AMLR for crypto: what crypto-asset service providers must verify
From 10 July 2027 the AMLR treats crypto-asset service providers as financial institutions. What they must verify, the EUR 1,000 threshold, what Article 79 prohibits, and what it does not: self-hosted wallets are not banned.

In short
AMLR crypto rules in short: from 10 July 2027 the EU Anti-Money Laundering Regulation (AMLR) will treat every crypto-asset service provider (CASP) as a financial institution. A CASP will have to identify and verify each customer, even for a one-off transaction below EUR 1,000, and may not keep anonymous accounts.[1]
- Full customer due diligence starts at account opening, or at an occasional transaction of EUR 1,000. Below EUR 1,000, the CASP still identifies the customer and verifies the identity.
- Anonymity-enhancing coins are off limits for providers. Self-hosted wallets are not banned.
- Self-hosted transfers need a risk assessment and a mitigating measure.
Headlines say the EU is banning privacy coins and self-custody. The text of Regulation (EU) 2024/1624 is narrower than that, and more demanding than a EUR 1,000 threshold. This guide quotes the articles that bind a CASP and shows where the Markets in Crypto-Assets Regulation (MiCA) and the Transfer of Funds Regulation (TFR) take over.
The AMLR is in force but does not apply yet: until 10 July 2027 the national laws that transpose the current directive apply.[1][12] For the whole regulation, start with AMLR explained.
AMLR crypto scope: a CASP is a financial institution
Article 3 lists three groups of obliged entities: credit institutions, financial institutions, and a set of professions and traders. Crypto has no line of its own. CASPs sit in the second group, because the definition of financial institution in Article 2(1)(6) includes "a crypto-asset service provider".[1]
The AMLR takes the meaning of CASP from MiCA, Regulation (EU) 2023/1114, and counts a provider "where performing one or more crypto-asset services". One service is carved out: "providing advice on crypto-assets".[1] So a CASP owes what any financial institution owes, plus a few crypto-specific rules.
The Council said the regulation extends the rules to "most of the crypto-sector",[10] and the Anti-Money Laundering Authority (AMLA) lists "certain crypto-asset service providers" among the newly covered entities.[13] Neither says every crypto firm is covered for the first time in 2027. Other categories are in the AMLR checklist by type of obliged entity.
| Trigger | What the CASP must do | Source |
|---|---|---|
| Account opening | Full customer due diligence | Art. 19(1)(a) |
| Occasional transaction of EUR 1,000 or more | Full customer due diligence | Art. 19(3)(a) |
| Occasional transaction below EUR 1,000 | At least identify the customer and verify the identity | Art. 19(3)(b) |
| Transfer to or from a self-hosted address | Assess the risk and apply one or more mitigating measures | Art. 40(1) |
| Self-hosted transfer exceeding EUR 1,000 | Assess whether the originator or beneficiary owns or controls the address | TFR Arts. 14(5), 16(2) |
Articles of the AMLR unless marked TFR.[1][2]
The EUR 1,000 threshold is not a KYC-free allowance
For most obliged entities an occasional transaction triggers customer due diligence (CDD) at EUR 10,000.[1] For CASPs the line is EUR 1,000, and a second rule sits under it.
Article 19(3)Regulation (EU) 2024/1624
"(a) apply customer due diligence measures when carrying out an occasional transaction that amounts to a value of at least EUR 1 000 [...]; (b) apply at least customer due diligence measures referred to in Article 20(1), point (a), when carrying out an occasional transaction where the value is below EUR 1 000"
Source: EUR-Lex, Regulation (EU) 2024/1624[1]
Article 20(1), point (a), is "identifying the customer and verifying the customer's identity". So a CASP runs that Know Your Customer (KYC) step for every occasional transaction, whatever the amount. From EUR 1,000 the other CDD measures apply too: beneficial owners, purpose and intended nature, the sanctions check, the politically exposed person (PEP) determination and ongoing monitoring.[1]
Under Article 22 the identity is verified by an identity document, or by electronic identification (eID) at assurance level substantial or high and relevant qualified trust services. If due diligence cannot be completed, the CASP must refrain from the transaction and consider a report to the financial intelligence unit (FIU).[1]
AMLA's final draft regulatory technical standards (RTS) on CDD, dated 30 September 2026, treat eID as the default remote route and document-based remote verification as an alternative the obliged entity must justify.[4][5] They are a final draft sent to the Commission: not adopted, not law. See AMLR identity verification and AMLA's final standards.
