How EU AMLR Changes KYC Obligations for Crypto Businesses

How EU AMLR Changes KYC Obligations for Crypto Businesses

Summary: The EU's Anti-Money Laundering Regulation has entered into force, but its obligations for obliged entities generally apply from 10 July 2027. In September 2026, EU crypto businesses remain subject to the existing AML framework alongside MiCA and the already applicable Transfer of Funds Regulation, while AMLA finalises the technical standards and guidance for the future Single Rulebook. AMLR does not introduce KYC from zero. It harmonises and further specifies customer due diligence across the EU, replacing a directive-based system that member states implemented differently. For crypto-asset service providers, the practical value of the transition period is gap analysis: identifying where current processes already meet the July 2027 framework and where they do not. AMLR defines the framework crypto businesses need to prepare for.

Note: None of this information should be considered as legal, tax, or investment advice. While we’ve done our best to ensure this information is accurate at the time of publication, laws and practices may change, so please double-check it.  

10 July 2027.

That date sits in Article 90 of Regulation (EU) 2024/1624, and it is the single most useful fact for an EU crypto business trying to work out what the Anti-Money Laundering Regulation requires of it today. The answer, as of 23 September 2026, is: not yet anything directly. AMLR was adopted in 2024 and entered into force after publication in the Official Journal, but the requirements it places on obliged entities generally begin to apply from that 2027 date.

(Source: Regulation (EU) 2024/1624, Article 90 — https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng)

That distinction matters commercially, not just as a point of legal pedantry, because a large amount of published commentary describes AMLR as though it is already reshaping KYC in Europe. It is not. What is reshaping KYC in Europe right now is a different set of instruments, and a compliance plan built on the wrong one will either over-engineer for rules that are still in draft or miss obligations that are already enforceable.

The accurate picture as of September 2026 has three layers. First, what applies today: MiCA authorization for crypto-asset service providers, the existing EU AML framework built on Directive (EU) 2015/849 as amended and transposed nationally, Regulation (EU) 2023/1113 for crypto transfer traceability, and the EBA guidance that supports it. Second, what is happening now: AMLA is developing the Level 2 technical standards and guidelines that will sit underneath AMLR, with two consultations directly relevant to KYC having run and closed during 2026. Third, what changes on 10 July 2027: AMLR becomes directly applicable, and a harmonised customer due diligence framework replaces the national variations that directives allowed.

Two dates have already changed the ground under EU crypto businesses without AMLR being involved at all. The MiCA transitional period for existing providers ended EU-wide on 1 July 2026, and the Transfer of Funds Regulation has applied since 30 December 2024. Those are current obligations, not future ones.

The through-line of this article is that AMLR does not invent KYC. Customer identification, verification, risk-based due diligence and ongoing monitoring all exist in EU law today. What AMLR changes is the legal form those obligations take, how uniform they are across member states, and how much detail sits behind each one.

AMLR and the EU AML Framework — What Applies in 2026?

Before looking at what changes, it helps to be precise about what is currently in force, because these instruments are routinely blurred together.

MiCA (Regulation (EU) 2023/1114)

Status on 23 September 2026: applicable; the EU-wide transitional period for existing providers ended 1 July 2026. Role: CASP authorization and sector regulation.

The AMLD framework (Directive (EU) 2015/849 as amended, transposed nationally)

Status: still the operative AML/CFT regime until AMLR applies. Role: current customer due diligence, reporting and recordkeeping obligations.

Transfer of Funds Regulation (Regulation (EU) 2023/1113)

Status: applicable since 30 December 2024, supported by EBA Travel Rule Guidelines from the same date. Role: traceability of crypto transfers — the EU Travel Rule.

AMLR (Regulation (EU) 2024/1624)

Status: in force as legislation; obligations for obliged entities generally apply from 10 July 2027. Role: the future directly applicable AML/CFT Single Rulebook.

AMLA (established under Regulation (EU) 2024/1620)

Status: operational and developing the Single Rulebook's technical standards; preparing its selection methodology for direct supervision. Role: standards and coordination now; direct supervision of a small number of selected entities later.

In practical terms, a CASP operating in the EU today answers to its national AML supervisor under nationally transposed rules, holds or is applying for MiCA authorization, and complies with the Travel Rule under the TFR. AMLR sits in the background as the framework that will replace the first of those three. The authorization side is a separate question from the AML side, and the MiCA authorization requirements for CASPs determine whether a firm may operate at all, not how it must run its KYC. On the transfer side, the EU Travel Rule requirements for CASPs are already enforceable and have been for well over a year.

