Financial sector · Art. 3(2)

EU AML rules for Crypto-asset service providers

Crypto-asset service providers authorised under MiCA are obliged entities under the AMLR. You must apply harmonised CDD, travel-rule compliance, and reporting like other financial firms — plus crypto-specific rules.

In scope from

10 July 2027

345d left

Single Rulebook applies

10 July 2027

Underlying AMLR obligations for most sectors

Scope notes: Includes exchanges, custodians, and other CASPs under Regulation (EU) 2023/1114. Self-hosted wallet transactions have dedicated AMLR requirements.

Legal stack — what binds when

Which legal layers govern your AML programme at each stage — national law, EU regulations, EBA legacy instruments, and AMLA Level 2/3 as they are adopted. Not legal advice; national transposition varies.

Sector note: Travel-rule and self-hosted wallet rules add crypto-specific layers on top of standard financial-sector CDD and STR obligations.

Current era: Today — transitional period · EBA → AMLA substitution guide

You are herePassed

Today — transitional period

You are already an obliged entity under national AML law and EBA guidance. The AML Package is published; AMLA is drafting the Level 2 detail that will replace much of the EBA rulebook.

What binds (stacked layers)

BindingNational law

National AMLD5/6 transposition

Member State AML laws implementing the AML Directives — customer identification, STR, internal controls, and registration with your national supervisor.

Scope & governanceCustomer due diligenceSuspicious reportingInternal controls & MLROSupervision
Comply or explainEBA legacy

EBA AML guidelines (legacy)

Risk factors (EBA/GL/2021/02), remote onboarding (EBA/GL/2022/15), compliance officer role, and other EBA/joint ESA instruments. Under AMLA Regulation Art. 54, existing EBA AML/CFT guidelines and standards remain valid until AMLA formally replaces them.

Customer due diligenceSuspicious reportingInternal controls & MLROSupervision
Official source
BindingEBA legacy

EBA travel rule (Reg. 2023/1113)

EBA/GL/2024/11 on transfers of funds and crypto-assets — payer/payee information, deficient transfers, self-hosted wallets. Remains until AMLA Art. 40 guidelines replace it.

Customer due diligenceSuspicious reporting
Official source
Prepare onlyIn development

AMLA draft RTS / ITS / guidelines

Consultations and drafts from AMLA — not yet binding but signal the technical standards that will supersede EBA guidance. Respond if your systems or policies will need to change.

Customer due diligenceSuspicious reportingInternal controls & MLRO
Official source
Prepare onlyEU regulation

AMLR & AMLD6 (published, preparing)

Primary legislation is in force but core AMLR obligations for obliged entities apply from 10 July 2027 — use the text now to gap-assess policies and programmes.

Scope & governanceCustomer due diligenceSuspicious reportingInternal controls & MLRO
Official source
Upcoming345d left

From 10 July 2027 — Single Rulebook

AMLR applies directly. EBA instruments stay in force until AMLA replaces them instrument-by-instrument. Level 2 and Level 3 adoption continues on a rolling basis.

What binds (stacked layers)

BindingEU regulation

AMLR — Single Rulebook (direct effect)

Harmonised Level 1 obligations on CDD, PEPs, STR, internal controls, and record-keeping apply directly — no national gold-plating on core requirements.

Scope & governanceCustomer due diligenceSuspicious reportingInternal controls & MLRO
Official source
BindingEU directive

AMLD6 — supervision & FIU mechanisms

Member States transpose supervision arrangements, FIU cooperation, and beneficial ownership registers — affects who supervises you and how STRs are handled nationally.

SupervisionSuspicious reporting
Official source
Comply or explainEBA legacy

EBA instruments (until AMLA replaces)

Under AMLA Regulation Art. 54, existing EBA AML/CFT guidelines and standards remain valid until AMLA formally replaces them.

Replaced instrument-by-instrument as AMLA publishes successors

Customer due diligenceInternal controls & MLROSupervision
Migration guide
Not yet in forceAMLA Level 2

AMLA RTS & ITS (as adopted)

Legally binding technical detail on CDD fields, STR formats, supervisory methodologies, and crypto-specific rules — adoption is rolling from the July 2026 delivery wave onward.

Customer due diligenceSuspicious reportingInternal controls & MLROSupervision
Official source
BindingEU regulation

eIDAS 2.0 — EUDI Wallet & remote identification

AMLR Art. 22(6)(b) requires acceptance of substantial/high eIDAS electronic identification — wallets roll out from 2026; Art. 28(1) RTS will specify attributes and reliable sources.

Customer due diligence
Migration guide
Comply or explainAMLA Level 3

AMLA guidelines (as published)

Level 3 guidelines shape supervisory expectations — comply or explain for supervised entities.

