D1 Sanctions
Sanctions is not yet covered for this jurisdiction in this report.
Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.
Romania's AML/CFT regime rests on Law 129/2019 (transposing EU AMLD4/5), with NOPCML/ONPCSB as FIU, NBR and FSA as prudential AML/CFT supervisors, and ONRC operating the beneficial ownership register.
Law made at European Economic Area level that applies in Romania is covered once, on the European Economic Area page. This page covers Romania’s own layer: implementation, national authorities, national options and local enforcement.
Sanctions is not yet covered for this jurisdiction in this report.
Beneficial Ownership is not yet covered for this jurisdiction in this report.
Enabler Jurisdictions is not yet covered for this jurisdiction in this report.
Conflict Finance is not yet covered for this jurisdiction in this report.
Romania's digital-asset supervisory perimeter tightened decisively this cycle. The 18-month transitional grandfathering window established under GEO 10/2025 for pre-MiCA crypto-asset service providers expired on 1 July 2026. From that date, no crypto-asset service provider may serve Romanian or EU clients without full MiCA authorisation from the Financial Supervisory Authority (ASF); the prior national ONPCSB-registration route that had allowed continued operation during the transition is now closed. This is a structural finding, not an incident: it marks the end of a permissive posture that had persisted since MiCA's phased rollout began, and it converts Romania's digital-asset market overnight from a transitional regime into a fully MiCA-governed one.
The practical consequence is already visible in supervisory behaviour. ASF has begun issuing its first coercive sanctioning decisions against digital-asset entities, specifically for periodic-reporting failures. The scale and substance of these actions have not yet been established in the evidence available this cycle, and the confidence on this specific enforcement-pattern claim is accordingly held at the uncertain tier pending further detail. What can be said with more confidence is the structural fact of the deadline itself and its binding effect on market access from 1 July 2026 onward.
This development should be read architecture-over-incident: the significant fact is not any single sanctioning decision but the transition from a permissive to an active supervisory posture. A regulator that has spent eighteen months administering a grandfathering window and then begins issuing coercive sanctions in the same quarter the window closes is signalling a change in enforcement philosophy, not merely processing a backlog. For institutions with correspondent or counterparty exposure to Romanian digital-asset entities, the relevant question going into the next cycle is whether ASF's enforcement activity remains confined to reporting-failure cases or expands to substantive licensing-perimeter violations.
The absence of a comparable finding on Romania's beneficial-ownership registry mechanics, sanctions-evasion architecture, or enabler-jurisdiction exposure this cycle should not be read as reassurance; it reflects the scope of what was researched, not a finding of clean status in those domains.
The immediate watch item is whether ASF's coercive sanctioning activity broadens beyond reporting-failure cases into substantive MiCA-authorisation enforcement, and whether the still-pending national MiCA-implementing draft ordinance (allocating supervisory powers between ASF and the National Bank of Romania) reaches final adoption. Until that ordinance is adopted, some ambiguity in the dual-authority supervisory model persists even as the core authorisation deadline has already taken effect.
Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.
MONEYVAL's follow-up report, published 6 July 2026, assessed Romania as compliant with 7 of the FATF 40 Recommendations, largely compliant with 20, and partially compliant with 13, recording specific improvement on Recommendations 6 and 7, which cover targeted financial sanctions, since the prior June 2025 report. Despite this incremental improvement, Romania remains under MONEYVAL's enhanced follow-up process. This is the architecture-level finding for the cycle: Romania's AML/CTF technical-compliance position is moving in the right direction on a subset of recommendations without yet reaching the threshold that would remove it from heightened monitoring.
This finding sits separately from Romania's FATF grey-list status. Romania is not on the FATF grey list; it is assessed instead through the MONEYVAL fifth-round mutual evaluation mechanism, a Council of Europe process rather than the FATF's own International Co-operation Review Group process that produces grey-listing. The two mechanisms should not be conflated: enhanced follow-up under MONEYVAL is a form of continued technical-compliance monitoring, while grey-listing carries its own distinct international signalling and correspondent-banking consequences. Romania's exposure runs only through the former.
