Banca d’Italia Orders Sanctions Screening on Every Crypto Transfer, No Thresholds Allowed

Daily Feed
Banca d’Italia Orders Sanctions Screening on Every Crypto Transfer, No Thresholds Allowed

Banca d’Italia demands checks on every crypto transfer has told Italian crypto-asset service providers to screen every transfer for sanctions compliance, no matter the size, and not to use minimum-value cutoffs that could let small transfers slip through.

  • Every crypto transfer must be screened for sanctions compliance.
  • No minimum-value threshold should be used to skip checks.
  • MiCA authorization does not replace sanctions controls.

The central bank is not rolling out a new sanctions regime. This is a supervisory reminder tied to existing European Banking Authority guidance on internal policies, procedures and controls for implementing EU and national restrictive measures. In plain English, if a firm moves crypto, it cannot treat small transfers as beneath the radar or assume a MiCA license makes it compliant on everything else.

That matters because crypto compliance is not just about a KYC form, a risk score, and a cheerful dashboard. It is also about stopping sanctioned persons, entities, and linked addresses from slipping through transfer rails built for speed, not for mercy.

What Banca d’Italia is pushing firms to do

The central bank said Italian crypto-asset service providers must verify that each transfer passes through sanctions screening, regardless of value. It also warned firms not to set internal systems with minimum transaction thresholds.

That is a direct shot at a familiar loophole. If a platform only screens “large” transfers, anyone trying to evade controls can simply break activity into smaller pieces. That’s structuring, a boring word for a very old trick.

In practice, screening should mean more than a box tick. Firms generally need to compare originator and beneficiary details against sanctions lists, assess wallet exposure where relevant, and escalate or pause transfers when there are red flags, missing data, or possible matches. The point is to catch prohibited dealings before execution, not after the money has already vanished into the digital ether.

Why crypto gets stricter treatment

Crypto transfers can move fast, cross borders in a flash, and involve addresses that are harder to pin to a real-world identity than a standard bank account. That makes them useful for legitimate users, and just as useful for people trying to dodge controls.

That is why regulators are paying more attention to the mix of sanctions screening and the Travel Rule. The Travel Rule requires transfer information, especially originator and beneficiary data, to travel with crypto transfers so firms can identify who is sending and receiving value. If that information is incomplete, firms are expected to handle it under the EBA’s guidance rather than pretend the problem will sort itself out.

Banca d’Italia also clarified that the instant-payment exceptions available to some payment service providers do not apply to crypto transfers processed by crypto-asset service providers, or CASPs. That distinction matters. Crypto firms do not get to borrow shortcuts from traditional payments and call it a day.

The legal framework behind the reminder

The underlying obligations come from European Banking Authority guidance on internal policies, procedures and controls for implementing restrictive measures. Those measures cover sanctions-related restrictions imposed by the EU and national authorities.

The EBA framework is broader than crypto alone. It also covers banks, investment firms, payment institutions and electronic-money institutions. Banca d’Italia incorporated the guidance through Note No. 52 on May 19, 2025, and the EBA’s amending guidelines apply from 30 December 2025. Separately, Regulation (EU) 2023/1113 on transfer information for funds and crypto-assets has applied since 30 December 2024.

That timeline is easy to mix up, but it matters. One set of rules deals with transfer information. The other tightens the internal controls firms are expected to use to implement restrictive measures. Same compliance universe, different moving parts.

MiCA is not a get-out-of-sanctions-free card

One of the more useful parts of Banca d’Italia’s reminder is the quiet correction to a bad habit in the market: treating MiCA authorization as if it solves everything.

It does not.

MiCA, the EU’s Markets in Crypto-Assets Regulation, is the framework for authorizing and supervising crypto-asset service providers. It covers conduct, governance, disclosures, and market rules. Sanctions screening sits in a separate lane. A firm can be authorized under MiCA and still be sloppy, lazy, or outright negligent on restrictive measures.

That should be obvious, but apparently “we got licensed” is still being used by some firms as a magical incantation against basic compliance duties. It is not magic. It is paperwork.

Why threshold-based screening is a bad idea

On paper, a minimum-value cutoff might look efficient. In reality, it is an open invitation to abuse. If a firm screens only above a certain amount, bad actors can split activity into smaller transfers and test the seams in the system.

That is exactly the sort of weakness regulators want to kill off early. Small-value transactions are not automatically clean. They can be part of a larger pattern, especially when someone is trying to avoid detection by staying under arbitrary internal limits.

Blockchain analytics can help firms trace exposure, spot clusters of linked addresses, and identify connections to sanctioned entities or addresses. But analytics are not a substitute for proper list screening, good governance, and manual review where needed. A shiny tool cannot save a broken policy.

The bigger compliance picture in Europe

The timing of the reminder is not random. European crypto regulation is still in transition, and the compliance burden is rising, not shrinking. The notes point to more than 1, 000 EEA crypto firms still lacking MiCA authorization after a major transition deadline, which says a lot about how uneven the market remains across the bloc.

That pressure has already been showing up across the market, as seen in EU MiCA Deadline Looms as 83% of Crypto Firms Lack Licenses and MiCA Deadline Hits July 1: Unlicensed Crypto Firms Face EU. The broader sanctions environment is getting heavier too. The notes say EU sanctions have targeted 14 crypto platforms and 94 financial institutions, expanding the set of counterparties firms may need to identify and screen. If those figures hold, they underline the obvious: compliance systems now have to deal with a wider surface area, not just a handful of obvious names.

There’s a practical consequence here. For crypto firms, sanctions screening is no longer just about checking whether a sender name appears on a list. It can involve originator and beneficiary data, wallet-address exposure, indirect ownership links, and incomplete transfer information. That is a lot more work than slapping a green checkmark on a transaction and hoping for the best.

What firms will actually need to do

For compliant operators, the message is simple: review screening systems, remove any minimum-value cutoffs, and make sure every transfer is assessed before execution. Originator and beneficiary information should be checked properly, not waved away when data is missing or messy.

Firms will also need to deal with more false positives and more manual review. That is the price of taking compliance seriously. It is annoying, yes. It is also cheaper than explaining to a regulator why a “risk-based” system had a giant hole in it.

For everyone else, the warning is clear: if your controls depend on a loophole, they are already weak. A compliance program is not meant to be convenient. It is meant to work.

Key questions and takeaways

  • Does every crypto transfer need sanctions screening?
    Yes. Banca d’Italia says Italian CASPs must make sure every transfer passes through sanctions screening, regardless of value.

  • Can firms set a minimum-value threshold?
    No. The central bank warned against internal thresholds because they can create a loophole for sanctions evasion.

  • Is this a new rule?
    No. It is a reminder of existing EBA restrictive-measures guidance and related transfer-information requirements already in force.

  • Does MiCA authorization replace sanctions compliance?
    No. MiCA is a market-authorisation framework; sanctions screening is a separate obligation.

  • Do instant-payment exceptions apply to crypto transfers?
    No. Banca d’Italia said the exception does not cover crypto transfers processed by CASPs.

Banca d’Italia’s position is blunt for a reason: crypto firms do not get to treat sanctions screening as optional, partial, or only for “important” transfers. Every transfer counts. Every counterparty matters. And every internal shortcut is just another way for bad actors to exploit weak controls.

Crypto will not mature by pretending compliance is beneath it. The firms that build real controls will be better positioned with regulators, counterparties, and banks. The firms that keep hunting for loopholes are not being clever. They are just making the eventual cleanup more painful.

Further reading

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog