Italy's New Rule Mandates Crypto Banking Sanctions Screening
On September 23, 2026, the Bank of Italy quietly rewrote crypto banking compliance for any firm moving euros or digital assets in the EU. The central bank now requires both sides of every funds or crypto-asset transfer to be screened against EU and national sanctions lists. This goes beyond existing Travel Rule expectations and makes sanctions screening crypto transfers a per-transfer duty for global business crypto banking.
Table of Contents
- What does the Bank of Italy's new rule require?
- Who is affected by this sanctions screening mandate?
- Why it matters now
- The compliance cliff
- How can my business ensure our crypto banking platform is compliant?
- What are the risks of ignoring these new screening requirements?
- How does this compare to existing Travel Rule obligations?
- What to watch next
- Key takeaways
What does the Bank of Italy's new rule require?
On September 7, the Bank of Italy published a formal clarification addressed to payment service providers (PSPs) and crypto-asset service providers (CASPs). The document, reported by AML Intelligence on September 23, 2026, instructs firms to always verify the originator’s and beneficiary’s data for transfers of funds or crypto-assets against current EU and national sanctions lists. No materiality threshold applies. Providers must screen both parties per transfer.
The Bank of Italy crypto regulation allows two narrow exceptions. Instant payments and formally assessed low-risk domestic Italy-to-Italy fund transfers may be handled with daily customer screening. The exemptions do not cover cross-border payments or any crypto-asset transfer.
This closes a gap in the EU crypto Travel Rule update. The Transfer of Funds Regulation requires information collection and transmission but does not mandate per-transfer beneficiary sanctions screening. As Grant Thornton’s 2026 crypto compliance outlook notes, national regulators are layering sanctions obligations on top of AML directives because the Travel Rule left this ambiguity.
Who is affected by this sanctions screening mandate?
The mandate directly applies to PSPs and CASPs supervised by the Bank of Italy. In practice it reaches any business sending, receiving, or intermediating euro-denominated transfers or crypto transactions through Italian financial institutions. That includes global businesses using crypto banking platforms whose European rails pass through Italian banks, DAOs and Web3 payroll providers converting crypto to euros, stablecoin on/off-ramps, and any CASP serving EU residents.
For crypto asset providers sanctions exposure now shifts upstream. If any linked address or beneficiary name is flagged by an Italian bank’s screening, the transaction can be stopped even when the DAO or startup is not Italian. A DAO treasury payment in USDC converted to euros for a vendor can freeze mid-flight if a counterparty triggers an alert.
Why it matters now
Platforms facilitating euro payments or crypto-to-fiat conversions through Italian rails are legally exposed if they do not screen both ends of every transaction. Even platforms without an Italian presence are affected because SEPA-connected correspondent banks must comply. Rejections do not simply bounce back; funds can be held in suspense for days or weeks while compliance teams resolve the alert. Repeated hits can trigger de-risking reviews and account termination, cutting a business off from EU fiat rails.
The compliance cliff
Traditional banks have screened SWIFT messages against sanctions lists for decades. Crypto banking grew with inconsistent screening, often only at the fiat on-ramp. Institutional-grade custody platforms such as Fireblocks made real-time checks possible, but many crypto-native platforms still lag. The shift echoes post-9/11 tightening in traditional banking.
The FATF Travel Rule was transposed into EU law through the TFR and 5AMLD. Those rules required VASPs to share originator and beneficiary information, while sanctions screening sat separately under EU restrictive measures regulations. As the TRM Labs crypto compliance glossary notes, the gap between AML information sharing and sanctions screening has been a persistent challenge in cross-border crypto payments regulation.
The Bank of Italy’s move responds to rising crypto flows and sanctions evasion concerns. The fourth annual CBC Summit USA, held on September 17, 2026, covered this intersection of crypto banking compliance and sanctions.
How can my business ensure our crypto banking platform is compliant?

Ask your crypto banking provider three written questions before the next cross-border payment:
- Does your platform screen both originator and beneficiary against EU and UN sanctions lists for every transfer?
- Are your banking partners compliant with the Bank of Italy’s September 7, 2026 instruction?
