AUSTRAC Cancels 45 Crypto and Remittance Registrations in Yearlong Sweep
Australia's financial intelligence regulator has taken action against 45 crypto and remittance providers in a single enforcement sweep, canceling, suspending or refusing to renew registrations across the sector. For accounting firms, auditors and CFOs with Australian digital asset clients, this is a direct signal: operating without a valid AUSTRAC registration is no longer a theoretical risk, it is an active enforcement priority with real consequences for business continuity and client onboarding.
What AUSTRAC Did and Why It Matters
The Australian Transaction Reports and Analysis Centre (AUSTRAC) confirmed on 8 September 2026 that over the preceding twelve months it had canceled, suspended or refused to renew 45 registrations covering both virtual asset service providers (VASPs) and remittance businesses. AUSTRAC CEO Brendan Thomas was unambiguous: any business whose registration has been canceled is no longer lawfully permitted to operate.
Grounds for the Actions
AUSTRAC identified several distinct categories of non-compliance driving the decisions:
- Inactivity: providers that had effectively ceased trading but retained their registration on the public register.
- Insolvency: businesses no longer financially capable of meeting their obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006.
- Capacity failures: providers that lacked the governance, systems or personnel to operate a compliant AML/CTF program.
- Failure to report material changes: entities that did not notify AUSTRAC of significant changes to ownership, control or business model as required.
- Incorrect registrations: businesses registered under the wrong category or whose actual activity did not match their registered description.
- High-risk profiles: cases presenting what AUSTRAC assessed as significant money laundering or terrorism financing risks.
Thomas also noted that individuals connected to some of the affected businesses have been referred to Australian and overseas law enforcement and regulatory partners, signaling that for the most serious cases the consequences extend well beyond deregistration.
The GetCoins Case
The most detailed example AUSTRAC provided centres on BA Digital Ventures, which traded as GetCoins. Its virtual asset registration was canceled in June 2026 following customer complaints. AUSTRAC said GetCoins was allegedly exploited by organised cryptocurrency investment scams, and that the cancellation was carried out in coordination with the National Anti-Scam Centre with the aim of disrupting that activity. This makes the GetCoins action notable beyond a routine compliance failure: it sits at the intersection of VASP registration enforcement and consumer fraud disruption, with a multi-agency dimension.
Other businesses named on AUSTRAC's public VASP register as subject to recent actions include Cryptolink, Self Custody, Jam Xchange and Coinsec Australia. AUSTRAC has not published a full list of all 45 entities or provided a numerical breakdown between crypto and remittance providers.
Regulatory Context: Australia's AML/CTF Reform Trajectory
This enforcement sweep does not sit in isolation. Australia completed a significant expansion of its AML/CTF framework in late 2024 and early 2025, extending designated service obligations to a broader range of professional service providers and tightening the registration and reporting requirements that apply to VASPs. The 45 actions announced this week reflect AUSTRAC applying heightened scrutiny that was always promised to follow those legislative changes.
Registration Is Not a Formality
A recurring theme in AUSTRAC's stated grounds is that registration was being treated as a one-time administrative step rather than an ongoing compliance status. Failures to report material changes, incorrect registrations and incapacity to operate a compliant AML/CTF program all point to entities that registered and then stopped engaging with their obligations. AUSTRAC's message is clear: the register is a live instrument, and it will be actively managed.
For accounting and audit professionals advising Australian digital asset businesses, this has practical consequences. Any engagement letter that includes a VASP or remittance provider as a client should now include a standing check on AUSTRAC registration status. A canceled registration is an immediate going-concern indicator. It also has cascading effects: banking relationships, payment processing, and exchange partnerships typically require valid registration as a contractual condition.
Accounting and Audit Implications for Firms and CFOs
The enforcement sweep creates several distinct action points for accounting professionals working in or adjacent to the Australian digital asset sector.
Going-Concern Assessment
Under AASB 101 (Presentation of Financial Statements), auditors must assess whether an entity can continue as a going concern. A canceled AUSTRAC registration removes the legal basis for the core revenue-generating activity of any VASP or remittance provider. Auditors engaged with such entities must now factor registration status into their going-concern procedures as a matter of routine, not exception. Where a registration has been canceled mid-period, the financial statements will need to reflect that the business cannot legally continue in its current form, and disclosures must be explicit.
Client Onboarding and AML Obligations for Accounting Firms
Accounting firms that are themselves registered reporting entities under the AML/CTF Act face their own obligations when taking on digital asset clients. Onboarding a VASP or remittance provider that lacks a valid AUSTRAC registration creates a significant risk exposure. Firms should build AUSTRAC register verification into their client due diligence workflows and re-verify at each engagement renewal. The public VASP register is accessible and regularly updated.
Revenue Recognition and Contract Continuity
Where a firm is engaged to prepare or audit financial statements for a period that includes a registration cancellation event, revenue recognition becomes complex. AASB 15 requires that performance obligations be assessed against contracts with customers. If the entity's ability to fulfil those contracts is impaired by the cancellation, or if customers have cancellation rights triggered by the loss of regulatory status, that affects how and whether revenue is recognised. This is not a remote scenario: the GetCoins case involved customer complaints, which suggests customer contract disputes are likely to follow.
