VASP/AMLEuropean UnionCrypto

VASP KYC and AML Compliance in the European Union

In-depth guide to VASP KYC and AML compliance requirements in the European Union. Covers AMLD5 and AMLD6 obligations, VASP registration, beneficial ownership rules, transaction monitoring, and practical implementation strategies for virtual asset service providers.

The EU's AML Framework for Virtual Asset Service Providers

Operate a Virtual Asset Service Provider (VASP) in the European Union and you sit under one of the world's most comprehensive anti-money laundering (AML) and Know Your Customer (KYC) regimes. The Fifth (AMLD5) and Sixth (AMLD6) Anti-Money Laundering Directives sit at the centre of that regime, backed by the EU's broader push to oversee digital assets. Identity verification, transaction monitoring, and suspicious activity reporting are required of every entity that facilitates virtual asset transactions.

This is strategy, not a box-ticking drill. Inadequate AML/KYC controls bring severe penalties, loss of registration, and exclusion from the EU's lucrative digital asset market. The sections below map the compliance terrain VASPs have to cross.

AMLD5: Bringing VASPs Into the Regulatory Perimeter

Historical Context

VASPs sat in a regulatory grey zone across much of Europe until AMLD5 (Directive 2018/843). National-level requirements already existed in some member states. Crypto-related businesses still had no harmonized EU duty to run AML controls or register with national authorities.

Two categories of crypto business were pulled expressly into EU AML law by AMLD5:

  • Providers engaged in exchange services between virtual currencies and fiat currencies
  • Custodian wallet providers offering services to safeguard private cryptographic keys on behalf of customers

Registration and KYC Obligations Under AMLD5

AMLD5 requires member states to see that VASPs are registered and supervised by a designated authority. Once on the register, a VASP must put in place:

  • Customer due diligence (CDD): Identify the customer and verify identity before opening a business relationship, or before running an occasional transaction above the applicable threshold.
  • Beneficial ownership identification: Establish which natural persons ultimately own or control corporate customers.
  • Ongoing monitoring: Check transactions throughout the relationship so they stay consistent with what the VASP knows about the customer.
  • Suspicious transaction reporting: File with the relevant Financial Intelligence Unit (FIU) when transactions or activity patterns point to possible money laundering or terrorist financing.

KYC principles and how they apply across financial services are covered in a comprehensive introduction in our guide on what is KYC.

AMLD6: Strengthened Enforcement and Harmonized Offences

Key Enhancements

AMLD6 (Directive 2018/1673) sits alongside AMLD5. It aligns the definition of money laundering offences across the EU and hardens the enforcement framework. The biggest consequences for VASPs include:

  • Extended criminal liability: Legal persons (companies) now carry criminal liability, not only natural persons. A VASP as a corporate entity can face criminal sanctions for facilitating money laundering.
  • Expanded predicate offences: Twenty-two categories of predicate offence can now underpin money laundering charges, cybercrime and environmental crime among them.
  • Aiding and abetting: The directive addresses aiding, abetting, and attempting money laundering in express terms, which widens potential liability where VASPs fail to install adequate controls.
  • Minimum sanctions: Member states must provide for minimum prison sentences of four years for money laundering offences — a clear signal of how seriously the EU treats AML failures.

Impact on VASP Compliance Programs

AMLD5 plus AMLD6 means a VASP compliance program has to be capable of:

  • Stopping the platform from being used to launder proceeds of a wide range of criminal activities
  • Showing that reasonable and proportionate measures were taken to detect and prevent illicit use
  • Cooperating fully with law enforcement and FIU inquiries
  • Keeping comprehensive records of all CDD measures and transactions for the prescribed retention period (typically five years)

Beneficial Ownership: A Critical Compliance Pillar

EU Beneficial Ownership Registers

Central registers of beneficial ownership information for legal entities and trusts are now an EU requirement on member states. VASPs must draw on those registers when they run CDD on corporate customers.

Key obligations include:

  • Verification against national registers: Beneficial ownership declarations from corporate customers are cross-checked against the relevant member state's central register.
  • Discrepancy reporting: Mismatches between what the customer supplied and what the register holds go to the competent authority.
  • Ongoing updates: Beneficial ownership information is re-verified at appropriate intervals, and whenever a trigger event suggests the ownership structure has changed.

Challenges for VASPs

The crypto sector makes beneficial ownership verification unusually difficult:

  • Crypto-related businesses often sit inside complex multi-jurisdictional corporate structures
  • Nominee arrangements and trust structures can hide the true beneficial owner
  • Blockchain's decentralized, pseudonymous character adds another layer when tracing ownership chains
  • Data quality is uneven across member state registers, so VASPs need extra verification steps

Practical KYC Implementation for EU VASPs

Risk Assessment Methodology

A documented risk assessment is mandatory for every VASP. It must identify, assess, and mitigate money laundering and terrorist financing risks that belong to that business model. Topics to cover:

  • Product risk: How risky the virtual assets and services themselves are (e.g., privacy coins versus mainstream cryptocurrencies)
  • Customer risk: Risk profiles of the target customer base, including geographic distribution and expected transaction volumes
  • Channel risk: What remote onboarding and digital service delivery introduce
  • Geographic risk: Exposure to high-risk jurisdictions, and how well AML regimes work in the countries where customers sit

Tiered Due Diligence

Due diligence under EU AML law must match the assessed risk:

Simplified Due Diligence (SDD): Available where the relationship is demonstrably lower-risk — regulated entities in low-risk jurisdictions, for example. Verification can be lighter. Identifying the customer is still required.

Standard Customer Due Diligence (CDD): The default for every business relationship: identity verification, beneficial ownership identification, and a clear picture of the purpose and intended nature of the relationship.

Enhanced Due Diligence (EDD): Required in higher-risk settings — PEPs, customers from high-risk third countries, complex or unusual transactions, and any other case where the risk assessment flags elevated concern. Typical EDD steps include extra identity documentation, source-of-funds and source-of-wealth checks, senior management approval of the relationship, and tighter ongoing monitoring.

Technology-Driven Compliance

Virtual asset transactions move too fast and at too great a scale for manual KYC to work at any VASP of significant size. Automated identity verification, transaction monitoring, and screening technologies now carry the load.

Joinble's AI-powered identity verification platform for crypto-asset service providers lets VASPs automate customer onboarding with document verification across EU-wide identity document types, biometric matching with certified liveness detection, and integrated sanctions and PEP screening. Wire those capabilities in through API integration and compliance need not create the friction that sends customers to unregulated alternatives — a balance that matters in a competitive crypto market.

The Evolving Regulatory Landscape

AMLR: The Next Generation

A new Anti-Money Laundering Regulation (AMLR) is moving through the EU. It will convert the present directive-based framework into a regulation that applies directly. For VASPs, AMLR will bring:

  • Directly applicable rules that remove inconsistencies in national transposition
  • The Anti-Money Laundering Authority (AMLA) as a centralized EU supervisory body
  • Expanded scope covering additional categories of crypto-asset service providers
  • Stricter beneficial ownership thresholds and enhanced transparency requirements
  • Harmonized maximum limits on large cash payments (with potential parallels for crypto transactions)

Watch AMLR's legislative progress. Start shaping compliance programs for the extra requirements it will add.

Interaction With MiCA

AML duties also meet the Markets in Crypto-Assets Regulation (MiCA). Licensing and operational rules for crypto-asset service providers sit in MiCA. AML compliance stays under the AMLD framework (and, later, AMLR). The two regimes complement each other: MiCA authorization demands demonstrated AML compliance, and AML obligations remain an ongoing condition of CASP authorization.

The KYC fundamentals that sit under both frameworks are set out in our resource on what is KYC, which is a useful place to start.

Record-Keeping and Data Retention

Under EU AML law, VASPs must keep:

  • Customer identification and verification records for at least five years after the end of the business relationship
  • Transaction records for at least five years after the transaction
  • Records of risk assessments and CDD measures applied
  • Correspondence and documentation related to suspicious transaction reports

Retention has to sit with GDPR. Personal data cannot be stored longer than needed for its stated purpose, and stored data needs appropriate security.

FAQ

What is a VASP and which entities qualify as VASPs in the EU?

Any entity that exchanges virtual currencies for fiat currencies, or that offers custodian wallet services, is a VASP (Virtual Asset Service Provider). EU AML directives require those entities to register with national authorities and to run comprehensive KYC and AML programs.

What are the main differences between AMLD5 and AMLD6 for VASPs?

VASPs entered the EU's AML perimeter for the first time under AMLD5, which imposed registration and CDD. Enforcement was hardened by AMLD6: criminal liability for legal persons, a longer list of predicate offences, and minimum sanctions. The two directives together form a comprehensive compliance framework for VASPs.

How do VASPs verify beneficial ownership for corporate clients?

All natural persons who ultimately own or control more than 25% of a corporate client must be identified. That information is checked against reliable sources, national beneficial ownership registers included, and any discrepancy is reported to the competent authority. Re-verification continues at appropriate intervals.

What penalties do VASPs face for AML non-compliance in the EU?

Member states set the detail, but the toolkit includes substantial administrative fines, criminal prosecution of individuals and corporate entities, revocation of VASP registration, public censure, and temporary or permanent prohibition orders against responsible managers. Minimum prison sentences of four years for money laundering offences are set by AMLD6.

How will the new EU AMLR affect VASP compliance obligations?

Directly applicable rules will replace the current directive-based framework. AMLA will sit as a centralized supervisory authority, and beneficial ownership requirements will tighten. Expanded compliance duties are the expected outcome; VASPs should start preparing for that shift in regulatory architecture.

Automate your compliance with AI Agents

Joinble's Agentic Identity platform reduces manual KYC reviews by up to 80%. Book a demo to see it in action.

Book a demo