From Cash to Crypto: Towards a Consistent Regulatory Approach to Illicit Payments

marsbitPublished on 2026-03-29Last updated on 2026-03-29

Abstract

"From Cash to Crypto: Towards a Consistent Regulatory Approach to Illicit Payments" by Andrea Minto et al. (BIS) examines the challenges for Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) regulation posed by the diversification of payment instruments, from cash and bank deposits to cryptoassets and CBDCs. The paper introduces a conceptual framework centered on the degree of intermediary involvement in a payment tool. It identifies a "waterbed effect": as regulators tighten AML/CFT rules on one type of instrument (e.g., bank transfers), illicit activity may shift to less-regulated alternatives with lower detection probabilities (e.g., self-hosted crypto wallets). This regulatory arbitrage undermines overall effectiveness. The framework categorizes payment tools as either intermediary-dependent (e.g., bank deposits, e-money, custodial wallets) where regulated entities perform checks, or non-intermediated (e.g., cash, self-hosted wallets, offline CBDCs) which offer higher anonymity and pose greater detection challenges. Malicious actors are assumed to choose tools that minimize their risk of detection. A case study of the EU's evolving AML/CFT regime illustrates this dynamic, showing how regulation has expanded over time to cover new entities like Crypto-Asset Service Providers (CASPs). However, inconsistencies remain, such as transaction limits for cash but not yet for self-hosted wallets or offline digital euro transactions. The paper concludes b...

Authors: Andrea Minto, Anneke Kosse, Takeshi Shirakami and Peter Wierts, BIS

Compiled by: Ma Yimeng, FinTech Research Institute

In March 2026, the Bank for International Settlements (BIS) published a working paper titled "From cash to crypto : towards a consistent regulatory approach to illicit payments". The paper explores the challenges faced by anti-money laundering and countering the financing of terrorism (AML/CFT) regulation in the context of the diversification of payment instruments. It proposes a conceptual framework to analyze the risk of regulatory arbitrage, known as the "waterbed effect," arising from the varying degrees of intermediary involvement across different payment instruments.

By examining the evolution of regulation in the European Union, the paper argues that achieving regulatory effectiveness requires a balance between general law (lex generalis) and special law (lex specialis). The FinTech Research Institute of Renmin University of China (WeChat ID: ruc_fintech) has compiled this research.

I. Introduction

With the rapid development of financial technology, we are undergoing a profound transformation in payment methods. From traditional cash and bank deposits to electronic money, and further to emerging cryptoassets and the much-discussed retail central bank digital currency (CBDC), the range of available payment instruments is unprecedentedly rich.

This diversification, on one hand, promotes competition and financial inclusion, but on the other hand, introduces new risks. Each payment instrument can be exploited by criminals for money laundering (ML) or terrorist financing (TF), thereby harming the integrity and stability of the financial system.

For a long time, regulatory authorities worldwide have addressed these risks through AML/CFT frameworks, requiring "obliged entities" such as financial institutions to fulfill obligations like customer due diligence (CDD), transaction monitoring, and suspicious transaction reporting.

However, regulation does not operate in a vacuum. When new payment instruments emerge, the regulatory framework needs constant adjustment to accommodate them. But there are inherent design differences among payment instruments, especially in their reliance on intermediaries, which may lead to inconsistencies in regulatory rules across these instruments.

This inconsistency can trigger a "waterbed effect": when regulators strengthen oversight in one payment area (e.g., bank transfers), plugging loopholes, fund flows may shift, like water pressed on one side of a waterbed, to another area with relatively lighter regulation (e.g., certain cryptocurrencies). This behavioral adjustment, whether malicious regulatory arbitrage or a choice by legitimate users for privacy reasons, undermines the overall effectiveness of regulation.

Therefore, the core question of this paper is: How does the AML/CFT framework influence, or even distort, users' choice of payment instruments? The authors aim to explore how to achieve a more consistent and effective regulatory path across different payment instruments by constructing a conceptual framework and using EU regulatory practice as a case study.

