MiCA + AML without slowing down your business
"We turn requirements into real processes: onboarding, scoring, evidence and ongoing review. Practical compliance, not 'paperwork'."
We are crypto lawyers in Spain providing expert legal advice on crypto-assets and blockchain: MiCA compliance, AML/CFT, the Travel Rule, on-chain traceability and defense against information requests, so you can operate with legal certainty.
Working with crypto? Free legal assessment
Tell us your situation and we'll tell you what you need to implement.
Six pillars for working with crypto-assets with legal certainty, compliance and solid evidence.
We analyze each token individually (utility, security, NFT, stablecoin) and issue reports that support your decisions and your dealings with regulators and partners.
Policies, controls and designated officers: on-chain/off-chain KYC/EDD, sanctions, monitoring and evidence in line with AML/CFT rules.
Verifiable source of funds: on-chain analysis, supporting documentation and a consistent narrative for audits, banks or investors.
Data-flow design, risk-based criteria and evidence so you can deal with counterparties while reducing blocked transfers and operational friction.
A documentation and operational roadmap: governance, policies, contracts, controls and preparation for registration/licensing and the EU passport.
Robust responses to the Spanish Tax Agency, banks and supervisors: risk analysis, documentation, strategy and consistency with how you actually operate.
Exchanges, custodians, DeFi platforms, token issuers or investors: each profile needs different controls and evidence.
"We turn requirements into real processes: onboarding, scoring, evidence and ongoing review. Practical compliance, not 'paperwork'."
"We build verifiable dossiers: on-chain analysis, off-chain documentation and a consistent narrative for banks, investors or audits."
"We design flows and criteria to share information in a controlled way, minimizing friction and maximizing traceability."
"We review operational risks, roles, controls and documentation. Less exposure, greater ability to respond."
Crypto regulation is getting tougher: MiCA, the AMLR and the Travel Rule are already in force. Non-compliance blocks your operations, your access to banking and your reputation.
Significant penalties for non-compliance: heavy fines and the risk of an operational shutdown for VASPs/CASPs without adequate controls.
Tougher KYC/EDD expectations, plus on-chain analysis, source-of-funds checks and the Travel Rule to deal with counterparties.
Growing requirements for digital documentation and record-keeping of evidence (customers and beneficial owners).
Providing crypto services without CASP authorization: suspension of activity, fines and public disclosure of the breach.
Banks, investors and partners cut ties if there are no verifiable AML controls, traceability and governance.
Penalties for very serious AML/CFT infringements applicable to crypto-asset service providers.
We help you with regulation, AML compliance, the Travel Rule, MiCA, traceability and defense against information requests, so you operate with evidence and sound judgment.
Legal and technical advice covering the regulatory, contractual and compliance aspects of crypto-assets and blockchain technology.
It includes token classification, the legal structuring of Web3 projects, AML/CFT policies, contract review and support before supervisors. The goal: to operate with sound judgment, evidence and legal certainty.
Exchanges, custodians, wallet providers, token issuers, DeFi/CeFi platforms, crypto payment businesses, tokenized asset managers, NFT marketplaces and family offices/investors with crypto exposure.
If you intermediate digital assets or handle fiat↔crypto flows, compliance is no longer optional.
Regulatory and risk assessment, design of on-chain and off-chain KYC/EDD programs, the Travel Rule, counterparty due diligence, terms and conditions, smart contract review, licensing/registration and support in investigations and sanctions proceedings.
Always with a practical approach: processes, designated owners and evidence.
An independent (legal and technical) review that assesses how effective your compliance program is: KYC/EDD, monitoring, on-chain traceability, governance and internal policies.
It helps you detect gaps and serves as documentary evidence for audits or supervisors.
Risk in crypto does not behave the way it does in traditional finance: on-chain patterns, mixers/bridges, complex structures and smart contract vulnerabilities.
Training + evidence = fewer operational errors and a stronger defense when you are reviewed.
Penalties, blocked operations, disqualifications, reputational damage, loss of banking access and exposure to incidents due to missing AML controls and governance.
Prevention is cheaper than reacting late, especially as supervision intensifies.
The MiCA Regulation (Markets in Crypto-Assets) sets a single EU regulatory framework for crypto-asset service providers (CASPs). It requires authorization and compliance with governance, capital, custody and transparency requirements.
If you operate as an exchange, custodian or crypto service platform, you need to comply with MiCA to keep operating and to access the EU passport.
The Travel Rule requires crypto-asset service providers to share originator and beneficiary information on transfers. It is key to complying with AML rules and dealing with counterparties.
Without the Travel Rule in place, transfers can be blocked and your relationships with banks and other CASPs become harder.
Crypto compliance is not just "having a manual": it is a set of workable controls adapted to on-chain and off-chain activity, backed by verifiable evidence. The key is a risk-based approach applied to digital assets.
Reducing the risk of money laundering, illicit finance and fraud in crypto-asset transactions through tailored controls, on-chain traceability and evidence you can defend before supervisors.
