Asia-PacificFinTech & RegTechRegulation & Policy

AUSTRAC Targets Virtual AAML Reforms Take Effect

AUSTRAC has launched two targeted supervisory campaigns examining how virtual asset service providers manage money laundering and terrorist financing risks.

The first campaign focuses on businesses providing over-the-counter crypto-to-cash and cash-to-crypto services. AUSTRAC is engaging directly with 36 businesses to assess their operating models, service channels, scale and AML/CTF risk management.

A second campaign covers 27 local virtual asset exchanges operating in Australia, with particular attention to their readiness for the reformed AML/CTF regime and the quality of their governance arrangements.

The action signals that AUSTRAC’s expansion of virtual asset regulation will be accompanied by active supervisory scrutiny, not simply new registration and reporting requirements.

Why AUSTRAC Is Focusing on OTC Services

Over-the-counter virtual asset services can provide customers with a direct way to exchange large amounts of cash and crypto outside the standard retail exchange interface.

These services may be legitimate, but they can present elevated risks where they involve:

  • Large cash transactions;
  • Limited transparency over the customer’s wealth;
  • Third-party payments or collections;
  • Rapid movement into external wallets;
  • Customers acting on behalf of undisclosed persons;
  • Cross-border wallet activity; or
  • Transactions structured to avoid internal controls.

An OTC provider should not assess risk only at the point where cash is received or paid out.

It should also understand where the virtual assets originated, where they are being sent and whether the overall activity is consistent with the customer’s profile and stated purpose.

This requires an effective connection between traditional customer and transaction monitoring and blockchain-based analysis.

Local Exchanges Face Broader Governance Scrutiny

AUSTRAC’s campaign involving local exchanges is focused on reform readiness and governance.

Under Australia’s updated framework, the term virtual asset service provider, or VASP, replaces the narrower concept of a digital currency exchange provider.

The regulated perimeter is also expanding beyond traditional exchanges between fiat currency and crypto. Depending on the service provided, the framework may cover:

  • Virtual asset-to-virtual asset exchange;
  • Virtual asset custody and safekeeping;
  • Transfers of virtual assets on behalf of customers;
  • Brokerage or arrangements for exchange; and
  • Certain financial services connected with the offer or sale of virtual assets.

For exchanges, compliance responsibility therefore extends beyond customer onboarding and basic transaction screening.

Senior management and governing bodies must be able to demonstrate that the business understands its virtual asset risks, allocates sufficient compliance resources and responds effectively when suspicious activity is detected.

On-Chain and Off-Chain Monitoring Must Work Together

A virtual asset provider typically holds two different categories of information.

Off-chain information may include:

  • Customer identity and beneficial ownership;
  • Account access records;
  • Bank account details;
  • Payment methods;
  • Device and IP information;
  • Declared occupation or business activity;
  • Source-of-funds information; and
  • The customer’s transaction history on the platform.

On-chain information may include:

  • Sending and receiving wallet addresses;
  • Transaction paths;
  • Exposure to mixers or obfuscation services;
  • Links to scams, ransomware or darknet markets;
  • Interaction with sanctioned addresses;
  • Transfers through high-risk services or jurisdictions; and
  • Rapid movement across multiple wallets or blockchains.

Neither dataset is sufficient on its own.

A wallet may appear high-risk on-chain, but the provider still needs to determine who controls it and why the customer is interacting with it. Conversely, a customer may pass identity checks while using the platform to move funds through wallets associated with criminal activity.

Effective monitoring should bring these signals together within the same customer risk and investigation process.

Cash Conversion Requires Additional Controls

Crypto-to-cash and cash-to-crypto services create a direct bridge between physical currency and digital assets.

Providers operating this model should be able to identify:

  • Unusually large cash exchanges;
  • Repeated transactions just below internal review thresholds;
  • Customers using multiple locations or agents;
  • Third parties delivering or collecting cash;
  • Transactions inconsistent with known income or business activity;
  • Requests to transfer virtual assets immediately after a cash deposit; and
  • Customers unwilling to explain the purpose of the exchange.

