Financial sector · Art. 3(2)
EU AML rules for Crypto-asset service providers
Crypto-asset service providers authorised under MiCA are obliged entities under the AMLR. You must apply harmonised CDD, travel-rule compliance, and reporting like other financial firms — plus crypto-specific rules.
In scope from
10 July 2027
Single Rulebook applies
10 July 2027
Underlying AMLR obligations for most sectors
Scope notes: Includes exchanges, custodians, and other CASPs under Regulation (EU) 2023/1114. Self-hosted wallet transactions have dedicated AMLR requirements.
Legal stack — what binds when
Which legal layers govern your AML programme at each stage — national law, EU regulations, EBA legacy instruments, and AMLA Level 2/3 as they are adopted. Not legal advice; national transposition varies.
Sector note: Travel-rule and self-hosted wallet rules add crypto-specific layers on top of standard financial-sector CDD and STR obligations.
Current era: Today — transitional period · EBA → AMLA substitution guide
Today — transitional period
You are already an obliged entity under national AML law and EBA guidance. The AML Package is published; AMLA is drafting the Level 2 detail that will replace much of the EBA rulebook.
What binds (stacked layers)
National AMLD5/6 transposition
Member State AML laws implementing the AML Directives — customer identification, STR, internal controls, and registration with your national supervisor.
EBA AML guidelines (legacy)
Risk factors (EBA/GL/2021/02), remote onboarding (EBA/GL/2022/15), compliance officer role, and other EBA/joint ESA instruments. Under AMLA Regulation Art. 54, existing EBA AML/CFT guidelines and standards remain valid until AMLA formally replaces them.
EBA travel rule (Reg. 2023/1113)
EBA/GL/2024/11 on transfers of funds and crypto-assets — payer/payee information, deficient transfers, self-hosted wallets. Remains until AMLA Art. 40 guidelines replace it.
AMLA draft RTS / ITS / guidelines
Consultations and drafts from AMLA — not yet binding but signal the technical standards that will supersede EBA guidance. Respond if your systems or policies will need to change.
AMLR & AMLD6 (published, preparing)
Primary legislation is in force but core AMLR obligations for obliged entities apply from 10 July 2027 — use the text now to gap-assess policies and programmes.
From 10 July 2027 — Single Rulebook
AMLR applies directly. EBA instruments stay in force until AMLA replaces them instrument-by-instrument. Level 2 and Level 3 adoption continues on a rolling basis.
What binds (stacked layers)
AMLR — Single Rulebook (direct effect)
Harmonised Level 1 obligations on CDD, PEPs, STR, internal controls, and record-keeping apply directly — no national gold-plating on core requirements.
AMLD6 — supervision & FIU mechanisms
Member States transpose supervision arrangements, FIU cooperation, and beneficial ownership registers — affects who supervises you and how STRs are handled nationally.
EBA instruments (until AMLA replaces)
Under AMLA Regulation Art. 54, existing EBA AML/CFT guidelines and standards remain valid until AMLA formally replaces them.
Replaced instrument-by-instrument as AMLA publishes successors
AMLA RTS & ITS (as adopted)
Legally binding technical detail on CDD fields, STR formats, supervisory methodologies, and crypto-specific rules — adoption is rolling from the July 2026 delivery wave onward.
eIDAS 2.0 — EUDI Wallet & remote identification
AMLR Art. 22(6)(b) requires acceptance of substantial/high eIDAS electronic identification — wallets roll out from 2026; Art. 28(1) RTS will specify attributes and reliable sources.
AMLA guidelines (as published)
Level 3 guidelines shape supervisory expectations — comply or explain for supervised entities.
AMLA crypto mandates (Art. 37, 40)
CASP-specific CDD and self-hosted wallet mitigating measures — track adoption alongside core financial CDD RTS.
Business-wide risk assessment
AMLR Art. 10 requires a documented BWRA using six mandatory information sources — including Annex I–III risk factors that also feed relationship-level CDD under Art. 20.
BWRA guide for CASP / CryptoFirst steps before 10 July 2027
- 1Confirm MiCA authorisation and which CASP activities you perform (exchange, custody, etc.).
- 2Track crypto-specific mandates — travel rule, self-hosted wallets, and CASP CDD standards.
- 3Prepare for harmonised STR formats and supervisory expectations as AMLA adopts ITS.
Who supervises you?
Supervision varies by EU Member State and sector. Under AMLR Art. 62, AMLA will publish a register of national competent authorities; until that is live, use the European Commission's register of supervisors and FIUs to find who covers crypto-asset service providers in your country.
Priority mandates for your sector
13 instrumentsInternal policies, procedures and controls — proportionality
Elements obliged entities should take into account — nature of business, risks, complexity and size — when deciding the extent of their internal policies, procedures and controls.
Business-wide risk assessment — minimum content
Minimum requirements for the content of the business-wide risk assessment and the additional information sources to take into account when carrying it out.
Why it matters: Your BWRA will be measured against this baseline from July 2027.
Business relationships, occasional and linked transactions
Criteria for identifying business relationships, occasional and linked transactions, and lower thresholds where simplified or enhanced CDD applies.
Risk variables and risk factors for CDD
Risk variables and risk factors obliged entities must weigh when entering business relationships or carrying out occasional transactions.
Why it matters: Successor to the EBA risk factors guidelines — your customer risk model will need to map to this taxonomy.
Ongoing monitoring of business relationships
Expectations for ongoing monitoring of business relationships and of the transactions carried out within them.
Customer due diligence — information requirements
The information obliged entities must collect and verify for standard, simplified and enhanced CDD, including sectoral adjustments.
Why it matters: The operational core of the Single Rulebook — defines what every onboarding and KYC file must contain across the EU.
Suspicious transaction reporting format
The format to be used for reporting suspicions and providing transaction records to FIUs.
Why it matters: STR/SAR workflows and transaction-monitoring outputs must produce this harmonised format.
Indicators of suspicious activity or behaviour
Indicators of suspicious activity or behaviours, to be periodically updated.
Why it matters: A living reference for transaction-monitoring scenario design and SAR decision-making.
Politically exposed persons
Criteria for identifying close associates and the level of risk associated with particular categories of PEPs, family members and close associates.
Reliance on other obliged entities
Acceptable conditions for relying on CDD information collected by another obliged entity — including remote CDD — and the roles and responsibilities involved.
CASP cross-border correspondent relationships
Criteria and elements crypto-asset service providers must take into account when assessing correspondent relationships and the corresponding risk-mitigating measures.
Self-hosted address transactions — mitigating measures
Mitigating measures for transfers from or to self-hosted addresses, including identification and verification of the originator or beneficiary.
Why it matters: Directly shapes CASP wallet-screening and travel-rule operations.
Risk profile assessment of obliged entities
Harmonised methodology for supervisors to assess and classify the inherent and residual ML/TF risk profile of obliged entities.
Why it matters: Determines how intensively your firm will be supervised — the same scoring logic will apply in every Member State.
This page is an independent orientation guide — not legal advice. National transposition and exemptions may apply. Always verify scope against the official AMLR text and your supervisor.