Crypto Travel Rule Australia: What VASPs Need to Do Before 1 July 2026

Short Answer

 

From 1 July 2026, Australian virtual asset service providers will need to be ready for expanded AML/CTF obligations, including travel rule obligations for certain virtual asset transfers. In practical terms, VASPs should assess which designated services they provide, confirm their AUSTRAC enrolment and registration position, update their AML/CTF program, map ordering and beneficiary institution responsibilities, build systems for collecting and transmitting required payer and payee information, and address higher-risk transfers involving custodial and self-hosted wallets.

For many crypto businesses, this is not just a compliance policy exercise. It may require changes to onboarding, wallet screening, transfer workflows, transaction monitoring, platform terms, privacy notices, vendor contracts and governance records.

Why This Matters Now

 

Australia’s AML/CTF reforms are changing the compliance position for crypto businesses. AUSTRAC now uses the language of “virtual assets” and “virtual asset service providers”, replacing the older digital currency exchange terminology in key reform materials.

The practical effect is that more crypto-related activities can be brought within AML/CTF regulation. This includes services beyond simple fiat-to-crypto exchange, such as virtual asset-to-virtual asset exchange, safekeeping services and accepting instructions to transfer virtual assets on behalf of customers.

For founders and operators, the risk is timing. A VASP cannot wait until July 2026 to start designing compliance workflows. The travel rule requires operational capability: customer data collection, verification logic, wallet due diligence, secure information transmission, records, exception handling and staff training.

Who Should Read This Article?

 

This article is for Australian and offshore crypto businesses that provide, or are considering providing, services to Australian customers, including:

  • crypto exchanges;
  • virtual asset service providers;
  • digital asset platforms;
  • wallet and custody providers;
  • OTC desks and brokers;
  • token platforms and settlement providers;
  • fintechs adding crypto functionality;
  • founders and directors of digital asset businesses;
  • AML/CTF compliance officers and operations teams.

It is also relevant to overseas platforms that provide services into Australia. Australian law can apply where services are provided in relation to Australia, and offshore structuring will not necessarily avoid Australian regulatory obligations.

What Is The Crypto Travel Rule?

 

The travel rule is an AML/CTF obligation that can apply when a reporting entity transfers or receives money, virtual assets or property on behalf of customers.

For virtual asset transfers, the rule is designed to ensure that certain information about the payer and payee travels through the transfer chain, or is otherwise collected and handled in accordance with the AML/CTF framework. The aim is to reduce anonymity in value transfers and improve the ability of regulated businesses and law enforcement to detect money laundering, terrorism financing and other serious financial crime.

In a crypto context, the travel rule can affect how a VASP handles transfers between:

  • one custodial platform and another custodial platform;
  • a custodial platform and a self-hosted wallet;
  • Australian and overseas virtual asset businesses;
  • a customer account and a wallet controlled by another party;
  • platform wallets, omnibus wallets and other custody structures.

 

The key commercial point is that the rule can change the customer experience. Transfers that previously required only a wallet address may now require additional data collection, risk checks, warnings, holds, rejection logic or manual review.

Key Dates For VASPs

 

The most important dates for many crypto businesses are:

Date Why it matters
31 March 2026 Some reform changes begin for currently regulated entities and certain virtual asset services. Existing digital currency exchange providers may need to transition details to the VASP framework.
1 July 2026 Expanded AML/CTF obligations apply to many newly regulated businesses and services, including key obligations for VASPs and virtual asset transfers.
29 July 2026 Providers of new virtual asset services must generally apply to enrol and register with AUSTRAC by this date if they fall within the relevant requirements.
31 March 2029 Reporting obligations for transfers involving unverified self-hosted virtual asset wallets are deferred for relevant reporting entities, but this does not remove the need to plan for the systems and policy changes.

Some transitional rules are nuanced. For example, AUSTRAC guidance indicates that certain obligations for new registrable virtual asset services are deferred until 1 July 2026, but that deferral does not apply in the same way to item 50A services involving exchange between virtual assets and fiat currency. Crypto businesses should not assume that every obligation has the same start date.

Which Virtual Asset Services Are Captured?

