MiCA Regulation (EU) 2023/1114 — In force since December 2024
VASP→CASP Transition Deadline: 1 July 2026
Offices in Düsseldorf · Vilnius · Tallinn
Free Initial Consultation

AML & KYC Requirements for Crypto Companies in the EU (2026)

AML and KYC requirements for crypto companies in the European Union

Every licensed crypto business in the EU is an obliged entity under anti-money-laundering law — and AML failings are the fastest route to losing a licence and banking relationships. This guide explains what an EU crypto AML/KYC programme must contain: customer due diligence, transaction monitoring, the Travel Rule, suspicious-activity reporting, and how the new EU AML package — the single rulebook (AMLR), AMLD6, and the new authority AMLA in Frankfurt — changes the bar.

Crypto Companies Are Obliged Entities

EU anti-money-laundering law designates crypto-asset service providers as obliged entities — the same category as banks and payment institutions. That brings the full weight of AML/CFT obligations: a documented risk-based programme, customer due diligence, ongoing monitoring, recordkeeping, and reporting to the national Financial Intelligence Unit.

AML is assessed both at authorization and continuously thereafter. A generic, off-the-shelf policy will not survive supervisory review — your programme must be tailored to your actual products, customers, and geographies.

Customer Due Diligence (KYC)

Customer due diligence is the foundation. A compliant CASP must:

  • Identify and verify every customer (and beneficial owners of corporate customers) before establishing a business relationship;
  • Understand the purpose and intended nature of the relationship;
  • Apply enhanced due diligence to higher-risk customers — politically exposed persons, high-risk jurisdictions, complex structures;
  • Apply CDD to occasional transactions at or above the regulatory threshold (€1,000 for crypto-asset transfers);
  • Keep customer information current through periodic review.

For crypto, identity verification increasingly pairs traditional KYC with blockchain analytics to assess the risk of the wallets a customer interacts with.

Ongoing Transaction Monitoring

You must monitor transactions throughout the relationship to detect activity that is inconsistent with what you know about the customer. For crypto this means screening both fiat and on-chain flows: sanctions and watchlist screening, wallet-risk scoring via blockchain analytics, and rules to flag structuring, mixing-service exposure, darknet links, and rapid in-out patterns.

Monitoring must be calibrated and documented. Alerts need a defined triage and escalation process, and you must be able to show a supervisor how thresholds were set and reviewed.

The Travel Rule

On top of CDD and monitoring, EU crypto firms must comply with the Travel Rule under the recast Transfer of Funds Regulation (EU) 2023/1113 — transmitting originator and beneficiary information with every CASP-to-CASP transfer, with no de minimis threshold, plus enhanced checks for self-hosted wallets above €1,000. We cover this in depth in our EU crypto Travel Rule guide.

Suspicious Activity Reporting & Recordkeeping

Where you know, suspect, or have reasonable grounds to suspect money laundering or terrorist financing, you must file a suspicious transaction/activity report with the national FIU — and not tip off the customer. You must keep CDD records and transaction data for the statutory retention period (generally five years) and make them available to authorities on request.

A designated compliance officer / MLRO owns this process. We cover that role in our MLRO guide.

The New EU AML Package — What's Changing

The EU adopted a major AML reform package in 2024 that reshapes the regime:

  • A directly applicable AML Regulation (AMLR) — a single rulebook harmonising CDD and obliged-entity duties across all member states;
  • The Sixth AML Directive (AMLD6) — institutional arrangements and FIU powers;
  • A new Anti-Money Laundering Authority (AMLA), headquartered in Frankfurt, which will coordinate national supervisors and directly supervise certain high-risk cross-border entities — crypto firms prominently among the candidates.

The package also introduces an EU-wide €10,000 cash payment limit. The practical message for crypto businesses: harmonised, stricter expectations and a powerful new EU-level supervisor. Build for that standard now.

Building a Supervisable AML Program

A credible CASP AML programme includes:

  • A business-wide ML/TF risk assessment;
  • Tailored policies, controls, and procedures approved by senior management;
  • KYC/CDD and onboarding workflows with verification tooling;
  • Transaction monitoring and blockchain analytics;
  • Travel Rule data flows;
  • A named MLRO and clear governance;
  • Training, independent testing, and recordkeeping.

This is exactly the scope of our AML/KYC service — built to pass supervisory review, not just to look complete on paper.

Frequently Asked Questions

Do EU crypto companies have to follow AML/KYC rules?
Yes. Crypto-asset service providers are obliged entities under EU anti-money-laundering law, with the same core duties as banks: a risk-based AML programme, customer due diligence (KYC), ongoing transaction monitoring, suspicious-activity reporting to the national FIU, recordkeeping, and Travel Rule compliance. AML is assessed at authorization and continuously afterwards.
What is the customer due diligence threshold for crypto?
CASPs must apply customer due diligence before establishing a business relationship and to occasional crypto-asset transactions at or above €1,000. Higher-risk customers — such as politically exposed persons or those linked to high-risk jurisdictions — require enhanced due diligence regardless of amount.
What is the new EU AML authority AMLA?
AMLA is the EU's new Anti-Money Laundering Authority, headquartered in Frankfurt, created by the 2024 AML reform package. It will coordinate national supervisors and directly supervise certain high-risk cross-border obliged entities, with crypto firms among the likely candidates, raising the supervisory bar across the EU.
Does a crypto company need an MLRO?
Yes. An obliged entity must appoint a compliance officer / Money Laundering Reporting Officer responsible for the AML programme, suspicious-activity reporting to the FIU, and liaison with supervisors. The role carries personal accountability and is assessed for fitness and propriety.
How long must crypto AML records be kept?
CDD records and transaction data must generally be retained for five years and made available to authorities on request. The exact retention and handling rules are being harmonised under the EU's single AML rulebook (AMLR).
Elena Fischer — AML/CFT Compliance Specialist
AML/CFT Compliance Specialist
Elena Fischer
Senior Compliance Advisor · Düsseldorf & Luxembourg

Elena Fischer builds AML/CFT programmes for crypto-asset service providers — risk assessments, KYC and customer due diligence, transaction monitoring, and Travel Rule controls — and prepares firms for supervisory review under the EU AML framework. Speak with our team →

Build an AML Program That Passes Review

We design risk-based AML/KYC programmes for CASPs — risk assessment, CDD, monitoring, Travel Rule, and MLRO support — calibrated to your business and ready for the new EU AML standard. Free 30-minute consultation.

Get an AML Program Built