Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should crypto businesses implement AML/CFT controls under…
Governance, Ownership & Risk

How should crypto businesses implement AML/CFT controls under AUSTRAC expectations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 10, 2026 Domain: Governance, Ownership & Risk

Start by tying onboarding, monitoring, reporting, and retention into one governed workflow. The practical test is whether the business can prove who was enrolled, why they were accepted, what activity was flagged, and how long the evidence will remain available for review.

What AUSTRAC expects from AML/CFT controls in practice

AUSTRAC expectations are not satisfied by isolated checks. Crypto businesses need a single control chain that connects customer due diligence, ongoing transaction monitoring, suspicious matter escalation, and record retention so the business can show a consistent decision trail from onboarding through reporting and review.

The practical standard is operational proof, not policy language: the firm should be able to demonstrate who was accepted, what risk factors were considered, what activity triggered review, and what evidence was retained for inspection. That is why the workflow has to be governed end to end rather than split across separate teams or tools.

For the underlying international baseline, the FATF Recommendations on AML and KYC remain the clearest reference point for customer due diligence, beneficial ownership, suspicious activity reporting, and virtual asset risk controls, while AUSTRAC translates those expectations into Australian supervisory practice.

How to build the control workflow crypto firms actually need

Start with onboarding controls that capture identity information, beneficial ownership where relevant, source-of-funds or source-of-wealth signals where risk warrants it, and a documented reason for acceptance or rejection. For a crypto business, that means the customer file must do more than hold static records, it must support later review of why the relationship was opened in the first place.

Next, make transaction monitoring proportionate to the product and risk profile. Monitoring needs to look for unusual velocity, layering patterns, rapid in-and-out movement, cross-chain or cross-asset hops, and behaviour that is inconsistent with the stated purpose of the account. Where monitoring is outsourced or rule-based, the business still needs to own the tuning logic, escalation path, and review outcome.

Retention is part of the control, not an administrative afterthought. If investigation notes, alerts, case decisions, and supporting evidence are not retained long enough to reconstruct the decision path, the business cannot prove compliance even when the underlying judgment was reasonable.

For broader control design, AUSTRAC-style programs usually align best with FATF Recommendations, the AML and KYC framework, because the customer due diligence, ongoing monitoring, and suspicious reporting model is already embedded there. Australian firms that need local supervisory context should also review FinCEN only as a comparative AML operations reference when building scalable case handling and reporting discipline.

What evidence proves the program is working

The strongest evidence is not a long policy library, it is a traceable record set. A sound program can show the intake record, the risk rating rationale, the monitoring rule or scenario that fired, the analyst disposition, the escalation decision, and the final retention location for each material case.

That evidence has to be usable on demand. If the business cannot quickly reconstruct a case from raw alert to final report, the control environment is too fragmented. The same test applies when reviewing false positives, because a high alert volume without documented tuning and disposition logic often indicates weak prioritisation rather than strong detection.

A useful technical comparator is the way financial-control regimes document decision trails. The EBA AML/CFT Guidance shows how supervisory expectations are usually operationalised through auditable onboarding, monitoring, and escalation processes, which is a useful pattern for crypto firms even outside the EU.

UK and EU practitioners often use the same operating logic across cases, so EBA AML/CFT Guidance can help teams compare their evidence model against a mature supervisory approach. Where suspicious activity reporting discipline is the main gap, FinCEN is a useful source for understanding how investigators expect alert triage and reporting to be documented.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingOngoing AML/CFT monitoring depends on alert review and escalation traceability.
IA-5 — Authenticator ManagementCustomer onboarding and case handling rely on controlled identity and evidence records.
Recommendation — Review suspicious alerts and case outcomes using auditable workflows and documented analyst actions. Manage customer and staff credentials so onboarding and case records remain attributable.
ISO/IEC 27001:2022A.5.15 — Access controlAML/CFT evidence systems need controlled access to preserve integrity and reviewability.
A.5.33 — Protection of recordsRecord retention and defensible case histories are central to AML/CFT compliance evidence.
Recommendation — Restrict access to onboarding, monitoring, and case records to authorised reviewers only. Protect and retain AML/CFT records so investigations and supervisory reviews can be reconstructed.
CIS Controls v8CIS-8 — Audit Log ManagementTransaction monitoring and suspicious activity review require reliable logs and retention.
Recommendation — Centralise and retain logs that support AML/CFT alert triage and investigation.

Practitioner Guidance

What to prioritise: Treat onboarding, monitoring, escalation, reporting, and retention as one governed workflow with one accountable owner. If those steps sit in separate teams or systems, the most common failure is not the absence of a rule, it is the inability to prove the end-to-end decision path later.

What to verify: Before trusting the program, verify that every material alert can be linked back to the customer file, the risk rationale, the analyst decision, and the preserved evidence set. If you cannot reproduce that trail for a sample of cases, the control is not yet audit-ready.

Common mistake: Teams often over-focus on writing policy and under-focus on case hygiene. In practice, AUSTRAC-style readiness depends more on whether the business can defend its decisions than on whether it has a generic AML manual.

Practitioner takeaway: The right test is not whether crypto aml/CFT controls exist, but whether the business can reconstruct and defend each customer and alert decision as a single, coherent record.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org