 registered digital currency exchanges and 5,112 remittance registrations, so double-digit action counts against a five-thousand-entity register are a supervisory posture rather than a purge, and anyone reading them as evidence that the register has been cleaned out is reading them wrong.

    Register integrity has become an objective in its own right, and AUSTRAC made the VASP register publicly searchable on 30 June 2026 while removing entities no longer genuinely operating or providing regulated services. A dormant registration used to be a harmless artifact kept alive in case the business restarted. It is now a public listing that anyone can check and that AUSTRAC has said it intends to clear out.

    Whether any of this is proportionate to the underlying risk is a fair question, and the answer differs by sector. The remittance register carries thousands of small businesses serving diaspora corridors that the banking system already treats as radioactive, and Treasury has named remittance providers and digital currency exchanges among the sectors disproportionately affected by de-banking, while conceding the data on how bad it is barely exists. Squeezing compliance costs upward in a sector that already struggles to hold a bank account pushes activity toward cash and informal channels, which is the opposite of what the regime is for. That tension has not been resolved, and the reforms did not attempt to.

    The transitions nobody has budgeted for run to 2029

    Reading 31 March 2026 as the finish line is a mistake that will surface in about two years. Existing reporting entities enrolled on 30 March 2026 may keep using their applicable customer identification procedures instead of the new initial customer due diligence obligations through 31 March 2029, provided they documented a transitional policy identifying customer classes and migration dates by 1 July 2026. Ongoing customer due diligence applied immediately from March, so a business is now monitoring a customer base it identified under the old standard and will re-paper over three years, which is a data migration project sitting inside a compliance obligation.

    International value transfer service reporting runs on a similar clock, with a default transition on 31 March 2029 and an option for eligible providers to nominate a substitute date out to 30 September 2029. Providers handling virtual asset transfers get no substitute date and must move on the default, which is the single sharpest signal in the transitional rules about where AUSTRAC thinks the risk is. Between now and then, IFTI reporting continues, which means a VASP that becomes an IVTS reporter under the new allocation is building toward an obligation that has a fixed date and no extension.

    Item 50C is the quiet one, and issuers are standing on it

    Four of the five virtual asset services describe things a business does to somebody else’s asset. The fifth covers participation in, and the provision of financial services connected with, an issuer’s offer or sale of a virtual asset, which reaches the primary market rather than the secondary one and captures businesses that would never describe themselves as exchanges or custodians. A launchpad, a distribution partner, a market maker engaged at issuance and a platform running a token sale for a third party are all doing something to an asset at the moment it comes into existence, and 50C reaches them on its face.

    Where its edges sit has not been tested, and the wording leans broad in a way that will eventually need guidance, because participation in an offer is a much softer concept than controlling a private key or matching an order. The overlap is what makes it consequential today. A stablecoin issuer distributing in Australia is inside 50C on the AML side and inside ASIC’s financial product perimeter on the Corporations Act side, which stacks a VASP registration and an AFS license onto a business whose entire activity is minting and redeeming a claim on a dollar, and that is what the law currently asks of it.

    AUSTRAC registration authorizes nothing, and ASIC made that concrete in June

    The most expensive misunderstanding in this whole area has nothing to do with which register you sit on. A VASP registration is an AML/CTF gate and says nothing about whether the products being offered are financial products under the Corporations Act. ASIC settled the substance of that question in October 2025, updating INFO 225 to confirm that stablecoins, wrapped tokens, tokenized securities and digital asset wallets are financial products under existing law, and granting a sector-wide no-action position to give firms time to license.

    That position expired on 30 June 2026. ASIC spent the run-up telling digital asset businesses to apply for a new or varied AFS license by that date, and the businesses it named included brokers, intermediaries, wallet providers and anyone distributing stablecoins or wrapped tokens. So a crypto business operating in Australia today answers to two regulators running two perimeters on two timetables, and a VASP registration settles one of those two questions.

    The asymmetry is worth sitting with, because a plain fiat remittance business, correctly registered, with clean corridor controls and no financial products in its stack, has a comparatively simple non-AUSTRAC profile. A VASP offering custody, stablecoin distribution, tokenized exposure or yield has an AFS licensing question attached to nearly every line item, and the two businesses look identical on an AUSTRAC search result.

    Classify at the flow level, because the Act does

    The way to get this right is unglamorous and mostly clerical. Map every product and transaction flow to a designated service item, and do it at the flow level, because a single company routinely provides several. Test each flow for the geographic link, since serving Australian customers through a website does not by itself create the permanent establishment the remittance definition requires, and test each for the business-context and rules-based exclusions rather than assuming the item number settles it. For anything involving both fiat and crypto, write down separately why each leg is remittance, VASP, both under different services, or outside the perimeter, and keep the reasoning where an auditor can find it.

