The €1,000 Threshold Is Not an Interpretation Problem
Two €1,000 thresholds in European crypto AML live in different regulations, apply to different populations, and do not even bite at the same number. AMLA's February 2026 draft RTS resolves the business-relationship question most of the debate has missed.
Deep dive on the €1,000 crypto AML threshold debate after AMLA's February 2026 consultations (closed 8 May 2026; draft RTS under Article 19(9) AMLR submitted to the Commission by 10 July 2026). Core thesis: the industry treats one number as one gate with one legal consequence; it is two instruments (AMLR Article 19(3) occasional-transaction CDD at "at least €1,000" from 10 July 2027 vs TFR Articles 14(5)/16(2) self-hosted wallet verification at "exceeding €1,000" live since 30 December 2024), different populations, different timelines, and not the same numeric trigger at exactly €1,000.00. AMLA draft RTS: business relationships and occasional transactions are mutually exclusive; online registration providing ongoing access (Recital 7, CASPs named) normally implies duration; exchange/transfer CASPs must consider three or more transactions in twelve months (Article 2(3)). The €1,000 occasional threshold governs guest checkouts, ATMs and walk-ups, not registered account holders who already received full CDD at onboarding under Article 19(1)(a). Article 34(4) AMLR: once higher risk is established, SoF/SoW are mandatory EDD elements, not permissive. Error in industry logic: conflating risk-factor presence (EBA/GL/2024/01 self-hosted/DeFi; Article 40 in EDD chapter) with automatic higher-risk classification for entire crypto customer base. Eight-scenario map (registered fiat purchase, kiosk, self-hosted payout, structuring, MiCA counterparty, unknown self-hosted origin, mixer/sanctions, regulated corporate settlement). AMLA Article 19(9) consultation chose Option A: no additional lower thresholds; proportionality and simplification cited. EBA/Op/2025/10 (28 July 2025): RegTech implicated in >50% serious EuReCA failures; 277 material RegTech weaknesses 2023–24; CDD 61% of breaches; €1,000 EDD escalation often product architecture (TFR gate built first, SoW prompt added as sprint). Draft RTS Article 3(1)(b)(v): linked transactions via same digital infrastructure; Recital 11 IP/device/geolocation data CASPs already hold. Opinion section: liability-allocation not interpretation problem; analytics answers SoF not SoW; defensibility from documented permissive policies; separate TFR and AMLR gates in system design; supervisory incentive gap on retrospective low-risk classification; uneven cost on small CASPs vs large exchanges; AMLA direct supervision ~40 entities from 1 Jan 2028, sanctions up to €10m/10% turnover. Eight compliance officer diagnostic questions. Related: PSD2/MiCA overlap, AI in AML under MiCA.
The €1,000 Threshold Is Not an Interpretation Problem MiCA Edge Cases | Where Innovation Meets Regulation Discussion note: this reflects positions we have argued in client working groups, licensing files and industry panels over the past eighteen months, and responds to a debate that keeps restarting from the same place. Written after the close of AMLA's February 2026 consultations, which answer more of the question than the debate has noticed. On 9 February 2026, AMLA published three consultation papers. Two of them concerned customer due diligence. The third, the draft Regulatory Technical Standards under Article 19(9) of Regulation (EU) 2024/1624, concerned something less glamorous: the criteria for telling a business relationship apart from an occasional transaction. The consultation closed on 8 May 2026. AMLA's deadline for submitting the draft to the Commission was 10 July 2026. Almost nobody in the crypto compliance debate read it, which is a shame, because it settles a question that debate has been circling for two years. The question, as it is usually posed: does €1,000 trigger Customer Due Diligence, or has it become a practical trigger for Source of Funds, Source of Wealth and Enhanced Due Diligence? Ask five practitioners, collect three answers, and observe that nobody volunteers to be the one who asked for less. We have sat in those rooms. The argument has a structural problem. It treats the €1,000 threshold as a single object, applied to a single population, with a single legal consequence. It is none of those things. Two Thresholds, One Number, Different Instruments There are two €1,000 thresholds in European crypto AML. They live in different regulations, apply to different populations and trigger different obligations. The first sits in AMLR Article 19(3) . By derogation from the general rule, crypto asset service providers apply full CDD to occasional transactions of at least €1,000 . Below that value, CASPs still apply at minimum the identification and verification measures in Article 20(1)(a). There is no zero CDD floor for this sector. A €40 occasional swap still requires the customer to be identified and verified. The second sits in TFR Article 14(5) and its mirror in Article 16(2). Where a transfer exceeding €1,000 goes to or comes from a self hosted address, the CASP must take adequate measures to assess whether that address is owned or controlled by its customer. This applies to every transfer of that size, whether or not there is a business relationship, and whether or not any CDD