
DCE vs VASP: Key Differences Under Australia’s Updated AML/CTF Regime
Australia’s crypto regulatory framework is undergoing a significant structural transition.
Following the passage of the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (AML/CTF Amendment Act 2024) in November 2024, the existing regime centred on the Digital Currency Exchange (DCE) registration framework is set to be reconfigured into a broader Virtual Asset Service Provider (VASP) regulatory model.
This is not merely a change in terminology or classification. It represents a substantial expansion of regulatory scope, compliance obligations, and enforcement boundaries.
Under the new framework, a wider range of crypto-related activities will fall within the scope of AML/CTF obligations. Compliance requirements are expected to become more rigorous and more closely aligned with the Financial Action Task Force (FATF) international standards. For market participants, compliance will no longer be a question of whether registration is required, but whether the organisation has the capability to meet ongoing regulatory obligations on a continuous basis.
It is important to note that while the overall direction of the reform is now clear, many key implementation details have yet to be released.
Based on the current regulatory timeline, supporting rules, technical standards and regulatory guidance are expected to be progressively issued by around late January 2026. This means that institutions must not only understand the regulatory direction, but also actively monitor how the detailed rules take shape over time.
Against this backdrop, CryptoLicense focuses on the aspects of the reform that will have the most direct operational impact on institutions. This article highlights the core compliance challenges VASPs are expected to face in areas such as registration, customer due diligence, transaction monitoring and the Travel Rule, with the aim of helping readers quickly assess:
- why this regulatory upgrade is taking place
- which changes are most relevant to their business
- and what preparations should begin now
I. Why Is Australia Upgrading Its Crypto Regulatory Framework?
This regulatory upgrade is not a simple rebranding exercise. It represents a substantive recalibration of Australia’s AML/CTF regime.
According to AUSTRAC’s public commentary, the existing framework contains clear regulatory gaps. As digital asset business models have diversified, the DCE-based registration regime has become increasingly insufficient to address emerging risks. Certain services characterised by anonymity, cross-border reach and rapid transaction flows can exploit regulatory blind spots under the current framework. These vulnerabilities have created opportunities for illicit actors to obscure fund flows, evade sanctions and conceal transaction origins. These are not theoretical risks, but real and recognised threats to the integrity of the financial system.
AUSTRAC has further acknowledged limitations in the current regime’s ability to collect intelligence, identify emerging risks and conduct effective supervisory oversight. These deficiencies weaken market confidence, increase systemic risk, and place Australia at a disadvantage in cross-border regulatory cooperation.
Against this backdrop, the objectives of the reform are clear and focused:
First, to close regulatory gaps.
Virtual asset services that were previously outside the regulatory perimeter will be brought within a unified VASP framework, ensuring that no materially risky activity remains unregulated.
Second, to align with international standards.
The new framework brings Australia’s regulatory approach into closer alignment with FATF standards, strengthening the country’s ability to detect and respond to cross-border money laundering and terrorism financing risks.
Third, to shift from reactive to proactive supervision.
By introducing more comprehensive compliance obligations and enhanced intelligence mechanisms, the regime aims to improve regulatory foresight—identifying risks earlier and intervening sooner, rather than addressing issues only after they materialise.
In short, this reform is not about replacing “DCE” with “VASP”. It is about upgrading the regulatory system from one that responds after the fact to one that is designed to manage risk proactively, enhancing the safety and sustainability of the financial system as a whole.
II. From DCE to VASP: Changes in Terminology and Regulatory Scope
Under Australia’s existing AML/CTF framework, regulatory focus has traditionally centred on Digital Currency Exchanges (DCEs). Businesses facilitating the buying and selling of cryptocurrencies were generally captured within the regime.
That approach is now being fundamentally rewritten.
With the passage of the AML/CTF Amendment Act 2024, regulation will no longer revolve around the single concept of an “exchange”. Instead, Australia is adopting the broader and internationally recognised concept of the Virtual Asset Service Provider (VASP).
This is not a cosmetic change. It reflects a clear shift in regulatory perspective: away from assessing whether an entity operates an exchange, and towards examining what services are being provided in relation to virtual assets.
Based on the draft legislation and AUSTRAC guidance, an entity may be classified as a VASP if it engages in any of the following activities, regardless of whether it operates a trading platform:
- exchange between virtual assets and fiat currencies
- exchange between one or more forms of virtual assets
- transfer of virtual assets on behalf of customers
- safekeeping or administration of virtual assets or instruments enabling control over virtual assets
- participation in, or provision of services related to, the issuance, sale or distribution of virtual assets (including token issuance-related services)
As a result, custodians, brokers, certain payment intermediaries, and even service providers supporting token issuance infrastructure may fall directly within the regulatory perimeter.
