Banca d'Italia Orders Sanctions Screening for Crypto Transfers
Italy's central bank issued a formal directive on 8 September 2026 requiring all crypto asset service providers operating under Italian jurisdiction to embed EU sanctions screening directly into their crypto transfer workflows. The mandate closes a compliance gap that regulators across the bloc have been watching closely, and it arrives at a moment when sanctioned actors are actively exploiting digital assets to move value across borders. For accounting firms, auditors, and CFOs who use crypto accounting software to record and reconcile digital asset activity, the directive has immediate operational consequences.
What Banca d'Italia Actually Requires
The Banca d'Italia instruction is direct: crypto asset service providers must establish documented internal policies and controls to enforce EU financial sanctions when processing cryptocurrency transfers. The word "policies" carries weight here. A control that exists only in an employee handbook does not satisfy a supervisory expectation for documented enforcement procedures.
Scope of the Obligation
The requirement applies to the identification of both customers and individual transactions linked to sanctioned entities. That is a broader test than a simple onboarding name-check. It means the screening obligation follows the transaction at the point of processing, not just at account opening. A CASP that screens clients at KYC but does not re-screen at the moment a transfer is submitted will not meet the standard the central bank is describing.
Why Now
The timing is not arbitrary. Banca d'Italia's directive explicitly acknowledges that cryptocurrencies are increasingly being used by Iranian and Russian entities to circumvent financial sanctions. One sanctions-targeted stablecoin alone processed over $110 billion in cumulative transactions between February 2025 and May 2026, according to blockchain security data cited in the original report. Separately, blockchain analytics research identified flows between a crypto exchange and sanctioned Iranian entities spanning more than seven years. The US Treasury also moved in July 2026 to freeze wallets linked to Iran's central bank. The regulatory response in Italy is, in that context, a reaction to documented evasion patterns rather than a precautionary posture.
The EU Sanctions Framework CASPs Must Now Enforce
EU financial sanctions are directly applicable across all member states under Council regulations. They prohibit making funds or economic resources available, directly or indirectly, to listed persons and entities. When a CASP processes a crypto transfer, it is acting as an intermediary in the movement of economic value, placing it squarely within the scope of those prohibitions.
Interaction with MiCA and AMLR
Italy's instruction does not operate in isolation. The EU's Markets in Crypto-Assets Regulation (MiCA) establishes the licensing framework for CASPs operating in the EU, while the forthcoming EU Anti-Money Laundering Regulation (AMLR) will impose harmonised AML and sanctions compliance obligations across the bloc. Banca d'Italia's directive acts as a bridge: it fills the supervisory space right now, before AMLR takes full effect, and signals that Italian supervisors will not wait for pan-European harmonisation to enforce existing EU sanctions rules.
For CASPs already preparing MiCA compliance programmes, this should be read as confirmation that sanctions screening capability is an expected component of the internal controls framework, not an optional enhancement.
Accounting and Audit Implications
The directive has consequences that extend well beyond the compliance team. Accounting firms handling CASP clients, and CFOs at firms that hold or transact in digital assets, need to understand where the new obligation intersects with their workflows.
Transaction-Level Controls and the Audit Trail
Auditors reviewing a CASP's control environment will now have a specific, regulator-stated benchmark: is there a documented policy? Is it enforced at the point of transfer processing? Does it produce an audit trail showing which transactions were screened, against which list version, and what the outcome was? These are testable controls. Audit firms that have not yet developed procedures to evaluate sanctions screening effectiveness in a crypto context should treat this directive as the specification they have been waiting for.
From a financial reporting perspective, any transfer that was processed without adequate screening and that is later identified as linked to a sanctioned entity creates potential exposure: frozen assets, regulatory fines, and possible restatement risk if the value was recognised in revenue or as a settled receivable. That exposure belongs in the risk section of a financial statement, and it may require disclosure depending on materiality thresholds.
Crypto Bookkeeping Software: Where Screening Must Connect
Most crypto bookkeeping software implementations treat transaction ingestion as a data problem: fetch the chain data, categorise the transfer, post the journal entry. The Banca d'Italia directive inserts a compliance gate before that final step. Specifically, the software stack needs to be able to flag or hold a transaction where the counterparty address or the underlying beneficiary maps to a sanctions list entry before the transfer is treated as settled for accounting purposes.
That requires two things: first, a live or near-live connection between the transfer processing layer and a sanctions database (OFAC SDN, EU Consolidated List, UN list at minimum); second, a documented escalation procedure so that a flagged transaction does not auto-post to the ledger while the compliance review is pending. Firms that rely on digital asset accounting software that does not currently support this kind of pre-posting flag should raise the gap with their vendor or their implementation team as a matter of urgency.
