EBA Report on Digital Currencies: What It Means for AML and Licensing
The European Banking Authority has published a 46-page opinion covering both centralised and decentralised digital currency systems, and the headline most outlets ran with, that regulated banks should avoid buying, holding, or selling crypto, tells only half the story. The report's short-term recommendations are, in several meaningful ways, good news for digital currency businesses and a clear signal to compliance and crypto accounting software teams that the compliance architecture of the sector is about to crystallise.
What the EBA Actually Evaluated
The EBA is the EU body charged with ensuring consistent and effective regulation of financial institutions across member states. Its digital currency opinion runs to 46 pages and covers a wide spectrum: from the operational mechanics of Bitcoin exchanges to the governance structures that could eventually underpin a bespoke regulatory regime.
Benefits the EBA acknowledged
The report opens by cataloguing both risks and benefits. On the positive side, the EBA acknowledges reduced transaction costs, shorter processing times, greater financial inclusion, and stronger privacy and security characteristics. It does, however, qualify each of these by suggesting they are not pressing problems in the EU context, a position that will raise eyebrows among firms operating cross-border payment infrastructure.
The seventy risks and why most are not new
Much of the media coverage focused on the EBA listing seventy distinct risks associated with digital currencies, ranging from exchange insolvency and customer fund misappropriation to regulators facing criticism for regulatory inaction. The list sounds alarming, but a closer reading shows that many of these risks already exist in conventional payment systems, investment products, and financial technologies. The EBA is not inventing novel dangers; it is mapping a known risk taxonomy onto a new asset class. That framing matters for firms building internal risk frameworks, because it means existing AML and operational risk infrastructure can be extended rather than built from scratch.
The Core Regulatory Stance: Bespoke Rules, Not a Quick Fix
The EBA is explicit that forcing digital currencies into existing legal wrappers, such as the Electronic Money Regulations or Payment Services Regulations, would be inappropriate. It warns against the square-peg-round-hole approach and argues that the fundamental differences between fiat and digital currencies require purpose-built regulation. That is intellectually honest, but it also means a comprehensive regime is years away from implementation.
Scheme governance authorities: the most contentious proposal
One proposal in the report stands out for its ambition and its tension with the nature of decentralised systems. The EBA floats the idea of "scheme governance authorities," non-governmental legal entities that would establish and govern the rules for individual digital currencies. The EBA itself concedes this may appear incompatible with the decentralised ethos of protocols like Bitcoin. The suggestion that such an authority could itself be decentralised while also constituting a legal person is not resolved in the document, and most practitioners will treat it as aspirational rather than actionable in the near term.
For accounting and legal teams, the practical takeaway is straightforward: do not build compliance workflows around this proposal yet. It is a long-range marker, not an imminent obligation.
Short-Term Recommendations That Matter Now
While the long-term regulatory architecture remains speculative, the EBA's immediate recommendations have direct operational consequences for firms active in the EU and UK digital asset space.
The bank firewall recommendation
The headline recommendation is that national supervisory authorities should discourage credit institutions, payment institutions, and e-money institutions from buying, holding, or selling digital currencies. This does not amount to a ban, and the EBA is careful to note that banks may still offer bank accounts to digital currency businesses. Investment firms, including hedge funds and asset managers, are explicitly excluded from this discouragement, a point that has received less attention than it deserves.
The practical effect of this recommendation for digital asset businesses is mixed. On one hand, it reduces the probability of incumbent banks entering the market as principal traders in the near term, preserving space for specialist operators. On the other, it does little to resolve the ongoing difficulty that crypto exchanges face when trying to open and maintain banking relationships. The EBA's explicit acknowledgement that banks can service crypto businesses without holding crypto themselves is a small but useful clarification that firms can use in conversations with correspondent banks.
AML and CTF coverage for exchanges
The recommendation that digital currency exchanges should fall within the scope of anti-money laundering and counter-terrorist financing requirements is the most operationally significant element of the report for compliance teams. This is not a theoretical aspiration; it is a direct signal to national supervisors about the policy direction they should pursue.
In the UK context, the EBA's report suggests that exchanges and related businesses could fall under HMRC's supervisory oversight for AML purposes, a point the report's authors acknowledged as imperfect but directionally correct. For EU operators, it foreshadows the kind of registration and authorisation requirements that have since been built into frameworks like MiCA. Understanding how MiCA is reshaping CASP registration across the EU is essential context for any firm planning its compliance roadmap.
Customer due diligence and client fund separation
The bespoke controls the EBA envisages for the longer term mirror those already in place for other payment systems: customer due diligence, transaction reporting, registration and authorisation, and the separation of client funds. For firms already operating under payment institution or e-money licences, these requirements will look familiar. For crypto-native businesses that have operated in a lighter-touch environment, they represent a meaningful uplift in operational and record-keeping requirements.
Firms that deploy robust crypto accounting software will be better placed to satisfy reporting requirements as they crystallise. The ability to produce clean, auditable records of customer transactions, wallet balances, and fund flows is not optional when AML supervisors begin asking for evidence of compliance.