One clarification worth making early, because it recurs in coverage of this topic: AMLR replacing the directive-based system does not mean national law becomes irrelevant. Member states retain roles under the accompanying directive, and national supervisors remain the day-to-day supervisors for most firms. What changes is that the substantive obligations stop being national transpositions and become a single regulation applying directly.

What AMLR Changes for Crypto KYC From July 2027

Start from the right baseline. Most of the core concepts in AMLR already exist in EU law: identifying and verifying customers, understanding beneficial ownership, assessing risk, monitoring the relationship over time, keeping records. A crypto business complying properly with its national AML rules today is not going to discover an entirely unfamiliar set of duties in July 2027. What AMLR changes is narrower and more structural:

  • Legal Form. A directly applicable regulation replaces national transpositions of a directive.
  • Consistency. The same text applies in every member state, removing the divergence that allowed the same activity to be handled differently in different countries.
  • Level of Detail. Obligations are specified more granularly, with technical standards adding further detail underneath.
  • Harmonised CDD. When due diligence is required, what must be collected, and how measures scale with risk are defined at EU level.
  • Customer-information requirements. What a firm must hold about a customer is set out with less room for interpretation.
  • Ongoing Monitoring. The framework for keeping information current and scrutinizing activity is formalized.
  • Governance and Controls. Internal organisation requirements are specified rather than left largely to national rules.

That list is deliberately unglamorous. The change is real, but it is a change in how existing obligations are written and enforced rather than the arrival of obligations nobody has seen before.

Customer Due Diligence Becomes More Uniform Across the EU

AMLR's due diligence architecture covers the familiar components: identifying the customer and verifying their identity, identifying beneficial owners where a legal entity is involved, understanding the purpose and intended nature of the business relationship, applying sanctions and politically exposed person checks, and monitoring the relationship on an ongoing basis. The substance of customer due diligence for crypto businesses does not change fundamentally; the uniformity of it does.

The provision most specific to crypto sits in Article 19, which addresses occasional transactions. Under AMLR, a CASP must apply full customer due diligence to an occasional transaction of EUR 1,000 or more. Below that figure, the obligation does not disappear — the CASP must still, at minimum, identify and verify the customer under Article 20(1)(a).

In practical terms, that means the AMLR threshold is not a line below which a crypto business can transact anonymously. It is a line that determines how much due diligence applies, with a verification floor underneath it. And critically, this is an AMLR rule that applies from July 2027. It is not the current general Travel Rule threshold, and confusing the two is one of the most common errors in EU crypto compliance writing — a point the Travel Rule section below addresses directly.

Ongoing Monitoring and Customer Data Updates

Ongoing monitoring is the part of AMLR most often misreported as an innovation. It is not new; it exists in the current framework and in FATF's standards. What AMLR does is specify it.

The expectations it formalizes are the ones a mature compliance function would recognize. Customer information should remain accurate and current rather than being archived after onboarding. Monitoring should compare what a customer actually does against what the firm knows about them. Changes in circumstances or activity can trigger reassessment rather than waiting for a scheduled review. And the frequency and depth of all of this should follow risk, with higher-risk relationships reviewed more often and more closely.

The new development here is not in the regulation but underneath it. On 3 June 2026, AMLA published a consultation paper on draft guidelines on the ongoing monitoring of business relationships under Article 26(5) of AMLR, covering how obliged entities should keep customer information up to date and how they should monitor transactions and activity. The consultation closed on 3 September 2026.

(Source: AMLA consultation on draft guidelines under Article 26(5) AMLR, 3 June – 3 September 2026 — https://www.amla.europa.eu/policy/public-consultations_en)

As of 23 September 2026 those guidelines remain draft. They indicate the direction of supervisory thinking, and they are worth reading by anyone designing monitoring systems now, but they should not be treated as settled requirements or implemented as though final. The operational capability they describe — continuous crypto transaction monitoring tied to customer context rather than running as a separate stream — is already what current supervisors expect, so building toward it is not a bet on a draft.

How Customer Identity and Transaction Activity Fit Together

This is where KYC stops being a filing exercise and starts doing work, and it is worth separating the two halves clearly.

The KYC profile supplies expected context: who the customer is, what they said they would use the account for, what kind of volumes and counterparties would be normal for someone in their position. Transaction monitoring tests whether actual activity fits that context. Neither half is useful alone. A verified identity with no behavioural baseline tells you nothing about whether today's transfer makes sense. An alert with no customer context produces noise that a reviewer cannot resolve.

