By CryptoTotem Research. Data current as of September 29, 2026.
About this research. CryptoTotem.com is an information platform covering crypto projects and service providers. This research was prepared by CryptoTotem Research for SpazioCrypto, based on a defined corpus of public documentation. CryptoTotem declares no paid placements, affiliate commissions, or other commercial relationships with the vendors included in this study. The SpazioCrypto editorial team verified data and sources and added the section on the UK and EU regulatory context.
KYC and AML compliance tools for European CASPs can now be sourced from a single platform: identity verification, sanctions screening, blockchain analytics, and Travel Rule software all bundled together. But buying those tools leaves a harder question open. Can the compliance team reconstruct how a specific customer or a specific transfer was assessed, which external services contributed to that assessment, and why someone approved the result?
CryptoTotem Research examined a sample of 19 compliance vendors with a documented connection to the European Union, coding seven functions and five areas of public information. According to CryptoTotem Research, the most represented categories are transaction monitoring and blockchain analytics, each described or declared by 12 of the 19 vendors. The Travel Rule appears in seven profiles. Yet the original document corpus contained detailed evidence on audit-trail exports for only two vendors, and on data processing arrangements for just one.
These findings concern a defined set of documents. They do not measure market share, product effectiveness, or regulatory compliance. Their practical value is to show where a product description stops answering a buyer’s questions, and where a demo, a contract, or an operational test must begin.
For crypto-asset service providers operating under EU law, the distinction matters right now. The maximum transitional period under the MiCA regulation closed on July 1, 2026, and the next European anti-money laundering deadlines are approaching fast. Buyers should map the proposed configuration against current obligations and identify which changes will be needed before the next application dates.
The European Regulatory Timeline
MiCA, the EU Markets in Crypto-Assets regulation, applies generally from December 30, 2024. Rules on asset-referenced tokens and e-money tokens entered into force earlier. The maximum transitional period for CASPs ended on July 1, 2026, though member states could shorten it or opt out entirely (MiCA Article 149; Article 143). That the deadline is real is illustrated by the regulatory scrutiny European supervisors have opened into services Binance continues to offer EU customers without a MiCA licence.
MiCA authorisation and AML operations answer different questions. Authorisation concerns the right to provide specific crypto-asset services, with a dedicated pathway for certain already-supervised intermediaries under Article 60. Customer due diligence, monitoring, and reporting remain continuous processes. The presence of a software vendor in this study says nothing about whether that vendor is itself authorised to provide regulated crypto-asset services (MiCA Article 59).
The Transfer of Funds Regulation (TFR) introduces a separate set of information obligations for crypto-asset transfers, also applicable from December 30, 2024. Buyers must distinguish the exchange of originator and beneficiary data from blockchain risk analysis: the fact that a message is delivered does not demonstrate that the transfer’s risk has been assessed (Regulation (EU) 2023/1113, Articles 14-17 and 40). Outside Europe, the same logic is producing even more demanding requirements: in Brazil, for example, Binance will require the purpose and counterparty of every cross-border crypto transfer.
The EU Anti-Money Laundering Regulation (AMLR) applies generally from July 10, 2027, including to CASPs. The European Anti-Money Laundering Authority (AMLA) is the Union’s supervisory body, and its roadmap is separate from the AMLR application date. The first selection procedure for direct supervision is scheduled between July and December 2027, with direct supervision beginning in 2028. It will cover up to 40 financial institutions or groups across the entire sector, not 40 crypto firms or all CASPs (AMLR, Article 90; AMLA note on direct supervision).

Application dates and supervisory milestones are distinct events. Milestones listed by month or year are not precise start dates. Sources: CryptoTotem Research, ESMA, AMLA, Bank of Italy, Consob.
For buyers, the practical question is which configured controls work against today’s obligations, and who carries the work required for the next change. A roadmap entry and a production-tested process belong in separate columns of that evaluation.
