The previous article on DORA compliance addressed technology resilience. This part examines the EU AML/KYC baseline, which combines national implementation of anti-money-laundering duties with directly applicable crypto-transfer rules. (Directive (EU) 2015/849, Arts. 2, 13, 33, 67; Regulation (EU) 2023/1113, Arts. 14, 16, 40.)
Summary
- Crypto AML compliance starts with the firm's activities and applicable national law. Directive (EU) 2015/849 covers the relevant crypto-asset service providers as financial institutions. The new AML Regulation generally applies from 10 July 2027. (Directive (EU) 2015/849, Arts. 2(1)(2), 3(2)(g), 3(19), 5; Regulation (EU) 2024/1624, Art. 90.)
- Customer due diligence applies when establishing a business relationship, regardless of its first transaction's value. It requires customer and beneficial-owner checks, an understanding of the relationship, and ongoing monitoring. (Directive (EU) 2015/849, Arts. 11(a), 13–14.)
- The firm must assess its risks and apply enhanced measures where required. Simplified checks depend on demonstrated lower risk and national permission; monitoring remains necessary. (Directive (EU) 2015/849, Arts. 8, 15, 18–20.)
- In-scope crypto transfers require originator and beneficiary information without a general minimum-value exemption. Transfers exceeding EUR 1,000 to or from a self-hosted address trigger an additional ownership-or-control assessment. (Regulation (EU) 2023/1113, Arts. 2, 14, 16.)
- Sanctions controls require a separate decision process. Transfer screening must address the applicable restrictions and resolve potential matches before assets are released where required. (Regulation (EU) 2023/1113, Art. 23; EBA/GL/2024/15, paras. 19–22, 34–38, 49.)
- Knowledge, suspicion or reasonable grounds for suspicion require prompt reporting to the financial intelligence unit. Attempted transactions are included. The firm must observe transaction-restraint and non-disclosure duties. (Directive (EU) 2015/849, Arts. 33, 35, 39.)
- AML records must preserve the customer checks and transaction evidence. Staff training, assigned responsibilities and testing must support the firm's actual controls. Retention periods and national extensions require separate treatment. (Directive (EU) 2015/849, Arts. 8(4)–(5), 40, 46; Regulation (EU) 2023/1113, Art. 26.)
Scope and applicable law
Current crypto AML regulations impose duties through national law and directly applicable EU transfer rules. Member States implement Directive (EU) 2015/849, which classifies the relevant crypto-asset service providers, or CASPs, as financial institutions. Its CASP definition excludes providing crypto advice alone. Another covered activity or stricter national legislation can still bring that business within AML duties. The scope assessment must therefore identify the firm's actual services and establishments. (Directive (EU) 2015/849, Arts. 2(1)(2), 3(2)(g), 3(19), 4–5, 48(4); Regulation (EU) 2023/1113, Art. 38.)
Regulation (EU) 2023/1113, the Transfer of Funds Regulation, has applied since 30 December 2024. Its crypto-transfer rules operate alongside customer due diligence. Regulation (EU) 2024/1624, the new AML Regulation, generally applies from 10 July 2027. Its future occasional-transaction requirements must not be used as the current basis for customer checks. Firms should maintain separate implementation dates for existing duties and the 2027 requirements. (Regulation (EU) 2023/1113, Arts. 1, 40; Regulation (EU) 2024/1624, Arts. 19(3), 90.)
The applicable EBA guidelines state supervisory expectations, and their recipients must make every effort to comply. They do not replace the legislation. Relevant EBA AML guidelines continue to apply until replacement AMLA guidelines on the same subject start to apply. (EBA/GL/2024/15, status paras. 1–2; Regulation (EU) 2024/1620, Art. 54(5).)
Customer checks before service
The firm must apply customer due diligence when establishing a business relationship. A relationship expected to have duration meets the Directive's definition even if the first deposit is small. Suspicion and doubts about existing identification data independently trigger checks. For occasional transactions, Article 11(b)(i) sets a general EUR 15,000 threshold, including apparently linked operations. The separate funds-transfer threshold does not establish a general crypto KYC exemption below EUR 1,000. National rules and the crypto-transfer duties must also be applied. (Directive (EU) 2015/849, Arts. 3(13), 5, 11(a)–(b), (e)–(f); Regulation (EU) 2023/1113, Arts. 14, 16.)
Customer due diligence requires identification and verification using reliable, independent documents, data or information. The firm must assess the purpose and intended nature of the relationship and monitor it throughout its duration. The customer record should explain the expected activity against which later transactions will be assessed. An identity document alone leaves the relationship-purpose and monitoring duties unfinished. Remote verification is permitted through the identification means and processes recognised in Article 13(1)(a); a remote process must still satisfy that verification requirement. (Directive (EU) 2015/849, Art. 13(1)–(4).)