 

AUSTRAC guidance identifies several virtual asset-related designated services that may be relevant. These include:

  • exchanging virtual assets for money, or money for virtual assets;
  • making arrangements for that type of exchange;
  • exchanging virtual assets for other virtual assets;
  • making arrangements for virtual asset-to-virtual asset exchange;
  • providing a virtual asset safekeeping service;
  • accepting instructions to transfer virtual assets on behalf of customers;
  • making transferred virtual assets available to customers;
  • providing certain financial services connected with the offer or sale of a virtual asset.

 

This is broader than the older idea of a digital currency exchange. A business may be captured even if it does not describe itself as an exchange. For example, an intermediary, platform operator, custody provider or business arranging peer-to-peer exchange may need to examine whether it is providing a designated service.

What Does A VASP Need To Do Before 1 July 2026?

 

A practical readiness plan should cover at least the following areas.

1. Confirm Whether The Business Is A VASP

 

Start with a service-by-service analysis. Do not rely only on labels such as “exchange”, “wallet”, “protocol”, “broker”, “marketplace” or “technology provider”.

A legal review should ask:

  • What services does the business actually provide?
  • Does it exchange virtual assets for money?
  • Does it exchange virtual assets for other virtual assets?
  • Does it arrange exchanges, even if another party executes them?
  • Does it control or manage virtual assets or private keys for customers?
  • Does it accept instructions to transfer virtual assets?
  • Does it make received virtual assets available to customers?
  • Does it provide services in connection with the offer or sale of a virtual asset?
  • Does the service have a geographical link to Australia?

 

The answer may differ across product lines. A business might be outside the regime for one service but regulated for another.

2. Check AUSTRAC Enrolment And Registration

 

VASPs must consider both enrolment and registration. AUSTRAC guidance states that remittance service providers and virtual asset service providers must enrol and apply for registration.

For newly regulated virtual asset services, providers must generally apply to enrol and register by 29 July 2026. Where a business applies before that date, transitional arrangements may allow it to continue providing the new virtual asset services until AUSTRAC makes a decision.

Existing digital currency exchange providers should also check whether they need to update details or transition their registration information. AUSTRAC has published guidance for moving from the DCE framework to the VASP framework.

This is a governance issue, not just an online form. Registration questions may require information about beneficial owners, key personnel, operational capability, countries of operation, risk management and matters relevant to whether the business can manage money laundering, terrorism financing and proliferation financing risk.

3. Update AML/CTF Program

 

A VASP’s AML/CTF program should be updated to reflect the actual risks of the virtual asset business. A generic AML policy is unlikely to be enough.

The program should address:

  • customer types and risk ratings;
  • products, tokens and chains supported;
  • custody and wallet architecture;
  • fiat ramps and banking arrangements;
  • exposure to mixers, bridges, privacy coins and high-risk wallets;
  • foreign jurisdiction risk;
  • sanctions screening;
  • blockchain analytics and wallet due diligence;
  • suspicious matter reporting;
  • threshold transaction reporting where relevant;
  • travel rule information collection and transmission;
  • record-keeping;
  • compliance officer responsibilities;
  • board or senior management oversight;
  • independent review or evaluation requirements.

 

The program should also explain how the business identifies, mitigates and manages risk in practice. AUSTRAC’s current approach places significant emphasis on risk assessment and operational controls.

4. Map Ordering, Intermediary And Beneficiary Institution Roles

 

The travel rule depends on the role a business plays in the transfer chain.

A VASP may be an ordering institution when it accepts a customer’s instruction to send virtual assets. It may be a beneficiary institution when it makes received virtual assets available to a payee. In some cases, a business may also need to consider whether it performs an intermediary role.

This role mapping should be done for each transfer flow, including:

  • customer withdrawal to another exchange;
  • customer withdrawal to a self-hosted wallet;
  • deposit from another exchange;
  • deposit from a self-hosted wallet;
  • internal transfers between customers;
  • cross-chain swaps;
  • omnibus wallet movements;
  • transfers involving offshore platforms;
  • transfers involving institutional custody arrangements.

 

Each flow should identify what information is collected, verified, transmitted, received, monitored and recorded.

5. Build A Travel Rule Data Model

 

The legal obligation needs to become a data model inside the product and compliance stack.

A VASP should identify:

  • what payer information must be collected;
  • what payer information must be verified;
  • what payee information must be collected;
  • what tracing information must be created or retained;
  • what information must be sent to another institution;
  • when information does not need to be sent because an exemption applies;
  • how information is protected in transit and at rest;
  • how incomplete or unreliable information is handled;
  • what records are retained and for how long.

