Transaction monitoring setup in Czech Republic
A virtual asset service provider (VASP) operating in or into the Czech Republic faces a precise legal obligation: build and maintain a transaction monitoring system that satisfies Czech AML legislation, the FATF Recommendations (including Recommendation 15, which brings VASPs into the standard AML/CFT perimeter), and – for firms with an EU passport or cross-border user base – the trajectory toward MiCA's CASP authorisation framework. The Czech Republic does not exist in regulatory isolation. An exchange serving Czech retail users while incorporated in another EU member state, or banking through a correspondent in Germany, faces the same substance requirements. The compliance question is not which regime applies: it is whether your monitoring architecture satisfies all of them simultaneously.
This page sets out what transaction monitoring means under Czech and EU law, how to build a compliant program, and where cross-border structure changes the analysis. We also address the common assumption that a single offshore registration covers global operations – it does not, and Czech supervisory practice is increasingly clear on the point.
The Czech regulatory basis for transaction monitoring
Transaction monitoring in the Czech Republic is anchored in the Act on Certain Measures Against the Legitimisation of Proceeds of Crime and Financing of Terrorism (the Czech AML Act), which implements successive EU AML Directives and incorporates the FATF standards for virtual assets. The Czech Financial Analytical Office (FAÚ) is the primary supervisory authority for AML/CFT obligations imposed on VASPs. FAÚ has jurisdiction over registration, on-site inspection and administrative sanctions. A firm providing crypto-exchange, custody or transfer services to Czech clients – regardless of where it is incorporated – is expected to meet these obligations.
The obligation to monitor transactions is not merely a reporting duty. It is a continuous, systemic requirement. Every covered entity must maintain documented customer risk profiles, apply transaction limits and behavioral thresholds, generate alerts for unusual activity, investigate those alerts within a defined internal timeframe, and file a suspicious transaction report (STR) with FAÚ where the investigation does not resolve the concern. The monitoring system must be calibrated to the firm's actual product and customer base – a generic, off-the-shelf ruleset with no Czech-market tuning will fail an audit.
For EU-licensed entities operating into the Czech market under MiCA passporting, the picture is layered. MiCA introduces CASP authorisation requirements that sit above domestic AML registration; the firm must satisfy both the home-state regulator and, for AML purposes, the host-state authority. FAÚ has been explicit that passporting does not displace Czech AML supervisory jurisdiction. Operators we advise on inbound Czech market entry regularly discover this layering at a late stage – often after banking has already been arranged on the assumption that home-state licensing covers everything.
Which businesses must build a transaction monitoring program in the Czech Republic?
Any entity that qualifies as an "obliged entity" under the Czech AML Act and provides virtual asset services must implement transaction monitoring – the obligation follows the activity, not the registration address. This covers cryptocurrency exchanges (fiat-to-crypto and crypto-to-crypto), custodians holding private keys on behalf of clients, transfer services routing on-chain payments, and intermediaries facilitating digital-asset transactions for Czech-resident counterparties.
The threshold question for inbound operators is whether Czech-resident clients trigger Czech AML obligations. The answer, in our cross-border practice, is almost always yes – particularly where the firm actively markets into the Czech Republic, accepts CZK or EUR deposits from Czech bank accounts, or holds customer assets in any custody arrangement. Passively serving a Czech client who found the platform independently does not eliminate the obligation; it shifts the analysis to risk-based calibration rather than full-market registration, but the monitoring duty itself remains.
Firms that are already registered with FAÚ as a provider of virtual asset services are subject to regular supervisory review. Those that are not registered but are nonetheless serving Czech clients should treat that gap as an immediate legal risk. FAÚ has the authority to impose administrative fines, require disgorgement of proceeds earned during an unlicensed period, and refer matters to the financial police. The loss of banking relationships is frequently the first practical consequence – Czech banks conduct their own due diligence on VASP counterparties and will exit a relationship when AML registration cannot be demonstrated.