What the Sample Measures
The research began with 25 candidates: seven from CryptoTotem’s initial list and 18 added during the document review phase. Nineteen satisfy the EU-connection criterion: one with a named European client case, 12 with an offering explicitly targeting Europe, and six with an indirect connection documented through a named integration. The client case is historical and does not demonstrate an active contract.
Six candidates were excluded because the documents reviewed did not demonstrate the required EU connection. Exclusion marks a research boundary, not a judgment on a vendor’s actual availability in Europe.
Each included brand was coded across seven functions: identity verification; business verification (KYB) and beneficial ownership; name and sanctions screening; transaction monitoring and case management; blockchain analytics; Travel Rule services; workflow orchestration. A vendor can appear in multiple categories. The denominator stays at 19, so percentages do not sum to 100.
The coding distinguishes between an own-brand product described operationally, an explicit partner implementation, a declaration with few supporting details, and an unknown. “Own-brand” does not mean owning every underlying database. No function was coded as confirmed absent: unresolved cases are marked as unknown.
This is a reasoned documentary sample, not a census. It contains no comparative product testing and no systematic search through every vendor’s full documentation library. The European perimeter covers the 27 EU member states: a headquarters outside the EU does not automatically exclude a company, and European rules are not automatically extended to every country in the European Economic Area.
Vendor Functions and Supporting Evidence
Transaction monitoring and blockchain analytics each appear in 12 of the 19 profiles, equivalent to 63.2% of the sample, according to CryptoTotem Research. Name and sanctions screening appears in ten, identity verification in eight, Travel Rule and orchestration in seven each, and business and beneficial-ownership verification in five.

Compliance functions documented across 19 KYC/AML providers with offerings aimed at European CASPs. Categories overlap and do not represent market share; “unknown” indicates data not found in public documentation, not a confirmed absence. Source: CryptoTotem Research, public documentation reviewed through September 29, 2026.
The chart separates operational descriptions from less detailed statements and incorporates four coding revisions that emerged from a second targeted review. Overall totals did not change.
The concentration of entries on monitoring and blockchain analytics reflects the composition of the selected sample, but does not prove that these categories dominate the entire European market. Similarly, five entries on KYB do not show that business verification is commercially scarce: an unknown cell may reflect incomplete research rather than an absent product.
Three profiles describe or claim all seven functions. That is an invitation to examine how components fit together, not evidence that three platforms can replace an entire compliance operating model. The same total can combine a detailed operational workflow, a partner integration, and a brief product statement.
This matters when comparing seemingly similar feature lists. Identity verification asks who a person is; KYB and beneficial ownership analysis examine a business and the people who own or control it. Name screening and blockchain address screening operate on different objects and different evidence, as illustrated by the Iran-sanctioned wallets that used USDT. Travel Rule messaging moves information between parties. A single green checkmark labeled “AML” erases all these distinctions before a purchase has genuinely begun.
What Vendor Partnerships Actually Cover
A named integration can be valuable evidence, but on its own it does not show which company manages the full workflow or signs the contract with the end client.
One example is the September 2026 announcement between Sardine and Notabene, describing the integration of Notabene's Travel Rule and transaction authorization functions into Sardine's platform. Direction matters: that announcement should not be transformed into a claim that Notabene independently supplies every identity or business verification component of the combined offering. In the matrix, those functions are coded as partner-implemented (joint offering described by Notabene).
Data dependencies deserve their own field. Sumsub's screening documentation describes a flow that uses third-party AML data, with ComplyAdvantage as the default provider: in the standard configuration, matches are processed with algorithms from both ComplyAdvantage and Sumsub, while other providers are available via bring-your-own-key integrations. The revised coding records the described product separately from these dependencies; otherwise a single label would conflate product ownership with upstream data ownership (Sumsub screening configuration).
