
Banca d’Italia told Italian crypto-asset service providers on Sept. 7 to verify that every transfer passes through sanctions screening, regardless of its value.
Summary
- Every crypto transfer must undergo sanctions screening, regardless of value, under existing European banking guidelines.
- Banca d’Italia told CASPs to verify screening systems contain no minimum transaction threshold configured internally.
- Firms must check originator and beneficiary information before executing individual crypto-asset transfers for customers consistently.
- The screening requirements have applied in Italy since December 30, 2025, rather than starting September.
- Instant-payment exceptions available to certain payment providers do not cover crypto transfers processed by CASPs.
The central bank specifically warned firms against setting a minimum transaction threshold within their screening systems. Such a threshold could allow small crypto transfers to avoid automated checks.
The communication does not establish a new sanctions rule. It reinforces requirements already contained in European Banking Authority guidelines that have applied in Italy since Dec. 30, 2025.
The reminder follows an expansion of European Union restrictive measures and growing regulatory attention on whether financial institutions can enforce sanctions effectively in daily operations.
Banca d’Italia requires checks on every crypto transfer
Banca d’Italia instructed crypto-asset service providers, known as CASPs, to screen information about both the sender and recipient before executing a crypto transfer. The requirement applies to individual transactions and does not depend on their value.
According to a report published through Borsa Italiana’s Radiocor service, the central bank asked operators to ensure their systems contain no minimum threshold that limits which transactions undergo screening.
The policy means a transfer cannot bypass sanctions controls merely because it is worth €1 or another small amount. It does not mean compliance employees must manually approve every micro-transfer.
CASPs may use automated systems that compare customer and transaction information with applicable sanctions lists. A possible match may then require closer examination before the provider executes or rejects the transfer.
Removing minimum thresholds also addresses structuring risks. A sanctioned person could otherwise divide a larger transfer into multiple smaller transactions designed to remain below an operator’s screening limit.
The rule predates the September warning
The underlying obligations were set out in the EBA’s guidelines covering internal policies, procedures and controls for implementing EU and national restrictive measures.
Banca d’Italia formally incorporated the guidance through Note No. 52 on May 19, 2025. The document says the guidelines became applicable on Dec. 30, 2025.
The rules cover banks, investment firms, payment institutions, electronic-money institutions and authorized crypto-asset service providers. They require those businesses to maintain governance arrangements and controls capable of identifying designated people and entities.
The September communication therefore represents a supervisory reminder rather than the introduction of a fresh legal threshold. Banca d’Italia is asking firms to confirm that their existing systems are properly configured and calibrated.
Sanctions compliance is also separate from authorization under the Markets in Crypto-Assets Regulation. MiCA establishes licensing, governance and conduct requirements, but receiving authorization does not remove obligations under EU restrictive-measures rules.
That distinction matters as national regulators complete Europe’s transition to MiCA. As crypto.news reported, more than 1,000 EEA crypto firms remained without MiCA authorization following a major transition deadline.
Instant-payment exceptions do not cover CASPs
European rules provide a different screening approach for certain instant credit transfers handled by payment service providers. Their speed makes transaction-by-transaction screening difficult without undermining the purpose of instant settlement.
Eligible payment providers may instead screen their entire customer base at least once daily and whenever new restrictive measures take effect. Banca d’Italia also permits that approach for some low-risk domestic transfers under the provider’s responsibility.
However, the central bank’s 2025 note expressly states that the exception does not cover crypto transfers processed by CASPs. Crypto providers must follow the relevant EBA provisions governing individual crypto-asset transfers.
The distinction means firms should not apply an instant-payment configuration to crypto services simply because a blockchain transaction settles quickly. CASPs must still screen the required information before execution.
Providers must also follow the EBA’s separate Travel Rule guidance. Those rules address missing or incomplete originator and beneficiary information accompanying fund and crypto transfers.
Crypto firms must now test their screening controls
Banca d’Italia’s reminder places immediate operational pressure on CASPs to review their sanctions controls. Firms need to confirm that transaction values do not determine whether screening occurs.
They must also examine how frequently their systems receive updated sanctions lists. Other controls may include matching aliases, handling transliterated names, investigating alerts and recording decisions for supervisory review.
Blockchain addresses linked to sanctioned parties present another challenge. Name screening alone may not identify exposure when a transfer involves an address associated with a designated entity, intermediary or sanctioned service.
Operators may therefore combine customer screening with blockchain analytics. However, analytics alerts require careful assessment because address attribution can change and transactions may involve indirect exposure rather than a designated party.
The central bank did not announce a new compliance deadline in its September communication. The applicable EBA requirements are already in force, meaning firms should treat the review as an existing responsibility.
Banca d’Italia also did not identify specific CASPs under investigation or announce penalties. Any enforcement action would require a separate regulatory decision based on an operator’s controls and conduct.
The reminder comes as the EU continues using financial restrictions against entities accused of supporting sanctions evasion. In related coverage, EU sanctions targeted 14 crypto platforms and 94 financial institutions, increasing the number of counterparties that compliance systems may need to identify.
For Italian crypto operators, the next step is a documented review of system settings, sanctions-list coverage and escalation procedures. A MiCA authorization alone will not demonstrate that those controls work on every transfer.

Leave feedback about this