Banca d’Italia has reminded crypto-asset service providers (CASPs) that sanctions screening must apply to every crypto transfer, regardless of its value, warning firms against using minimum transaction thresholds that could allow small payments to escape automated checks.
The central bank’s latest communication does not introduce a new sanctions requirement. Instead, it reinforces obligations already established under European Banking Authority (EBA) guidelines, which have been applicable in Italy since December 30, 2025.
The warning comes as the European Union expands its sanctions framework and regulators place greater scrutiny on whether financial institutions have effective systems for enforcing restrictive measures in day-to-day transactions.
Table of Contents
ToggleEvery crypto transfer must undergo screening
Under the requirements highlighted by Banca d’Italia, CASPs must screen information relating to both the originator and beneficiary before executing a crypto-asset transfer.
The requirement applies regardless of whether a transaction involves thousands of euros or just a few euros. According to reporting by Borsa Italiana’s Radiocor service, the central bank specifically told operators to ensure that their screening systems do not contain minimum-value thresholds that determine which transactions are checked.
This means a €1 crypto transfer cannot automatically avoid sanctions screening simply because its value is considered insignificant.
The requirement does not, however, mean compliance staff must manually review every small transaction. Crypto companies can use automated screening systems that compare customer and transaction information against applicable sanctions lists.
Where a system identifies a potential match, the transaction can then be flagged for additional investigation before the provider decides whether to proceed or reject it.
The removal of minimum thresholds is also designed to reduce the risk of transaction structuring. Without such controls, a sanctioned individual or entity could attempt to split a larger transfer into numerous smaller payments to remain below an automated screening threshold.
The requirements were already in force
Banca d’Italia’s September reminder builds on rules that were established before the latest communication.
The underlying obligations come from EBA guidelines covering the internal policies, procedures and controls financial institutions must maintain to implement EU and national restrictive measures.
Banca d’Italia incorporated those guidelines through Note No. 52, issued on May 19, 2025. The requirements became applicable on December 30, 2025.
The framework covers banks, investment firms, payment institutions, electronic-money institutions and authorized crypto-asset service providers. Among other requirements, firms must maintain governance structures and controls capable of identifying sanctioned individuals and organizations.
As a result, the latest communication should be viewed as a supervisory reminder rather than a new legal rule. Banca d’Italia is effectively asking crypto operators to verify that their existing sanctions-screening systems are correctly configured.
Sanctions compliance also remains separate from authorization under the European Union’s Markets in Crypto-Assets Regulation (MiCA). While MiCA establishes licensing, governance and conduct requirements for crypto businesses, authorization under the framework does not exempt firms from their obligations under EU restrictive-measures legislation.
The distinction is particularly important as European regulators continue the transition to MiCA and assess the compliance status of crypto businesses operating across the European Economic Area.
Instant-payment rules do not provide an exemption for crypto
European regulations allow certain payment service providers to use an alternative sanctions-screening model for specific instant credit transfers.
Because instant payments settle extremely quickly, transaction-by-transaction screening can create operational difficulties. Under certain conditions, eligible payment providers can instead screen their entire customer base at least once every day and whenever new restrictive measures come into force.
Banca d’Italia has also permitted similar arrangements for certain low-risk domestic transfers under the responsibility of the relevant provider.
However, that approach does not extend to crypto transfers handled by CASPs.
Banca d’Italia’s 2025 guidance makes clear that crypto-asset transfers are subject to the applicable EBA requirements governing individual transactions. Crypto firms therefore cannot assume that the rapid settlement of a blockchain transaction qualifies them for the same screening arrangements available to some instant-payment providers.
CASPs must also comply with separate EBA requirements concerning the Travel Rule, which requires relevant originator and beneficiary information to accompany certain transfers of funds and crypto assets.
Crypto firms face pressure to strengthen screening systems
The central bank’s reminder is likely to prompt Italian crypto operators to review their sanctions-compliance systems.
Among the areas firms may need to examine are transaction-value settings, sanctions-list updates, name-matching procedures, alias detection, transliteration handling, alert investigations and record-keeping.
Crypto businesses also face additional challenges when sanctions exposure involves blockchain addresses rather than identifiable names.
A conventional customer-name screening system may fail to detect transactions involving a wallet address associated with a sanctioned individual, organization or service. As a result, some operators use blockchain analytics alongside traditional sanctions-screening tools to identify potentially risky addresses and transaction patterns.
Such systems can nevertheless generate complex alerts. Blockchain addresses may be indirectly connected to sanctioned entities, while attribution can change as new information becomes available. Compliance teams therefore need procedures for investigating and documenting potential matches rather than relying solely on automated alerts.
Banca d’Italia did not announce a new compliance deadline in its September communication, nor did it identify specific CASPs as being under investigation.
The requirements themselves are already applicable, meaning firms should treat the communication as a reminder of an existing regulatory obligation rather than a future compliance deadline.
EU sanctions increase scrutiny of crypto transactions
The warning arrives as the European Union continues expanding financial restrictions targeting entities and networks accused of sanctions evasion.
The growing number of sanctioned entities and crypto-related counterparties increases the challenge for financial institutions and CASPs, which must ensure their screening systems can identify relevant individuals, organizations and transaction exposures.
For Italian crypto operators, the immediate priority is therefore to conduct a documented review of their sanctions controls. That includes checking transaction-screening settings, confirming sanctions lists are updated promptly, reviewing procedures for handling potential matches and ensuring alerts are escalated appropriately.
Banca d’Italia’s message is clear: the size of a crypto transfer cannot determine whether sanctions screening takes place. For CASPs operating in Italy, every applicable crypto transfer must be subject to the required controls, whether it involves €1 or a much larger amount.









