Home › Academy › Library › Report on tackling ML TF risks in crypto-asset…
Synthesis note · Report

Report on tackling ML TF risks in crypto-asset services through supervision

European Banking Authority (EBA) · 2025 · Report · 28 pages · Intermediate

This report addresses the risks of money laundering and terrorist financing (ML/TF) in crypto-asset services, emphasizing the need for effective supervision. It examines strategies used by some businesses to circumvent AML/CFT regulations and highlights measures introduced by the MiCA regulation to strengthen the regulatory framework. Finally, the report provides recommendations to ensure the effective application…

General Information

This document is a report entitled "Report on tackling ML/TF risks in crypto-asset services through supervision: Lessons learned from recent cases", published by the European Banking Authority (EBA) in October 2025. It covers the analysis of money laundering and terrorist financing (ML/TF) risks in the crypto-asset sector, particularly in crypto-asset services within the European Union. The report is based on recent cases before and after the entry into force of the new European regulatory framework MiCA (Markets in Crypto-Assets) and developments in the AML/CFT (anti-money laundering / countering the financing of terrorism) regime up to 2025. The scope includes crypto-asset service providers (CASPs), token issuers, and competent supervisory authorities in the EU.

Executive Summary

The report addresses money laundering and terrorist financing (ML/TF) risks in the dynamic and fast-growing crypto-asset sector, which remains vulnerable to these illicit uses. Since 2018, certain crypto-asset activities have been subject to the EU AML/CFT regime, and since 31 December 2024, the MiCA regulation has established a unified framework for the issuance, trading, and provision of crypto-asset services, also extending AML/CFT obligations. The report summarizes lessons learned from interventions by competent authorities and the EBA on strategies used by some actors to circumvent AML/CFT supervision, notably: unauthorized operations, forum shopping among Member States, abusive use of the reverse solicitation exemption, weaknesses in AML/CFT frameworks, opaque ownership and governance structures, and multi-entity arrangements with high-risk counterparties (p. 3, 7-16). The new MiCA framework and strengthened AML/CFT rules introduce safeguards such as a harmonized authorization and passport regime, increased governance and transparency requirements on beneficial ownership, as well as full integration of AML/CFT obligations. Their effectiveness will depend on vigilant monitoring of unauthorized activities, rigorous assessment of inherited AML/CFT issues, continuous risk identification, and supervision of related entities. Cross-border cooperation and information sharing among authorities, as well as public transparency, are essential to avoid regulatory gaps. This report aims to support the effective implementation of MiCA and the strengthened AML/CFT framework, to promote a robust and forward-looking approach to combating financial crime in this sector (p. 3).

Context and Objectives

Blockchain technology, supporting crypto-asset services, offers opportunities to combat financial crime, notably through transaction traceability, facilitated monitoring, compliance automation via smart contracts, and personal data protection. However, the sector is also exposed to high ML/TF risks. Several crypto-asset companies have faced significant sanctions for non-compliance with AML/CFT obligations. The cross-border nature of activities complicates supervision and enforcement of rules. Before MiCA, fragmented national regulation created gaps exploited by some actors. To address this, the EU progressively expanded the AML/CFT regime scope to crypto-asset service providers (CASPs) and issuers, notably through AMLD5 Directive in 2018, then MiCA and AMLR, AMLD6, and AMLAR regulations in 2024-2025. The EBA has played a central role in information gathering, coordination among authorities, and issuing recommendations to strengthen supervision and compliance in this sector. This report aims to share lessons learned from recent cases, inform supervisory approaches, and reinforce AML/CFT mechanisms under the new MiCA regime (p. 4-6).

Summary of Key Points by Theme

1. Circumvention of AML/CFT supervision by certain crypto actors (p. 7-16):

- Unauthorized operations: entities provided services in several Member States without license or registration, notably from third countries lacking robust AML/CFT frameworks. These entities often submitted incomplete files or insufficient AML/CFT programs during MiCA authorization requests. The "grandfathering" regime allows a transitional period until July 2026, but some continue to operate illegally or appeal negative decisions (p. 7-8).

- Forum shopping: entities exploited regulatory fragmentation by applying for licenses in Member States perceived as more permissive, withdrawing applications in face of strict controls, or transferring clients to authorized entities in other States to circumvent local supervision (p. 8-9).

- Abusive use of the reverse solicitation exemption: some third-country providers claimed that commercial relationships were initiated solely by European clients, while conducting targeted marketing actions, thus escaping supervision (p. 9-10).