Consider a scoped assessment of your Czech-market exposure before your banking relationship is at risk. The process above describes the standard path. Your facts – entity structure, user base location, product offering – change the analysis materially. To map your position, contact OBOLUS at info@oboluslaw.com.
How should a VASP structure its transaction monitoring program?
A compliant transaction monitoring program under Czech and EU AML law has five core components: a risk-based customer classification model, automated alert generation calibrated to product risk, a documented investigation and escalation workflow, an STR filing process tied directly to FAÚ, and a record-keeping architecture that satisfies the retention obligations under the Czech AML Act.
The risk classification model must be built before monitoring rules are written. A VASP that begins with generic velocity rules – flagging transactions above a round-number threshold regardless of customer profile – will generate alert volumes it cannot operationally manage, and will miss the pattern-based indicators that regulators actually look for. Czech supervisory guidance and FAÚ inspection findings both point to inadequate customer risk scoring as the most common structural weakness. In our practice, we regularly advise firms to conduct a product risk assessment as the first step: map every service to a customer type and transaction pattern, then design monitoring rules that correspond to those patterns.
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer) adds a second layer to the architecture. Czech law implements the EU Funds Transfer Regulation, which applies the Travel Rule to virtual asset transfers. A VASP must therefore capture, verify and transmit the required data fields on transfers above the applicable threshold – and must build a monitoring component that identifies transfers where that data is missing or inconsistent. A monitoring system that tracks value but ignores data completeness will fail a Travel Rule audit.
The investigation workflow is where most programs break down in practice. An alert is worth nothing if it sits in a queue. The program must specify who reviews each alert category, what information is pulled for the review, what the escalation triggers are, and how the outcome is documented. FAÚ expects to see this workflow described in the firm's internal AML policy, and to see evidence during an inspection that the workflow is actually followed. A gap between the written policy and the operational reality is a finding in its own right.
Who is responsible for AML governance, and what does the MLRO do?
Czech AML law requires every obliged entity to appoint a Money Laundering Reporting Officer (MLRO) – the individual accountable for the firm's AML/CFT compliance program, including the transaction monitoring function. The MLRO must have sufficient seniority, authority and resource access to discharge the role effectively. FAÚ will assess the MLRO appointment as part of any supervisory review and will expect the MLRO to be identifiable, reachable, and capable of explaining the firm's risk methodology.
For a VASP with Czech-resident clients, the MLRO does not need to be physically located in the Czech Republic – but the function must be substantively exercised in relation to Czech-market activity. An MLRO based in another EU jurisdiction who has no visibility into the Czech client population, no access to Czech-market transaction data, and no relationship with FAÚ is not discharging the function. We have seen this structure challenged during inspections, particularly where the MLRO is also carrying the same role for multiple entities across several jurisdictions simultaneously.
The MLRO is also the formal STR channel. When a transaction monitoring alert escalates to a suspicious transaction report, it is the MLRO who files with FAÚ, maintains the filing record, and ensures that the underlying client relationship is managed in accordance with the tipping-off prohibition. That prohibition – which prevents the firm from disclosing to the subject that a report has been filed – has nuanced cross-border implications where the client relationship involves entities in multiple jurisdictions.
How does the Travel Rule interact with cross-border transaction monitoring?
The Travel Rule is the single most operationally complex element of a Czech VASP's monitoring architecture, precisely because it is a cross-border obligation by design. Every virtual asset transfer sent to or received from an external VASP must carry the required originator and beneficiary data – and the Czech firm's monitoring system must verify that the data is present, consistent with its own customer records, and not on a sanctions list.
The challenge is that many of the counterparty VASPs a Czech exchange deals with are domiciled outside the EU. FATF has incorporated the Travel Rule into its standard recommendations, and most major jurisdictions have or are implementing a version of it – but implementation timelines, data-field requirements and de-minimis thresholds vary. A Czech VASP sending to a Singapore-based counterparty must transmit EU-compliant data; whether the Singapore entity's response meets Czech expectations depends on its own regime. The monitoring program must be designed to manage these asymmetries, not to assume away the gaps.
