EP. 118 | Inside Australia’s Historic AML Reform with AUSTRAC’s Brad Brown
30m 57s
The World Cup exposed a global pattern of early-stage crypto scams, with TRM detecting fraudulent ticketing, betting, and fan token schemes that exploited event momentum. These activities reflect a broader trend where criminal infrastructure is built months in advance, highlighting the need for early intervention. In Australia, Ostrac has significantly expanded its regulatory reach to cover over 50,000 businesses, including legal and financial services, and now formally regulates virtual asset service providers (VASPs) under FATF-aligned standards. A key shift in regulatory thinking is toward a risk-based, outcomes-driven approach—moving beyond compliance checklists to actively mitigate real-world financial crime. Ostrac leverages intelligence, public-private partnerships like the Beacon Network and Fintel Alliance, and targeted education to strengthen detection and prevention. Scams remain a major global concern, with fraud estimated at $500 billion annually, prompting Australia’s coordinated response that includes public awareness and cross-sector collaboration. Regulators emphasize that businesses should not only meet compliance obligations but actively understand and manage risks, with enforcement reserved for cases of systemic failure. This model of risk intelligence, education, and partnership is seen as a vital framework for future regulation in the evolving digital asset economy.
I'm Erie Redbord and this is TRM Talks. I am global head of policy at TRM
Labs. At TRM, we provide blockchain intelligence software to support law
enforcement investigations and to help financial institutions and cryptocurrency
businesses mitigate financial crime risk within the emerging digital asset
economy. Prior to joining TRM, I spent 15 years in the US federal government
first as a prosecutor at the Department of Justice and then as a Treasury
Department official where I work to safeguard the financial system against
terrorist financiers, weapons of mass destruction proliferators, drug kingpins,
and other rogue actors. On TRM Talks, I sit down with business leaders, policy
makers, investigators, and friends from across the crypto ecosystem who are
working to build a safer financial system. On today's TRM Talks, I sit down
with Brad Brown of Australian regulator, Ostrack, but first inside the lab
where I share data-driven insights from our blockchain intelligence team. On
today's inside the lab, we're talking World Cup. While Spain is our champion,
the reality is that the World Cup was a playground for scammers who built
infrastructure even weeks before a single match kicked off. TRM was
tracking fake ticketing sites, fixed matched betting schemes, fishing kits, and
opportunistic meme coins, riding the tournament's weight. This is a pattern we have
seen before at every major global event. For context, roughly 35 billion dollars
blow to scam linked wallets in 2025. Part of a record $158 billion in total
is a crypto activity. As of early June, TRM had identified four scam
addresses tied to three live World Cup themed operations. Dollar amounts were
not a lie, under $1,700 combined, but that's the nature of event-driven
scams early on. One ticketing scam on Polygon took in most of its money in a
single day, suggesting a viral push drove the short burst of victims. A fan
token curled World Cup, was trading on one exchange with no connection to
FIFA, impersonating the tournament directly, and proceeds were routing through
cross-chain bridges towards TRON, a pattern tie to an estimated $1.9 billion in
all-time scam funds. The point is timing. The infrastructure exists for this
months before kickoff, which means there's a real window to disrupt cash out
points before losses scale. Fans should be skeptical of anything not coming
directly from FIFA or any other official sites, and reports suspicious addresses to
chain abuse or the FBI's IC3. The World Cup might be over, Spain may be the
champion, but we are going to see this pattern play out over and over again from
the Super Bowl to the Olympics and beyond. And now, Austrax Brad Brown. Today I am
joined by the National Manager for Regulatory Operations for Austrak, Brad Brown,
Brad. Thank you so much for joining TRM Talks.