- Weaknesses in AML/CFT compliance: insufficient controls, excessive outsourcing to entities outside the EU without adequate supervision, lack of training, failures in applying the Travel Rule, insufficient suspicious activity reports, and underestimation of risks linked to decentralized products (DeFi) (p. 10-12).

- Opaque ownership and governance structures: complexity and lack of transparency in ownership chains, inconsistent information between Member States, use of shell companies or trusts, and delegation of AML/CFT activities to entities in low-control jurisdictions (p. 12-14).

- Multi-entity arrangements with high-risk entities: use of related companies to maintain market presence despite prohibition measures, acquisition of shares below regulatory thresholds, use of electronic money or payment institutions to outsource critical functions, and increased risks related to stablecoins issued or traded via entities with deficient AML/CFT controls (p. 14-16).

2. Safeguards and recommendations for effective implementation of the new MiCA and AML/CFT framework (p. 17-26):

- Harmonized authorization and passport regime: MiCA imposes a single authorization valid throughout the EU, replacing disparate national regimes, with harmonized prudential, organizational, governance, and AML/CFT requirements. The regime strictly limits the reverse solicitation exemption and grants enhanced powers to authorities to sanction infringements (p. 17-19).

- Dynamic supervision and risk management: authorities must adopt a proactive approach, regularly update their knowledge of ML/TF risks, engage with the private sector, develop risk indicators, train their teams, and use supervisory technological tools (SupTech) (p. 20-21).

- Increased transparency and strengthened governance: maintenance of centralized registers of beneficial ownership, rigorous checks of the integrity of directors and shareholders, in-depth analysis of complex structures, and supervision of related entities to prevent hidden influences and circumvention risks (p. 21-23).

- Cooperation among authorities and public transparency: enhanced information exchanges between national, European, and international authorities, publication of a public register of authorized CASPs, and a key role for the Central Contact Point to facilitate cross-border supervision. Obstacles remain, notably the multiplicity of authorities and complexity of exchanges, but progress is notable (p. 24-26).

Main Findings and Lessons Learned

Established facts:

- Many CASPs attempted to circumvent AML/CFT supervision before and after MiCA's entry into force, through unauthorized operations, forum shopping, abusive use of exemptions, and opaque structures (p. 7-16).

- Weaknesses in AML/CFT frameworks, notably outsourcing outside the EU, poor application of the Travel Rule, and instability of compliance functions, increase ML/TF risks (p. 10-12).

- The new MiCA framework, combined with AML/CFT developments, establishes a harmonized regime of authorization, governance, transparency, and enhanced cooperation (p. 17-26).

Hypotheses and interpretations:

- The transitional period (grandfathering) until July 2026 poses a risk of maintaining non-compliant entities on the market (p. 7-8, 17-19).

- Cooperation among authorities, although strengthened, remains sometimes hindered by the multiplicity and diversity of competent authorities (p. 24-26).

Uncertainties:

- The actual effectiveness of implementing the new rules will depend on authorities' vigilance, their capacity to detect unauthorized activities, and cross-border cooperation (p. 3, 27).

- The rapid evolution of decentralized technologies (DeFi) and ML/TF typologies requires continuous adaptation of supervisory tools and methods (p. 20-21).

Conclusions and Recommendations

The report concludes that the new MiCA regulatory framework, combined with AML/CFT regime enhancements, offers for the first time a comprehensive and harmonized regime for regulation, supervision, and governance of crypto-asset activities in the EU, with significant potential to reduce financial crime risks and strengthen the resilience of the European financial system (p. 27).

To ensure effective implementation, it is essential that all competent authorities cooperate closely to identify and promptly address vulnerabilities and risks. The authorization process must act as a rigorous filter, ensuring that only compliant actors mastering their ML/TF risks access the market. Coordination and information sharing among national, European, and international authorities are essential to ensure a coherent approach and avoid regulatory arbitrage.

The EBA will continue to play a key role in the sector, notably through its MiCA mandate, supporting the fight against financial crime, promoting convergence of supervisory practices, and ensuring emerging risks are promptly addressed. The transfer of AML/CFT competences to the Anti-Money Laundering Authority (AMLA) planned for late 2025 will mark a new step in this dynamic (p. 27).

Key takeaways

References

Year
2025
Type
Report
Level
Intermediate
Licence
Attribution required
Original document
https://www.eba.europa.eu/sites/default/files/2025-10/6a64efb9-98e9-4…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.