Beyond ASIC's No-Action Period: What Digital Asset Firms in Australia Need to Know
TRM User Conference
Which mission will you select?
Digital asset regulation in Australia has been changing quickly this year, and on more than one front.
Since March 31, 2026, the Australian Transaction Reports and Analysis Center (AUSTRAC) has regulated a wider range of virtual asset services under reforms to the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. These anti-money laundering obligations now apply whether or not a business also needs an Australian Financial Services License (AFSL). The transitional relief periods for different requirements vary from 2026 to 2029.
Under the Corporations Act 2001, businesses that deal in or hold digital assets that are financial products need an AFSL. The Australian Securities and Investments Commission (ASIC) clarified Information Sheet 225 (INFO 225) in December 2025 to explain how this law applies to digital assets. Along with the clarification, ASIC set out a no-action position until September 30, 2026, which gave unlicensed firms time to apply for a license before they lose the benefit of ASIC's stated forbearance. This no-action period has now ended.
From April 9, 2027, the Corporations Amendment (Digital Assets Framework) Act 2026 will require digital asset platforms (DAP) and tokenized custody platforms (TCP) to hold an AFSL, even if the tokens they hold are not financial products.
The current state of play
Australia's crypto framework is changing along three separate tracks, each with its own timetable. Firms can easily end up compliant on one track and exposed on another.
Track 1: The licensing obligation that already applies
Information Sheet 225 (INFO 225) is ASIC's guidance on how existing financial services law applies to digital assets. First published in 2017 in response to initial coin offerings, it was updated following ASIC's Consultation Paper 381 (CP 381), released in December 2024.
The guidance clarifies that many digital asset offerings, including certain stablecoins, wrapped tokens, tokenized securities, staking arrangements, and digital asset wallets, can carry rights that make them financial products under the Corporations Act 2001. Businesses that deal in, advise on, make a market in, or provide custody of these products, generally need an Australian Financial Services License (AFSL). This includes offshore businesses that promote or provide these services to people in Australia. Platforms may also need a market or clearing and settlement facility license. Some relief applies, such as ASIC's class relief for distributors of eligible stablecoins and wrapped tokens.
Source: ASIC's worked examples (INFO 225)
The guidance is directed at existing financial services and markets businesses (including those tokenizing real-world assets), digital asset businesses, brokers and intermediaries, and their professional advisers.
To support an orderly transition, ASIC adopted a no-action position: it would not take action for unlicensed conduct where a firm lodged an AFSL application or variation by the deadline. Originally set for June 30, 2026, the deadline was extended to September 30, 2026 to accommodate industry transition challenges.
From October 1, 2026, firms operating in-scope digital asset services without having met the no-action position's conditions are exposed to enforcement action for unlicensed conduct. ASIC's guidance describes the consequences as civil and criminal penalties, including fines that can reach 10% of annual turnover.
As of September 2, 2026, ASIC has recorded over 45 license applications from businesses seeking relevant authorizations to provide financial services relating to digital assets.
Track 2: The Digital Assets Framework Act
The Corporations Amendment (Digital Assets Framework) Act 2026 integrates digital asset platforms into Australia's existing financial services regime for the first time, bringing cryptocurrency exchanges, custodians, and certain token platforms within the AFSL framework.
The Act introduces two new categories of regulated financial product:
- Digital Asset Platforms (DAPs): A DAP is a facility under which the operator holds digital tokens on behalf of clients and records clients' interests in an account. This captures most cryptocurrency exchanges, brokers, custodians, and other intermediaries that hold crypto assets for clients.
- Tokenized Custody Platforms (TCPs): A TCP is a facility under which the operator holds real-world assets, such as commodities, securities or other property, and issues a digital token representing the client's right to redeem or take delivery of the underlying asset. This captures tokenized securities, tokenized gold, and similar products.
Under the Act, platform operators will be required to:
- Hold an AFSL authorizing financial services relating to the DAP or TCP
- Maintain platform rules covering eligibility; client obligations; settlement; fees; asset availability; and how assets are deposited, redeemed, and delivered
- Deliver a formal DAP/TCP Guide to retail consumers prior to onboarding or platform issuance
- Comply with statutory market misconduct prohibitions
- Remain subject to ASIC's proactive product intervention powers
The Act also includes specific regulatory carve-outs, including a de minimis exemption for low-volume, small-scale platforms, alongside targeted exclusions for public digital token infrastructure and distinct custodial staking arrangements.