The procurement implication is specific: ask which entity supplies each input data point, what happens when that data is unavailable, and how any change to it reaches the buyer's controls. A partner logo answers none of those questions, and the number of assets supported by a messaging product does not demonstrate the coverage of its blockchain risk data. The question of third-party dependencies is the same one European authorities raise regarding the use of non-European AI in EU finance.
How Better Documentation Changed Four Classifications
The second review found more detailed operational documentation for Sumsub, compared to the source initially linked, covering docless identity verification and business verification flows. Both moved from “statement with few details” to “documented own-brand product.” The screening cell was also updated, keeping the external data dependency explicit (identity verification flow; business verification flow).
The fourth revision concerns ComplyAdvantage's transaction processing API, which describes configurable screening and monitoring execution and transaction outcomes: sufficient for a documented orchestration code within that perimeter, not for orchestration extending across every onboarding or third-party system (transaction processing API).
These changes expose a limit of document research: findings depend on what was found and how carefully it was read. Changes are recorded rather than silently overwritten, and they remain a targeted improvement, not an independent review with a second coder or a technical audit of comparable depth across all 19 providers.
Category totals remain useful as a map of this corpus, but they should not become a ranking. Before using a single cell to select a vendor, buyers should request current documentation and test the specific flow they intend to use.
What Public Information Leaves Unanswered
The first analysis examined five fields against a defined grid: unknown, partial or generic, operationally detailed. Detailed information on coverage appears for 4 of the 19 providers, on named dependencies for three, on pricing unit for three, on evidence export for two, and on data handling for one.

Information found in public documentation from the same 19 providers on coverage, evidence export, third-party dependencies, data handling, and pricing unit. This measures public document transparency, not a vendor ranking.
The chart retains the original corpus: the subsequent targeted review of functions did not systematically update these five fields for every provider. Low numbers do not prove that other companies lack contracts, exports, or privacy protections. Some information may appear in documents outside the corpus, be available on request, or depend on negotiated configuration. The result is that the research team could not resolve these questions with the material coded at this stage.
Even detailed information has limits. A public per-verification price may exclude retries, manual review, volume minimums, and additional modules. A privacy page does not equal an analysis of the contracting entity, configuration, or data flow. A sample report shows how evidence is presented, but does not demonstrate that past decisions remain reconstructible after a configuration change.
Buyers can use these unknowns to structure their requests: a sample case export, the applicable service description, a dependency list, and the pricing for the proposed configuration, kept alongside the assumptions under which the demo was run.
What This Means for CASPs in Italy
Italy illustrates the practical gap between authorization and ongoing controls. Under Legislative Decree 129/2024, which aligned Italian law with MiCA, Italy designated Consob and the Bank of Italy as competent authorities for CASP authorization: authorization is granted by Consob, in coordination with the Bank of Italy for matters within its remit (Bank of Italy, CASP page). Before MiCA, virtual asset operators (VASPs) were registered in a register maintained by OAM, the Agents and Mediators Body.
The national transitional regime, extended by Decree-Law 95/2025, allowed VASPs registered with OAM as of December 27, 2024 to continue operating if they had filed an authorization application as a CASP, in Italy or another EU member state, by December 30, 2025, pending the grant or denial of authorization and no later than June 30, 2026 (joint Consob-Bank of Italy notice of July 2, 2025). At the close of that period, the joint statement of June 30, 2026 identified 9 authorized entities in Italy: 8 CASPs authorized by Consob in close coordination with the Bank of Italy, plus one notified banking intermediary. Those that had not obtained authorization in at least one EU country were required to cease operations, limiting activity to an orderly wind-down in compliance with anti-money-laundering obligations (joint statement of June 30, 2026). On the supervisory side, Consob remains active against unauthorized operators, as shown by the crypto sites blocked in recent years.
Anti-money laundering compliance runs on a parallel track. The Banca d'Italia FAQ on CASPs explains how a measure dated 23 July 2025 extended customer due diligence, organisational, and control requirements to the relevant CASPs. For an Italian firm, practical verification must therefore link product configuration to applicable national AML procedures as well as the European framework (Banca d'Italia CASP FAQ).
