XregOS · MiCACompliance OS · MiCA
← Blog2026-07-29

AMLR 2027 crypto changes: CASP requirements from July 2027

Regulation (EU) 2024/1624 (the Anti-Money Laundering Regulation, AMLR) applies from 10 July 2027. Crypto-asset service providers authorized under MiCA become obliged entities under the AMLR on that date. The regulation replaces the Fourth, Fifth, and Sixth Anti-Money Laundering Directives with directly applicable Union law. A CASP must implement customer due diligence, beneficial ownership verification, transaction monitoring, and reporting to financial intelligence units before the application date.

What the AMLR replaces

The AMLR consolidates and replaces Directives (EU) 2015/849, (EU) 2018/843, and (EU) 2024/1640 (the Fourth, Fifth, and Sixth Anti-Money Laundering Directives). Member states transposed those directives into national law with divergent thresholds, exemptions, and procedural requirements. The AMLR is a regulation and applies uniformly across the European Economic Area without transposition. A CASP operating in multiple member states faces one set of rules rather than 30 implementations.

The Transfer of Funds Regulation (Regulation (EU) 2023/1113, TFR) remains in force and applies in parallel. The TFR governs originator and beneficiary information in crypto-asset transfers. The AMLR governs customer identification, risk assessment, ongoing monitoring, and suspicious transaction reporting. Both apply to CASPs from 10 July 2027.

Who is an obliged entity

Article 3 AMLR defines obliged entities. Paragraph 3(j) names crypto-asset service providers as defined in Article 3(1)(15) of Regulation (EU) 2023/1114. A firm authorized under MiCA to provide one or more of the services listed in Section A of Annex I MiCA is an obliged entity. The obligation applies whether the CASP holds a full authorization or operates under a transitional registration.

Issuers of asset-referenced tokens and e-money tokens are obliged entities under Article 3(3)(k) AMLR if they offer services directly to the public. An issuer that distributes only through authorized intermediaries may not be directly subject to customer due diligence obligations, but the intermediary CASP is.

A non-EU firm providing services into the EEA without authorization is not an obliged entity under the AMLR because it is not a lawful CASP. Such a firm commits an infringement of Article 59 MiCA. The AMLR does not regulate unlawful actors; member state enforcement targets the infringement itself.

Customer due diligence requirements from 10 July 2027

Article 15 AMLR requires obliged entities to apply customer due diligence measures when establishing a business relationship, carrying out an occasional transaction above EUR 1,000, or suspecting money laundering or terrorist financing. For a CASP, establishing a business relationship means onboarding a client for custody, exchange, or order execution services.

Customer due diligence comprises four elements under Article 16 AMLR:

  1. Identifying the customer and verifying identity using reliable, independent source documents, data, or information.
  2. Identifying the beneficial owner and taking reasonable measures to verify identity, including understanding the ownership and control structure.
  3. Assessing and obtaining information on the purpose and intended nature of the business relationship.
  4. Conducting ongoing monitoring of the business relationship, including scrutinizing transactions to ensure consistency with knowledge of the customer.

A CASP must complete identification and verification before permitting the customer to transact. Article 18 AMLR permits a derogation to complete verification during establishment of the relationship if the risk of money laundering or terrorist financing is low, and it is necessary not to interrupt the normal conduct of business. A CASP relying on this derogation must complete verification as soon as practicable and suspend the relationship if verification cannot be completed.

You can verify whether a firm holds CASP authorization and is therefore subject to these obligations from 10 July 2027 at /verify.

Beneficial ownership verification

Article 16(3) AMLR defines the beneficial owner of a legal entity as the natural person who ultimately owns or controls the entity, directly or indirectly. A CASP must identify the beneficial owner when onboarding a corporate customer. The beneficial owner is the natural person who holds more than 25% of the shares or voting rights, or who otherwise exercises control over the management of the entity.

If no natural person holds more than 25%, the beneficial owner is the natural person who controls the entity through other means. If no natural person is identified under either criterion, the beneficial owner is the natural person who holds the position of senior managing official.

A CASP must obtain the name, date of birth, nationality, and residential address of each beneficial owner. For legal entities established in a member state, the CASP may rely on information in the national beneficial ownership register established under Article 11 of Directive (EU) 2024/1640. The AMLR does not replace the beneficial ownership register provisions; those remain in national law until a Union register is established under Regulation (EU) 2024/1620.

Where a beneficial owner is resident in a third country and no reliable register is available, the CASP must obtain equivalent identity verification documents and retain copies.

Transaction monitoring and risk assessment

Article 16(4) AMLR requires ongoing monitoring of the business relationship. A CASP must scrutinize transactions to ensure they are consistent with the knowledge obtained of the customer, the business relationship, and the risk profile. Monitoring must be sufficient to detect unusual or suspicious transactions.

Article 9 AMLR requires obliged entities to assess the risks of money laundering and terrorist financing to which they are exposed. The assessment must take into account risk factors relating to customers, countries, products, services, transactions, and delivery channels. A CASP must document the risk assessment and make it available to the competent supervisory authority.

