The Anti-Money Laundering Regulation (AMLR), formally Regulation (EU) 2024/1624, is a major part of the European Union's updated framework for preventing money laundering and terrorist financing. Unlike EU anti-money laundering directives, which require transposition into national law, AMLR is an EU regulation that will apply directly across Member States in accordance with its application timetable.
For the crypto industry, AMLR is particularly important because crypto-asset service providers (CASPs) are included within its scope as obliged entities. This brings activities involving crypto-assets into a more harmonized EU anti-money laundering and counter-terrorist financing (AML/CFT) framework.
The regulation was adopted on May 31, 2024 and published in the Official Journal of the European Union on June 19, 2024. Most of its provisions will apply from July 10, 2027. The full legal text is available through the official EUR-Lex AMLR page.
AMLR stands for Anti-Money Laundering Regulation and refers to Regulation (EU) 2024/1624.
Most AMLR rules apply from July 10, 2027.
Crypto-asset service providers are covered as obliged entities under the regulation.
Customer due diligence remains central, including identifying customers and beneficial owners and understanding the purpose of business relationships.
Crypto transactions involving self-hosted addresses receive specific attention under AMLR's risk-based requirements.
Anonymous crypto-asset accounts are prohibited under the regulation.
AMLR works alongside MiCA and the EU Transfer of Funds Regulation as part of the broader European regulatory framework for crypto-assets.
The EU has developed anti-money laundering legislation over several decades through successive Anti-Money Laundering Directives. While these directives established common objectives, Member States implemented them through national legislation, which could result in differences in how requirements were applied across the EU.
AMLR is intended to increase harmonization by creating a common set of directly applicable AML/CFT requirements. It forms part of the EU's broader AML package alongside Directive (EU) 2024/1640 and the establishment of the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA).
For a broader introduction to how the EU's anti-money laundering directives developed and how AMLR fits into that framework, CoinW users can read our guide to AMLD and its impact on crypto users.
Regulation (EU) 2024/1624 entered into force following its publication in the Official Journal of the European Union in June 2024. Under Article 90, most provisions of AMLR will apply from July 10, 2027.
This distinction is important: the regulation already exists as EU law, but most of its operational requirements do not become applicable until July 2027. Certain categories of obliged entities specified by the regulation have a later application date.
The period before application gives regulated businesses and supervisory authorities time to prepare systems, internal controls, risk assessments, customer due diligence procedures, and other processes required by the new framework.
Crypto-assets are explicitly integrated into AMLR. The regulation incorporates the concept of a crypto-asset service provider using the regulatory framework established under the EU's Markets in Crypto-Assets Regulation (MiCA).
The regulation recognizes that the EU's earlier AML framework covered certain virtual-currency exchange and custodian wallet providers, while the development of crypto markets and international standards created a need for a broader approach.
MiCA expanded the regulatory definition of crypto-asset services, while AMLR incorporates relevant crypto-asset service providers into the EU's harmonized AML/CFT framework.
This means AMLR and MiCA should not be viewed as competing regulations. They address different regulatory objectives. Users can learn more about the market framework in CoinW's guide to the EU MiCA regulation.
AMLR applies to a broad range of organizations and professionals classified as obliged entities. These include credit institutions, financial institutions, certain professional service providers, gambling operators, traders in specified high-value goods, and other businesses identified by the regulation.
Importantly for the digital-asset industry, the definition of financial institutions includes crypto-asset service providers.
Once the relevant AMLR provisions become applicable, covered CASPs must apply relevant AML/CFT controls, including internal risk management, customer due diligence, ongoing monitoring, and measures addressing higher-risk relationships and transactions.
AMLR establishes a broad compliance framework rather than a single verification requirement. For crypto-asset service providers within its scope, AMLR will establish requirements across several key areas once the relevant provisions become applicable, including:
Customer due diligence: covered providers must identify customers, verify relevant identity information, identify beneficial owners where applicable, and understand the purpose and intended nature of business relationships.
Ongoing monitoring: business relationships and transactions must be monitored according to applicable risk and due diligence requirements.
Risk assessment: obliged entities must identify and assess money laundering and terrorist financing risks and implement appropriate controls.
Enhanced due diligence: higher-risk situations can trigger additional checks and monitoring.
Internal controls: obliged entities must establish appropriate policies, procedures, and controls to manage AML/CFT risks.
Record keeping: relevant customer and transaction documentation must be retained according to the requirements established by the regulation.
Self-hosted address controls: CASPs must assess and mitigate risks associated with certain transfers to or from self-hosted crypto addresses.
Know Your Customer (KYC) procedures are one practical component of the broader customer due diligence requirements established by anti-money laundering frameworks.
Under AMLR, obliged entities must perform customer due diligence when establishing a business relationship and in other circumstances specified by the regulation. Customer due diligence can involve identifying and verifying the customer, identifying beneficial owners where relevant, assessing the purpose and intended nature of a business relationship, and conducting ongoing monitoring.
