A crypto-asset service provider writes to the accounting team of a measurement technology manufacturer. It needs a self-certification with company name, address, country of residence and tax identification number, at the latest by 1 January 2027. If it still does not arrive after a reminder, the provider must exclude the company from reportable transactions no later than 90 days after the first request. Anyone who fails to provide the certification also commits an administrative offence. The letter rests on a German law that has applied since December 2025.
That law is one of five rules that apply to a company, whether its stablecoins were issued under MiCAR, under US law or elsewhere. Three of them oblige the service provider: the travel rule, tax reporting under DAC8 and anti-money-laundering checks. The information they need, however, comes from the company. Two rules hit the company itself, with no provider in between: sanctions and accounting. This article describes all five as of September 2026. How the information reaches the ERP system is described in Data Standard & Account Statement.
What Travels with Every Transfer
Since 30 December 2024, EU Regulation 2023/1113 on information accompanying transfers of funds and certain crypto-assets has applied. It extends to crypto-assets what already applies to bank transfers: every transfer between two service providers carries information on the originator and the beneficiary, regardless of the amount. For the originator, this means the name, the address on the blockchain and a postal address including the country. Added to this are either the number of an official document plus the customer number, or the date and place of birth. The legal entity identifier (LEI) is added if the originator has given it to its provider. For the beneficiary, it means the name, the address and the LEI as well. The information does not have to be attached to the transfer itself; it can be sent before, at the same time or in parallel.
A separate rule applies to a wallet that a company runs itself. If a transfer goes to or comes from such a self-hosted address, the provider obtains the information from its customer and keeps it. If the amount exceeds EUR 1,000, it must also establish whether the address is owned or controlled by its customer. The regulation does not specify how the customer proves this. Transfers from wallet to wallet without any provider involved are not covered.
If information is missing, the beneficiary's provider decides. It rejects the transfer, returns the crypto-assets or requests the information before making the crypto-assets available to the beneficiary. For a company, this means that a payment can have arrived on the blockchain and still not be available. The implementing guidelines of the European Banking Authority (EBA) have applied since the same day as the regulation.
The Company as a Reported User
The second rule concerns tax. Since 1 January 2026, EU Directive 2023/2226, known as DAC8, has applied, transposed in Germany by the Crypto-Asset Tax Transparency Act (KStTG) of 22 December 2025. Crypto-asset service providers report annually by 31 July to the Federal Central Tax Office (BZSt), for the first time for the year 2026. Reported users are natural persons and entities, which includes companies. According to the European Commission, this expressly covers customers resident in the provider's own country.
The report contains name, address, country of residence and tax identification number, plus aggregated values per crypto-asset. It covers purchases and sales against money or other crypto-assets, transfers, and payments for goods or services above USD 50,000. If a provider handles such a payment for a merchant, the merchant's customer also counts as a reported user. This applies insofar as the provider has to identify that customer under anti-money-laundering law.
It all rests on the customer's self-certification. For a company, it contains the company name, address, every country of residence and the tax identification number. For customers whose business relationship began before 2026, the provider must complete this by 1 January 2027. If the certification is still missing after a reminder, it blocks such a customer from reportable transactions after no less than 60 and no more than 90 days. Anyone who does not provide the certification or provides it incorrectly risks a fine of up to EUR 50,000. Before the first report, the provider must inform its customers.
Not every stablecoin falls under this report. The KStTG excludes electronic money, and an e-money token under MiCAR counts as electronic money if it has three features. It represents a single official currency, constitutes a claim on the issuer in that currency, and is redeemable at any time and at par value under the rules that apply to the issuer. Such holdings are covered instead by the existing financial account reporting, unless the balance never exceeds USD 10,000 on a rolling 90-day average. The law does not name which tokens these are.
Anti-Money-Laundering Checks Today and from July 2027
For anti-money laundering (AML), crypto-asset service providers are obliged entities under the German Anti-Money Laundering Act (GwG). From a corporate customer, they collect the company name, legal form, register number, registered address and the names of the members of the board. They also collect the beneficial owners, as a rule anyone holding more than 25 per cent of the shares or voting rights. The provider must collect this information from the customer; a look at the transparency register is expressly not sufficient. The customer is obliged to provide the necessary documents and to report changes without delay. This is the familiar know your customer (KYC) procedure that companies know from their banks.
From 10 July 2027, EU Regulation 2024/1624 on preventing money laundering (AMLR) applies. It prohibits anonymous crypto-asset accounts, including those that create anonymity through special coins. And it requires providers to assess the risk of transfers to or from self-hosted addresses. The new EU Anti-Money Laundering Authority (AMLA), based in Frankfurt, will take over direct supervision of selected obliged entities from 2028. Candidates are high-risk financial firms active in at least six member states, and these may include crypto-asset service providers.
Sanctions Apply Directly
With sanctions, the addressee changes. EU sanctions regulations apply directly in every member state, to every person and company in the EU and to every business conducted there in whole or in part. Under Regulation 269/2014, all funds and economic resources of listed persons must be frozen, and no one may make such resources available to them, directly or indirectly. Economic resources there means assets of every kind, tangible or intangible. Germany prosecutes breaches under the Foreign Trade and Payments Act as a criminal or an administrative offence.
For crypto-assets, Regulation 833/2014 has become more explicit. It prohibits any transaction involving the token A7A5 since 25 November 2025, and involving RUBx and the digital rouble since 24 May 2026. It also prohibits any transaction with a crypto-asset service provider or a crypto trading platform established in Russia. Neither prohibition is addressed to providers alone; both apply to everyone.
