Regulatory analysis · EU supervision
A virtual IBAN looks like an account number and is not one. It is a pointer to somebody else's master account, and the payment service provider that issued it frequently cannot see who is behind it.
Almost a quarter of the EU supervisors responsible for payment institutions told the European Banking Authority that virtual IBANs obscure the true identity of account holders. Below: what the EBA's fifth Opinion found, why the crypto and payments sectors are converging into the same supervisory problem, and where the rules stand now that the authority that wrote them no longer holds the mandate.
Where the numbers come from
The Opinion of the European Banking Authority on money laundering and terrorist financing risks affecting the EU's financial sector (EBA/Op/2025/10, 28 July 2025) is the EBA's fifth. It rests on responses from 52 competent authorities across 29 EU Member States and EEA countries, out of 58 approached, covering January 2022 to December 2024.
That denominator matters. Every percentage below is a proportion of supervisors who reported something, not a proportion of firms found to be doing it.
Note also what this Opinion now is. Since 1 January 2026 the EU's anti-money-laundering mandates have sat with a different authority (see below), so this is the EBA's last word on the subject rather than a staging post in a continuing series. No successor is scheduled in the new authority's published programme.
What supervisors said about crypto
The sector has grown faster than the supervision of it. The Opinion records that between 2022 and 2024 the number of licensed or registered crypto-asset service providers "multiplied by 2.5 to reach 2 525 at the end of 2024, as has the volume and average value of crypto transactions" — so a comparable 2.5-fold rise in volumes and average values, not merely in firm count.
Three findings sit behind that growth:
| Finding | Share of competent authorities |
|---|---|
| Lack of understanding of the ML/TF risks associated with individual business relationships | 53% |
| Failure to ensure adequate verification of customers' or beneficial owners' identity | 43% |
| Increasing crossover in services between CASPs and e-money institutions and payment institutions | 35% |
The first two are ordinary customer-due-diligence failures, at scale, in a sector that grew two-and-a-half-fold in two years. The third is the one that changes the shape of the problem, and it is where virtual IBANs come in.
What a virtual IBAN actually is
An IBAN is a standardised account identifier of up to 34 alphanumeric characters under ISO 13616. A virtual IBAN is a sub-identifier that references a master IBAN held by a payment service provider, so that many end-users can receive payments through distinct identifiers that all route into one underlying account.
The commercial logic is obvious — reconciliation, per-customer identifiers, cross-border collection without local accounts. The supervisory difficulty follows immediately. The Opinion identifies, at paragraph 39, "ML/TF risks stemming from lack of visibility of the identity of the end users of vIBANs, creating challenges for payment service providers (PSPs) in monitoring their business relationships and their customers' transactions".
Three features make it worse.
Cascading. A provider issues its customers virtual IBANs that were themselves generated by another institution — "also known as reissuing". Each layer puts another party between the transaction and the person behind it.
Geographic mismatch. The Opinion notes the case "where the master account is held in a different [Member State] from that of the end customer and where a vIBAN contains a different country code from the IBAN of the master account". The identifier then points at the wrong jurisdiction, and the supervisor who thinks the relationship is theirs may not be the supervisor who has it.
Divergent national treatment. The EBA's conclusion is that these "divergent approaches create a risk of supervisory gaps and risks of regulatory arbitrage".
Supervisors of credit institutions report a different version of the same problem: difficulty distinguishing payments received through virtual accounts from those received through traditional current accounts.
Why this is now a crypto question
Take the three findings together. A third of supervisors see crypto firms converging with e-money and payment institutions on the same services. Almost a quarter of payment-institution supervisors see virtual IBANs concealing who is behind an account. And 43% see identity verification failing in the crypto sector already.
The convergence means an identifier issued in the payments world routinely terminates in the crypto world, and the reverse. A crypto-asset service provider that collects fiat through virtual IBANs inherits the opacity; a payment institution serving crypto customers inherits the verification problem. Neither sector's supervisor necessarily sees the whole chain.
That is not hypothetical. The EBA's Report on tackling ML/TF risks in crypto-asset services through supervision: lessons learned from recent cases (EBA/REP/2025/28, October 2025) sets out six circumvention strategies observed in real cases — unauthorised operation, forum shopping, abuse of reverse solicitation, weaknesses in AML/CFT compliance and risk management, opaque ownership structures, and multi-entity arrangements — across 28 documented use cases. Opaque ownership and multi-entity arrangements are exactly what a cascading virtual IBAN supplies in the payments layer.
What is being done about it
Registration. Directive (EU) 2024/1640, the sixth Anti-Money Laundering Directive, requires at Article 16(1) that virtual IBANs be captured in the national centralised automated mechanisms — the central bank-account registers. That closes the visibility gap for law enforcement and financial intelligence units. It does not close it for the issuing provider's own monitoring. Regulation (EU) 2024/1624, the Anti-Money Laundering Regulation, addresses virtual IBANs separately at Article 22(3) and applies from 10 July 2027.
