Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · Australia

Payment-processing controls under Australia: the essentials

A payments firm processing remittances across the Asia-Pacific region flags an incoming transfer linked to a counterparty whose ultimate beneficial owner appears on Australia's consolidated autonomous sanctions list. The instruction has already passed through correspondent banking checks in two other jurisdictions. Now the compliance team must decide: does Australian law require a freeze, a report, or both? And what obligations attach to the payment processor specifically – not just the trade-finance bank?

Payment-processing controls under Australia's autonomous sanctions regime require any person or entity subject to Australian law to refuse to make a payment, transfer funds, or provide a financial service that is prohibited under the relevant thematic sanctions regulations administered by the Department of Foreign Affairs and Trade (DFAT). The obligation is strict, applies to direct and indirect dealings, and carries criminal penalties for breach. As of mid-2026, the regime sits under the Autonomous Sanctions Act and is enforced through a combination of DFAT oversight and referral to the Australian Federal Police.

This briefing sets out the governing authority, the specific prohibitions that affect payment processors and financial intermediaries, the ownership and control test, the licensing and reporting mechanics, and the points at which the Australian regime diverges from – or overlaps with – the US, UK, and UN positions that a cross-border operator will also need to satisfy.

Who administers Australia's payment-processing controls?

DFAT administers Australia's autonomous sanctions regime under the Autonomous Sanctions Act and the associated Autonomous Sanctions Regulations. Payment-processing prohibitions flow from thematic sanctions instruments targeting specific situations and individuals – each with its own list of designated persons and entities (the Consolidated List, maintained by DFAT and updated on a rolling basis).

DFAT holds responsibility for designating individuals and entities, maintaining the Consolidated List, issuing permits (Australia's equivalent of a specific licence), and publishing guidance on prohibited dealings. The Australian Federal Police and the Commonwealth Director of Public Prosecutions handle criminal referrals. There is no stand-alone financial-sanctions enforcement body comparable to OFSI in the UK; Australia's model is more prosecutorial in character.

This matters for payment processors in a practical sense. The absence of a dedicated civil-penalty regime – one comparable to OFAC's administrative process – means that enforcement in Australia tends to run toward criminal sanction rather than a negotiated monetary settlement. The risk calculus is therefore different from what US or UK-regulated firms may be used to.

In our cross-border practice, we regularly see firms that are comfortable with OFAC's civil-penalty structure but underestimate the criminal character of Australian enforcement. The two regimes are not interchangeable, and compliance programmes calibrated only to the US model may leave gaps under Australian law.

What does the prohibition on payment processing actually cover?

The core prohibition prevents a person from making an asset available – directly or indirectly – to or for the benefit of a designated person or entity. For a payment processor or financial intermediary, "making an asset available" encompasses initiating a payment, routing a transfer, settling an instruction, or providing access to clearing infrastructure where any designated person is the originator, beneficiary, or a party through whose account the funds pass.

The prohibition is not limited to payments that go directly to a listed name. Indirect dealings are equally caught. A payment that transits an account controlled by a designated entity, or that is intended for the ultimate benefit of a designated person even when routed through intermediaries, falls within the prohibition. This has particular relevance for correspondent banking chains and multi-leg remittance flows.

What else does the prohibition capture? It also covers the provision of financial services more broadly – opening accounts, processing letters of credit, extending credit facilities, and processing trade-finance instruments – where the underlying transaction involves a designated counterparty. Payment processors that handle only the settlement leg may consider themselves one step removed, but the statutory language does not distinguish between the payment-initiation and settlement functions.

A second limb of the prohibition covers dealing with assets that are owned or controlled by a designated person. This means that a processor that holds funds on behalf of a customer later found to be designated must freeze those funds rather than process an outgoing instruction. The obligation to freeze attaches at the point of knowledge or reasonable grounds for belief that the person is designated.

How does the ownership and control test work under Australian law?

Australia's sanctions regulations apply to entities that are owned or controlled by a designated person, not only to designated persons themselves – but the test differs in important respects from both the US and UK approaches, and understanding that difference is essential for a payment processor screening a corporate customer.

Under OFAC's rules, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in aggregate by blocked persons as themselves blocked) operates automatically: an entity crosses the threshold by mathematics alone, with no discretionary element. Under Australian law, the position is less mechanical. The relevant regulations use language that encompasses entities "owned or controlled" by a designated person, but DFAT's guidance indicates that control can be established through legal, financial, or operational means – not only through a shareholding threshold.

This has two practical consequences for screening. First, an entity that falls below a simple majority-ownership line may still be caught if a designated person exercises effective control through board composition, voting agreements, or operational management. Second, a payment processor cannot simply apply OFAC's 50 percent aggregation rule as a proxy and assume Australian compliance follows automatically. The populations of prohibited counterparties under the two regimes may overlap substantially, but they are not coextensive.

