CASP COMPLIANCE
One Platform For Every New CASP Obligation
AMLR applies to every MiCA-authorised crypto-asset service provider from 10 July 2027. Shufti maps AML Screening, Know Your Business, Crypto Wallet Screening and Travel Rule messaging directly to the articles, on one platform.
PROVEN PERFORMANCE
Our impact, by the numbers
- 15 MinSanctions & PEP Refresh
- 4,000+Watchlists Screened
- 10 July 2027AMLR Application Date
Trusted by 2000+ Clients Worldwide
Compliance without compromise
Why CASP Platforms Choose Shufti
-
Stay Ahead of Regulation
AMLR applies to every MiCA-authorised CASP from 10 July 2027, with AMLA already supervising since 1 July 2025. The FATF Travel Rule, MiCA compliance and MiCA authorisation requirements run on overlapping timelines, and Shufti's rule sets update as each obligation takes effect.
-
Stop Fraud Before It Onboards
Illicit crypto-address activity reached at least $154 billion in 2025, up 162% year-on-year, with impersonation scams up 1,400%. Shufti's biometric identity verification binds every AML hit to a verified person, not a raw name string.
-
Onboard Without Losing Users
Shufti runs AML Screening, KYB, Crypto Wallet Screening and Travel Rule messaging through one API rather than four stitched-together vendors, refreshed every 15 minutes so risk-tier decisions do not wait on a daily batch cycle.
Secure Every Stage Of The CASP Customer Lifecycle
Sign Up
Bot Account Farming
Bots cycle through exchange sign-up forms at scale, each instance using a fresh email and IP, targeting sign-up bonuses.
How Shufti solves it
Device Fingerprinting catches shared emulator stacks and proxy infrastructure. Behavioural Biometrics stops the campaign at registration, since machine-speed form fills have no human equivalent.
Synthetic Identity Registration
A fraudster stitches together stolen PII and fabricated financial history to open a trading account, bypassing basic format checks.
How Shufti solves it
eIDV cross-references every submitted detail against government databases, so a synthetic identity with no verifiable footprint fails immediately.
Multi-Accounting via Device Reuse
The same person opens several accounts under different names or emails to farm referral bonuses or bypass per-account limits.
How Shufti solves it
Device Fingerprinting links the accounts to shared hardware, and 1:N biometric deduplication catches the same face behind each new identity.
Verify Your Identity
AI-Generated Fake IDs
A fraud service sold AI-generated fake IDs for roughly $15 each, capable of bulk-generating dozens at once, and reportedly bypassed KYC checks at major exchanges.
How Shufti solves it
Document forensics is trained to detect AI-synthesised security features that a human reviewer would miss.
Deepfake Liveness Spoofing
An injected or pre-recorded video attempts to fool a selfie-liveness check during onboarding.
How Shufti solves it
Passive liveness detection and biometric-anchored matching block presentation and injection attacks before the account is approved, not after.
Dark-Web Identity Kits
A genuine-looking ID document is paired with matching biometric images, sold specifically to bypass KYC on crypto platforms.
How Shufti solves it
Document forensics plus a live face-match defeat a submission that isn't backed by a real, physically present person.
Safety & Background Checks
Common-Name Sanctions Evasion
A customer shares a name with a sanctioned entity, risking either a false alarm or a real hit hiding behind common-name noise.
How Shufti solves it
Identity-anchored matching (face, OCR and date of birth) disambiguates the verified person from the raw name string.
Stale-List Exposure
A counterparty is designated on a sanctions list mid-session, after a once-daily batch update has already run.
How Shufti solves it
Shufti's 15-minute refresh cycle for sanctions, PEP and adverse-media data catches new designations far faster.
Adverse Media Blind Spot
A customer clears sanctions screening cleanly but is named in credible negative press over a past fraud or enforcement action.
How Shufti solves it
Adverse-media screening surfaces the reputational risk that a sanctions-only check would miss entirely.
Add Money
Sanctioned Wallet Deposit
A deposit originates from an OFAC-listed wallet address.
How Shufti solves it
Crypto Wallet Screening checks the address against government and regulatory sanctioned-address lists before the funds are credited.