Identification. Level 2 work under Article 28 AMLR points toward identifying and verifying the person using a virtual IBAN. That work is now the new authority's rather than the EBA's; it consulted on the draft technical standards between 9 February and 8 May 2026, and the package carries a virtual-IBAN article. The cost of that duty is one the payments industry has not yet had to price.
Restrictive-measures screening. Two sets of EBA guidelines — EBA/GL/2024/14 and EBA/GL/2024/15, both dated 14 November 2024 — have applied since 30 December 2025. The second is issued under Article 23 of Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, and is addressed to payment service providers and crypto-asset service providers specifically; it is the first common EU standard for implementing restrictive measures when performing transfers. The first is the broader internal-governance instrument.
Both are eight months into application as this is written. The EBA publishes a compliance table for each, recording which competent authorities comply, intend to comply, or do not. Read the table for the jurisdiction that matters to you rather than assuming uniform application — and note that the table for /14 has not been updated since 30 July 2025, five months before the guidelines applied, so it cannot yet be read as a picture of compliance in application. No dedicated implementation report and no public enforcement action under either instrument has been traced.
The authority that wrote these rules no longer holds the mandate
On 1 January 2026 the EBA and the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) completed the transfer of all AML/CFT mandates and functions from the EBA to AMLA — the EuReCA database included. AMLA, seated in Frankfurt under Regulation (EU) 2024/1620, is now the EU's AML/CFT rule-maker.
Existing EBA guidelines remain in force until AMLA replaces them, so nothing above has lapsed. They are simply AMLA's instruments to maintain now.
AMLA's own timetable is close. Data collection from national supervisors was scheduled to complete in mid-August 2026, with a provisional list of entities for direct supervision to be finalised at the end of September 2026. Direct supervision begins in 2028.
Two further dates have already passed and are easy to miss. The transition under the EBA's No-Action Letter on the interplay between the second Payment Services Directive (Directive (EU) 2015/2366) and the Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114) ended on 2 March 2026: a crypto-asset service provider offering e-money-token payment services without PSD2 authorisation had by then to be authorised, to hold a compliant pending application meeting strict conditions, or to cease the service and offboard its customers. And MiCA's own national transitional periods ended on 1 July 2026.
For the practitioner
Check what your virtual IBAN actually points at. The questions are whether the identifier was issued by you or reissued from another institution, whether the master account sits in the same Member State as the end customer, and whether the country code in the virtual IBAN matches the master. Each mismatch is a supervisory finding waiting to be made, and the third is the one the EBA singles out.
A percentage of supervisors is not a percentage of firms. Fifty-three per cent of competent authorities reporting a risk as significant tells you what supervisors will ask about. It does not tell you how many firms are failing. Anyone citing these figures the other way round will be caught out.
Read the compliance table before assuming the guidelines bite — and read its date. National compliance is recorded instrument by instrument and authority by authority, and one of the two tables predates application.
Update the institution, not just the rule. A compliance file that names the EBA as the responsible AML/CFT authority is now wrong on the institution even where it is right on the rule. That is a small correction with an outsized effect on whether a file reads as maintained.
Key takeaways
- The EBA's fifth Opinion (EBA/Op/2025/10, 28 July 2025) draws on 52 competent authorities across 29 EU and EEA jurisdictions, covering 2022–2024.
- Licensed or registered CASPs multiplied 2.5-fold to 2,525 by end-2024, with a comparable rise in transaction volumes and average values.
- 53% of supervisors report gaps in CASPs' understanding of relationship-level risk; 43% report identity-verification failures; 35% see crypto converging with e-money and payment institutions.
- Almost a quarter of payment-institution supervisors say virtual IBANs obscure who holds the account. Cascading, cross-border mismatches and divergent national treatment compound it.
- Since 1 January 2026 AMLA, not the EBA, holds every EU AML/CFT mandate. Its provisional list of directly supervised entities is due end-September 2026; supervision begins 2028.
Sources
Primary
- EBA/Op/2025/10 — Opinion and Report on ML/TF risks affecting the EU's financial sector, 28 July 2025 (the Opinion and its Report are one document with one pagination)
- EBA/REP/2025/28 — Tackling ML/TF risks in crypto-asset services through supervision, October 2025
- EBA/GL/2024/14 and EBA/GL/2024/15 — restrictive-measures guidelines, 14 November 2024, applicable 30 December 2025, with compliance tables
- EBA/Op/2026/01 — Opinion on supervisory priorities at the end of the PSD2/MiCA No-Action Letter transition, 12 February 2026
- Regulation (EU) 2023/1113 — transfers of funds and certain crypto-assets
- Regulation (EU) 2024/1624 — the Anti-Money Laundering Regulation · Directive (EU) 2024/1640 — the sixth Anti-Money Laundering Directive
- Regulation (EU) 2024/1620 — establishing AMLA
Institutional
- AMLA — EBA and AMLA complete handover of AML/CFT mandates, 19 January 2026
- AMLA — next step toward the 2027 selection of entities for direct supervision
Research and analysis, not legal advice · figures are proportions of responding supervisors, not of supervised firms · positions stated as at 23 August 2026.