The European Banking Authority on January 16, 2024 published final amendments extending its money-laundering and terrorist-financing risk-factor guidelines to crypto-asset service providers across the European Union.

The document, designated EBA/GL/2024/01, placed crypto businesses within a harmonized framework for identifying higher- and lower-risk customers, products, transactions, delivery channels and geographic relationships. It also described measures firms could use to manage the risks they identified, including blockchain-analytics tools.

The development mattered because the European Union had already enacted its Markets in Crypto-Assets Regulation and rules covering information accompanying crypto transfers, but much of that framework would not apply until later in 2024. The January 16 guidelines supplied more detailed supervisory expectations before the principal crypto-service-provider regime took effect.

They did not prohibit self-custody, decentralized protocols or privacy-enhancing technology. Nor did publication make every requirement immediately applicable: the EBA specified December 30, 2024 as the application date.

Crypto-specific risk indicators

The EBA amended its existing 2021 risk-factor guidelines rather than creating an unrelated rulebook. A new sectoral section directed crypto-asset service providers to evaluate risks associated with their business relationships alongside the general factors already applicable to credit and financial institutions.

Transaction-related indicators included transfers involving self-hosted addresses, decentralized platforms and providers that were not authorized or regulated under MiCA. Product-related indicators included features that could increase anonymity or permit transfers between a regulated provider and self-hosted or decentralized environments.

Customer conduct also mattered. The final report identified inconsistent or incorrect information and transaction volumes or patterns that did not fit the expected customer profile as possible warning signs. Geographic exposure could increase risk when customers, beneficial owners or transactions were connected to jurisdictions associated with elevated money-laundering or terrorist-financing risk.

These were risk factors, not automatic findings that a customer or transaction was illicit. The guidelines described a risk-based process: firms were expected to assess the facts, develop an understanding of their customers and adjust controls proportionately. The lists were expressly non-exhaustive, leaving room for business models and threats to evolve.

Banks were also part of the framework

The amendments reached beyond exchanges, brokers and custodians. They included guidance for banks and other financial institutions whose customers provided crypto services or whose activities exposed them to crypto assets.

The EBA highlighted relationships with service providers that were not authorized under MiCA as an area of potentially increased risk. That did not require banks to terminate every such relationship. It required institutions to recognize the additional uncertainty and apply controls appropriate to the assessed exposure.

This wider scope reflected the connection between crypto markets and conventional finance. Customer deposits, settlement accounts and payment services can connect a crypto business to banks even when blockchain transactions occur outside the banking system.

Guidance within an enacted legal transition

Regulation (EU) 2023/1113 had already amended the EU anti-money-laundering directive and instructed the EBA to address risk variables for crypto-asset service providers. The legislation specifically called attention to transactions involving self-hosted addresses and technologies capable of facilitating anonymity, including privacy wallets, mixers and tumblers.

The January 16 publication implemented part of that institutional mandate. It should not be confused with a legislative vote, an enforcement action against a particular company or the separate travel-rule guidance that remained under consultation at the time.

For crypto firms planning to operate under MiCA, the practical message was that authorization would not be the only compliance test. Providers would also need documented methods for assessing customers and transactions within the EU’s broader anti-financial-crime framework.

No cryptocurrency price, trading-volume or market-share conclusion can be attributed to the guidelines from the reviewed records. Their immediate importance was operational and regulatory: firms received advance notice of the risk framework scheduled to apply on December 30, 2024.

Primary sourceEuropean Banking Authority — Guidance for crypto-asset service providers on ML/TF risks

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.