Licensed by the Estonian FIU · FIU000117Operating since 2014Punane 6, Tallinn

info@micaconsult.com+372 5089565

LexorCorp Global

Guide

AML procedures for a MiCA CASP application

The risk assessment, internal rules and procedures a crypto-asset service provider files with its application.

LexorCorp Global OÜ · published 7 October 2026

An application for authorisation as a crypto-asset service provider under Regulation (EU) 2023/1114 (MiCA) is read as a whole, but two parts of it are read with particular care: how the applicant will prevent money laundering and terrorist financing, and how it will comply with the Travel Rule. This guide explains what the anti-money-laundering documents of a CASP applicant are, how they relate to the rest of the application file, and what our AML/CFT documents for a crypto-asset service provider contain.

The guide is general information, not legal advice. We prepare documents and organise the application; the authorisation is granted or refused by the Financial Supervision Authority alone, and no document guarantees the outcome.

Does a MiCA application need anti-money-laundering procedures?

Yes. The application file describes, among its other parts, the applicant's procedures for preventing money laundering and terrorist financing, and its Travel Rule arrangements for transfers of crypto-assets under Regulation (EU) 2023/1113. The full list of what the application contains is in our guide to the MiCA CASP licence in Estonia.

The authority reads these documents to judge whether the applicant understands its own business. Generic templates are easy to recognise and are a common reason for long rounds of questions: an exchange, a custody provider and a trading platform face different risks, and the rules must match the services actually applied for.

Which documents make up the AML/CFT framework?

  • Business-wide risk assessment — the money-laundering and terrorist-financing risks of the applicant's customers, products, channels and countries, and the measures that address them.
  • Internal rules on customer due diligence — identification and verification, beneficial owners, politically exposed persons, ongoing monitoring, and enhanced measures for higher-risk situations.
  • Sanctions screening and reporting procedure — how customers and transfers are screened and how a suspicion is reported to the Financial Intelligence Unit.
  • Training plan — who is trained, on what and how often, and who is responsible for it.

A compliance officer applies these rules in practice. Appointing that person is the applicant's own task; we do not act as the compliance officer.

How do the AML documents fit with the Travel Rule?

Since 30 December 2024 every crypto-asset service provider in the EU must send, receive and check information about the originator and the beneficiary of each transfer of crypto-assets. The Travel Rule procedure decides what happens when information is missing, how ownership of a self-hosted address is verified, and how the data feeds into transaction monitoring and suspicious transaction reporting. The two sets of documents therefore have to say the same thing: a transfer that the Travel Rule procedure suspends must be a case the AML rules know how to handle. The rule itself is explained in our guide to the Travel Rule for crypto-asset service providers; it is prepared as its own Travel Rule set-up.

Which add-ons belong with which class?

The classes of a MiCA authorisation are explained in the guide to MiCA licence classes and capital. In the order form the add-ons that an applicant of the chosen class needs in practice arrive ticked; you can untick any of them and add the others.

Common mistakes

  • A risk assessment that does not mention the applicant's own services. The assessment must follow the programme of operations: if the application names custody, the risks of custody are assessed.
  • Rules that contradict the Travel Rule procedure. Both are read together; thresholds and escalation steps must match.
  • Treating the documents as the end of the work. The applicant must apply the rules in practice, with a compliance officer and trained staff; software for screening and blockchain analytics is chosen and paid by the applicant.

What our AML/CFT documents for a CASP include

The AML/CFT internal rules, risk assessment and procedures for a crypto-asset service provider (from €3,200) are ordered and paid on the crypto licensing page, together with the application or separately. They include:

  • the business-wide risk assessment;
  • the internal rules and customer due diligence procedures;
  • the sanctions screening and reporting procedure;
  • the training plan.

The documents are usually delivered within 7 working days after we have received the necessary information. Not included: acting as your compliance officer or MLRO, screening and blockchain analytics software, staff training, and approval by any authority.

The amount is our fee for the standard scope and excludes VAT; state fees and the fees of the supervisory authority are paid by the applicant. All prices are on the price list. All communication takes place by email.

Ready to start? Choose the MiCA CASP class; the AML/CFT documents and the Travel Rule set-up arrive ticked. Order.

Frequently asked questions

What is in the AML/CFT documents for a crypto-asset service provider?

A business-wide risk assessment, internal rules with the customer due diligence procedures, a sanctions screening and reporting procedure and a training plan. They are usually delivered within 7 working days after we have received the necessary information. Acting as your compliance officer, software and staff training are not included.

Related guides

More on this topic: MiCA crypto licensing.

Order the AML/CFT documents

Choose the MiCA CASP class; the AML/CFT documents and the Travel Rule set-up arrive ticked.

Order MiCA crypto licensing