Pleasure to be here, Ari. Thank you. If I can kick us off, I feel like there's always
an interesting journey to a role like you have really seeing a really
overseeing a lot of the regulatory work for Austrak in Australia. Would you
tell me about your journey a little bit? How did you get interested in this
topic? Yeah, I'm going to say I've had an incredibly rewarding career. It's a
career over that now spends decades. It just means I'm showing my age, but
I started within law enforcement in policing with a quite a lengthy background
in intelligence before I joined Austrak in 2004. So I joined within our
intelligence responsibilities within Austrak, but over the journey and over the
course of multiple years, I've also worked in our policy, which is an
important consideration in terms of the anti-money laundering reforms that are
just upon us also worked in our education space and our international
engagement in work in terms of our fintail alliance and our partnership with
businesses and now more recently in terms of our regulatory responsibilities and
supervisory engagements with businesses over the last four to five years. So I
think it's the culmination of all of those parts of my career that sort of
lead me to where I am now. It's probably the focus and the engagement I've had
with businesses that helps shape how I focus upon the work that I'm doing. I
really believe in the, even though I'm the regulatory, I also really believe in
the partnerships that we naturally have with businesses and working with
businesses in the first instance to achieve the right outcome. Perhaps my
background leads to one consideration is that I'll also, you know, where it's
necessary take action and I'll be assertive and necessarily expect that businesses
improve and I'll support my team doing that as well, which is perhaps what we
need to do as a regulator. It's really interesting. I mean in terms of your
law enforcement background as well, I spent about 11 years as a federal
prosecutor here in the US and then went to Treasury where I sort of more of a
regulatory role. You don't meet a lot of people who have the combined law
enforcement plus regulatory policy piece. Tell me a little bit about your law
enforcement career and then maybe how is it informed the work that you do as a
regulator today? I mean, interesting. I'd probably say it hasn't in too many ways
informed my regulatory approach. I mean, I certainly in more of a state-based
policing agency in Australia within Queensland. I think what has more
informed the way I approach my current role and the role that I have as a
regulator is is more all of the years that I've had and that's probably more than
the decade now where I have actually worked directly with businesses on
policy, directly with business on what they need to help them understand what
they need to do. And I think that's actually really shaped how I approach my
engagement with businesses more so now than that that impacts anything to do
with where I was in policing and law enforcement. We have a pretty sophisticated
audience of complaints, professionals, global regulators, law enforcement, it's
it's really a cool mix. Would you just spend a moment or two sort of talking
about the role of Ostrac in sort of the financial space within Australian
sort of the mandate? Yes, well, Ostrac has two primary functions. It's Australia's
financial intelligence units. So as a financial intelligence unit we collect and
analyze information and generate insights and intelligence which we then
provide to law enforcement, national security, and other partners within Australia
and at times internationally to assist with investigations. We're also
Australia's anti-money laundering and counterterrorism financing regulator and
that's the key part of that role that I play and in that we necessarily ensure
that businesses are complying with the the legislation that in Australia that
might mean primarily that we engage in education and providing advice etc. but
also we'll certainly check people's homework so to speak and ensure they're
doing the right thing and and then in certain cases where we consider there's
more serious harms or systemic failures that's where we will take a harsh
your approach and and utilize the enforcement powers that Ostrac also has.
Talk me through sort of your role day to day. Yeah, so I have I have multiple teams
have have a large group of staff that necessary work with with that work with me give
a take it's about a hundred and and we conduct assessments of businesses that
are regulated in Australia so we'll we will engage with them we will as I say check
their homework to to actually assess whether they have put the obligations in
place under law in place that means we'll go and speak with them we'll ask
some questions will inspect files will interview key people in key roles at
different points of time we'll leverage our data that we have available to us
in Ostrac to actually determine whether there are businesses that are that
outliers will engage with our intelligence colleagues to determine whether
there's anyone that we think is involved in in any activity that we would
actually want to see stopped and take action in that regard. So multiple teams
normally they're focused a bit on on different industries so we have a team for
example it focuses on our payments and and remittance and virtual assets we
have a team that's focused on banking and and and I like we've had teams that
are being focused on all of the gambling and consideration in on casinos and
corporate bookmakers so sports betting getting a little more granular it's
interesting would you brief this group here a little bit on really the first
AML or biggest AML reforms in 20 years dropped really just a few months ago
would you walk us through what those reforms look like yeah first and foremost
an incredible amount of complexity yeah and complexity in relation to what the
changes that we had to put from legislation into policy and then into practice
so a whole lot of people involved a whole lot of new systems you know on Ostrac's
end but a whole lot of engagement yeah it looked like I'm gonna say the most
comprehensive level of engagement and co-design with businesses that Ostrac has
ever done in its history massive amount of credit has to go to our our CEO the
boss of our organization and senior executive we also looked at some of the
most innovative thinking and. and things to put in place to assist businesses to understand the risks that they face in relation to
criminal activities, but also necessary how to apply. So OzTrack has now a world first in turn
to a program start-a-kits, which will help businesses. We hope start the journey of what they have
to do to be regulated. And as a final point about that briefing, it's maintaining pace over
probably what has been 18 months, 18 months and delivery, 18 months of engagement to get us to a
point to have businesses ready. We hope from the 31st of March when some of the obligations commenced
and more recently the 1st of July, which was the key date in the legislative timetable.
