top of page
fnlogo.png

AUSTRAC Removes 45 Payment and Virtual Asset Businesses as Regulatory Pressure Intensifies

1 day ago
7 min read

Australia’s financial crime regulator has stepped up its scrutiny of remittance businesses and virtual asset service providers, removing 45 businesses from its registers over the past year after identifying a range of regulatory, operational and money laundering concerns.


AUSTRAC Removes 45 Payment and Virtual Asset Businesses as Regulatory Pressure Intensifies

The action represents a significant warning to businesses operating in high-risk payment sectors as Australia enters a new phase of its anti-money laundering and counter-terrorism financing framework. The regulator cancelled registrations, suspended businesses or refused renewal applications involving remittance providers and virtual asset service providers, citing concerns ranging from inactivity and inadequate operational capacity to failures to maintain appropriate registration and significant money laundering and terrorism financing risks.


The intervention comes at a particularly important time for Australia’s financial sector. The country has been implementing substantial reforms to its AML/CTF framework during 2026, while regulators have simultaneously increased their focus on payment channels that can be exploited to move criminal proceeds rapidly across borders.


Remittance businesses and virtual asset providers occupy a particularly sensitive position within that environment. Both sectors can facilitate legitimate international payments and financial inclusion, but their services can also be exploited by organised criminal groups seeking to move funds between jurisdictions, disguise the origin of proceeds or transfer value outside conventional banking channels.


The regulator's latest action demonstrates that registration is not being treated as a one-time administrative exercise. Businesses are expected to maintain the operational capability, governance arrangements and compliance infrastructure necessary to support the activities for which they are registered.


Among the businesses targeted were entities that lacked the capacity to commence or continue operations, remained dormant or inactive, had not provided designated services for extended periods, or had become insolvent. Other cases involved businesses that failed to maintain the appropriate registration or failed to notify the regulator about material changes to their circumstances.


The significance of these categories extends beyond administrative compliance. An inactive or poorly maintained registration can create uncertainty about who is actually operating a business, what services it provides, who controls it and whether the information held by the regulator accurately reflects its current activities.


For an AML/CTF regulator, these issues are particularly important because accurate registration information is a fundamental component of effective supervision. If ownership, management, business activities or operating arrangements change without being reported, a regulator may no longer have an accurate picture of the risks associated with the entity.


The crackdown also highlights the distinction between being technically registered and being genuinely capable of operating a compliant financial business.


A company may have completed its registration process and established an apparent corporate structure, but that does not necessarily demonstrate that it has the systems, personnel, controls and governance arrangements required to manage financial crime risks.


This is particularly relevant to virtual asset businesses, where the underlying technology can allow transactions to occur at high speed and across multiple jurisdictions. Effective controls therefore need to operate continuously rather than simply at onboarding or registration stage.


The regulator specifically highlighted the risks created by rapid cross-border movement of money. Such transactions can be legitimate, but the same characteristics can make remittance and payment services attractive to criminal organisations seeking to move illicit funds away from the jurisdiction in which they were generated.


The risk becomes even more pronounced where cross-border payment services intersect with cryptocurrency.


Digital assets can provide criminal groups with another mechanism for transferring value internationally, while crypto exchanges, brokers, ATM networks and other virtual asset businesses can provide points at which illicit funds enter or leave the regulated financial system.


This is one reason why regulators are increasingly treating the wider payment ecosystem as an interconnected financial crime risk rather than assessing individual businesses in isolation.


One case highlighted by the regulator involved a virtual asset service provider that allegedly became exposed to organised cryptocurrency investment scams. The business, operating under the name GetCoins, came under scrutiny following customer complaints, with the regulator seeking information about its ability to manage its money laundering risks. The case involved cooperation with Australia's National Anti-Scam Centre and ultimately resulted in cancellation of the provider's registration.


The case demonstrates an increasingly important aspect of financial crime supervision: regulators are looking not only at whether a business itself is deliberately facilitating criminal activity, but also at whether its systems are sufficiently robust to prevent criminals from exploiting its services.


This distinction is important for compliance officers.


A financial institution or virtual asset provider does not necessarily have to be knowingly involved in criminal activity to become exposed to significant AML risk. Weak customer due diligence, inadequate transaction monitoring, insufficient understanding of source of funds or ineffective escalation procedures can allow third parties to exploit the institution's infrastructure.


The resulting risk can include fraud, money laundering, scams, sanctions evasion and potentially terrorism financing.


The regulatory response therefore places greater emphasis on the ability of businesses to demonstrate that their controls operate effectively in practice.


For remittance businesses, this includes maintaining an accurate understanding of customers and beneficiaries, identifying unusual transaction patterns, assessing geographic exposure and monitoring the use of agents and intermediaries.


A business sending significant volumes of funds internationally should be able to explain why those transactions are taking place, who the parties are, where the money originates and where it ultimately goes. Transactions involving high-risk jurisdictions or unusual payment structures may require enhanced scrutiny.


The same principle applies to virtual asset providers, although the monitoring environment can be more complex.


