Course Images

CASP AML Compliance, Governance and Financial Crime (FC) Risk Essentials

CASP AML Compliance, Governance and Financial Crime (FC) Risk Essentials

Dates

  • December 2026
      to   (2 sessions)
    Delivered Online
    €240+ VAT
    Book
    View Dates Hide Dates
    • to
      Delivered Online
    • to
      Delivered Online


Highlights

  • Live Online

  • 5 CPD Hours | 5 Hours


The EIMF Live Online Learning Experience

Participants will receive access to the recorded sessions of the course.

EIMF subject-matter experts deliver engaging and interactive courses across a broad spectrum of areas, that can be enjoyed in the comfort of your own chosen environment. Read more


Course Overview

This programme provides a practical and industry-focused overview of AML/CFT compliance, governance and financial crime risk management for Crypto-Asset Service Providers (CASPs) and related regulated entities.

It examines how regulatory expectations under MiCA, the EU AML framework, FATF standards, the Transfer of Funds Regulation and the Travel Rule translate into day-to-day compliance obligations. Participants will explore CASP business models, risk-based approaches, governance arrangements, CDD/KYB, sanctions, transaction monitoring, suspicious activity reporting and the use of RegTech solutions such as eKYC, blockchain analytics and Travel Rule tools.

Through practical examples, case studies and group exercises, participants will assess realistic CASP scenarios, identify red flags and control gaps, and consider proportionate escalation, reporting and remediation actions.


Training Objectives

By the end of the programme, participants will be able to:

  • Describe the main CASP business models, crypto-asset services, wallet arrangements and AML/CFT exposure points.

  • Identify the core obligations arising from MiCA, the EU AML framework, the Transfer of Funds Regulation, the Travel Rule and FATF standards.

  • Recognise ML/TF/PF, sanctions, fraud, operational and reputational risks linked to crypto-asset activity.

  • Explain the risk-based approach and its practical application to CASP business-wide and customer-level risk assessments.

  • Apply CDD, KYB, UBO verification, EDD and ongoing monitoring requirements to realistic CASP scenarios.

  • Analyse crypto-related red flags using onboarding information, fiat transaction data, wallet information and blockchain analytics outputs.

  • Choose appropriate escalation, mitigation, restriction and reporting actions for unusual or suspicious activity.

  • Identify how RegTech, blockchain analytics, screening, transaction monitoring and Travel Rule technology support effective CASP compliance.


Training Outline

Introduction and Learning Agenda

  • CASP operations, AML/CFT compliance and supervisory readiness

  • Why AML compliance is a board, management and control-function priority

  • Regulatory map: MiCA, EU AML framework, FATF standards, Transfer of Funds Regulation and Travel Rule

  • Interactive discussion on practical AML challenges faced by CASPs

CASP Business Models and Crypto-Asset Fundamentals

  • Crypto-assets, tokens, stablecoins, e-money tokens, asset-referenced tokens and relevant terminology

  • CASP services and operating models: custody, exchange, execution, reception and transmission of orders, trading platforms, advisory and portfolio services

  • Hosted and unhosted wallets, key management, on-chain and off-chain activity

  • Interaction between fiat flows, crypto flows, wallets, exchanges and counterparties

Regulatory Architecture for CASPs

  • MiCA authorisation, governance, organisation, prudential, conduct and safeguarding expectations

  • EU AML framework, CDD, EDD, PEPs, UBOs, record-keeping and reporting

  • FATF Recommendation 15 and guidance for virtual assets and VASPs/CASPs

  • Transfer of Funds Regulation and Travel Rule implementation considerations

  • Supervisory readiness, evidence packs, management information and remediation tracking

AML Governance and Compliance Operating Model

  • Senior management accountability, board oversight, three lines of defence and the role of the MLRO/AMLCO

  • AML/CFT policies, procedures, standards, controls and escalation paths

  • Business-wide risk assessment, risk appetite, client acceptance criteria and control ownership

  • Outsourcing, third-party providers and accountability for KYC, KYB, screening, blockchain analytics and Travel Rule arrangements

  • Compliance management information, KRIs, training, independent review and audit trail expectations

Risk-Based Approach and CASP Risk Assessment

  • Risk-based approach principles across CASP activities

  • Customer, product/service, crypto-asset type, geography, delivery channel, wallet, transaction and counterparty risk factors

  • Customer risk assessment, scoring methodology, calibration and dynamic risk triggers

  • Higher-risk indicators: high-risk jurisdictions, unhosted wallets, mixers/tumblers, bridges, rapid movement of funds and high-risk counterparties

  • Exercise: build a high-level CASP risk factor matrix and mitigation plan

CDD, KYB, Onboarding and Ongoing Monitoring

  • Customer identification and verification, eKYC standards, digital identity and fraud-prevention controls

  • Corporate onboarding, KYB, UBO verification, ownership/control structures and complex legal entities

  • Purpose and intended nature of the relationship, source of funds/source of wealth and expected activity profiles

  • Enhanced due diligence and ongoing monitoring, including periodic and trigger-based reviews

Transaction Monitoring, Blockchain Analytics and Travel Rule Implementation

  • Off-chain and on-chain monitoring, scenarios, thresholds, typologies and alert calibration

  • Blockchain analytics outputs: wallet attribution, illicit-service exposure, clustering, risk scoring and source/destination of funds analysis

  • Travel Rule implementation: data capture, transmission, counterparty CASP due diligence and exception handling

  • Case management, false positives, alert investigation, documentation and audit trail standards

  • Practical walkthrough: analysing an alert using customer profile, fiat activity and blockchain indicators

Sanctions, Red Flags and Suspicious Activity Reporting

  • Sanctions screening across customers, counterparties, wallets, jurisdictions, tokens and blockchain exposure