What we through sort of, you know, from a high level perspective, or what would you consider
to be sort of key takeaways from this trudge? I mean, the most important takeaway and change is
certainly that we have expanded the regulation in Australia. So our regulation and our responsibilities
now cover other businesses that we previously didn't regulate. So those that are providing
legal services, accounting services, real estate services, trust and company service providers,
and dealers and precious metals and stones. So that's the most significant because that has a major
impact around the population that we regulate. So previously, it was about 19,000. It's certainly
growing every day and above 50,000 at the moment in terms of that population that we'll have
responsibility for. We also expanded considerations around our virtual assets, or digital currencies,
crypto, whichever word you wish to use. And to along that more with the global obligations that
we necessarily have to have regard to. It's interesting, you know, talk me through that a little bit.
You even change sort of the way you refer to these types of businesses, whether they're exchanges,
they were called in Australia's policy documents, digital currency exchanges. You've moved to
sort of fadifs. The way the financial action task force refers to these types of services,
vasps, virtual assets, service providers, I constantly joke that depending where I am or what audience,
I never know exactly what to say, right, distributed ledger services, casps in Europe. We have all
kinds of crazy names for them in the United States. So fadif has really always been sort of where I
landed. And obviously, this is where ostrac specifically wanted to get having implemented
fadif standards for years, talking through sort of maybe specifically what this means for virtual
asset service providers in Australia. I was going to say I wish it was just a name change, but no,
it's not there's a little bit more to it. There's some substance here too. So you're absolutely
corrected. There's more to it. And I think as I mentioned first and foremost, we are now more in
line with the with the financial action task force standards. And that relates to particularly what
services that are being offered by a ever-expanding and maturing financial sector. And that is the
virtual asset services providers. So previously in Australia, we regulated the otherwise the
ordinary frames, you know, so cash to crypto crypto back to cash. So that that's now been expanded
to include, you know, virtual asset to virtual assets, the, you know, the safekeeping and wallets,
the and also the trends, the transfer of virtual assets and making that making value available
to others. So all of those services are added up led to us necessarily incorporating in the
naming as it is in those standards. And importantly, also for virtual asset providers like other
businesses that we regulate, the regime now is also been adjusted to have that outcomes focus. So
that that means really focusing upon the risks and harms that that your business might be exposed
to and how you respond to that. And that's that's going to be an important part of how we look at
businesses going forward. I love that it's interesting. We do have a lot of current regulators
on this podcast on TRM talks. And we are starting to see at least I, for my empirical evidence of
this on the show, seeing consistency around that that globally we're seeing this outcomes
true risk based approach. It used to be just something you would say. And now it's like we really
need to move away from this checked box regime where compliance teams are just doing what they
think we need to see or want to see to doing how you really mitigate risk on their platforms.
Does that sound right from the conversations you're having with your global counterparts as well?