Verification normally precedes the relationship or transaction. Member States may permit completion during establishment where necessary to avoid interrupting normal business and where money-laundering or terrorist-financing risk is low. Completion must then follow as soon as practicable. A separate national option permits account opening with safeguards preventing transactions until the required identity checks are complete. The firm's account states and transaction permissions should reflect the particular exception it can lawfully use. (Directive (EU) 2015/849, Art. 14(1)–(3).)
Where the firm cannot complete customer identification, beneficial-owner verification or the assessment of the relationship's purpose, Article 14(4) requires refusal of the relevant transaction or relationship, or termination of an existing relationship. The firm must also consider a suspicious transaction report. Failure to provide a document does not automatically establish the separate reporting threshold; the reporting decision must assess the facts under Article 33. (Directive (EU) 2015/849, Arts. 13(1)(a)–(c), 14(4), 33.)
Beneficial owners and representatives
Corporate onboarding must establish the natural persons who ultimately own or control the customer, subject to the exception for companies listed on a regulated market with disclosure requirements consistent with EU law or equivalent international standards ensuring adequate transparency of ownership information. The Directive treats 25% plus one share, or an ownership interest exceeding 25%, as an indication of ownership. Control through other means remains relevant, and Member States may use lower percentages. A procedure that stops after checking shareholders above 25% can therefore miss a controlling individual. The firm must take reasonable measures to verify beneficial owners and understand the ownership and control structure. (Directive (EU) 2015/849, Arts. 3(6)(a), 13(1)(b).)
The senior-managing-official fallback has conditions. The firm must first exhaust all possible means of identifying the beneficial owner, with no grounds for suspicion. The firm may use that fallback only if no beneficial owner is identified or doubt remains about the person identified. The firm must retain the actions taken and verify the relevant official's identity. Naming a director cannot cure an unexplained ownership structure before those conditions are met. Trusts require identification of the relevant settlors, trustees, protectors, beneficiaries or beneficiary class, and other ultimate controllers under their separate definition. (Directive (EU) 2015/849, Arts. 3(6)(a)(ii), 3(6)(b), 13(1)(b), (6).)
Anyone acting for the customer must be identified, verified and authorised to act. For entities and arrangements subject to beneficial-ownership registration, the firm must obtain the required registration evidence when starting a new relationship. It cannot rely exclusively on the central register to fulfil due diligence. The onboarding record should connect the ownership evidence, representative's authority and verification result to the customer account. (Directive (EU) 2015/849, Arts. 13(1), final subparagraph, 14(1), 30(8), 31(6).)
Risk assessment and enhanced checks
The firm's assessment must address customers, geography, products, services, transactions and delivery channels. It must be current and available to the relevant authority. Article 8(2) permits an authority to dispense with an individual documented assessment where the sector's specific risks are clear and understood; the firm cannot grant itself that dispensation. Otherwise, the written assessment should explain how the services offered create risks and which controls address them. (Directive (EU) 2015/849, Art. 8(1)–(3).)
Enhanced due diligence applies to the prescribed cases and other identified higher-risk situations. Simplified measures require an identified lower degree of risk and permission under national law. Even then, the firm must monitor sufficiently to detect unusual or suspicious activity. A lower-risk classification must therefore affect the extent of checks through an authorised procedure, while preserving the applicable identification and monitoring duties. (Directive (EU) 2015/849, Arts. 13(2)–(4), 15–16, 18(1).)
Relationships or transactions involving Commission-designated high-risk third countries require the measures in Article 18a. They include additional customer and beneficial-owner information, transaction reasons, source of funds and wealth, senior-management approval and enhanced monitoring. Article 18(1) retains specific risk-based treatment for branches or majority-owned subsidiaries in those countries of obliged entities established in the EU. Those branches or subsidiaries must comply fully with the group-wide policies and procedures required by Article 45. The firm must apply the legal country designation and relevant exception, rather than treating every foreign customer identically. (Directive (EU) 2015/849, Arts. 9(2), 18(1), 18a, 45.)
Source-of-funds enquiries under ordinary ongoing monitoring apply where necessary. The prescribed enhanced regimes can require more. For a higher-risk crypto relationship, supporting records should explain how the customer acquired the assets being used and resolve inconsistencies with the declared activity. The EBA's crypto guidance identifies source-of-assets evidence and more frequent reviews among the measures selected according to the risk. These are distinct from assuming that every customer must prove their entire wealth before any transaction. (Directive (EU) 2015/849, Arts. 13(1)(d), 18; EBA/GL/2021/02, as amended by EBA/GL/2024/01, paras. 21.12(c)–(f).)