Self-Hosted Wallet Ownership Gap
A deposit arrives from an unverified self-hosted wallet, with no visibility into who controls it.
How Shufti solves it
AMLR Article 40 requires risk-based identification of who owns or controls the self-hosted address behind the transfer.
Structured Micro-Deposits
Several small deposits are made just under a reporting threshold to avoid triggering a full check.
How Shufti solves it
AMLR's €1,000 crypto CDD trigger (Article 19(3)(a)) sits far below the general threshold specifically to close this gap.
Trade
Wash Trading Patterns
A user trades against their own linked accounts to fabricate volume.
How Shufti solves it
Transaction-pattern monitoring flags velocity and structuring anomalies inconsistent with genuine trading behaviour.
Rapid Cross-Pair Layering
Funds are rapidly converted crypto-to-crypto across multiple pairs to obscure their origin.
How Shufti solves it
Rule-based and ML-driven monitoring surfaces the layering pattern for review rather than letting it pass as routine trading.
Pump-and-Dump Coordination
Linked accounts coordinate to inflate a low-liquidity token's price before selling into it.
How Shufti solves it
Transaction-pattern monitoring correlates trading activity across accounts that would otherwise look unrelated.
Withdraw Money
Unresolvable Counterparty VASP
A withdrawal targets an exchange that isn't yet reachable on any Travel Rule protocol, known as the "sunrise problem."
How Shufti solves it
Shufti's policy path releases the transfer under policy, backfills the data from the customer, or escalates it as a formal claim.
Sanctioned Destination Address
A withdrawal is directed to a wallet on a government sanctions list.
How Shufti solves it
The destination address is screened and flagged before funds leave the platform, not after.
Mixer-Associated Routing
A withdrawal is routed toward a service designed to obscure the trail of funds.
How Shufti solves it
Wallet screening flags addresses associated with known mixing services before the transfer completes.
Upgrade Your Account
Undisclosed Source Of Funds
A customer requests a large trading-limit increase without a credible explanation for the funds.
How Shufti solves it
Enhanced due diligence triggers additional source-of-funds and source-of-wealth checks before the tier change is approved.
Custody Service Step-Up
A customer applies for custody or portfolio-management services, a separate MiCA-listed crypto-asset service.
How Shufti solves it
The platform re-runs risk classification for the new service scope rather than carrying over the original onboarding tier.
Third-Country Relationship Risk
A business customer wants to route activity through a counterparty based in a higher-risk jurisdiction.
How Shufti solves it
AMLR's tiered country-risk regime (Articles 29-31) applies enhanced diligence before the relationship is approved.
Update Your Details
Undisclosed Ownership Change
A business customer's shareholding structure changes without notice.
How Shufti solves it
Live registry re-checks catch the discrepancy and re-map beneficial owners against the 25%-or-more threshold set by AMLR Article 52.
Shell-Layer Ownership Obscuring
A new intermediate holding entity is inserted to dilute a beneficial owner's stake below the reporting threshold.
How Shufti solves it
Multi-tier chain calculation multiplies and sums ownership across the new structure to re-test whether the threshold is still met.
Nominee Director Arrangement
A named director is acting as a nominee for an undisclosed controller.
How Shufti solves it
AMLR's control-based beneficial-ownership track (Article 53) looks past formal titles to identify who actually directs the business.
Ongoing Checks
Post-Onboarding PEP Designation
A customer becomes politically exposed after onboarding is already complete.
How Shufti solves it
The 15-minute refresh cycle catches the new PEP status without waiting for the next scheduled periodic review.
Behavioural Drift
A previously dormant account suddenly transacts at high velocity.
How Shufti solves it
Continuous transaction-pattern monitoring flags the deviation from the account's established baseline for review.
Cross-Account Coordination
Several seemingly unrelated accounts begin transacting with each other in a pattern consistent with a single controller.
How Shufti solves it
Ongoing monitoring correlates the activity instead of reviewing each account in isolation.
Regular Check-In
Overdue Risk Refresh
A high-risk customer's file approaches the one-year review ceiling.
How Shufti solves it
Automated scheduling flags the account for re-verification before the AMLR Article 26(2) deadline lapses.