Provisions and Contingent Liabilities
AUSTRAC enforcement can carry civil penalty exposure. Where individuals connected to canceled registrations have been referred to law enforcement, there is potential for criminal proceedings as well. Entities in this position, and their auditors, need to assess whether provisions or contingent liability disclosures are required under AASB 137.
What Crypto Businesses Operating in Australia Should Do Now
The 45 actions cover both existing cancellations and refusals to renew, meaning some businesses may have allowed their registrations to lapse without realising the enforcement risk that creates. Any Australian business providing digital currency exchange, custody, or remittance services should treat the following as immediate priorities.
Verify and Maintain Registration Status
Check the AUSTRAC public register to confirm that your registration is current, correctly categorised and reflects your actual business activity. If there has been any change to ownership, control structure, key personnel, or the nature of the services offered, and that change has not been reported to AUSTRAC, that is a material change notification failure of exactly the type AUSTRAC cited in this sweep.
Review Your AML/CTF Program
AUSTRAC's reference to "capacity failures" indicates that some entities had programs that existed on paper but were not operationally functional. A program that cannot be evidenced through transaction monitoring outputs, staff training records, and a current risk assessment is unlikely to satisfy an AUSTRAC review. The AML/CTF program requirements under the Act require both Part A (governing) and Part B (customer due diligence) components to be maintained and applied.
Assess Third-Party and Correspondent Relationships
If your business relies on other VASPs or remittance providers, confirm their registration status as part of your third-party due diligence. Transacting with a deregistered entity creates its own AML/CTF risk exposure, and AUSTRAC's focus on organised scam activity (as illustrated by the GetCoins case) means that correspondent relationships with non-compliant entities could attract scrutiny.
The Broader AML Enforcement Signal
Australia's approach echoes a global pattern of regulators moving from registration-as-entry-point to registration-as-ongoing-obligation. The referral of individuals to law enforcement, including overseas partners, also reflects the increasingly cross-border nature of crypto enforcement. Firms and CFOs advising clients in this space should be aware that AUSTRAC coordinates with counterparts in other jurisdictions, and that enforcement consequences can extend beyond Australia.
This is consistent with what we have seen from other regulators. The FinCEN analysis linking billions in crypto scam proceeds to overseas criminal networks highlighted the same dynamic: domestic enforcement gaps enable internationally organised fraud. Australia's cancellation of GetCoins as part of a coordinated anti-scam effort is a practical example of how that plays out at the VASP registration level. For further context on AML enforcement trends affecting crypto businesses, see our analysis of FinCEN's $13 billion crypto scam centre findings.
Accounting firms that have invested in crypto accounting software capable of tracking regulatory status changes across client portfolios will have a material advantage here. Registration cancellations can happen at any point in a financial year, and the accounting implications, going concern, revenue recognition, provisions, are time-sensitive. Manual monitoring of the AUSTRAC register across a client base of any scale is impractical. Firms should ensure their practice management and digital asset accounting software workflows flag regulatory status changes automatically. For Australian-focused licensing obligations and what the ASIC licensing deadlines mean for turnover-based penalties, see our earlier piece on ASIC's crypto licensing deadline and 10% turnover fines.
Frequently Asked Questions
Can a business continue operating after AUSTRAC cancels its registration?
No. AUSTRAC CEO Brendan Thomas stated explicitly that businesses whose registrations have been canceled are no longer permitted to operate. Continuing to provide designated services without a valid registration is a breach of the AML/CTF Act and creates both civil and potentially criminal liability.
What does a canceled AUSTRAC registration mean for an audit engagement?
It is a significant going-concern indicator. Under AASB 101, auditors must assess whether the entity can continue as a going concern. A canceled registration removes the lawful basis for the entity's core business activity, which typically means the going-concern assumption cannot be applied without substantial doubt disclosures or a modified opinion.
Does AUSTRAC publish the full list of deregistered entities?
AUSTRAC has not published the names of all 45 entities affected by this sweep. It maintains a public VASP register that reflects recent actions, and the entities named in relation to this sweep include GetCoins, Cryptolink, Self Custody, Jam Xchange and Coinsec Australia. Firms should check the register directly for current status information.
What triggers a "material change" notification requirement to AUSTRAC?
Under the AML/CTF Act, registered entities must notify AUSTRAC of significant changes to their business, including changes in ownership or control, key personnel, the nature of services provided, and other matters specified in the Act. AUSTRAC identified failure to report material changes as one of the grounds for registration actions in this sweep.
How should accounting firms handle a crypto client that has had its AUSTRAC registration canceled?
Immediately: verify the cancellation via the public register, reassess the going-concern status of the entity, review revenue recognition for the current period, consider whether provisions or contingent liability disclosures are required, and assess whether continuing to act for the client creates any risk under the firm's own AML/CTF obligations. Legal advice on the specific circumstances is advisable where enforcement referrals are involved.
Source: Cointelegraph
