D1 Sanctions
Sanctions is not yet covered for this jurisdiction in this report.
Croatia's AML/CFT regime rests on the Anti-Money Laundering and Terrorist Financing Law (AMLTFL, 2017, amended 2023), supervised by the Ministry of Finance's Anti-Money Laundering Office (AMLO/FIU), HNB (banking) and HANFA/CFSSA (capital markets).
Law made at European Economic Area level that applies in Croatia is covered once, on the European Economic Area page. This page covers Croatia’s own layer: implementation, national authorities, national options and local enforcement.
Sanctions is not yet covered for this jurisdiction in this report.
Beneficial Ownership is not yet covered for this jurisdiction in this report.
Enabler Jurisdictions is not yet covered for this jurisdiction in this report.
Conflict Finance is not yet covered for this jurisdiction in this report.
Croatia's crypto-asset AML/CFT perimeter tightened structurally on 1 July 2026 with the end of the MiCA transitional period. Prior to that date, virtual-asset service providers in Croatia could operate under a partial supervisory arrangement, subject to AML/CFT-Act oversight by HANFA without holding full MiCA Crypto-Asset Service Provider authorisation. That partial route has now closed: HANFA's own publication confirms that provision of crypto-asset services in Croatia is now mandatory-authorisation-only, meaning any AML/CFT gap that existed under the prior AML-only supervisory track has been folded into the harmonised, EU-wide MiCA licensing perimeter rather than persisting as a national side-channel.
From an AML/CFT architecture standpoint, this is significant precisely because it eliminates a structural seam rather than because it responds to a specific illicit-finance incident. A firm operating under AML/CFT-Act-only supervision was, by definition, outside the full prudential and conduct requirements MiCA CASP authorisation imposes, even while remaining inside HANFA's AML/CFT monitoring scope. Closing that seam means every crypto-asset firm still operating in Croatia now sits inside the same harmonised authorisation-and-supervision perimeter, which is the kind of structural tightening that a purely incident-driven enforcement narrative would miss entirely.
No HANFA enforcement action against a specific VASP that failed to transition by the 1 July 2026 deadline has been located in the evidence reaching this cycle. This absence is itself worth noting under an enablement-as-signal framing: whether the absence reflects full market compliance by the deadline or simply reflects that no enforcement action has yet been reported cannot be determined from the evidence available, and should not be read as evidence of either outcome specifically.
The structural question to track is whether any firm that operated under the prior AML-only route has continued operating without securing CASP authorisation, and if so, whether HANFA takes a formal enforcement action. A second item to track is whether Croatia's crypto-asset AML/CFT perimeter interacts distinctly with the broader EU AML Package as AMLR implementation advances, given that crypto-asset service providers are among the obliged-entity categories the AMLR framework is designed to capture.
Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.
Croatia's technical-compliance trajectory against the FATF 40 Recommendations moved structurally forward this cycle. MONEYVAL's January 2026 follow-up assessment re-rated Croatia Largely Compliant on Recommendation 8, which governs the AML/CFT treatment of non-profit organisations, correcting technical-compliance deficiencies that had previously constrained Croatia's standing on this Recommendation. The re-rating brings Croatia's overall standing across all 40 FATF Recommendations to 7 rated Compliant, 27 rated Largely Compliant, and 3 rated Partially Compliant, with none rated Non-Compliant, a distribution that places Croatia comfortably within a technically well-regarded AML/CFT jurisdiction by FATF's own assessment architecture, even as specific gaps remain.
The most significant of those remaining gaps sits on Recommendation 24, covering beneficial-ownership transparency, which MONEYVAL's follow-up confirms remains rated Partially Compliant and was not actioned in this particular follow-up round. The architecture-over-incident framing here matters: an outstanding Partially Compliant rating that persists unchanged across a follow-up round is not a null finding, it is a structural signal that Croatia's beneficial-ownership registry or verification mechanism has not yet closed the specific deficiency FATF identified, even while adjacent Recommendations have moved favourably.
Structurally, Croatia's binding relationship to the EU AML Package is also worth stating plainly: as an EU-27 member state, Croatia will be bound directly by the AML Regulation (AMLR) once it takes effect, through direct application rather than national transposition, distinguishing it from the sixth AML Directive (6AMLD), which Member States transpose individually. No Croatia-specific 6AMLD transposition status or AMLA direct/indirect supervisory-perimeter development for Croatia specifically was located this cycle; this structural fact is stated as backdrop rather than as evidence of any Croatia-specific movement this cycle.
