What an AML/CTF Program Actually Contains for a Crypto Company
Running a crypto company in 2026 means complying with fully enforced Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) regulations. Whether you are applying for a license in Estonia, Lithuania, or Panama, a written AML/CTF program is a mandatory requirement. This article provides a practical checklist of what your program must contain, based on current Financial Action Task Force (FATF) standards and EU MiCA rules.
Your AML/CTF program is not just a document to file with the regulator. It is the operational backbone of your compliance framework. A well-structured program demonstrates to authorities that you understand your risks and have concrete measures to mitigate them. Consulting24 has helped over 500 crypto firms build compliant programs across multiple jurisdictions. Below we break down each essential component with detailed examples, tables, and actionable steps.
Overview: What Is an AML/CTF Program?
An AML/CTF program is a written set of policies, procedures, and controls that a crypto company implements to prevent, detect, and report money laundering and terrorist financing. It is a legal requirement under most licensing regimes, including the EU's Markets in Crypto-Assets Regulation (MiCA) which is fully in force in 2026. The program must be risk-based, meaning it reflects the specific threats your business faces. For example, a crypto exchange handling high volumes of privacy coins like Monero must have enhanced due diligence (EDD) procedures for such transactions.
Key elements include customer due diligence (CDD), transaction monitoring, record keeping, internal controls, and independent audit. The program must be approved by senior management and reviewed regularly. Failure to maintain an adequate program can result in fines, license revocation, or criminal liability for directors. In 2026, regulators are increasingly scrutinizing crypto firms, making a strong program non-negotiable.
Who Needs an AML/CTF Program?
Any entity that provides crypto-asset services must have an AML/CTF program. This includes:
- Crypto exchanges (centralized and decentralized)
- Custodial wallet providers
- Brokers and dealers in crypto-assets
- Payment service providers using crypto
- Issuers of stablecoins and other crypto-assets
- Any entity subject to registration or licensing under MiCA or equivalent national laws
Even if you operate in a jurisdiction with lighter regulation, such as Panama, having a strong AML/CTF program is essential for banking relationships and partner trust. Consulting24 advises clients in all regions to treat the program as a core business asset. For instance, a Panama-based crypto fund we assisted needed a detailed program to open a corporate bank account in Switzerland. Without it, the bank would not proceed.
License Type & Regulator
Under MiCA, crypto-asset service providers (CASPs) are licensed by the national competent authority of their home EU member state. The license covers activities such as custody, exchange, and transfer services. In Lithuania, the regulator is the Bank of Lithuania; in Estonia, it is the Financial Supervisory Authority (FSA). For Panama, the regulator is the Superintendencia de Bancos de Panamá (SBP) for financial entities, while crypto-specific licensing remains under development as of 2026. However, Panama's flat fee of EUR 6,000 includes a comprehensive compliance package that meets international standards.
Consulting24 delivers direct licensing in Estonia, Lithuania, and Panama. For other jurisdictions, we advise and coordinate with local partners. Each regulator expects a tailored AML/CTF program that aligns with their specific guidelines and local laws. For example, the Bank of Lithuania requires a separate risk assessment document, while Estonia's FSA focuses on the operational implementation of controls.
Cost & Timeline for AML/CTF Program Development
The cost of developing an AML/CTF program varies by jurisdiction and complexity. Below is a typical breakdown for Panama, Estonia, and Lithuania. Exact pricing is confirmed in a consultation.
| Jurisdiction | Program Development Fee (EUR) | Typical Timeline | Key Inclusions |
|---|---|---|---|
| Panama | Included in EUR 6,000 flat fee | 2-4 weeks | Risk assessment, policies, procedures, templates, banking intro |
| Estonia | 1,500 - 3,000 | 3-6 weeks | MiCA-aligned program, employee training module, audit prep |
| Lithuania | 2,000 - 4,000 | 4-8 weeks | Full CDD/EDD procedures, transaction monitoring setup, independent review |
Timelines depend on the complexity of your business model and the readiness of your internal documentation. Consulting24 streamlines the process by providing templates and expert review. For example, a client running a simple P2P exchange completed their Panama program in 10 days, while a multi-service platform in Lithuania took 6 weeks due to additional EDD requirements.
Capital Requirement
Under MiCA, capital requirements for CASPs are tiered by service type: EUR 50,000 for simple services like custody, EUR 125,000 for exchange services, and EUR 150,000 for more complex activities. These figures are minimums and may be higher if the regulator deems it necessary based on risk. In Panama, there is no statutory minimum capital for crypto companies, but a prudent amount (typically EUR 10,000-50,000) is recommended to demonstrate substance. Consulting24 advises clients on appropriate capital levels during the licensing process. For instance, a Panama-based client with a custodial wallet service opted for EUR 20,000 in capital to satisfy bank due diligence.
