The End of the MiCAR Transitional Period: AML Risks and Compliance Priorities for Crypto-Asset Service Providers

The end of the Markets in Crypto-Assets Regulation (“MiCAR”) transitional period marks a defining moment for the European crypto-asset sector. From 1st July 2026, firms providing crypto-asset services in the European Union will need to be authorised as MiCAR-compliant crypto-asset service providers (“CASPs”) in order to continue operating lawfully.

While much of the attention has focused on licensing, authorisation and market access, the end of the transitional period also creates important anti-money laundering and countering the financing of terrorism (“AML/CFT”) risks. The Anti-Money Laundering Authority (“AMLA”) has highlighted that the exit of unauthorised virtual asset service providers (“VASPs”), the transfer or termination of customer relationships, and the concentration of activity among a smaller number of authorised CASPs may materially change the risk profile of the EU crypto market.

For crypto firms, this is not simply a regulatory deadline. It is an AML/CFT stress test.

Why the Transitional Period Creates AML Risk

During periods of regulatory transition, financial crime risks often increase. Customers move between providers. Firms wind down services. Compliance teams operate under pressure. New customer inflows may be processed quickly. Some firms may reduce investment in controls once they know they will no longer operate in the market.

This creates opportunities for illicit actors.

A customer holding crypto-assets with an unauthorised VASP may seek to move assets quickly before the provider exits the market. Another may attempt to transfer funds across several platforms to obscure their origin. A sanctioned or high-risk customer may exploit the disruption to seek access to a newly authorised CASP. A firm under wind-down pressure may fail to maintain the same level of customer monitoring, transaction screening or suspicious activity reporting.

AMLA’s message is clear: the end of the transitional period must not become a window for weakened AML/CFT controls.

The Risk for Unauthorised VASPs

Unauthorised VASPs exiting the market face one of the most immediate AML/CFT risks. Wind-down processes can place significant pressure on governance, staffing, monitoring systems and customer communication procedures.

The risk is particularly acute where a VASP has already been identified as having AML/CFT deficiencies. In such cases, the final stages of operation may involve high volumes of withdrawals, transfers, account closures and customer requests, precisely at the moment when the firm’s internal focus may be shifting away from long-term compliance investment.

This can create a dangerous gap.

For example, a customer may request a rapid transfer of crypto-assets to an external wallet shortly before the VASP ceases operations. If the firm treats this as a routine exit request without adequate screening, wallet risk assessment or transaction monitoring, illicit funds may be moved out of the regulated perimeter with limited scrutiny.

To mitigate this, unauthorised VASPs should maintain effective AML/CFT governance until all regulated activities have ceased. Wind-down does not mean compliance can be relaxed. Customer due diligence information should remain up to date, suspicious activity should continue to be identified and reported, and enhanced monitoring should be applied where exit-related activity appears unusual or inconsistent with the customer’s known profile.

The Risk for Authorised CASPs

Authorised CASPs may face the opposite problem: sudden growth.

As unauthorised VASPs leave the market, customers may move to authorised providers. This can result in rapid onboarding volumes, larger transaction flows and more diverse customer risk profiles. A CASP that was previously servicing a narrower customer base may suddenly receive higher-risk customers, complex portfolios, or customers with incomplete historical records.

This creates pressure on onboarding teams, compliance officers, MLROs and transaction monitoring systems.

The AML risk is not that these customers should automatically be rejected. AMLA specifically warns against blanket de-risking. The correct response is not to refuse all customers coming from unauthorised VASPs, but to assess them individually under a risk-based approach.

In practice, this means authorised CASPs should ask several key questions before accepting transferred customers:

  • Who is the customer?
  • Where did the crypto-assets originate?
  • Is there a clear transaction history?
  • Are external wallets involved?
  • Does the customer’s activity make sense in light of their profile?
  • Are there links to high-risk jurisdictions, sanctions exposure, darknet markets, mixers, fraud typologies or other indicators of concern?

Where risks are higher, enhanced due diligence should be applied. This may include deeper source of wealth and source of funds analysis, blockchain analytics, wallet screening, review of transaction history and additional senior management approval.

Transaction Monitoring Must Be Scalable

One of the most practical risks identified by AMLA is pressure on transaction monitoring capacity.

