Crypto in Australia has moved from a lightly supervised corner of financial services into its mainstream. That shift did not arrive as a single law with a single switch-on date. It is three separate frameworks, run by two regulators, each with its own scope, obligations, and penalties, and many businesses fall under more than one at the same time.
This guide is a working reference to all three. It sets out who regulates what, the milestones on the way to full effect, how a business works out which rules apply to it, and the controls regulators expect to see. It is written for compliance, legal, and operations teams at Australian exchanges, custody providers, over-the-counter desks, and the international platforms that serve Australian customers.
The Australian Securities and Investments Commission, or ASIC, is the conduct and licensing regulator. The Australian Transaction Reports and Analysis Centre, or AUSTRAC, is the financial-intelligence and anti-money-laundering regulator. They operate independently, so a single business can hold obligations to both at once. Other bodies touch crypto at the edges, including the Australian Taxation Office on tax and the Reserve Bank of Australia on payments, but ASIC and AUSTRAC carry the core compliance load.
The obligations do not all begin on the same day. Reading them as one timeline makes the sequence clear. The status labels below update to reflect the current date.
Two pressures sit behind Australia's approach, and both are durable rather than one-off. The first is international. As a member of the Financial Action Task Force (FATF), Australia is expected to apply the global anti-money-laundering standards for virtual assets, including the Travel Rule, and it is periodically reviewed on how well it does so. The second is domestic. Regulators have chosen to bring crypto under the same investor-protection and market-integrity rules that already apply to other financial products, rather than leave it in a separate, lighter regime.
A High Court decision reinforced the point, confirming that the financial-product definitions in existing law are broad and technology neutral. That gave ASIC the basis to apply current law to digital assets now, while the purpose-built framework is developed in parallel. The direction of travel, more supervision and closer alignment with global standards, is unlikely to reverse.
ASIC's guidance on when a digital asset is a financial product is set out in Information Sheet 225, updated in October 2025. The test is a rights-and-benefits analysis, not the label a token carries overseas. In ASIC's worked examples, Bitcoin and most meme coins are unlikely to be financial products, while yield-bearing stablecoins and tokenised real estate are likely managed investment schemes, and wallets and non-interest stablecoins are likely non-cash payment facilities. Because an asset's status can change as its features change, ASIC expects firms to reassess over time.
The transitional relief was regulatory forbearance, not an exemption. ASIC first set it to end on June 30, 2026, then extended it to September 30, 2026, describing the move as a pragmatic response to industry transition challenges that supports an orderly path to licensing. Applications rose sharply through the transition, passing 45 by September 2026.
ASIC sets out three routes, depending on what a firm does.
The reform widens supervision from digital currency exchanges to all virtual asset service providers, or VASPs, and applies the Financial Action Task Force (FATF) Travel Rule to transfers with no small-transfer exemption. Newly covered firms were required to register with AUSTRAC on renewable three-year terms and to appoint and notify an AML and CTF compliance officer.
The core obligations are risk-based. A firm must identify, assess, and mitigate money-laundering and terrorism-financing risk across its products, customers, channels, and jurisdictions, then monitor transactions against that risk. The Travel Rule requires collecting and transmitting originator and beneficiary information on transfers. Reporting from the sector indicates AUSTRAC is running targeted campaigns on over-the-counter desks and local exchanges, and is testing whether controls work in practice rather than reviewing documentation alone.
Note. The AUSTRAC dates and obligations above are drawn from industry compliance reporting. Confirm them against AUSTRAC's own guidance before relying on them for a filing.
Commencement is the start of an 18-month implementation, not the day licences open. A digital asset platform, or DAP, is a platform that enables digital-asset trading and transactions. A tokenised custody platform, or TCP, provides custody for tokenised assets. Both require financial-services licensing under tailored conduct, asset-holding, settlement, and financial-resource standards.
ASIC's roadmap runs in three phases. In the first six months, roughly April to September 2027, it holds roundtables, sets up advisory groups, and consults on guidance and standards. In months six to 12, it issues a new regulatory guide for DAPs and TCPs alongside asset-holding, settlement, and financial requirements. In months 12 to 18, licence applications open, with relief available while ASIC processes them. Full supervision and enforcement follow from around October 2028.
The frameworks overlap but do not substitute for one another. A single exchange can owe obligations under all three.
Sources: ASIC news releases and Information Sheet 225; industry reporting on the AUSTRAC reform.
Across the three frameworks, the same working steps carry a business through.
Two regulators share it. ASIC oversees digital assets that are financial products under the Corporations Act, including licensing and market conduct. AUSTRAC supervises anti-money-laundering and counter-terrorism-financing obligations for virtual asset service providers, including the Travel Rule. From April 9, 2027, ASIC also licenses digital asset platforms and tokenised custody platforms under the Digital Assets Framework.
Yes. Buying, holding, and trading crypto is legal in Australia. What has changed is that the businesses providing crypto services are now regulated, through AUSTRAC's anti-money-laundering regime, ASIC's financial-product licensing, and the incoming Digital Assets Framework for platforms.
When it provides a financial service in a digital asset that meets the financial-product definition under the Corporations Act, assessed through Information Sheet 225's rights-and-benefits test. Bitcoin and most meme coins are unlikely to qualify, while yield-bearing stablecoins and tokenised real estate are likely to. ASIC's transitional relief for this ran until September 30, 2026.
ASIC has warned that firms operating in breach after the transitional relief ends face civil and criminal penalties, including fines of up to 10% of annual turnover. The exposure depends on the conduct and the firm's circumstances.
They are separate. AUSTRAC supervises anti-money-laundering and counter-terrorism-financing obligations for virtual asset service providers, in force from July 1, 2026 and including the Travel Rule. ASIC supervises digital assets that are financial products under the Corporations Act. A firm can owe obligations to both, and meeting one does not satisfy the other.
They are the two new licensed categories created by the Corporations Amendment (Digital Assets Framework) Act 2026. A digital asset platform enables digital-asset trading and transactions. A tokenised custody platform provides custody for tokenised assets. Both need a bespoke financial-services licence once ASIC's 18-month rollout from April 2027 reaches the application stage.
ASIC's guidance stresses that Australian law can apply to conduct directed at Australian customers regardless of where a business or its servers are located, and that overseas classifications do not automatically translate. Offshore firms serving Australian users should assess their obligations under Australian law rather than assume a home-jurisdiction licence is sufficient.
Scorechain is a blockchain analytics and crypto AML compliance platform, EU-hosted and built over more than 10 years of work with regulated firms. Australia's obligations map onto the same controls compliance teams run elsewhere, and these are the areas where analytics tooling does the work.
Transaction monitoring: Risk-based monitoring of on-chain activity against typologies and thresholds.
Wallet screening: Real-time address risk checks for onboarding and ongoing review.
Travel Rule API: Automating originator and beneficiary data on virtual asset transfers.
VASP entity directory: Counterparty due diligence across a large directory of VASP entities.































