Key facts
The Three Instruments You Must Not Confuse: AMLR, AMLAR and AMLD6
The 2024 EU AML overhaul replaced the fragmented AMLD4/5 patchwork with three distinct instruments published simultaneously in the Official Journal. Conflating them is one of the most common compliance-drafting errors — and a consequential one, because each carries separate article numbering, a different legal form, and different addressees. Before reading any secondary analysis, pin these three down precisely.
| Instrument | Legal act | Who it addresses | Application / transposition date |
|---|---|---|---|
| AMLR — the single rulebook | Regulation (EU) 2024/1624 |
Obliged entities directly (banks, CASPs, payment firms, etc.) — no national transposition needed | 10 July 2027 (most provisions) |
| AMLAR — the authority regulation | Regulation (EU) 2024/1620 |
EU Member States and national supervisors; establishes AMLA as an EU agency (operational 1 July 2025, headquartered in Frankfurt) | Entered into force 2024; AMLA operational from 1 July 2025; direct supervision from 2028 |
| AMLD6 — the directive | Directive (EU) 2024/1640 |
Member States — governs national FIU structures, beneficial-ownership registers and national supervisory frameworks; requires transposition | Member States must transpose by 10 July 2027 |
For a MiCA-authorised CASP, Regulation (EU) 2024/1624 (AMLR) is the primary operational concern: it sets CDD obligations, STR duties, the privacy-coin prohibition under Article 79, and transaction-monitoring requirements that apply directly without any national implementing act. AMLAR matters because it defines which firms fall under AMLA direct supervision (see CASP licence requirements for the authorisation context). AMLD6 matters indirectly — it shapes the national supervisor your firm deals with and the beneficial-ownership data you can query. Together with Regulation (EU) 2023/1114 (MiCA) and the Transfer of Funds Regulation (EU) 2023/1113 (TFR), these instruments form the complete EU CASP compliance framework — see our Travel Rule / TFR guide for the fund-transfer layer. When citing any article number in internal documentation, always specify which of the three instruments you are referencing — "Article 12 AMLAR" and "Article 12 AMLR" are entirely different provisions.
Who Is In Scope: CASPs as Obliged Entities Under AMLR Article 3
Article 3 of Regulation (EU) 2024/1624 (AMLR) lists the categories of obliged entities subject to the full AML/CFT rulebook. MiCA-authorised CASPs appear explicitly in that list. The practical consequence is straightforward: if your firm holds a CASP authorisation under MiCA, it is an obliged entity under AMLR with no de minimis carve-out based on size or transaction volume. This covers exchanges (crypto-to-fiat and crypto-to-crypto), custodians, brokers executing orders, firms operating trading platforms, portfolio managers, and providers of transfer services for crypto-assets. There is no grace period layered on top of the 10 July 2027 application date — the obligations attach the moment the Regulation applies.
One important qualification, confirmed by legal analysis of the AMLR text: CASPs that provide exclusively crypto-asset advice may not fall within the obliged-entity definition and should conduct a specific categorisation analysis before assuming full AMLR scope applies to them. This is a narrow carve-out — the moment an advisory firm also executes, custodies, or transfers assets, it is squarely in scope — but it is not a nuance to ignore. Separately, Article 3, points (3)(n) and (o) defer certain other categories (notably football clubs and agents) to 10 July 2029; this illustrates that the AMLR does not impose simultaneous obligations on every listed category, and the precise entry into force of each category matters. CASPs face the 2027 date, not 2029.
It is also worth stating the obvious: MiCA authorisation is a legal prerequisite for operating as a CASP in the EU in the first place. A firm that is not yet MiCA-authorised cannot legally offer crypto-asset services to EU clients — so the sequence is authorisation first, then AMLR compliance on top. If your firm is still working through the MiCA licensing process, the CASP licence requirements guide covers that foundation. For firms already authorised, the AMLR compliance buildout should be running in parallel with — not after — the 2026 MiCA compliance deadlines you are already tracking.
Customer Due Diligence: New Thresholds and the €1,000 CASP Standard
AMLR Articles 19–28 establish the complete CDD framework that applies to CASPs from 10 July 2027. For crypto-asset service providers, the headline rule is a €1,000 threshold for full CDD on occasional transactions — far stricter than the general obliged-entity threshold, which AMLR itself tightened from €15,000 to €10,000. That comparison matters: the €10,000 figure is not a stable baseline but is already a regulatory tightening for other sectors. CASPs sit at one-tenth of even that reduced floor, reflecting the legislature's explicit risk judgment about the anonymity and cross-border characteristics of crypto-asset flows.
A critical nuance that practitioners must not miss: falling below €1,000 does not eliminate CDD obligations entirely. Even for sub-threshold occasional transactions, CASPs are still required to identify the customer and verify their identity. The €1,000 line is the trigger for full CDD — purpose of the relationship, beneficial ownership, risk classification, and ongoing monitoring — not the line between some obligation and zero obligation. For legal-entity customers, Article 22(1) AMLR requires identification of the legal entity itself, including collection of the Legal Entity Identifier (LEI) where one is available. Standard CDD elements confirmed by the AMLR framework include: identity establishment and verification (Article 22); determination of the purpose and intended nature of the relationship (Article 25); and ongoing monitoring of transactions and periodic refreshing of CDD data (Article 26). Simplified due diligence (SDD) is permitted for demonstrably lower-risk customer categories; enhanced due diligence (EDD) is mandatory for higher-risk relationships, including politically exposed persons and high-risk third-country counterparties. All CDD records must form an auditable, timestamped dataset — continuous and refreshable — not a static document archive checked at onboarding and forgotten.
| Transaction / relationship type | Threshold | CDD level required |
|---|---|---|
| Occasional crypto-asset transaction (CASP) | At or above €1,000 | Full CDD (identity, verification, purpose, ongoing monitoring) |
| Occasional crypto-asset transaction (CASP) | Below €1,000 | Minimum: customer identification and identity verification |
| Occasional transaction — other obliged entities (non-CASP) | At or above €10,000 (reduced from €15,000) | Full CDD |
| Ongoing business relationship (all CASPs) | No threshold — applies from outset | Full CDD at entry; ongoing monitoring per Article 26 AMLR |
| Lower-risk customer / relationship (qualifying criteria met) | Risk-based, no fixed amount | Simplified due diligence (SDD) |
| PEPs, high-risk third countries, complex structures | Risk-based, no fixed amount | Enhanced due diligence (EDD), senior management approval |
Practically, CASPs should treat every customer record as a living compliance file. A CDD dataset that cannot demonstrate when it was last reviewed, what triggered the review, and what the outcome was will not satisfy supervisory expectations under AMLR — whether from a national competent authority or, for qualifying firms, from AMLA directly. Firms that have grown accustomed to onboarding-only KYC processes under pre-2027 national AML regimes will need to rebuild their workflows around continuous, event-triggered re-verification before the July 2027 application date. For the interaction between CDD obligations and transaction-monitoring duties when assets move between wallets, see the EU Travel Rule and TFR compliance guide.
Article 79 AMLR: The Anonymous-Account and Privacy-Coin Prohibition
Article 79 of Regulation (EU) 2024/1624 prohibits CASPs from maintaining three categories of account: anonymous crypto-asset accounts; accounts that allow the anonymisation or increased obfuscation of transactions; and accounts that hold or use anonymity-enhancing coins where the CASP cannot satisfy its customer due diligence obligations. The prohibition covers account-level arrangements — it does not restrict individuals from holding assets in self-custody. The framework is legally settled: Article 79 AMLR is in force. What remains open is the precise implementation scope, which depends on delegated acts from EBA and AMLA that had not been finalised as of the date of this article.
Monero (XMR) is the clearest case. Its mandatory ring-signature and stealth-address protocol structurally prevents a CASP from identifying counterparties or reconstructing transaction trails — the CDD obligations in Articles 20–22 AMLR are objectively impossible to satisfy for XMR holdings. Zcash is more complex: shielded-pool (z-addr) transactions raise the same traceability problem, but ZEC also supports fully transparent addresses (t-addr) and viewing-key disclosure. Whether a CASP can lawfully retain ZEC by restricting users to transparent addresses is likely to depend on how EBA defines "anonymisation function" in forthcoming delegated acts; some platforms have taken that position, others have not. Treat the Zcash question as legally unsettled until EBA publishes its final interpretation. The EBA launched a consultation on the AML package specifically noting that rules on anonymous accounts and privacy coins may be subject to further calibration — track those outcomes.
The prohibition does not arrive without precedent. Article 72(2) of Regulation (EU) 2023/1114 (MiCA) already prohibits crypto-asset trading platforms from admitting to trading any crypto-asset that has an in-built anonymisation function, unless the issuer or the CASP can de-anonymise the holdings on request by competent authorities. Article 79 AMLR extends and reinforces that restriction across all CASP service types — custody, exchange, transfer — not just trading platforms. Firms that have already reviewed their asset catalogue for MiCA Article 72(2) compliance have a head start, but the AMLR sweep is broader. Practical steps to take now:
- Audit every listed or custodied asset against the Article 79 criteria and document your legal position in writing
- For assets you conclude are covered, design a controlled offboarding process — notification timelines, user communication, withdrawal windows — before 10 July 2027
- For borderline assets (including ZEC), record your reasoning explicitly and build a trigger to revisit once EBA finalises its delegated act
- Note that major exchanges including Binance, Kraken and OKX have already delisted Monero in EU-facing markets — regulators will treat industry precedent as a reference point
Suspicious Transaction Reporting and FIU Obligations
Under Regulation (EU) 2024/1624 (AMLR), every MiCA-authorised CASP is an obliged entity with a direct duty to report suspicions of money laundering or terrorist financing to the national Financial Intelligence Unit (FIU). The reporting obligation is substantive: a CASP must file a suspicious transaction report (STR) whenever it has reasonable grounds — regardless of the transaction amount, and regardless of whether the transaction has been completed or merely attempted. Article 69 AMLR sets the general obligation to report; Article 70 AMLR adds specific provisions for certain categories of obliged entities. These are not discretionary thresholds — a failure to report where suspicion exists is itself a breach.
Tipping-off is prohibited. Once a CASP has filed or is about to file an STR, it cannot alert the customer or any connected third party that a report has been made or that an investigation is underway. The prohibition exists to prevent asset dissipation and to protect the integrity of FIU investigations. Separately, STR records and supporting documentation must be retained for a minimum of five years from the date of the report — consistent with the broader record-keeping baseline across AMLR. Where a national FIU requests additional information following an STR, the CASP must cooperate fully and within the timeframe the FIU specifies; the substantive duty to respond promptly is clear even where the AMLR does not prescribe a fixed number of days in every scenario.
One structurally new element is AMLA's coordination role. For the first time, the Authority has a mandate to facilitate joint FIU analyses across Member States — enabling cross-border suspicious-pattern detection at EU scale rather than stopping at national borders. This matters for CASPs operating in multiple jurisdictions, where a pattern fragmented across Member State FIUs may previously have gone undetected. There is also a direct operational link to Regulation (EU) 2022/2554 (DORA): transaction monitoring systems that generate or process STRs qualify as critical ICT systems and must satisfy DORA's resilience, incident-response and testing requirements in parallel. Compliance teams should treat the STR pipeline — data ingestion, alert generation, case management, FIU submission — as a single auditable ICT process subject to both AMLR and DORA obligations. See our DORA compliance guide for CASPs for the full technical resilience requirements.
AMLA's Two-Tier Supervisory Model: Are You a Candidate for Direct Oversight?
Regulation (EU) 2024/1620 — the AMLA Regulation — establishes a two-tier supervisory architecture. The tier a CASP sits in is not a choice; it is determined by objective selection criteria applied by AMLA itself. Most CASPs will remain in Tier 2 indefinitely, but any firm with meaningful cross-border scale needs to assess its exposure to direct oversight now, before the first supervision cycle begins on 1 January 2028.