Very much so. I mean, and if it's if it's not only with our global counterparts, it's really
just thinking that we have within Australia. I mean, what do we want to see? What do we want to
see minimized? We want to see the that we have an impact on on harms to the community where we're
going to have an impact on on businesses that might be doing the wrong thing, you know, so that's
that's certainly squarely in our in our focus our focus from as an intelligence agency and our
focus is a regulator. So that's yeah, and absolutely agree. Other countries that we engage with
definitely squarely are also focused on making sure that you know, we protect where we can protect
and we minimize the risk where we can minimize it. I think it's really one of the most important
shifts that we've seen over the last couple years. This is moved from for regulators to really push
beyond this sort of check box model for a lot of a lot of compliance teams. It's interesting. I
feel like you have a number of roles and part of that is hey, you're the regulator compliance is
critical. You're looking at enforcement, but there's this other piece where you're as an FIU
trying to mitigate risk. You want to make sure that bad actors aren't engaging with your regulated
entities. What do you when when you look at the risk landscape out there, the threat landscape,
what are what are really some threats that are top of mind for you from an illicit finance
perspective? First and foremost, I mean, again, Ulstrak Australia has has has generated national
risk assessments on money laundering terrors and financing and proliferation financing and
those risks and those threats that they that are outlined are certainly continue to stand
today. I think what the most considerable elements are is just the the shifts and the efforts
that criminals are making in terms of exploiting the channels. The greater level of sophistication,
you know, far more digitally savvy and necessarily, which means that we have to keep pace with that
and and look to look to have an impact. You know, as I mentioned, so the digitally enabled
crime is is is incredibly relevant for us and the and the considerations that we have in place.
We're having a look at necessarily implications of serious and organized crime and organized
criminal groups that are the continue to impact our payment system virtual assets and they're
transfers. You know, so these are sort of key threats that are that our intelligence capability
continues to to be aware of and continues to to look to address. It's so interesting when I think
about the threat landscape in Australia and a lot of this is just sort of watching the way Ulstrak
operates in the space. Scams are obviously very clearly top of mind. You've done a lot of work
there over the last few years. We've seen a lot of guidance. There's been public service
announcement type of activity. Talk me through how you're dealing with scams. I mean,
this is a global scourge, but it's very clearly having a dramatic effect in Australia.
Yeah, I mean, your point about global is certainly certainly right. I mean, I think just for context,
I think again, the financial action task force has done some work on this in the in the more recent
times and and nearly every country that is being assessed by them as highlighting fraud as a major
predicate crime to money laundering. I think the more recent statistical indications are give a
take about US $500 billion potentially globally is the impact of fraud in 2024, 25. So, you know,
and that plays out in Australia. That plays out in terms of of necessarily the risks of frauds
and scams. I think in terms of our response, our response is not just those track. Our response
is is more whole of whole of government as there are the scams prevention framework is being put
in place in in Australia. We're looking to leverage the telecommunications, the banking again,
partnering to ensure that we can have an impact and protect as many people from being come from
becoming victims of scams. I think that's that's again, what it boils down to is there's an
incredible amount of harm that is caused to individual people through scams. Many of them are can
be industrialized just to such a level. They are very organized in terms of their operations and
their targeting. But what it does is it hurts. It hurts people. It's a huge focus for us at Tierra
and something we're thinking about all the time. How can we work with law enforcement? How can we
work with regulators to stop this activity? It's funny, my wife. My wife is a dermatologist. She's
a skin cancer surgeon. For years, she has told me about the public awareness campaigns that Australia
has done in that space. The slip, slop, slap, the sunscreen, kids are wearing rash cards on the
beaches, which we haven't. We just started doing here. What you're describing here makes me think
of something that Australia is really very good at and that is getting the word out to citizens
about doing potential harm to themselves. The public is absolutely critical. The more people
become aware, the more they're aware of what they have to be aware of to assist themselves
or potentially not be influenced, controlled, tricked is incredibly important. There is a lot of
that messaging occurring whether it be through Oztrak, but again, I'm going to say more broadly
across at the Australian
- Sure, no one agency, no one country
can deal with this alone.
