AMLA Flags AML Risks in Post-MiCA Client Migration: What Accounting Firms and CFOs Must Act On Now
The chair of the European Union's Anti-Money Laundering Authority has issued a pointed warning: the current wave of customer transfers between crypto asset service providers, driven by the post-MiCA licensing shake-out, is creating identifiable gaps in AML coverage that bad actors can and will exploit. For accounting firms advising digital asset clients, auditors signing off on CASP controls, and CFOs overseeing treasury operations that touch crypto, this is not a background regulatory development. It is an active compliance risk that demands an immediate procedural response.
The MiCA Migration Wave and Why It Creates Risk
The Markets in Crypto-Assets Regulation required crypto asset service providers operating across the EU to obtain a MiCA licence or exit the market. That deadline has passed, and the market is now in its consolidation phase: some CASPs secured their authorisation, others did not, and the firms that could not or chose not to complete the process are unwinding their customer books. Those customers need somewhere to go, and licensed CASPs are absorbing large volumes of incoming account transfers in a compressed timeframe.
Where the AML gap opens
That transfer process is precisely where the AMLA chair has identified the risk. When a customer moves from a closing or non-compliant CASP to a newly licensed one, the receiving firm must conduct its own know-your-customer and due diligence checks from scratch. It cannot simply inherit the previous provider's file. In practice, onboarding backlogs mean those checks are sometimes deferred, compressed, or handled by stretched compliance teams working at exceptional volumes. The result is a window during which the receiving CASP holds assets for customers whose full risk profile has not yet been validated to the MiCA standard.
The AMLA chair's specific concern
The AMLA chair's remarks make clear that the authority regards this transition period as a systemic, not isolated, vulnerability. The concern is structural: it is not about one firm cutting corners, but about an industry-wide migration creating simultaneous onboarding peaks across multiple licensed CASPs at the same moment. That concentration of compressed due diligence is, in the regulator's view, an AML risk in itself, one that requires proactive rather than reactive management.
What MiCA and AMLA Require of Licensed CASPs
MiCA imposes AML obligations on CASPs by reference to the existing EU AML framework, including the Transfer of Funds Regulation as updated for crypto assets. Under those rules, CASPs are required to apply customer due diligence at onboarding and on an ongoing basis, to screen for sanctions and adverse media, and to file suspicious transaction reports where warranted. None of those obligations are suspended or lightened because the customer is arriving from another regulated firm rather than from the retail market directly.
Inherited files are not compliant files
This is the point that accounting firms and compliance officers must drive home to CASP clients: accepting a customer data export from a transferring firm does not constitute a completed KYC process. The receiving CASP is responsible for its own due diligence. If an inherited customer later turns out to have been involved in illicit flows, regulators will look at whether the receiving firm conducted adequate independent verification, not whether it received a tidy handover pack from the departing provider.
AMLA's supervisory role going forward
AMLA becomes the direct AML supervisor of the largest cross-border CASPs under the EU's new AML package, with national competent authorities retaining oversight of smaller domestic players. The chair's public comments signal that AMLA is already watching how CASPs handle the migration period, and that supervisory attention will be concentrated on onboarding controls, transaction monitoring continuity, and the adequacy of risk assessments for transferred customer books.
Accounting and Audit Implications for Firms
For accounting practices and auditors serving CASP clients, the AMLA warning translates into concrete work. MiCA compliance is increasingly a component of financial statement risk, not just a regulatory box-tick. Where a CASP has absorbed a large volume of migrated customers, auditors need to assess whether the firm's AML control environment scaled proportionately, and whether any control gaps during the migration window have been remediated or remain open.
Control gap documentation
Auditors and compliance reviewers should request evidence that the CASP established a specific migration onboarding protocol: a written policy distinguishing the standard retail onboarding process from the accelerated or batched process used for transferred customers, with documented risk justifications for any variation. If no such protocol exists, that is a finding. If it exists but was not followed consistently, that is a more serious finding.
Transaction monitoring continuity
A subtler risk sits in transaction monitoring. When a customer migrates, their historical transaction data held by the departing CASP typically does not transfer to the receiving firm's monitoring system. The receiving CASP therefore begins monitoring from a cold start, with no behavioural baseline. Any anomalies present in the customer's pre-migration activity are invisible to the new firm's systems unless the firm specifically requests and reviews historical data, and then loads it in a format compatible with its monitoring tools. Firms using robust digital asset accounting software should verify that their transaction surveillance feeds are configured to flag new-to-firm customers during an elevated-risk period.
Regulatory capital and provisioning considerations
Where a CASP faces potential supervisory action arising from migration-period AML lapses, the possibility of financial penalties creates a provisioning question for the CFO and auditor. MiCA enforcement is still in its early stages, but AMLA's public statements suggest that supervisory intensity will increase during this period. Prudent financial reporting requires at least a disclosure of the contingent risk where a firm's migration-period controls were materially stretched.