The EU ownership-and-control approach, applied under the relevant Council regulations, goes further still: it looks at the ability of a designated person to dominate economic decisions, not only formal shareholding. In our experience, a corporate customer that survives OFAC screening and EU screening may still require closer scrutiny under Australian law if a designated person holds a minority stake accompanied by contractual control rights. Cross-border payment processors operating in multiple jurisdictions must apply the strictest applicable test rather than assuming that passing one regime clears all others.

How does the permit and reporting mechanism operate?

Australia's mechanism for authorising otherwise-prohibited transactions is the permit – a specific written authorisation issued by the Minister for Foreign Affairs or a delegated official of DFAT. There is no standing general-permit system comparable to OFAC's general licences that automatically authorise broad categories of transaction; each Australian permit is case-specific.

A payment processor that identifies a proposed transaction touching a designated person and believes a ground for authorisation exists must apply to DFAT for a permit before the transaction is executed. Common grounds for permit applications include humanitarian necessity, enabling legal proceedings, or satisfying a pre-existing contractual obligation entered into before designation. DFAT assesses applications against the policy objectives of the relevant sanctions instrument, and processing times are not fixed by statute – they depend on the complexity and the operational urgency presented.

Separately, Australian law requires the reporting of certain dealings. A person who holds or controls assets belonging to a designated person has an obligation to report that holding to DFAT. For payment processors, this means that where frozen funds are held in a customer account following a sanctions hit, the firm must notify DFAT within the period specified in the applicable regulations. Failure to report is itself an offence independent of any failure to freeze.

If a transaction has already been flagged, or a payment instruction has been halted pending a compliance review, an early legal assessment can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss next steps.

Where does the Australian regime diverge from OFAC, OFSI, and the UN list?

A payment processor subject to multiple regimes simultaneously – which is typical for any firm operating in the Asia-Pacific corridor – must map the divergences rather than assume alignment. Three divergences are practically significant.

First, list coverage. Australia's Consolidated List does not replicate the UN Consolidated List in full, and it diverges from OFAC's SDN List in both directions: some persons appear on the Australian list but not OFAC's, and a significant number of OFAC-designated persons are not on Australia's list. A firm that screens only against OFAC lists and assumes UN coverage handles Australian obligations separately will miss this gap. All four lists must be screened independently.

Second, secondary-sanctions risk. OFAC operates a secondary-sanctions architecture under which non-US persons who engage in significant transactions with certain designated parties can themselves be designated or blocked from the US financial system. Australia does not operate a secondary-sanctions mechanism. However, a payment processor that is also active in the US market – or that uses US correspondent banking infrastructure – faces OFAC secondary-sanctions exposure even when a transaction has no direct US nexus beyond the use of dollar clearing. The two regimes must be managed together.

Third, enforcement character. As noted above, Australia's enforcement model is primarily criminal; OFAC's is primarily civil-administrative; OFSI in the UK operates a civil monetary-penalty regime alongside criminal referral. A voluntary self-disclosure (VSD – a proactive report of a potential breach to the relevant authority) carries different weight in each system. In the US, a VSD is a formal OFAC process with published aggravating and mitigating factors. In Australia, self-reporting to DFAT can inform prosecutorial discretion, but there is no published penalty-reduction matrix equivalent to OFAC's enforcement guidelines. Early legal advice on the appropriate disclosure route is therefore more important, not less, in the Australian context.

UN Security Council measures form the floor. Where the Security Council has imposed asset-freeze and dealing prohibitions, Australian law implements those measures through its own instruments. The Australian obligation is therefore additive to UN obligations, not a substitute. A payment processor must satisfy both.

What are the principal risk flags for payment processors operating under this regime?

Certain patterns recur in the payment-processing context as indicators of elevated sanctions risk under the Australian regime. Recognising them is the first step of an effective screening and monitoring programme.

Correspondent chain opacity is the most common. A payment processor that sees only its immediate counterparty – the sending or receiving bank – without access to the originator or beneficiary information in the underlying transaction cannot perform meaningful sanctions screening. Where MT 103 or ISO 20022 message data is incomplete or stripped, the processor faces both a sanctions-screening gap and a potential obligation breach if any undisclosed party is designated.

Beneficial-ownership gaps in corporate customers create a related risk. A payment processor onboarding a corporate client without resolving the ultimate beneficial-ownership chain to the level required by Australian anti-money-laundering rules may simultaneously be failing its sanctions-screening obligation. The two regimes interact: AML beneficial-ownership data feeds the sanctions check.

Jurisdictional routing patterns are a third indicator. Payments routed through jurisdictions subject to thematic Australian sanctions – using intermediary accounts or shell structures – may be structured to obscure a designated beneficiary. Processors should apply enhanced scrutiny to transactions where the payment route and the stated commercial purpose are inconsistent.

