What Happened?
AUSTRAC announced on 7 September 2026 that it had cancelled, suspended or refused renewal of 45 remittance and digital-currency exchange (virtual-asset service provider) registrations over the preceding year, as part of what it described as intensified scrutiny of high-risk payment channels.
The regulator said the affected businesses fell into several categories: entities that lacked the operational capacity to begin or continue trading, businesses that were dormant or inactive, businesses that were insolvent, operators that did not hold the correct registration for the services they were providing, and businesses that failed to notify AUSTRAC of material changes. Others were removed for otherwise posing significant money-laundering or terrorism-financing risk.
AUSTRAC highlighted one business it said had been exploited by organised investment scams, and confirmed that individuals connected to some of the removed businesses had been referred to law-enforcement and other regulatory partners.
Where Was the Supplier Risk?
Most of the failure conditions AUSTRAC listed — insolvency, dormancy, a change of ownership, holding the wrong registration — are not visible at the point of onboarding. They emerge afterwards, in the months or years a counterparty sits on an approved list.
Any business that used one of these 45 entities as a supplier, a payment partner or a customer would have completed its checks against a company that looked legitimate at the time. The registration was real, the entity was real, and a point-in-time screen would not have flagged what AUSTRAC later acted on.
The risk sits in the gap between 'we verified this third party' and 'we would know if its legal status, solvency, registration or ownership materially changed'. For a remittance or digital-currency counterparty, that gap also carries regulatory exposure: a partner losing its registration can put your own compliance position at risk.
What Went Wrong?
Third-party due diligence is still widely run as a one-off gate — a company is screened, approved and added to a master file, and the file is not revisited unless someone has a specific reason to. AUSTRAC's action is effectively a list of the things that change quietly after that gate closes.
A dormant or insolvent counterparty rarely announces it. A change of ownership or a lapsed registration is visible in corporate-registry and regulator data, but only to an organisation that is watching that data on an ongoing basis rather than at onboarding alone.
This is a monitoring problem, not a screening problem. It is not solved by running a better check once; it is solved by re-checking the same population on a schedule and having a defined response when a material change appears. Detecting scam or laundering patterns in payment flows is a separate, specialist AML transaction-monitoring capability — the point here is knowing when a third party's own status has changed.
What Should Businesses Do?
Treat approved third parties as a population to monitor, not a file to archive
Once a supplier, payment partner or counterparty is approved, its legal status, solvency, registration and ownership can all change without notice. Put the approved population under ongoing monitoring so a material change surfaces on its own, rather than waiting for a loss or a regulator to surface it.
Watch registration and regulatory standing, not just the company record
For remittance, digital-currency and other regulated counterparties, a lapsed, suspended or incorrect registration is a leading indicator of trouble — and it can expose your own compliance position. Track licence and regulator status as a monitored attribute, not a one-time tick at onboarding.
Re-screen for ownership change and adverse media on a schedule
Beneficial owners and controllers change; adverse news and enforcement referrals appear long after onboarding. Periodic sanctions and PEP re-screening plus adverse-media monitoring catch the change a point-in-time onboarding check never had the chance to see.
Keep an auditable record of what changed and what you did
When a third party's status changes, log what the change was, when it was detected, and the action taken — offboard, pause payments, or request updated documentation. If a regulator or auditor later asks how you managed a counterparty that was removed or sanctioned, that record is the answer.
The ArayaPRO Response
How ArayaPRO Helps
This is exactly the type of supplier risk ArayaPRO is built to control.
Further Reading