While the Act sets the architecture, ASIC will set the detailed, binding standards by legislative instrument. To prepare for this, ASIC has rolled out a phased 18-month implementation roadmap. It starts with stakeholder roundtables and consultation on standards and guidance, and ends with license applications and full supervision. ASIC will consult on:
- Asset-holding standards (section 912BE): Rules on how licensees safeguard, record, and use client assets, including holding client money in trust
- Transactional and settlement standards (section 912BF): Baselines for trade execution, settlement, and market-making activity
- Financial requirements: Modelled on RG 166, including minimum capital adequacy metrics, liquidity thresholds, net tangible assets (NTA) floors, and audit obligations for digital asset platform (DAP) and tokenized custody platform (TCP) licensees
As part of its consultation, ASIC is also seeking views on how it will apply its discretions, standard license conditions, a streamlined variation process for recently licensed firms, and whether additional navigation aids are needed.
Track 3: The reformed AML/CTF regime
The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 took effect on March 31, 2026. It significantly expands how Australia's AML/CTF regime applies to virtual assets. Virtual asset exchanges were first regulated in 2018; until these reforms, only exchanges between digital currency and fiat currency were covered.
The reforms replace "digital currency" with "virtual asset" and "digital currency exchange provider" with "virtual asset service provider" (VASP). The new definition is deliberately broad. It covers digital representations of value that function as a medium of exchange, store of economic value, unit of account, or investment. Central bank digital currencies, in-game currencies, and loyalty points are excluded.
The virtual asset services that now trigger AML/CTF obligations are (AUSTRAC):
- Exchanging virtual assets for money (item 50A): In Australian dollars or foreign currency; this service was already regulated before the reforms
- Exchanging one virtual asset for another (item 50B): Whether of the same type or a different type, including facilitating peer-to-peer trades on a platform
- Safekeeping (item 46A): Holding or administering virtual assets, or the private keys that control them, for or on behalf of customers, including under multi-signature arrangements
- Transfers (items 29–30): Transferring virtual assets on behalf of customers; these services also carry Travel Rule obligations
- Issuance and sale services (item 50C): Providing financial services connected with the issuance or sale of a virtual asset where the business actively participates, for example through underwriting, market-making or placement
The revised regime took effect on March 31, 2026. Rather than one transition window, AUSTRAC's transitional rules defer specific obligations to different dates.
It should be noted that AML/CTF obligations AML/CTF obligations apply where a service has a "geographical link to Australia," for example where it is provided through a permanent establishment in Australia, or by an Australian resident or a subsidiary of an Australian company operating overseas. Where a business cannot yet meet an obligation, AUSTRAC expects a documented implementation plan. The plan should identify the gaps and explain how risk is being managed in the meantime.
What compliance teams should focus on now
- Map your products to the new categories. Test each arrangement against the DAP definition in s.761GC and the TCP definition in s.761GD. Then check the exclusions, low-value platform exemption, and public digital token infrastructure. (Act)
- Map your operations against the standards ASIC is consulting on.
- Take part in consultation. The roadmap includes stakeholder roundtables, an industry advisory group, and consultation on guidance and standards. (ASIC roadmap)
- Show how financial crime controls fit your risk framework. ASIC expects licensees to have risk management systems that identify and evaluate the risks their business faces, focusing on risks that adversely affect consumers or market integrity, and to maintain controls to manage them (RG 104). Firms applying for an AFSL should be able to show how their financial crime controls fit within their wider risk management framework. For digital asset activity, tools like TRM Transaction Monitoring can help put this into practice, flagging risky on-chain exposure in real time and giving teams an auditable record that links their controls back to the risks they've assessed.
- Make Travel Rule compliance work in practice. Put in place counterparty VASP identification, secure information exchange, and self-hosted wallet verification, and start building for the 2029 reporting requirement.
What lies ahead
With the end of ASIC’s no-action relief, compliance teams must pivot from application drafting to active operational readiness. As ASIC reviews the initial wave of applications and begins building out its 18-month policy roadmap, the baseline for compliance remains a moving target.
The businesses that thrive will be those that actively participate in the upcoming consultation rounds and design flexible architectures capable of adapting to the final asset-holding and financial requirements before they legally bite.
{{horizontal-line}}
Assessing digital asset risk across Australia’s evolving regulations? See how TRM helps compliance teams monitor exposure.




