Accounting and Compliance Implications for Firms
What B2B teams should do now
The EBA report provides a clear policy direction even if its long-term architecture is unresolved. Compliance officers, CFOs, and accounting firms serving digital asset clients should treat the AML/CTF recommendation as the operative signal and act accordingly.
First, map existing customer due diligence processes against the standards already applied to payment institutions. Identify gaps in onboarding documentation, beneficial ownership verification, and transaction monitoring coverage. Second, ensure that the firm's digital asset accounting software can produce transaction-level records in a format that would satisfy a regulatory request, including timestamps, counterparty identifiers, and wallet addresses. Third, engage with legal counsel on the implications of the bank firewall recommendation for any arrangements where a regulated credit institution currently provides custody or settlement services.
For firms advising crypto exchanges specifically, the AML registration pathway is the most urgent near-term action. In the UK, this means engaging with HMRC's cryptoasset business registration process under the Money Laundering Regulations. In the EU, it means tracking national transposition of MiCA's CASP authorisation requirements and ensuring clients are on track for compliance.
Record-keeping and the audit trail
Any AML or CTF regime carries with it a reporting infrastructure obligation. Firms need to be able to demonstrate, on demand, that they know who their customers are, what they transacted, and when. For businesses handling digital assets, this requires crypto bookkeeping software capable of ingesting data from multiple chains and exchanges, reconciling it to fiat equivalents at the time of transaction, and producing reports that map to the categories supervisors will care about.
The importance of continuous transaction monitoring and its role in crypto AML risk management has grown significantly as regulators move from principles-based guidance to enforceable rules. Point-in-time screening is no longer sufficient; the EBA's framing of ongoing supervisory oversight implies a continuous compliance posture.
The banking access problem: a partial resolution
One of the most persistent operational problems for crypto businesses has been the inability to open and maintain bank accounts. Banks have historically cited the absence of AML/CTF oversight as a key reason for declining or terminating these relationships. If the EBA's recommendation leads to formal AML registration for exchanges, it removes one of the most commonly used pretexts for denial.
This does not guarantee that banking relationships will open up, but it shifts the conversation. A registered, AML-supervised crypto exchange is a materially different counterparty from one operating without any supervisory oversight. Compliance teams should document their registration status and supervisory relationship clearly in any new banking application or relationship review.
The Competitive Landscape: Why the Breathing Space Matters
The EBA's short-term approach deliberately keeps large incumbent financial institutions at arm's length from the digital currency market as principals. The discouragement of banks from buying and holding crypto, combined with the exclusion of investment firms from that same restriction, creates an asymmetric environment where specialist operators and alternative investment vehicles have more room to manoeuvre than retail banks.
For accounting firms advising clients on market entry or expansion, this is a useful period in which to help clients build compliant infrastructure before the full regulatory framework is in place. Firms that establish clean AML processes, robust digital asset accounting software stacks, and documented compliance programmes now will be ahead of competitors who wait for the final rules before acting.
The EBA itself acknowledges that by the time comprehensive bespoke regulation is implemented, the digital currency landscape may look substantially different. That is not a reason to delay compliance investment; it is a reason to build flexible, adaptable systems rather than point solutions tied to a specific regulatory snapshot.
Frequently Asked Questions
Does the EBA report prohibit banks from working with crypto businesses?
No. The report recommends that national supervisors discourage credit institutions, payment institutions, and e-money institutions from buying, holding, or selling digital currencies as principals. It explicitly acknowledges that banks may still offer accounts and banking services to digital currency businesses. Investment firms are excluded from the discouragement entirely.
Which businesses are most affected by the AML and CTF recommendations?
Digital currency exchanges are the primary focus. The EBA recommends that they be brought within the scope of AML and CTF requirements, which would mean registration, customer due diligence obligations, transaction monitoring, and reporting to the relevant national supervisor. Businesses offering custody, payment, or wallet services are also likely to fall within scope as national frameworks develop.
How should accounting firms advising crypto clients respond to this report?
The most immediate action is to review whether clients that operate digital currency exchanges or related services are registered with the relevant AML supervisor, whether HMRC in the UK or the national competent authority in their EU member state. Beyond registration, firms should assess whether existing record-keeping and transaction reporting systems can satisfy supervisory requests. Crypto accounting software that produces auditable, transaction-level records is an essential part of that infrastructure.
What is a "scheme governance authority" and does it require action now?
A scheme governance authority is a concept floated in the EBA report: a non-governmental legal entity that would govern the rules for a specific digital currency. The EBA acknowledges it may be incompatible with the decentralised nature of protocols like Bitcoin and provides no implementation timeline. It does not require any action from businesses or accounting teams at this stage and should be treated as a long-range policy discussion rather than a near-term obligation.
Does this report have any relevance for UK firms post-Brexit?
Yes. While the EBA report is addressed to EU member states, its AML and CTF recommendations reflect international standards that the UK has largely aligned with. The report's suggestion that UK exchanges might fall under HMRC's AML supervisory oversight was directionally accurate: the Money Laundering Regulations were subsequently extended to cover cryptoasset businesses, and HMRC operates as the supervisor for those not otherwise regulated by the FCA. UK firms should treat the EBA's framework as consistent with, rather than separate from, their domestic obligations.
Source: Elliptic