II. Conceptual Framework: AML/CFT Measures and Interaction with Payment Instrument Choice

Intermediary Role and Regulatory Arbitrage

The core of this paper is a qualitative analytical framework based on design differences in payment instruments. The core variable of this framework is the degree of involvement of intermediary institutions. Based on this variable, the authors categorize payment instruments into two broad types:

  • Intermediary-Dependent Instruments: Include bank deposits, electronic money, custodial wallet cryptoassets, and online retail CBDC. These transactions pass through one or more regulated intermediaries, which act as "obliged entities," performing customer due diligence, monitoring transactions, and reporting suspicious activities to the Financial Intelligence Unit (FIU). Consequently, such instruments are designed with a high probability of detecting illicit transactions.

  • Non-Intermediary-Dependent Instruments: Include cash, self-custody wallets cryptoassets, and offline retail CBDC. In these transactions, no intermediary institution is authorized or able to act as a "gatekeeper." Transaction information is primarily confined to the payer and payee. Therefore, theoretically, the design of these instruments results in a lower detection probability.

Based on this, the model derives the first key hypothesis: Malicious actors will choose the payment instrument with the lowest expected detection probability to maximize the expected net benefit of their illegal activities. Among non-intermediary-dependent instruments, cash, while offering the highest anonymity, is limited in its practicality for large-value, remote transactions due to its physical form.

Self-custody wallets may become a more attractive alternative, as they combine relatively high anonymity with digital convenience. Offline CBDC, although leaving electronic traces, if designed without intermediary involvement, also poses a higher risk than intermediary-dependent instruments.

Waterbed Effect and Regulatory Response

The second key part of the framework describes the dynamic game between behavioral adjustment and regulatory response. When regulators strengthen oversight of a certain type of instrument, for example, by implementing strict monitoring of bank deposits, this increases its "cost of use" (the detection risk for malicious actors).

According to the "waterbed effect," malicious activity will shift to other payment instruments with weaker regulation and lower detection probabilities (e.g., self-custody wallets). This arbitrage behavior weakens the overall effectiveness of regulation, forcing regulators to intervene. The intervention typically involves further expanding the regulatory scope to include newly emerged, uncovered payment instruments, thus triggering a new round of behavioral adjustment.

This dynamic cycle explains why the AML/CFT framework is constantly evolving and "catching up" with technological innovation. This effect exists not only between different payment instruments but also potentially between different jurisdictions, forming geographical regulatory arbitrage.

Side Effects on Legitimate Users: Privacy and Freedom of Choice

The third part of the framework considers the side effects of regulation on legitimate users. AML/CFT measures, while necessary for combating crime, inevitably infringe upon users' informational privacy.

Transaction monitoring and data sharing mean that part of the user's personal information is held by third parties (intermediaries, regulators). This trade-off between privacy and financial integrity is an unavoidable core contradiction in regulatory design. Even for legitimate purposes, some users may prefer payment instruments with a higher degree of privacy protection due to concerns about data security or the value orientation that "payment is a private matter."

Therefore, legitimate users and malicious actors may converge in behavior: both prefer non-intermediary-dependent instruments. However, the reasons are截然不同: Malicious actors aim to evade regulation, while legitimate users seek to protect their privacy and personal freedom. This makes policymaking more complex, as simply tightening regulation to plug loopholes may excessively sacrifice the freedom of ordinary citizens.

III. Legal Analysis: The Case of the European Union

The EU has continuously evolved its AML/CFT framework since 1991, gradually expanding from initial financial institutions like banks to accountants, lawyers, real estate agents, and finally explicitly bringing crypto-asset service providers (CASPs) under regulation in the 2018 and 2024 reforms. This evolution clearly shows the framework's trajectory of constantly adapting to new risks. However, the case study also reveals that inconsistencies still exist in the current framework, which may trigger the "waterbed effect."

  • Cash: The EU has introduced a €10,000 upper threshold for cash transactions, directing large-value transactions towards instruments involving intermediaries.