On sanctions-list mechanics, Romania's exposure to the EU list of high-risk third countries, the 26-country list in force from 29 January 2026, continues to apply through the standard AMLR mechanism, with no Romania-specific autonomous divergence identified. This is a continuity finding confirming Romania has not diverged from the EU-wide baseline on high-risk-country screening obligations.
No Romania-specific finding on beneficial-ownership registry mechanics beyond MONEYVAL's general transparency commentary, sanctions-evasion architecture, enabler-jurisdiction exposure, or conflict-finance nexus was located this cycle. These gaps reflect the scope of research conducted, not a finding of clean status.
The next MONEYVAL follow-up report will be the natural checkpoint for whether Romania's partial-compliance items on the remaining 13 Recommendations narrow further, and whether continued improvement is sufficient to support eventual exit from enhanced follow-up. In the interim, the improvement on Recommendations 6 and 7 specifically reinforces the targeted-financial-sanctions screening infrastructure that also underpins Romania's EU high-risk-third-country list application noted above.
Commercial Activity is not yet covered for this jurisdiction in this report.
The July 2026 MONEYVAL follow-up shows partial compliance on 13 of 40 Recommendations, which may affect correspondent due-diligence posture toward Romanian counterparties even as targeted-sanctions screening compliance improves.
Any Romanian counterparty relationship premised on transitional national registration rather than full MiCA authorisation is no longer compliant as of 1 July 2026.
This signals a new enforcement posture from ASF; the scale and legal substance of these decisions is not yet established, warranting monitoring of enforcement precedent as it develops.
Board-level risk assessment of Romanian exposure should distinguish between the slow-moving mutual-evaluation trajectory and the fast-moving digital-asset supervisory shift, as they carry different risk horizons.
Technical infrastructure and client-onboarding systems referencing the prior ONPCSB-registration route need review against the current MiCA-only authorisation requirement.
Risk concentration models should treat Romanian digital-asset counterparty exposure as a distinct, more acute risk vector than general AML/CTF country risk, which is improving incrementally.
No material change for this persona this cycle
Audit testing of high-risk-country screening controls for Romanian exposure can continue against the existing 26-country EU list baseline with no divergent national variant to test for.
Romania remains under MONEYVAL enhanced follow-up despite improved Recommendation 6/7 compliance.
Romania's MiCA transitional deadline closed 1 July 2026, ending the national grandfathering route for crypto-asset service providers.
ASF has begun issuing first coercive sanctions against digital-asset entities for reporting failures.
Romania's AML/CTF and digital-asset postures are diverging: gradual architecture-level improvement alongside abrupt sectoral enforcement tightening.
MiCA authorisation is now the sole legal basis for serving Romanian crypto clients; the transitional national registration pathway no longer exists.
Divergent trajectories across AML/CTF architecture and digital-asset supervision in Romania this cycle.
No material change this cycle.
EU high-risk third-country list screening mechanism for Romania confirmed unchanged via standard AMLR application.
Illustrative orientation only: as the AMLA Regulation (Reg (EU) 2024/1620) moves toward operational supervisory capacity alongside the directly-applicable AMLR (Reg (EU) 2024/1624) and per-Member-State 6AMLD transposition, the structural move from purely national supervision toward a hybrid EU-level supervisory perimeter could reshape how cross-border obliged entities are monitored. For a jurisdiction such as Romania, still navigating enhanced follow-up under MONEYVAL, this architecture shift could eventually alter which layer, national or EU-level, carries primary supervisory weight for cross-border-active obliged entities. This is illustrative structural orientation, not an observed development or a prediction of Romania-specific outcome.
Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.
| Tracker | Status | Note |
|---|---|---|
| T1 · Russian Sanctions-Evasion Architecture | stable | |
| T2 · EU AML Package / AMLA | watch | |
| T3 · FATF Grey List | stable | |
| T4 · Beneficial-Ownership Register Status | watch | |
| T5 · Crypto & Digital-Asset Integrity | material_change | |
| T6 · Sanctions Regime Divergence | stable |