What AML/CFT obligations apply to crypto-asset service providers?
Why CASPs carry the same AML/CFT duties as banks and investment firms, when due diligence applies, how the EU travel rule works for crypto-asset transfers, and what CySEC's 2021 policy statement covered.
By the ExamPass CY editorial teamLast reviewed 5 min read
Topic 5 of 5 · all topics in this chapter
Short answer
CASPs count as obliged entities for AML/CFT purposes, supervised by CySEC, so every AML/CFT duty applies to them: risk assessment, customer due diligence including enhanced measures, beneficial owners, economic profiles and source of funds, ongoing monitoring, suspicious transaction reporting to MOKAS, record keeping and training. Due diligence also applies to occasional transactions of €1,000 or more. Since 30 December 2024 the EU travel rule requires sender and recipient information to accompany every crypto-asset transfer made or received by a CASP, whatever its size. The aim is preventing money laundering and terrorist financing.
CASP AML/CFT duties at a glance
| Point | Rule |
|---|---|
| Status | Obliged entities under Law 188(I)/2007 (as financial organisations since Law 96(I)/2025); a firm whose only crypto-asset service is advice falls outside the definition |
| AML supervisor | CySEC (Article 59(1)(b)(vii)) |
| Duties | Risk assessment, CDD and EDD, beneficial owners, economic profile, source of funds, monitoring, reporting to MOKAS, records, training |
| Occasional transactions | CDD at €1,000 or more, in one operation or several that appear linked (Article 60) |
| Travel rule | Regulation (EU) 2023/1113 since 30 December 2024: originator and beneficiary information with every crypto-asset transfer involving a CASP, no minimum amount |
| Self-hosted addresses | Extra checks and risk-mitigating measures; for transfers over €1,000, adequate measures to assess whether the address is owned or controlled by the client |
| PS-01-2021 | CySEC's 2021 policy statement explaining the national CASP rules; its regime ended on 1 July 2026 |
Source: Law 188(I)/2007, Articles 2, 2A, 59, 60 and 64, as amended by Law 96(I)/2025; Regulation (EU) 2023/1113, Articles 14, 16 and 40; CySEC Circular C675; CySEC Policy Statement PS-01-2021.
Why do CASPs have the same AML/CFT duties as other firms?
Crypto-assets can be moved quickly across borders and through many addresses, which makes them attractive for laundering money and financing terrorism. The AML/CFT Law therefore treats CASPs as obliged entities. Since Law 96(I)/2025 a CASP is defined as in MiCA (a firm whose only service is advice on crypto-assets is not covered) and counts as a financial organisation under the Law, and CySEC supervises CASPs for AML/CFT purposes.
Being an obliged entity means the whole AML/CFT framework applies, exactly as for a bank or an investment firm: a firm-wide risk assessment and proportionate measures for each client, activity and crypto-asset; customer due diligence, with enhanced measures for higher risk; identifying beneficial owners; building an economic profile and establishing the source of clients' funds; ongoing monitoring of transactions; reporting suspicious transactions to MOKAS; keeping records; appointing a compliance officer and training staff. The purpose is preventing money laundering and terrorist financing, not protecting investors from price swings.
Due diligence applies when a business relationship starts, whenever there is a suspicion, when there are doubts about identification data obtained earlier, and for occasional transactions of €1,000 or more, whether carried out in one operation or in several that appear to be linked.
Terms used in this note
- Travel rule
- The requirement that information on the sender and the recipient travels with a transfer of funds or crypto-assets.
- Self-hosted address
- A crypto-asset address or wallet controlled by its user rather than held with a CASP.
- Obliged entity
- A person or firm that must apply the AML/CFT Law's measures, such as due diligence and reporting suspicions.
What is the travel rule for crypto-asset transfers?
Since 30 December 2024, Regulation (EU) 2023/1113 has required CASPs to send information on the originator and the beneficiary with every transfer of crypto-assets, and to check that the information arrives with the transfers they receive. There is no minimum amount: the rule applies whenever a CASP is involved. CySEC has told CASPs to follow the EBA's travel rule guidelines, which apply from the same date.
Transfers to or from self-hosted addresses, meaning wallets not held with a CASP, need extra care. The CASP collects the information about the transfer, assesses the risks and, for transfers above €1,000 involving its own client, takes adequate measures to assess whether the self-hosted address is owned or controlled by that client. Cyprus law also requires CASPs to have policies to identify and manage the risks of such transfers, and CySEC can sanction repeated failures to send the required information.
What was CySEC's policy statement PS-01-2021?
In 2021 CySEC issued Policy Statement PS-01-2021 on the registration and operations of CASPs. It explained the national rules that applied to them: the AML/CFT Law, CySEC's Directive for the register of CASPs and CySEC's AML/CFT Directive, and it included CySEC's early guidance on sending information with crypto-asset transfers.
The statement describes a regime that ended when MiCA's transitional period finished on 1 July 2026, and its travel rule guidance has been replaced by the EU regulation. The AML/CFT duties themselves continue for CASPs authorised under MiCA, as updated by Law 96(I)/2025 and the EU travel rule.
How to think about it
Answer CASP AML questions exactly as you would for a bank or an investment firm: risk-based CDD and EDD, beneficial owners, source of funds, monitoring, reporting to MOKAS, records and training, all supervised by CySEC. The objective is preventing ML/TF, not investor protection or volatility control. Then add the crypto-specific points: CDD for occasional transactions from €1,000, and the travel rule on every crypto-asset transfer involving a CASP, with no minimum.
Common mistakes
Treating CASPs as outside the AML/CFT Law. They are obliged entities, so all AML/CFT obligations apply.
Saying the aim of the rules is investor protection. The AML/CFT obligations exist to prevent money laundering and terrorist financing.
Applying the travel rule only above €1,000. The EU rule covers every crypto-asset transfer involving a CASP. Separately, CDD applies to occasional transactions of €1,000 or more, and extra checks apply to self-hosted transfers above €1,000.
Relying on PS-01-2021 as current guidance. It explained the national regime, which ended on 1 July 2026; the EU travel rule has replaced its transfer guidance.
Legal references
- The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), consolidated Greek text on CyLaw (amendments up to Law 25(I)/2026) (opens in a new tab)
Articles 2 and 2A: CASPs as financial organisations and obliged entities · Article 59: CySEC as supervisor · Article 60: CDD triggers · Article 64(5): self-hosted addresses
- Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets (opens in a new tab)
Articles 14 and 16: information with crypto-asset transfers and checks, including self-hosted addresses · Article 40: application from 30 December 2024
- CySEC Circular C675: Regulation (EU) 2023/1113 and EBA guidelines (27 December 2024) (opens in a new tab)
- CySEC Policy Statement PS-01-2021 on the registration and operations of CASPs (opens in a new tab)
Practise this topic
Test what you just read
The Chapter 8 pack has 35 exam-style questions, 4 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 15 free Chapter 8 flashcards →