Take the illustrative case of a retail customer who indicated at onboarding that they expected to trade a few thousand euros a month, and who six months later is moving ten times that. The important point is what that does and does not mean. An unusual change is not automatically suspicious activity. People change jobs, receive inheritances, sell property, or simply become more active traders. What the change creates is a reason to look: to reassess the customer's risk rating, to ask about source of funds where appropriate, and to update the profile with whatever the review establishes. Sometimes that ends in a suspicious transaction report. More often it ends in a corrected expectation and a customer file that now reflects reality.

That feedback loop — monitoring produces findings, findings update the profile, the updated profile changes what counts as normal — is the mechanism that keeps a KYC file from going stale. Under the current framework it is good practice supported by national rules. Under AMLR it becomes a harmonised expectation with technical standards behind it. These concepts are not entirely new; AMLR formalizes them.

Operationally, this requires the identity layer and the monitoring layer to share data rather than sitting in separate systems with separate owners. Most firms get there by connecting automated KYC and KYB verification at onboarding to the monitoring that runs afterwards, so that a risk rating derived from identity data is actually visible to the system generating alerts, and vice versa.

The Travel Rule Is Already in Force — and It Is Not AMLR

This section exists to correct a conflation that appears constantly, including in earlier versions of this article.

The EU Travel Rule for crypto comes from Regulation (EU) 2023/1113, the recast Transfer of Funds Regulation. It has applied since 30 December 2024, supported by EBA guidelines applicable from the same date. It is a separate legal instrument from AMLR. The two complement each other — traceability data is more useful when the underlying customer identification is sound — but they are different laws with different timelines, and AMLR does not create the Travel Rule.

(Source: Regulation (EU) 2023/1113 — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1113; EBA Guidelines on information requirements for transfers of funds and certain crypto-asset transfers — https://www.eba.europa.eu/activities/single-rulebook/regulatory-activities/anti-money-laundering-and-countering-financing-terrorism/guidelines-information-requirements-relation-transfers-funds-and-certain-crypto-assets-transfers)

In substance, the TFR requires information on the originator and the beneficiary to accompany crypto transfers mediated by CASPs, so that transfers can be traced and incomplete or missing information can be detected and acted on. There is no general EUR 1,000 de minimis exemption for CASP-mediated crypto transfers in the EU. This is the single most important correction in this article. Statements that the EU Travel Rule "applies above EUR 1,000" are wrong, and they lead businesses to build screening thresholds that leave them non-compliant on low-value transfers.

Where the EUR 1,000 Figure Actually Belongs

The EUR 1,000 figure that circulates in Travel Rule commentary relates to self-hosted addresses. Under the TFR, transfers involving a customer's self-hosted address attract an additional requirement to assess ownership or control when the relevant transfer exceeds EUR 1,000. That is a narrower function than a general exemption, and it does not switch off the underlying information requirements below that amount.

Two further clarifications follow from that. First, it is the TFR — not AMLR — that governs self-hosted transfer obligations today. Second, AMLR will add its own layer from July 2027: Article 40 provides a broader risk-based framework for transactions involving self-hosted addresses, which sits alongside rather than replacing the TFR requirements. Businesses should not describe either rule as the other's, and should not assume the future AMLR framework changes what applies now. The detailed mechanics are covered in the EU Crypto Travel Rule requirements.

To restate the two thresholds cleanly, because they are easy to merge: the EUR 1,000 in AMLR Article 19 concerns full CDD for occasional CASP transactions from July 2027. The EUR 1,000 in the TFR concerns additional ownership or control assessment for certain self-hosted-address transfers, and applies today. Different instruments, different functions, different dates.

Which Crypto Businesses Will AMLR Cover?

AMLR brings crypto-asset service providers within its obliged-entity framework, and it does so by reference to EU legal definitions connected to the MiCA crypto-asset service framework rather than by listing business types informally.

That distinction matters because scope questions in crypto are usually answered badly. The activities clearly within the CASP concept include exchanging crypto-assets for funds, exchanging crypto-assets for other crypto-assets, providing custody and administration of crypto-assets on behalf of clients, operating a trading platform, executing orders, providing transfer services for crypto-assets on behalf of clients, and the other services defined in the EU framework.

What this article will not do is assert that decentralized finance protocols, NFT projects, mining pools, gaming platforms or metaverse services are automatically within scope. Some entities operating in those areas may fall within an obliged-entity category depending on what they actually do and how they are structured; others will not. Scope depends on the actual service performed and whether the entity falls within an obliged-entity category — not on which sector label the business uses.