Crypto businesses may need to assess blockchain addresses, wallet activity, counterparties and transaction patterns in addition to conventional customer information. A customer may be properly identified while the external wallet receiving their assets remains associated with fraud, sanctions exposure or other criminal activity.


Consequently, effective AML controls increasingly require businesses to connect customer-level information with transaction-level intelligence.


The regulator's actions also carry an important message concerning corporate governance.


Where a business is inactive, insolvent, incorrectly registered or unable to demonstrate operational capacity, the problem may not be limited to its AML program. It can indicate weaknesses in the wider governance framework, including management oversight, regulatory reporting, ownership records and compliance accountability.


Businesses operating in regulated financial sectors should therefore ensure that changes in directors, shareholders, beneficial owners, business activities, operating models and service providers are properly documented and reported where required.


Failure to maintain accurate regulatory information can itself become a significant compliance problem.


The latest actions also form part of a broader expansion of regulatory scrutiny across Australia's payment and financial services sectors. The regulator has recently taken action in relation to other payment and virtual asset businesses, including an investigation into Western Union and action concerning a cryptocurrency ATM network.


The increased attention is consistent with Australia's wider assessment of money laundering threats. The country's 2026 money laundering update identified a continuing evolution of established laundering channels, with traditional risks increasingly being exploited through more complex, interconnected and transnational methods. Technological developments and changes in the regulatory environment are also contributing to the changing risk landscape.


This means businesses cannot necessarily rely on historical risk assessments.


A payment company whose principal risk assessment was conducted several years ago may now face substantially different threats. The growth of instant payments, cryptocurrency, online scams, digital identity fraud and cross-border payment platforms has changed the ways in which criminal proceeds can move through the financial system.


AML programs therefore need to evolve alongside the risks they are intended to address.


For compliance departments, the AUSTRAC action provides several practical lessons.


First, regulatory registration should be treated as an ongoing obligation rather than a one-off approval. Businesses need processes to ensure that their registration information remains accurate and that changes to ownership, management, activities and operations are properly identified and reported.


Second, businesses need to demonstrate genuine operational capability. Having an AML policy on paper is not sufficient if the organisation lacks appropriately trained personnel, effective transaction monitoring, reliable customer due diligence procedures or sufficient resources to investigate alerts and suspicious activity.


Third, virtual asset and payment businesses need to pay particular attention to transaction monitoring. Rapid transfers, unusual geographic corridors, high-risk counterparties, unexplained transaction volumes and exposure to known scam infrastructure should be considered within a broader risk-based framework.


Fourth, businesses should establish clear escalation procedures. Where a transaction or customer relationship presents a potentially serious financial crime concern, the compliance function should have the authority and resources to investigate, restrict activity where appropriate and determine whether regulatory reporting is required.


Finally, senior management and directors need to understand that AML compliance is a governance responsibility rather than solely a compliance department issue.


The regulator's latest message is particularly clear on this point. Businesses that cannot adequately understand and manage their financial crime risks may ultimately lose the ability to operate.


Cyprus Company Formation

That represents an important shift in regulatory expectations. Supervisors are increasingly prepared to use registration powers not merely to punish businesses after serious misconduct has been established, but to remove businesses from the regulated ecosystem where they lack the capacity or willingness to meet the required standards.


The approach is also significant for banks and other financial institutions that maintain relationships with remittance and virtual asset businesses.


A bank assessing a payment-sector customer can no longer necessarily treat regulatory registration as sufficient evidence of a low-risk relationship. Institutions may need to assess whether the customer remains appropriately registered, whether its ownership and activities remain consistent with the information provided, whether it has experienced regulatory action and whether its transaction profile corresponds with its stated business model.


Correspondent and banking relationships can themselves become an important source of financial crime exposure. Weaknesses at a remittance or virtual asset provider can potentially transmit risk into other parts of the financial system.


This makes ongoing due diligence particularly important.


The wider regulatory direction suggests that Australia's financial crime framework is moving toward more active supervision of high-risk payment channels. The objective is not simply to identify suspicious transactions after they occur, but to ensure that businesses providing financial services are structurally capable of preventing their infrastructure from being misused.


For the remittance and virtual asset industries, the implications are substantial.


Businesses entering or operating in these sectors should expect greater scrutiny of ownership structures, management capability, AML/CTF programs, customer due diligence, transaction monitoring, suspicious matter reporting, regulatory notifications and ongoing operational activity.


Dormant entities, outdated registrations and nominal compliance arrangements are increasingly difficult to reconcile with this regulatory environment.


The removal of 45 businesses therefore represents more than a numerical enforcement statistic. It signals a broader regulatory philosophy in which access to the financial system is increasingly dependent on demonstrating that a business can actively manage the risks created by its services.


As cross-border payments and digital assets continue to expand, regulators are likely to maintain pressure on the businesses positioned at the points through which money moves internationally. For firms operating in these sectors, the message is straightforward: registration provides permission to operate, but continued access to the regulated financial system depends on maintaining effective controls, accurate regulatory information and demonstrable capacity to manage money laundering and terrorism financing risks.

By fLEXI tEAM

Comments


bottom of page