Skip to main content

MyMoney® is reviewing its service model in light of evolving ASIC regulatory guidance. Some features are temporarily unavailable.

AFSL 222640 · Global Mutual Funds Pty Ltd
Auditor
digital-asset-platform
DAF-Act
AFSL

Digital Asset Platform Audit Obligations in Australia 2026: A Guide to the DAF Act and AFSL Requirements

Australia's DAF Act 2026 brings crypto platforms under AFSL rules with mandatory auditor reviews. Learn what digital asset businesses must do now.

MyMoney® Editorial1 September 2026 7 min read

Australia's digital asset sector entered a new regulatory era in 2026. The Corporations Amendment (Digital Assets Framework) Act 2026 (DAF Act), which received Royal Assent in April 2026, brings digital asset platforms and tokenised custody platforms squarely within the Australian financial services licensing regime — and with that comes a mandatory requirement for review by a registered company auditor. For businesses operating in the crypto and digital asset space, understanding these audit obligations is now a compliance imperative, not an optional consideration.

Understanding the Digital Assets Framework Act 2026

The DAF Act represents the most significant structural reform to Australia's digital asset regulatory landscape since the sector emerged. Rather than creating a standalone crypto-specific regime, the government has integrated digital asset regulation into the existing Corporations Act 2001 and Australian financial services framework — ensuring consistency with the standards that apply to traditional financial markets.

Under the DAF Act, two new categories of regulated entity are created.

  • Digital Asset Platforms (DAPs) — Businesses that operate platforms facilitating the exchange, trading, or transfer of digital assets on behalf of clients. This includes centralised exchanges, over-the-counter desks, and platforms that hold or manage client digital assets.
  • Tokenised Custody Platforms (TCPs) — Businesses that provide custody services for tokenised assets, including tokenised securities, real-world assets, and other blockchain-based financial instruments.

Both DAPs and TCPs are required to hold an Australian Financial Services Licence (AFSL) and comply with the financial requirements set out in ASIC's Regulatory Guide 166 (RG 166). These requirements include maintaining adequate capital, meeting net tangible asset (NTA) thresholds, and — critically — having their financial requirements reviewed by a registered company auditor.

The Mandatory Auditor Review Requirement

The requirement for a registered company auditor review is one of the most significant new obligations for digital asset businesses under the DAF Act framework. This is not a voluntary or best-practice recommendation — it is a mandatory condition of holding an AFSL as a DAP or TCP.

The auditor review covers the financial requirements imposed under RG 166, which include the following areas.

  • Cash needs and liquidity — The platform must demonstrate it holds sufficient liquid assets to meet operational requirements and client withdrawal obligations.
  • Net tangible assets (NTA) — The platform must maintain NTA above the prescribed minimum threshold, which varies based on the nature and scale of the business.
  • Client asset segregation — Digital assets held on behalf of clients must be held on trust and segregated from the platform's own assets. The auditor must verify that segregation controls are operating effectively.
  • Record-keeping and reconciliation — The platform must maintain accurate records of all client assets and transactions, with regular reconciliation between on-chain balances and internal records.

The auditor conducting this review must be a registered company auditor (RCA) — that is, an individual registered with ASIC under Part 9.2 of the Corporations Act 2001. Not all accountants or auditors hold RCA registration, and digital asset businesses must verify their auditor's credentials before engaging them for this purpose.

Implementation Timeline and Transitional Obligations

The DAF Act operates on a dual-timeline approach that digital asset businesses must understand carefully to avoid inadvertent non-compliance.

Immediate Obligations (From 1 July 2026)

ASIC's class no-action position under Information Sheet 225 (INFO 225) expired on 30 June 2026. Businesses that relied on this no-action position were required to have been operating by 31 December 2025 and to have lodged a complete AFSL application by 30 June 2026. From 1 July 2026, all digital asset platforms must comply with existing AFSL licensing requirements while the new DAF Act framework is finalised.

This means that businesses currently operating without an AFSL — or that missed the application deadline — are now operating outside the law and face potential ASIC enforcement action.

DAF Act Full Commencement (9 April 2027)

The DAF Act enters full commencement on 9 April 2027, following an 18-month implementation period from Royal Assent. The licensing window for new AFSL applications under the specific digital asset framework opens in April 2027, with full ASIC supervision and enforcement beginning in October 2027.

Businesses that are already AFSL-licensed under the existing framework will need to review their licence conditions and financial requirements to ensure they align with the DAF Act's specific provisions for DAPs and TCPs.

AML/CTF Obligations Running Concurrently

In addition to the AFSL and auditor review requirements, digital asset businesses must maintain registration with AUSTRAC and comply with Australia's anti-money laundering and counter-terrorism financing (AML/CTF) framework.

AUSTRAC's updated regime replaces the former "Digital Currency Exchange" (DCE) designation with the broader "Virtual Asset Service Provider" (VASP) terminology, aligning Australia with the Financial Action Task Force (FATF) standards. Key obligations include mandatory transaction monitoring, appointment of a compliance officer, and compliance with the "Travel Rule" — which requires the transmission of originator and beneficiary data for transfers — effective from 1 July 2026.

Auditors reviewing digital asset platforms should be aware that AML/CTF compliance is a separate but related obligation. While the registered company auditor review focuses on financial requirements under RG 166, a comprehensive assurance engagement may also consider whether the platform's AML/CTF controls are operating effectively.

Common Mistakes and Red Flags

The complexity of the DAF Act framework means that digital asset businesses frequently make errors that create compliance risk. Auditors and businesses should be alert to the following.

  • Assuming the no-action position still applies — INFO 225 expired on 30 June 2026. Businesses that have not lodged an AFSL application are now operating without regulatory cover and face enforcement risk.
  • Engaging an unregistered auditor — The financial requirements review must be conducted by a registered company auditor. Engaging an accountant or auditor who is not RCA-registered does not satisfy the obligation.
  • Inadequate client asset segregation — Commingling client digital assets with the platform's own assets is a serious compliance failure. Auditors must verify that segregation controls are technically implemented and operationally effective.
  • Incomplete reconciliation records — On-chain balances must reconcile with internal records at all times. Platforms that cannot produce complete reconciliation records will face significant difficulties in the auditor review process.
  • Overlooking the NTA threshold — The NTA requirement is a minimum capital floor, not a target. Platforms that operate close to the minimum threshold without adequate buffer risk breaching the requirement during periods of market volatility.

Australian Regulatory Context

The DAF Act is administered by ASIC, which has primary responsibility for licensing and supervising digital asset platforms under the Australian financial services framework. ASIC's Regulatory Guide 166 (RG 166) sets out the detailed financial requirements that AFSL holders must meet, including the specific obligations applicable to DAPs and TCPs.

ASIC has signalled that it will take a risk-based approach to supervision, focusing initial enforcement attention on platforms that hold the largest volumes of client assets and those that have failed to engage with the licensing process. However, ASIC has also made clear that it will not tolerate ongoing non-compliance — businesses that have not taken steps to obtain an AFSL by 1 July 2026 should seek urgent legal and compliance advice.

The registered company auditor requirement is consistent with the approach taken for other AFSL holders under RG 166. ASIC maintains a public register of registered company auditors, which businesses can use to verify their auditor's credentials. The register is available on the ASIC website and is updated regularly.

AUSTRAC's VASP regime, which took effect from 1 July 2026, is administered separately from the AFSL framework but creates overlapping obligations for digital asset businesses. Businesses must ensure they are registered with AUSTRAC and have implemented the Travel Rule compliance infrastructure before operating.

Questions to Ask When Choosing an Auditor for Your Digital Asset Platform

Not all auditors have the technical expertise to conduct a meaningful review of a digital asset platform's financial requirements. When selecting an auditor, digital asset businesses should ask the following questions.

  1. Are you a registered company auditor (RCA) with ASIC? — This is a non-negotiable requirement. Ask for the auditor's RCA registration number and verify it on the ASIC register.
  2. Do you have experience auditing AFSL holders under RG 166? — The financial requirements for digital asset platforms are based on the existing RG 166 framework. Experience with traditional AFSL holders is directly relevant.
  3. Do you understand blockchain-based asset verification? — Verifying on-chain balances requires technical knowledge of blockchain explorers, wallet structures, and cryptographic proof of reserves. Ensure your auditor has this capability or engages a specialist.
  4. How do you approach client asset segregation testing? — Ask the auditor to describe their methodology for verifying that client assets are held on trust and segregated from the platform's own assets.
  5. Are you familiar with the DAF Act and its transitional provisions? — The auditor should be able to explain the current obligations under the existing AFSL framework and how they will evolve when the DAF Act fully commences in April 2027.

How MyMoney® Can Help

The DAF Act has created a new and complex compliance environment for Australian digital asset businesses. Engaging a qualified registered company auditor with experience in financial services licensing and digital asset operations is essential to meeting your obligations under the new framework.

MyMoney® connects Australian businesses with experienced auditors who understand the AFSL framework, RG 166 financial requirements, and the specific challenges of auditing digital asset platforms. Whether you need a registered company auditor for your annual financial requirements review or a comprehensive assurance engagement covering AML/CTF controls, our network of professionals is ready to assist.

Post a Brief to receive tailored proposals from qualified auditors, or Browse Auditors to find a specialist with digital asset platform experience.

This article provides general information only and does not constitute personal financial advice. Consider whether the information is appropriate for individual circumstances before acting on it. MyMoney® Marketplace is operated by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640).

Need Professional Help?

Post a brief and let verified professionals compete with transparent, scored proposals.