CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

MiCA, Sanctions and DeFi AML: The 2023 Regulatory Outlook for Crypto Accounting

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING MiCA, Sanctions and DeFi AML: The 2023Regulatory Outlook for CryptoAccounting

Five regulatory forces are converging in 2023, and the combination is set to reshape how firms approach crypto bookkeeping software, AML screening, and on-chain record-keeping. MiCA is moving from a European rule into a de facto global template. Sanctions pressure is extending from exchanges into mining operations, mixers, and decentralised protocols. And the collapse of FTX has handed policymakers the political momentum they needed to accelerate licensing and custody requirements. For accounting firms, auditors, and CFOs managing digital asset positions, the window for a "wait and see" posture is closing fast.

MiCA, Sanctions and DeFi AML: The 2023 Regulatory Outlook for Crypto Accounting

MiCA as the Global Regulatory Blueprint

The Markets in Crypto-Assets Regulation is the most structurally significant piece of crypto legislation enacted anywhere in the world. Its importance in 2023 goes well beyond the EU's own borders.

Why other jurisdictions are watching MiCA closely

Regulators in third countries consistently study the most detailed, enacted frameworks available when designing their own rules. MiCA is, at this point, the only comprehensive statutory regime for crypto-asset service providers and issuers that has cleared a major legislative body. It covers authorisation requirements, prudential standards, market abuse prohibitions, and consumer protection obligations in a single instrument. That breadth makes it a natural reference point for any jurisdiction that wants to move beyond one-off guidance into binding legislation.

The post-FTX environment has accelerated that process. Policymakers who were previously content to observe are now under public and parliamentary pressure to act. MiCA gives them a ready-made structure to adapt, which means EU compliance standards are likely to migrate into other markets faster than many firms currently anticipate. Firms using crypto accounting software that only covers EU-specific reporting fields should be testing whether their systems can flex to accommodate MiCA-derived rules appearing in non-EU jurisdictions.

The FTX effect on custody and disclosure standards

The FTX collapse demonstrated, in the starkest possible way, what happens when client asset segregation is absent and internal record-keeping is unreliable. Regulators have taken note. The 2023 outlook points to heightened scrutiny of how crypto-asset service providers hold client funds, how they produce financial statements, and how frequently they reconcile on-chain balances against internal ledgers. For accounting teams, this translates into a practical requirement: audit trails must be granular enough to reconstruct any transaction at any point in time, and reconciliation cycles that were previously monthly may need to become daily or near-real-time.

Sanctions Pressure on Mining, Mixers and DeFi

Sanctions enforcement in the crypto space has been expanding steadily, but the focus is shifting. The emphasis is no longer limited to centralised exchanges acting as off-ramps. In 2023, regulators and enforcement agencies are turning attention to the infrastructure layer: mining pools, transaction obfuscation services, and decentralised protocols.

Mining pools and sanctions nexus risk

Mining pools aggregate hash rate from operators across multiple jurisdictions. Where some of that hash rate originates from sanctioned jurisdictions or from individuals on sanctions lists, the pool as a whole can become a vector for sanctions exposure. For CFOs overseeing mining operations or treasury teams holding mining rewards, the accounting implication is direct: the provenance of block rewards is not simply a compliance question, it is a financial reporting question. If a payment received is later determined to have a sanctions nexus, the asset may need to be frozen, and the revenue recognition entry reversed or restated.

Mixers and transaction obfuscation

Regulators have made clear that services designed to obscure the on-chain trail of funds sit at the highest end of the risk spectrum. For any firm that receives funds from a counterparty who has used a mixing service, the compliance burden falls on the recipient to identify the risk and escalate accordingly. Digital asset accounting software that cannot flag mixer-touched inputs at the point of transaction will leave firms exposed to regulatory findings after the fact.

DeFi protocols under the AML microscope

DeFi represents the sharpest edge of the 2023 regulatory debate. The core question regulators are asking is whether the absence of a central operator genuinely removes AML obligations, or whether developers, governance token holders, or front-end operators remain obligated entities. The answer varies by jurisdiction and is still evolving, but the direction of travel is toward greater, not lesser, accountability for DeFi participants.

Practically, this means protocols need the ability to screen wallets and transactions continuously, not just at onboarding. Screening only a protocol's native asset, or only transactions on a single chain, is insufficient. DeFi activity is inherently multi-asset and cross-chain. A wallet that appears clean when assessed against one network may carry risk flags on another. Firms advising DeFi clients, or holding governance tokens as treasury assets, should be asking whether their current crypto accounting software surfaces cross-chain risk data alongside the accounting entries it generates. For further context on how US legislators are approaching the accountability question for non-decentralised DeFi operators, see our coverage of how the revised CLARITY Act targets non-decentralised DeFi operators.

Accounting and Audit Implications Across Both Themes

The two dominant themes, MiCA adoption and sanctions/AML expansion, converge on a single operational pressure: record-keeping that satisfies both financial reporting and regulatory inquiry at the same time.