Occasional or ongoing
AMLA's final draft RTS under Article 19(9) adds no lower thresholds. For certain CASPs it uses "carrying out three or more transactions within the last 12 months" as a repetition criterion, the sign of a business relationship, and "a period of one month" for linking transactions.[3] It is also a draft the Commission has not adopted.
Article 79: anonymous accounts and anonymity-enhancing coins
This is the article behind the "privacy coin ban" headlines.
Article 79(1)Regulation (EU) 2024/1624
"Credit institutions, financial institutions and crypto-asset service providers shall be prohibited from keeping anonymous bank and payment accounts, anonymous passbooks, anonymous safe-deposit boxes or anonymous crypto-asset accounts as well as any account otherwise allowing for the anonymisation of the customer account holder or the anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins."
Source: EUR-Lex, Regulation (EU) 2024/1624[1]
The article binds credit institutions, financial institutions and CASPs, and the prohibited act is keeping accounts. The coins appear as one way of anonymising them, and Article 2(1)(25) defines them as "crypto-assets that have built-in features designed to make crypto-asset transfer information anonymous, either systematically or optionally".[1] The regulation never says "privacy coins", and "optionally" brings in assets whose anonymity feature is a setting.
The article does not regulate individuals who hold such assets. Recital 160 also draws a line around tools: "That prohibition does not apply to providers of hardware and software or providers of self-hosted wallets insofar as they do not possess access to or control over those crypto-asset wallets."[1] A recital is not an operative article, but it shows where the prohibition was meant to stop.
Owners and beneficiaries of existing anonymous accounts "shall be subject to customer due diligence measures before those accounts, passbooks, or deposit boxes are used in any way".[1]
| Common claim | What the text says | Source |
|---|---|---|
| "The AMLR bans privacy coins" | It prohibits providers from keeping accounts that allow anonymisation, "including through anonymity-enhancing coins". It does not regulate individuals who hold them. | Art. 79(1)[1] |
| "Self-hosted wallets are banned" | Providers of self-hosted wallets without access to or control over the wallets are outside the prohibition. | Recital 160[1] |
| "A CASP may not send to a self-hosted address" | Such transfers need a risk assessment and one or more mitigating measures. Not a ban. | Art. 40[1] |
| "AMLA has published the final rules" | AMLA finalised drafts. They bind only after Commission adoption and publication in the Official Journal. | AMLA[5] |
Self-hosted addresses and correspondent relationships: the enhanced measures
Enhanced due diligence applies in the cases listed in Articles 36 to 46, among others.[1] Two are written for CASPs: correspondent relationships (Article 37) and transfers involving self-hosted addresses (Article 40).
Article 40(1)Regulation (EU) 2024/1624
"shall identify and assess the risk [...] associated with transfers of crypto-assets directed to or originating from a self-hosted address"
Source: EUR-Lex, Regulation (EU) 2024/1624[1]
The mitigating measures "shall include one or more of the following": risk-based measures to identify and verify the originator or beneficiary of the transfer, additional information on the origin and destination of the crypto-assets, enhanced ongoing monitoring, or any other measure.[1] A neighbouring rule is already in force. Under Articles 14(5) and 16(2) of the TFR, for a transfer "exceeding EUR 1 000" to or from a self-hosted address the CASP "shall take adequate measures to assess whether that address is owned or controlled by" the originator or beneficiary.[2]
AMLA must issue guidelines on these measures by 10 July 2027.[1] We found no draft on AMLA's site as of 2 October 2026,[6] so their content is not yet known.
For correspondent relationships, Article 37 requires a CASP, on top of the measures that apply to other financial institutions, to "determine if the respondent entity is licensed or registered" and to update its information "on a regular basis or when new risks emerge". Under Article 39, CASPs "shall ensure that their accounts are not used by shell institutions".[1]
For financial institutions the sanctions check is repeated "upon any new designation in relation to targeted financial sanctions",[1] and AMLA's final draft RTS extends screening to "digital wallet addresses" where the lists include them.[4]
AMLR for crypto next to MiCA and the travel rule
Three EU regulations meet in a CASP's onboarding and transfer flows. Each answers a different question.