In practical terms, a firm with a non-standard model should resolve that question against the legal definitions with proper advice, rather than against a list in an article. The cost of getting it wrong runs in both directions: an unregulated firm discovering it should have been authorised, or a firm building a full compliance programme it did not need.

Governance and Accountability Under the New Framework

AMLR will require more than documented procedures. From July 2027 it sets expectations about how compliance is organised internally: written policies, controls and procedures proportionate to the business; a designated member of senior management responsible for AML/CFT; a compliance function with adequate resources, including staff and technology, proportionate to the entity's size, nature and risks; staff training; independent testing; and recordkeeping.

The proportionality point deserves emphasis, because it is often read as a demand for large compliance departments. A small crypto payments firm will not be expected to mirror the structure of a major exchange. What it will be expected to show is that someone identifiable owns the obligation, that the function has the authority and access to do its job, and that the controls match the risk the business actually carries.

AMLA's Role Is Not What Most Coverage Suggests

AMLA is operational and doing substantial work, but it does not directly supervise EU crypto businesses in 2026, and it is not going to directly supervise most of them ever.

The design is narrow by construction. AMLA is to begin its first selection process by 1 July 2027 and conclude it within six months, with direct supervision of the selected entities starting from 1 January 2028. The population is small — around 40 of the highest-risk credit and financial institutions or groups operating across at least six member states — and selection then repeats periodically.

(Source: AMLA, explainer on direct supervision and final reports on the selection RTS — https://www.amla.europa.eu/policy_en)

For the overwhelming majority of CASPs, the practical supervisor remains the national authority. AMLA's relevance is indirect but real: it writes the technical standards and guidelines that national supervisors will apply, which is why its 2026 consultations matter more to an ordinary crypto business than its supervisory mandate does.

What AMLA Has Already Clarified in 2026

Two AMLA workstreams bear directly on crypto KYC. Both ran as public consultations during 2026, and both are closed but not yet final as of 23 September 2026.

Draft RTS on Customer Due Diligence

On 9 February 2026, AMLA launched a consultation on draft regulatory technical standards under Article 28(1) of AMLR, specifying in more detail the requirements and information to be collected for standard, simplified and enhanced customer due diligence. The same round included draft RTS on the criteria for identifying business relationships, occasional transactions and linked transactions under Article 19(9) — directly relevant to the occasional-transaction threshold discussed above. The consultation closed on 8 May 2026.

(Source: AMLA, consultation on the draft RTS on Customer Due Diligence — https://www.amla.europa.eu/policy/public-consultations/consultation-draft-rts-customer-due-diligence_en)

These drafts indicate what "collect the information" is likely to mean in operational terms once AMLR applies. They are not yet binding, and the final standards submitted to the European Commission may differ from the consulted versions.

Draft Guidelines on Ongoing Monitoring

The second workstream, described earlier, is the draft guidelines under Article 26(5) covering the ongoing monitoring of business relationships — keeping customer information up to date, and monitoring transactions and activity. That consultation ran from 3 June to 3 September 2026.

The reason to track both is timing rather than curiosity. The underlying AMLR requirements apply from 10 July 2027, which means the window between final standards and the application date is short. A firm that waits for everything to be finalised before starting will have very little time to implement.

What Crypto Businesses Should Do Before July 2027

This is a gap analysis, not a compliance checklist. The useful exercise is comparing what a business does now against what the July 2027 framework will require, and identifying where those differ.

Areas worth examining:

  • whether the customer data currently collected maps to AMLR's CDD requirements, or whether fields are missing;
  • how and when customer information is refreshed, and whether that cadence is risk-based or calendar-based by default;
  • whether the customer profile and the transaction monitoring system are actually connected, or only nominally;
  • what triggers a risk reassessment, and whether those triggers fire automatically or depend on someone noticing;
  • how sanctions and PEP screening runs, and how often it re-runs against existing customers;
  • how enhanced due diligence is escalated, by whom, and on what evidence;
  • what records exist, in what form, and how quickly they could be produced to a supervisor;
  • who owns AML/CFT accountability at management level, in writing;
  • whether third-party KYC and monitoring providers can supply the audit evidence a supervisor would ask for, not just the decision output.

That last point is easy to miss and expensive to discover late. Outsourcing execution does not outsource accountability, and a vendor that cannot produce a defensible record of why a decision was made leaves the gap with the regulated firm. It is one of the considerations that should shape how a business selects an AML platform for EU crypto compliance during the transition rather than after it.

