By NHI Mgmt Group Editorial TeamBased on SumSub: “Australia Launches Public VASP Register as Travel Rule to Take Effect” (June 30, 2026)

TL;DR: Australia has made its VASP register public and, from July 1, Travel Rule obligations apply to newly regulated virtual asset services, requiring sender and recipient information plus seven-year retention, according to SumSub. The shift makes registration status, transfer-chain data, and offboarding discipline central to virtual asset governance rather than back-office compliance.


At a glance

What this is: Australia has opened its public VASP register and aligned newly regulated virtual asset services with Travel Rule obligations that tighten visibility across transfers and retention.

Why it matters: For IAM, PAM, and compliance teams, the change turns registration status, data collection, and lifecycle offboarding into operating controls rather than background regulatory tasks.


Context

Australia's public VASP register is a governance control, not just a consumer lookup tool. Once registration status becomes visible, the compliance question shifts from whether a business exists to whether it is still authorised, still operating, and still aligned to the services it is offering.

The Travel Rule adds a second layer of identity governance around virtual asset transfers. Providers now have to verify payer information, collect recipient details, pass data through the transfer chain, and retain records for seven years, which makes transfer integrity and offboarding discipline part of day-to-day compliance.


Key questions

Q: What breaks when a virtual asset provider is no longer operating but still appears trusted in market workflows?

A: When registration state drifts from actual service delivery, counterparties can continue routing activity to a provider that should no longer be treated as active. That creates a governance gap where market trust, operational reality, and regulatory status no longer match. The result is weaker screening, slower intervention, and a higher chance of residual compliance exposure.

Q: When should organisations prioritise transfer-chain identity data over customer onboarding checks in crypto compliance?

A: They should prioritise transfer-chain identity data whenever the business moves value between platforms, wallets, or intermediaries. Onboarding checks alone do not preserve traceability once a transaction leaves the first service boundary. The transfer chain is where compliance evidence is most likely to fragment, so it deserves equal or greater control attention.

Q: What are the signs that Travel Rule controls are not working as intended?

A: Common warning signs include missing payer or recipient fields, inconsistent data between transfer participants, manual exceptions that are not tracked, and records that cannot be reconstructed later. If the organisation cannot show who sent value, who received it, and how the information moved, the control is functioning only partially.

Q: Who is accountable when a VASP registration lapses but the service continues to operate?

A: Accountability sits with the provider, but the governance failure usually spans compliance, operations, and risk ownership. If a business continues offering covered services after its registration status changes, that is a lifecycle control failure. The organisation needs a single owner for status reconciliation, because fragmented responsibility leaves gaps between licensing and delivery.


Technical breakdown

Public registration changes the trust model for VASPs

A public register changes the way counterparties establish trust. Instead of relying on a closed supervisory relationship, users and businesses can check whether a provider is registered before transacting, while AUSTRAC can suspend, cancel, or refuse renewal when financial crime risk becomes unacceptable. That turns registration into an ongoing governance state, not a one-time approval. It also means a provider that is no longer offering virtual asset services must be removed from circulation rather than left visible as though it were active.

Practical implication: treat registration status as a lifecycle control that needs continuous monitoring, not a static onboarding check.

How the Travel Rule pushes identity data through the transfer chain

The Travel Rule requires providers involved in a transfer to collect and verify payer information, collect key recipient details, and pass required information through the transfer chain. In practice, that means the compliance burden sits across the full transaction path, not only at the customer edge. It also creates a dependency on data consistency between originator, intermediary, and beneficiary systems, because missing or mismatched identity data can break the transfer record and the audit trail.

Practical implication: map where payer and recipient data is created, validated, and transmitted so transfer records remain complete end to end.

Seven-year retention makes evidence management part of the control

Retention for seven years means compliance is only as strong as the evidence that can still be produced later. That matters because virtual asset activity often spans multiple systems, wallets, platforms, and service relationships over time. If the record set is incomplete, the organisation may have performed the check operationally but still be unable to demonstrate it. Retention therefore functions as both an investigation enabler and a governance test for whether the transfer process was actually controlled.

Practical implication: design retention and retrieval so registration, transfer, and customer records are reconstructable for the full regulatory window.


NHI Mgmt Group analysis

Public registration turns provider status into an identity control, not a directory listing. The moment a VASP register becomes public, the trust decision moves outward to consumers, counterparties, and supervisors. That makes registration status part of the assurance model for virtual asset services, and it exposes a common governance weakness: organisations often treat licence state as administrative metadata rather than an active control. The practitioner takeaway is that visibility changes accountability.

The Travel Rule is fundamentally a transfer-chain governance problem. The rule does not just ask whether a provider knows its customer, it asks whether the provider can preserve identity context across every hop in a virtual asset transfer. That makes the quality of payer and recipient data central to compliance, especially where different platforms or wallets sit between origin and destination. The practitioner takeaway is to govern the transfer chain as one control surface, not a series of isolated checks.

Seven-year retention makes evidence durability part of the control design. Retention periods only matter if the organisation can still retrieve usable records years later, after systems, vendors, and service relationships have changed. In virtual asset programmes, that shifts the focus from collecting compliance data to preserving evidential continuity across the lifecycle. The practitioner takeaway is that retention is not storage, it is proof availability.

Offboarding is now a compliance event, not a back-office afterthought. AUSTRAC's ability to cancel registrations for businesses that are no longer providing virtual asset services shows that inactive providers cannot simply linger in a semi-governed state. This is where lifecycle governance matters most: once service delivery stops, registration and transfer obligations need to be reconciled with the operational reality. The practitioner takeaway is to align registry status with actual service cessation.

Crypto compliance is converging with broader identity governance discipline. The same programme patterns that govern accounts, privileges, and lifecycle states in IAM now apply to virtual asset providers and transfer participants. That convergence matters because financial crime controls fail when identity state, transaction state, and service state drift apart. The practitioner takeaway is to build one governance view that covers registration, transfers, and offboarding together.

What this signals

Public register visibility changes the governance model: once counterparties can check provider status directly, stale registration data becomes an operational risk rather than a filing issue. Teams should expect greater scrutiny of whether market-facing status matches the services actually being delivered.

The more the Travel Rule depends on end-to-end transfer data, the less tolerance there is for disconnected compliance ownership. IAM-style lifecycle thinking now applies to virtual asset providers, because the control fails when registration, transfer evidence, and offboarding are managed as separate problems.


For practitioners

  • Map registration status to operating reality Create a control that reconciles public register status with actual services offered, so inactive or suspended providers are removed from your trusted counterparties list.
  • Validate payer and recipient data capture Check that the information collected for virtual asset transfers is complete, verified, and passed through every intermediary that touches the transaction.
  • Test seven-year record retrieval Prove that registration, transfer, and customer records can still be reconstructed after long retention periods and platform changes.
  • Align offboarding with service cessation When a virtual asset service stops operating, ensure registration, counterparties, and transfer controls are updated together rather than left to separate teams.

Key takeaways

  • Australia's public VASP register makes provider status part of the trust decision for consumers, businesses, and supervisors.
  • Travel Rule compliance now depends on complete payer, recipient, and transfer-chain data, plus records that remain usable for seven years.
  • The practical control issue is lifecycle alignment: registration status, service delivery, and offboarding all have to move together.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organisational ContextThe article is about regulatory operating context for virtual asset services.
PR.DS-01 — Data-at-Rest is ProtectedSeven-year retention makes long-term record protection and retrieval central to compliance.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsTransfer-chain controls depend on who can originate, verify, and pass identity data.
Recommendation — Map VASP obligations into governance context and keep registration state aligned with operating reality. Protect retained transfer records so evidence remains available throughout the full retention period. Limit who can alter transfer identity data and verify authorisation at each handoff.
CIS Controls v8CIS-5 — Account ManagementRegistration changes and service cessation require disciplined lifecycle management of provider accounts.
Recommendation — Reconcile account and service lifecycles so inactive virtual asset providers are removed cleanly.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article explicitly discusses canceling registrations when services stop operating.
Recommendation — Offboard virtual asset providers promptly when they stop delivering covered services.

Key terms

  • Virtual Asset Service Provider (VASP) Register: A VASP register is the authoritative list of businesses authorised to provide covered virtual asset services. In practice, it becomes a market trust signal as much as a compliance record, because counterparties and users rely on it to judge whether a provider is currently legitimate and active.
  • Travel Rule: A Travel Rule is a regulated requirement for financial platforms to exchange originator and beneficiary information during qualifying transfers. In crypto, it turns transfer handling into an identity and compliance workflow, where the platform must know which counterparties can receive data and how that exchange is recorded.
  • Transfer Chain: The transfer chain is the sequence of providers, wallets, and intermediaries that handle a virtual asset movement from sender to recipient. Governance fails when identity data breaks at any handoff, because the compliance record then becomes incomplete even if the initial collection step was performed correctly.
  • Off-boarding: Off-boarding is the process of removing a departing user’s access, credentials, and related entitlements from the environment. In mature IAM programmes, it also includes reviewing sessions, shared secrets, delegated roles, and linked non-human identities so that exit events do not leave behind hidden access paths.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org