  • Self-Custody Wallets: For such tools that do not involve intermediaries, regulation primarily monitors them through their "touch points" with intermediaries (e.g., when converting crypto assets to fiat currency). However, there is currently no transaction or holding limit similar to that for cash.

  • Offline Digital Euro: In the European Commission's digital euro proposal, offline transactions are designed to be without intermediary involvement to provide a cash-like privacy experience. To balance the risks, the proposal授权 the European Commission to set limits for such transactions, but these have not been finalized yet.

IV. Building a Consistent AML/CFT Regulatory Path: Conclusions and Recommendations

Based on the above analysis, the paper proposes a core policy recommendation: adopt a regulatory model that combines "general law" and "special law" to achieve both consistent and flexible regulatory effects.

  • General Law (Lex Generalis): Refers to the application of uniform, universal principles and core requirements to all payment instruments with similar characteristics. Specifically, for all payment instruments involving intermediaries (bank deposits, electronic money, online CBDC, custodial wallets), a unified regulatory "baseline" should be established. This means all such intermediaries should bear the same basic obligations: conducting customer due diligence, monitoring transactions, keeping records, and reporting suspicious transactions. At the same time, privacy and data protection standards applicable to these intermediaries should be as unified as possible to ensure that the trade-off between privacy and integrity is consistent across the industry.

  • Special Law (Lex Specialis): Refers to the formulation of supplementary, targeted rules based on the general law, addressing the unique design or functions of specific payment instruments. For example:

Forcash, its physical characteristics make the direct application of general law difficult, hence the need for special law, such as the €10,000 transaction limit, as a supplement.

Foroffline CBDC, since its design deliberately excludes intermediaries to provide a cash-like experience, special law is also needed to manage its risks, such as setting transaction and holding limits.

Forself-custody wallets, special law is needed to address the unique challenges they pose. This may include further strengthening the regulation of "touch points" with intermediaries, or exploring technical compliance (e.g., setting limits at the protocol level), and enhancing the requirements for wallet service providers (even if they do not directly custody assets).

For payment instruments that do not rely on intermediaries, regulators need to go beyond the traditional model of "intermediary accountability" and explore more diverse regulatory instruments. This may include:

  • Utilizingtouch points: Strengthening the monitoring of all channels through which illicit funds enter or exit the non-intermediated realm.

  • Setting transaction limits: As done for cash and offline CBDC, and using this as a universal risk management tool. For self-custody wallets, although enforcing such limits is technically challenging, it is not impossible and is a direction worth exploring in the future.

  • Enhancing issuer responsibility: Requiring issuers of payment instruments (e.g., the central bank's currency issuance department, stablecoin issuers) to take on more AML/CFT responsibilities, such as taking more active measures (e.g., discontinuing high-denomination banknotes, freezing suspicious addresses) to maintain the integrity of their issued instruments.

  • Increasing the cost of violation: Imposing stricter penalties on individuals or entities that use non-intermediated payment instruments for transactions in professional activities.

Finally, the paper emphasizes that a truly effective AML/CFT framework must be forward-looking and adaptable. There will inevitably be more innovative payment instruments in the future that we cannot foresee today. By establishing a framework based on the principles of "general law" and broadly defining the function of "payment instruments," future innovations can be默认纳入 regulatory视野, thereby breaking the passive cycle of "innovation-regulation-re-innovation-re-regulation" and guiding financial innovation towards a direction more beneficial to social welfare.

Related Questions

QWhat is the 'waterbed effect' in the context of AML/CFT regulation of payment instruments?

AThe 'waterbed effect' refers to the phenomenon where increased regulatory pressure on one type of payment instrument (e.g., bank transfers) causes illicit financial flows to shift, like water in a mattress, to other, less regulated instruments (e.g., certain cryptocurrencies). This behavioral adjustment, whether for malicious regulatory arbitrage or legitimate privacy reasons, undermines the overall effectiveness of the regulatory framework.

QHow does the article categorize payment instruments based on their design?

