
What happened
According to Elliptic, supervisors worldwide expect financial institutions to identify and control risks associated with cryptocurrencies without creating separate compliance structures.
Why it matters
This change signals that working with cryptocurrencies has moved from a gray area into the field of close scrutiny by official regulators. Financial organizations can no longer ignore crypto risks or consider them secondary; failure to meet these new expectations could lead to serious sanctions from supervisory authorities.
Banking regulators around the world now explicitly expect financial institutions to identify and manage risks associated with crypto assets. This requirement extends to any activity, products, or counterparties related to the crypto sphere and covers areas including anti-money laundering, counter-terrorist financing, sanctions compliance, and corporate governance.
Elliptic's blog emphasizes that current supervisory expectations do not require financial institutions to develop a completely separate compliance program specifically for cryptocurrencies. Instead, crypto asset risks must be integrated into existing risk management systems.
This approach means that banks are obligated to apply the same rigorous due diligence and monitoring standards to digital asset operations as they do to traditional financial instruments, ensuring compliance with all applicable regulatory requirements without creating isolated procedures.
Confirmed facts
- Banking regulators worldwide expect financial institutions to identify and manage risks associated with crypto assets.
- Requirements cover areas of AML/CFT, sanctions compliance, and corporate governance.
- The source states that managing crypto risks does not require creating a separate compliance program.
- Information is based on an Elliptic blog post published on July 16, 2026.
Context
Previously, many financial institutions viewed cryptocurrencies as a niche asset with unique requirements, often separating them from core risk management processes. The current regulatory position unifies the approach, equating the level of responsibility for crypto assets to that of traditional assets.
What remains unknown
- What specific risk assessment methodologies will regulators in different jurisdictions propose for integrating crypto assets?
- How will smaller financial institutions cope with the burden of implementing these requirements without allocating additional resources?
- Will formal legislative acts follow these statements, or will they remain at the level of advisory guidelines?
AI analysis
Confidence: medium
Analysis indicates a strategic shift in regulation: rather than creating a new, complex layer of rules exclusively for blockchain, global supervisory bodies prefer to adapt already functioning financial control mechanisms. This lowers the barrier to entry for understanding requirements but simultaneously tightens accountability, making the argument of 'technology novelty' as justification for insufficient control impossible. The assertion that a separate program is unnecessary can be interpreted in two ways: as a simplification of the process for banks or as a signal that current systems must be immediately expanded without excuses.
Strategic AI conclusion
The most likely consequence will be a mass audit of internal bank policies regarding the inclusion of crypto scenarios in the coming quarters. The next observable signal will be the first fines or directives issued for the lack of explicit crypto risk management procedures within general compliance reports. The main uncertainty lies in the differing interpretations of the term 'sufficient risk management' by regulators in different countries, which could create a fragmented landscape of requirements.