I mean, we're dealing with transnational criminal organizations
that are doing this stuff at scale, absolutely.
Austria supervises something like 19,000 business
across all these different sectors.
I mean, that is crazy.
How do you think about private sector engagement
when you're dealing with this many entities
and helping to really push risk-based compliance
with your regulated entities?
- Yeah, I mean, our focus is on intelligence-led
and risk-based supervisory activities.
So we leverage an incredible amount of information,
intelligence and data that Oztrak receives.
We have a significant amount of information
that we get from the businesses that we regulate
that helps us necessary or find our understanding
of who may have a greater level of exposure
to the risks that we're trying to address.
We engage with businesses frequently.
So that just builds our understanding and knowledge
of necessarily where we need to deploy our resources
at the right point in time.
We certainly do not treat all businesses the same,
but that's a key thing.
So where we think there is a greater level of harm,
you might have a greater level of scrutiny,
but there's also a very large and vast,
and the vast number of businesses
that we regulate that our focus
more around uplift, education, guidance, communication,
through this, through our messaging
that we provide to actually then reach the many
and some of our actions and engagements
will necessarily touch upon the few
and in those engagements, as I said earlier,
that's where we sometimes ask the tougher questions
to give it deeper, identify who their customers are
and whether and how they deal with them appropriately.
- It's interesting when I'm answering that question,
you went right to intelligence immediately,
like that's absolutely the key to how we engage.
We think a lot about intelligence sharing,
private public, private public.
We operate something called the Beacon Network,
which is the largest public private information sharing,
interdiction, seizure network within the crypto ecosystem.
Australian federal police are a member of the Beacon Network.
They share alerts with these exchanges,
combining your sort of law enforcement background
with what you do or have done an abstract talk me
through like intelligence sharing,
how we can really use it at scale to stop these bad actors.
- Yeah, we probably have an example in an abstract
that we've established the Fintel Alliance,
which is our public private partnership,
and I think it's had some great success in leveraging
the effort and the information that's available
to a whole lot of private sector
and other law enforcement partners.
What we learned from that,
we then tried to provide a level of insight
to which we provide to the entire regulated population
and publicly they're available on our abstracts websites
and we do different indicators, papers and financial crime guides
in relation to a range of both criminal activities,
but also methodologies that criminals are looking to exploit.
So I think that is a way that we provide information
and regular information to the masses ultimately
and similarly our national risk assessments
and more recently our annual updates also really provide
a level of information to businesses that helps them.
There's also increasingly a level of engagement
between law enforcement with businesses directly
and obviously that's, there's a great opportunity
for businesses to learn from that direct engagement
oftentimes it might be through particular questions
that come their way that they necessarily
have to respond to but they learn.
That means they can adapt and understand
it may be a different risk that they face
to that they need to be cognizant of in their work.
- My guess is that this part of guess
is gonna be very well received
and certainly listened to by compliance professionals
within Australia, certainly in regulated entities,
maybe a message to them in terms of how our strike
wants to work with compliance teams, regulated entities,
how they should potentially engage with you.
- Yeah, I mean first and foremost,
I think our message is that we are seeking
to set businesses up for success
and that we achieve that by providing an incredible amount
of guidance and information that's either through
messaging like this or through other forms of education,
through e-learning packages that OzTrack has.
So we want businesses to understand their risks
and apply their obligations to, you know,
based on the knowledge that we have provided them.
So I think that's first and foremost.
We have articulated over the course of the last 12 months
a pretty clear expectation that again,
we want businesses to manage their risks.
We want people to necessarily delve in
and understand the risks that their businesses face
and where that doesn't occur is where there's necessarily
a greater likely hookwack that you'll necessarily
be caught upon by myself or my teams
as necessarily the regulator and ask questions.
But that is a critical and core opponent
of our regime.
Understand the risks, apply the obligations.
We probably, and we have indicated particularly
as it relates to the reform
that we don't expect everyone's going to be perfect.
We're not looking for perfection as well.
What we're looking for is best efforts.
We're looking for people to apply that to us
to necessarily give it a go to understand
what they need to do about their obligations
to report suspicious matters to OzTrack
because that then helps what we actually do
with more enforcement.
Again, it's that sort of journey between, you know,
being exposed to activity, looking, learning,
and then actually taking action.
And then that action might lead to us
doing something with it.
- Terrific, let's get out of here with this one more.
And that is when you are not leading teams at OzTrack,
helping provide clarity to the space, enforcement,
and compliance, what do you do for fun?
What do you like to do to, I don't know,
let off a little steam?
- Yeah, well, for myself personally, I'm a lover of sport.
And you watch more sport when you actually can't play it.
So that's next all the way to work.
That's the moment.
- What are your sports, what are your teams?
- You have no football world cups on at the moment,
so that's worth a watch at the moment.
But my normal team, so certainly the Australian football league,
which is not around ball, but an oval shape ball
in Australia is a key to my winter sports.
And then a cricket ball and watching cricket is certainly
my summer sport of choice to watch.
But when I'm not doing that,
I'm also now thinking about grandparenting duties
as when the grand son sort of comes and visits.
So that's plenty of time and effort now.
- I love that.
When you played, what sports did you play?
Was it also cricket and football?
- Yeah, I played cricket back in the day,
but definitely not that good time.
- All right, I've got one more question for you.
And you can, in the context of your grandchildren
is probably perfect.
So when I was in Australia, I got turned on to these.
They're very good, just alone I've decided.
But the slam is just, it's a transformative food.
Like I actually found a place that sells them here.
These are not the ones I got in Australia.
Are you a fan?
Is this something you do with your,
you would have done with your kids?
John O'Neumann on my team and Angela Ong and others.
We were doing these out one morning after coffee,
after a run.
Tell me any, any fun stories about these guys?
- Well, welcome.
I'm going to say, hey, Ronnie, it's Tim Tam.
So that is absolutely,
I should also say that one of my,
one of the things I do is now is actually go to the gym.
So I'm actually trying to have less sugar
because I'm not in the last 10 times.
All right, so I should, I should,
you know, I also felt bad that I was going to bring these
and show you them, but I wasn't going to send you some.
So, but now you don't feel as bad about that, for sure.
- It's funny and funny, so I'm serious about it.
- Yeah, what I did is I ate a lot of Tim Tam's,
but I also ran around the opera house a lot
when I was in Sydney.
- That's the awesome thing.
- That week, which was a very awesome day.
- Absolutely gorgeous.
Hey, Brad, thank you so much for joining TRM Talks
and thank you for all the work you do
on behalf of the Australian people
and really look forward to continuing
the conversation with you.
- Thank you very much.
- I thought Brad made some really critical points here
and there are a number of key takeaways.
I think the biggest one for me is we're really seeing
a global move towards this idea of outcomes.
To this idea of like a true risk based approach
that what's expected of compliance professionals
not to just check the box or give the regulator the answer
they want, it's hey, how can we actually mitigate real risk
that could potentially be on your platform?
How can we actually stop bad actors
and how can we enable outcomes?
And I think we're seeing this like global shift,
we're hearing a lot of this from FATIF,
the financial action task force,
all the conversations I'm having with FinSEN,
it's really the same.
We've seen speeches from the US Treasury Secretary
on this, Brad immediately went there
where he's really pushing for this move away
from check box compliance to something much more outcomes
oriented, actually, risk based.
So that was my sort of biggest takeaway today
from the conversation, but I would also say that
Austria is obviously laser focused
as our a number of different key agencies
across Australia on scams.
And this has been a year's long campaign
to not only disrupt and go after the bad actors,
but really help Australians and stop them.
Australians from being victims of scams, and I think that it's obviously such a huge
priority.
So a really interesting conversation today with Brad Brown.
On the next TRM Talks, I sit down with head of digital assets for Morgan Stanley, Amy
Oldenburg.
If you love the show, leave a review wherever you're listening to it, and follow us on LinkedIn
to get the latest news on Crypto Regulation, Compliance, and Investigations.
TRM Talks is brought to you by TRM Labs, the leading provider of blockchain intelligence
and anti-money laundering software.
This episode was produced in partnership with Valtage Productions.
The music for this show was provided by E-Collix.
Now, let's get back to build it.
[BLANK_AUDIO]
Podcast Summary
Key Points:
Global scams, including those targeting major events like the World Cup, exploit digital infrastructure months in advance, with TRM identifying fake ticketing sites, rigged betting schemes, and fraudulent fan tokens linked to over $158 billion in crypto activity.
Australia’s Ostrac has expanded its regulatory scope to include over 50,000 businesses—such as legal, accounting, and real estate services—and now regulates virtual asset service providers (VASPs) under FATF-aligned standards.
A shift toward risk-based, outcomes-focused regulation is evident globally, moving away from checklist compliance to actively mitigating real financial crime risks through intelligent, proactive measures.
Ostrac employs intelligence-led, risk-based supervision, leveraging data and private-public partnerships like the Beacon Network and Fintel Alliance to detect and disrupt illicit activities.
Scams are a major global threat, with fraud estimated at $500 billion annually, prompting Australia’s whole-of-government response including public awareness campaigns and cross-sector collaboration.
Regulators emphasize education, guidance, and transparency—offering e-learning tools and risk assessments to help businesses understand and act on their obligations.
Enforcement is balanced with support
Personal engagement with businesses through direct interviews and intelligence sharing fosters deeper understanding of risks, enabling more effective compliance and prevention strategies.
Summary:
The World Cup exposed a global pattern of early-stage crypto scams, with TRM detecting fraudulent ticketing, betting, and fan token schemes that exploited event momentum. These activities reflect a broader trend where criminal infrastructure is built months in advance, highlighting the need for early intervention. In Australia, Ostrac has significantly expanded its regulatory reach to cover over 50,000 businesses, including legal and financial services, and now formally regulates virtual asset service providers (VASPs) under FATF-aligned standards.
A key shift in regulatory thinking is toward a risk-based, outcomes-driven approach—moving beyond compliance checklists to actively mitigate real-world financial crime. Ostrac leverages intelligence, public-private partnerships like the Beacon Network and Fintel Alliance, and targeted education to strengthen detection and prevention. Scams remain a major global concern, with fraud estimated at $500 billion annually, prompting Australia’s coordinated response that includes public awareness and cross-sector collaboration.
Regulators emphasize that businesses should not only meet compliance obligations but actively understand and manage risks, with enforcement reserved for cases of systemic failure. This model of risk intelligence, education, and partnership is seen as a vital framework for future regulation in the evolving digital asset economy.
FAQs
Ostrac serves as Australia's financial intelligence unit, collecting and analyzing data to support law enforcement and national security. It also acts as the country's anti-money laundering and counter-terrorism financing regulator, ensuring businesses comply with relevant laws and conducting supervision and enforcement when necessary.
Australia has expanded its regulation to include businesses in legal services, accounting, real estate, trust and company services, and precious metals dealers. This has increased the regulated population from around 19,000 to over 50,000, reflecting a broader focus on financial crime risks.
Regulators now focus on actual risks and harms rather than compliance checklists. This means businesses are expected to proactively assess and mitigate risks, aligning with global trends and improving the effectiveness of anti-financial crime efforts.
Ostrac leverages intelligence from businesses and law enforcement to identify fraudulent activity. It collaborates through whole-of-government frameworks, such as the Scams Prevention Framework, and uses public awareness campaigns to help individuals avoid scams.
The Beacon Network is Australia’s largest public-private information-sharing network in the crypto space. It enables real-time alerts and intelligence sharing between regulators, law enforcement, and private sector entities to disrupt illicit activities and seize assets.
Ostrac engages through risk-based supervision, education, and targeted outreach, offering guidance, e-learning modules, and public reports on financial crime threats. The goal is to help businesses understand risks and apply obligations in a practical, proactive way.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.