This final report amends the guidelines on risk-based supervision by incorporating crypto-asset service providers into the anti-money laundering and countering the financing of terrorism (AML/CFT) framework. The amendments emphasize the importance of cooperation among competent authorities and provide guidance on the supervision of these providers. The guidelines will come into effect on December 30, 2024, after…
This document is the final report of the European Banking Authority (EBA) published in 2023, entitled "Final report on amending Guidelines on risk-based supervision." It is a 38-page guide (36 provided) amending the EBA's revised Risk-Based Supervision Guidelines for anti-money laundering and counter-terrorist financing (AML/CFT) supervision. The extended scope now covers crypto-asset service providers (CASPs) as defined in Regulation (EU) 2023/1114 (MiCAR). The document aims to harmonize the understanding and application of risk-based AML/CFT supervision for these actors within the European Union, effective from 30 December 2024 (p. 1-3).
The final report presents amendments to the EBA's AML/CFT risk-based supervision guidelines, extending their scope to supervisors of crypto-asset service providers (CASPs). This extension responds to the legal mandate given by Regulation (EU) 2023/1113 (FTR), which subjects CASPs to the same AML/CFT requirements as traditional financial institutions, with application from 30 December 2024 (p. 3-4).
The amendments aim to:
- Strengthen cooperation between competent authorities, prudential supervisors, and other stakeholders, notably in cases of shared supervision of the same entity (p. 3, 12).
- Clarify information sources to be used for supervising CASPs, including advanced analytics tools and specific notifications provided by the FTR (p. 13-14).
- Define the modalities for developing and communicating sectoral guidance adapted to the specific nature of CASPs (p. 16-17).
- Emphasize supervisory staff training, integrating the technical skills needed to understand underlying technologies (DLT, anonymization) and use technological supervision tools (p. 18-19).
The report highlights that these amendments do not create major additional costs, these being mainly related to the legislative changes themselves. The EBA conducted a public consultation between March and June 2023, receiving eight responses including from the Banking Stakeholder Group (BSG), which broadly supported the changes while proposing clarifications on technology understanding and supervisor training (p. 23-26).
The amended guidelines will apply from 30 December 2024, with an obligation for competent authorities to notify their compliance within two months following publication of the translated versions (p. 3, 11).
In July 2021, the European Commission proposed a reform of the EU AML/CFT framework, including revision of the Funds Transfer Regulation (FTR) to integrate crypto-asset transfers and subject CASPs to AML/CFT requirements (p. 4). Regulation (EU) 2023/1113, published in June 2023, extends the definition of financial institutions to CASPs, requiring the EBA to provide specific guidelines on risk-based supervision of these actors (p. 4-5).
The EBA analyzed its existing guidelines and concluded they could be extended to CASPs but required clarifications to account for the technological and operational specificities of these providers (p. 5-6). The document aims to provide a harmonized framework for competent authorities, considering issues related to blockchain technology, analytical tools, and supervisor training. The public consultation allowed adjustment of proposals to address expressed concerns (p. 6-7, 23-28).
1. Scope extension and definitions:
- The amendments explicitly integrate CASPs into the definition of AML/CFT supervised financial institutions, in accordance with Regulation (EU) 2023/1113 (p. 12).
- Definitions used are those of Directive (EU) 2015/849 and Regulation (EU) 2023/1113, ensuring legal consistency (p. 12).
2. Implementation of the risk-based supervision (RBS) model:
- Authorities must isolate entities presenting significantly different risks within the same cluster for individualized assessment (p. 12-13).
- Cooperation between competent authorities, notably prudential and AML/CFT supervisors, is essential for coherent supervision (p. 13).
3. Risk identification and mitigating factors:
- Information sources now include advanced analytics tools and specific notifications related to CASPs (p. 13).
- Authorities must understand the impact of key technologies such as DLT and anonymization features on ML/TF risks (p. 14).
- Sectors and subsectors must be defined and analyzed based on common characteristics, e.g., crypto exchanges (p. 14).
4. Risk assessment:
- AML/CFT controls required by Articles 8(4) and 19a of Directive (EU) 2015/849 must be implemented and assessed for adequacy to CASP-specific risks (p. 15).
5. Supervision strategy and tools:
- Authorities must define a medium-long term AML/CFT supervision strategy, allocate necessary human and technological resources, and plan ad hoc inspections in case of increased risks (p. 15-16).
- Communication and regular updating of sectoral guidance are encouraged, notably upon regulatory changes or sector feedback (p. 16-17).
- The quality of suspicious transaction reports (STRs) is a key indicator to adjust supervision and guidance (p. 16-17).
6. Supervisory staff training:
- A training program adapted to functions, responsibilities, and experience of staff is mandatory, including technical expertise on technologies used by CASPs (p. 18-19).
- Training may include external providers and must be monitored and regularly updated (p. 18).
- Joint training between competent authorities sharing supervision of the same sector is recommended (p. 19).
7. Monitoring and updating the RBS model:
- Authorities must regularly evaluate the effectiveness of their RBS model, considering rapid technological and risk developments (p. 19-20).
Findings:
- Regulation (EU) 2023/1113 extends AML/CFT supervision to CASPs, now included in the definition of financial institutions (p. 4-5).
- The EBA conducted a public consultation with eight responses, including the BSG, which broadly supported the amendments while proposing technical clarifications (p. 23-26).
- The amendments specify information sources, supervision tools, training, and inter-authority cooperation necessary to effectively supervise CASPs (p. 12-20).
Assumptions:
- Extending the guidelines to CASPs will enable more coherent and effective supervision, reducing ML/TF risks related to crypto-assets (p. 5, 21).
- Adequate training and technological resources for competent authorities are essential to meet challenges posed by blockchain technologies and CASP business models (p. 18-19).
Interpretations:
- The EBA considers the amendments necessary to reflect CASP specificities and that costs related to these changes are limited compared to expected benefits (p. 21).
- Enhanced cooperation between authorities and targeted communication with the sector are key levers for effective supervision (p. 13, 16).
Uncertainties:
- The actual capacity of competent authorities to quickly acquire required technical skills and mobilize necessary resources remains a challenge (p. 27-28).
- Rapid evolution of crypto technologies and ML/TF typologies requires constant monitoring and regular adaptation of supervision tools and methods (p. 19-20).
The EBA concludes that extending the AML/CFT risk-based supervision guidelines to CASPs is necessary and beneficial to ensure consistent and effective application of AML/CFT requirements in the EU (p. 21). The amendments provide important clarifications on technological and operational specificities of CASPs, strengthen inter-authority cooperation, and emphasize technical training of supervisory staff (p. 3-20).
The report recommends:
- Application of the guidelines from 30 December 2024, with an obligation for competent authorities to notify their compliance within two months following publication of official translations (p. 3, 11).
- Implementation of adapted training programs to ensure supervisors' technical competence, notably on blockchain technologies and analytical tools (p. 18-19).
- Coordination between authorities supervising the same sector to harmonize expectations and guidance (p. 16-17).
- Use of multiple information sources, including advanced analytics tools, for precise identification of ML/TF risks (p. 13-14).
These measures aim to prevent amplification of ML/TF risks related to crypto-assets and ensure a robust supervision framework adapted to technological developments.
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.