Register Discrepancy
An independently verified beneficial-ownership finding no longer matches the central register.
How Shufti solves it
The discrepancy is logged for reporting within the 14-calendar-day window set by AMLR Article 24(1).
Dormant-to-Active Reawakening
An account that passed its last review as low-risk suddenly resumes high-value activity.
How Shufti solves it
Event-driven review triggers under Article 26(3) force a fresh look regardless of the scheduled review date.
Close Your Account
Exit Before Escalation
A flagged customer attempts to close their account and withdraw remaining funds before an open case is resolved.
How Shufti solves it
The final screening pass runs before closure is permitted, not after.
Post-Closure Record Retention
A regulator requests the full decision history after an account has already been closed.
How Shufti solves it
The audit trail, covering originator data, screening results, risk scores and delivery status, stays retrievable for the required retention period.
Re-Onboarding Under a New Identity
Someone whose account was closed for cause tries to sign up again under a different name.
How Shufti solves it
1:N biometric deduplication catches the same face attempting to re-enter the platform after closure.
Built For Every Role That Owns The Compliance Decision
Combine products across identity, compliance, and fraud defence to build a verification stack that meets AMLR's requirements, without rebuilding the integration each time a new article takes effect.
Compliance Officer
Stop manually reconciling vendor data. Shufti automates the audit trail and provides a unified, article-specific evidence package for every customer, updated in real time. AMLR Articles 19, 24, 26, 37, 40 and 52 coverage in one place.
Head of Product
Onboard customers without adding friction. One flow covers identity, AML screening, KYB and wallet checks, so compliance never becomes a drop-off point at sign-up.
Head of Engineering
One REST API for the full CASP customer lifecycle. Deploy across document verification, biometric liveness, AML screening, KYB, wallet screening and Travel Rule messaging, through a single sandbox, without managing vendor sprawl.
Fraud Analyst
Cut manual review time with AI-assisted triage that surfaces the reason behind every flag before the case is opened. Cross-account signals, device links, and AML match context, all in one view.
Independent Validation
Validated by Leading Analysts and Certification Bodies

Ranked Exceptional in the Liminal Index 2026 for age estimation
View Report
Differentiated by Gartner on document diversity and country coverage
Read more
Certified at iBeta Level 3 PAD with 0% APCER
Read Blog
Broadest global reach in the 2025 KuppingerCole Extended IDV report
Download Report
Ranked Top 5 in the DHS RIVR 2025 for identity validation
Read Blog
Ranked Exceptional for age verification by Liminal Index 2026
View Report
Recognised as a Leader in G2 Summer 2026 reports
View ReviewsEverything you need to know in one place
Frequently Asked Questions
A crypto-asset service provider (CASP) is a legal person authorised under MiCA Article 59 to provide one or more of ten defined crypto-asset services, including custody, trading-platform operation, exchange, advice and portfolio management (MiCA Article 3(1)(15)-(16)).
AMLR (Regulation (EU) 2024/1624) applies from 10 July 2027, directly and identically across all EU member states, with no national transposition required.
FATF Recommendation 16 requires CASPs to collect and transmit originator and beneficiary information for crypto transfers above a jurisdiction-specific threshold. In the EU, this is implemented through the Transfer of Funds Regulation (2023/1113), with no minimum threshold for CASP-to-CASP transfers.
Yes. Article 40 requires CASPs to assess and mitigate money-laundering and terrorist-financing risk on transfers to or from self-hosted addresses, including risk-based identification of the wallet's owner or controller.
Article 52 sets a harmonised EU-wide threshold of 25% or more of ownership or control, replacing the "more than 25%" language and inconsistent national interpretations that preceded it.
Integration runs through a single API covering AML screening, KYB, wallet screening and Travel Rule messaging, with a sandbox environment for testing before go-live, so CASPs are not stitching together a separate integration for each requirement.
Evaluate Shufti Against Your Current CASP Stack
Most CASPs are stitching together four different tools for AML, KYB, wallet checks, and Travel Rule reporting. Shufti runs all four on one platform, built around the same verified identity.





