← All articlesAll firms28 May 2026 · 6 min read

Accepting crypto payments at an Irish firm: the AML angle

Thinking of accepting crypto payments at your Irish firm? The AML risks, the AMLR rules for crypto-asset services, and the checks to build in first.

Sooner or later, an Irish firm gets the question: "Can I pay you in crypto?" Or the bigger one: a client wants to fund a property purchase, an investment or a company formation from crypto-asset gains. Some firms say yes to seem modern. Some say no out of vague unease. Neither is a compliance position.

Crypto payments are not banned, and crypto-derived funds are not automatically criminal. But they change your money-laundering risk picture in specific ways, and the EU's new rulebook - Regulation (EU) 2024/1624, the AMLR, applying from 10 July 2027 - treats the crypto sector with notable strictness. Here is how a designated person should think it through.

Does accepting crypto make you a CASP?

Almost certainly not - and the distinction matters. Crypto-asset service providers (CASPs) - exchanges, custodians and similar businesses providing crypto-asset services in line with the EU's MiCA framework - are fully within the AMLR's scope as obliged entities, supervised in Ireland by the Central Bank of Ireland. The AMLR sets them a notably low customer due diligence threshold: CDD from 1,000 euro. That is the clearest signal of how the EU rates risk in this sector - compare it with the 10,000 euro occasional-transaction threshold that applies generally.

A solicitor, accountant or estate agent accepting payment of their own fees in a crypto-asset is not thereby providing crypto-asset services. You remain what you were - a designated person in your own sector - but you have taken on a payment channel whose risks your AML programme must now address.

What actually changes in your risk picture?

Three things, principally:

  • Source-of-funds work gets harder. Your core CDD question - where did this money come from? - is more difficult when the answer involves wallets, exchanges and conversions rather than a payslip and a bank statement. Harder does not mean impossible: records of purchases through a regulated exchange, transaction histories and disposal records can evidence legitimate origin. But "I've done well on crypto" is not evidence; it is a claim awaiting evidence.
  • Counterparty opacity increases. A bank transfer arrives from an identifiable, regulated institution. A transfer from a self-hosted wallet arrives from software. The compensating control is to know which regulated CASP, if any, sits in the chain.
  • Your risk assessment is probably silent. Most Irish firms' business-wide risk assessments were written before this question arose. If you accept crypto in any form, your BWRA needs a section on it: the scenarios you will accept, the ones you will not, and the controls in between.

Note one common confusion: the AMLR's 10,000 euro cap on commercial payments is a cash cap. Crypto is not cash for that purpose - but that is no comfort, because crypto payments carry their own risk profile and their own CDD expectations.

What controls should you build before saying yes?

A proportionate framework for a small firm that decides to accept crypto exposure - whether as fee payment or as the source of funds in a client transaction - looks like this:

  1. Decide your policy first. Accept conversion-to-euro through a regulated CASP only? Accept direct wallet payments never? Whatever you decide, write it down before the first request, not after.
  2. Identify the rails. Establish which exchange or CASP the funds pass through and whether it is a regulated obliged entity. Funds arriving via a Central Bank-supervised or other EU-regulated CASP have passed through a firm with its own CDD obligations; funds from a self-hosted wallet have not.
  3. Do real source-of-funds work. Ask for the acquisition and disposal records. Dates, amounts, the platform used, and the bank account that originally funded the purchases. Tie the story together or decline.
  4. Risk-rate accordingly. Crypto involvement is a risk factor to weigh, not an automatic bar - but combined with other factors (non-resident client, complex structure, urgency), it can tip a file into enhanced due diligence.
  5. Know your reporting duty. If the explanation does not hold together, the suspicion regime applies exactly as it does to cash or bank funds: a Suspicious Transaction Report to FIU Ireland through goAML at fiu-ireland.ie and to Revenue through ROS - and no tipping off.

What is still to come from AMLA?

The fine detail of how obliged entities should treat crypto-asset flows - including expectations around transfers involving self-hosted wallets - is among the areas where AMLA's technical standards and guidance will matter. AMLA submitted its first draft technical standards to the European Commission around 10 July 2026, and adoption is awaited. Where your procedures touch crypto, mark them for review when those standards land rather than guessing at specifics now.

What to do now

  • Write a one-page crypto policy: what you will accept, through what rails, and what you will refuse.
  • Add crypto-asset exposure to your business-wide risk assessment, even if only to record that you do not accept it.
  • Build a source-of-funds question set for crypto-derived wealth: acquisition records, platform, disposal, receiving account.
  • Train client-facing staff to route any crypto payment request to the MLRO before agreeing anything.
  • Check whether any existing client's funds had crypto origins that were never evidenced, and remediate the file.
  • Diarise a review of the policy once AMLA's standards are adopted.

Where CompliDesk fits

CompliDesk Ireland builds risk factors like crypto exposure into client risk-rating and keeps the source-of-funds evidence on the file where an inspector can find it. Not sure how the AMLR applies to your business in the first place? Take the am-I-in-scope check.

General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.

Get AMLR-ready before 10 July 2027

Join the waitlist for CompliDesk Ireland and lock in founding-member pricing.

Join the waitlist