EST · MMXXVI
Home/Jurisdictions/Eu Mica/AML and travel rule regime in European Union (MiCA)
Compliance, AML & Travel Rule

AML and travel rule regime in European Union (MiCA)

Aml and travel rule regime in European Union (MiCA). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS

For a CASP (crypto-asset service provider) seeking authorisation under MiCA (the Markets in Crypto-Assets Regulation), the anti-money laundering regime is not optional background compliance – it is a condition precedent to operating lawfully in the European Union. ESMA and the relevant national competent authority will scrutinize AML and KYC frameworks as part of the authorisation review. Getting this wrong does not merely delay a licence application; it triggers enforcement, frozen banking rails and the loss of the EU passport.

This page sets out the regulated basis for AML and Travel Rule obligations under the EU-MiCA environment, maps the process for an inbound operator, addresses the cross-border complications that practitioners encounter most frequently, and identifies the decision points that determine whether a business is genuinely compliant or merely technically registered.

What is the legal basis for AML obligations on CASPs under MiCA?

The AML obligations on CASPs operate on two intersecting legal tracks. MiCA governs market conduct, authorisation and the whitepaper regime. The Anti-Money Laundering Directives – and the evolving EU AML/CFT package replacing them – govern customer due diligence, beneficial ownership verification, transaction monitoring and suspicious transaction reporting. In our practice, the two tracks are inseparable: a CASP that passes MiCA authorisation review but cannot demonstrate a functioning AML program will find its licence suspended or conditions attached before operations begin.

ESMA and national competent authorities treat AML fitness as a prerequisite, not an afterthought. The EU's dedicated AML Authority – AMLA – is scheduled to assume direct supervisory competence over the highest-risk CASPs operating across the Union, a structural shift that significantly raises the compliance bar for any exchange or custodian with material EU volume. Operators we advise have consistently found that the practical AML standards expected at the EU level now match or exceed those in other leading hubs.

For an inbound business, this means the AML architecture must be designed before the MiCA application is filed, not retrofitted after authorisation is granted.

For a scoped assessment of your MiCA AML readiness before filing, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base geography and the banking relationships – change the analysis materially. Map your options

What does the Travel Rule require from CASPs operating in the EU?

The Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer) applies to all CASPs transferring crypto-assets on behalf of customers, and its implementation in EU law brings it substantially into line with FATF Recommendation 15 as the global standard. Under the applicable EU Transfer of Funds Regulation provisions – extended to crypto-asset transfers – the transferring CASP must obtain, verify and transmit originator information, and the beneficiary CASP must detect and handle transfers where required information is missing or incomplete.

The practical mechanics raise four issues that recur in every mandate we handle. First, the de-minimis threshold determines which transfers trigger full Travel Rule data obligations; the specific figure is set by the applicable EU regulation and is subject to review, so operators should consult current legislation rather than rely on market summaries. Second, data must be transmitted before or simultaneously with the transfer – not after settlement. Third, the standard requires CASP-to-CASP data exchange, which means counterparty identification: sending to an unhosted wallet raises distinct obligations. Fourth, record-keeping requirements attach to every transmittal, and regulators expect audit-ready logs.

Interoperability between Travel Rule solution providers remains a live operational challenge. We have seen cases where a CASP's technical implementation was compliant on paper but failed in practice because its counterparty network operated on an incompatible messaging protocol. The result was gaps in the data chain – exactly what the regulatory audit will expose.

How does the KYC and CDD framework apply under the EU AML regime?

Customer due diligence for CASPs under the EU framework is risk-based, meaning the depth of verification scales with the assessed risk of the customer and the transaction type. Standard CDD covers identity verification, beneficial ownership identification and the purpose of the relationship. Enhanced due diligence applies to politically exposed persons, high-risk third-country nationals and transactions above applicable thresholds. Simplified CDD is available in defined low-risk circumstances, but regulators approach CASP reliance on simplified measures with scepticism given the pseudonymous nature of blockchain activity.

The KYC framework also requires CASPs to monitor ongoing relationships – not merely onboard. Transaction monitoring systems must flag unusual patterns against the customer's risk profile, and the outputs of those systems must feed a documented escalation process. ESMA's supervisory convergence guidance increasingly expects automated monitoring tools to be calibrated to crypto-specific typologies, including layering through decentralized protocols and rapid cross-chain movement. A static rules engine built for traditional payment monitoring will not satisfy a competent authority reviewing a CASP's AML controls.