The presence of cash does not automatically make a transaction suspicious. However, it can increase anonymity and make the origin of funds more difficult to establish.

Where the risk is higher, the provider may need additional information or evidence concerning the customer’s source of funds or source of wealth.

These checks should be proportionate to the risk rather than applied as a routine document-collection exercise to every customer.

High-Risk Wallets Require a Defined Response

Blockchain analytics can identify wallet exposure to known or suspected illicit activity, but a risk score should not be treated as a final compliance decision.

Providers need documented rules for determining:

  • Which wallet indicators require further review;
  • When a transfer should be delayed or rejected;
  • When enhanced customer due diligence is necessary;
  • How indirect exposure is evaluated;
  • When a customer should be asked for an explanation;
  • When a suspicious matter report should be considered; and
  • How decisions and supporting evidence are recorded.

A wallet that has indirect or historical exposure to a high-risk service may require a different response from a wallet directly linked to sanctions, ransomware or stolen assets.

The purpose of blockchain analytics is to support risk-based decisions, not to replace investigation and judgement.

Travel Rule Readiness Is Becoming Essential

The reforms introduce expanded Travel Rule obligations for businesses transferring or receiving virtual assets on behalf of customers.

Depending on its role in a transfer, a VASP may need to collect, verify, transmit or retain specified information about the parties to the transaction.

Providers will also need procedures for distinguishing between:

  • Transfers involving another regulated custodial provider; and
  • Transfers involving a self-hosted wallet.

For custodial wallets, the provider may need to assess whether the receiving or sending business is appropriately licensed or registered.

For self-hosted wallets, additional due diligence may be required to identify the person controlling the wallet and manage the associated risks.

Travel Rule compliance should therefore be integrated with wallet screening and transaction monitoring. Collecting transfer information without using it in the customer-risk and monitoring process would provide limited AML value.

What VASPs Should Review

AUSTRAC’s supervisory campaigns indicate several areas that virtual asset providers should examine:

  1. Whether all regulated services have been correctly identified;
  2. Whether enrolment and VASP registration information is complete and current;
  3. Whether the AML/CTF risk assessment reflects the actual business model;
  4. Whether OTC cash risks are specifically addressed;
  5. Whether on-chain and off-chain monitoring results are connected;
  6. Whether source-of-funds checks are applied proportionately in higher-risk cases;
  7. Whether wallet risk indicators lead to documented actions;
  8. Whether Travel Rule processes are operational;
  9. Whether compliance staff have sufficient authority and resources; and
  10. Whether senior management receives meaningful information about AML/CTF risks and control weaknesses.

Businesses should also be able to demonstrate how their controls work in practice.

A written AML/CTF program will provide limited protection if customer risk ratings are not updated, wallet alerts are not investigated or suspicious matters are not escalated.

A More Active Phase of Virtual Asset Supervision

AUSTRAC’s two campaigns do not mean that every OTC provider or local exchange has breached the law.

They do show that virtual asset supervision in Australia is entering a more active phase.

As the regulatory perimeter expands, VASPs will be expected to manage risks across the complete transaction lifecycle—from customer onboarding and fiat funding to wallet transfers and eventual cash withdrawal.

The key compliance challenge is no longer simply identifying the customer or screening a blockchain address.

It is connecting the customer, the money and the on-chain activity into a coherent view of risk.

Main Source

AUSTRAC — AUSTRAC Steps Up Supervision of Virtual Assets Sector as Reforms Take Effect

https://www.austrac.gov.au/new-and-media/news/austrac-steps-supervision-virtual-assets-sector-reforms-take-effect

Adminrichie

AML Observatory Webmaster, responsible for the website's operations.

Related Articles

Leave a Reply

Back to top button