  • Crypto-related red flags: chain-hopping, mixers, tumblers, fraud/scam proceeds, ransomware, mule accounts, structuring and high-risk exchanges

  • Internal escalation, MLRO/AMLCO assessment, SAR/STR decision-making, tipping-off risks and record-keeping

  • Regulatory and law-enforcement interaction, freezing/restricting activity and preserving evidence

  • Mini case study: monitor, restrict, reject, exit or report

RegTech Enablement and Control Automation for CASPs

  • eKYC, KYB, biometric verification, fraud controls, sanctions/adverse media screening, blockchain analytics, transaction monitoring, Travel Rule and case management

  • Vendor selection, implementation governance, data quality, model/alert governance, auditability and outsourcing considerations

  • Responsible use of AI/ML, explainability, false positives, human oversight and management accountability

  • Dashboards and metrics for operational performance, control effectiveness, risk trends and board reporting

Practical Case Study and Group Exercise

  • Review of a CASP AML framework, onboarding file, transaction activity and blockchain analytics output

  • Identification of risk indicators, control gaps and escalation points

  • Prioritisation of remediation actions and preparation of a concise management update

  • Group discussion, facilitator feedback and practical lessons learned


Training Style

The programme combines short lectures, practical examples, case studies, group discussions and control-mapping exercises. Participants will work through realistic CASP onboarding, monitoring, blockchain analytics and escalation scenarios and take away practical implementation considerations for their workplace.


CPD Recognition

This programme may be approved for up to 5 CPD units in Financial Regulation & AML. Eligibility criteria and CPD Units are verified directly by your association, regulator or other bodies which you hold membership.

This training course may be approved as an external activity under the new ACAMS recertification category ”non-ACAMS credits” for up to 5 CPD units. Eligibility criteria and CPD Units are verified directly by the Association of Anti-Money Laundering Specialists (ACAMS). To read more about the non-ACAMS credits policies and eligibility criteria please click here.


Who Should Attend

The seminar is ideal for:

  • Board Members, Executive Directors and Non-Executive Directors

  • Chief Executive Officers, Chief Operating Officers and other Senior Managers

  • MLROs, AMLCOs, Compliance Officers and Deputy Compliance Officers

  • AML/CFT, Financial Crime, Sanctions and Transaction Monitoring Analysts

  • Risk Management, Internal Audit and Independent Control Function professionals

  • Legal, Regulatory, Governance and Licensing professionals

  • Client Onboarding, KYC/KYB, Operations and Customer Support teams

  • Product, Technology, Cybersecurity, Data and Digital Transformation professionals

  • RegTech, blockchain analytics and Travel Rule solution stakeholders

  • Consultants, lawyers and advisors supporting CASP authorisation, remediation or supervisory readiness projects


In-house Training

For groups within the same organisation, this course may be customised to meet any specific needs and delivered in-house.

Facilitators

  • Giorgos Konstantinou

    Giorgos Konstantinou

    Read moreShow less

    Giorgos has 15+ years of senior management experience in Fintech and Financial Services, specializing in sales and business development, regulatory risk advisory, financial crime, regulatory compliance, AML risk assessments and international & corporate banking. He is a recognized Subject Matter Expert (SME) in Regulatory Technology (RegTech), specializing in end-to-end AML solutions for process digitalization and automation. Throughout his career, he has worked with a wide range of regulated financial institutions globally, including in Europe and the Gulf region, and has collaborated with various regulatory authorities. He is the Founder and Managing Director of K.G.K. ReguTech Advisors Ltd (“ReguTech”), a boutique firm specializing in top-tier AML advisory and compliance services, compliance retainers, regulatory inspection preparation and response, and AML assessments. ReguTech brings comprehensive AML Regtech solutions for process automation to both regulated financial institutions (FIs) and regulatory authorities. Prior to this, Giorgos led the operations of Identomat as Regional Director, overseeing business development and operations for the markets under the responsibility of the Cyprus representative office. Previously, he serves as the Group AML Director for a regulated group of companies, where he spearheaded the implementation of the group's Compliance AML strategy to align with business objectives. Before that, as Senior Manager at Deloitte's Risk Advisory Department, he advised financial institutions across Cyprus, Southern Europe, and the Gulf (Saudi Arabia, UAE, Qatar), including regulatory authorities, credit institutions, insurance companies, and investment firms, focusing on AML compliance, risk assessments, and regulatory readiness. Earlier, he led PwC's Risk & Quality team and founded the Central Compliance Services team. He began his career at Barclays Bank, managing relationships with international corporate clients from the CIS, the CEE, the Middle East, and Asia.

Frequently Asked Questions

  • When will I receive my invoice?

    The invoice is issued on the day the course starts.

  • What payment methods are accepted?

    Payments can be made by bank transfer, cheque, or credit card.

  • When will my certificate be issued?

    Certificates are issued within 7–10 days after the course has been completed, provided that the invoice has been paid.

  • How can I access my certificate?

    Once your certificate has been issued, you will receive an automated email from Cademy notifying you that it is available.

    Click the Get Your Certificate button in the email to download your certificate.

    You can also access it from your Cademy account:

    1. Log in to your Cademy account from https://cademy.io
    2. Click on My Account from the top-right corner.
    3. From the drop-down menu select My Courses and Bookings.
    4. Choose the relevant course.
    5. Under Participants, click the three dots located next to your name. 
    6. Select Get Certificate.
  • Where can I access the course material?

    To access the course materials, such as presentations and recordings:

    1. Log in to your Cademy account from https://cademy.io
    2. Click on My Account from the top-right corner.
    3. From the drop-down menu select My Courses and Bookings.
    4. Choose the relevant course.
    5. Under Extra Details, you will find all the available course materials.