My bookmarksSign up free

Regulation (EU) 2023/1113 Section 3 — Obligations on intermediary crypto-asset service providers

Article 19–Article 22 · 4 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Retention of information on the originator and the beneficiary accompanying the transfer

Article 19

Intermediary crypto-asset service providers shall ensure that all the information received on the originator and the beneficiary that accompanies a transfer of crypto-assets is transmitted with the transfer and that records of such information are retained and made available on request to the competent authorities.

Detection of missing information on the originator or the beneficiary

Article 20

The intermediary crypto-asset service provider shall implement effective procedures, including, where appropriate, monitoring after or during the transfers, in order to detect whether the information on the originator or the beneficiary referred to in Article 14(1), points (a), (b) and (c), and Article 14(2), points (a), (b) and (c), has been submitted previously, simultaneously or concurrently with the transfer or batch file transfer of crypto-assets, including where the transfer is made to or from a self-hosted address.

Transfers of crypto-assets with missing information on the originator or the beneficiary

Article 21

1.   The intermediary crypto-asset service provider shall establish effective risk-based procedures, including procedures based on the risk-sensitive basis referred to in Article 13 of Directive (EU) 2015/849, for determining whether to execute, reject, return or suspend a transfer of crypto-assets lacking the required information on the originator and the beneficiary and for taking the appropriate follow up action. Where the intermediary crypto-asset service provider becomes aware, when receiving a transfer of crypto-assets, that the information referred to in Article 14(1), points (a), (b) and (c), and Article 14(2), points (a), (b) and (c), or Article 15(1), is missing or incomplete, that intermediary crypto-asset service provider shall, on a risk-sensitive basis and without undue delay: (a) reject the transfer or return the transferred crypto-assets; or (b) request the required information on the originator and the beneficiary before making the transmission of the transfer of crypto-assets. 2.   Where the crypto-asset service provider repeatedly fails to provide the required information on the originator or the beneficiary, the intermediary crypto-asset service provider shall: (a) take steps, which may initially include the issuing of warnings and setting of deadlines, before proceeding to a rejection, restriction or termination in accordance with point (b) if the required information is still not provided; or (b) directly reject any future transfers of crypto-assets to or from, or restrict or terminate its business relationship with, that crypto-asset service provider. The intermediary crypto-asset service provider shall report that failure, and the steps taken, to the competent authority responsible for monitoring compliance with anti-money laundering and counter-terrorist financing provisions.

Assessment and reporting

Article 22

The intermediary crypto-asset service provider shall take into account missing information on the originator or the beneficiary as a factor when assessing whether a transfer of crypto-assets, or any related transaction, is suspicious, and whether it is to be reported to the FIU in accordance with Directive (EU) 2015/849.

Back to Regulation (EU) 2023/1113 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next