Join our Newsletter — 33% off our NHI Course

Australian Financial Services Licence (AFSL)

A licence required for certain activities involving financial products and services in Australia. For crypto businesses, the key question is whether the asset or service meets the legal definition of a financial product. If it does, the operator may need licensing, disclosure, conduct controls, and broader compliance obligations.

Expanded Definition

An Australian Financial Services Licence, or AFSL, is the authorisation that permits a person or business to carry on specified financial services in Australia. In practice, the relevance for crypto, payments, and digital asset businesses depends on whether the product or activity falls within the statutory definition of a financial product or financial service, rather than on the technology used to deliver it.

That distinction matters because AFSL obligations are not just about holding a licence. They can also shape how a firm must manage disclosure, conflicted remuneration, recordkeeping, governance, supervision, and dispute handling. For identity and access teams, the operational impact often shows up in approval workflows, segregation of duties, auditability, and the control evidence needed to demonstrate that regulated activities are being performed by authorised personnel. The most common misapplication is treating AFSL as a generic business registration, which occurs when firms assume any crypto service is outside financial services law until a regulator challenge reveals otherwise.

Examples and Use Cases

Implementing AFSL-related obligations rigorously often introduces product classification and control overhead, requiring organisations to weigh faster go-to-market decisions against the cost of stronger compliance review.

  • A crypto exchange assesses whether a tokenised product is a financial product before launching custody or dealing services.
  • A fintech documents who can approve statements, promotions, and advice-related content so that licensed activities are tightly supervised.
  • An operations team builds evidence trails for complaints handling, training completion, and incident escalation to support regulatory reviews.
  • A payments provider maps its access controls and logging to control expectations similar to those described in NIST SP 800-53 Rev 5 Security and Privacy Controls when demonstrating governance over regulated workflows.
  • A firm offering digital onboarding checks whether identity verification steps meet the assurance needed for the service model, with practices often benchmarked against NIST SP 800-63 Digital Identity Guidelines when internal controls depend on reliable identity proofing.

Why It Matters for Security Teams

For security and governance teams, AFSL is important because regulatory scope affects system design, access control, monitoring, and evidence retention. If a business is operating within AFSL-regulated activity, then identity governance, privileged access review, transaction approval chains, and audit logs become part of the compliance posture, not just technical hygiene. That is especially relevant where staff, contractors, and automated workflows can trigger customer-facing actions or approve disclosures.

AFSL also intersects with digital identity and non-human identity controls when onboarding, approvals, and customer communications are mediated by applications, service accounts, or AI-assisted workflows. In those environments, weak identity assurance or poorly governed machine access can create both security exposure and licensing risk. The practical challenge is that legal classification often precedes technical remediation: once a service is determined to fall inside the AFSL perimeter, teams may need to retrofit access reviews, change approval paths, and formalise evidence capture. Organisations typically encounter licensing gaps, control weaknesses, and remediation deadlines only after a product review or regulator inquiry, at which point AFSL becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV-01 Governance oversight supports regulated service classification and accountability.
NIST SP 800-53 Rev 5 AC-2 Account management underpins controlled access to regulated financial service workflows.
NIST SP 800-63 IAL2 Identity proofing assurance is relevant where customer onboarding supports regulated services.
OWASP Non-Human Identity Top 10 NHI governance is relevant when service accounts execute regulated workflows.
NIST AI RMF GOVERN AI governance applies if automated systems influence regulated communications or approvals.

Require appropriate identity proofing before allowing onboarding into regulated channels.