The risk assessment determines the extent of customer due diligence measures. Article 19 AMLR permits simplified due diligence where the CASP has established that the risk of money laundering or terrorist financing is low. Article 20 requires enhanced due diligence in higher-risk situations, including relationships with politically exposed persons, correspondent relationships with third-country institutions, and transactions involving high-risk third countries listed under Article 30.

A CASP providing custody or operating a trading platform must integrate transaction monitoring into the technical infrastructure. The regulation does not prescribe monitoring thresholds or algorithms, but the system must flag patterns inconsistent with the customer's stated purpose, transaction history, or risk profile.

Reporting obligations to financial intelligence units

Article 69 AMLR requires obliged entities to report to the national financial intelligence unit (FIU) when they know, suspect, or have reasonable grounds to suspect that funds are the proceeds of criminal activity or are related to terrorist financing. The report must be made promptly and must not exceed five working days from the formation of the suspicion.

A CASP authorized in one member state and providing services across the EEA under the passport reports to the FIU of its home member state. The home FIU coordinates with FIUs in host member states where necessary. A CASP operating branches in multiple member states reports to the home FIU, which disseminates relevant information to host FIUs through the FIU.net system established under Council Decision 2000/642/JHA.

Article 70 AMLR prohibits tipping off. A CASP must not disclose to the customer or any third party that a suspicious transaction report has been submitted or that a money laundering or terrorist financing investigation is being or may be carried out. The prohibition applies to all employees, directors, and agents of the CASP.

Article 71 requires the CASP to refrain from carrying out a suspicious transaction before submitting the report, unless refraining is impossible or likely to frustrate efforts to pursue the beneficiaries of a suspected money laundering or terrorist financing operation. Where the transaction is carried out before the report, the CASP must inform the FIU immediately afterward.

Timeline for CASPs

DateObligation
10 July 2027AMLR applies; CASPs become obliged entities
10 July 2027Customer due diligence, beneficial ownership verification, and transaction monitoring required for all new business relationships
10 July 2027Suspicious transaction reporting to the national FIU required
10 July 2027Ten-year record retention requirement begins for all records created on or after this date
1 July 2027AMLA may assume direct supervision of selected CASPs (list not yet published)

A CASP authorized before 10 July 2027 must apply the AMLR to all existing customers. Article 16(4) AMLR requires ongoing monitoring of all business relationships, not only those established after the application date. A CASP must review its customer base and apply customer due diligence to relationships established before 10 July 2027 on a risk-sensitive basis. High-risk customers, PEPs, and customers for whom the CASP holds incomplete identification records must be prioritized.

The AMLR does not prescribe a deadline for completing retroactive due diligence. The supervisory authority expects a CASP to have completed the review within a reasonable period, typically interpreted as 12 to 24 months. A CASP that identifies a customer it cannot verify must terminate the business relationship or, where the customer does not cooperate with updated due diligence requests, submit a suspicious transaction report.

Supervision and enforcement

Article 88 AMLR designates competent authorities to supervise obliged entities. For CASPs, the competent authority is the same authority that supervises the CASP under MiCA. In most member states, this is the financial services supervisor or central bank. You can confirm which authority supervises CASPs in a specific member state by checking the register at /registry.

The supervisory authority may conduct on-site inspections, require production of documents, and impose administrative sanctions for infringements. Article 118 AMLR lists administrative sanctions, including public warnings, temporary prohibition of individuals from exercising management functions, and administrative pecuniary sanctions up to 10% of total annual turnover or EUR 5,000,000, whichever is higher.

For natural persons, the maximum administrative pecuniary sanction is EUR 1,000,000 or, where the infringement generated a profit, twice the amount of the profit.

Article 5 of Regulation (EU) 2024/1620 (the Anti-Money Laundering Authority Regulation) establishes the Anti-Money Laundering Authority (AMLA). AMLA begins operations on 1 July 2025 and assumes direct supervision of selected obliged entities from 1 July 2027. The list of directly supervised entities is not yet published. CASPs operating in multiple member states or with high-risk profiles may be designated for direct supervision by AMLA, in which case the national competent authority ceases to be the direct supervisor for AML purposes but remains the MiCA supervisor.

FAQ

Does the AMLR apply to CASPs operating under transitional registration?

Yes. Article 3(3)(j) AMLR names crypto-asset service providers as defined in MiCA. A CASP operating under Article 143 MiCA transitional registration is a CASP and becomes an obliged entity on 10 July 2027.

Must a CASP apply due diligence to customers onboarded before 10 July 2027?

Yes. Article 16(4) AMLR requires ongoing monitoring of all business relationships. A CASP must review existing customers on a risk-sensitive basis and complete due diligence where records are incomplete. Supervisors expect the review to be completed within 12 to 24 months.

Does a CASP report to one FIU or to the FIU in each member state where it provides services?

A CASP reports to the FIU of its home member state. The home FIU coordinates with host FIUs through FIU.net. A CASP does not submit separate reports to each host member state.

What is the retention period for customer due diligence records?

Article 55 AMLR requires ten years from the end of the business relationship or the date of the occasional transaction. Member states may require longer periods for specific record types.

Does the AMLR replace the Transfer of Funds Regulation?

No. The TFR remains in force. The AMLR governs customer identification and monitoring; the TFR governs originator and beneficiary information in transfers. Both apply to CASPs from 10 July 2027.