GLEIF logo

GLEIF-accredited LEI Issuer. #1 LEI Issuer Globally.

AMLR for crypto-asset service providers: in scope from 2027

Picture of Steve Waite
Steve Waite
CMO, Ubisecure RapidLEI
AMLR for crypto-asset service providers

Table of Contents

AMLR (Regulation (EU) 2024/1624) brings crypto-asset service providers (CASPs) fully into scope as obliged entities from 10 July 2027. CASPs must apply customer due diligence, including on occasional transactions of EUR 1,000 or more, identify and verify customers and beneficial owners, and report suspicions. When identifying a legal-entity customer, AMLR Article 22 requires collection of the Legal Entity Identifier (LEI) “where available”. Alongside AMLR, the recast Transfer of Funds Regulation already asks that crypto transfers carry originator and beneficiary information, including the LEI where available.


The problem: from MiCA authorisation to AML obligation

CASPs spent recent years getting authorised under MiCA. AMLR is the next layer. Where MiCA governs how you operate as a crypto business, AMLR governs how you identify and monitor the people and entities you serve. From 10 July 2027, a CASP is an obliged entity under the EU’s single AML rulebook, with the same core customer due diligence duties as a bank, applied to the realities of crypto.

For a CASP compliance or product team, the work is to build or harden customer due diligence and monitoring to a standard that is now directly applicable and uniform across the EU, and to do it against the specific thresholds and data requirements AMLR sets.

Who is an obliged entity under AMLR From 10 July 2027 the rulebook binds a wider population than the previous AML directives. Already in scope, standard continues ●  Credit institutions and financial institutions ●  Auditors, accountants, tax advisers ●  Notaries and other independent legal professionals, in defined situations ●  Trust and company service providers ●  Estate agents and letting agents ●  Gambling services ●  Dealers subject to existing thresholds NEW UNDER AMLR Brought into scope ●  Crypto-asset service providers (CASPs), aligned with MiCA ●  Crowdfunding service providers and crowdfunding intermediaries ●  Traders in high-value goods, such as precious metals and stones ●  Professional football clubs and agents applies from 10 July 2029 Smallest entities may benefit from exemptions. Check Article 3 for the full obliged-entity list. Source: Regulation (EU) 2024/1624, Article 3. Verified June 2026.

What AMLR requires of a CASP

Customer due diligence, including at EUR 1,000. CASPs must apply customer due diligence measures, and AMLR sets a threshold for occasional transactions: a CASP carries out CDD on an occasional transaction amounting to EUR 1,000 or more. This is materially lower than the general occasional-cash-transaction threshold of EUR 3,000, reflecting the risk profile the regulation assigns to crypto.

Identification of legal-entity customers (Article 22). Where a CASP’s customer is a legal entity, the Article 22 dataset applies: legal form and name, registered office and country of creation, legal representatives, and “where available” the registration number, tax identification number and Legal Entity Identifier. The LEI is the 20-character ISO 17442 code that identifies a legal entity uniquely worldwide. For a CASP onboarding institutional or corporate clients, the LEI is the precise, machine-readable identifier the regulation points to.

Where the LEI sits in AMLR customer due diligence AMLR Article 22: information an obliged entity must collect to identify a legal-entity customer. Article 22(1)(b): identifying a legal entity •  Legal form and name •  Registered / official office address, country of creation •  Names of legal representatives •  Registration number (where available) •  Tax identification number (where available) NAMED IN THE TEXT Legal Entity Identifier (LEI) where available •  Nominee shareholders / directors, where applicable Why the LEI matters here Named in the rulebook The LEI sits in the binding Article 22 dataset. Collected by the obliged entity whenever a customer holds one. A faster, cleaner check An active LEI hands every counterparty the exact identifier AMLR points to. Collected “where available”, so the LEI is the identifier the regulation reaches for whenever a customer has one. An entity that holds a valid, active LEI hands every counterparty the precise, machine-readable identifier the regulation references, which speeds their due diligence. Source: Regulation (EU) 2024/1624, Article 22(1). Verified June 2026.