What MiCA-aligned record-keeping looks like in practice

MiCA imposes transaction reporting and record-keeping obligations on crypto-asset service providers that go significantly further than generic financial services requirements. Firms subject to MiCA, and increasingly those in jurisdictions modelling their own rules on it, need records that capture the asset type, the transaction timestamp at the blockchain level (not just the booking date), the wallet addresses involved, and the applicable valuation at the time of execution. Crypto bookkeeping software that records only fiat-equivalent amounts without preserving on-chain metadata will not satisfy these requirements.

Sanctions screening integrated with the accounting ledger

One of the more consequential operational shifts required in 2023 is the integration of sanctions screening outputs directly into accounting workflows. When a transaction is flagged by a screening tool, the accounting entry for that transaction cannot simply proceed through the normal posting cycle. It needs to be held, documented, and escalated before it is recognised in the ledger. Firms that operate their AML screening and their accounting systems as entirely separate processes will find that gap increasingly difficult to justify to auditors and regulators alike.

Real-time, API-driven screening, where wallet risk is assessed at the point of interaction rather than in a batch review after the fact, is becoming the operational baseline. For accounting teams, the implication is that their digital asset accounting software needs to be capable of receiving and acting on screening signals within the same workflow that processes the transaction, not in a separate system that is reconciled weekly.

Audit trail requirements for cross-chain activity

Auditors reviewing digital asset holdings in 2023 are increasingly asking for cross-chain evidence. A client that holds assets across Ethereum, a layer-2 network, and a separate layer-1 chain presents an audit challenge that a single-chain reporting tool cannot address. The audit trail must account for bridges, wrapped assets, and gas fee expenditure across all networks. Each of those has its own accounting treatment, and each creates a potential gap if the underlying software lacks multi-chain coverage. For an overview of how the industry is developing standards for this kind of on-chain risk assessment, see our article on what Elliptic's standard for agentic on-chain risk means for compliance teams.

What Firms Should Be Doing Now

The regulatory outlook for 2023 is not a prediction of future rules. Much of what is described above is already legally in force or operationally expected by regulators conducting supervisory visits. The gap between firms that have adapted their infrastructure and those that have not is widening.

A practical review checklist for accounting and compliance teams

Start with a gap assessment against MiCA's record-keeping requirements, even if your firm is not domiciled in the EU. Identify which asset types, chains, and transaction categories your current crypto accounting software covers, and map the gaps explicitly. Then review your sanctions screening process and ask whether flagged transactions are automatically held from the accounting ledger or whether that step is manual. Manual holds are audit findings waiting to happen.

For firms with DeFi exposure, whether as a protocol operator, a governance participant, or simply as a treasury investor in DeFi tokens, document your position on AML obligations now. Regulators are more likely to take a proportionate approach to firms that can demonstrate they considered the question and put controls in place than to firms that treated DeFi as a regulation-free zone.

Finally, consider the pace of international MiCA adoption when planning your compliance technology roadmap. If the EU framework is likely to appear in your other operating jurisdictions within 12 to 18 months, it makes more sense to build toward MiCA-compliant infrastructure now than to implement twice.

MiCA, Sanctions and DeFi AML: The 2023 Regulatory Outlook for Crypto Accounting

Frequently Asked Questions

Does MiCA apply to firms outside the EU?

MiCA directly applies to crypto-asset service providers and issuers that offer services to EU clients, regardless of where the firm is incorporated. Beyond that direct extraterritorial reach, MiCA is also influencing the design of new crypto legislation in other jurisdictions, so firms operating globally should monitor how MiCA-derived standards are appearing in local rules.

What does increased sanctions pressure on DeFi mean for an accounting team?

It means that transactions involving DeFi protocols can no longer be treated as inherently lower-risk than centralised exchange transactions. If your firm holds DeFi positions or processes client transactions involving DeFi protocols, you need a screening process that covers those interactions and that integrates with your accounting ledger so flagged transactions are not posted until cleared.

How should mixer-touched funds be treated in the accounts?

Where funds received have a demonstrable connection to a mixing service, the safest accounting treatment is to hold the entry unposted until compliance and legal have assessed the sanctions and AML risk. If the funds are subsequently frozen or returned, the accounting entry will need to reflect that outcome. Documenting the decision process is as important as the entry itself for audit purposes.

What does "real-time API-driven screening" mean for our current crypto bookkeeping software setup?

It means that rather than running AML checks in a batch process after transactions have already been posted, the screening tool assesses wallet risk at the moment of transaction and passes that result back to your accounting system before the entry is finalised. If your current setup does not support this integration, that is a gap worth addressing as a priority given current regulatory expectations.

Are mining rewards subject to sanctions screening?

Yes, potentially. If a mining pool includes participants from sanctioned jurisdictions, block rewards distributed by that pool may carry sanctions exposure. Firms receiving mining rewards should maintain documentation of the pool's jurisdiction screening practices and should ensure their digital asset accounting software records sufficient on-chain metadata to support a sanctions review if required.

Source: Elliptic

EUGLOBAL#defiGeneralProposedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Crypto in Conflict: Sanctions Risk, DeFi Fundraising, and What Firms Must Know
AML/KYC & Licensing
AI Governance in Compliance: The Accountability and Control Gap Regulators Are Already Watching
AML/KYC & Licensing
Five Crypto Financial Crime Typologies for FI Compliance Programs
AML/KYC & Licensing
Cross-Chain Bridge AML Risk: $540M Laundered Through RenBridge