In our cross-border practice, we see the KYC framework produce its most acute friction at the point of banking. European payment institution and e-money institution partners conducting their own due diligence on a CASP client will request evidence of the CASP's own KYC standards. A weak or undocumented onboarding framework is frequently the reason a CASP loses its banking relationship – not any formal regulatory action.

Who must act as MLRO and what governance does the EU AML regime require?

Every CASP subject to the EU AML regime must designate a Money Laundering Reporting Officer (MLRO), the individual responsible for receiving internal suspicious activity reports, making external disclosures to the relevant financial intelligence unit and maintaining the AML/CFT program. The MLRO must have sufficient seniority, independence and access to information to perform the function effectively – a requirement that national competent authorities assess both at authorisation and during ongoing supervision.

Governance requirements extend beyond the MLRO. Senior management must approve the AML policy, own the risk appetite and demonstrate awareness of the firm's exposure. Board-level AML reporting, documented risk assessments updated at a frequency commensurate with the firm's risk profile, and a culture of compliance that is demonstrable rather than asserted are all elements regulators examine during authorisation review and supervisory visits.

For a CASP structured with its licensed entity in one EU member state but management distributed across multiple countries – a structure we see frequently among scaling crypto businesses – the question of where the MLRO is physically located, who they report to and how quickly they can access transaction data across distributed infrastructure is a recurring point of friction with the supervising NCA. It is not a question that can be answered with an organisational chart alone.

How does the cross-border reality complicate MiCA AML compliance?

Operating a CASP under MiCA's passport means a single authorisation covers the EU/EEA – but AML compliance does not stop at the EU border. A CASP licensed in, say, a Baltic or Southern European member state and serving users across the EU must apply the host-member-state supervisory expectations of each market it passports into, while satisfying the home NCA's baseline requirements. Where AMLA assumes direct supervisory authority over high-risk cross-border CASPs, the compliance addressee shifts entirely.

The cross-border dimension intensifies further when the CASP's counterparties include firms regulated outside the EU. Transfers to exchanges operating under MAS in Singapore, the SFC in Hong Kong or VARA in Dubai trigger the Travel Rule's treatment of non-EU CASPs. The transferring EU CASP must assess whether the receiving firm is subject to equivalent AML requirements – a determination that requires both legal analysis and a documented counterparty risk framework.

Banking is the third cross-border pressure point. EU banks and payment institutions providing services to CASPs conduct their own correspondent banking due diligence. A CASP that has obtained MiCA authorisation but whose banking counterpart is located outside the EU – accessing the EU market through a correspondent – faces a layered de-risking risk. We map the licence, banking and compliance layers together, because solving the licence without solving the banking produces a firm that is authorised but operationally stranded.

If a prior application stalled or banking access was withdrawn, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw. Map your options

How do EU regulators audit a CASP's AML program in practice?

Supervisory examination of a CASP's AML program typically covers three dimensions: documentation, systems and culture. Documentation review includes the written AML/CFT policy, the business-wide risk assessment, the customer risk-rating methodology, the Travel Rule procedures manual and the MLRO's annual report. Systems review looks at the transaction monitoring engine, the sanctions screening setup, the Travel Rule technical solution and the data architecture supporting all of them. Culture is assessed through management interviews, governance minutes and the escalation record.

National competent authorities vary in their supervisory intensity, and the introduction of AMLA will create a more uniform high-water mark for the largest CASPs. In the interim, we have observed a material increase in thematic supervisory exercises focused on Travel Rule implementation – with regulators requesting evidence of actual data transmittals, not merely policy documents asserting compliance. A CASP that has the policy but cannot produce transmittal logs for a sample period is in a difficult supervisory position.

Sanctions screening deserves separate mention. EU sanctions regimes – including those administered by the EU itself and those implementing UN Security Council measures – require real-time screening of customers, counterparties and, in the view of leading NCAs, the wallet addresses involved in transfers. A CASP that screens customer names but does not screen wallet addresses is operating a materially incomplete sanctions compliance program.

