European Union regulatory stack

    EU AML compliance software covering MiCA, MiFID II and GDPR.

    EU firms no longer face a single rulebook: crypto-asset service providers answer to MiCA and the Transfer of Funds Regulation, investment firms answer to MiFID II and the AML Regulation, and every customer record is governed by GDPR. ComplianceSuite runs AML controls, KYC, sanctions screening and evidence management in one layer, with EU data residency and regulator-ready exports.

    • AML, KYC and sanctions controls aligned with the EU AML package
    • MiCA and Travel Rule workflows for CASPs
    • MiFID II onboarding, suitability and record-keeping support
    • GDPR-aligned data protection with EU hosting

    MiCA and crypto Travel Rule

    Operate the controls expected of an authorised crypto-asset service provider: customer due diligence, wallet screening, Travel Rule data exchange under the Transfer of Funds Regulation, and governance evidence for national competent authorities.

    • CASP onboarding and risk scoring
    • Originator and beneficiary data under the TFR
    • Self-hosted-wallet verification evidence
    • Authorisation and governance documentation

    MiFID II for investment firms

    Support the compliance obligations of investment firms, broker-dealers and asset managers with onboarding, suitability workflows, ongoing monitoring and the record-keeping that MiFID II and national regulators expect.

    • Client categorisation and onboarding checks
    • Suitability and appropriateness workflows
    • Time-stamped records and retention controls
    • Alerts, cases and escalation for regulatory review

    EU AML package readiness

    Map directive-based national rules and the directly applicable AML Regulation side by side. Each control is versioned with an effective date, so you can show BaFin, ACPR, DNB, MFSA or any national FIU exactly what applied when a decision was made.

    • CDD, ECDD and UBO verification
    • EU Consolidated List and UN sanctions screening
    • FIU reporting workflows per member state
    • AMLA supervision readiness for selected entities

    GDPR-aligned data protection

    Financial-crime data is personal data. Tenants can be pinned to EU hosting with AES-256 encryption at rest, TLS 1.3 in transit, role-based access, maker-checker controls and immutable audit logs, supported by a GDPR-aligned DPA and ISO 27001-certified operations.

    • EU data residency and tenant isolation
    • Retention and erasure workflow support
    • Access controls with full audit trail
    • GDPR-aligned DPA and ISO 27001, 9001, 22301 certifications

    FAQ

    Regulator questions, answered.

    Who is the EU AML page for?

    It is for EU-regulated firms — banks, EMIs, investment firms, crypto-asset service providers and payment institutions — that must run AML controls across MiCA, MiFID II, the EU AML package and GDPR without maintaining separate systems for each framework.

    How does ComplianceSuite handle MiCA alongside traditional AML rules?

    MiCA and Transfer of Funds Regulation workflows run in the same platform as AMLD/AMLR controls. CASPs get wallet screening, Travel Rule data exchange and governance evidence, while the AML programme shares one customer record, one screening engine and one case file.

    Does the platform cover MiFID II record-keeping?

    The platform supports onboarding, client categorisation, suitability workflows and time-stamped, exportable records that support MiFID II evidence expectations. Your compliance team remains responsible for the legal interpretation of MiFID II obligations for your specific permissions.

    How is GDPR addressed?

    Tenants can be pinned to EU hosting with AES-256 encryption at rest, TLS 1.3 in transit, role-based access and immutable audit logs. ComplianceSuite operates under ISO 27001, ISO 9001 and ISO 22301 certifications and ships with a GDPR-aligned data processing agreement.

    Can one tenant serve entities in several EU member states?

    Yes. Multi-entity support gives each legal entity its own risk model, screening configuration and FIU reporting workflow, while group compliance sees consolidated risk across member states.

    How do EU implementations usually start?

    Most teams begin with a scoped discovery session mapping current controls, supervisory findings and data sources to a target programme, typically with a 6-10 week implementation plan and a parallel-run period.

    Run MiCA, MiFID II and GDPR evidence from one platform.

    Book a session and we will map your EU obligations to the controls and evidence your regulators expect.