Customer due diligenceSuspicious reportingInternal controls & MLRO
Official source
Not yet in forceAMLA Level 2

AMLA crypto mandates (Art. 37, 40)

CASP-specific CDD and self-hosted wallet mitigating measures — track adoption alongside core financial CDD RTS.

Customer due diligenceSuspicious reporting

Business-wide risk assessment

AMLR Art. 10 requires a documented BWRA using six mandatory information sources — including Annex I–III risk factors that also feed relationship-level CDD under Art. 20.

BWRA guide for CASP / Crypto

First steps before 10 July 2027

  1. 1Confirm MiCA authorisation and which CASP activities you perform (exchange, custody, etc.).
  2. 2Track crypto-specific mandates — travel rule, self-hosted wallets, and CASP CDD standards.
  3. 3Prepare for harmonised STR formats and supervisory expectations as AMLA adopts ITS.

Who supervises you?

Supervision varies by EU Member State and sector. Under AMLR Art. 62, AMLA will publish a register of national competent authorities; until that is live, use the European Commission's register of supervisors and FIUs to find who covers crypto-asset service providers in your country.

Priority mandates for your sector

13 instruments
GuidelinesIn developmentPassedAMLR Art. 9

Internal policies, procedures and controls — proportionality

Elements obliged entities should take into account — nature of business, risks, complexity and size — when deciding the extent of their internal policies, procedures and controls.

GuidelinesConsultation closed · draftingPassedAMLR Art. 10(4)

Business-wide risk assessment — minimum content

Minimum requirements for the content of the business-wide risk assessment and the additional information sources to take into account when carrying it out.

Why it matters: Your BWRA will be measured against this baseline from July 2027.

RTSConsultation closed · draftingPassedAMLR Art. 19(9)

Business relationships, occasional and linked transactions

Criteria for identifying business relationships, occasional and linked transactions, and lower thresholds where simplified or enhanced CDD applies.

GuidelinesIn developmentPassedAMLR Art. 20

Risk variables and risk factors for CDD

Risk variables and risk factors obliged entities must weigh when entering business relationships or carrying out occasional transactions.

Why it matters: Successor to the EBA risk factors guidelines — your customer risk model will need to map to this taxonomy.

GuidelinesConsultation openPassedAMLR Art. 26(5)

Ongoing monitoring of business relationships

Expectations for ongoing monitoring of business relationships and of the transactions carried out within them.

RTSConsultation closed · draftingPassedAMLR Art. 28(1)

Customer due diligence — information requirements

The information obliged entities must collect and verify for standard, simplified and enhanced CDD, including sectoral adjustments.

Why it matters: The operational core of the Single Rulebook — defines what every onboarding and KYC file must contain across the EU.

ITSConsultation openPassedAMLR Art. 69

Suspicious transaction reporting format

The format to be used for reporting suspicions and providing transaction records to FIUs.

Why it matters: STR/SAR workflows and transaction-monitoring outputs must produce this harmonised format.

GuidelinesIn development345d leftAMLR Art. 69

Indicators of suspicious activity or behaviour

Indicators of suspicious activity or behaviours, to be periodically updated.

Why it matters: A living reference for transaction-monitoring scenario design and SAR decision-making.

GuidelinesIn development345d leftAMLR Art. 42

Politically exposed persons

Criteria for identifying close associates and the level of risk associated with particular categories of PEPs, family members and close associates.

GuidelinesIn development345d leftAMLR Art. 50

Reliance on other obliged entities

Acceptable conditions for relying on CDD information collected by another obliged entity — including remote CDD — and the roles and responsibilities involved.

GuidelinesIn development345d leftAMLR Art. 37

CASP cross-border correspondent relationships

Criteria and elements crypto-asset service providers must take into account when assessing correspondent relationships and the corresponding risk-mitigating measures.

GuidelinesIn development345d leftAMLR Art. 40

Self-hosted address transactions — mitigating measures

Mitigating measures for transfers from or to self-hosted addresses, including identification and verification of the originator or beneficiary.

Why it matters: Directly shapes CASP wallet-screening and travel-rule operations.

RTSSubmitted to CommissionPassedAMLD6 Art. 40(2)

Risk profile assessment of obliged entities

Harmonised methodology for supervisors to assess and classify the inherent and residual ML/TF risk profile of obliged entities.

Why it matters: Determines how intensively your firm will be supervised — the same scoring logic will apply in every Member State.

All rules for this sectorAMLR Art. 3 on EUR-Lex

This page is an independent orientation guide — not legal advice. National transposition and exemptions may apply. Always verify scope against the official AMLR text and your supervisor.