EST · MMXXVI
Home/Jurisdictions/France/Sanctions screening for crypto in France (AMF/PSAN)
Compliance, AML & Travel Rule

Sanctions screening for crypto in France (AMF/PSAN)

Sanctions screening for crypto in France (AMF/PSAN). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS

France's PSAN (prestataire de services sur actifs numériques) regime, administered jointly by the Autorité des marchés financiers (AMF) and the Autorité de contrôle prudentiel et de résolution (ACPR), requires every registered or authorised crypto service provider to maintain a real-time sanctions screening program aligned with European Union financial sanctions law and FATF Recommendation 15 (the obligation to apply anti-money-laundering and counter-terrorist-financing controls to virtual asset activity). Operating without that program — or operating with one that cannot demonstrate completeness — exposes the business to regulatory enforcement, suspension of PSAN registration and the closure of euro-denominated banking rails. This page sets out the legal basis, the practical program requirements, the cross-border complications and the decision points for an inbound operator building or correcting its compliance posture in France.

Sanctions screening for a PSAN-registered or PSAN-authorised firm rests on two interlocking pillars: EU sanctions regulations — which apply directly in France without domestic transposition — and the national AML/CFT framework that sits beneath the Directive on Prevention of Use of the Financial System for Money Laundering or Terrorist Financing (commonly called AMLD). The AMF sets the registration and authorisation conditions; the ACPR carries primary supervisory responsibility for AML/CFT compliance by PSANs. Both regulators may issue an enforcement action. A PSAN that ignores sanctions exposure is therefore facing two separate supervisory lines.

EU sanctions are administered centrally by the European Commission. The relevant EU designations cover individuals, entities and jurisdictions. A French-registered PSAN must screen all customers, counterparties, wallet addresses and transaction flows against those consolidated lists. The obligation is continuous — not a one-time onboarding check. Regulators expect a documented, systematic process that catches new designations within hours of publication.

The domestic AML layer adds enhanced due diligence triggers, suspicious transaction reporting to TRACFIN (the French financial intelligence unit), and internal governance requirements: a dedicated responsable de la conformité, documented risk appetite and written procedures. The ACPR supervises these domestic obligations. Where the two frameworks interact — as they do at every sanctions hit — the PSAN must follow the stricter standard.

Who is required to comply, and does a PSAN registration alone trigger the full obligation?

Every entity holding PSAN registration or authorisation under French law is within scope of the full sanctions and AML regime from the moment the registration is granted — there is no grace period or reduced-obligation track. The PSAN regime covers at minimum: custody of digital assets, buying and selling digital assets against legal tender, and operating a digital-asset trading platform. Advisory, portfolio management and related services fall under the optional authorisation track and carry equivalent compliance obligations once pursued.

A firm that obtained PSAN registration before the current supervisory posture tightened should not assume its original program remains adequate. The ACPR has increased the depth of its thematic reviews, and expectations around real-time screening, transaction monitoring and Travel Rule implementation have moved materially since the original regime launched.

Critically, the obligation follows the activity, not the corporate seat. A firm incorporated outside France that solicits French retail or professional clients without a PSAN registration is operating in breach of French financial law — and no offshore registration substitutes for the French registration where French clients are the target. We regularly advise operators who discover mid-build that their offshore structure does not protect them from ACPR scrutiny when their French user base becomes visible.

To assess whether your current structure triggers a French PSAN obligation — and whether your sanctions program meets current ACPR expectations — contact OBOLUS at info@oboluslaw.com. The process above describes the standard onboarding path. Your entity structure, user geography and token scope change the analysis materially.

What does a compliant sanctions screening program look like in practice?

A compliant program under the PSAN regime has five operational components, each of which the ACPR may examine during a thematic review or authorisation assessment.

First, list coverage. The program must screen against EU consolidated sanctions lists, OFAC's Specially Designated Nationals list where US-dollar flows are involved, and any UN Security Council list incorporated by EU regulation. A PSAN handling stablecoin flows — particularly USDT or USDC — should also account for issuer-level freeze authority: both Tether and Circle maintain contract-level blacklist capability and generally act on law-enforcement or OFAC designation. Omitting issuer-level risk from your sanctions matrix is a structural gap that regulators and correspondent banks will identify.

Second, wallet screening. Screening names and entities at onboarding is necessary but not sufficient. Regulators expect on-chain address screening against publicly maintained sanction-related wallet databases. A deposit from a sanctioned wallet address triggers an obligation regardless of whether the depositing customer passed name screening at account opening.