Anti-money laundering duties
AMLR
- Due diligence, monitoring, reporting and records
- Prohibits anonymous accounts
- Applies from 10 July 2027
Regulation (EU) 2024/1624
Transfers
TFR, the travel rule
- Transfers of funds and crypto-assets
- Ownership check on self-hosted addresses above EUR 1,000
- Already in force
Regulation (EU) 2023/1113
Who is a CASP
MiCA
- Defines the crypto-asset service provider
- The AMLR borrows that definition, minus advice
- Outside the four-act package the AMLR names
Regulation (EU) 2023/1114
What each regulation governs for a CASP.[1][2]
The AMLR names its own package: with the directive, the TFR and the regulation that creates AMLA, it forms "the legal framework governing the AML/CFT requirements to be met by obliged entities".[1] MiCA is not in that list. For what MiCA and the travel rule require, see our guides to the MiCA compliance stack for CASPs and the travel rule for EU crypto providers. Until AMLA's own instruments take over, the European Banking Authority's Travel Rule Guidelines continue to apply.[6]
A CASP onboarding and a first transfer, step by step
The flow follows one retail customer from account opening to a first withdrawal.
1The customer opens an account
A business relationship is established, so due diligence applies. Article 19(1)(a).
2Identify and verify
The Article 22 data set, verified by eID or by an identity document.
3Screen and decide
Sanctions, PEP status, purpose. The risk profile and the onboarding decision stay with the CASP. Articles 20(1) and 18(3).
Is the first transfer going to a self-hosted address
Apply Article 40
Assess the risk and apply a mitigating measure. Above EUR 1,000, assess who owns or controls the address.
Transfer to another provider
The travel rule in the TFR governs the transfer.
4Monitor and keep the record
Ongoing monitoring under Article 26. Records kept for 5 years after the relationship ends.
Onboarding and a first transfer at a CASP under the AMLR and the TFR.[1][2]
What follows the first transfer is covered in ongoing monitoring under Article 26.
AMLA direct supervision and large cross-border CASPs
AMLA will not supervise every CASP. From 2028 it will directly supervise a selected group,[8] and national supervisors keep their role for everyone else.[11]
Eligible are credit and financial institutions and groups that operate "in at least six Member States, including the home Member State" and whose residual risk profile "has been classified as high". If more than 40 qualify in the first round, AMLA takes "the 40 obliged entities or groups operating in the highest number of Member States". The first selection starts by 1 July 2027.[7]
Not yet known
CASPs are financial institutions under the AMLR, so on our reading a CASP group active in six or more Member States is within reach of this selection. Whether any will be selected is not known: AMLA expected the provisional list of eligible entities "to be finalised by end-September 2026",[9] and we found no published list as of 2 October 2026.
A selected group would answer to AMLA, whose basic fine for serious CDD breaches found in two or more Member States is "at least EUR 500 000".[7] For other CASPs national penalties apply. For financial institutions the national maximum must be at least EUR 10,000,000 or 10 % of total annual turnover.[12] Either way, obliged entities "shall at all times be able to demonstrate to their supervisors that the measures taken are appropriate in view of the risks".[1] More in our guide to AMLA.
How Didit helps a CASP meet these duties
Didit supplies the checks and the evidence for the duties above in one workflow, priced per check. The article by article map is on the AMLR solution page, and the integration steps are in the AMLR guide in the docs.
Identity verification covers 220+ countries and territories, and a full KYC check costs $0.33. For the eID route, the digital ID wallets in production include MitID, Smart-ID and BankID Sweden. EUDI Wallet support is coming soon. AML screening covers 1,300+ sanctions, PEP and watchlists at $0.20 per check, and ongoing monitoring re-screens daily for $0.07 per person per year.
Transaction monitoring runs real-time rules for fiat and crypto, with alerts, case management and FIU report preparation. Wallet screening sits inside it. Travel rule messaging is described on the crypto travel rule page, and other prices are on the pricing page.
Didit does not take over the CASP's decisions. Under Article 18 the obliged entity "shall remain fully liable", and six tasks can never be outsourced.[1] See AMLR Article 18: what you can outsource.
