Ireland's New AML Strategy: What Enhanced Checks on Private Crypto Wallets Mean for Accounting Firms and CFOs
Ireland has published a national anti-money laundering strategy that puts private, self-custodied, and unhosted crypto wallets squarely in the crosshairs of enhanced due diligence. For accounting firms, auditors, and CFOs with Irish or broader EU-domiciled clients holding digital assets, this is a live supervisory signal, not a distant policy aspiration. The strategy commits obliged entities to apply heightened scrutiny whenever client transaction flows involve wallets that cannot be tied to a regulated, identifiable counterparty. Understanding precisely what that means operationally is now urgent work.
What the Irish AML Strategy Actually Says About Crypto
Ireland's new national AML strategy identifies the crypto sector as a priority risk area. The specific measure that will affect the widest range of professional services firms is the introduction of enhanced checks on private crypto wallets. In AML terminology, a "private" or "unhosted" wallet is one held outside a regulated custodian: a hardware device, a software wallet installed on a personal device, or any arrangement where the individual, not an exchange or custodian, controls the private keys.
The strategy signals that obliged entities, including accountants, auditors, tax advisers, and trust and company service providers, must treat transactions involving such wallets as higher risk by default. That means standard customer due diligence is unlikely to be sufficient when a client's crypto activity routes through an unhosted wallet. Enhanced due diligence, with additional source-of-funds documentation and transaction monitoring, becomes the expected baseline.
The Regulatory Architecture Behind the Move
Ireland's strategy does not emerge in isolation. It sits within the EU's broader AML reform agenda. The EU's sixth Anti-Money Laundering Directive and the directly applicable AML Regulation, which transfers core AML rule-making from national law to a single EU-level rulebook, are the legislative spine. The new European Anti-Money Laundering Authority (AMLA), which will take up its supervisory mandate in coming years, will have direct oversight of the highest-risk obliged entities across the bloc.
Ireland is, in effect, pre-positioning its supervised population for what AMLA will expect at EU level. Firms that treat this as a purely domestic Irish issue are misreading the regulatory direction of travel. The enhanced wallet-check requirement reflects standards that will propagate across all EU member states as the single AML rulebook comes into force.
This also connects to the Travel Rule obligations under the EU's Transfer of Funds Regulation, which already requires crypto-asset service providers (CASPs) to collect and transmit originator and beneficiary information on transfers. Where a transfer originates from or terminates at an unhosted wallet, the CASP must obtain additional information from the customer. Ireland's strategy reinforces that expectation at the national level and extends the risk signal to non-CASP obliged entities, including professional services firms, that may encounter the same wallet types through client advisory work.
Who Is Directly Affected
The phrase "obliged entity" carries a specific legal meaning under Irish AML legislation, which transposes the Fourth and Fifth AML Directives. The list includes credit institutions, financial institutions, and a broad category of designated non-financial businesses and professions (DNFBPs). Accountants, tax advisers, auditors, and company service providers all fall within this category when they provide certain services.
Accounting and Audit Firms
Any firm engaged in bookkeeping, tax advice, statutory audit, or company formation for clients who hold or transact in crypto assets is an obliged entity for those services. If a client's balance sheet includes crypto holdings routed through an unhosted wallet, the firm's AML risk assessment for that client must now reflect the elevated profile assigned to private wallets by the new strategy. This is not only about onboarding checks: ongoing monitoring obligations apply, and firms must be able to demonstrate their processes to the relevant supervisory body, which for accountants in Ireland is typically the relevant professional body acting under delegation from the Department of Finance.
CFOs and In-House Finance Teams
CFOs at Irish-registered entities that hold crypto on their balance sheet face a related but distinct set of considerations. If the entity uses or receives payments via unhosted wallets, the internal AML and compliance framework must be updated to classify those flows as higher risk. That has downstream effects on banking relationships, because Irish banks and payment institutions are themselves obliged entities and will be scrutinising their own clients' crypto-related activity. A CFO who cannot demonstrate a documented, risk-based approach to unhosted wallet exposure may find that banking counterparties ask uncomfortable questions.