Third, transaction monitoring. Automated systems should flag transactions that meet pre-defined risk criteria — high-value transfers to high-risk jurisdictions, rapid consolidation of small deposits (a structuring pattern), and counterparty addresses linked to mixers or dark-market infrastructure identified in forensic databases. The monitoring ruleset must be documented, reviewed and updated periodically.

Fourth, escalation and reporting. A sanctions hit — a positive match against a designated individual or entity — requires immediate asset freeze, no-tipping-off compliance, and a report to TRACFIN. The PSAN must retain records of the match, the freeze action and the report. There is no discretion to release assets pending further review once a match is confirmed against an EU designation.

Fifth, governance and testing. The ACPR expects independent testing of the screening program at intervals proportionate to the firm's risk profile. For a trading platform with meaningful transaction volumes, annual independent testing is the baseline expectation. Results must be documented and acted upon.

How does the Travel Rule interact with sanctions screening for a French PSAN?

The Travel Rule (the obligation to pass originator and beneficiary identifying data with a virtual asset transfer) operates as a parallel compliance layer that amplifies sanctions exposure. Under the applicable EU Transfer of Funds Regulation provisions extended to crypto-asset transfers under MiCA, a sending PSAN must transmit originator data and a receiving PSAN must screen that data before crediting the transfer. A VASP that receives a transfer without the required data — or whose screening system cannot process the received data against sanctions lists — is carrying unquantified sanctions risk on every inbound transaction.

In our practice, the Travel Rule is where sanctions screening failures become most visible to regulators. A firm may have a credible name-screening program at onboarding but a manual, slow or incomplete process for screening Travel Rule data in transit. ACPR and its EU counterparts treat that gap as a material deficiency. The consequence is not merely a corrective action letter — it can affect the PSAN's ability to maintain correspondent banking relationships, since the bank's own AML team will assess the PSAN's Travel Rule posture.

The Travel Rule also has a cross-border dimension that catches operators off guard. A French PSAN sending assets to a VASP in a jurisdiction without Travel Rule implementation must still transmit the required data and document why the receiving entity could not complete the exchange. The obligation does not dissolve because the counterparty is in a non-compliant jurisdiction. Operators we advise routinely underestimate this asymmetry.

What are the cross-border complications for a PSAN's sanctions and banking posture?

A French PSAN holding euro rails through a French or EU credit institution faces a practical dynamic that goes beyond regulatory compliance: the bank's own sanctions team will conduct independent due diligence on the PSAN as a client. That review is ongoing, not a one-time KYB assessment. A PSAN whose transaction monitoring generates unexplained anomalies — or whose customer book includes counterparties that the bank's own systems flag — risks a unilateral account closure. Banking loss is frequently faster and more operationally damaging than a formal ACPR enforcement action.

For a PSAN with cross-border operations — a parent or subsidiary in the UAE under VARA, a holding structure in the ADGM, or a custody entity in Singapore under the Payment Services Act — the sanctions posture of the group matters. A PSAN registered in France with a group entity in a sanctioned jurisdiction or with a beneficial owner structure that has not been fully disclosed to the AMF and ACPR will face questions that go beyond the French operation alone. Regulators communicate. Group-level sanctions risk is consolidated back to the regulated French entity.

Tax is a secondary but real interaction. Where a French PSAN is part of a group structure, transfer pricing on inter-company service arrangements — technology services, compliance platforms, data feeds — must be defensible. The French tax authority pays close attention to arrangements that shift margin from the regulated French entity to offshore affiliates. We map the licence, banking and tax stack together because in practice they are interconnected; a structure optimised for tax but opaque to the ACPR is a liability.

If a prior application stalled or a banking relationship was closed, a second assessment can surface the structural reason and the route forward. Contact OBOLUS at info@oboluslaw.com.

A sanctions gap identified before enforcement: how a French PSAN avoided deregistration

In a recent compliance matter, a payments technology company holding PSAN registration discovered during an internal audit that its wallet screening did not cover a category of inbound transfers routed through a non-EU VASP. The gap had existed since registration and had generated several unscreened transactions involving addresses later listed in EU sanctions updates. We advised on the scope of the retrospective screening review, the appropriate voluntary disclosure framework toward the ACPR, and the design of a remediated program covering both wallet-level and Travel Rule data screening. The matter was resolved through structured supervisory engagement; the registration was maintained and the firm upgraded its compliance infrastructure before any formal enforcement action was issued. Timing was critical — the firm's annual supervisory cycle was weeks away when the gap was identified.

Which operator profile needs what level of sanctions program in France?

The appropriate program depth turns on three axes: the licence category held, the transaction volume and client risk profile, and the group structure around the French entity.