Tier 1 — AMLA direct supervision applies to firms designated as selected obliged entities under Article 13 of Regulation (EU) 2024/1620. The first cohort is expected to comprise approximately 40 firms. Selection is not based on size alone: a CASP must operate in at least six Member States and meet risk-based thresholds — including, based on available regulatory guidance, approximately 20,000 customers and a transaction volume of around €50 million. AMLA can impose pecuniary sanctions of up to 10% of annual group turnover for serious, systematic or repeated breaches — a materially higher ceiling than most national regimes. Tier 2 — national supervision covers all other CASPs. The competent authority is the same body that granted the MiCA authorisation, but it now operates against AMLA-drafted technical standards and binding guidelines. Supervisory findings feed into the central AML/CFT database under Article 11 of Regulation (EU) 2024/1620, making national supervision visible at EU level for the first time — a firm cannot assume that a local finding stays local.
| Tier | Who supervises | Selection trigger | Key AMLA powers |
|---|---|---|---|
| Tier 1 — Direct | AMLA (Frankfurt) | ≥6 Member States; ~20,000 customers; ~€50m transaction volume; high-risk profile | On-site inspections; binding decisions; sanctions up to 10% of group annual turnover |
| Tier 2 — Indirect | National competent authority (MiCA licensor) | All other MiCA-authorised CASPs not selected for Tier 1 | National enforcement under AMLA standards; findings entered into central AML/CFT database (Art. 11) |
The practical implication is that Tier 2 is not a lighter regime — it is the same substantive rulebook applied locally. AMLA's technical standards bind national supervisors, and data sharing via the central database means cross-border risk flags aggregate regardless of tier. CASPs should map which Member States they serve, count active customers and transaction volumes now, and document that analysis. If a firm is approaching the Tier 1 thresholds, it should begin building the governance infrastructure — dedicated AML officer capacity, escalation procedures, board-level AML reporting — that direct AMLA oversight will demand. For the full licensing context, see our CASP licence requirements guide and the MiCA compliance deadlines overview.
Internal Governance: MLRO, Risk Assessment and AML Policies
Every MiCA-authorised CASP must embed a formal AML governance structure before 10 July 2027 — not as a paper exercise, but as a live, risk-calibrated framework. The starting point is an enterprise-wide risk assessment that maps the firm's actual customer mix, product set, delivery channels and geographies. That assessment must be updated before any material change: launching a new product, adding a trading pair with elevated anonymity characteristics, or expanding into a new member state all trigger a reassessment obligation under Regulation (EU) 2024/1624 (AMLR). A static risk assessment filed at authorisation and never revisited will not survive supervisory scrutiny.
Internal policies, procedures and controls must be proportionate to the firm's risk profile and size, written down, and formally approved by the management body — board-level sign-off, not delegated to a mid-level manager. The compliance manager or Money Laundering Reporting Officer (MLRO) must hold sufficient seniority and authority to act independently; AMLR requires that internal procedures be approved at minimum at compliance manager level. Firms should not underestimate this: regulators examine whether the MLRO has genuine escalation paths and budget, not just a title. Staff across customer-facing, product and operations functions must receive regular AML training. These obligations dovetail directly with the competence and knowledge requirements already imposed on CASPs under MiCA Article 81 — see the MiCA Article 81 staff training guide for detail on how to integrate both frameworks efficiently.
Beneficial ownership identification is a specific area of exam failure. Under AMLR Articles 51–55, CASPs must identify and verify the ultimate beneficial owner (UBO) of legal-entity customers, cross-referencing national beneficial ownership registries — self-declared UBO data accepted without independent cross-verification is a documented supervisory red flag. For politically exposed persons (PEPs), enhanced due diligence applies for at least 12 months after the individual leaves a prominent public function; firms that immediately downgrade a former PEP to standard CDD are non-compliant. Build PEP-exit monitoring into your periodic review cycle, not just onboarding screening.
Pre-July 2027 Readiness Checklist for MiCA-Authorised CASPs
2026 is the action year. AMLA is already publishing technical standards and guidelines that will form the examination baseline for 2027 supervisory reviews. A CASP that waits until Q2 2027 to begin gap analysis will not have enough runway to remediate findings, retrain staff, and document updated policies before Regulation (EU) 2024/1624 applies on 10 July 2027. Treat the table below as a gap-analysis framework, not a theoretical roadmap — each phase has a concrete owner and a defined deliverable.
