Anti-Money Laundering Regulation (AMLR) Regulation (EU) 2024/1624 (Crypto Provisions)
- Issuing authority
- European Parliament and Council of the European Union
- Effective date
- Entered into force on 9 July 2024. Most provisions apply from 10 July 2027
- Scope
- European Union
Key requirements
1. Customer due diligence (CDD): Identify and verify customers, including beneficial owners where required. 2. €1,000 occasional transaction threshold: Apply CDD to qualifying occasional cryptoasset transactions of €1,000 or more, including linked transactions where applicable. 3. Self-hosted addresses: Assess the ML/TF risks of transfers involving self-hosted addresses and apply appropriate risk-based measures. 4. Anonymous cryptoasset accounts: Do not provide anonymous accounts or services that prevent customer identification or effective transaction monitoring. 5. Suspicious activity reporting: Report suspected money laundering or terrorist financing to the relevant Financial Intelligence Unit and comply with tipping-off restrictions.
Quick Summary
The Anti-Money Laundering Regulation creates a single set of AML and counter-terrorist financing rules that will apply directly across the European Union. For crypto businesses, the Regulation confirms that Crypto-Asset Service Providers (CASPs) are obliged entities. This means they must carry out customer due diligence, monitor transactions, report suspicious activity and maintain appropriate AML controls. The Regulation also introduces specific rules for occasional crypto transactions, self-hosted addresses and anonymous cryptoasset accounts.
What is it?
Before the AMLR, much of the EU’s AML framework was set out in Directives. Each Member State had to introduce those rules through its own national legislation, which sometimes resulted in differences between countries. The AMLR replaces much of that fragmented approach with one directly applicable EU rulebook. For CASPs operating across several EU countries, this should create greater consistency because the same core AML requirements will apply throughout the Union.
Who does it apply to?
- Crypto-Asset Service Providers authorised under MiCA
- Crypto exchanges
- Crypto custodians
- Crypto brokers
- Crypto trading platforms
- Other businesses providing regulated cryptoasset services in the EU
What should firms do?
- Review customer due diligence procedures ahead of July 2027.
- Ensure occasional transactions of €1,000 or more trigger the required checks.
- Assess the risks associated with self-hosted addresses.
- Review whether any products or accounts allow customer identity or transaction activity to be obscured.
- Strengthen transaction-monitoring and suspicious-activity reporting processes.
- Align AML controls with MiCA and the Transfer of Funds Regulation.
- Train staff on the new EU-wide requirements.
AboutAML Breakdown
The AMLR is one part of a wider EU crypto-regulatory framework. CASP may need to comply with several rules at the same time. For example, MiCA may determine whether the firm needs authorisation, the AMLR determines how it must manage money-laundering risks, and the TFR determines what information must accompany a crypto transfer.
