Banca d’Italia is closing a loophole, not writing a new rule. In an official communication released Sept. 7, 2026 on procedures for complying with EU and national restrictive measures, the central bank told Italy’s licensed crypto-asset service providers, or CASPs, that every single crypto transfer needs sanctions screening before it goes through, no matter how small the amount involved.
The specific target: minimum transaction thresholds built into screening software. If a firm’s system only checks transfers above a certain euro value, anything below that line slides through unexamined, and Banca d’Italia wants that gap closed.
Why this isn’t new Italy crypto regulation, just a sharper reminder
Nothing about this creates a fresh legal obligation. The requirement traces back to guidance the European Banking Authority issued for restrictive-measures controls, which Banca d’Italia folded into Italian supervision via Note No. 52 back in May 2025, with enforceability kicking in across the country on December 30 that year.
Those guidelines already required banks, payment firms, e-money institutions, and licensed CASPs to run governance and screening controls capable of catching sanctioned individuals and entities.
What’s changed is emphasis, not law. Regulators across the EU have been paying closer attention lately to whether sanctions enforcement actually holds up in daily operations, not just on paper — and this reminder lands squarely in that push.
It’s also a distinct issue from MiCA licensing, worth separating clearly. Holding a MiCA authorization proves a firm meets Europe’s conduct and governance standards; it says nothing about whether that firm’s sanctions screening is actually configured correctly.
A licensed CASP can still fail this specific test. That distinction matters right now given how much of the sector is mid-transition, following MiCA’s rollout, only a small fraction of the roughly 1,200 firms that once operated under national crypto registrations across the EU had converted to full authorization, leaving a large share of the market still catching up on compliance basics generally.
What Banca d’Italia’s screening rules actually require
In practice, this doesn’t mean a compliance officer eyeballing every micro-transaction by hand. CASPs run automated systems that check sender and recipient details against sanctions lists before a transfer clears; a match kicks the transaction into manual review before it’s approved or blocked. What Banca d’Italia is insisting on is that this automated check can’t be skipped just because a transfer is tiny.
There’s a structuring risk behind that insistence, too. Someone trying to move sanctioned funds could split one large transfer into a string of small ones, each one designed to duck under a screening threshold. Removing the threshold removes that workaround.
Address-based risk adds another layer entirely. Screening a customer’s name doesn’t catch a wallet address tied to a sanctioned actor if that address itself isn’t on a watchlist tied to the person’s identity, which is why firms are expected to pair name-based checks with blockchain analytics.
Even then, an analytics flag needs real judgment before acting on it, since address ownership can shift and a flagged wallet might sit several hops away from any actual sanctioned party.
No shortcut through the instant-payment rules
Some EU payment rules let certain instant transfers skip transaction-by-transaction screening, checking a provider’s full customer base periodically instead — daily, plus whenever new sanctions take effect.
Crypto firms don’t get that option. Banca d’Italia’s 2025 note is explicit that this exception doesn’t extend to CASPs, regardless of how fast a blockchain settlement happens to be. A transaction settling in seconds still needs the same per-transfer check as one that takes days.
CASPs also carry a separate obligation under the EBA’s Travel Rule guidance, covering what happens when originator or beneficiary details are missing or incomplete on a transfer — another layer sitting on top of sanctions screening itself.
What Italian crypto firms need to do now
No new deadline came with this reminder, and Banca d’Italia didn’t name any firm or announce penalties. But the underlying obligation has been enforceable since December 2025, so there’s no grace period to point to.
The expectation is a paper trail proving the review happened: confirming no value threshold silently exempts transactions, checking how often sanctions-list data actually updates, and testing whether the system catches alias variations and transliterated names, not just exact matches.
The timing lines up with a broader EU sanctions push, the Council of the EU’s 21st sanctions package, adopted in July 2026, froze assets tied to 94 banks and major financial institutions and banned transactions with 14 crypto-related service platforms operating out of Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan, and Belarus, expanding the list of counterparties every CASP’s screening system needs to recognize.
For firms operating under Italy crypto regulation requirements, a MiCA license on the wall won’t be enough if the screening logic underneath it still has gaps.