All That Praise Went to Poland – and for VASP?

Table of contents

    The Polish Ministry of Finance has issued Communication No. 87, addressing Virtual Asset Service Providers (VASPs) regarding the impending enforcement of Regulation (EU) 2023/1113, commonly known as the Transfer of Funds Regulation (TFR). Effective December 30, 2024, this regulation mandates that VASPs implement comprehensive measures to enhance transparency and security in cryptocurrency transactions.

    The TFR introduces stringent requirements for VASPs, including:

    • Verification of Beneficial Ownership: VASPs must verify the beneficial ownership or control of non-hosted addresses involved in cryptocurrency transfers.
    • Information Disclosure: Providers are obligated to furnish detailed information about the originator and beneficiary in each cryptocurrency transfer.

    These measures aim to bolster the European Union’s framework for combating money laundering and terrorist financing.

    The Ministry emphasizes the necessity for VASPs to adapt their procedures to comply with the TFR. This adaptation involves implementing appropriate solutions for the new Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) obligations. By December 30, 2024, all entities registered in the VASP register maintained by the Director of the Chamber of Fiscal Administration in Katowice are expected to comply with these requirements.

    Guidance from the European Banking Authority (EBA)

    To facilitate compliance, the Ministry refers VASPs to several key documents issued by the EBA:

    • Travel Rule Guidance Note (EBA/GL/2024/11): Released on July 4, 2024, this guidance outlines information requirements for fund transfers and certain cryptocurrency transfers under the TFR.
    • Risk Factors Guidelines (EBA/GL/2021/02): Initially published on July 31, 2021, and subsequently amended on January 16, 2024 (EBA/GL/2024/01), these guidelines assist VASPs in assessing customer risk and applying appropriate financial security measures.

    The Ministry advises VASPs to consult these documents during their preparatory activities to ensure full compliance with the TFR.

    The Ministry’s communication was developed in consultation with the Polish Financial Supervision Authority (KNF), underscoring a coordinated approach to implementing the TFR within Poland’s regulatory framework.

    The enforcement of the TFR represents a significant shift in the regulatory landscape for VASPs operating within the European Union. By mandating transparency and due diligence, the regulation aims to mitigate risks of money laundering and terrorist financing in crypto. Authorities encourage VASPs to align their operations with these new requirements to ensure compliance.

    As the December 30, 2024, deadline approaches, VASPs should prioritize the implementation of necessary technical and organizational measures. Engaging with the EBA’s guidelines and collaborating with national regulatory authorities will be crucial steps in navigating this regulatory transition.

    RegulationWeb 3.0
    Audited Up to Here: What a Smart Contract Audit Checks
    Smart contract exploits cost $905.4 million across 122 protocols during 2025. Cetus lost $223 million and Balancer roughly $128 million, and in both cases the broken code sat outside the scope of the audits covering those protocols. Automation is fast and partial, and the best three-tool combination in a 2025 evaluation caught 76.78% of annotated […]...
    5 days ago
    Regulation
    Possession Is Nine Tenths of the Ledger: Tokenized Asset Ownership
    Of the four tokenization structures SEC staff mapped in January 2026, one moves the security itself. The September exemptive order makes every venue verify that a tokenized share carries the same dividend, voting, and liquidation rights as the conventional one. Swiss law lets a qualifying ledger hold the security itself under four statutory conditions, while […]...
    6 days ago
    Regulation
    Outsourcing Crypto Compliance Is a Staffing Decision
    MiCA Article 73 and FCA SYSC 8.1.8R both require an outsourcing firm to keep in-house expertise for evaluating the vendor’s work. A European CASP carries MiCA and DORA at once, and Article 73 compliance settles nothing under DORA. Supervisors can order a firm to drop a designated critical ICT provider. Washington proposed replacing the 2023 […]...
    6 days ago