 

Product teams should be involved early. If the transfer workflow is designed without legal and compliance input, the business may later need costly rework.

6. Deal Carefully With Self-Hosted Wallets

 

Self-hosted wallets are a major practical issue for crypto travel rule implementation.

AUSTRAC guidance recognises an exemption from sending information to another business in the transfer chain when the transfer is to a self-hosted virtual asset wallet. But that does not mean self-hosted wallet transfers can be ignored.

For transfers to self-hosted wallets, an ordering institution may still need to collect and verify payer information, collect payee information and collect tracing information. For transfers received from self-hosted wallets, a beneficiary institution may need to obtain payer information, tracing information and, if not already held, the payee’s full name before making virtual assets available.

VASPs should decide how they will establish reasonable grounds for wallet characterisation. This may include blockchain analytics, customer attestations, wallet screening, address ownership checks or other evidence-based controls.

The policy should also explain what happens where a self-hosted wallet cannot be verified, where blockchain analytics show elevated risk, or where the customer’s explanation is inconsistent with transaction behaviour.

7. Review Privacy, Data Security And Customer Terms

 

Travel rule implementation involves collecting, using and sharing more personal information. That raises privacy, cybersecurity and contract issues.

A VASP should review:

  • privacy notices and collection statements;
  • customer terms of use;
  • transfer consent wording;
  • data retention policies;
  • cross-border disclosure arrangements;
  • vendor contracts with travel rule solution providers;
  • blockchain analytics provider agreements;
  • incident response procedures;
  • customer support scripts for delayed or rejected transfers.

 

This is particularly important where travel rule data is sent to overseas counterparties or handled by third-party technology providers. The business should understand where data is stored, who can access it, and whether the recipient can receive it securely.

8. Prepare Transfer Exception And Rejection Rules

 

The travel rule creates operational questions that must be answered before launch.

For example:

  • When will a transfer be delayed?
  • When will a transfer be rejected?
  • When will the business ask the customer for more information?
  • Who can approve a manual override?
  • What happens if the beneficiary institution cannot securely receive required information?
  • What happens if a counterparty is required to be licensed or registered but appears not to be?
  • What happens if the wallet is linked to sanctions, scams, darknet markets or mixers?
  • When should a suspicious matter report be considered?

 

These decisions should not be made ad hoc by customer support staff. They should be built into a documented control framework.

9. Train Staff Before The Rules Go Live

 

Travel rule compliance will involve compliance teams, product teams, engineering teams, customer support, legal, operations and senior management.

Training should cover:

  • what the travel rule is;
  • which transfer types are affected;
  • what information must be collected;
  • how to identify red flags;
  • how to handle incomplete transfer information;
  • when to escalate;
  • how to avoid tipping off;
  • how customer communications should be framed;
  • how records must be kept.

 

For directors and founders, training should also cover governance responsibility. Regulators will expect senior management to understand the risk profile of the business, not just delegate compliance to one person.

10. Consider ASIC Licensing And Financial Services Overlap

 

AML/CTF compliance is only one part of the regulatory picture.

ASIC’s updated digital assets guidance makes clear that businesses involved with digital assets need to assess whether the asset, product or related arrangement is a financial product under the Corporations Act. Depending on the structure, a digital asset or related service may involve a managed investment scheme, security, derivative, non-cash payment facility, custody service, financial product advice, dealing, market operation or other regulated activity.

A crypto business may therefore need to consider:

  • whether it requires an Australian financial services licence;
  • whether it is operating a financial market;
  • whether custody arrangements trigger financial services obligations;
  • whether retail client obligations apply;
  • whether AFCA membership or internal dispute resolution requirements apply;
  • whether design and distribution obligations apply;
  • whether marketing claims are misleading or deceptive;
  • whether token classification has changed over time.

 

The commercial lesson is that VASP compliance should not be reviewed in isolation. A platform may be compliant with AUSTRAC registration requirements but still have unresolved ASIC licensing or consumer protection risk.

Practical VASP Readiness Checklist

 

Before 1 July 2026, VASPs should consider the following actions:

  • Prepare a designated services analysis.
  • Confirm AUSTRAC enrolment and registration requirements.
  • Identify whether any transitional rules apply.
  • Map each transfer flow by ordering, intermediary and beneficiary role.
  • Update the AML/CTF risk assessment.
  • Update the AML/CTF program.
  • Build travel rule data fields into onboarding and transfer workflows.
  • Select and contract with any travel rule technology provider.
  • Review blockchain analytics and wallet screening controls.
  • Prepare self-hosted wallet procedures.
  • Update customer terms and privacy notices.
  • Review cross-border data sharing.
  • Set exception, delay and rejection rules.
  • Train staff.
  • Prepare board or management reporting.
  • Review ASIC licensing overlap.
  • Prepare an implementation evidence file.

 

Common Mistakes For Crypto Businesses To Avoid

 

Assuming The Rules Only Apply To Traditional Exchanges

 

The reforms can capture a broader range of services than simple fiat-to-crypto exchange. Custody, exchange arrangements and transfer services may all need review.

Treating Travel Rule Compliance As A Vendor Purchase

 

Technology can help, but it does not replace a legal analysis, risk assessment, AML/CTF program or governance framework. The business remains responsible for how the system is configured and used.

Leaving Privacy Review Until The End

 

Travel rule data is sensitive. If privacy notices, customer terms and data transfer arrangements are not updated early, launch can be delayed.

Ignoring Self-Hosted Wallet Workflows

 

Self-hosted wallets create some of the hardest implementation questions. A business should decide in advance how it will identify, verify, risk-rate and monitor these transfers.

Failing To Connect AUSTRAC And ASIC Workstreams

 

Crypto businesses often face overlapping AML/CTF, financial services, consumer protection, privacy and sanctions risks. A narrow AUSTRAC-only review may miss major licensing issues.

FAQs

 

Does Every Crypto Business Need To Register With AUSTRAC?

 

No. The answer depends on the services the business provides and whether those services have the required Australian connection. A business should assess each product and service against the virtual asset designated services and registration requirements.

What Is A Virtual Asset Service Provider In Australia?

 

A VASP is generally a business that provides certain virtual asset services, such as exchange, transfer or safekeeping services, where the relevant statutory requirements are met. The concept is broader than the older digital currency exchange terminology.

When Do The Crypto Travel Rule Obligations Start?

 

For many VASPs, key travel rule obligations for virtual asset transfers need to be ready by 1 July 2026. Transitional rules may affect some obligations and services, so businesses should check their exact service profile.

Do The Rules Apply To Self-Hosted Wallets?

 

Self-hosted wallets are treated differently from transfers between regulated custodial institutions, but they are not outside the compliance framework. VASPs may still need to collect, verify or obtain information, conduct due diligence and manage wallet-related ML/TF risk.

Can A VASP Keep Operating If Its Registration Application Is Pending?

 

AUSTRAC guidance indicates that providers of new virtual asset services that apply for registration before 29 July 2026 may continue providing those new services until AUSTRAC makes a decision. This depends on the business and service type, so it should be checked carefully.

Does AUSTRAC Registration Mean A Crypto Business Does Not Need An AFSL?

 

No. AUSTRAC registration and ASIC licensing deal with different legal regimes. A crypto business may need to comply with AML/CTF laws and also assess whether its digital assets or related services are financial products or financial services under the Corporations Act.

What Should A VASP Do First?

 

The first step is a legal and operational mapping exercise. Identify each service, each customer flow, each wallet flow and each regulatory role. From there, the business can build the AML/CTF program, registration strategy and travel rule implementation plan.

Key Takeaways

 

The crypto travel rule in Australia is not just a compliance deadline. It is a systems, data, governance and customer experience project.

VASPs should use the period before 1 July 2026 to confirm their regulatory status, update their AML/CTF framework, build transfer information workflows, address self-hosted wallet risk, review customer terms and privacy documentation, and check whether ASIC licensing issues also arise.

For founders and directors, the safest approach is to treat travel rule readiness as a board-level implementation project. The businesses that prepare early will be better placed to keep transfers moving, answer regulator questions and maintain customer trust when the new regime takes effect.

Disclaimer

 

This article provides general information only and is not legal advice. Crypto / virtual asset, financial services and AML/CTF obligations are fact-specific and can change depending on the structure of the business, the assets involved, the customer base and the services provided. Businesses should obtain legal advice before relying on this information for compliance decisions.

Set up, grow, scale or sell your business with expert legal guidance.

Book a free consultation with us and let’s talk about how we can help your business succeed and stay competitive in the market.