Understanding how AML failures drive enforcement exposure for crypto firms is essential context here: the pattern of regulators moving from guidance to enforcement action on exactly these kinds of control gaps is well established. See our analysis of how AML failures drive enforcement exposure for crypto firms for a detailed breakdown of that dynamic.
Internal Controls Documentation
Banca d'Italia's use of the word "policies" in the directive is significant for CFOs and compliance officers preparing for supervisory review. Regulators distinguish between having a control and being able to demonstrate it. The documentation requirement implies that firms need a written sanctions screening policy, evidence that it is reviewed and updated when sanction lists change, records of every screening result, and a log of exceptions or escalations. That documentation does not generate itself: it requires a workflow that your crypto accounting software stack either supports natively or integrates with via API.
Practical Steps for Firms and Their Advisors
Immediate Priorities
Italian CASPs and their advisors should act on several fronts in parallel. First, map the current transfer processing workflow against the directive's two-part test: customer identification and transaction-level screening. Identify where, precisely, the sanctions check sits, and whether it runs at the time of transfer submission or only at onboarding. Second, confirm that the sanctions lists being screened are current. EU Consolidated List updates can be frequent during periods of heightened geopolitical activity, and a check against a stale list does not satisfy the obligation.
Third, assess whether the firm's crypto bookkeeping software can produce the audit trail the directive implies. If it cannot, document the gap and the interim manual control that covers it. Regulators do not expect perfection on day one of a new directive, but they do expect evidence of a credible response.
For Accounting Firms Advising CASP Clients
The directive creates a new due diligence question for accountants and auditors: does your client's crypto transfer processing include documented sanctions screening? If the answer is no, or the client is unsure, that gap needs to be addressed in the engagement file and raised with management. For firms conducting agreed-upon procedures or assurance engagements over AML controls, the Banca d'Italia standard now provides an explicit regulatory benchmark against which to test.
The parallel with AUSTRAC's approach is instructive. Australia's financial intelligence agency cancelled 45 crypto and remittance registrations after finding systemic control failures across its regulated population. The lesson from AUSTRAC's cancellation sweep as a model for registration-based AML enforcement is that supervisors will act when they find documented evidence of absent controls, and they will act at scale.
Cross-Border Considerations for EU Firms
While the directive comes from Banca d'Italia and applies directly to Italian CASPs, firms operating across the EU under MiCA passporting rights should treat it as a strong signal of supervisory intent at the bloc level. The EU Consolidated List is the same list across every member state. A firm that builds adequate screening in Italy will have the architecture it needs to satisfy equivalent expectations when other national competent authorities issue their own guidance, or when AMLR requirements crystallise.
Frequently Asked Questions
Does this directive apply to CASPs passporting into Italy from another EU member state?
The directive is issued by Banca d'Italia as the Italian competent authority. CASPs providing services into Italy under MiCA passport rights should review the precise jurisdictional scope of the instruction with legal counsel, but the underlying EU sanctions obligations apply to all entities making funds available to sanctioned persons within the EU, regardless of where the CASP is licensed.
What sanctions lists must be screened at minimum?
The directive references EU financial sanctions, meaning the EU Consolidated List of persons, groups, and entities subject to EU financial sanctions is the primary reference. CASPs with any exposure to US-dollar-denominated assets or US-connected counterparties should also screen against the OFAC Specially Designated Nationals list. UN Security Council lists underpin both.
How does sanctions screening interact with GDPR when processing personal data for screening purposes?
Processing personal data to comply with a legal obligation is a recognised lawful basis under GDPR Article 6(1)(c). CASPs should document this basis in their Record of Processing Activities and ensure data retention periods for screening records are proportionate and consistent with AML record-keeping requirements, typically five years under EU AML rules.
Does a flagged transaction need to be suspended before it is posted to the ledger?
Yes, in practice. Posting a transfer as settled in your accounting records before a compliance hold is resolved risks recognising value from a transaction that may subsequently be frozen or reversed. The accounting treatment should follow the legal and compliance outcome: do not recognise settlement until the screening result is clear and any required regulatory notification has been made.
What evidence will Banca d'Italia expect to see during a supervisory review?
Based on standard EU supervisory practice, expect requests for: the written sanctions screening policy, evidence of list version management and update frequency, a sample of screening records for recent transfers, escalation logs for any flagged matches or near-matches, and training records for staff involved in the process. Firms without this documentation should prioritise building it now rather than waiting for an examination date.
Source: Cointelegraph Regulation
