Banca d'Italia has directed all crypto-asset service providers (CASPs) operating in Italy to screen every single transfer against international sanctions lists, with no minimum transaction threshold. In a communication published on September 7, 2026, the central bank made clear that no amount is too small to escape compliance controls. Even a one-euro crypto transfer must pass through automated sanctions screening before it is executed. This marks a decisive shift from regulatory theory to day-to-day operational compliance.
The directive is technical in nature but carries immediate, concrete consequences for anyone operating in the Italian crypto market. After years focused first on building the regulatory architecture, then on obtaining authorizations under the EU's MiCA framework, operators now face a third phase: proving, in practice and every day, that their systems actually work.
What Banca d'Italia Actually Requires
The communication's core is a direct reference to European Banking Authority (EBA) guidelines governing controls on transfers of funds and crypto-assets. Those guidelines require CASPs to screen both the sender and the recipient of every transfer against the relevant sanctions lists, and to do so before the transfer is executed. The requirement applies both to ongoing customer relationships and to one-off transactions.
The specific point Banca d'Italia highlights, the one most operators will need to act on, is operational: no minimum amount threshold may be configured in the screening system that would automatically exclude smaller transactions from the check. A system set up to wave through transfers below, say, 100 euros without verifying them against sanctions lists is non-compliant. Every transfer, regardless of value, must be screened. The central bank also requires operators to verify that their systems are correctly configured and calibrated in line with the EBA's technical standards.
Does Every Single Euro Really Need Screening?
The question sounds provocative, but it's entirely legitimate. Does a two-euro crypto transfer genuinely need to run through a sanctions check? The answer is yes, and understanding exactly what that means matters.
It does not mean every micro-transaction gets manually reviewed by a compliance officer, or that small transfers get blocked or delayed. That would be operationally impossible at scale. What it means is more precise: no monetary threshold may exist that automatically removes a transaction from the scope of the required controls. Screening is an automated process that compares the sender and recipient against the relevant sanctioned-party lists. That comparison must be capable of running on any transaction, whatever its size.
The rationale is straightforward. A sanctioned individual could attempt to evade detection precisely by breaking larger movements into many small transfers, each designed to fall below a presumed safe threshold. Eliminating that threshold closes that gap. One technical exception is worth noting: under EU rules, instant credit transfers are permitted a slightly different approach. Given their extreme speed, operators may conduct preventive customer-level screening on at least a daily basis rather than transaction by transaction.

From Abstract Rules to Daily Operational Compliance
The deeper significance of this communication lies in the phase transition it signals for the whole sector. For years, the crypto regulatory debate in Europe was largely abstract, focused on grand principles and the architecture of future rules. Then came the authorization phase, with operators scrambling to obtain MiCA licenses and register with national competent authorities. Now comes the third phase, the most concrete one: daily operational compliance.
Banca d'Italia's implicit message is blunt. Holding a MiCA authorization is no longer sufficient on its own. Operators must demonstrate, in practice, every day, that their systems genuinely intercept sanctioned parties on every transfer. This confirms a principle worth stating plainly: MiCA compliance and sanctions compliance are two separate, parallel obligations. Obtaining one does not satisfy the other. This communication is the Italian operational chapter of that principle, and it confirms that regulatory compliance in the crypto sector now involves multiple overlapping layers that cannot be collapsed into a single authorization.

The Bigger Picture: Crypto Grows Up
Technical as it is, this communication tells a larger story about the integration of crypto-assets into the mainstream financial regulatory system. Crypto is no longer a parallel universe operating under looser rules. CASPs in Italy, and by extension across the EU under MiCA, are now subject to the same rigorous sanctions-control obligations that have long applied to banks and payment institutions, including the full complexity of international restrictive measures frameworks.
For operators, the lesson is concrete. The real challenge is no longer purely technological or commercial: it is compliance. Building and maintaining robust, correctly calibrated screening systems is now a fixed operational cost and an inescapable legal responsibility. Firms without that infrastructure are simply not credible regulated entities, whatever license they hold. For the ordinary user, this evolution is, in the end, a form of protection: knowing that the platforms handling your crypto transfers are subject to controls as stringent as those applied to your bank account adds a layer of legitimacy and security to the whole ecosystem. The path to a fully mature crypto sector runs through unglamorous but essential steps like this one, where digital assets stop being frontier territory and become a fully regulated component of the financial system. For a broader grounding in the rules shaping this landscape, the EU's MiCA framework and the EBA's sanctions guidelines remain the essential starting points.



