Financial crime compliance

The EU's AML Reset Is the Operating System for Crypto

MiCAR controls entry. AMLR, the Travel Rule and AMLA shape the evidence an authorised firm must produce every day.

Abstract illustration of national supervisors feeding into a single European rulebook overseen by a new authority

The 2027 deadline is only part of the timetable. The crypto Travel Rule is already live, AMLA is writing the supervisory detail and the first direct-supervision selection begins in 2027.

The calendar before the theory

The anti-money-laundering package is often presented as a 10 July 2027 deadline. That date is central because the AMLR generally starts applying and the new national mechanisms are due to be in place.12

Work has already moved. Regulation (EU) 2023/1113 brought the crypto Travel Rule into application on 30 December 2024. AMLA began building its operating functions in 2025 and spent 2026 developing technical standards and guidelines on customer due diligence, group controls, business-wide risk assessment and ongoing monitoring.456

The first direct-supervision selection takes place in 2027. Supervision of the selected population begins in 2028. A firm that waits for the AMLR application date will arrive with policies drafted against legislation but systems built against older practice.

DateMilestoneOperational Effect
30 Dec 2024Crypto Travel Rule appliesTransfer data, counterparty handling and self-hosted-address controls are live
2025-2026AMLA develops technical instrumentsCDD, monitoring, group and supervisory detail is being specified
10 Jul 2027AMLR generally appliesCore private-sector duties become directly applicable
2027First direct-supervision selectionEligible cross-border entities are assessed under the common methodology
2028AMLA direct supervision startsUp to 40 selected entities or groups enter joint EU-level supervision

AMLA changes the method

AMLA does not replace CySEC, BaFin, AMF or the other national supervisors. Most firms will continue to answer to a national authority.

The new authority still changes the method. It writes standards, coordinates supervisors, supports colleges, conducts peer review and can act where national supervision is ineffective. It also supports financial intelligence units, while suspicious transaction reports continue to go to the competent national FIU.37

Up to 40 financial institutions or groups will enter direct supervision from 2028. Eligibility requires activity in at least six Member States; selection then turns on residual money-laundering and terrorist-financing risk after controls are considered.89

In cross-border reviews I see a recurring problem: the group can describe its control framework, but it cannot reproduce the same customer, monitoring or alert data from each entity. AMLA's model will make that inconsistency harder to defend.

Diagram of a central authority connected to a network of national supervisors, with selected entities under direct oversight
AMLA coordinates a national supervisory network and directly supervises a selected population.

Article 79 and self-hosted addresses

Article 79 prohibits covered credit institutions, financial institutions and CASPs from keeping anonymous crypto-asset accounts, including accounts that allow anonymisation of the holder or increased obfuscation of transactions through anonymity-enhancing coins.1

The legal target is the institutional account or service. An individual does not commit an offence under Article 79 merely by holding a privacy-enhancing asset in a wallet they control. Software or hardware that gives the provider no access or control also falls outside the account-keeping prohibition.

The commercial effect for a CASP can still be severe. The firm has to assess whether custody, transfer, exchange or trading-platform functionality permits the prohibited anonymity. MiCAR already requires platform rules to address crypto-assets with inbuilt anonymisation functions unless holders and transaction history can be identified.10

Self-hosted wallets follow a separate logic. For transfers involving a self-hosted address, the CASP gathers the prescribed originator or beneficiary information and ensures the transfer can be individually identified. Above EUR 1,000, in the circumstances specified by the Regulation, it must assess whether the address is owned or controlled by its customer.411

“The regime closes anonymous services inside regulated firms. It does not outlaw personal custody.

Travel Rule evidence is already being created

The Travel Rule applies to covered crypto transfers regardless of amount. The originating and beneficiary information accompanies the transfer, and the receiving provider needs risk-based procedures for missing or incomplete data.411

That process produces evidence beyond the message itself. Counterparty identity, customer profile, wallet address and on-chain transaction can be analysed together. A provider that stores the payload but does not use it in risk assessment or monitoring misses much of the regulatory value.

Interoperability remains uneven. Protocols differ, some counterparties return incomplete fields and third-country implementation varies. The control objective is a consistent decision process with protected personal data, documented exceptions and a clear escalation route.

Monitoring is wider than alerts

AMLA's 2026 draft guidance treats ongoing monitoring as a continuing review of the business relationship. Transaction alerts are one component. The customer profile, source and destination of value, wallet exposure, product use and changes in activity also have to inform the risk view.13

Automated systems can prioritise lower-risk outputs, but the model needs an explainable logic, documented limitations and effective human review. A low score cannot close a case where the available information points to suspicion.

For a CASP, the useful view joins on-chain and off-chain data. Device and geographic signals, fiat movements, sanctions exposure, Travel Rule data and customer records often sit in separate tools. The supervisory problem appears at the join.

Row of panels representing the AML operating stack: identity, transfer data, monitoring, reporting and governance
The operating model joins customer identity, transfer evidence, monitoring and governance.

A 2026 implementation file

The implementation programme should be managed as evidence, not a policy rewrite. Six workstreams are enough to expose whether the firm is moving.

1Map the perimeter List obliged entities, branches, services, customer types, transfer flows, group dependencies, vendors and data stores.
2Translate requirements Link each AMLR, directive and Travel Rule duty to a process, system, owner, test and record.
3Remediate customer files Quantify missing identification, beneficial ownership, risk ratings and review dates before the deadline.
4Test transfer controls Run end-to-end cases for provider transfers, third-party wallets, ownership checks, sanctions and rejected data.
5Join monitoring data Document scenarios, model limits, human review, tuning, quality assurance and suspicious-activity decisions.
6Rehearse supervision Produce samples, dashboards, audit evidence and board records as if a supervisor had requested them tomorrow.

The test in July 2027

The board needs trend information before it needs another policy. Overdue reviews, unresolved ownership discrepancies, Travel Rule failures by counterparty, alert ageing, sanctions incidents, monitoring gaps, audit findings and remediation dates show whether the system is improving.

My reading is that the strongest firms will use the harmonisation to simplify group controls while preserving local accountability. The weakest will add an EU policy layer above fragmented data and call the project complete.

On 10 July 2027, the decisive question will be practical: can the firm show who its customers are, explain the movement of value and reproduce the judgement applied when the evidence did not fit a standard case?

“INSIGHTS”