Supplier Risk Watch
Undetected Third-Party Change·Australia·

AUSTRAC Removes 45 High-Risk Payment Businesses — The Case Against Point-in-Time Due Diligence

AUSTRAC cancelled, suspended or refused 45 remittance and digital-currency exchange registrations in a year, citing businesses that were dormant, insolvent, wrongly registered, or that failed to notify it of material changes to their operations and ownership.

Source: AUSTRAC · 7 September 2026 · Read original article →

Risk Snapshot

Loss

45

Control Failure

Point-in-Time Due Diligence

Risk

Undetected Third-Party Change

Region

Australia

What Happened?

AUSTRAC announced on 7 September 2026 that it had cancelled, suspended or refused renewal of 45 remittance and digital-currency exchange (virtual-asset service provider) registrations over the preceding year, as part of what it described as intensified scrutiny of high-risk payment channels.

The regulator said the affected businesses fell into several categories: entities that lacked the operational capacity to begin or continue trading, businesses that were dormant or inactive, businesses that were insolvent, operators that did not hold the correct registration for the services they were providing, and businesses that failed to notify AUSTRAC of material changes. Others were removed for otherwise posing significant money-laundering or terrorism-financing risk.

AUSTRAC highlighted one business it said had been exploited by organised investment scams, and confirmed that individuals connected to some of the removed businesses had been referred to law-enforcement and other regulatory partners.

Where Was the Supplier Risk?

Most of the failure conditions AUSTRAC listed — insolvency, dormancy, a change of ownership, holding the wrong registration — are not visible at the point of onboarding. They emerge afterwards, in the months or years a counterparty sits on an approved list.

Any business that used one of these 45 entities as a supplier, a payment partner or a customer would have completed its checks against a company that looked legitimate at the time. The registration was real, the entity was real, and a point-in-time screen would not have flagged what AUSTRAC later acted on.

The risk sits in the gap between 'we verified this third party' and 'we would know if its legal status, solvency, registration or ownership materially changed'. For a remittance or digital-currency counterparty, that gap also carries regulatory exposure: a partner losing its registration can put your own compliance position at risk.

What Went Wrong?

Third-party due diligence is still widely run as a one-off gate — a company is screened, approved and added to a master file, and the file is not revisited unless someone has a specific reason to. AUSTRAC's action is effectively a list of the things that change quietly after that gate closes.

A dormant or insolvent counterparty rarely announces it. A change of ownership or a lapsed registration is visible in corporate-registry and regulator data, but only to an organisation that is watching that data on an ongoing basis rather than at onboarding alone.

This is a monitoring problem, not a screening problem. It is not solved by running a better check once; it is solved by re-checking the same population on a schedule and having a defined response when a material change appears. Detecting scam or laundering patterns in payment flows is a separate, specialist AML transaction-monitoring capability — the point here is knowing when a third party's own status has changed.

What Should Businesses Do?

  • Treat approved third parties as a population to monitor, not a file to archive

    Once a supplier, payment partner or counterparty is approved, its legal status, solvency, registration and ownership can all change without notice. Put the approved population under ongoing monitoring so a material change surfaces on its own, rather than waiting for a loss or a regulator to surface it.

  • Watch registration and regulatory standing, not just the company record

    For remittance, digital-currency and other regulated counterparties, a lapsed, suspended or incorrect registration is a leading indicator of trouble — and it can expose your own compliance position. Track licence and regulator status as a monitored attribute, not a one-time tick at onboarding.

  • Re-screen for ownership change and adverse media on a schedule

    Beneficial owners and controllers change; adverse news and enforcement referrals appear long after onboarding. Periodic sanctions and PEP re-screening plus adverse-media monitoring catch the change a point-in-time onboarding check never had the chance to see.

  • Keep an auditable record of what changed and what you did

    When a third party's status changes, log what the change was, when it was detected, and the action taken — offboard, pause payments, or request updated documentation. If a regulator or auditor later asks how you managed a counterparty that was removed or sanctioned, that record is the answer.

The ArayaPRO Response

How ArayaPRO Helps

This is exactly the type of supplier risk ArayaPRO is built to control.

Explore ArayaPRO

Further Reading

Supplier Risk Watch

Stay ahead of supplier risk.

Practical intelligence on emerging supplier threats, real-world incidents and the controls that reduce your exposure.

Supplier-risk intelligence delivered to your inbox. No noise. Submitting this form subscribes you to Supplier Risk Watch emails — see our Privacy Policy.