Beneficial ownership. CASPs must identify and verify beneficial owners on the AMLR basis, at the 25% or more threshold. A lower threshold can apply in higher-risk sectors, set centrally rather than by Member States at will: the European Commission may, following an assessment due by 10 July 2029, set a lower threshold by delegated act, capped at 15%.

Enhanced and specific measures. AMLR includes provisions aimed at crypto risk, including specific enhanced due diligence for cross-border correspondent relationships involving CASPs, and measures to mitigate risks in relation to transactions with self-hosted addresses. The precise scope of the self-hosted-address measures should be read directly from the regulation; an earlier proposal for a hard payment cap on self-hosted-wallet transactions was changed during negotiation, so do not assume a fixed figure applies. Read the adopted text before building a control around it.

The travel rule and the LEI

Running alongside AMLR is the recast Transfer of Funds Regulation (Regulation (EU) 2023/1113), the EU’s implementation of the “travel rule” for crypto. It requires that transfers are accompanied by information on both the originator and the beneficiary, including, where available, the LEI. For a CASP, this is a concrete, present-tense reason the LEI matters: it is named in the data that must travel with a transfer involving a legal entity. A counterparty CASP or institution that holds an LEI lets you populate that field cleanly and machine-readably, rather than relying on names, which are a poor proxy for identity.

Crypto’s scale makes this matter. CASPs verify large numbers of counterparties, often repeatedly. A globally interoperable identifier that resolves to public reference data is more reliable at machine speed than name-matching, and it is the identifier both AMLR and the travel rule reference for legal entities.

Where the LEI sits across EU regulation The strength of the LEI link varies by instrument. AMLR names the LEI, to be collected where available. Direct mandate A valid, active LEI is required. EMIR / EMIR REFIT Derivatives reporting MiFID II / MiFIR “No LEI, no trade” SFTR Securities financing reporting DORA ICT third-party register Named, where available Collected if the entity has one. AMLR (Article 22) Customer due diligence on legal-entity customers Transfer of Funds Reg Originator / beneficiary data, including the LEI where available The duty is on the obliged entity to collect it, not on the customer to obtain it. Optional / alternative The LEI may be used, not required. EU Instant Payments Verification of Payee: the LEI “may be used as an alternative” to the payee name. Link strength strongest weakest Source: EMIR, MiFIR, SFTR, DORA, AMLR (2024/1624), TFR (2023/1113), EU Instant Payments Regulation. Verified June 2026.

The vLEI and digital verification

AMLR permits identity verification through electronic identification means meeting the eIDAS “substantial” or “high” assurance levels. The vLEI, the cryptographically verifiable form of the LEI, is built for machine-verifiable entity identity and fits crypto infrastructure, where cryptographic verification is native. The vLEI is not referenced in AMLR and is not a requirement; it is the emerging standard worth tracking as a CASP builds for the long term.

What to do before 10 July 2027

  1. Confirm your obliged-entity status and scope. If you are a MiCA-authorised CASP, you are in scope. Map which AMLR duties are new for you.
  2. Build CDD to the EUR 1,000 occasional-transaction threshold, with legal-entity identification that captures the LEI where the customer has one.
  3. Add the LEI to your counterparty and travel-rule data model. It is named in the travel rule today and in AMLR from 2027.
  4. Read the self-hosted-address provisions in the adopted AMLR text before designing controls, rather than relying on proposal-stage figures.
  5. Get your own entity’s LEI in order. Your CASP is a legal entity that banks, counterparties and other CASPs must identify. A valid, active LEI reduces friction in every relationship you are the customer in.

Building the LEI in early

AMLR turns CASPs into full obliged entities from 10 July 2027, with customer due diligence from EUR 1,000, beneficial ownership at 25%, and the LEI named in the identification dataset “where available”. The travel rule already references the LEI for crypto transfers today. For a CASP, building the LEI into counterparty and transfer data is a present-day data-quality move that the EU framework is steadily reinforcing.

Next step: make sure your own entity carries a valid, active LEI, and build the LEI into your counterparty data. Register or renew an LEI, or talk to us about embedding LEI issuance into onboarding through the Validation Agent model.

Related resources

Recent Articles