Before using this checklist, confirm your scope. Most MiCA-authorised CASPs become obliged entities under AMLR Article 3 on the application date, with no grace period. The one material carve-out: CASPs that provide exclusively advisory services relating to crypto-assets may fall outside the obliged-entity definition — verify this with legal counsel against your exact service authorisation. For all in-scope CASPs, obligations go live simultaneously; there is no phased roll-in by service type.
| Phase | Actions | Owner |
|---|---|---|
| Immediately / Q3 2026 |
|
CCO / Legal |
| Q4 2026 |
|
MLRO / Compliance |
| Q1–Q2 2027 |
|
MLRO / IT / HR |
| By 10 July 2027 |
|
Board / CCO |
AMLA's technical standards, once finalised, will define the specific examination criteria supervisors apply from July 2027. Firms that align their gap analysis to draft standards now — rather than waiting for final texts — absorb implementation risk gradually. Review your MiCA compliance deadlines alongside this AMLR timeline: the two regimes share a supervisory audience, and a combined readiness review is more efficient than treating them separately.
Frequently asked questions
Does the AMLR apply to all MiCA-authorised CASPs automatically from 10 July 2027?
Broadly yes. Article 3 of Regulation (EU) 2024/1624 includes every MiCA-authorised CASP as an obliged entity with no de minimis threshold, and there is no grace period beyond the 10 July 2027 application date. The one important caveat: CASPs providing *only* crypto-asset advice may not fall within the obliged-entity definition and should confirm their status against the AMLR text and any forthcoming AMLA guidance before assuming full scope.
What is the CDD threshold for CASPs under the AMLR — and is there any obligation below €1,000?
Full customer due diligence is required for occasional crypto-asset transactions at or above €1,000. However, below €1,000 does not mean zero obligation: CASPs must still perform at minimum customer identification (name and identity verification). This is materially stricter than the €10,000 threshold that applies to most other obliged entities — itself already a reduction from the prior €15,000 general threshold under AMLD5.
Will AMLA directly supervise my CASP?
Only a small number of firms — approximately 40 in the first cohort from 1 January 2028 — will be selected for AMLA direct supervision under Article 13 of Regulation (EU) 2024/1620. Selection requires operating in at least six EU Member States and meeting risk-based thresholds that include approximately 20,000 customers and €50 million in transaction volume. All other CASPs remain supervised by their national competent authority, but against AMLA-issued standards and methodology.
Do we need to delist Monero and other privacy coins before July 2027?
Article 79 of the AMLR prohibits CASPs from maintaining accounts that use anonymity-enhancing coins from 10 July 2027. Monero (XMR) and similar assets with default transaction obfuscation are the clearest cases. For assets like Zcash (ZEC) that combine shielded and transparent modes, the final scope will depend on EBA and AMLA delegated acts that are still being finalised. The broader legal framework is settled; CASPs should document their asset-support position now and monitor EBA consultation outcomes. Many major EU-facing exchanges have already delisted privacy coins ahead of the deadline.
How does the AMLR interact with MiCA and DORA for CASPs?
The three instruments are complementary and must all be satisfied simultaneously. MiCA governs authorisation and market-conduct obligations — a CASP must be MiCA-authorised before AMLR obligations attach. The AMLR then imposes AML/CFT rules (CDD, STR, beneficial ownership, anonymity prohibitions). DORA applies a digital-operational resilience layer: transaction-monitoring and STR-filing systems qualify as critical ICT systems under DORA and must meet its resilience, incident-reporting and third-party risk requirements.
What sanctions can AMLA impose on directly supervised CASPs?
For selected obliged entities under direct supervision, AMLA can impose administrative pecuniary sanctions of up to 10% of total annual group turnover for serious, systematic or repeated breaches of AMLR obligations. This sanction ceiling is established in Regulation (EU) 2024/1620 and is substantially higher than most national supervisors have historically applied.