Tax Treatment
Tax treatment of crypto activities varies: in Estonia, corporate income tax is 0% on retained profits (20% on distributions). Lithuania applies a standard 15% corporate tax, with potential exemptions for small companies. Panama taxes only locally sourced income, and crypto gains from foreign sources are generally tax-free. However, all jurisdictions require proper accounting and reporting. Consulting24 works with local tax advisors to ensure your AML/CTF program includes tax compliance procedures where relevant. For example, in Lithuania, your program must document how you handle VAT on crypto transactions, while in Panama, no such requirement exists.
Allowed Activities Under the AML/CTF Program
Your AML/CTF program must cover all regulated activities you perform. Typically, these include:
- Custody and administration of crypto-assets on behalf of clients
- Operation of a trading platform (exchange)
- Exchange of crypto-assets for fiat currency or other crypto-assets
- Transfer services (sending crypto on behalf of clients)
- Advising on crypto-asset investments
- Issuance and sale of crypto-assets (including ICOs/STOs)
Each activity carries distinct risks that must be addressed in your program. For example, a custody service needs strong wallet security and asset segregation procedures, while an exchange needs real-time transaction monitoring. A client of ours running a crypto ATM network had to include specific procedures for cash transactions and geographic risk assessment in their program.
Step-by-Step Process to Build Your AML/CTF Program
- Risk Assessment: Conduct a business-wide risk assessment identifying money laundering and terrorist financing risks specific to your products, customers, and geographic exposure. For instance, if you serve users from high-risk countries, your program must include enhanced due diligence.
- Policy Drafting: Write policies covering CDD, enhanced due diligence (EDD), transaction monitoring, suspicious activity reporting (SAR), record keeping, and internal controls. Use clear language and reference specific regulatory articles.
- Procedures: Develop step-by-step procedures for onboarding customers, monitoring transactions, and escalating suspicious cases. Include screenshots of your compliance software if possible.
- Controls: Implement technical controls such as automated screening against sanctions lists and transaction monitoring software. For example, integrate with Chainalysis or Elliptic for blockchain analytics.
- Training: Prepare a training program for all employees on AML/CTF obligations, including annual refreshers and role-specific modules.
- Independent Review: Arrange for an annual independent audit of your program by a qualified third party.
- Approval: Have the program approved by senior management and board, documented in meeting minutes.
Consulting24 can guide you through each step and provide templates that meet regulatory standards. We also offer a gap analysis service to identify missing elements in your existing program.
Banking & Payments Integration
A key practical challenge for crypto companies is obtaining a bank account. Banks require proof of a strong AML/CTF program before onboarding. Your program should include procedures for handling fiat transactions, including source of funds checks and ongoing monitoring. In Panama, the flat fee of EUR 6,000 includes assistance with bank introductions. In Lithuania and Estonia, Consulting24 helps clients prepare the compliance documentation that banks expect. Without a credible AML/CTF program, banking will be nearly impossible. For example, one client in Estonia had to revise their program three times before a local bank accepted it. We helped them add specific procedures for verifying source of wealth for high-net-worth clients.
Benefits of a Well-Structured AML/CTF Program
- Regulatory Compliance: Meet licensing requirements and avoid fines or sanctions. In 2026, EU regulators are conducting on-site inspections, and a documented program is your first line of defense.
- Banking Relationships: Easier to open and maintain corporate bank accounts. Banks often request a copy of your program during due diligence.
- Partner Trust: Attract institutional investors and business partners who require proof of compliance before engaging.
- Operational Efficiency: Clear procedures reduce errors and fraud. For instance, automated transaction monitoring can flag suspicious activity in real time, saving manual review time.
- Reputation: Demonstrate commitment to integrity and security, which is critical in the crypto space where trust is scarce.
In competitive markets like Estonia and Lithuania, a strong program can differentiate your company. One of our clients in Lithuania reported that their comprehensive program helped them secure a partnership with a major European payment processor.
Compliance & Trust: Ongoing Obligations
An AML/CTF program is not a one-time document. You must update it regularly to reflect new risks, regulatory changes, and business developments. Key ongoing obligations include:
- Annual independent audit of the program
- Ongoing employee training (at least annually)
- Periodic risk assessments (every 1-2 years)
- Timely filing of suspicious activity reports
- Record keeping for at least 5 years (8 years under some regimes)
This is general guidance, not legal advice. Consulting24 provides ongoing compliance support to ensure your program remains effective and up to date. For example, when MiCA introduced new requirements for stablecoin issuers in 2025, we helped our clients update their programs to include specific stablecoin risk assessments.
Common Mistakes in AML/CTF Programs
- Using generic templates: Regulators expect a program tailored to your specific business model and risks. A copy-paste approach will be rejected.
- Ignoring crypto-specific risks: Privacy coins, mixers, and DeFi interactions require special attention. For example, your program must address how you handle transactions involving Tornado Cash or similar protocols.
- Inadequate transaction monitoring: Manual monitoring is insufficient; automated tools are expected. Regulators look for evidence of real-time screening and threshold-based alerts.
- Lack of senior management involvement: The program must be approved and championed by the board. A program signed off by a junior compliance officer will not pass scrutiny.
- Poor record keeping: Incomplete or disorganized records can lead to compliance failures. Maintain a central repository for all CDD documents, transaction logs, and SAR filings.
Avoid these pitfalls by working with experts like Consulting24, who have reviewed hundreds of programs across various jurisdictions. We recently helped a client in Panama fix a program that had no EDD procedures for politically exposed persons (PEPs), a critical gap.
Alternatives: Comparing Panama with Other Jurisdictions
When choosing a jurisdiction for your crypto license, the AML/CTF program requirements vary. Panama offers a straightforward flat fee of EUR 6,000 and no minimum capital, making it attractive for startups. In contrast, Lithuania requires a more detailed program aligned with MiCA, with minimum capital of EUR 125,000 for exchanges. Estonia also follows MiCA but has a faster licensing process. For non-EU options, the UAE (Dubai) has its own regime under VARA, which demands a similarly strong program but with higher operational costs. Consulting24 helps you compare and choose the best fit for your business.
For a deeper comparison, see our guide on Panama vs Lithuania. We also have resources on Dubai and El Salvador for those exploring non-EU options.
How Consulting24 Can Help
Consulting24 has assisted over 500 crypto companies in obtaining licenses and building compliant AML/CTF programs. We deliver directly in Estonia, Lithuania, and Panama, and advise on other jurisdictions. Our services include:
- Risk assessment and program drafting
- Template provision tailored to your business
- Review and gap analysis of existing programs
- Ongoing compliance support and training
- Banking introductions
Contact us via WhatsApp or book a consultation to discuss your AML/CTF program needs. We will provide a free initial assessment of your current compliance status and a roadmap to meet regulatory requirements.
Frequently asked questions
What is the primary purpose of an AML/CTF program for a crypto company?
The primary purpose is to prevent, detect, and report money laundering and terrorist financing activities. It ensures the company complies with legal obligations under MiCA or local laws, protects against financial crime, and maintains trust with regulators, banks, and partners. A well-designed program also reduces operational risk by providing clear procedures for staff.
Is an AML/CTF program mandatory for all crypto businesses?
Yes, any entity providing crypto-asset services must have a written AML/CTF program. This includes exchanges, wallet providers, brokers, and payment processors. Even in jurisdictions with lighter regulation like Panama, a program is essential for banking and partner due diligence. Failure to have one can result in fines or license denial.
How often should an AML/CTF program be updated?
At least annually, or whenever there are significant changes to your business model, customer base, or regulatory environment. For example, if you add a new product like a stablecoin, you must update your program to address associated risks. Regulators expect programs to be living documents reviewed by senior management.
What happens if my AML/CTF program is inadequate?
Regulators can impose fines, suspend or revoke your license, and even pursue criminal charges against directors. In 2026, EU regulators are conducting more frequent inspections. Inadequate programs also make it difficult to open bank accounts or secure partnerships. Consulting24 can help you avoid these risks through a thorough review.
Can I use a template for my AML/CTF program?
Using a generic template is risky because regulators expect a program tailored to your specific risks and operations. A template can serve as a starting point, but you must customize it with details about your products, customer types, and geographic exposure. Consulting24 provides templates that are 70% complete and then customizes the remaining 30%.
What is the difference between CDD and EDD?
Customer Due Diligence (CDD) is the standard process of verifying customer identity and assessing risk. Enhanced Due Diligence (EDD) applies to higher-risk customers, such as PEPs or those from high-risk countries, and involves additional checks like source of wealth verification and ongoing monitoring. Your program must outline when EDD is triggered.
How does transaction monitoring work in a crypto AML program?
Transaction monitoring involves screening transactions in real time against sanctions lists, and flagging suspicious patterns like rapid trading, mixing services, or high-value transfers to unhosted wallets. Automated tools like Chainalysis or Elliptic are commonly used. Your program must specify thresholds and escalation procedures for alerts.
Do I need an independent audit of my AML/CTF program?
Yes, most regulators require an annual independent audit of your program. The audit assesses whether controls are effective and compliant. In Lithuania, the audit must be conducted by a certified auditor. Consulting24 can recommend qualified auditors and help you prepare for the audit process.
What record keeping requirements apply to AML/CTF programs?
You must keep all CDD records, transaction data, and SAR filings for at least 5 years (8 years under some regimes like Estonia). Records must be readily accessible to regulators upon request. Your program should specify how records are stored, backed up, and protected from unauthorized access.
Can Consulting24 help if I already have an AML/CTF program?
Yes, we offer gap analysis and review services. We compare your existing program against regulatory requirements and best practices, then provide a detailed report with recommendations. Many clients come to us after their program was rejected by a regulator or bank. Contact us for a free initial assessment.
Official sources
Related jurisdictions

Talk to a crypto-licensing expert
500+ licenses across Estonia, Lithuania, Panama and beyond. Tell us your model and we'll map the right route — honestly.
💬 Talk to an expertFree consultationGeneral guidance, not legal advice. Rules and fees evolve — we confirm current requirements for your case.