Financial crime compliance
The EU's AML Reset Is the Operating System for Crypto
MiCAR controls entry. AMLR, the Travel Rule and AMLA shape the evidence an authorised firm must produce every day.
The 2027 deadline is only part of the timetable. The crypto Travel Rule is already live, AMLA is writing the supervisory detail and the first direct-supervision selection begins in 2027.
The calendar before the theory
The anti-money-laundering package is often presented as a 10 July 2027 deadline. That date is central because the AMLR generally starts applying and the new national mechanisms are due to be in place.12
Work has already moved. Regulation (EU) 2023/1113 brought the crypto Travel Rule into application on 30 December 2024. AMLA began building its operating functions in 2025 and spent 2026 developing technical standards and guidelines on customer due diligence, group controls, business-wide risk assessment and ongoing monitoring.456
The first direct-supervision selection takes place in 2027. Supervision of the selected population begins in 2028. A firm that waits for the AMLR application date will arrive with policies drafted against legislation but systems built against older practice.
| Date | Milestone | Operational Effect |
|---|---|---|
| 30 Dec 2024 | Crypto Travel Rule applies | Transfer data, counterparty handling and self-hosted-address controls are live |
| 2025-2026 | AMLA develops technical instruments | CDD, monitoring, group and supervisory detail is being specified |
| 10 Jul 2027 | AMLR generally applies | Core private-sector duties become directly applicable |
| 2027 | First direct-supervision selection | Eligible cross-border entities are assessed under the common methodology |
| 2028 | AMLA direct supervision starts | Up to 40 selected entities or groups enter joint EU-level supervision |
AMLA changes the method
AMLA does not replace CySEC, BaFin, AMF or the other national supervisors. Most firms will continue to answer to a national authority.
The new authority still changes the method. It writes standards, coordinates supervisors, supports colleges, conducts peer review and can act where national supervision is ineffective. It also supports financial intelligence units, while suspicious transaction reports continue to go to the competent national FIU.37
Up to 40 financial institutions or groups will enter direct supervision from 2028. Eligibility requires activity in at least six Member States; selection then turns on residual money-laundering and terrorist-financing risk after controls are considered.89
In cross-border reviews I see a recurring problem: the group can describe its control framework, but it cannot reproduce the same customer, monitoring or alert data from each entity. AMLA's model will make that inconsistency harder to defend.
Article 79 and self-hosted addresses
Article 79 prohibits covered credit institutions, financial institutions and CASPs from keeping anonymous crypto-asset accounts, including accounts that allow anonymisation of the holder or increased obfuscation of transactions through anonymity-enhancing coins.1
The legal target is the institutional account or service. An individual does not commit an offence under Article 79 merely by holding a privacy-enhancing asset in a wallet they control. Software or hardware that gives the provider no access or control also falls outside the account-keeping prohibition.
The commercial effect for a CASP can still be severe. The firm has to assess whether custody, transfer, exchange or trading-platform functionality permits the prohibited anonymity. MiCAR already requires platform rules to address crypto-assets with inbuilt anonymisation functions unless holders and transaction history can be identified.10
Self-hosted wallets follow a separate logic. For transfers involving a self-hosted address, the CASP gathers the prescribed originator or beneficiary information and ensures the transfer can be individually identified. Above EUR 1,000, in the circumstances specified by the Regulation, it must assess whether the address is owned or controlled by its customer.411
“The regime closes anonymous services inside regulated firms. It does not outlaw personal custody.”
Travel Rule evidence is already being created
The Travel Rule applies to covered crypto transfers regardless of amount. The originating and beneficiary information accompanies the transfer, and the receiving provider needs risk-based procedures for missing or incomplete data.411
That process produces evidence beyond the message itself. Counterparty identity, customer profile, wallet address and on-chain transaction can be analysed together. A provider that stores the payload but does not use it in risk assessment or monitoring misses much of the regulatory value.
Interoperability remains uneven. Protocols differ, some counterparties return incomplete fields and third-country implementation varies. The control objective is a consistent decision process with protected personal data, documented exceptions and a clear escalation route.
Monitoring is wider than alerts
AMLA's 2026 draft guidance treats ongoing monitoring as a continuing review of the business relationship. Transaction alerts are one component. The customer profile, source and destination of value, wallet exposure, product use and changes in activity also have to inform the risk view.13
Automated systems can prioritise lower-risk outputs, but the model needs an explainable logic, documented limitations and effective human review. A low score cannot close a case where the available information points to suspicion.
For a CASP, the useful view joins on-chain and off-chain data. Device and geographic signals, fiat movements, sanctions exposure, Travel Rule data and customer records often sit in separate tools. The supervisory problem appears at the join.
A 2026 implementation file
The implementation programme should be managed as evidence, not a policy rewrite. Six workstreams are enough to expose whether the firm is moving.
| 1 | Map the perimeter List obliged entities, branches, services, customer types, transfer flows, group dependencies, vendors and data stores. |
|---|---|
| 2 | Translate requirements Link each AMLR, directive and Travel Rule duty to a process, system, owner, test and record. |
| 3 | Remediate customer files Quantify missing identification, beneficial ownership, risk ratings and review dates before the deadline. |
| 4 | Test transfer controls Run end-to-end cases for provider transfers, third-party wallets, ownership checks, sanctions and rejected data. |
| 5 | Join monitoring data Document scenarios, model limits, human review, tuning, quality assurance and suspicious-activity decisions. |
| 6 | Rehearse supervision Produce samples, dashboards, audit evidence and board records as if a supervisor had requested them tomorrow. |
The test in July 2027
The board needs trend information before it needs another policy. Overdue reviews, unresolved ownership discrepancies, Travel Rule failures by counterparty, alert ageing, sanctions incidents, monitoring gaps, audit findings and remediation dates show whether the system is improving.
My reading is that the strongest firms will use the harmonisation to simplify group controls while preserving local accountability. The weakest will add an EU policy layer above fragmented data and call the project complete.
On 10 July 2027, the decisive question will be practical: can the firm show who its customers are, explain the movement of value and reproduce the judgement applied when the evidence did not fit a standard case?
“INSIGHTS”