AThe article categorizes payment instruments into two main types based on the degree of intermediary involvement. 'Intermediary-reliant instruments' include bank deposits, e-money, custodial wallet cryptoassets, and online retail CBDCs, which involve regulated intermediaries that perform AML/CFT duties. 'Non-intermediary-reliant instruments' include cash, self-custody wallet cryptoassets, and offline retail CBDCs, where no intermediary acts as a gatekeeper, leading to a lower theoretical probability of detecting illicit transactions.

QWhat core policy recommendation does the article propose for a consistent regulatory approach?

AThe article proposes a hybrid regulatory model combining 'Lex Generalis' (general law) and 'Lex Specialis' (special law). Lex Generalis establishes a unified regulatory baseline of core AML/CFT requirements for all intermediary-reliant payment instruments. Lex Specialis provides supplementary, targeted rules for specific instruments with unique designs, such as transaction limits for cash and offline CBDCs, or specific measures to address the challenges posed by self-custody wallets.

QAccording to the conceptual framework, why might legitimate users prefer non-intermediary-reliant payment tools?

ALegitimate users might prefer non-intermediary-reliant tools due to concerns about informational privacy and a desire for personal freedom. While AML/CFT measures are necessary, they involve transaction monitoring data and information sharing with third parties (intermediaries, regulators), which can be seen as an intrusion. Users may choose tools like cash or self-custody wallets to maintain greater degree of privacy, even for entirely legal purposes.

QWhat regulatory tools are suggested for managing risks of non-intermediary-reliant payment instruments?

AFor managing risks of non-intermediary-reliant instruments, the article suggests regulatory tools that go beyond the traditional 'intermediary accountability' model. These include: leveraging 'touch points' (monitoring entry/exit points to the regulated system), setting transaction or holding limits (as with cash), enhancing issuer responsibility (e.g., central banks for cash, stablecoin issuers), and increasing penalties for using these instruments for illicit activities in a professional context.

Related Reads

Only 153 Venture Capital Firms Invested in July: Is the Crypto VC Industry Experiencing a 'Mass Extinction'?

In July 2026, only 153 unique venture capital firms participated in disclosed crypto funding rounds, marking the lowest monthly count since November 2020. This figure represents an 87% decline from the peak of 1,177 firms in 2022. Overall, the first seven months of 2026 saw crypto projects raise approximately $11.78 billion across 481 rounds. This crypto VC contraction contrasts sharply with the broader venture capital landscape, where global VC investment reached a record $560.4 billion in H1 2026, heavily fueled by major AI company financings. This shift in capital allocation has drawn funds away from the crypto sector. Within crypto, funding is highly concentrated. Trading platforms, prediction markets, and payment sectors absorbed 53% of the total capital. While early-stage deals remain frequent, the largest sums flow to a few late-stage rounds and mergers & acquisitions, which surged to $7.23 billion in Q2 2026. The market is consolidating around top funds like a16z crypto and Dragonfly, which successfully raised new multi-billion dollar funds, while many smaller firms have retreated. Analysts describe this as a "great extinction" for crypto VCs, where capital is becoming more selective, favoring proven business models and assets over early-stage speculation. This raises the bar for project quality, funding efficiency, and viable exit paths.

marsbit18m ago

Only 153 Venture Capital Firms Invested in July: Is the Crypto VC Industry Experiencing a 'Mass Extinction'?

