Anti-Money Laundering (AML/CFT)

We assist financial intermediaries, crypto-asset service providers (CASPs), professionals, and businesses with their anti-money laundering obligations: customer due diligence, risk assessment, organisational safeguards, record-keeping, and suspicious transaction reporting. We provide support both in establishing the necessary safeguards and when inspections or sanctions arise.

What we do

  • Assessment and gap analysis — assessment of safeguards against Legislative Decree 231/2007 and the AML Package, with a scheduled remediation plan.
  • Procedures and organisational safeguards — risk-based customer due diligence, record-keeping, suspicious transaction reporting, and the AML function.
  • Travel rule for crypto-assets — compliance with Regulation (EU) 2023/1113 (TFR II) for exchanges, wallet providers, and CASPs.
  • Training — programmes for senior management, control functions, and operational staff.
  • AML software and tools — legal advisory for developers and providers of monitoring and reporting solutions.
  • Inspections, pre-litigation, and litigation — assistance during inspections by the UIF, Guardia di Finanza, and supervisory authorities, as well as in sanction proceedings.
  • National framework — Legislative Decree 231/2007. The current operational framework: obliged entities, customer due diligence, record-keeping, reporting, and the role of the UIF. For crypto operators, the OAM register is also relevant and must be considered in coordination with the new MiCAR framework.
  • AMLR — Regulation (EU) 2024/1624. The anti-money laundering “single rulebook”: uniform and directly applicable rules on customer due diligence, beneficial ownership, and monitoring. It applies from 2027.
  • 6AMLD — Directive (EU) 2024/1640. Governs national systems, beneficial ownership registers, risk assessments, and high-risk third countries. Transposition is due by 2027.
  • AMLA — Regulation (EU) 2024/1620. Establishes the European Anti-Money Laundering Authority, based in Frankfurt and operational since mid-2025, with direct supervision of the highest-risk entities and coordination of FIUs.
  • Crypto-assets — TFR II (Regulation (EU) 2023/1113). Extends the travel rule to crypto-asset transfers from December 2024, together with the EBA guidelines issued in 2024 and in coordination with MiCAR. See the Blockchain and Crypto-assets practice.
  • Criminal law aspects. Inadequate administrative safeguards may also result in criminal exposure — money laundering (Art. 648-bis of the Italian Criminal Code), use of illicit proceeds (Art. 648-ter), and self-laundering (Art. 648-ter.1) — including corporate liability under Legislative Decree 231/2001.

How we work

Anti-money laundering is not a formal compliance exercise: it is a system that must withstand regulatory scrutiny and, where necessary, litigation. We build it by looking at the rules, the business process, and the technology used to implement it, with training tailored to the target audience.

Would you like to be contacted?


Contact information