MLRs 2017 and the EU AML framework
What does a crypto AML policy template have to contain?
The answer differs by regime, and the first question is which one you are in. A UK cryptoasset exchange provider or custodian wallet provider is supervised by the FCA under the Money Laundering Regulations 2017. A crypto-asset service provider authorised under MiCA is an obliged entity under the AML law of its member state, and both are caught by a travel rule, with different thresholds. Tell us where you sit and specialist advisers will quote you.
Three steps
- Tell us which regime applies, what you need and how big the business is. Two minutes, no account.
- We pass your details to AML compliance consultancies and regulatory law firms that work with crypto businesses, and to no one else.
- They contact you directly with scope and price. Compare, choose, or walk away.
Crypto AML Policy is a free introduction service operated by Ellul Solutions Ltd. We pass your details to relevant AML compliance consultancies and regulatory law firms, who quote you directly; we may receive a fee from them, you pay nothing and are under no obligation. We are not a law firm, we are not authorised or registered by any regulator, and we are not affiliated with or endorsed by the FCA, HMRC, the National Crime Agency, ESMA, the EBA or any national competent authority or financial intelligence unit. Nothing here is legal or regulatory advice, and this site does not tell you whether a specific transaction is reportable: take advice from a qualified professional in the jurisdiction that supervises you.
Prefer to ask a question first?
Send us the position and we will point it at an AML specialist who works with crypto businesses.
What a crypto AML policy must contain, and the rule that requires it
Last updated
Each obligation, the UK provision that creates it, and the EU provision that does the same job. Read from the legislation itself rather than from a template vendor's feature list.
UK column read from the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (S.I. 2017/692) as amended, on legislation.gov.uk on 15 August 2026. EU column read from Directive (EU) 2015/849 as it currently applies through national transposition, Regulation (EU) 2023/1113 for the travel rule, and Regulation (EU) 2023/1114 Article 68(8) for the MiCA overlay. Regulation (EU) 2024/1624 replaces most of the EU column from 10 July 2027 and is shown where it changes the substance. This table names sources, it is not advice on how to apply them.
| Obligation | UK provision | EU provision |
|---|---|---|
| A written business-wide money laundering and terrorist financing risk assessment, kept up to date and given to the supervisor on request | MLRs 2017, regulation 18 | Directive (EU) 2015/849 Article 8, as transposed nationally |
| Written policies, controls and procedures to mitigate the identified risks, proportionate to the business and approved by senior management | MLRs 2017, regulation 19 | Directive (EU) 2015/849 Article 8(3) to (5); MiCA Article 68(8) for CASPs |
| Group-wide policies applied to subsidiaries and branches, including those outside the home state | MLRs 2017, regulation 20 | Directive (EU) 2015/849 Article 45 |
| A board or senior management officer responsible for compliance, screening of relevant employees, and an independent audit function | MLRs 2017, regulation 21 | Directive (EU) 2015/849 Article 8(4)(a) and (b) |
| Training for relevant employees and agents on the law and on recognising suspicious activity, with a written record of what was given | MLRs 2017, regulation 24 | Directive (EU) 2015/849 Article 46(1) |
| Customer due diligence on establishing a business relationship and on qualifying occasional transactions | MLRs 2017, regulations 27 and 28 | Directive (EU) 2015/849 Articles 11 to 13 |
| Enhanced due diligence for high-risk cases, high-risk third countries, politically exposed persons and unusual transactions | MLRs 2017, regulation 33 | Directive (EU) 2015/849 Articles 18 to 22 |
| Information accompanying transfers of crypto-assets (the travel rule) | MLRs 2017, Part 7A, regulations 64A to 64G, in force 1 September 2023 | Regulation (EU) 2023/1113 Articles 14 to 21, applying from 30 December 2024 |
| Reporting suspicion to the financial intelligence unit | Proceeds of Crime Act 2002 Part 7 and Terrorism Act 2000 Part 3: a SAR to the National Crime Agency | Directive (EU) 2015/849 Article 33: a report to the national FIU |
| Keeping customer due diligence and transaction records for five years | MLRs 2017, regulation 40(3) | Directive (EU) 2015/849 Article 40 |
| A prohibition on anonymous crypto-asset accounts and anonymity-enhancing coins | No equivalent standalone prohibition in the MLRs | Regulation (EU) 2024/1624 Article 79, applying from 10 July 2027 |
- In the UK, cryptoasset exchange providers and custodian wallet providers are supervised for anti-money laundering by the FCA under regulation 7(1)(a)(viii) and (ix) of the Money Laundering Regulations 2017, and may not operate without being on the FCA register.