A CASP may have a technically compliant transaction monitoring framework on paper, but if the system is calibrated for 20,000 customers and suddenly needs to manage 100,000 customers, the effectiveness of that framework may deteriorate quickly.

Alerts may increase. False positives may rise. Investigations may be delayed. Backlogs may develop. Compliance teams may struggle to distinguish between normal migration-related flows and suspicious movement of funds.

This is why scalability matters.

CASPs should review whether their monitoring systems, blockchain analytics tools, alert triage procedures and compliance staffing are capable of handling increased volumes of crypto-asset transfers. A surge in customers should be treated as a change in the firm’s business risk assessment, not merely as a commercial opportunity.

The Risk of Concealment During Customer Transfers

The movement of customers from unauthorised VASPs to authorised CASPs may also create new typologies.

Illicit actors may attempt to use the transition period to obscure asset trails by moving funds between multiple CASPs, self-hosted wallets and jurisdictions. They may claim that unusual activity is simply part of the MiCAR transition. They may close accounts with one provider, open accounts with another, and use the process to reset the compliance history attached to their activity.

This is particularly relevant where the receiving CASP does not obtain sufficient information about the customer’s previous activity or where the customer is able to transfer assets through external wallets before entering the new provider’s ecosystem.

A practical example would be a customer who exits an unauthorised VASP, transfers assets to a private wallet, routes them through several wallets, and then deposits them with an authorised CASP. Without blockchain analytics and proper risk assessment, the receiving CASP may only see the final deposit, not the wider transaction chain.

This is precisely why customer migration should not be treated as a purely administrative process. It is an AML event.

Supervisory and FIU Coordination

AMLA also highlights the role of AML/CFT supervisors and financial intelligence units (“FIUs”). The end of the transitional period may create supervisory blind spots, particularly where multiple unauthorised VASPs are winding down while authorised CASPs are receiving large customer inflows.

Supervisors will need visibility over which firms are exiting, where customers are moving, and whether AML/CFT controls remain effective during the transition. Inconsistent approaches across Member States may create opportunities for regulatory arbitrage, where illicit actors exploit weaker or less coordinated supervisory responses.

FIUs may also observe new patterns in suspicious activity reporting. Mass transfers, rapid asset movements, unusual wallet behaviour and cross-border movements between CASPs may generate new intelligence signals. Effective cooperation between FIUs will be essential to detect whether transition-related flows are being used to conceal money laundering or terrorist financing risks.

What CASPs Should Do Now

The firms best positioned for the end of the MiCAR transitional period will be those that treat AML/CFT readiness as part of their licensing and operational strategy.

Key actions include:

  • Reviewing the business risk assessment to reflect expected customer migration and increased volumes;
  • Testing whether transaction monitoring systems can manage higher transaction flows;
  • Ensuring onboarding processes can assess customers transferring from unauthorised VASPs;
  • Avoiding blanket de-risking while applying enhanced due diligence where required;
  • Strengthening wallet screening, blockchain analytics and source of funds controls;
  • Ensuring suspicious activity reporting remains effective during onboarding surges;
  • Maintaining sufficient compliance staffing and escalation procedures; and
  • Documenting decisions clearly to evidence a risk-based approach.

For unauthorised VASPs, the priority is different but equally important: wind down in an orderly, documented and AML-compliant manner. Customer exits must remain subject to monitoring, suspicious activity must still be reported, and compliance obligations should continue until all regulated activity has ceased.

A New AML Phase for the European Crypto Market

The end of the MiCAR transitional period is more than a licensing deadline. It is a structural reshaping of the European crypto-asset market.

Some firms will exit. Others will consolidate. Customers will move. Risk profiles will change. Supervisors and FIUs will need to monitor the transition closely. Authorised CASPs will need to absorb new business without compromising financial crime controls.

The central AML lesson is clear: regulatory transition creates opportunity, but also vulnerability.

For compliant firms, this is a chance to demonstrate maturity, resilience and credibility. For illicit actors, it may be seen as a moment to exploit disruption. The difference will depend on how effectively CASPs, VASPs, supervisors and FIUs apply a coordinated, risk-based and forward-looking AML/CFT response.

As MiCAR moves from transition to enforcement, AML/CFT compliance will remain one of the key tests of whether the European crypto market can become not only more regulated, but also safer, more transparent and more trusted.