Skip to main content
The CASP Directory
Checklist

The EU crypto travel rule and AML rules for CASPs

MiCA authorises you; the Transfer of Funds Regulation and the EU AML framework govern how you handle transfers and onboard clients. A plain map of how the three stack, the no-threshold rule for CASP-to-CASP transfers, the self-hosted wallet measures, and the 2027 anonymity ban.

Three regimes, not one

A compliant CASP sits under three stacked obligations, and meeting one does not satisfy the others. MiCA authorises the firm and governs conduct, custody, and prudential rules. The Transfer of Funds Regulation (the EU travel rule) governs the information that must travel with crypto transfers. The EU anti-money-laundering framework governs customer due diligence and reporting. You need all three.

Informational only, not legal or compliance advice. Confirm current obligations against the regulations and your national authority before acting.

The three layers

MiCA

Authorisation and conduct: licensing, custody (Article 75), governance (Article 68), and prudential safeguards (Article 67). Applies to CASP services from 30 December 2024.

Travel Rule (TFR)

Regulation (EU) 2023/1113. Originator and beneficiary information must accompany crypto transfers. Applies to CASPs from 30 December 2024, alongside MiCA.

AML framework

The AML Regulation (EU) 2024/1624 and the new EU authority AMLA set customer due diligence, beneficial-ownership, and reporting duties, phasing in across 2026 to 2028.

What the travel rule actually requires

  • For transfers between CASPs, there is no de minimis threshold: originator and beneficiary information must accompany the transfer regardless of amount. This is stricter than the fiat travel rule, which keeps a €1,000 threshold.
  • For transfers to or from a self-hosted (unhosted) wallet, additional measures apply above €1,000, including verifying that your customer owns or controls the wallet.
  • Required data includes names, the originator’s account or wallet address, and identifiers; missing-information procedures must decide whether to execute, reject, or return a transfer.
  • Keep records and run risk-based monitoring on transfers below the verification threshold too.

What the AML rules add

  • Customer due diligence and identity verification, with enhanced measures for higher-risk relationships.
  • Beneficial-ownership checks and ongoing monitoring.
  • Suspicious-transaction reporting to the national financial intelligence unit.
  • From 10 July 2027 the AML Regulation prohibits CASPs from keeping anonymous accounts and from handling anonymity-enhancing crypto-assets such as privacy coins. This is an AML rule, not MiCA, and it does not stop individuals self-custodying those assets.
  • AMLA, the new EU anti-money-laundering authority, will directly or indirectly supervise parts of the sector as it stands up.

How to keep it straight

When a question comes up, attribute it to the right regime first, because the answer and the deadline differ. “Do I need a licence” is MiCA. “What data rides with this transfer” is the travel rule. “Who is this customer and is this suspicious” is AML. “Can I offer an anonymous account or a privacy coin” is the AML Regulation, from July 2027. Build the evidence once, to the strictest applicable standard, and map each control to its regime so an examiner can follow it.

Useful next pages

MiCA and CASP FAQ

Short answers on the travel rule, self-custody, and the privacy-coin question.