AMLRadar
AMLRadar
← Back to Blog
Compliance2 September 2026·5 min read

The EU Extended Its Russian Ownership Ban to Every MiCA CASP on August 25 — Has Anyone Actually Checked?

Since August 25, 2026, EU sanctions bar Russian and Belarusian nationals from owning, controlling, or sitting on the board of any MiCA-authorised CASP — not just custody providers, as before. Here is what changed, who it hits hardest, and why your wallet screener won't catch it.


A week ago, on August 25, a provision from the EU's 21st Russia sanctions package quietly took effect. It didn't add a single new name to a screening list. It didn't ban a single transaction. It changed who is allowed to own and run a MiCA-authorised crypto-asset service provider — and for a lot of firms, that's a harder thing to check than a wallet address.

We wrote about the same sanctions package three weeks ago, covering the 14 newly designated platforms and the new third-country ban mechanism. This is the part of that package we didn't cover then, because it hadn't taken effect yet. It has now, and it deserves its own look — it's a genuinely different kind of obligation.

What changed on August 25

Since an earlier sanctions package, EU law has barred Russian and Belarusian nationals and residents from owning, controlling, or holding a seat on the governing body of an EU-incorporated firm providing crypto wallet, account, or custody services. That restriction was narrow by design — it covered a specific slice of the crypto industry.

Council Regulation (EU) 2026/1848, adopted on July 23 as part of the 21st package, rewrote that scope. From August 25, the same ownership and board restriction applies to any EU-incorporated entity providing crypto-asset services as defined under MiCA — exchanges, trading platforms, portfolio managers, every licensed CASP category, not just custody. A parallel amendment extends the same rule under the Belarus sanctions regime.

In plain terms: if a MiCA-authorised CASP has a Russian or Belarusian national on its cap table with ownership or control rights, or on its board, that firm has been out of compliance since August 25 — regardless of how clean its transaction monitoring is.

Why the timing makes this worse

MiCA's transitional period ended on July 1. A wave of CASPs — plenty of them Italian, plenty of them across the rest of the EU — obtained their authorisation only in the weeks immediately around that deadline. Those firms went straight from "not yet MiCA-authorised" to "subject to an expanded sanctions restriction on who can own us" in under two months, often without anyone flagging that the second thing had happened at all.

It's an easy gap to fall into. MiCA authorisation and sanctions compliance are two separate regulatory tracks that happen to collide here. Passing your MiCA licensing review says nothing about whether your shareholder register would survive a sanctions audit — they're evaluated by different people, against different rules, on different timelines.

This isn't only a problem for the CASPs themselves. If you're a bank, EMI, or payment provider onboarding a crypto-exposed client or partner that happens to be a MiCA CASP, this is now a fact worth confirming as part of enhanced due diligence — not because you're liable for their cap table, but because a counterparty in breach of sanctions law from day one of its licence is not a counterparty whose risk profile you want to discover after the relationship starts.

Why this isn't a screening problem

It's worth being direct about this, because it's tempting to treat every new sanctions development as "add it to the screening pipeline." This one doesn't work that way.

Transaction and wallet screening tells you whether an address or an entity has touched a sanctioned counterparty. It tells you nothing about who owns the equity or holds a board seat at a firm you're screening. That information lives in corporate registries, shareholder agreements, and beneficial ownership filings — not in blockchain data. A CASP can screen every transaction it processes flawlessly and still be in breach of this rule if nobody has looked at the cap table since the ownership restriction expanded.

That makes this fundamentally a governance review, not a monitoring one. It needs to happen once now, and again any time ownership or board composition changes — not on a transaction-by-transaction basis.

What to check now

  • If you're a MiCA-authorised CASP, review your own shareholder register and board composition for any Russian or Belarusian national with ownership, control, or a governing-body seat. Document the review — a dated record that you checked is exactly what an examiner wants to see, whatever the answer turns out to be.
  • If you're onboarding or maintaining a relationship with a CASP counterparty, add this to your enhanced due diligence checklist for any MiCA-authorised entity, not just new onboarding. A relationship that started clean in June should be re-checked against a rule that only started applying in August.
  • Re-run this check after any ownership or board change, not just once. A cap table is not a fact you verify once and file away.
  • If you operate under the Belarus sanctions regime too, confirm the corresponding provision — the restriction runs on a parallel track there, not a shared one.

How AML Radar fits in

This is one of those cases where we'd rather be precise than oversell what our platform does. The Wallet Screener checks transactions and addresses — it has no visibility into who sits on a CASP's board, and no automated tool that relies on blockchain or sanctions-list data will either. That part of the review has to be done against corporate registry and beneficial ownership data, by a human, for now.

Where the CASP Registry does help is scope: it tracks which entities are actually MiCA-authorised across EU jurisdictions, which is precisely the population this restriction applies to. If you're not sure whether a counterparty falls under this rule at all, that's the first question to answer, and it's one we can answer faster than a manual lookup. Once the ownership review itself is done, logging it to the MLRO Audit Trail means the record exists with a timestamp — so if a supervisor asks when you last checked, the answer isn't "we should probably do that."

Conclusion

The 14 platform designations from the same sanctions package got the headlines. This provision got almost none, and it's arguably the one more MiCA CASPs are currently in breach of without knowing it. If your firm was authorised anywhere near the July 1 deadline, the cap table review this requires has probably not happened yet — and it's been due since August 25.

Try the AML Radar CASP Registry — free to start.


This article is for informational purposes only and does not constitute legal advice. Always consult a qualified compliance professional for guidance specific to your jurisdiction and business.

Ready to screen a wallet address?

Use AMLRadar's free screener to check any crypto address against OFAC, EU, and UK sanctions lists instantly.

Try the Screener