As Australia prepares to introduce a comprehensive licensing framework for crypto asset service providers, questions remain about which regulator will take the lead. The two primary candidates are AUSTRAC, the anti-money laundering and counter-terrorism financing authority, and ASIC, the corporate and financial markets regulator. Each plays a different role under current laws, but the future may see a shift or redistribution of responsibilities. This article outlines the current division of powers and explores who might regulate crypto in Australia’s evolving legal landscape.
Current Roles: AUSTRAC and ASIC Explained
AUSTRAC (Australian Transaction Reports and Analysis Centre)
- Responsible for enforcing Australia’s Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act).
- Regulates Digital Currency Exchanges (DCEs) that convert fiat to crypto (and vice versa).
- Requires registration, customer due diligence, transaction monitoring, and reporting of suspicious activity.
- Does not license businesses or assess the financial soundness of crypto firms.
ASIC (Australian Securities and Investments Commission)
- Regulates companies, financial products, financial services, and markets.
- Enforces the Corporations Act 2001 and the Australian Securities and Investments Commission Act 2001.
- Oversees crypto assets that are classified as financial products (e.g. tokenised securities, derivatives).
- Licenses financial services businesses under the Australian Financial Services Licence (AFSL) regime.
Why the Distinction Matters
The main distinction is that AUSTRAC focuses on financial crime prevention, while ASIC is responsible for investor protection, corporate governance, and market integrity. As the crypto ecosystem becomes more complex, many crypto businesses fall into both categories—handling financial assets and operating in ways that attract AML/CTF risks.
This overlap has led to concerns about:
- Duplicative or inconsistent regulation
- Regulatory gaps, especially in areas like custody or crypto-to-crypto trading
- Uncertainty for businesses seeking clarity on licensing and compliance obligations
AUSTRAC’s Position on Future Regulation
In its submission to Treasury’s consultation, AUSTRAC made the following recommendations:
- Replace the current DCE registration regime with a comprehensive licensing framework.
- Regulate all services outlined in the FATF’s VASP definition—not just fiat exchanges.
- Maintain AUSTRAC’s responsibility for AML/CTF compliance, but let another authority handle licensing.
- Emphasise a single, streamlined licensing system, with AUSTRAC supervising AML/CTF obligations and another agency managing broader financial regulation.
In short, AUSTRAC supports a model in which it handles AML supervision, but not the full licensing regime.
ASIC’s Role Likely to Expand
Given ASIC’s experience in licensing financial services, it is likely to play a central role in the future framework. ASIC could be responsible for:
- Issuing licenses to crypto asset service providers
- Enforcing conduct standards and consumer protections
- Supervising trading platforms, custody, and financial promotions
- Coordinating with AUSTRAC on AML/CTF compliance issues.
Some functions may also be shared with APRA or a new digital assets regulatory body if one is created.
What Crypto Businesses Should Expect
Under the proposed framework, crypto businesses in Australia may need to:
- Obtain a license from ASIC (or another authority), based on the nature of their services
- Continue complying with AUSTRAC’s AML/CTF rules
- Meet fit and proper person requirements for owners and key personnel
- Implement risk-based systems for both financial crime and consumer protection.
This will create a more formalised environment, comparable to traditional financial institutions.
Conclusion: Cooperation Over Competition
Rather than a battle between AUSTRAC and ASIC, Australia’s crypto regulation is likely to evolve into a co-regulatory model, with each agency playing to its strengths. AUSTRAC will continue to focus on AML/CTF obligations, while ASIC or another financial regulator takes the lead on licensing and consumer protection.
For crypto businesses, the message is clear: dual compliance is the new baseline. Understanding both regulators’ expectations—and preparing systems accordingly—will be essential for sustainable operation in Australia’s regulated digital asset sector.