← All articlesAll firms20 June 2026 · 6 min read

CASPs and the AMLR: CDD from €1,000 and alignment with MiCA

What the AMLR means for crypto-asset service providers in Ireland: customer due diligence from €1,000, MiCA-aligned scope, and how to prepare for 10 July 2027.

If your firm provides crypto-asset services in Ireland, two regulatory currents are converging on you at once. MiCA has already reshaped how crypto-asset service providers (CASPs) are authorised and supervised across the EU. Now the EU's new anti-money laundering rulebook — Regulation (EU) 2024/1624, known as the AMLR — applies from 10 July 2027 and rewrites your AML obligations too.

The headline for CASPs is stark: while most obliged entities will apply customer due diligence (CDD) to occasional transactions from €10,000, CASPs must apply CDD from just €1,000. That is a materially lower trigger than almost any other sector faces, and it has real operational consequences for how you onboard customers and monitor transactions.

This post explains what changes, why the AMLR treats CASPs differently, and what a practical preparation plan looks like between now and July 2027.

The AMLR brings CASPs fully into the single rulebook

The AMLR is a directly applicable EU regulation — no Irish transposition, no national gold-plating of the core rules. From 10 July 2027 it replaces the substantive AML rulebook that Irish designated persons currently work under, which sits in the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 (as amended).

Two things matter for crypto firms in particular:

  • Scope is widened and harmonised. The AMLR brings CASPs fully within the list of obliged entities, with the scope aligned to MiCA. In practice, if your activities make you a CASP for MiCA purposes, you should assume you are an obliged entity for AMLR purposes and plan accordingly.
  • Terminology shifts. Irish law calls regulated firms "designated persons"; the AMLR calls them "obliged entities." Expect to see both terms in supervisor communications through the transition.

For CASPs this is less of a shock than for some sectors — virtual asset service providers have been within the Irish AML net for several years, supervised by the Central Bank of Ireland. But "already in scope" is not the same as "already compliant with the new rules." The thresholds, the prescribed governance roles and the documentation expectations all change.

CDD from €1,000: what the lower threshold actually means

Under the AMLR, the general trigger for CDD on occasional transactions drops to €10,000 (from the €15,000 figure firms have worked with under the current regime). Occasional cash transactions of €3,000 or more trigger limited CDD. For CASPs, however, the trigger for occasional transactions is €1,000.

Think through what that means in a crypto context:

  • Volume. A €1,000 threshold catches a far larger share of everyday transactions than a €10,000 one. If your current systems only escalate identification and verification at higher values, the population of transactions needing CDD will grow substantially.
  • Linked transactions. Occasional-transaction thresholds are typically assessed across linked operations, not just single payments. Your systems need to recognise a series of smaller transactions that together cross the line, not just one large transfer.
  • Speed. Crypto transactions settle quickly. CDD that depends on a manual, back-office review the following day will not keep pace. Verification needs to be embedded in the transaction flow itself.

The practical conclusion: for most CASPs, the cleanest operating model under the AMLR is to treat identity verification as a standard part of onboarding rather than something triggered transaction-by-transaction. Trying to run a business where sub-€1,000 activity is unverified and everything above is verified creates a fragile control environment and a difficult audit trail.

One helpful note on the technology side: the AMLR explicitly recognises eIDAS-aligned electronic identification for identity verification. For digital-first firms, that is a genuine opportunity — electronic ID and verification flows that meet the eIDAS framework have a clear legal footing.

Your supervisor: the Central Bank of Ireland

Getting the supervisor right matters. In Ireland, CASPs sit with the Central Bank of Ireland for AML supervision — the same competent authority that supervises banks, funds, payment firms and insurers. That has two implications:

  • Expectations are calibrated to financial services. The Central Bank's supervisory approach to AML is mature and documentation-heavy. Risk assessments, board oversight and evidence of ongoing monitoring are expected as a matter of course, not as a nice-to-have.
  • AMLA raises the bar further. The EU's new Anti-Money Laundering Authority (AMLA), established under Regulation (EU) 2024/1620 and operational in Frankfurt since 1 July 2025, is issuing the technical standards and guidelines that will flesh out the AMLR. National supervisors, including the Central Bank, will apply them. Track amla.europa.eu for the standards as they land.

Other AMLR obligations CASPs should not overlook

The €1,000 threshold gets the headlines, but the AMLR package touches almost every part of your AML programme:

AreaWhat the AMLR requires
GovernanceA board-level compliance manager plus a compliance officer of sufficiently high standing
SanctionsThe compliance officer becomes responsible for targeted financial sanctions implementation from 10 July 2027
Beneficial ownershipHarmonised EU-wide test: 25% or more ownership interest, direct or indirect
FIU requestsResponses required within 5 working days (shorter for some categories)
RecordsRetain for 5 years, then delete — deletion is an obligation, not an option

On reporting: nothing in the AMLR removes your Irish suspicious transaction reporting duties. STRs in Ireland are dual-reported — to FIU Ireland via the goAML portal (fiu-ireland.ie) and to the Revenue Commissioners via ROS (revenue.ie). Your MLRO should be registered on both. Note that Ireland has no threshold transaction reporting regime — reporting is suspicion-based, not value-based.

What to do now

With just over a year to the application date, a sensible sequence looks like this:

  1. Confirm your scope position. Map your services against the MiCA CASP categories and confirm you are treating yourself as an AMLR obliged entity. If you are unsure, resolve it now, not in 2027.
  2. Model the €1,000 threshold against your transaction data. Work out what proportion of your current activity would trigger CDD under the new threshold, including linked transactions, and decide whether verify-at-onboarding is the cleaner answer.
  3. Refresh your business-wide risk assessment against the AMLR's requirements rather than the CJA 2010 framework it was probably written for.
  4. Designate the prescribed roles. Identify your board-level compliance manager and your compliance officer, and document the appointment, reporting lines and sanctions responsibilities.
  5. Review verification tooling. Assess whether your identity verification flow can operate at onboarding speed and whether eIDAS-aligned electronic identification fits your customer journey.
  6. Check your reporting registrations. Confirm goAML and Revenue ROS registrations are current and that your STR process records both submissions.
  7. Build retention and deletion into your data plan. Five years, then delete — make sure your systems can actually do the deletion part.
  8. Watch the technical standards. AMLA's regulatory technical standards and guidelines will sharpen many of these requirements. Assign someone to track them.

How CompliDesk can help

CompliDesk Ireland is being built AMLR-native — thresholds, policy templates and workflows designed around Regulation (EU) 2024/1624 from day one, hosted in Ireland. If you want to see where your current programme stands against the new rulebook, start with our AMLR explainer.

General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.

Get AMLR-ready before 10 July 2027

Join the waitlist for CompliDesk Ireland and lock in founding-member pricing.

Join the waitlist