    Then treat registration as a live obligation rather than a one-time filing. Changes to beneficial owners, key personnel, countries, counterparties, products and services generally have to reach AUSTRAC within 14 days, and the registration assessment itself looks at readiness, resourcing, the experience of key personnel and their criminal and compliance history, which means an applicant treating the compliance officer as a post-approval hire is answering a question AUSTRAC has already asked. Reconcile transaction ledgers against what was reported instead of trusting front-end alerting, because the February 2025 campaign and the Cryptolink suspension both started with reports that never arrived rather than with a controls review that went badly.

    What has genuinely changed since 2020 is that the two regimes have converged everywhere except the one place operators keep looking for a distinction. Program, governance, customer due diligence, monitoring, reporting and the travel rule are now close to common ground, and the register you land on turns on nothing more than whether the thing you moved was a virtual asset. The old mental model, where crypto businesses had a lighter perimeter and remitters carried the transfer-data burden, described the world accurately until March 2026 and describes nothing now.

    See more: Compare Australia licensed companies for sale

    Frequently Asked Questions (FAQ)

    Can a business hold AUSTRAC remittance registration and provide virtual asset services under it?  +

    No. The definition of a registrable remittance service excludes services involving a transfer of virtual assets, and virtual asset transfers, exchange, safekeeping and issuer-related services sit under the separate VASP framework. A business doing both needs both registrations.

    Did existing digital currency exchange registrations have to be re-applied for?  +

    No. DCE registrations transitioned automatically into VASP status from 31 March 2026. Businesses newly captured by the expanded perimeter had to apply by 29 July 2026 to keep operating while their application was assessed, and that window has closed.

    How long does AUSTRAC take to assess a registration application?  +

    AUSTRAC states it may take up to 90 days, and the period can restart when it requests further information. Registration runs for three years, and you cannot start providing registrable remittance or virtual asset services before approval.

    Is a large crypto trade a threshold transaction?  +

    No. Threshold transaction reporting is triggered by physical currency at or above A$10,000, not by transaction value, so a large electronic or virtual asset transaction is not reportable on that basis. A cash deposit of A$10,000 or more at a crypto ATM is.

    Does the travel rule apply to domestic transfers?  +

    Yes. The value transfer chain that commenced on 31 March 2026 covers money, virtual assets and property, and applies to domestic as well as cross-border transfers, which is broader than the previous financial-institution-only requirement.

    What can AUSTRAC do short of taking a business to court?  +

    Impose conditions on a registration, suspend it, cancel it or refuse renewal. AUSTRAC used conditions to set a A$5,000 cash cap, enhanced due diligence and scam warnings across crypto ATM operators, and suspended Cryptolink's registration on 9 August 2026 for three months, taking 96 ATMs offline.

    Does AUSTRAC registration mean a crypto business is licensed in Australia?  +

    No. ASIC confirmed in October 2025 that stablecoins, wrapped tokens, tokenized securities and digital asset wallets are financial products under existing law, and its sector-wide no-action position for firms seeking an AFS license ended on 30 June 2026.

    When do the transitional arrangements finish?  +

    Applicable customer identification procedures may be used in place of initial customer due diligence through 31 March 2029, with a transitional policy required by 1 July 2026. IVTS reporting defaults to 31 March 2029, with a substitute date available to 30 September 2029 for eligible providers, though not for those handling virtual asset transfers.

    Regulation
    Canada Stablecoin Act Has a Trust Issue
    The Stablecoin Act received Royal Assent on 26 March 2026 and is still tagged “[Act not in force]”, with commencement left to a Governor in Council order that has not been made and Finance Canada pointing at 2027. Section 12 excludes financial institutions, and the Act borrows the Bank Act definition, which covers provincially chartered […]...
    7 hours ago
    LegalRegulation
    DCM Explained: The Regulatory License Behind Prediction Markets
    A designated contract market (DCM) is an exchange registered with the US Commodity Futures Trading Commission (CFTC) under Section 5 of the Commodity Exchange Act (CEA) and Part 38 of the CFTC’s regulations. It may list futures, options and event contracts, and it may admit retail customers directly. Event contracts count as derivatives under federal […]...
    1 week ago
    RegulationSafety
    Off the Books: Blockchain Analytics and the RWA Register Problem
    The ECB found that none of the largest tokenized money market funds is fully on-chain, and around half still use a traditional book-entry ledger as the primary record of ownership. Analytics reading those chains is reading a notification layer. Crypto analytics was built to de-anonymize a pseudonymous ledger. ERC-3643 tokens are identity-bound at the gate […]...
    2 weeks ago