Practical Compliance Implications
The immediate operational question is: what does "enhanced checks" require in practice? While the strategy document sets the policy direction, the detailed procedural requirements will be calibrated against the existing AML framework. Based on that framework, the following areas require immediate attention.
Client Risk Reassessment
Firms should conduct a review of their existing client base to identify any clients whose crypto activity involves unhosted or private wallets. Where such clients exist and were previously classified as standard risk, the risk rating should be reconsidered in light of the new strategy. This is not a theoretical exercise: supervisors reviewing AML files will now have a published national strategy document against which to benchmark a firm's judgments.
Source-of-Funds Documentation
Enhanced due diligence requires more than identity verification. Firms will need to obtain and retain satisfactory evidence of the origin of funds or assets held in unhosted wallets. This is challenging precisely because the defining characteristic of an unhosted wallet is the absence of a regulated intermediary that would ordinarily generate a paper trail. Clients may need to provide transaction histories from public blockchain records, supported by explanations of how the assets were acquired, whether through purchase, mining, staking, or receipt as payment.
Ongoing Transaction Monitoring
Enhanced due diligence is not a one-time gate at onboarding. It requires ongoing monitoring calibrated to the higher risk rating. For clients transacting regularly with unhosted wallets, this means periodic review of transaction patterns for anything inconsistent with the client's stated business or financial profile. Crypto accounting software that can pull wallet transaction data and flag anomalies against expected patterns becomes operationally relevant here, not as a substitute for professional judgment, but as a tool that supports the monitoring obligation in a defensible, auditable way.
Record-Keeping
Irish AML legislation requires obliged entities to retain records of CDD measures and supporting documents for a minimum period. Given that enhanced due diligence generates a richer documentary record than standard checks, firms need to ensure their systems can store and retrieve that information in a form that satisfies supervisory inspection. This is one of the areas where structured crypto compliance reporting infrastructure pays for itself: an ad hoc spreadsheet approach will not scale as the volume of enhanced-check clients grows.
The Accounting Treatment Dimension
There is a dimension to this story that sits at the intersection of AML compliance and financial reporting, and it is one that accounting firms advising crypto-holding clients cannot ignore. The enhanced risk classification of unhosted wallets has implications for how holdings in those wallets are treated in financial statements.
Under IFRS, crypto assets held by an entity are generally accounted for as intangible assets at cost less impairment, or at fair value through profit or loss if the entity is a broker-trader, unless they meet the definition of cash or a financial asset. The AML risk profile of the wallet type does not directly alter the accounting classification, but it does affect the risk disclosures a reporting entity should consider. If a CFO is required by the AML framework to classify unhosted wallet holdings as higher risk, that risk profile should be reflected in the going concern assessment and in the notes to the financial statements where material concentrations or operational risks are described.
Auditors, in turn, face a heightened responsibility when auditing entities with significant unhosted wallet balances. The enhanced risk profile now has regulatory backing, which means an auditor who treats such holdings as equivalent in risk to exchange-held assets, without additional procedures, is unlikely to satisfy the professional standards that govern the audit. This connects directly to how the profession has been reading broader EU-level AML signals: see our earlier analysis of how the A7 stablecoin flows exposed AML gaps in crypto accounting for context on what supervisors are looking for when they examine audit files touching high-risk crypto activity.
The EU Context Firms Must Not Overlook
Ireland's strategy lands at a moment when EU-level AML architecture is being substantially rebuilt. The single AML rulebook, which transfers binding AML rules from national directives into a directly applicable EU regulation, is being phased in. AMLA will begin exercising direct supervisory authority over the most significant cross-border obliged entities, and national supervisors, including Irish ones, will be expected to align their supervisory practices with AMLA's methodology.
The practical consequence is that an Irish accounting firm or CFO that upgrades its AML processes to meet the new national strategy is also, in effect, building toward the standard that AMLA will apply. Conversely, a firm that treats the Irish strategy as a soft signal that can be addressed gradually is taking a risk that the next supervisory cycle catches them in an exposed position.