The depth of these checks can depend on risk. Higher-risk situations may require enhanced due diligence, while the regulation provides a framework for proportionate measures where lower risks have been identified.
For crypto users, this helps explain why identity verification and requests for additional information can form part of compliance procedures on regulated financial and crypto platforms.
AMLR contains specific provisions addressing transactions involving self-hosted addresses. In general terms, these are crypto-asset addresses controlled outside a crypto-asset service provider rather than managed by the provider on the user's behalf.
Article 40 requires crypto-asset service providers to identify and assess the money laundering and terrorist financing risks associated with transfers of crypto-assets to or from self-hosted addresses.
Importantly, AMLR does not establish a blanket prohibition on transfers involving self-hosted addresses. Instead, it requires CASPs to apply risk-based mitigating measures.
Depending on the identified risk, those measures can include identifying and verifying the originator or beneficiary, requesting additional information concerning the origin or destination of crypto-assets, and conducting enhanced ongoing monitoring.
AMLA is also required to develop guidelines specifying relevant criteria and risk-mitigation measures, including criteria concerning whether a self-hosted address is owned or controlled by a customer.
AMLR places restrictions on anonymous financial accounts, including crypto-asset accounts.
Once applicable, Article 79 will prohibit credit institutions, financial institutions, and crypto-asset service providers from maintaining anonymous crypto-asset accounts or accounts that otherwise allow the identity of the customer account holder to be anonymized or transactions to be subject to increased obfuscation.
The regulation also addresses anonymity-enhancing coins in this context.
This provision reflects a central principle of the EU AML/CFT framework: obliged financial entities must be able to conduct appropriate customer due diligence rather than provide anonymous accounts that prevent identification of their holders.
The distinction between a regulation and a directive is particularly important. AMLR is designed to reduce differences in AML/CFT requirements across Member States by providing directly applicable rules.
AMLR and MiCA both affect the European crypto industry, but their primary purposes differ.
The two frameworks also interact. AMLR uses definitions connected to MiCA when determining which crypto-asset service providers and crypto services fall within relevant parts of the AML/CFT framework.
The EU's Transfer of Funds Regulation (TFR) and AMLR are closely connected but serve different functions.
The TFR establishes traceability requirements for transfers of funds and certain transfers of crypto-assets. In the crypto context, it requires specified information about the originator and beneficiary to accompany transfers where the regulation applies.
AMLR provides the broader AML/CFT rulebook governing obliged entities, including customer due diligence, internal controls, risk management, enhanced due diligence, and specific measures concerning crypto activities.
CoinW users can learn more about these transfer requirements in our guide to the EU Crypto Travel Rule and Transfer of Funds Regulation.
AMLR also establishes enhanced due diligence measures for certain cross-border correspondent relationships involving crypto-asset services.
Under Article 37, once the relevant AMLR provisions apply, a CASP entering into a covered correspondent relationship with a respondent entity outside the EU providing similar crypto services will be required to perform additional checks.
These measures include determining whether the respondent is licensed or registered, gathering information to understand its business and reputation, assessing its AML/CFT controls, obtaining appropriate senior-management approval, and documenting the responsibilities of each party.
This reflects AMLR's broader risk-based approach: cross-border crypto relationships can require additional controls when their structure or jurisdiction creates heightened AML/CFT risks.
A central feature of AMLR is its risk-based approach. Not every customer, transaction, business relationship, or jurisdiction presents the same money laundering or terrorist financing risk.
Obliged entities must therefore assess relevant risks and apply measures appropriate to the circumstances. Situations presenting higher risk can trigger enhanced due diligence, additional information requirements, closer transaction monitoring, or other mitigating measures.
This principle is particularly relevant to crypto because digital assets can move rapidly across borders and can interact with both regulated platforms and self-hosted infrastructure.
AML compliance requires financial institutions and crypto-asset service providers to collect, verify, process, and retain certain personal information. At the same time, organizations operating in Europe may also be subject to the EU's data protection framework.
AMLR and the General Data Protection Regulation (GDPR) therefore address different objectives. AMLR establishes requirements intended to prevent money laundering and terrorist financing, while GDPR governs the protection and lawful processing of personal data.
Users interested in the data-protection side of crypto compliance can read CoinW's guide to GDPR and what it means for crypto users.
For CoinW users, AMLR is best understood as part of the continuing development of a more harmonized regulatory environment for crypto services in Europe. The application of AMLR to a particular provider, service or relationship depends on the relevant entity, service, jurisdiction and circumstances under the Regulation.
Customer identification, risk assessment, transaction monitoring, and requests for additional information are not unique to AMLR or to crypto exchanges. They are components of the broader AML/CFT controls used throughout regulated financial markets.
Depending on applicable laws, jurisdiction, risk profile, transaction type, and other circumstances, users of crypto services may encounter identity verification requirements or requests for additional information relating to particular transactions.
AMLR should also be considered alongside MiCA, the Transfer of Funds Regulation, GDPR, AMLD, and other parts of the EU regulatory framework. CoinW's EU Compliance & Regulation Hub provides a broader overview of how major European regulations affect crypto users.
Together, these frameworks illustrate how EU crypto regulation extends beyond a single law. Different regulations address market access, financial crime, transfer traceability, operational requirements, and personal-data protection.
Expect identity verification to remain important: customer due diligence is a core component of AML/CFT compliance.
Additional information may sometimes be required: higher-risk transactions or relationships can result in enhanced checks.
Self-hosted wallets are not automatically prohibited: AMLR instead establishes risk-assessment and mitigation requirements for CASPs dealing with transfers to or from self-hosted addresses.
Crypto is increasingly integrated into mainstream financial regulation: CASPs are explicitly incorporated into the EU AML/CFT framework.
Different EU rules have different purposes: AMLR, MiCA, TFR, and GDPR should not be treated as interchangeable regulations.
AMLR stands for Anti-Money Laundering Regulation. In this context, it refers to Regulation (EU) 2024/1624 on preventing the use of the financial system for money laundering or terrorist financing.
Most provisions of Regulation (EU) 2024/1624 apply from July 10, 2027. Certain entities specified by the regulation have a later application date.
Crypto-asset service providers are included within AMLR's definition of financial institutions and are obliged entities when performing covered crypto-asset services.
AMLR establishes customer due diligence requirements for obliged entities, including relevant crypto-asset service providers. These include identifying and verifying customers in circumstances specified by the regulation and applying ongoing and risk-based controls.
No. AMLR does not establish a general ban on self-hosted crypto addresses. Article 40 instead requires CASPs within its scope to identify and assess risks associated with transfers involving self-hosted addresses and apply proportionate risk-mitigation measures.
Once applicable, AMLR will prohibit crypto-asset service providers and other covered financial institutions from keeping anonymous crypto-asset accounts or accounts that allow the customer account holder to remain anonymous or transactions to be subject to increased obfuscation.
No. AMLR focuses on preventing money laundering and terrorist financing, while MiCA establishes a broader regulatory framework for crypto-assets and crypto-asset service providers in the EU.
No. The EU Crypto Travel Rule is primarily implemented through the Transfer of Funds Regulation and concerns information accompanying covered crypto transfers. AMLR establishes broader AML/CFT requirements for obliged entities.
AMLA is the European Union's Authority for Anti-Money Laundering and Countering the Financing of Terrorism. It forms part of the EU's strengthened AML/CFT framework and has responsibilities that include developing regulatory guidance and contributing to consistent supervision.
AMLR represents a significant step toward a more harmonized anti-money laundering framework across the European Union. For the crypto industry, one of its most important features is the explicit inclusion of crypto-asset service providers within the EU's AML/CFT rulebook.
From July 10, 2027, most AMLR provisions will apply directly across the EU. Covered CASPs will operate under requirements addressing customer due diligence, risk assessment, transaction monitoring, internal controls, higher-risk relationships, self-hosted addresses, and other areas relevant to preventing money laundering and terrorist financing.
For crypto users, AMLR should be understood as one part of a wider regulatory system. MiCA regulates important aspects of crypto markets and service providers, the Transfer of Funds Regulation establishes traceability requirements for covered crypto transfers, GDPR addresses personal-data protection, and AMLR provides harmonized AML/CFT requirements.
Understanding these distinctions can help CoinW users better understand why crypto platforms may require identity verification, transaction information, or additional compliance checks as the European regulatory environment continues to develop.
EUR-Lex — Regulation (EU) 2024/1624 (Anti-Money Laundering Regulation)
CoinW Academy — What Is AMLD and How Does It Affect CoinW Users?
CoinW Academy — Learn About the EU MiCA Regulation
CoinW Academy — EU Transfer of Funds Regulation and Crypto Travel Rule
CoinW Academy — GDPR Explained
CoinW Academy — EU Compliance & Regulation Hub

Learn how DAC8 affects crypto users and service providers, including EU tax reporting, transaction data, RCASPs, MiCA, and the rules applying from 2026.

Using CoinW for the first time and not sure where to start? This article helps you understand what each entry point on the website is for and which one to click when you run into a problem, and strings the six key steps—registration → identity verification → deposit → buy crypto → trade → withdraw—into one clear path to getting started.

CoinW Academy · Security / Product Guide. Once you understand CoinW's lines of defense—forced liquidation, the insurance fund, and auto-deleveraging—you'll see how the platform safeguards overall stability in extreme markets and keeps systemic risk at bay.