Currency and asset-type shifts also matter. The sanctions-related payment-processing prohibition in Australia is not limited to Australian-dollar transactions or transactions settled through Australian infrastructure. A firm processing a transaction in any currency that has a nexus to Australia – because the processor is incorporated in Australia, has a branch there, or is carrying on business there – is subject to Australian law regardless of the currency in which the payment is denominated.

The position above covers the standard compliance case. Your facts – the customer profile, the payment route, the jurisdictions involved, and the specific sanctions instruments in play – will change the analysis. For a review of your screening programme and its adequacy against the Australian regime, write to Calder & Vance at info@caldervance.com.

A common misconception: "We are not a bank, so sanctions do not fully apply to us"

In our experience, payment processors that are not deposit-taking institutions sometimes approach Australian sanctions obligations with the assumption that the full regime applies only to banks. That assumption is wrong, and it is among the more consequential misreadings of the regime we encounter.

The Autonomous Sanctions Act and the relevant thematic regulations impose obligations on "persons" – a term that encompasses natural persons and legal entities of any description, including licensed payment-service providers, digital-wallet operators, buy-now-pay-later platforms, and virtual-asset service providers (VASPs). The obligations are not gated by licensing status or by whether the entity holds a banking licence. If an entity provides a financial service or makes an asset available in connection with a payment, it is within scope.

This means that the prohibition on making assets available to designated persons applies equally to a payment processor handling the settlement leg of a transaction as it does to the originating bank. It applies to a VASP that converts fiat to a digital asset for a designated person. It applies to a foreign-exchange provider processing a remittance on behalf of a customer whose ultimate principal is designated. The regime is function-based, not entity-type-based.

We regularly advise non-bank payment firms that have previously operated without a formal sanctions programme on the grounds that they are "too small" or "not a regulated bank." Size and licensing category are not defences under Australian law. A well-tested compliance programme – calibrated to the payment-processing function specifically, not simply imported from a banking template – is the appropriate response.

When should a payment processor involve external sanctions counsel?

Certain situations in the payment-processing context warrant early involvement of external counsel, rather than internal escalation alone. Recognising those triggers is itself a compliance discipline.

A designated-person hit on a live transaction requires immediate legal assessment. The processor must decide within a short window whether to freeze, reject, or return the funds – and each option carries different regulatory implications. Acting without legal guidance risks either an unlawful payment on one side or an unlawful refusal on the other, depending on the complexity of the ownership and control analysis.

A permit application to DFAT is a legal proceeding in substance, even if it is not styled as one. The grounds for the application, the evidence marshalled in support, and the framing of the humanitarian or other basis require legal drafting. A poorly prepared permit application may be refused where a well-prepared one would succeed.

A potential breach – whether identified through an internal audit, a whistle-blower report, or a correspondent bank query – triggers the question of voluntary self-disclosure. As noted above, the Australian VSD position is less codified than OFAC's. Counsel should be involved before any approach is made to DFAT or to the Australian Federal Police, to ensure that the disclosure is appropriately scoped, accurately presented, and does not inadvertently expand the apparent violation.

Cross-regime exposure – where the same transaction may implicate OFAC, OFSI, and Australian rules simultaneously – requires coordinated advice across the relevant regimes. In our cross-border practice, we manage exactly this coordination, ensuring that a disclosure or a permit application in one jurisdiction does not create an adverse evidentiary record in another.

Related practices

Frequently asked questions

Who administers payment-processing controls under Australia?
The Department of Foreign Affairs and Trade (DFAT) administers Australia's autonomous sanctions regime, including the payment-processing prohibitions, under the Autonomous Sanctions Act and associated regulations. DFAT maintains the Consolidated List, issues permits for authorised dealings, and receives reports of frozen assets. Criminal enforcement is handled by the Australian Federal Police and the Commonwealth Director of Public Prosecutions, rather than through a dedicated financial-sanctions enforcement body.
What does Australia prohibit in relation to payment-processing controls?
Australian sanctions law prohibits any person from making an asset available – directly or indirectly – to or for the benefit of a designated person or entity. For payment processors, this covers initiating, routing, or settling a payment, providing access to clearing infrastructure, and processing trade-finance instruments where a designated counterparty is involved. A separate obligation requires freezing and reporting assets held for designated persons. The prohibition applies regardless of the currency in which the transaction is denominated.
How is payment-processing controls enforced under Australia?
Australia's sanctions regime is primarily criminal in enforcement character. Breach of a sanctions prohibition can result in criminal prosecution rather than the civil monetary penalty more familiar from OFAC or OFSI practice. There is no published penalty-reduction matrix for voluntary self-disclosure comparable to OFAC's enforcement guidelines. Firms considering self-reporting a potential breach to DFAT or the Australian Federal Police should take legal advice before doing so, to ensure the disclosure is appropriately scoped and presented.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.