The Bank of Italy requires domestic crypto asset service providers to conduct sanctions screening on both payer and payee information before executing customer transfers, and prohibits skipping checks due to small transaction amounts. This statement is not introducing new regulations but rather reiterating that existing European requirements are already in effect in Italy.
No minimum screening threshold shall be set.
According to the notice issued by the Bank of Italy on September 7, crypto-asset service providers (CASPs) must confirm that their internal screening systems do not set minimum transaction amount thresholds. All transactions, whether a €1 transfer or a larger amount, must be subject to sanctions screening.
This requirement applies to automated control settings, not to compliance personnel manually reviewing every small transaction. Institutions may still use automated systems to compare customer and transaction information against sanctions lists, and only initiate further review when potential matches are identified.
One reason for removing the minimum transaction amount is to prevent sanctioned entities from splitting large transfers into multiple smaller transactions to evade system screening.
The related obligations have been applicable since the end of last year.
The Bank of Italy notes that the relevant underlying obligations stem from the European Banking Authority’s (EBA) guidelines on internal policies and controls for implementing EU and member state restrictive measures. These guidelines have been incorporated into Italy’s regulatory framework through Bank of Italy Document No. 52 dated May 19, 2025, and will apply as of December 30, 2025.
Therefore, this September's communication was more of a regulatory reminder than the introduction of new legal requirements. The regulatory focus is on whether relevant institutions have properly configured and calibrated their existing screening systems.
The Bank of Italy also emphasized that obtaining MiCA authorization does not replace obligations related to sanctions compliance. MiCA primarily addresses licensing, governance, and operational requirements, while EU restrictive measures must still be enforced separately.
Instant payment exceptions do not apply to cryptocurrency transfers.
European regulations apply different screening methods to certain instant credit transfers. Due to the faster settlement speed, some payment service providers may switch to screening all customers at least once daily and update checks when new restrictive measures take effect.
However, the Bank of Italy's 2025 document explicitly states that this exception does not apply to cryptocurrency transfers processed by CASPs. Even though blockchain transactions are confirmed quickly, cryptocurrency service providers must still complete the required information screening before execution.
In addition to sanctions list screening, relevant institutions must also comply with EBA’s separate guidance on the Travel Rule to address missing or incomplete information for senders and recipients in transfers.
Cryptocurrency service providers face pressure for system review.
This alert means that Italian cryptocurrency service providers must promptly review whether their existing sanctions controls cover all transaction amounts, and confirm that sanctions list update frequencies, alert handling procedures, and audit trails are properly in place.
In addition to name matching, on-chain address identification is also a challenge. Screening by name alone may not reliably identify connections between addresses and sanctioned entities, related intermediaries, or restricted services.
Therefore, some institutions may need to combine customer screening with on-chain analysis. However, on-chain analysis results still require human judgment, as address ownership may change and some transactions may only be indirectly related.
The Bank of Italy did not announce a new compliance deadline, nor did it name specific entities under investigation or cite any penalty cases. For local crypto operators, the more practical next step is to create documented review records to confirm that system configurations, list coverage, and escalation procedures encompass every transaction.