KYC/EDD, on-chain analysis, the Travel Rule, governance, capital and custody requirements, internal policies and an escalation channel. All documented and auditable.
A crypto compliance program is proven by how it is executed: alert logs, on-chain analysis, justified decisions, minutes and periodic reviews are the first things examined.
If you need to put crypto compliance into practice, see our crypto legal services or, for an independent review, the external expert report.
An effective crypto compliance program is not a document: it is a set of repeatable decisions (on-chain KYC, Travel Rule, traceability, monitoring and escalations) with a full audit trail. Here is a visual overview of how it works in practice.
1) OnboardingIdentification and verification adapted to digital assets: traditional documentation + wallet analysis, on-chain history and risk scoring.
2) TraceabilityVerifiable dossiers that combine on-chain analysis with off-chain documentation for banking access, audits and investors.
3) OngoingData flows between counterparties, detection rules, mixers/bridges and alert management with a full audit trail.
4) GovernanceCASP license readiness, capital requirements, custody, internal governance and periodic audits of the compliance program.
Quick decisionStandard KYC + basic wallet verification + periodic review.
On-chain analysis + Travel Rule + enhanced controls + evidence.
EDD + verified source of funds + internal escalation + intensive monitoring.
Identity verification + wallet analysis, risk scoring and periodic updates.
KYC file, wallet report, risk profile and review date.
Analysis of fund flows, identification of mixers/bridges and a verifiable narrative.
On-chain report, off-chain documentation, source-of-funds dossier.
Sharing originator/beneficiary data with counterparties on a risk basis.
Transfer log, data shared, exceptions and justifications.
Authorization, governance, capital, custody, transparency and internal policies.
Authorization application file, policies, contracts, controls and governance minutes.
Periodic program reviews, gap detection and corrective actions.
Audit reports, remediation plan, KPIs and evidence of improvement.
Indicators to adjust your controls and justify enhanced due diligence.
If you are implementing crypto compliance, these terms come up in audits, with regulators and in day-to-day operations. Understanding them well helps you design workable controls.
EU regulation that sets the authorization, governance and compliance framework for crypto-asset service providers (CASPs).
A provider of crypto-asset services subject to authorization and supervision under MiCA: exchanges, custodians, trading platforms and advisers.
The obligation to share originator and beneficiary data on crypto-asset transfers between service providers.
Customer identification that combines traditional documentation with wallet analysis, on-chain history and risk scoring.
Tracking the origin and destination of crypto-assets with blockchain analytics tools to document provenance and detect risks.
Tools that mix transactions to make them harder to trace. Their use by customers is a red flag that calls for enhanced analysis.
Financial protocols built on smart contracts without centralized intermediaries. They raise specific regulatory challenges in AML and governance.
A digital asset representing economic or governance rights comparable to those of a financial instrument. Subject to MiFID II and securities market rules.
The ability to work with banks while having exposure to crypto-assets. It requires traceability, a documented source of funds and verifiable AML controls.
The 10 controls that exchanges, custodians, token issuers and crypto projects must implement under MiCA, the AMLR and the Travel Rule, with the evidence expected for each one.
No spam. Your email is only used to send you this checklist and, occasionally, relevant crypto regulatory updates (MiCA, AMLR, Travel Rule).
The checklist is downloading right now. If it doesn't start automatically, click here.
Once you've read it, do you need help implementing any of the steps? Message us directly:
The regulation of crypto-assets and blockchain in Spain and the European Union has undergone a structural shift with the entry into force of the MiCA Regulation (Markets in Crypto-Assets), which sets a harmonized framework for the authorization, governance and supervision of crypto-asset service providers (CASPs). MiCA compliance in Spain means obtaining a license and meeting capital, custody, transparency and internal policy requirements.
Crypto-asset service providers are obliged entities for anti-money laundering purposes under Law 10/2010 and the new EU Anti-Money Laundering Regulation (AMLR). This means KYC/EDD adapted to on-chain and off-chain activity, transaction monitoring, sanctions and PEP screening, and reporting suspicious transactions to SEPBLAC (Spain's Financial Intelligence Unit).
The Travel Rule (the Transfer of Funds Regulation, extended to crypto-assets) requires CASPs to share originator and beneficiary information on every transfer. In addition, on-chain traceability has become a de facto standard for proving the source of funds, gaining access to banking and passing audits.
The taxation of crypto-asset transactions (swaps, staking, DeFi, airdrops, mining) requires sound judgment, supporting documentation and consistency with your tax return. Form 721 (Modelo 721) requires you to report cryptocurrencies held abroad, and the Spanish Tax Agency (AEAT) is stepping up its checks on the origin, valuation and taxation of digital assets.
The Bank of Spain kept the register of virtual currency exchange and custodial wallet providers until the Spanish MiCA transitional period ended on 30 June 2026. The CNMV (Spanish Securities Market Commission) is the competent authority under MiCA for authorizing and supervising CASPs: since 1 July 2026, only CASPs authorized by the CNMV or passported from another EU Member State may operate in Spain. Both regulators are stepping up their inspection and enforcement activity.