Article 73 of MiCA establishes that CASPs outsourcing functions remain fully responsible for all their obligations, and sets out the resources, information access, and written agreements required to supervise outsourced functions (MiCA Article 73). Buyers must be able to name their own decision-makers alongside their vendors. Who resolves a screening match? Who approves a policy change? Who confirms that expected transactions reached the monitoring layer and were processed under the correct rules? These responsibilities must survive both staff turnover and vendor changes.
Configuration errors can leave transactions only partially monitored, as illustrated by the settlement between the Central Bank of Ireland and Coinbase Europe. The Central Bank identified approximately 30 million transactions between 23 April 2021 and 29 April 2022, representing roughly 31% of Coinbase Europe's transactions during that period, that were not subject to the relevant monitoring rules due to configuration errors, per the Central Bank of Ireland settlement notice (paragraphs 14 and 18). The final penalty reached 21,464,734 euros, and 2,708 suspicious transaction reports were ultimately filed. The figure of approximately 176 billion euros describes the value of the affected transactions, not a finding that those funds were proceeds of crime. The case demonstrates how essential it is to validate monitoring configuration and coverage; it is not an assessment of any vendor included in this study (Central Bank of Ireland settlement notice, paragraphs 14 and 18).
What to Ask Before a Provider Demo
The questions below translate this research into a practical verification exercise. They are proposed buying tests, not a complete legal checklist. Anyone building an initial shortlist can use the CryptoTotem guide to KYC and AML providers to identify vendor categories, then apply these checks to the intended configuration. The guide is a separate navigation resource, not the dataset for this study.

A simple demonstration can reveal more than a lengthy feature walkthrough. Present the vendor with a hypothetical corporate client carrying an unresolved ownership discrepancy, then introduce a screening alert and a transfer with incomplete counterparty information. Ask the team to show where each process stops, who can resolve each issue, and what the final case file contains. These are illustrative test conditions, not results on any specific vendor.
Operational continuity belongs in the same conversation. The DORA regulation on digital operational resilience has applied since 17 January 2025, covering ICT risk including third-party dependencies for entities within its scope. Practical verification should include service interruption and recovery scenarios: a commercial resilience statement is not the outcome of a test (ESMA factsheet on DORA).
The most reliable step, ultimately, is a documented simulation of your own process. This research points to where sharper questions should be directed; the answers must come from the configuration, evidence, and accountability structures that will actually sustain operations across Europe.
Methodology and Transparency
The supporting materials contain the sample, cell-level sources, coding definitions, the four function revisions, and chart data. The public information chart uses the original corpus; function counts use revision 2. Vendor statements remain vendor statements: no comparative performance testing or independent legal review was conducted.
CryptoTotem is an information platform covering crypto projects and service providers. This research was prepared for SpazioCrypto. CryptoTotem states it has no paid placements, affiliate commissions, or other commercial relationships with the vendors included. The study does not recommend any vendor and does not certify compliance; the regulatory analysis is limited to the sources and scope indicated.
Appendix: Provider Function Matrix
The matrix records evidence found in the reviewed documents for all 19 providers included. It does not rank quality or performance: each cell reflects the public documentation found, not the vendor's actual capability.

Function coding, revision 2. Asterisks indicate the four targeted revisions; all other codes are from the original corpus. Source: CryptoTotem Research, data current as of 29 September 2026.
IDV = identity verification; KYB = business and beneficial owner verification; SCR = name and sanctions screening; TM = transaction monitoring and case management; BC = blockchain analytics; TR = Travel Rule; ORC = workflow orchestration. N = own-brand product described operationally; P = explicit implementation via partner or joint offering; C = claim with limited detail; U = unknown in the reviewed corpus. No function is coded as confirmed absent. N does not imply ownership of all upstream data. Notabene P cells refer to the joint offering with Sardine: contractual scope and availability should be confirmed independently.