The principal item to track is whether a future MONEYVAL follow-up round actions Croatia's outstanding Recommendation 24 rating on beneficial-ownership transparency, which would close the last remaining substantive gap in an otherwise strong technical-compliance record. A second item is whether Croatia's national implementing measures for 6AMLD transposition, or its engagement with AMLA's emerging supervisory perimeter, surface as distinct developments in a subsequent cycle.
Commercial Activity is not yet covered for this jurisdiction in this report.
Croatian crypto-asset firms formerly reporting under AML/CFT-Act-only supervision must now hold full MiCA CASP authorisation; MLROs at any institution with Croatian crypto-asset counterparties should treat unauthorised-status counterparties as carrying elevated AML/CFT exposure until authorisation is confirmed.
The improved MONEYVAL standing supports a lower baseline jurisdictional-risk weighting for Croatia in AML/CFT risk-scoring models, though the outstanding Partially Compliant rating on beneficial-ownership transparency (R.24) should still be factored into any Croatia-specific enhanced due-diligence trigger logic.
No material change for this persona this cycle
The Board-level takeaway is that Croatia's regulatory trajectory is structurally improving, supporting continued or expanded institutional exposure to the jurisdiction, while the outstanding R.24 gap warrants continued monitoring rather than immediate concern.
Any technology stack built to support the prior AML/CFT-Act-only compliance posture for Croatian crypto-asset counterparties needs review against the full MiCA CASP authorisation requirements now in force, particularly around custody, prudential and conduct-of-business technical controls that the AML-only route did not require.
Risk functions should continue applying enhanced scrutiny to Croatian beneficial-ownership verification specifically, even as the jurisdiction's overall AML/CFT risk profile improves on other dimensions; this is a persistent rather than newly-emerging gap.
No material change for this persona this cycle
Internal audit functions relying on MONEYVAL ratings as external benchmarking evidence for Croatia-related AML/CFT control testing should update reference documentation to reflect the January 2026 R.8 re-rating and the current 7/27/3/0 distribution across the 40 Recommendations.
MiCA transitional closure ends the AML-only VASP supervisory route in Croatia, mandating full CASP authorisation for continued crypto-asset AML/CFT compliance.
Croatia's overall FATF technical-compliance standing improves to 7 Compliant, 27 Largely Compliant, 3 Partially Compliant of 40 Recommendations following the R.8 re-rating.
No material change this cycle.
Croatia's AML/CFT and crypto-asset supervisory architecture is tightening structurally, reducing jurisdictional financial-crime risk even as a beneficial-ownership transparency gap persists.
Croatian CASP authorisation architecture now mandatory-only; technical systems supporting crypto-asset AML/CFT compliance must map to full MiCA CASP obligations rather than the retired AML-only regime.
Beneficial-ownership transparency (FATF R.24) remains an unresolved structural gap in Croatia's AML/CFT regime despite broader technical-compliance improvement.
No material change this cycle.
MONEYVAL's follow-up re-rating provides updated external assurance evidence supporting Croatia's AML/CFT control-environment assessment.
As an illustrative orientation only, consider how the shift from purely national AML supervision toward AMLA direct and indirect supervision of cross-border obliged entities, operating alongside the directly-applicable AMLR and per-Member-State 6AMLD transposition, could reshape the AML/CFT landscape for crypto-asset service providers such as those now operating under Croatia's post-MiCA-transition CASP perimeter. A cross-border CASP group passporting services from Croatia into other EU member states could, under a hypothetical future AMLA direct-supervision designation, face a harmonised supervisory relationship replacing what is today a purely national HANFA-based AML/CFT oversight relationship. This is architecture-over-incident illustration: it describes a possible structural mechanism the AMLA transition could introduce, not an observed development, and not a prediction of how or whether AMLA will in fact designate any specific Croatian CASP for direct supervision.
Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.
| Tracker | Status | Note |
|---|---|---|
| T1 · Russian Sanctions-Evasion Architecture | no_change | |
| T2 · EU AML Package / AMLA | no_change | |
| T3 · FATF Grey List | no_change | |
| T4 · Beneficial-Ownership Register Status | no_change | |
| T5 · Crypto & Digital-Asset Integrity | material_change | |
| T6 · Sanctions Regime Divergence | no_change |