To support this expanded scope, the legislation also introduces a fundamental definitional change: the replacement of the narrower concept of “digital currency” with the broader term “virtual asset”.
Under the new definition, an asset may be classified as a virtual asset if it:
- exists in electronic form and is transferable, storable or tradable
- is not fiat currency
- and performs at least one of the following functions:
- acts as a medium of exchange or store of value
- serves as an investment or unit of account
- confers rights on the holder (such as governance or voting rights)
This significantly broadens the regulatory lens.
Bitcoin and Ethereum are clearly included, but stablecoins, utility tokens, governance tokens and potentially certain NFTs may also fall within scope if they possess tradable economic characteristics.
That said, the boundaries are not unlimited.
Central bank digital currencies (CBDCs), closed-loop gaming credits, customer loyalty points and similar instruments that lack independent market value are expressly excluded.
Overall, the transition from DCE to VASP reflects Australia’s intent to align its regulatory language, regulatory perimeter and risk assessment methodology with FATF global standards.
The objective is straightforward: to reduce ambiguity and eliminate regulatory blind spots that could otherwise be exploited by higher-risk activities.
III. DCE vs VASP: A Clear Comparison of the Key Differences
To start with the conclusion: this reform is not about renaming DCEs as VASPs.
It represents a fundamental shift in regulatory focus—from regulating exchange activity to regulating the entire virtual asset service value chain.
The table below highlights the key differences between the DCE and VASP frameworks at a glance.
Key Differences Between DCE and VASP
In practical terms, this comparison highlights several critical considerations.
1、The regulatory focus is no longer limited to “exchanges”
Under the DCE regime, many institutions assumed that as long as they were not directly involved in “currency exchange”, they fell outside the regulatory perimeter.
That assumption no longer holds.
Under the VASP framework, any entity involved in the transfer, custody, or issuance-related services of virtual assets may be brought within scope. In other words:
Custodians, brokers, infrastructure providers and service platforms must now assess their exposure based on the services they provide, not the labels they use.
2、The asset scope is broader—but not unlimited
The VASP framework adopts the FATF concept of “virtual assets”. The core test is straightforward:
Does the asset have tradable economic value, or does it represent a set of rights?
As a result:
- Stablecoins and governance tokens are generally within scope
- Pure in-game credits, loyalty points and fiat currencies are expressly excluded
This is not an attempt to regulate everything. Rather, the reform is designed to reclaim regulatory grey areas that previously fell outside the perimeter.
3、Compliance shifts from “formal requirements” to “accountability for outcomes”
Historically, many institutions approached compliance as a checklist exercise:
- Do we have policies?
- Have we conducted KYC?
- Have reports been submitted?
Under the VASP framework, regulators are asking different questions:
- Have risks been properly identified?
- Are controls effective on an ongoing basis?
- When issues arise, who is accountable?
This shift explains why:
- AML/CTF Programs must be formally approved by the board
- Senior management responsibilities are explicitly embedded in the regulatory design
Compliance is no longer confined to the compliance function. It is now a management-level responsibility.
4、Technology and operational processes become real barriers to entry
Requirements such as the Travel Rule, reporting obligations for unhosted wallets, sanctions screening, and more granular transaction reporting cannot be addressed through documentation alone.
Without adequate systems and operational processes in place:
In practice, technical readiness and workflow integration will increasingly determine whether a business can operate sustainably under the VASP regime.
IV. Entering the VASP Era: Compliance Requirements That Cannot Be Avoided
1. The Travel Rule
The Amendment Act formally extends the application of the Travel Rule to VASPs through newly introduced provisions.
In practical terms, where a virtual asset transfer is involved, service providers are required to meet three core obligations:
- collect, verify and transmit identifying information of both the originator and the beneficiary
- determine the nature of the counterparty wallet, including whether it is operated by a regulated VASP, an unregulated VASP, an illicit VASP, or a self-hosted (unhosted) wallet
- ensure the security and confidentiality of the information throughout the transmission process
Exemptions may only apply in limited circumstances where it is genuinely not possible to comply safely with these requirements or to adequately safeguard the information.
The Travel Rule obligations are scheduled to take effect from 31 March 2026, and will be implemented in parallel with AUSTRAC’s transition from the International Funds Transfer Instruction (IFTI) regime to the new International Value Transfer Report (IVTR) framework.
2. Reporting Obligations for Unverified Self-Hosted Wallets
The framework introduces heightened obligations for VASPs that facilitate transfers to unverified self-hosted wallets.
Regulators have consistently taken the view that such wallets present greater challenges in tracing money laundering and terrorism financing risks.
Accordingly, where a VASP assists in transferring value to an unverified self-hosted wallet, it will be required to submit a dedicated report to AUSTRAC within 10 business days, supported by enhanced customer due diligence measures.