A startup PSAN holding only the custody and buy/sell registration, with a limited French retail client base and no cross-border VASP-to-VASP transfers, can operate a proportionate program: automated name and wallet screening at onboarding, a documented monitoring ruleset, manual escalation to the responsable de la conformité, and annual independent testing. That is the floor, not the target. As volume grows, manual escalation becomes untenable.

A trading platform PSAN with institutional counterparties, significant transaction volumes and inbound flows from multiple jurisdictions needs an automated real-time system: API-connected list screening updated within hours of EU designation updates, automated Travel Rule data ingestion and screening, a tiered monitoring ruleset calibrated to the platform's specific risk typologies, a dedicated MLRO-equivalent with direct board reporting, and quarterly internal and annual independent testing. Regulators at this tier expect the firm to demonstrate program adequacy proactively — not in response to an examination finding.

A group-embedded PSAN — one that is part of a larger digital-asset group with entities in VARA, ADGM or MAS-regulated jurisdictions — must additionally manage the group-level sanctions matrix. Jurisdictional differences in sanctions list coverage, de-minimis thresholds and reporting obligations mean the group compliance function cannot simply export one program to every entity. The French entity bears responsibility for the adequacy of its own program regardless of what the group does centrally.

What are the most common sanctions compliance mistakes made by PSANs in France?

Regulators in the leading hubs increasingly expect firms to self-identify weaknesses before examination. In our cross-border practice, we see the same categories of failure repeat across PSAN applicants and existing registrants.

The first is treating sanctions screening as an onboarding event rather than a continuous process. A customer who clears screening on day one may be designated on day one hundred. Systems must re-screen the existing customer book against updated lists at regular, documented intervals — and immediately on notification of a new EU designation batch.

The second is wallet screening that covers only counterparty exchanges, not the ultimate originating address. Chain-of-custody analysis matters. A transfer routed through a compliant intermediary VASP does not insulate the receiving PSAN from liability if the original source wallet is sanctioned.

The third is a Travel Rule implementation that handles outbound flows only. Inbound Travel Rule data must be screened. Many PSANs implement outbound data transmission correctly and then credit inbound transfers without screening the originator data received. That asymmetry is precisely what examination teams look for.

The fourth is documentation failure. A PSAN may in practice operate a sound program, but if the procedures are not written, the risk assessment is not current, and the testing results are not retained, the ACPR cannot assess adequacy during a review. Regulatory capital adequacy can be demonstrated with a number; compliance program adequacy requires documentation.

A common assumption among operators entering France is that a pre-existing compliance program built for another EU jurisdiction — Malta, Lithuania or Cyprus — can be transposed directly without adaptation. That assumption is incorrect. The ACPR has its own supervisory expectations, its own guidance on risk categorisation and its own relationship with TRACFIN. A program that satisfies the Bank of Lithuania does not automatically satisfy the ACPR. We have seen operators discover this at the PSAN application stage, which is a manageable problem, and also at the first supervisory examination, which is not.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a virtual asset service provider to transmit identifying information about the originator and beneficiary of a virtual asset transfer alongside the transaction itself. For EU-regulated entities, including French PSANs, the applicable obligation is set out under the extended Transfer of Funds Regulation framework brought within the MiCA regime. Both the sending and receiving VASP carry obligations: the sender must transmit; the receiver must screen the transmitted data before crediting the funds. The specific data-threshold and de-minimis rules vary and should be confirmed against current legislation.

Who must act as MLRO for a crypto firm?

A French PSAN must designate a responsible person for AML/CFT compliance — functionally equivalent to a money-laundering reporting officer. That individual must have sufficient seniority and independence to escalate concerns to senior management or the board, and sufficient operational authority to freeze transactions and file suspicious transaction reports with TRACFIN. The ACPR will assess the adequacy of that designation as part of its supervisory review. In practice, the role must be filled by a natural person with documented competence in financial crime prevention — not a compliance function shared with an external service provider without clear internal accountability.

How do regulators audit crypto AML programs?

The ACPR conducts thematic reviews and firm-specific examinations of PSAN AML/CFT programs. An examination will typically assess: the written risk assessment, the customer due diligence procedures, the transaction monitoring ruleset and alert management records, the Travel Rule data handling logs, the sanctions screening coverage and hit-management documentation, TRACFIN reporting history, and governance records including board and compliance committee minutes. Gaps in documentation are treated as program deficiencies even where the underlying controls are operational. Firms should expect examinations to extend to the technology and service providers underpinning the compliance function.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit — and where a prior application stalled or banking was lost, we surface the structural reason and the route forward. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst — specialising in PSAN, CASP and VASP compliance program design, sanctions screening and ACPR supervisory engagement across the EU and cross-border digital-asset operations.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours