Banca d’Italia is reminding crypto firms in Italy of a rule that leaves very little room for “small enough to ignore” transactions: every crypto transfer must go through sanctions screening, regardless of its value.
In a communication issued on Sept. 7, the central bank told crypto-asset service providers (CASPs) not to build minimum transaction thresholds into their screening systems. A €1 transfer, in other words, should not get a compliance free pass simply because it is tiny.
The message is less about introducing a new rule than making sure existing rules are actually being followed. The requirements come from European Banking Authority guidelines that have applied in Italy since Dec. 30, 2025.
Banca d’Italia is closing the tiny-transfer loophole
The practical issue is straightforward. CASPs are expected to check information on both the sender and recipient before carrying out a crypto transfer, without using the transaction amount as a filter.
That does not mean a compliance officer needs to manually inspect every micropayment. Automated screening can compare customer and transaction data against applicable sanctions lists, with potential matches sent for further review.
But Banca d’Italia is specifically warning firms against configuring those systems with a floor below which screening does not happen.
That matters because transaction splitting can turn a compliance control into a sieve. If a provider only screens transfers above a certain amount, a larger transaction could theoretically be broken into smaller pieces designed to slip underneath that threshold.
The Italian central bank’s reminder follows the EU’s expanding use of restrictive measures and growing scrutiny over whether financial institutions can enforce sanctions consistently in ordinary, day-to-day transactions.
The rule predates the latest Banca d’Italia warning
The foundations were already in place. Banca d’Italia incorporated the EBA guidance through Note No. 52 on May 19, 2025, with the guidelines becoming applicable on Dec. 30 of that year.
Those requirements extend beyond crypto. They cover banks, investment firms, payment institutions, electronic-money institutions and authorized CASPs, requiring firms to maintain controls capable of identifying sanctioned individuals and entities.
That makes the Sept. 7 communication more of a regulatory nudge than a new legal development. Banca d’Italia is effectively asking Italian operators to check whether the systems they already have in place are configured correctly.
And MiCA does not change that obligation. Authorization under the EU’s Markets in Crypto-Assets Regulation covers licensing, governance and conduct requirements, but it does not replace separate obligations tied to EU sanctions.
For crypto firms, that distinction is becoming increasingly important as Europe finishes its transition to MiCA. More than 1,000 crypto companies in the European Economic Area were still without MiCA authorization after a major transition deadline, according to related reporting cited in the reference material.
Why instant crypto transfers do not get a pass
There is a notable wrinkle in the broader European rules around instant payments.
Certain payment service providers can use an alternative screening model for eligible instant credit transfers because checking every payment individually could interfere with the very speed those systems are designed to provide. Instead, they may screen their customer base at least daily and whenever new restrictive measures are introduced.
Banca d’Italia also allows that approach for some low-risk domestic transfers under the provider’s responsibility.
Crypto transfers handled by CASPs are different.
The central bank’s 2025 note explicitly excludes them from that exception. Even though blockchain transactions can settle extremely quickly, speed does not mean a CASP can simply adopt the same screening setup used for qualifying instant payments.
For crypto transfers, the expectation remains transaction-by-transaction screening under the relevant EBA provisions.
Crypto screening is about more than names
The operational headache does not end with downloading the latest sanctions list.
Providers also need to consider how frequently those lists are refreshed, how aliases and transliterated names are handled, how alerts are investigated and how decisions are documented for supervisory purposes.
Then there is the blockchain itself.
A transfer may involve an address associated with a sanctioned entity even when a conventional name-based check reveals nothing. That is why some operators combine customer screening with blockchain analytics to identify exposure involving sanctioned addresses, intermediaries or services.
Those systems can generate their own complications. Blockchain address attribution is not always static, and an alert may indicate indirect exposure rather than a direct link to a designated party. That means analytics can flag a transaction, but human judgment may still be needed to determine what the connection actually means.
Banca d’Italia did not announce a new compliance deadline in its Sept. 7 communication. Nor did it identify specific CASPs as being under investigation or announce penalties.
For Italian crypto firms, however, the message is hard to misread: existing controls are supposed to work on every transfer, not just the large or suspicious-looking ones.
The reminder also arrives as the EU broadens its efforts to counter sanctions evasion. Related EU measures have targeted 14 crypto platforms and 94 financial institutions, adding to the number of entities and counterparties that compliance systems may need to recognize.
For Banca d’Italia crypto transfers requirements, the immediate task is therefore less glamorous than launching another product or chasing another blockchain trend. Firms need to audit their screening settings, confirm sanctions-list coverage, test escalation procedures and make sure transaction size cannot quietly determine whether a transfer gets checked.
MiCA authorization may put a firm inside Europe’s regulated crypto framework. It does not, on its own, prove that the firm can detect sanctions exposure when money starts moving.