Didit provides
- Identity checks by digital ID wallet or by document
- Sanctions, PEP and watchlist screening, re-screened daily
- Transaction monitoring with wallet screening
- Prepared FIU reports and the evidence of every check
Stays with you
- The risk assessment, the policies and their approval
- The customer risk profile and the onboarding decision
- Approval of the criteria that detect suspicious transactions
- Filing reports with the financial intelligence unit, and the liability
Verify crypto customers and screen their transfers in one workflow
Set up identity verification, screening and transaction monitoring with wallet screening, and pay per check.
Key takeaways
- Under the AMLR a CASP is a financial institution. The rules apply from 10 July 2027.
- A CASP identifies and verifies every occasional customer. Full due diligence starts at EUR 1,000.
- Article 79 bars providers from keeping anonymous accounts. Self-hosted wallets are not banned.
Frequently asked questions
Does the AMLR ban privacy coins?
Not in general. Article 79(1) prohibits credit institutions, financial institutions and CASPs from keeping accounts that allow anonymisation, including through anonymity-enhancing coins. It does not regulate individuals who hold such assets.
Are self-hosted wallets banned under the AMLR?
No. Recital 160 puts providers of self-hosted wallets without access to or control over the wallets outside the Article 79 prohibition. A CASP must still assess the risk of transfers to or from a self-hosted address under Article 40.
Do CASPs have to verify customers for transactions under EUR 1,000?
Yes. Article 19(3) requires full customer due diligence from EUR 1,000, and at least identification and verification of the customer below EUR 1,000.
When do the AMLR crypto rules apply?
From 10 July 2027. Until then the national laws that transpose the current directive apply. The Transfer of Funds Regulation is already in force.
What must a CASP do when a customer sends crypto to a self-hosted address?
Assess the risk and apply one or more of the mitigating measures in Article 40(1), such as identifying the beneficiary or enhanced ongoing monitoring. Above EUR 1,000, the Transfer of Funds Regulation also requires adequate measures to assess whether the originator or beneficiary owns or controls the address.
What is the difference between the AMLR, MiCA and the travel rule?
MiCA defines what a crypto-asset service provider is. The AMLR takes that definition and sets the anti-money laundering duties, from customer due diligence to the prohibition of anonymous accounts. The Transfer of Funds Regulation covers transfers of funds and crypto-assets.
Will AMLA supervise crypto exchanges directly?
Only those that are selected. From 2028 AMLA will directly supervise a limited group of credit and financial institutions active in at least six Member States with a high residual risk profile, capped at 40 in the first round. All other CASPs stay with their national supervisor.
Can a CASP outsource customer verification to a provider?
Yes, within limits. Article 18 allows outsourcing, but the obliged entity remains fully liable. Six tasks can never be outsourced, including the onboarding decision and reporting to the financial intelligence unit.
Sources
- Regulation (EU) 2024/1624 (AMLR), EUR-Lex, Official Journal of 19 June 2024.
- Regulation (EU) 2023/1113 (TFR, transfers of funds and crypto-assets), EUR-Lex.
- Final Report, draft RTS under Article 19(9) AMLR, AMLA, announced 1 October 2026.
- Final Report, draft RTS under Article 28(1) AMLR, AMLA, 30 September 2026.
- AMLA finalises key standards for the private sector, AMLA press release, 1 October 2026.
- Regulatory instruments tracker, AMLA, last update 30 September 2026.
- Regulation (EU) 2024/1620 (the AMLA regulation), EUR-Lex.
- AMLA takes major step toward harmonised EU supervision, AMLA.
- AMLA takes next step toward 2027 selection of entities for direct supervision, AMLA.
- Anti-money laundering: Council adopts package of rules, Council of the EU, 30 May 2024.
- Frequently asked questions, AMLA.
- Directive (EU) 2024/1640 (AMLD6), EUR-Lex.
- AMLA consults on draft guidelines on ongoing monitoring of business relationships, AMLA, 3 June 2026.
The requirement by requirement map, with the article behind each check, is on the AMLR solution page.
Build your crypto onboarding flow ahead of the AMLR
Configure the checks your risk assessment calls for and keep the evidence of each one.
Related articles
- The EU's EUR 10,000 cash limit from July 2027: who it binds
- AMLR software: what to build, what to buy and what it costs
- AMLR identity verification: eID first, documents as the alternative
- AMLR and the EUDI Wallet: when you must accept it, and what is left
- AMLR checklist by obliged entity, with the article behind every line
- AMLR beneficial ownership: the 25% rule, control and worked examples