Politically exposed persons
The firm must determine whether a customer or beneficial owner is a politically exposed person, or PEP. For a PEP relationship, the prescribed measures include senior-management approval, adequate measures to establish source of wealth and funds, and enhanced ongoing monitoring. Relevant family members and known close associates are also covered. The procedure should identify the applicable public function or connection, the approval decision and the enquiries made. PEP status triggers enhanced treatment under these provisions; it does not itself prohibit the relationship. (Directive (EU) 2015/849, Arts. 3(9)–(11), 20, 23.)
Leaving office does not immediately end the required treatment. The firm must consider the continuing risk for at least 12 months and apply appropriate risk-sensitive measures until the person poses no further PEP-specific risk. A screening system that removes the classification automatically on the departure date would fail to apply that continuing assessment. (Directive (EU) 2015/849, Art. 22.)
Transaction monitoring and self-hosted addresses
The firm must compare activity with its knowledge of the customer, business and risk profile, and keep due-diligence information current. Existing customers require review at appropriate risk-sensitive times, when relevant circumstances change and on the further triggers in Article 14(5). Monitoring should connect fiat movements, crypto transactions and the customer's explanation where those records concern the same activity. This connection implements the duty to assess whether transactions fit the known relationship. (Directive (EU) 2015/849, Arts. 13(1)(d), 14(5).)
Article 18(2) requires examination, as far as reasonably possible, when a transaction meets any one of four conditions: complexity, unusual size, an unusual pattern, or no apparent economic or lawful purpose. The firm must examine its background and purpose and increase monitoring to assess suspicion. An alert should lead to a recorded assessment of the relevant condition, available explanation and reporting threshold. The law does not require all four conditions to occur together. (Directive (EU) 2015/849, Arts. 18(2), 33.)
Transfers involving self-hosted addresses require a specific assessment of money-laundering and terrorist-financing risk. Article 19a requires measures commensurate with that risk. Available measures include risk-based identification and identity verification of the other party or beneficial owner, further origin-and-destination information and enhanced ongoing monitoring. The firm should record which risk prompted which measure. Self-hosting alone does not establish that every transfer is prohibited or that the other address holder must become a customer. (Directive (EU) 2015/849, Art. 19a(1).)
The EBA's crypto guidance calls for suitable monitoring tools and risk-sensitive advanced analytics. A firm should combine the resulting transaction history and risk indicators with customer information when assessing an alert. The guidance also calls for specialised staff training on crypto risks. A blockchain risk score therefore needs an operational procedure that identifies what staff must examine and when to escalate. (EBA/GL/2021/02, as amended by EBA/GL/2024/01, paras. 21.11–21.13; Directive (EU) 2015/849, Arts. 13(1)(d), 18(2), 33.)
Transfer information and other providers
The Travel Rule requires a separate transfer-information process for transactions within Regulation 2023/1113. For a transfer between CASPs, the sending provider must obtain and transmit the prescribed originator and beneficiary information and verify its originator. The required information must travel securely before or with the transfer; it need not be recorded on-chain. The receiving CASP must detect missing information and verify its beneficiary before making assets available. Existing compliant identity verification can satisfy the relevant verification conditions. These duties have no general minimum-value exemption; the Regulation's express scope exclusions still apply. (Regulation (EU) 2023/1113, Arts. 2, 14, 16.)
For transfers to or from a self-hosted address, the CASP must obtain and retain the prescribed information and identify the transfer individually. Where the amount exceeds EUR 1,000, it must take adequate measures to assess whether its customer owns or controls that address. The threshold governs that additional assessment, while the information duties and separate risk-based measures continue below it. (Regulation (EU) 2023/1113, Arts. 14(5), 16(2); Directive (EU) 2015/849, Art. 19a.)
Missing or incomplete information requires a risk-sensitive decision without undue delay: reject or return the transfer, or request the information before releasing assets. Repeated failures require further action concerning the other provider and a report to the competent authority. Missing data is also a factor in assessing whether a suspicious transaction report is needed. Staff must distinguish that assessment from the separate report about a provider's repeated failures. (Regulation (EU) 2023/1113, Arts. 17–18.)
Cross-border correspondent relationships with providers outside the EU attract further checks under Article 19b. These concern registration or licensing, business and reputation, supervision, AML controls, senior-management approval and the parties' respective responsibilities. Payable-through crypto accounts require further assurance about the respondent's customer checks and access to the relevant data. Those requirements attach to the defined correspondent relationship; an isolated transfer does not establish that relationship by itself. (Directive (EU) 2015/849, Arts. 3(8), 19b(1).)
Sanctions screening
Article 23 of Regulation 2023/1113 requires internal policies, procedures and controls for implementing EU and national restrictive measures. The EBA guidelines applicable from 30 December 2025 address screening customers, beneficial owners, representatives and transfer parties. They also cover relevant wallet addresses appearing on official restrictive-measures lists. Screening should incorporate newly obtained transfer information and a process for resolving possible matches. The applicable restrictions determine whether the firm must freeze assets, withhold a service or take another action. (Regulation (EU) 2023/1113, Art. 23; EBA/GL/2024/15, implementation para. 8, operative paras. 15–22, 34–38, 49.)
A potential screening match requires examination before it is treated as a confirmed designation. The firm should record the identifying information used, the reason for the decision and any referral to the competent authority. Where a restriction applies, an AML risk rating cannot authorise conduct that the restriction prohibits. A suspicious transaction report must also be considered on its own legal threshold; filing it does not perform the required sanctions action. (EBA/GL/2024/15, paras. 31–38, 49–51; Directive (EU) 2015/849, Art. 33.)
Suspicion reports and customer communications
The firm must promptly inform the financial intelligence unit, or FIU, when it knows, suspects or has reasonable grounds to suspect the relevant criminal proceeds or terrorist financing. The amount does not determine that duty, and attempted suspicious transactions must also be reported. Procedures must give staff a route to the reporting function and preserve the facts supporting the decision. Waiting for proof of the underlying offence would impose a higher threshold than Article 33 requires. (Directive (EU) 2015/849, Art. 33(1)–(2).)
The firm must refrain from carrying out a transaction it knows or suspects is connected with criminal proceeds or terrorist financing until it has taken the required reporting action and followed applicable authority instructions. If restraint is impossible or likely to frustrate efforts to pursue the suspected operation's beneficiaries, the FIU must be informed immediately afterwards. The operational procedure must apply the relevant national instructions and distinguish that exception from ordinary processing convenience. (Directive (EU) 2015/849, Art. 35.)
The firm, its directors and employees must not tell the customer or other third parties about the report or relevant AML analysis. Article 39 permits specified disclosures to authorities and certain qualifying institutions or group entities. Customer-support messages and information requests must preserve that boundary. Staff should be able to explain an account restriction without disclosing protected reporting or analysis information. (Directive (EU) 2015/849, Art. 39(1)–(5).)
Records, responsibilities and control testing
The Directive requires retention of necessary customer-due-diligence records and supporting transaction evidence for five years after the relationship ends or the occasional transaction occurs. National law may permit or require further retention under the prescribed conditions, for no more than five additional years. The Travel Rule separately requires five-year retention of its specified information, with a conditional national extension. The firm's retention schedule must identify the legal category, starting event and applicable extension. (Directive (EU) 2015/849, Art. 40(1); Regulation (EU) 2023/1113, Art. 26(1)–(2).)
Customer records must remain retrievable after a transaction is complete. They should connect the verified person, beneficial owner, risk assessment, transfer and subsequent investigation or reporting decision. The EBA guidance says that a CASP should not rely on the distributed ledger alone to discharge recordkeeping duties. Personal data collected under the transfer rules must not be repurposed for commercial use. (Directive (EU) 2015/849, Arts. 8(2), 13, 40; EBA/GL/2021/02, as amended by EBA/GL/2024/01, para. 21.16; Regulation (EU) 2023/1113, Art. 25(2).)
Senior management must approve AML policies and controls. The Directive requires a management-level compliance officer and an independent audit function where appropriate to the business's size and nature. Employees require ongoing training on recognising relevant activity and responding to it. The firm should test whether customer permissions, enhanced-check approvals, alerts and reporting decisions follow those procedures, with defects assigned for correction. (Directive (EU) 2015/849, Arts. 8(4)–(5), 46(1), (4).)
Control failures and enforcement
National authorities enforce the implementing AML duties and can require relevant records and perform checks. The Directive requires sanctions for serious, repeated or systematic failures in customer due diligence, reporting, records and internal controls. Available measures include orders to cease the breach and, where applicable, suspension or withdrawal of authorisation. Financial penalties and individual responsibility depend on the governing national provisions. A remediation decision should identify the failed duty, affected customers or transactions, corrective action and the records that demonstrate completion. (Directive (EU) 2015/849, Arts. 48(1)–(3), 58–60.)