The EU's sanctions architecture adds a further layer. As covered in our breakdown of what the EU's 21st sanctions package crypto rules mean for your firm, the intersection of sanctions compliance and crypto AML is tightening across the bloc. Unhosted wallets are a known vector for sanctions evasion precisely because they remove the regulated intermediary that would ordinarily screen against sanctions lists. Ireland's enhanced check requirement directly addresses that risk.
Steps Firms Should Take Now
Given the above, here is a structured set of immediate actions for accounting firms, auditors, and CFOs operating in the Irish and EU market.
Review and Update Your AML Risk Assessment
Your firm-wide AML risk assessment, required under Irish AML legislation, must be updated to reflect the elevated risk profile of unhosted crypto wallets as articulated in the new national strategy. This document is the first thing a supervisor will ask for, and it needs to show that your firm has read and acted on the strategy.
Upgrade Client-Level Due Diligence Files
For any existing client with material unhosted wallet activity, open a review of the due diligence file and document why the current risk rating remains appropriate, or upgrade it and apply enhanced measures accordingly. Do not wait for the next scheduled review cycle.
Invest in Structured Data Capture
The monitoring obligation for enhanced-risk clients is ongoing. Firms that rely on clients self-reporting their crypto activity, without any systematic data capture, will find it impossible to demonstrate compliance under scrutiny. Digital asset accounting software that ingests wallet transaction data, categorises it, and flags anomalies is not a luxury at this point; it is part of the infrastructure that makes the monitoring obligation achievable. The same structured data is also what populates a defensible audit trail if a supervisor ever asks to see your monitoring records.
Train Your Team
The enhanced check requirement is specific enough that front-line staff, whether client-facing accountants or in-house finance team members, need to understand what triggers the obligation and what they are expected to do. A training log showing that staff have been briefed on the new strategy is a simple but powerful piece of supervisory evidence.
Frequently Asked Questions
Does this strategy apply only to CASPs, or does it cover accountants and auditors too?
The strategy applies to all obliged entities under Irish AML legislation, which includes designated non-financial businesses and professions such as accountants, auditors, and tax advisers when they are providing relevant services. CASPs have their own specific Travel Rule obligations, but the enhanced wallet check requirement extends beyond CASPs to any obliged entity whose clients interact with unhosted wallets.
What counts as a "private" or "unhosted" wallet for the purpose of enhanced checks?
An unhosted wallet is one where the individual or entity holds the private keys directly, without a regulated custodian or exchange acting as intermediary. Hardware wallets, software wallets installed on personal devices, and similar self-custody arrangements all fall into this category. Wallets held at a regulated, licensed exchange or custodian are hosted and do not automatically trigger the enhanced check requirement, though other risk factors may still apply.
What does enhanced due diligence actually require in practice?
Enhanced due diligence goes beyond standard identity verification. It typically requires obtaining satisfactory evidence of the source of the funds or assets, applying more intensive ongoing monitoring, seeking senior management approval for the relationship in some cases, and documenting the measures taken and the reasoning behind the risk assessment. The exact calibration depends on the overall risk profile of the client, but the starting point is that unhosted wallet activity is treated as higher risk by default.
How does this interact with the EU Travel Rule?
The EU Transfer of Funds Regulation already requires CASPs to collect additional information when a transfer involves an unhosted wallet. Ireland's national AML strategy reinforces that obligation and extends the risk signal to non-CASP obliged entities. The two frameworks operate in parallel: a CASP must comply with the Travel Rule, and any professional services firm acting for that CASP or its clients must also apply appropriate AML measures based on the risk profile the strategy now assigns to unhosted wallet activity.
Will crypto accounting software be sufficient to meet the monitoring obligation?
Digital asset accounting software and crypto bookkeeping software can significantly support the ongoing monitoring obligation by providing structured, auditable records of wallet transaction data. However, software is a tool, not a substitute for professional judgment. Firms still need qualified staff to interpret the data, make risk-based decisions, and document their reasoning. The software makes it feasible to monitor at scale; the professional judgment is what makes the monitoring defensible.
Source: Decrypt
