Italy’s central bank tells crypto firms: screen every transfer, no matter how small
Banca d’Italia has told Italian crypto-asset service providers to verify that every transfer they process passes through sanctions screening, regardless of its value. The September 7 communication, reported through Borsa Italiana’s Radiocor service, does not create a new rule. Instead, it is a pointed supervisory reminder that requirements already in force since December 30, 2025 apply to every single transaction, and that firms should not configure their systems with minimum thresholds that let small transfers slip through unchecked.
The message from the central bank is unusually concrete for a supervisory letter. Operators were asked to confirm that their screening systems contain no minimum transaction threshold configured internally. In plain terms, a transfer cannot bypass sanctions controls merely because it is worth one euro or another small amount. That does not mean compliance employees must manually approve every micro-transfer. Firms may rely on automated systems that compare customer and transaction information against applicable sanctions lists, with potential matches routed for closer examination before a transfer is executed or rejected.
Why thresholds are the weak point
The central bank’s focus on minimum thresholds addresses a specific abuse pattern: structuring. A sanctioned person could otherwise divide a larger transfer into many smaller transactions designed to stay below an operator’s screening limit, keeping each piece invisible to automated checks. By insisting that screening apply at any value, Banca d’Italia closes that door for crypto-asset service providers, known as CASPs, operating under its supervision.
Firms must check both originator and beneficiary information before executing individual crypto-asset transfers for customers. The requirement applies transaction by transaction, which places crypto firms under stricter operational expectations than some other parts of the payments system.
The rules predate the September warning
The underlying obligations come from the European Banking Authority’s guidelines covering internal policies, procedures, and controls for implementing EU and national restrictive measures. Banca d’Italia formally incorporated that guidance through Note No. 52 on May 19, 2025, with the guidelines becoming applicable in Italy on December 30, 2025. The rules cover banks, investment firms, payment institutions, electronic-money institutions, and authorized crypto-asset service providers alike, requiring all of them to maintain governance arrangements capable of identifying designated people and entities.
The September communication therefore represents a calibration check rather than a legal shift. The central bank is asking firms to confirm that existing systems are properly configured, and the timing follows an expansion of European Union restrictive measures alongside growing regulatory attention on whether financial institutions can actually enforce sanctions in daily operations, not just on paper.
MiCA authorization does not exempt anyone
Banca d’Italia was careful to separate sanctions compliance from authorization under the Markets in Crypto-Assets Regulation. MiCA establishes licensing, governance, and conduct requirements, but receiving authorization does not remove obligations under EU restrictive-measures rules. That distinction matters as national regulators complete Europe’s transition to MiCA. More than 1,000 crypto firms in the European Economic Area remained without MiCA authorization following a major transition deadline, a reminder that licensing status and sanctions readiness are two separate conversations for every CASP operating in the bloc.
The instant-payment exception does not cover crypto
One of the more technical points in the communication concerns instant credit transfers. European rules allow certain payment service providers handling instant transfers to screen their entire customer base at least once daily, and whenever new restrictive measures take effect, rather than screening each transaction individually. The exception exists because transaction-by-transaction screening at instant settlement speeds can undermine the purpose of the product. Banca d’Italia also permits that approach for some low-risk domestic transfers under the provider’s responsibility.
But the central bank’s 2025 note expressly states that the exception does not cover crypto transfers processed by CASPs. Crypto providers must follow the EBA provisions governing individual crypto-asset transfers, and firms should not apply an instant-payment screening configuration to crypto services simply because blockchain transactions settle quickly. Providers must also follow the EBA’s separate Travel Rule guidance, which addresses missing or incomplete originator and beneficiary information accompanying fund and crypto transfers.
Immediate operational pressure
The practical effect of the reminder is that Italian CASPs are now expected to test their screening controls, verify that no minimum thresholds are configured, and document that originator and beneficiary checks happen before execution on every transfer. For firms that built their compliance stacks around threshold-based screening borrowed from traditional payments, that may require real re-engineering rather than a policy memo.
Italy is one of Europe’s largest crypto markets, and its regulator has been among the more active in spelling out supervisory expectations under MiCA. With the EU’s restrictive-measures framework expanding and enforcement scrutiny rising across the bloc, Banca d’Italia’s message to its CASPs is a template other national regulators may well copy: sanctions screening applies to every transfer, and small is not exempt.
Market snapshot at time of writing: Bitcoin trades near 78,400 USD, Ethereum around 2,474 USD, and Solana near 103 USD.
Disclaimer: This article is for informational purposes only and does not constitute financial advice.
No minimum threshold means every 5 euro transfer gets screened. Compliance cost per transaction just became the real story for Italian CASPs, not the rule itself.
The December 30, 2025 date matters. This is not new law, it is a warning shot that some firms configured thresholds anyway and Banca d’Italia noticed.
the pointed supervisory reminder phrasing reads like exam findings are already written. someone is about to get a very expensive letter.
no minimum threshold means every 5 euro tip gets screened. italian CASPs are about to have a fun quarter of compliance work
its worse than screening volume, its false positive queues. sanctions lists at 5 euro granularity will bury italian compliance teams in noise
the false positive queue angle is the real cost here. screening every 1 euro transfer against full sanctions lists means italian CASPs need actual compliance headcount now, not just nicer screening software
automation only helps if the list data is clean. half the fuzz matches come from garbled transliterations alone
this. a shop routing four figure transfer counts per day now needs a dedicated screening ops team. curious how many smaller italian casps just hand back the license instead
the noise is manageable if the matching engine is tuned well. the real cost is human review, every flagged 5 euro transfer needs eyes before release
its not even a new rule, the Dec 30 2025 requirements were already there. they just noticed firms were setting thresholds to skip small transfers
^ exactly. the reminder wording is the point, expect actual fines next if the configs dont change
expect the fines in the new year honestly. they asked firms to CONFIRM no threshold is configured, and that confirmation is now on file and auditable
on file is the key part. that confirmation is basically a signed confession if any threshold shows up in a later audit, smart supervising honestly
the Radiocor detail about firms confirming no threshold configured internally is the part that stings. basically asking CASPs to self-report in writing before an audit finds it
the written confirmation trick is genius supervision honestly. no fine today, just a paper trail that makes the next fine undefendable
exactly, the rules were live since dec 30. a letter like this only goes out because some audit found a configured floor somewhere
screening a 1 euro transfer costs more in compute than the transfer carries. europe keeps confusing compliance theater with actual safety
theater or not its still cheaper than a sanctions fine. firms will automate and eat the compute cost, the headcount is where the margins actually go
compute is cheap tho, its the reviewer headcount that kills. every false positive needs a human sign off before release and that scales linearly with volume
headcount plus every false positive freezing a customer transfer while review happens. the complaints queue is the cost nobody prices in
the letter explicitly allows automated screening with human review only on hits. still headcount, but its the exceptions queue not every micro transfer
letters like this never go out before an exam cycle finds something. some casp is getting made an example of by q2
structuring one big transfer into 1 euro bits was always the obvious loophole. the letter pointing at no minimum threshold reads like they caught someone doing exactly that during the 2024-2026 review
Structuring into tiny transfers was the obvious abuse from day one. Thresholds were comfortable for firms and a gift to anyone dodging sanctions screening.
confirm in writing that no threshold exists is such an italian supervisory move. polite today, merciless at the next audit