Practical Steps for CFOs and Compliance Officers
The AMLA chair's warning is a prompt for immediate internal review rather than a reason for alarm. The following steps are grounded in existing MiCA and EU AML requirements, not new obligations invented by this article.
Audit your migration onboarding queue
CFOs and chief compliance officers at CASPs that have absorbed transferred customers should run a status report on every migrated account opened since the MiCA transition. The report should show: whether full KYC documentation has been collected and verified, whether a risk rating has been assigned, whether enhanced due diligence has been applied to higher-risk profiles, and whether any accounts remain in a provisional or incomplete state. Any incomplete files represent open AML exposure.
Review transaction monitoring configuration
Confirm with your compliance technology team that migrated customers are flagged as new-to-firm in your monitoring system and that appropriate elevated-risk rules are applied to their activity during an initial observation period. Where historical transaction data is available from the departing CASP, assess whether it can be ingested into your system to establish a behavioural baseline. Firms relying on crypto bookkeeping software or digital asset accounting software should ensure that data flows between the accounting layer and the compliance monitoring layer are intact and current for all migrated accounts.
Document supervisory readiness
AMLA and national competent authorities are on notice about migration-period risk. A supervisory inquiry or on-site visit triggered by the migration wave is a realistic near-term scenario. Compliance teams should prepare a migration file: a consolidated record of the onboarding protocol used, the volume of customers transferred in, the timeline of KYC completion, and any escalations or SARs filed during the period. That file should be audit-ready before any regulator asks for it.
Engage legal counsel on inherited liability
Where a transferred customer is later found to have been engaged in illicit activity prior to the migration, questions of liability between the departing and receiving CASPs may arise. Firms should take early legal advice on the scope of their exposure and on whether the terms of any customer transfer agreement from the departing provider contain relevant representations or indemnities.
The Broader MiCA Compliance Picture
This warning from AMLA does not arrive in isolation. ESMA has already conducted supervisory assessments of CASP custody practices, and national regulators across the EU have been issuing guidance and enforcement actions as the MiCA regime beds in. The AMLA chair's remarks are the AML counterpart to that broader supervisory intensification. Taken together, the signals from EU authorities are consistent: MiCA licensing was the threshold, and the real supervisory work begins now.
Accounting firms advising CASPs on MiCA compliance crypto obligations should treat the migration AML risk as a live engagement item, not a background watch. The window in which this risk is most acute is the current one, and the firms that document their controls and remediate gaps now will be in a materially better position when supervisory scrutiny arrives. For a broader view of ongoing MiCA supervisory developments, see our coverage of MiCA licensing obligations for crypto custodians and the ESMA Q&A on CASP custody obligations.
Frequently Asked Questions
Does a MiCA-licensed CASP need to redo KYC for customers transferred from a non-licensed provider?
Yes. A receiving CASP must conduct its own customer due diligence under the EU AML framework and MiCA requirements. Accepting a data file from the departing provider is not a substitute for independent verification. The receiving firm is fully responsible for the adequacy of its own KYC and risk assessment process from the moment it accepts the customer.
What is AMLA and when does it take over direct supervisory responsibility for CASPs?
The Anti-Money Laundering Authority is the EU's new centralised AML supervisor, established under the 2024 EU AML package. It will assume direct supervisory responsibility for the largest cross-border CASPs as part of the phased rollout of that package. Smaller domestic CASPs remain under national competent authority oversight, but AMLA sets the supervisory standards and coordinates across jurisdictions.
How should an accounting firm treat migration-period AML gaps when auditing a CASP client?
Auditors should assess whether the CASP established and followed a documented migration onboarding protocol, whether transaction monitoring was configured appropriately for new-to-firm customers, and whether any control gaps during the migration window have been remediated. Unresolved gaps are control findings. Where those gaps carry a realistic risk of regulatory penalty, the CFO and auditor should consider whether a contingent liability disclosure is required in the financial statements.
Does this AML risk apply to CASPs that only received a small number of migrated customers?
The obligation to conduct adequate KYC applies regardless of volume. A CASP that onboarded even a small cohort of transferred customers without completing independent due diligence has the same compliance exposure in respect of those accounts as a firm that onboarded thousands. Volume affects operational risk management; it does not affect the legal requirement.
What should a CFO include in a migration compliance file to prepare for potential supervisory review?
The file should contain the written migration onboarding protocol, a quantitative summary of transferred accounts, a status log showing the completion rate and timeline of KYC checks, records of any enhanced due diligence applied to higher-risk transferred customers, and copies of any suspicious activity or transaction reports filed in connection with migrated accounts. That documentation should be maintained and accessible before any supervisory inquiry is received.
Source: Cointelegraph Regulation