The US goes one step further into the technology. The Office of Foreign Assets Control (OFAC) makes clear that sanctions obligations are the same for digital currencies as for traditional ones. It adds wallet addresses to its sanctions list but points out that these entries are unlikely to be exhaustive. It expects users of digital currencies to run a risk-based programme that generally includes screening against sanctions lists. The addressees are US persons and others subject to OFAC jurisdiction. For a German company with a subsidiary in the US, this raises the question of which entity screens the addresses.
This becomes practical with the company's own wallet. If a company pays from it directly to a supplier's wallet, there is no provider in between to collect information or check addresses. The check then rests with the company alone.
Three Standard Setters Without a Common Answer on Stablecoins
No provider takes over the balance sheet either. For crypto-assets such as Bitcoin, the IFRS Interpretations Committee stated in June 2019 that they are neither cash nor a financial asset. What remains is inventory under IAS 2 or an intangible asset under IAS 38. What this means for a holding is described in Bitcoin in a Corporate Context. For stablecoins, one restriction is decisive. The decision only covers cryptocurrencies that do not give rise to a contract between the holder and another party. A stablecoin with a right of redemption against the issuer does give rise to such a contract. The decision gives no answer for it, and the International Accounting Standards Board (IASB) has no project of its own on the subject.
In the US, the Financial Accounting Standards Board (FASB) has gone further. For fiscal years beginning after 15 December 2024, it requires certain crypto assets to be measured at fair value (ASU 2023-08). Excluded are assets that give the holder enforceable rights to underlying assets. By the wording of this criterion, a stablecoin with a right of redemption does not fall under it. On 18 August 2026, the FASB published a proposal intended to clarify how the definition of cash equivalents applies to digital assets such as stablecoins. The proposal does not change the definition itself. It is meant to bring more consistent application for entities that present such assets as cash equivalents. In its tentative decisions of April 2026, the FASB named one aspect for this: the nature of the contractual right to redeem for cash on demand with the issuer. Comments are possible until 19 November 2026.
Under the German Commercial Code (HGB), there is no specific rule for stablecoins. A company therefore clarifies how to classify a holding with its auditor before the first payment arrives. For a group with a US subsidiary, this creates a tension. Under the FASB proposal, the subsidiary may in future be able to show a stablecoin as a cash equivalent. IFRS and the HGB make no comparable statement for the parent. Loan agreements that base their ratios on cash and cash equivalents then read different figures in two financial statements.
One Incoming Payment, Five Rules
The measurement technology manufacturer from the opening receives EUR 80,000 in a euro stablecoin from a customer in Spain, via an account with its crypto-asset service provider. It transfers part of it to its own wallet, from which it pays a supplier. As of September 2026, all five rules touch this single transaction:
| Rule | Whom it obliges | What the company contributes | Since when |
|---|---|---|---|
| Travel rule (Reg. 2023/1113) | the providers on both sides | LEI; proof for its own wallet above EUR 1,000 | 30.12.2024 |
| DAC8 / KStTG | the provider reporting to the BZSt | self-certification with tax identification number | 01.01.2026, first report by 31.07.2027 |
| Anti-Money Laundering Act, AMLR from 2027 | the provider | company data, beneficial owners, changes | GwG today, AMLR from 10.07.2027 |
| Sanctions | the company itself | checking counterparty and address | ongoing |
| Accounting | the company itself | classification with the auditor | no specific rule under IFRS and HGB, FASB proposal until 19.11.2026 |
The first three rows oblige the provider but, in case of doubt, block the company. If information on the originator is missing, the provider can reject or hold back the EUR 80,000. If the self-certification is missing, it blocks reportable transactions. The tax report itself depends on the token. Whether the euro stablecoin falls under DAC8 or, as electronic money, under financial account reporting is decided by the three features in the KStTG.
The transfer to the supplier shifts responsibility. It goes to the company's own wallet for more than EUR 1,000, so the provider must establish whether that wallet belongs to the company. From there to the supplier, the payment runs without a provider, and nobody except the company checks whether the recipient address is on a sanctions list. The risk thus lies less in a single breach than in the gap between responsibilities. How wallet and counterparty master data are protected is described in Master Data, Privacy & Security.
Responsibility in House
Every company already holds the information these rules require. It is usually kept in different places, though. The tax department has the tax identification number, the legal department the beneficial owners, treasury the LEI and IT the keys to the company's own wallet. The provider requests them with deadlines whose consequences go as far as a block. This leaves a question that no provider and no law answers: who in the company delivers this information in full before the provider holds back a payment?
Sources & Date
- •European Union (EUR-Lex) – Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets – (travel rule; wording of Articles 14, 16, 17 and 40, applicable since 30 December 2024)
- •German Federal Ministry of Justice (gesetze-im-internet.de) – Kryptowerte-Steuertransparenz-Gesetz (KStTG) of 22 December 2025 – (German transposition of DAC8; self-certification, reporting to the BZSt, fines; read on 19 September 2026; in German)
- •Financial Accounting Standards Board – FASB Seeks Public Comment on Proposal to Enhance Cash Equivalents Disclosures and Clarify the Cash Equivalents Evaluation for Certain Digital Assets – (media release of 18 August 2026, comments until 19 November 2026)
As of: 19.09.2026