Australia's financial intelligence and regulatory agency AUSTRAC ordered an external compliance audit of Airwallex on 22 January 2026, citing suspected weaknesses in the Melbourne-headquartered fintech's anti-money laundering and counter-terrorism financing controls. The order subjects Airwallex to an independent review of its compliance infrastructure at a moment when the company has been rapidly expanding its cross-border payments business across multiple international markets, raising questions about whether its compliance capabilities have kept pace with its commercial growth.

AUSTRAC's audit order covers three specific areas of Airwallex's compliance programme: customer due-diligence processes, transaction-monitoring systems, and suspicious-matter reporting procedures. These are the foundational pillars of any AML/CTF framework, and deficiencies in any one of them can create material exposure to financial crime risk. The agency's decision to mandate an external reviewer rather than rely solely on the company's internal assurance indicates the seriousness with which it is treating the suspected shortcomings identified during its supervisory work.

SCOPE OF THE AUDIT AND AIRWALLEX'S RESPONSE

The external audit will be conducted by an independent compliance specialist appointed under AUSTRAC's regulatory framework. Airwallex stated in response to the order that it is cooperating fully with the process and that it has made significant investments in its compliance infrastructure in recent periods. The company's public posture was one of constructive engagement rather than dispute, acknowledging the audit while seeking to reassure clients and partners that it takes its regulatory obligations seriously and intends to work openly with both the auditor and the agency throughout the review.

Airwallex operates as a registered reporting entity under Australian AML/CTF legislation, which obliges it to maintain robust systems for identifying customers, monitoring transactions for suspicious activity, and reporting to AUSTRAC when it identifies matters of concern. As a company whose core business involves facilitating high-volume, multi-currency payments for business clients across borders, the adequacy of these controls is directly material to its operating licence and to its relationships with the correspondent banking partners whose infrastructure underpins its cross-border capabilities.

REGULATORY CONTEXT AND INDUSTRY IMPLICATIONS

AUSTRAC has in recent years demonstrated a willingness to take significant enforcement action against financial services firms where compliance failings are identified, including landmark cases against major banks and money transfer operators. The agency's use of an audit order in Airwallex's case is a regulatory tool that sits below a formal enforcement action in terms of severity, but it carries meaningful consequences: the audit findings will be reported to AUSTRAC, and if material weaknesses are confirmed, they could form the basis for further regulatory intervention or remediation requirements.

For the broader fintech sector in Australia, the Airwallex audit is a reminder that scale and growth do not exempt digital payments companies from the compliance obligations that apply equally to traditional banks. AUSTRAC has signalled consistently that its supervisory attention extends across the full spectrum of registered reporting entities, and that the pace of a fintech's commercial expansion does not reduce the standard expected of its compliance function or its obligations under the law.

Airwallex has not disclosed a timeline for the completion of the audit or indicated when findings might be communicated to regulators or the market. The company is expected to continue normal operations during the review period, as AUSTRAC's order does not constitute a suspension or restriction of its authorisation to conduct business in Australia.