One caution on all of this: the AMLA drafts discussed above may change before they are finalized. Building systems that are flexible in configuration, rather than hard-coded to a consulted draft, is the sensible posture for the next nine months.

Preparing for Two Different Sets of Rules

AMLR is adopted and in force as legislation. Its application to obliged entities generally begins on 10 July 2027. Those two statements are not in tension, and holding both is the whole point.

Meanwhile, the framework EU crypto businesses actually operate under has already changed substantially without AMLR's involvement. MiCA's transitional period ended on 1 July 2026, and the Transfer of Funds Regulation has applied since 30 December 2024. A CASP that has not addressed those is behind on obligations that are enforceable today, regardless of what happens in 2027.

The direction of travel is clear enough to plan against. Customer due diligence becomes more uniform, ongoing monitoring becomes more specified, and governance expectations become explicit. What remains uncertain is the detail, because AMLA's technical standards and guidelines on exactly those subjects are still being finalized, and treating consulted drafts as final rules is its own kind of error.

Crypto businesses should distinguish between obligations already enforceable today and AMLR requirements they need to prepare to apply from July 2027. Those are two different compliance conversations, and running them together is how firms end up simultaneously over-prepared and non-compliant.

If it would help to pressure-test where your current KYC and monitoring setup sits against the July 2027 framework, that gap analysis is a good use of the transition period — and it is considerably cheaper now than it will be in mid-2027.

FAQ

Is the EU AMLR Already Applicable in 2026?

No. Regulation (EU) 2024/1624 has entered into force, but most of its requirements for obliged entities apply from 10 July 2027. In 2026, crypto-asset service providers are still operating under the existing EU AML framework together with MiCA and the already applicable Transfer of Funds Regulation.

When Does AMLR Apply to Crypto Businesses?

AMLR's relevant obligations for CASPs and other private-sector obliged entities apply from 10 July 2027, as set out in Article 90 of the Regulation. It is not being phased in gradually across 2025 and 2026. Until that date, national AML rules transposed from the existing directive framework remain the operative requirements.

What AML Rules Apply to EU CASPs in 2026?

Four things. The existing EU AML framework based on Directive (EU) 2015/849 as amended and transposed into national law. Regulation (EU) 2023/1113, the Transfer of Funds Regulation, which carries the Travel Rule. The applicable EBA guidance supporting it. And the MiCA authorization framework, which governs whether a firm may provide crypto-asset services at all.

What Does AMLR Change for KYC?

AMLR harmonises customer due diligence rules across the EU and further specifies customer identification, beneficial ownership, risk-based due diligence, ongoing monitoring, customer-data updating and internal controls. Ongoing KYC is not introduced by AMLR — it already exists in the current framework. What changes is that the requirements become directly applicable, more detailed, and consistent across member states.

Does AMLR Require KYC for Crypto Transactions Below €1,000?

Yes, in reduced form. For occasional crypto transactions below €1,000, Article 19 requires CASPs to apply at least customer identification and verification under Article 20(1)(a). Full customer due diligence applies to occasional transactions of €1,000 or more. This AMLR framework applies from July 2027, not today.

Does the EU Travel Rule Have a €1,000 Minimum Threshold?

No. The EU Travel Rule applies broadly to CASP-mediated crypto transfers without a general €1,000 de minimis exemption. The €1,000 figure is relevant to additional ownership or control assessment for certain transfers involving self-hosted addresses, which is a much narrower function than an exemption from the rule itself.

Is the Travel Rule Part of AMLR?

No. The EU Travel Rule is established through Regulation (EU) 2023/1113, the recast Transfer of Funds Regulation, and has applied since 30 December 2024. AMLR is a separate instrument applying from July 2027. The two frameworks complement each other but are different laws with different scopes and timelines.

Does AMLA Directly Supervise Crypto Businesses in 2026?

Not in the new direct-supervision system. AMLA is operational and preparing the framework, including its selection methodology. The first selection of directly supervised entities takes place in 2027 and direct supervision begins in 2028, covering a small number of high-risk cross-border financial institutions rather than most CASPs.

What Should CASPs Do Before AMLR Applies?

Run a gap analysis. Compare current KYC and CDD data against AMLR's requirements, check how customer information is refreshed, confirm that customer profiles and transaction monitoring are actually connected, review what triggers risk reassessment, and test governance ownership, recordkeeping and whether third-party providers can supply audit evidence.