threshold has been crossed. Note the wording. AMLR says "at least EUR 1 000." TFR says "exceeding EUR 1 000." A transaction of exactly €1,000.00 triggers AMLR CDD and does not trigger TFR wallet verification. The two thresholds that the industry has merged into one number do not agree on the number. | | AMLR Article 19(3) | TFR Articles 14(5), 16(2) | | | | | | Trigger value | At least €1,000 | Exceeding €1,000 | | Applies to | Occasional transactions only | Every transfer to or from a self hosted address | | Population | Customers with no business relationship | All customers, including account holders | | Obligation | Full CDD (Article 20) | Adequate measures to assess ownership or control | | Applies from | 10 July 2027 | 30 December 2024, already live | | Below the line | At least Article 20(1)(a) identification and verification | Originator and beneficiary data still required | The Business Relationship Question Almost Nobody Asked Article 19(1)(a) requires CDD when establishing a business relationship. Article 19(1)(b) requires it for occasional transactions above threshold. Article 2(1), point (19) defines a business relationship by reference to an element of repetition or duration, or the expectation of one at the time contact is established. AMLA's draft RTS defines occasional transactions negatively: a transaction, or provision of services connected to a transaction, that is not carried out as part of a business relationship. The consultation paper states the consequence plainly. Business relationships and occasional transactions are mutually exclusive. Any engagement that does not meet the definition of a business relationship is an occasional transaction by default, and any engagement that does meet it is not. Article 2(1) of the draft RTS then sets out the one horizontal criterion binding on every obliged entity in the Union: firms must at least take into account the use of online services through a registration providing ongoing access when considering the element of duration. Recital 7 names the sector directly. Online services offered by payment service providers and crypto asset service providers fall within this, and the recital adds that use of an online service after any form of registration normally implies that some duration may reasonably be expected. Which is a bureaucratic way of saying that people who open accounts tend to come back. Read that against the mutual exclusivity rule. A retail customer who registers with an exchange, passes onboarding and holds an account is in a business relationship. CDD applies at onboarding, in full, under Article 20, regardless of transaction value. The occasional transaction threshold in Article 19(3) does not apply to that customer. Not at €1,000, not at €1,200, not at €40,000. It is the wrong limb of the wrong paragraph. For exchange and transfer services specifically, the draft RTS goes further. Article 2(3) applies to CASPs providing the services in MiCA Article 3(1), points (16)(c), (d) and (j): exchange of crypto assets for funds, exchange of crypto assets for other crypto assets, and transfer services on behalf of clients. Those firms must at least take into account three or more transactions within a rolling twelve month period as a criterion for repetition. Three transactions in a year, and the repetition element is in play. The rolling period does not reset in January. So what does the €1,000 occasional transaction threshold actually govern? Guest checkouts. Crypto ATMs and kiosks. One off conversions where no account is opened and no ongoing access is granted. Walk ups. A real and risk relevant population, and a rounding error against European retail crypto volume. Two years of argument, several thousand LinkedIn comments and an entire vendor product category have been organised around a provision that does not apply to most of the customers it is being applied to. Aggregation Collapses Into the Same Question The immediate objection is structuring, and it is the right objection. Draw a line at €1,000 and somebody will transact at €950. The framework worked this out in 1991, and the draft RTS is more specific about it than most implementations assume. Article 19 applies its thresholds whether the value arrives in a single operation or through linked transactions. Article 2(1), point (20) defines those as two or more transactions with either identical or similar origin, destination and purpose, or other relevant characteristics, over a specific period. Four weekly transfers of €950 to the same address are not four sub threshold events. Draft RTS Article 3(1) sets out what must at least be considered. Transactions performed or received by the same person. Where the information is already available: customers who are family members, business partners, operating in concert, subsidiaries or beneficial owners of the same parent, using common intermediaries, or using the same digital infrastructure . Transactions pertaining to the same purchase, including instalments. Transactions performed within a short timeframe. The qualifier matters. These criteria bite on information the firm already holds. Recital 11 gives the sector example: crypto asset service providers have their customers' IP addresses. Device identifiers and geolocation appear in Recital 13, alongside the reasoning, which is that schemes built to defeat thresholds increasingly run many