Crypto Companies Are Obliged Entities
EU anti-money-laundering law designates crypto-asset service providers as obliged entities — the same category as banks and payment institutions. That brings the full weight of AML/CFT obligations: a documented risk-based programme, customer due diligence, ongoing monitoring, recordkeeping, and reporting to the national Financial Intelligence Unit.
AML is assessed both at authorization and continuously thereafter. A generic, off-the-shelf policy will not survive supervisory review — your programme must be tailored to your actual products, customers, and geographies.
Customer Due Diligence (KYC)
Customer due diligence is the foundation. A compliant CASP must:
- Identify and verify every customer (and beneficial owners of corporate customers) before establishing a business relationship;
- Understand the purpose and intended nature of the relationship;
- Apply enhanced due diligence to higher-risk customers — politically exposed persons, high-risk jurisdictions, complex structures;
- Apply CDD to occasional transactions at or above the regulatory threshold (€1,000 for crypto-asset transfers);
- Keep customer information current through periodic review.
For crypto, identity verification increasingly pairs traditional KYC with blockchain analytics to assess the risk of the wallets a customer interacts with.
Ongoing Transaction Monitoring
You must monitor transactions throughout the relationship to detect activity that is inconsistent with what you know about the customer. For crypto this means screening both fiat and on-chain flows: sanctions and watchlist screening, wallet-risk scoring via blockchain analytics, and rules to flag structuring, mixing-service exposure, darknet links, and rapid in-out patterns.
Monitoring must be calibrated and documented. Alerts need a defined triage and escalation process, and you must be able to show a supervisor how thresholds were set and reviewed.
The Travel Rule
On top of CDD and monitoring, EU crypto firms must comply with the Travel Rule under the recast Transfer of Funds Regulation (EU) 2023/1113 — transmitting originator and beneficiary information with every CASP-to-CASP transfer, with no de minimis threshold, plus enhanced checks for self-hosted wallets above €1,000. We cover this in depth in our EU crypto Travel Rule guide.
Suspicious Activity Reporting & Recordkeeping
Where you know, suspect, or have reasonable grounds to suspect money laundering or terrorist financing, you must file a suspicious transaction/activity report with the national FIU — and not tip off the customer. You must keep CDD records and transaction data for the statutory retention period (generally five years) and make them available to authorities on request.
A designated compliance officer / MLRO owns this process. We cover that role in our MLRO guide.
The New EU AML Package — What's Changing
The EU adopted a major AML reform package in 2024 that reshapes the regime:
- A directly applicable AML Regulation (AMLR) — a single rulebook harmonising CDD and obliged-entity duties across all member states;
- The Sixth AML Directive (AMLD6) — institutional arrangements and FIU powers;
- A new Anti-Money Laundering Authority (AMLA), headquartered in Frankfurt, which will coordinate national supervisors and directly supervise certain high-risk cross-border entities — crypto firms prominently among the candidates.
The package also introduces an EU-wide €10,000 cash payment limit. The practical message for crypto businesses: harmonised, stricter expectations and a powerful new EU-level supervisor. Build for that standard now.
Building a Supervisable AML Program
A credible CASP AML programme includes:
- A business-wide ML/TF risk assessment;
- Tailored policies, controls, and procedures approved by senior management;
- KYC/CDD and onboarding workflows with verification tooling;
- Transaction monitoring and blockchain analytics;
- Travel Rule data flows;
- A named MLRO and clear governance;
- Training, independent testing, and recordkeeping.
This is exactly the scope of our AML/KYC service — built to pass supervisory review, not just to look complete on paper.