A practical example of AML compliance in a cross-border context

In a recent licensing matter, a payments-focused operator sought MiCA authorisation through a member state NCA while simultaneously maintaining an existing entity registered under a prior national VASP regime. The AML program built for the legacy registration did not meet the enhanced documentation and transaction monitoring standards required under MiCA. We conducted a gap analysis across both entities, rebuilt the business-wide risk assessment to reflect the full EU user base, redesigned the Travel Rule procedures to address unhosted wallet transfers explicitly, and prepared the MLRO governance documentation from the ground up. The updated AML program was accepted as part of the authorisation package, and the firm retained its banking relationship through the transition. The matter completed within a single quarter.

Which compliance structure is right for your CASP profile?

The right AML architecture depends on the operator's activity set, geographic exposure and growth plan. Three profiles illustrate the decision points clearly.

A CASP providing custody services only – with no exchange or transfer activity – faces a materially lower Travel Rule burden than a full-service exchange. The key risk for a custody-only firm is the adequacy of its CDD at onboarding and its sanctions screening at the wallet address level. The compliance program can be lean, but it cannot be absent.

A CASP running an exchange with fiat-to-crypto conversion and cross-border withdrawals faces the full Travel Rule stack, a high-risk customer base by default and pressure from banking partners to demonstrate robust transaction monitoring. For this profile, the MLRO must be senior, the monitoring system must be crypto-specific and the Travel Rule solution must cover both EU and non-EU counterparty transfers. Timeline to a compliant state from a standing start is typically measured in months, not weeks.

A CASP structured as a DeFi-adjacent protocol or a non-custodial interface faces the most contested question in EU AML law: whether and to what extent the MiCA and AML frameworks apply to its activities. Regulators are actively developing guidance on this boundary. Operators in this space should not assume that a non-custodial structure provides a blanket exclusion from AML obligations; the substance of the activity, not its technical form, drives the analysis under the EU approach.

Related at OBOLUS

What are the most common AML compliance failures in MiCA applications?

A common assumption among operators preparing for MiCA authorisation is that passing the financial-crime section of the application checklist is sufficient for ongoing compliance. It is not. The AML program submitted at authorisation is a baseline; the NCA expects it to evolve as the firm's risk profile changes. A static compliance document filed in year one and never updated is itself a supervisory finding.

The mistakes we see most frequently are: an AML policy that was drafted for a different jurisdiction and not adapted to the EU framework; a transaction monitoring system that produces too many alerts to investigate meaningfully, creating a documented backlog that becomes a liability in examination; Travel Rule procedures that address inbound transfers but are silent on outbound or self-hosted wallet transfers; and an MLRO who is technically appointed but operationally excluded from governance decisions.

Each of these failures is correctable. None of them are correctable quickly once a supervisory review has commenced. The leverage is in the design phase.

FAQ

What does the Travel Rule require from a VASP?

Under the applicable EU Transfer of Funds Regulation provisions extended to crypto-asset transfers, a VASP – or CASP under MiCA – must obtain, verify and transmit originator and beneficiary information alongside every qualifying virtual asset transfer. The transferring firm is responsible for sending the data; the receiving firm must detect and manage transfers where required information is absent. Obligations apply before or simultaneously with the transfer, not after settlement. Record-keeping requirements attach to every transmittal for the mandatory retention period under the applicable EU AML legislation.

Who must act as MLRO for a crypto firm?

A CASP subject to EU AML requirements must designate an individual MLRO with sufficient seniority, independence and operational access to discharge the function. The MLRO receives internal suspicious activity reports, makes external disclosures to the relevant financial intelligence unit and owns the AML/CFT program on behalf of senior management. National competent authorities assess MLRO fitness both at authorisation and during ongoing supervision. For a cross-border operation, the question of the MLRO's physical location and reporting line relative to the licensed entity is a recurring supervisory focus.

How do regulators audit crypto AML programs?

EU national competent authorities and, increasingly, AMLA examine AML programs across three dimensions: documentation (written policy, business-wide risk assessment, MLRO reports), systems (transaction monitoring, sanctions screening, Travel Rule technical solution) and culture (governance minutes, management interview, escalation records). Thematic exercises on Travel Rule implementation are common, with regulators requesting actual transmittal logs rather than policy assertions. Sanctions screening of wallet addresses – not only customer names – is a focus area in current supervisory practice across leading EU member states.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and Travel Rule programs that sit around them. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your AML compliance position under MiCA, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in EU MiCA authorisation, CASP AML program design and cross-border compliance architecture.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours