Aug 14
/
Evdokia Pitsillidou
Regulatory Updates on AML, MiCAR & CIF as a CASP in 2026
about the author
Evdokia, a partner at SALVUS Funds, is actively advising and working on all matters related to licensing, regulatory compliance, and internal audit for investment firms, funds, Electronic Money Institutions (EMI) & Crypto-Asset Services Providers (CASP).
- Member of the Global Institute of Internal Auditors (IIA)
- Member of the Cyprus Investment Funds Association (CIFA)
- Certified Actuarial Analyst (CAA)
- CySEC Advanced Certified Person
- CySEC certified Anti-Money Laundering Compliance Officer (AMLCO)
Anti-Money Laundering (AML) requirements and the Markets in Crypto-Assets Regulation (MiCAR) continue to reshape the regulatory environment for financial institutions, Crypto-Asset Service Providers (CASPs), and Cyprus Investment Firms (CIFs) seeking to expand their activities into crypto-assets.
As the regulatory framework develops, professionals operating within regulated financial services need to understand not only the AML requirements applicable to crypto-asset activities, but also the organisational, governance and authorisation requirements introduced under MiCAR. This becomes particularly important for existing CIFs considering how they may become authorised to operate as MiCAR CASPs.
In this blog post, Evdokia Pitsillidou, Global Chief Risk & Compliance Officer at SALVUS Funds, introduces the key themes covered in the online course “Regulatory Updates on AML, MiCAR & CIF as a CASP in 2026”, available through the Institute for Professional Excellence platform.
The Importance of Regulatory Updates on AML, MiCAR & CIF as a CASP
The European regulatory environment surrounding financial crime prevention and crypto-assets continues to evolve, making it increasingly important for regulated entities and their professionals to remain informed about developments affecting their activities.
The AML regulatory framework remains fundamental to the integrity, accountability, and trustworthiness of European financial markets. At the same time, MiCAR establishes a harmonised regulatory framework governing the authorisation, operation, organisation and governance of activities involving crypto-assets, including requirements applying to Crypto-Asset Service Providers and crypto-asset issuers.
For existing CIFs, the development of the MiCAR framework also introduces important considerations where a firm intends to expand its regulated activities into crypto-asset services. Understanding the eligibility criteria, applicable obligations and organisational requirements for becoming a MiCAR CASP is therefore essential for firms considering this transition.
Keeping pace with these developments enables professionals to better understand their regulatory responsibilities, identify and assess the risks associated with fiat, digital and crypto-assets, and establish appropriate measures for managing and mitigating those risks.
Strengthening Identity Verification and Ongoing Monitoring
CASPs are required to maintain a more comprehensive approach to customer identification and transaction-related data. Beyond standard identification details, such as names, addresses, and identification numbers, firms should capture relevant digital and transactional information, including wallet addresses, IP records, geolocation information, device identifiers, and transaction hashes.
This broader data framework strengthens ongoing customer and transaction monitoring. CASPs should have appropriate systems and controls in place to identify potentially unusual or suspicious activity, generate and review alerts, investigate identified risk indicators, and escalate concerns where necessary. Monitoring arrangements should remain responsive to changes in customer behaviour, atypical transaction activity, and exposure to crypto-assets or transaction types presenting a higher level of risk.
The supporting internal control framework should be clearly documented, regularly reviewed, and updated where necessary to reflect developments in the firm’s services, regulatory expectations, and risk profile. CASPs should also ensure that both their monitoring systems and responsible personnel are adequately equipped to identify reportable activity and prepare and submit Suspicious Transaction Reports (STRs) within the applicable regulatory timeframes.
What is the “Regulatory Updates on AML, MiCAR & CIF as a CASP” course and what does it include?
As the regulatory framework develops, professionals operating within regulated financial services need to understand not only the AML requirements applicable to crypto-asset activities, but also the organisational, governance and authorisation requirements introduced under MiCAR. This becomes particularly important for existing CIFs considering how they may become authorised to operate as MiCAR CASPs.
In this blog post, Evdokia Pitsillidou, Global Chief Risk & Compliance Officer at SALVUS Funds, introduces the key themes covered in the online course “Regulatory Updates on AML, MiCAR & CIF as a CASP in 2026”, available through the Institute for Professional Excellence platform.
The Importance of Regulatory Updates on AML, MiCAR & CIF as a CASP
The European regulatory environment surrounding financial crime prevention and crypto-assets continues to evolve, making it increasingly important for regulated entities and their professionals to remain informed about developments affecting their activities.
The AML regulatory framework remains fundamental to the integrity, accountability, and trustworthiness of European financial markets. At the same time, MiCAR establishes a harmonised regulatory framework governing the authorisation, operation, organisation and governance of activities involving crypto-assets, including requirements applying to Crypto-Asset Service Providers and crypto-asset issuers.
For existing CIFs, the development of the MiCAR framework also introduces important considerations where a firm intends to expand its regulated activities into crypto-asset services. Understanding the eligibility criteria, applicable obligations and organisational requirements for becoming a MiCAR CASP is therefore essential for firms considering this transition.
Keeping pace with these developments enables professionals to better understand their regulatory responsibilities, identify and assess the risks associated with fiat, digital and crypto-assets, and establish appropriate measures for managing and mitigating those risks.
Strengthening Identity Verification and Ongoing Monitoring
CASPs are required to maintain a more comprehensive approach to customer identification and transaction-related data. Beyond standard identification details, such as names, addresses, and identification numbers, firms should capture relevant digital and transactional information, including wallet addresses, IP records, geolocation information, device identifiers, and transaction hashes.
This broader data framework strengthens ongoing customer and transaction monitoring. CASPs should have appropriate systems and controls in place to identify potentially unusual or suspicious activity, generate and review alerts, investigate identified risk indicators, and escalate concerns where necessary. Monitoring arrangements should remain responsive to changes in customer behaviour, atypical transaction activity, and exposure to crypto-assets or transaction types presenting a higher level of risk.
The supporting internal control framework should be clearly documented, regularly reviewed, and updated where necessary to reflect developments in the firm’s services, regulatory expectations, and risk profile. CASPs should also ensure that both their monitoring systems and responsible personnel are adequately equipped to identify reportable activity and prepare and submit Suspicious Transaction Reports (STRs) within the applicable regulatory timeframes.
What is the “Regulatory Updates on AML, MiCAR & CIF as a CASP” course and what does it include?
Delivered by Evdokia Pitsillidou, Global Chief Risk & Compliance Officer and Partner at SALVUS Funds, the course serves as a comprehensive guide through the evolving regulatory landscape surrounding crypto-assets. It considers the essential obligations applicable to regulated CASPs alongside the broader and rigorous AML framework governing financial services.
The course is particularly suited to professionals holding key positions within Cyprus Investment Firms, CASPs and other entities regulated by the Cyprus Securities and Exchange Commission or the Central Bank of Cyprus. It is also relevant to AML Compliance Officers working within entities regulated by the Institute of Certified Public Accountants in Cyprus and the Cyprus Bar Association.
The syllabus of the course includes:
- Regulatory Framework: AML, MiCAR, DORA & MAR
- Supervisory Authorities
- Powers of CySEC
- Anti-Money Laundering (AML) Framework
- Transfer of Funds Regulation (TFR) - tracing crypto-asset transfers
- Markets in Crypto-Assets Regulation (MiCAR)
- Digital Operational Resilience Act (DORA)
- Market Abuse Regulation (MAR)
- Money Laundering & Terrorist Financing
- What is Money Laundering?
- Stages of Money Laundering
- Methods of Money Laundering
- What is Terrorist Financing?
- Differences between ML & TF
- Similarities between ML & TF
- ML & TF risks emanating from crypto-assets
- What is a Fiat Currency?
- What is a Digital Asset?
- What is a Crypto Asset?
- Fiat vs. Crypto
- What is a Crypto Asset Service Provider?
- Crypto-Asset Services by CIF
- Crypto-Asset Services vs Investment Services
- Notification Requirements
- Timelines
- Stages of Money Laundering
- Methods of Money Laundering
- What is Terrorist Financing?
- Differences between ML & TF
- Similarities between ML & TF
- ML & TF risks emanating from crypto-assets
- Fiat Currency, Digital and Crypto Assets, and a CASP
- What is a Fiat Currency?
- What is a Digital Asset?
- What is a Crypto Asset?
- Fiat vs. Crypto
- What is a Crypto Asset Service Provider?
- A CIF as dual license MiFID & MiCAR services
- Crypto-Asset Services by CIF
- Crypto-Asset Services vs Investment Services
- Notification Requirements
- Timelines
- Introduction to MiCA Regulation
- What is MiCA?
- Aim & Objectives
- Who is obliged under MiCA?
- Who is out of the scope of MiCA?
- Coming into force
- MiCA Implementation Timeline
- Main provisions
- Aim & Objectives
- Who is obliged under MiCA?
- Who is out of the scope of MiCA?
- Coming into force
- MiCA Implementation Timeline
- Main provisions
- MiCA Provisions for Crypto-Asset Service Providers
- Authorisation
- Cross-border provision of services
- CASP Obligations
- ESMA Register
- Cross-border provision of services
- CASP Obligations
- ESMA Register
- AML/CFT obligations of MiCA CASPs
- EBA ML/TF Risk Factors Guidelines
- #G1: Identifying ML/TF risk factors
- #G2: Assessing the ML/TF risk
- #G3: Customer Due Diligence, Enhanced and Simplified
- #G4: CASP ML/TF specific factors
The course is delivered through online video recordings and downloadable PDF study material, allowing professionals to learn whenever and wherever it suits them best. Participants can progress at their own pace, revisit topics as needed, and reinforce their knowledge through accessible and structured learning resources.
Upon successful completion, participants receive a certificate awarding 5 CPD hours, recognised by CySEC, the Central Bank of Cyprus, and other professional supervisory bodies. The course contributes towards the annual CPD requirements of CySEC Advanced, Basic and AML Certification holders, as well as professionals registered with ICPAC and the Cyprus Bar Association.
- #G1: Identifying ML/TF risk factors
- #G2: Assessing the ML/TF risk
- #G3: Customer Due Diligence, Enhanced and Simplified
- #G4: CASP ML/TF specific factors
- Regulatory Updates
- Circular C756 – Dual Licensing of CASPs under PSD2
- Circular C758 – ESMA’s CSA 2026
- Circular C762 – FATF Targeted Report on Stablecoins & Unhosted Wallets
- Circular C758 – ESMA’s CSA 2026
- Circular C762 – FATF Targeted Report on Stablecoins & Unhosted Wallets
The course is delivered through online video recordings and downloadable PDF study material, allowing professionals to learn whenever and wherever it suits them best. Participants can progress at their own pace, revisit topics as needed, and reinforce their knowledge through accessible and structured learning resources.
Upon successful completion, participants receive a certificate awarding 5 CPD hours, recognised by CySEC, the Central Bank of Cyprus, and other professional supervisory bodies. The course contributes towards the annual CPD requirements of CySEC Advanced, Basic and AML Certification holders, as well as professionals registered with ICPAC and the Cyprus Bar Association.
Get in touch
If you have any questions about Evdokia's course or any other questions related to your training requirements, please contact us; we would love to help.
If you have any questions about Evdokia's course or any other questions related to your training requirements, please contact us; we would love to help.
From all of us at IforPE, the Institute for Professional Excellence,
Ancora Imparo
Ancora Imparo
#1 for CySEC, CBC, ICPAC & CBA CPD education
The Institute for Professional Excellence (IforPE)
Copyright © 2019-2026
The Institute for Professional Excellence (IforPE)
Copyright © 2019-2026
navigate
The Institute for Professional Excellence is protected under a registered European trade mark. The figurative trade mark registration number is 018854840. This trade mark is protected under the European Union's legislation.