- What happens when a sanctions match occurs? Will funds be held for manual review?
For DAO treasury compliance, add a pre-transaction screening layer before funds leave the multi-sig. Use a compliance API such as Sygnum’s crypto compliance and RegTech division to check wallet addresses and counterparty names against global sanctions databases. Whitelist recurring counterparties and re-screen them daily. Platforms that integrate Fireblocks custody compliance can embed crypto payment screening directly in the payment workflow.
A working checklist for global business crypto banking:
| Step | Action | Frequency |
|---|---|---|
| 1 | Screen counterparty wallet addresses via a recognized sanctions API. | Per payment; daily for whitelists |
| 2 | Confirm beneficiary legal name and country are not on EU/UN sanctions lists. | Per payment |
| 3 | Request confirmation that correspondent banks screen dual-party for Italy-linked transfers. | Quarterly |
| 4 | Document screening results with timestamp and tool used. | Per payment |
| 5 | Assign a named individual for sanctions sign-off before multi-sig execution. | Ongoing |
Platforms like OneSafe, which combine fiat and crypto rails and integrate Fireblocks, can streamline steps 1, 3, and 4 by embedding screening within the payment workflow.
What are the risks of ignoring these new screening requirements?
Ignoring the mandate can lead to frozen transfers, liquidity disruptions, and account termination. If an Italian bank blocks a payment because the beneficiary was not screened, funds can be held for days while compliance teams resolve the alert. Repeated incidents trigger de-risking reviews that often end with offboarding from the banking relationship, cutting the business off from EU fiat rails. A platform that knowingly fails to screen also risks regulatory enforcement, fines, and possible license revocation.
How does this compare to existing Travel Rule obligations?

The EU Travel Rule requires CASPs and PSPs to collect, verify, and transmit originator and beneficiary information. It does not mandate per-transfer beneficiary sanctions screening; that duty comes from separate EU sanctions regulations and has been applied unevenly. Under the Bank of Italy crypto regulation, dual-party sanctions screening is a per-transfer obligation, beyond the Travel Rule’s data-transmission requirements. Information sharing alone no longer suffices for any transaction touching Italian rails.
| Aspect | Bank of Italy instruction | EU Travel Rule (TFR) |
|---|---|---|
| Screening obligation | Both originator and beneficiary against EU/national sanctions lists, per transfer | Collect and transmit identifying data; no explicit per-transfer dual-party sanctions screen |
| Scope | PSPs and CASPs supervised by Bank of Italy | All EU CASPs and PSPs |
| Exemptions | Instant payments and assessed low-risk domestic transfers only | No equivalent sanctions screening exemption |
| Practical effect | Real-time dual-party screening for any transaction touching Italian rails | Information sharing; national implementation left to states |
What to watch next
Other EU member states may follow. France, Germany, and Spain are discussing tighter sanctions enforcement; once one major EBA member state formalizes a standard, pressure builds elsewhere. Monitor the Latham & Watkins US Crypto Policy Tracker for US/EU alignment or divergence.
Compliance-forward hubs such as Switzerland, Liechtenstein, and the UAE may gain an edge as SEPA-connected liquidity excludes lighter-screening offshore platforms. The Circle–Tazapay partnership, which expanded stablecoin payment corridors, points to regulated stablecoin infrastructure converging around strict compliance standards.
The instruction also pushes the sector toward a technical standard for real-time dual-party crypto payment screening. CBC Summit discussions highlight fragmented screening capabilities among CASPs; a common API standard could force smaller platforms to upgrade or consolidate within 12–18 months.
Key takeaways
- The Bank of Italy now requires all crypto-asset and payment service providers to screen both originator and beneficiary per transfer, with only narrow exemptions.
- This mandate affects any global business moving euros or crypto through Italian banking rails, including DAOs and remote startups.
- Platforms that fail dual-party crypto payment screening expose clients to frozen payments and account de-risking.
- Ask providers about screening practices and implement pre-transaction checks.
- The gap between Travel Rule data sharing and sanctions screening is closing; real-time dual-party screening standards are likely.





