AUSTRAC’s 10 August announcement says it suspended Cryptolink Pty Ltd’s Virtual Asset Service Provider registration for three months from Sunday, 9 August 2026. The suspension prevents Cryptolink from operating its 96 cryptocurrency automatic teller machines in Australia. AUSTRAC attributed the action to required threshold transaction reports that were not submitted and a request for information that went unanswered.
The exact status matters. This is a three-month registration suspension, not a revocation, a criminal finding or proof that every Cryptolink service has closed. AUSTRAC has not disclosed the number or dates of the missing reports, the terms of its information request, the precise reinstatement conditions or effects beyond the 96 CATMs. No current Cryptolink response to the suspension was verified before delivery.
What changed and what it means
AUSTRAC’s three-month suspension stopped Cryptolink’s 96 CATMs, making mandatory-report completeness and regulator-response controls an operating-access issue.
- Decision affected
- Test whether threshold-report completeness, regulator-request escalation and suspension-continuity controls have named owners, due-date thresholds and retained evidence.
- Evidence in brief
- AUSTRAC says Cryptolink met the undertaking’s stipulated conditions, then failed to submit required threshold transaction reports or answer an information request; its VASP registration was suspended from 9 August 2026.
- What remains unresolved
- AUSTRAC did not disclose the number or dates of missing reports, the information-request terms, exact reinstatement conditions or effects beyond the 96 CATMs; no current Cryptolink response was verified.
- Next verification
- Reconcile source cash transactions to accepted TTRs, test aged exceptions and regulator-request escalation, and monitor AUSTRAC for reinstatement or further action.
Key takeaways
- AUSTRAC suspended Cryptolink’s VASP registration for three months from 9 August 2026, stopping operation of 96 Australian CATMs.
- AUSTRAC says Cryptolink met the stipulated conditions of its earlier undertaking, then failed to submit required threshold reports or answer an information request.
- AML/CTF control owners should test report-population completeness, submission acceptance, aged exceptions and regulator-request escalation separately.
- The number of missing reports, precise suspension terms and current company response remain undisclosed or unverified.
What AUSTRAC suspended, and what it did not establish
AUSTRAC suspended the registration that permitted Cryptolink to operate its Australian CATM network. The regulator said it would monitor Cryptolink’s compliance with the suspension. It did not announce a permanent removal from the VASP register, identify an exact expiry date or state that all of the company’s activities were prohibited. The SEC Regulation Crypto status test applies the same boundary: a cancelled meeting that never issued a proposing release is not a proposal, final rule or compliance date.
The announcement also reports AUSTRAC’s assessment of compliance risk. It should not be expanded into findings that the company laundered money, knowingly facilitated crime or breached the earlier undertaking. Those propositions are not established by the material reviewed for this article.
How the case moved from remediation to operating restriction
The previous state was AUSTRAC’s October 2025 action. The regulator issued an A$56,340 infringement notice and accepted a court-enforceable undertaking after its Crypto Taskforce identified alleged late reporting of large cash transactions and weaknesses in Cryptolink’s AML/CTF risk assessments. AUSTRAC said payment of the notice was not an admission of liability.
The undertaking required third-party reviewers to validate whether all required threshold transactions had been reported, assess controls for large cash transactions and review the company’s risk assessment. In the new announcement, AUSTRAC says Cryptolink met the conditions stipulated in that undertaking. It then attributes the suspension to subsequent reporting failures and the unanswered information request.
That sequence is the central operating lesson. Completion of a remediation programme is not evidence that every recurring report, exception and regulator request will remain controlled after the review closes. The control owner needs continuing evidence, not a one-time project sign-off.
Three controls need separate evidence
1. Prove the report population is complete
AUSTRAC’s threshold-reporting guidance says a threshold transaction report is required when a designated service involves A$10,000 or more in physical currency, with submission due within 10 business days after the transaction day.
A reporting control should therefore begin with the source population, not the reports already generated. The owner should reconcile every eligible cash transaction to a report record, a submission result and a final exception disposition. Counts and values should be segmented by legal entity, machine or location, transaction date and reporting due date. A dashboard that only counts files sent can miss eligible transactions that never entered the reporting workflow.
A finance systems integration map can make those states explicit: source transaction, eligibility decision, report creation, transmission, acceptance or rejection, correction and retained evidence. It should also show who owns a break at each boundary.
2. Separate submission from acceptance and correction
A technical transmission is not the same as an accepted and complete regulatory report. The operating record should retain the transaction identifier, report identifier, submission time, acknowledgement, rejection or validation result, correction history and accountable owner. Reports approaching the 10-business-day deadline need escalation before they become overdue, while rejected or incomplete reports need a separate ageing view.
Testing should include missing source records, duplicate transactions, late-arriving data, failed batches, partial acceptance, rejected fields and corrections after submission. The purpose is to prove that every eligible transaction reaches a final state once, within the required period.
3. Escalate regulator requests outside the ordinary queue
AUSTRAC’s announcement separately cites failure to respond to a request for information. A regulator request should not depend on the same queue used for routine customer or operations cases. It needs a dedicated register with the received date, scope, responsible executive, legal or specialist reviewer, response deadline, evidence owner, approval status and proof of delivery.
Escalation thresholds should be time-based and authority-based. An approaching deadline, disputed scope, unavailable evidence or unresolved ownership should move the request to senior compliance and legal review. That is an operating design recommendation, not a statement about the undisclosed content or deadline of AUSTRAC’s request to Cryptolink.
Connect reporting failure to business continuity
The three-month suspension turns mandatory reporting into an operating-access control. A VASP, payments or cash-conversion business should know how it would stop the affected service, preserve records, reconcile in-flight transactions and communicate the service state without creating new customer or accounting breaks.
A continuity test should identify who can disable transaction acceptance, how cash and unsettled transactions are reconciled, which vendors and locations must be notified, what evidence must remain available to the regulator and what conditions govern restart. These are control questions for the reader’s organisation. They are not claims about Cryptolink’s undisclosed continuity arrangements.
What AUSTRAC has not disclosed
The regulator’s announcement does not state how many threshold reports were missing, when the underlying transactions occurred, whether any reports were later filed, what information was requested, when a response was due or what Cryptolink must demonstrate before the suspension ends. It also does not quantify revenue, customer, cash or remediation effects.
Those gaps prevent a reliable estimate of financial loss or a detailed reconstruction of the control failure. They also make a current company response material. Until one is obtained, the article should retain regulator attribution and avoid conclusions about intent, root cause or the adequacy of Cryptolink’s present systems.
What AML/CTF control owners should verify now
- Rebuild the eligible population. Extract physical-currency transactions at or above A$10,000 and reconcile them to report records and acknowledgements.
- Test the deadline clock. Confirm the 10-business-day timer starts from the transaction day and that weekends, holidays and late source data cannot hide an approaching breach.
- Inspect exceptions. Review missing, rejected, corrected and duplicate reports by age, value, machine or location and named owner.
- Trace accountability. Confirm each system-generated report has an accountable person and retained evidence of review, submission and final status.
- Audit regulator requests. Test receipt capture, deadline escalation, evidence assembly, legal review, approval and proof of response.
- Exercise suspension continuity. Run a tabletop test for stopping the regulated service, reconciling in-flight activity, preserving evidence and controlling restart.
The control objective is not simply to show that a reporting system exists. It is to prove that the complete eligible population reached an accepted outcome on time, that every break had an owner and that a regulator request could not expire inside an ordinary operations queue.