- The UK travel rule for crypto transfers has applied since 1 September 2023 under Part 7A of the MLRs 2017, with the extra originator information required on cross-border transfers of GBP 800 or more; the EU rule in Regulation (EU) 2023/1113 has applied since 30 December 2024 with no de minimis threshold at all.
- Regulation (EU) 2024/1624, the EU single AML rulebook, applies from 10 July 2027 and prohibits crypto-asset service providers from keeping anonymous crypto-asset accounts or accounts allowing anonymisation, including through anonymity-enhancing coins.
Cite this page
“What a crypto AML policy must contain, and the rule that requires it”, Crypto AML Policy, https://cryptoamlpolicy.com/ (updated 2026-08-15). UK column read from the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (S.I. 2017/692) as amended, on legislation.gov.uk on 15 August 2026. EU column read from Directive (EU) 2015/849 as it currently applies through national transposition, Regulation (EU) 2023/1113 for the travel rule, and Regulation (EU) 2023/1114 Article 68(8) for the MiCA overlay. Regulation (EU) 2024/1624 replaces most of the EU column from 10 July 2027 and is shown where it changes the substance. This table names sources, it is not advice on how to apply them.
Straight answers
What must a crypto AML policy contain?
At minimum: a written business-wide risk assessment, written policies, controls and procedures approved by senior management, a nominated compliance officer, employee screening, an independent audit function, training with a written record, customer due diligence and enhanced due diligence procedures, travel rule handling and five-year record keeping. In the UK those come from regulations 18, 19, 21, 24, 27, 28, 33, 40 and Part 7A of the MLRs 2017.
Which AML regime applies to my crypto business?
It follows where you are supervised. A UK cryptoasset exchange provider or custodian wallet provider is supervised by the FCA under the Money Laundering Regulations 2017. A crypto-asset service provider authorised under MiCA is an obliged entity under the AML law of its member state, and will fall under Regulation (EU) 2024/1624 from 10 July 2027.
Do I need an MLRO?
Regulation 21 of the MLRs 2017 requires a board or senior management officer responsible for compliance where appropriate to the size and nature of the business, and regulation 57 asks for the nominated officer's name on a registration application. The nominated officer is the person who receives internal reports and makes suspicious activity reports to the National Crime Agency under the Proceeds of Crime Act 2002.
How long do crypto firms keep AML records?
Five years in both regimes. Regulation 40(3) of the UK MLRs 2017 runs the period from the end of the business relationship or completion of the occasional transaction, and expressly covers documents received under the travel rule obligations. Article 40 of Directive (EU) 2015/849 sets the same period in the EU.
Can I use an off-the-shelf AML policy template?
As a starting point only. Both regimes require the policy to reflect your own risk assessment and to be proportionate to the size and nature of your business, so a template that does not match your customers, products, geographies and delivery channels fails the test it was bought to pass.
Is this quote service really free?
Yes, free to you, with no obligation to accept any quote. We pass your details only to relevant AML compliance specialists, who quote you directly; we may receive a fee from them, which is how the service is funded.
Sources
- Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (S.I. 2017/692)
- MLRs 2017, Part 7A: cryptoasset transfers (the UK travel rule)
- MLRs 2017, regulation 14A: cryptoasset exchange providers and custodian wallet providers
- Proceeds of Crime Act 2002, Part 7 (money laundering)
- National Crime Agency, suspicious activity reports
- FCA, cryptoasset firms: registration under the MLRs ahead of the new FSMA regime
- Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets
- Directive (EU) 2015/849 (the fourth AML directive, as amended)
- Regulation (EU) 2024/1624 (AMLR), applying from 10 July 2027
- Directive (EU) 2024/1640 (AMLD6), transposition by 10 July 2027
- Regulation (EU) 2024/1620 establishing AMLA
- Regulation (EU) 2023/1114 (MiCA), Article 68(8)