In our cross-border practice, the firms that handle this most cleanly maintain a VASP counterparty register – a documented assessment of each counterparty's regulatory status, Travel Rule implementation capability, and the data fields they actually transmit. That register feeds the monitoring system's alert rules: transfers to or from unregistered or unverified counterparties automatically flag for enhanced review. FAÚ has indicated in published guidance that inadequate counterparty due diligence is an area of increasing supervisory focus.
For a business sitting between Czech AML obligations and a cross-border banking structure, the legal question turns on where substance sits. The bank that provides CZK settlement rails will conduct its own VASP due diligence. It will look at the monitoring program, the MLRO appointment, the Travel Rule implementation, and the STR-filing track record. A monitoring architecture that satisfies FAÚ also satisfies the bank's compliance team. The two audiences are not as different as operators assume.
What are the most common transaction monitoring failures Czech regulators identify?
FAÚ's inspection experience and published guidance point consistently to the same categories of failure, and operators we advise frequently encounter them when inheriting a program built without specialist input.
The first is static rule sets. A monitoring program configured at launch and never updated against product changes, new client segments or emerging typologies will produce alerts that are increasingly disconnected from actual risk. Czech law requires an ongoing, risk-based approach – "ongoing" is an operative word. The program must be reviewed and updated at defined intervals, and those reviews must be documented.
The second is inadequate calibration for crypto-specific typologies. Standard AML monitoring tools built for payments or banking do not natively recognise blockchain-specific patterns: layering through multiple wallet hops, rapid conversion between assets, mixer or tumbler interactions, or transfers to addresses flagged by blockchain analytics providers. A Czech VASP must supplement its core monitoring system with on-chain analytics capability – either built in or integrated through a forensics provider – and must map those analytics outputs to its alert and investigation workflow.
The third is the documentation gap. FAÚ inspectors review the written program, the alert records, the investigation notes, and the STR filings. Where the documentation does not support the narrative the firm presents, that is a finding. We have seen well-intentioned firms produce strong monitoring results in practice but be unable to demonstrate the results evidentially. The monitoring program must be documented so thoroughly that an inspector can reconstruct every decision from the records alone.
Practice illustration: inherited program, failing inspection
In a recent compliance matter, a European crypto exchange had registered with FAÚ and deployed an off-the-shelf transaction monitoring tool without adapting it to its product risk assessment. When FAÚ initiated a desk-based review, the firm's alert volumes were unmanageable, its investigation workflow was undocumented, and it had not filed a single STR in two years of operation. We were engaged to rebuild the program architecture, recalibrate the monitoring rules against a purpose-built customer risk model, and prepare the MLRO to respond to FAÚ's information requests. The firm addressed the findings within the supervisory timeframe and retained its registration. The core lesson: the tool is not the program. The program is the governance structure that surrounds the tool.
Does an offshore licence eliminate Czech AML obligations?
A common assumption among operators entering the Czech market is that a registration or licence obtained in a less demanding jurisdiction – whether a Caribbean VASP registration or a historic Baltic AML filing – removes the obligation to comply with Czech law when serving Czech clients. This assumption is incorrect, and it is becoming more costly to act on.
Czech AML law, like the EU AML Directives it implements, applies to obliged entities on the basis of activity, not registration. A firm that provides virtual asset services to Czech-resident clients is an obliged entity for Czech AML purposes, regardless of where it is incorporated. FAÚ does not recognise an offshore registration as a substitute for Czech compliance; it treats it as a separate, potentially aggravating factor.
Under MiCA, the position is becoming formally clearer. CASP authorisation is required for firms offering crypto-asset services across the EU. An offshore-registered VASP without a CASP authorisation – or a transitional arrangement with a national competent authority – will not be able to passport into the Czech market legally as MiCA is fully implemented. Operators who planned their structure around offshore registration alone should treat the MiCA transition timeline as a restructuring trigger, not a background regulatory development.
If a prior compliance review stalled or a banking relationship was closed, a second read of the program can identify the structural cause. To discuss your position, write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw.
Which monitoring architecture suits which operator profile?
The right monitoring architecture depends on the firm's product complexity, client risk profile, and the jurisdictions its transfers touch. The following profiles represent the main decision branches we work through with clients.
Profile A – Early-stage Czech VASP, single product, domestic client base. A new exchange serving Czech retail clients with a single fiat-to-crypto product. The appropriate architecture is a customer risk model built on the firm's actual onboarding data, a monitoring tool with rules calibrated to the product's velocity and value patterns, a documented investigation workflow, and MLRO governance with direct FAÚ contact. The Travel Rule posture is relatively contained – transfers are primarily to and from Czech-resident wallets and a small set of counterparty exchanges. Timeline to a compliant, documented program: a matter of weeks with proper specification.
Profile B – EU-licensed VASP passporting into Czech Republic, cross-border client base. A CASP authorised in another EU member state that is expanding its Czech market presence. The monitoring architecture must satisfy both the home-state NCA and FAÚ's AML jurisdiction. The Travel Rule component is material – transfers across multiple EU and non-EU jurisdictions require a counterparty register and asymmetric-data management. The MLRO function must demonstrably cover the Czech client population. Timeline to augmented program: longer, because the architecture must layer onto an existing system without disrupting home-state compliance posture.
Profile C – Non-EU VASP with Czech-resident clients, no EU registration. The highest-risk profile. The firm is an obliged entity under Czech AML law but has no supervisory relationship with FAÚ. The immediate priority is a gap analysis: what activities trigger Czech obligations, what the registration pathway looks like, and whether the product can be structured to limit Czech-market exposure while the registration is obtained. Continuing to operate without engagement is an enforcement risk. The monitoring architecture question cannot be answered independently of the registration question.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – full-scope AML program design, Travel Rule implementation and ongoing MLRO support across jurisdictions
- AML/CFT policy drafting in Turkey – jurisdiction-specific AML policy work for operators expanding into emerging VASP regimes
- Hong Kong vs United Kingdom: where to license a crypto business – comparative licensing analysis for operators choosing between major regulated hubs
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP to collect, verify and transmit originator and beneficiary identification data alongside every qualifying virtual asset transfer. In the Czech Republic, the obligation derives from the EU Funds Transfer Regulation as applied to crypto assets. The data must travel with the transaction to the receiving VASP. Where a counterparty cannot receive or transmit the required data, the sending VASP must assess whether to proceed with the transfer at all – and document that assessment. Thresholds and precise data fields vary by jurisdiction and should be confirmed against current legislation.
Who must act as MLRO for a crypto firm?
Czech AML law requires every obliged entity to designate a Money Laundering Reporting Officer (MLRO) – an individual with sufficient authority, resource access and AML knowledge to manage the firm's compliance program and act as the formal channel for suspicious transaction reports to FAÚ. The MLRO need not be Czech-resident, but the function must be substantively exercised in relation to the Czech client population. FAÚ will assess the adequacy of the appointment during any supervisory review. A shared or nominal MLRO who cannot demonstrate active oversight of Czech-market activity is a supervisory finding waiting to happen.
How do regulators audit crypto AML programs?
FAÚ and other EU AML supervisors typically combine desk-based document review with on-site or remote inspection. Inspectors examine the written AML policy, the customer risk model, alert logs, investigation records and STR-filing history. They will test whether the documented program matches operational practice. Blockchain analytics capability, Travel Rule implementation records, and MLRO appointment documentation are all within scope. The most common findings concern undocumented investigation workflows, static monitoring rules and inadequate counterparty due diligence. A program that is operationally sound but poorly documented will still generate findings.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance programs that regulators and banks require. We map the licence stack across operating, custody and payment layers before you commit – and we advise clients who have already committed and need the structure corrected. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialises in AML program architecture, VASP registration and supervisory engagement for digital-asset businesses in EU and Central European jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.