Recent rulings by Malta’s Arbiter for Financial Services signal a significant shift in how Crypto-Asset Service Providers (CASPs) must approach Travel Rule compliance. While historically viewed as a technical anti-money laundering (AML) requirement, the Travel Rule (Regulation (EU) 2023/1113) is increasingly being repurposed by the Arbiter as a core benchmark for a CASPs duty of care and fiduciary obligations toward retail consumers.
In recent cases involving Crypto.com, the Arbiter established that relying on automated“tick-box self-declarations for transfers exceeding €1,000 to self-hosted wallets is legally insufficient. Under the EBA Guidelines, firms are expected to demonstrate“adequate measures”to verify wallet ownership, which necessitates robust technical verification such as test transactions or cryptographic proofs, rather than mere reliance on customer input.
The Arbiter has clarified that while he cannot sanction firms for AML breaches (a power reserved for the FIAU), he is fully competent to adjudicate whether a failure to implement Travel Rule standards prejudices a consumer. This distinction creates a new layer of civil liability: I.e Even if a CASP like Crypto.com is not fined by a regulator, it may still be ordered to compensate clients if its failure to apply rigorous Travel Rule controls is causally linked to a loss.
These decisions demonstrate that contractual disclaimers and standard in-app warnings are insufficient shields when internal controls are structurally weak. As the industry evolves, the bar for“adequate measures”has been raised, requiring firms to integrate dynamic transaction monitoring with their Travel Rule protocols.
This jurisprudential shift underscores that compliance is no longer a box-ticking exercise; it is now a critical component of litigation risk management, where structural weaknesses in a CASP’s architecture can lead to substantial financial liability.
Authors
Share this article