AUSTRAC has indicated that more detailed operational guidance on these reporting requirements is expected to be released in the coming months.
3. Targeted Financial Sanctions
While targeted financial sanctions are not limited to VASPs, the revised draft AML/CTF Rules make it clear that:
all reporting entities must implement enforceable sanctions compliance frameworks, including asset-freezing mechanisms and related control measures.
Notably, the reforms also explicitly elevate proliferation financing risk as a regulatory priority. Institutions will be required to incorporate these risks into both their enterprise-wide risk assessments and ongoing monitoring arrangements.
4. Enhanced Requirements for Suspicious Matter Reports (SMRs) and Threshold Transaction Reports (TTRs)
The new rules introduce more granular information requirements for both SMRs and TTRs.
Where a transaction involves virtual assets, reports are expected to include, at a minimum:
- the type of virtual asset and any associated backing assets
- the quantity of units transferred
- the value expressed in Australian dollars
- the exchange rate used for valuation
- a unique transaction reference (such as a transaction hash)
- wallet addresses and any associated identifiers (for example, destination tags or memos)
AUSTRAC is concurrently developing updated online reporting forms to support these expanded data requirements.
5. Significantly Tightened VASP Registration Requirements
Under the latest draft AML/CTF Rules, VASP registration is no longer intended to be a procedural formality.
AUSTRAC is expected to maintain a publicly accessible VASP register, with key information disclosed. This marks a notable departure from the current DCE register, which is not publicly available.
The revised registration requirements place particular emphasis on:
- identifying and assessing money laundering, terrorism financing and proliferation financing risks relevant to the business, and establishing appropriate risk mitigation frameworks
- clearly articulating AML/CTF governance arrangements, including the competence, training and experience of key personnel
- providing more detailed business information, such as the types of virtual assets involved, methods of service delivery, and the intended use or custody arrangements for customer assets or virtual assets
V. The VASP Compliance Timeline: Key Milestones at a Glance
To assist in understanding how VASP compliance requirements will be rolled out, the following timeline summarises the key regulatory milestones based on AUSTRAC’s official disclosures.
From the formal release of legislative instruments, through the progressive issuance of guidance and industry education materials, to the phased commencement of AML/CTF obligations, the regulatory trajectory reflects a clear progression from high-level framework to operational execution.
These milestones will have a direct impact on how institutions plan and sequence their compliance preparation and implementation efforts, and warrant close attention.
VI. The Final Step: A VASP Compliance Self-Assessment Checklist
In light of this latest regulatory overhaul, institutions that are likely to fall within the VASP regulatory perimeter are no longer facing a simple question of whether they are compliant, but whether they have already begun preparing.
From a regulatory sequencing perspective, the window for institutions to absorb and adjust to the new requirements is relatively limited. The earlier a structured self-assessment is completed, the lower the cost and operational friction are likely to be during implementation.
CryptoLicense recommends that institutions conduct a systematic review of their compliance readiness by considering the following questions:
- Does the current business model involve any designated virtual asset services that will be brought into scope under the new regime?
- Has the institution already registered, or does it need to re-register, with AUSTRAC as a VASP?
- Is there a registration submission that adequately explains how money laundering, terrorism financing and proliferation financing risks are identified and managed?
- Has the AML/CTF risk assessment been updated to explicitly cover proliferation financing and targeted financial sanctions obligations?
- Have the AML/CTF Program and internal policies been upgraded accordingly, particularly in relation to counterparty wallet due diligence and Travel Rule requirements?
- Does the organisational structure meet the new regulatory expectations, including the appointment of a suitably qualified compliance officer?
- Are staff compliance training, ongoing review and record-keeping mechanisms in place and operating effectively?
- Are internal processes and data capabilities sufficient to support the enhanced SMR and TTR reporting requirements?
VASP Compliance in Practice: Insights and Support from CryptoLicense
This round of AML/CTF reform marks Australia’s virtual asset regulatory framework entering a phase defined by stronger enforcement capability and greater regulatory certainty. The expansion of regulatory scope, the refinement of compliance obligations, and the phased implementation timeline are collectively raising the bar for how VASPs assess and execute compliance.
As the regulatory framework continues to evolve, the critical task is not to wait for every implementation detail to be finalised, but to determine early whether a business falls within the regulatory perimeter, and to assess feasible compliance pathways and preparation timelines accordingly. For institutions facing registration, framework design and ongoing compliance obligations, early assessment often has a decisive impact on downstream costs and risk exposure.
CryptoLicense continues to monitor regulatory developments in Australia and other major jurisdictions, combining regulatory insight with practical implementation experience to support institutions in clarifying regulatory expectations, assessing compliance feasibility, and navigating key milestones.
For further discussion on VASP compliance strategy, implementation timelines or regulatory considerations, please contact CryptoLicense.