The European Council adopts Regulation to make crypto-asset transfers traceable
The first thing to note is that this is a regulation so it's part of the EU's Centralisation and Direct Rule system which bypasses Directives and national parliaments and regulators.
The Regulation redefines that of Crypto-currencies which is in two existing Directives. The Council, somewhat disingenuously saying it is acting because of "international developments" including at the Financial Action Task Force, says there is a need "to regulate additional categories of virtual asset service providers not yet covered and to broaden the current definition of virtual currency." It's disingenuous because the European Union is a major driver of the FATF's policies, not the other way around.
In the Regulation, the Council says "This Regulation is not intended to impose unnecessary burdens or costs on payment service providers, crypto-asset service providers or persons who use their services. In that
regard, the preventative approach should be targeted and proportionate and should be in full compliance with the free movement of capital, which is guaranteed throughout the Union." That says, in essence, that the Council will impose whatever it thinks fit and declare it as necessary so that no one can complain about costs and that international transfers will not be hampered - so long as the new requirements are met. The second is good; the first is manipulative.
Interestingly, the Council says that there are risks but that no one in its circle of influence knows what they are or how big they are. It says "Certain transfers of crypto-assets entail specific high-risk factors for money laundering, terrorist financing and other criminal activities, in particular transfers related to products, transactions or technologies designed to enhance anonymity, including privacy wallets, mixers or tumblers. To ensure the traceability of such transfers, the European Supervisory Authority (European Banking Authority), established by Regulation (EU) No 1093/2010 of the European Parliament and of the Council1 (EBA), should clarify, in particular, how the risk factors listed in Annex III to Directive (EU) 2015/849 are to be taken into account by crypto-asset service providers, including when carrying out transactions with non-Union entities that are not regulated, registered or licensed in any third country, or with self- hosted addresses."
The fact is that the nature of the risks are exactly the same as with any other currency or asset and it could and should be managed in a similar way.
And the Council isn't actually acting as it first appeared that it would - it's delegating: . Where situations of higher risk are identified, the European Banking Authority should issue guidelines specifying the enhanced due diligence measures that obliged entities should consider applying to mitigate such risks, including the adoption of appropriate procedures such as the use of distributed ledger technology analytic tools, to detect the origin or destination of crypto-assets."
Question: why isn't this falling within the ambit of the new, very grand and very expensive "Anti Money Laundering Authority"?
Non-Fungible Tokens are expressly excluded - unless they are covered under something else.
It is also appropriate to exclude from the scope
of this Regulation transfers of funds and of electronic money tokens, as defined in
Article 3(1), point (7), of Regulation (EU) 2023/...+, that represent a low risk of money laundering or terrorist financing. Such exclusions should cover payment cards, electronic money instruments, mobile phones or other digital or information technology (IT) prepaid or postpaid devices with similar characteristics, where they are used exclusively for the purchase of goods or services and the number of the card, instrument or device accompanies all transfers. However, the use of a payment card, an electronic money instrument, a mobile phone or any other digital or IT prepaid or postpaid device with similar characteristics in order to effect a transfer of funds or of electronic money tokens between natural persons acting as consumers for purposes other than trade, business or
professional activity, falls within the scope of this Regulation.
The nested exclusions - and inclusions - makes it difficult to work out what is included and is not. It's going to be much simpler for regulated businesses to adopt a single system across all products - simpler that is until someone notices that a blanket system would mean passing information that need not be passed - and then GDPR will kick in.
Remember that claim about no unnecessary costs? It's looking pretty weak now, isn't it?
It gets worse: "In addition, automated teller machine withdrawals, payments of taxes, fines or other levies, transfers of funds carried out through cheque images exchanges, including truncated cheques, or bills of exchange, and transfers of funds where both the payer and the payee are payment service providers acting on their own behalf should be excluded from the scope of this Regulation" but "Crypto-asset automated teller machines (the ‘crypto-ATMs’) can enable users to perform transfers of crypto-assets to a crypto-asset address by depositing cash, often without any form of customer identification and verification. Crypto-ATMs are particularly exposed to money laundering and terrorist financing risks because the anonymity they provide, and the possibility of operating with cash of unknown origin, make them an ideal vehicle for illicit activities. Given the role of crypto-ATMs in providing or actively facilitating transfers of crypto-assets, transfers of crypto-assets linked to crypto-ATMs should fall under the scope of this Regulation."
It's a big, complex, regulation that will require considerable study. To set the application, a long and very detailed questionnaire will be required.
But when it gets down to the operational part, it's actually pretty simple:
The crypto-asset service provider of the originator should also ensure that transfers of crypto-assets are accompanied by the name of the beneficiary, the beneficiary’s distributed ledger address, in cases where a transfer of crypto-assets is registered on a network using distributed ledger or similar technology, the beneficiary’s account number, in cases where such an account exists and is used to process the transaction and, subject to the existence of the necessary field in the relevant message format and where provided by the originator to its crypto-asset service provider, the current LEI or, in its absence, any other available equivalent official identifier of the beneficiary. The information should be submitted in a secure manner and in advance of, or simultaneously or concurrently with, the transfer of crypto-assets."
There is also this:
38. Regarding transfers of crypto-assets, the requirements of this Regulation should apply to all transfers including transfers of crypto-assets to or from a self-hosted address, as long as
there is a crypto-asset service provider involved.
(39) In the case of a transfer to or from a self-hosted address, the crypto-asset service provider should collect the information on both the originator and the beneficiary, usually from its
client. A crypto-asset service provider should in principle not be required to verify the information on the user of the self-hosted address. Nonetheless, in the case of a transfer of an amount exceeding EUR 1 000 that is sent or received on behalf of a client of a crypto-asset service provider to or from a self-hosted address, that crypto-asset service provider should verify whether that self-hosted address is effectively owned or controlled by that client.
(40) As regards transfers of funds from a single payer to several payees that are to be sent in a batch file transfer containing individual transfers from the Union to outside the Union, provision should be made for such individual transfers to carry only the payment account number of the payer or the unique transaction identifier, as well as complete information on the payee, provided that the batch file contains complete information on the payer that is verified for accuracy and complete information on the payee that is fully traceable."
Compliance is prescriptive for various functions and combine ordinary banking, etc. compliance with money transfer/SWIFT measures.
The effect of the Regulation will be to put crypto-transfers on a footing that is similar to that of fiat currency and other asset transfers.
Will it work in relation to large-scale laundering of crypto?
No, of course not. Self-hosted wallets operating though offshore agencies with no EU presence will remain invisible.
But it might work, at least a bit, in relation to romance scams and sextortion where the amounts of money involved are too small to justify complex avoidance measures. Those things are a public menace and so some reduction in that type of crime will be welcome.
And it will have muscle: although no one is saying it out loud, just as with the USA's approach to correspondent banking, any non-EU exchange that isn't in compliance will find that it difficult to do business with those within the EU that are.
----------------------------------------
The text of the Regulation (in English) is here: https://data.consilium.europa.eu/doc/document/PE-53-2022-INIT/en/pdf