marsbit18m ago

Strategy's Loss in the Second Quarter Reaches $8.22 Billion Amid Bitcoin Decline

Strategy, the largest corporate holder of Bitcoin, reported a net loss of $8.22 billion for the second quarter. This loss was primarily driven by an $8.32 billion unrealized loss on its Bitcoin holdings due to a decline in the asset's price during the period. Despite these paper losses, the company increased its Bitcoin holdings to 843,775 BTC, a 25% growth since the start of the year. As part of a new monetization strategy, Strategy sold approximately $218.4 million worth of Bitcoin, mainly to fund dividends for preferred shareholders, with $216 million of that sold after Q2 ended. The company also built a $3.75 billion cash reserve, which it claims is sufficient to cover over two years of dividend and interest payments, aiming to insulate itself from Bitcoin's volatility while meeting obligations. Following the earnings release, Strategy's stock (MSTR) rose 4.7% in regular trading but corrected slightly after-hours. This pattern reflects how the company's accounting results are heavily tied to Bitcoin's price swings, even as its long-term strategy remains unchanged. The report indicates that Strategy is maintaining its core strategy of accumulating Bitcoin while building a financial buffer. This quarterly loss follows a recognizable pattern, with the company posting significant unrealized losses in previous quarters (e.g., $12.4 billion in Q4 2025 and ~$12.5 billion in Q1 2026) due to fair-value accounting. A key technical shift is its new monetization program, which introduces periodic selling pressure on the market, transitioning Strategy from a pure accumulator to a participant that occasionally adds supply. A critical question remains: how long can the cash reserve cover dividend obligations if a Bitcoin price downturn persists beyond two years?

cryptonews.ru38m ago

Strategy's Loss in the Second Quarter Reaches $8.22 Billion Amid Bitcoin Decline

cryptonews.ru38m ago

Will Terrorist Durov Ban Russian Officials?

Telegram founder Pavel Durov publicly reacted to being labeled a "terrorist" by Russian authorities, stating the designation came after he refused demands for mass surveillance and censorship on the platform. In a Telegram post, he highlighted that this status formally bans him from "publishing information online." Durov concluded with a statement widely circulated: Russian officials "clearly don't understand who can ban whom on the internet." This remark suggests Durov could potentially restrict official Russian government and officials' channels on Telegram, which continue to operate on the platform despite its formal blocking in Russia. The situation parallels previous, slow-moving state directives, like switching officials to domestic cars, contrasted with the current push to migrate all government communication to the Russian-made messenger MAX by 2030. However, reports indicate many officials still use Telegram via workarounds, fearing surveillance on MAX, while alternatives like BiP and KakaoTalk recently became inaccessible in Russia without a VPN. Durov has not specified any immediate actions against state channels. His statement is an initial response, with further developments depending on the authorities' reaction. The dynamic differs from 2020 when Russian regulators lifted a block on Telegram; now, Durov implies control from within the platform itself over the official accounts that persisted through that earlier blockade.

cryptonews.ru38m ago

Will Terrorist Durov Ban Russian Officials?

cryptonews.ru38m ago

DeepSeek V4 Official Version Arrives, New Capabilities Emerge, Value-for-Money King Enters the Fray

On July 31st, DeepSeek officially launched the public API beta for its DeepSeek-V4-Flash model. A key highlight is its performance on multiple Agent benchmark tests, reportedly nearing or even surpassing the level of the V4-Pro preview version from three months ago. Notably, the Flash model achieves this with significantly smaller scale (130B active parameters vs. Pro's 490B), suggesting that post-training optimization and data quality may be as crucial as raw model size. DeepSeek emphasized that the V4-Flash-0731 uses the same model architecture and size as its preview version, with improvements attributed solely to "re-trained post-training." The update also marks the official debut of DeepSeek's self-developed Agent framework, "Harness." The move signals DeepSeek's strategic push to position its cost-effective Flash model as a competitive base for Agent applications—scenarios requiring autonomous planning, tool usage, and complex task execution—where inference speed and cost are critical. By natively supporting OpenAI's Responses API format and adapting for code-generation scenarios, DeepSeek aims not just to be a cheaper alternative but to establish its own ecosystem in the Agent era. This release follows DeepSeek's record-breaking ~$50 billion fundraising round roughly two months prior, underscoring market confidence in its technology and commercialization prospects. The company is reportedly preparing for another funding round at a valuation of approximately $71 billion. The Flash model's advancement represents a step in fulfilling the high expectations that come with this valuation, setting the stage for the impending release of the V4-Pro official version and intensifying competition in the global Agent landscape.

marsbit42m ago

DeepSeek V4 Official Version Arrives, New Capabilities Emerge, Value-for-Money King Enters the Fray

marsbit42m ago

Trading

Spot
活动图片