Financial Integrity Monitor

Netherlands NL

Domains (D1–D6)
6
Sources
10
Role actions
8
Horizon <90d
5
Jurisdiction profile
Largely CompliantTier ARisk: StableMixed

Netherlands operates a twin-peaks AML/CFT supervisory system (DNB prudential, AFM conduct) under the Wwft, with FIU-Netherlands as national financial intelligence unit.

MoreFATF rates the framework largely compliant (10 C/29 LC/1 PC post-2025 follow-up) but flags legal-person misuse, DNFBP supervision intensity, and sanctions dissuasiveness as unresolved.

Key deficiencies
  • Beneficial ownership register historically under-populated and definitional gaps (no 'ultimate effective control' test) permitting conduit/mailbox company misuse
  • Risk-based supervision of DNFBPs (trust offices, corporate lawyers, high-value dealers) under-resourced relative to risk
  • Sanctions for ML/TF offences assessed as insufficiently proportionate and dissuasive
  • Netherlands' role as domicile/transit hub for global commodity trading houses and crypto infrastructure creates enabler exposure disproportionate to domestic risk profile
Recent developments (18m)
  • FATF 1st Enhanced Follow-Up Report (23 Sept 2025): Recommendation 15 (VASPs) upgraded Partially Compliant to Largely Compliant; NL now 10 Compliant/29 Largely Compliant/1 Partially Compliant
  • AFM published dedicated Wwft guidance annex for crypto-asset service providers (2 May 2025) covering CDD, transaction monitoring, BO verification and SAR filing
  • EU cash-payment limit of EUR 3,000 entered into force (1 Jan 2025) as part of the Dutch AML action plan
  • FIU-Netherlands reinforced with additional FTE capacity as part of national AML strengthening programme
  • AMLA became operational (mid-2025, Frankfurt seat, chair Bruna Szego) beginning to shape the future direct/indirect supervisory perimeter that will include Dutch high-risk obliged entities
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

The Netherlands profile assembled this cycle depicts a structurally mixed enabler jurisdiction rather than a straightforwardly compliant or a straightforwardly permissive one. The Financial Action Task Force rates the Netherlands at 10 Compliant, 29 Largely Compliant and 1 Partially Compliant following a September 2025 enhanced follow-up report that upgraded Recommendation 15 on virtual-asset service providers from Partially Compliant to Largely Compliant. That upgrade sits alongside two structural findings the follow-up did not touch: a beneficial-ownership definition that fails to capture persons exercising ultimate effective control, enabling continued misuse of Dutch conduit and mailbox companies, and an assessed insufficiency in the supervisory intensity applied to trust offices and corporate lawyers relative to identified risk. Both gaps trace to the 2022 mutual evaluation and remain open. Layered onto this compliance picture is a track record in which offshore-controlled crypto-laundering infrastructure, including the Cryptex, PM2BTC and Sinbad.io networks linked to Russian and DPRK proceeds, has repeatedly been physically hosted on Dutch servers, disrupted principally through a coordinated OFAC, FinCEN and FIOD action rather than independent domestic detection.

This composite is read against a fast-moving regulatory horizon. The Anti-Money Laundering Authority has been operational since mid-2025 from its Frankfurt seat, the directly applicable AML Regulation is expected to apply from 2027 and will progressively supersede the Dutch Wwft framework, and the national transitional window under which Dutch crypto-asset service providers operated under MiCA grandfathering closed on 1 July 2026. Architecture over incident: a jurisdiction rated largely compliant on paper can still function as enabling infrastructure through definitional gaps, supervisory capacity constraints and corporate-domicile convenience that persist independently of any single enforcement episode.

Other Developments

EU sanctions packages tighten obligations that apply in the Netherlands with no transposition delay. The EU 19th sanctions package, adopted 23 October 2025, introduced the first-ever EU sanctions on crypto providers, targeting the Russian state-linked A7A5 stablecoin ecosystem, alongside a phased LNG import ban and 117 additional shadow-fleet vessel listings bringing the total to 557. The EU 20th sanctions package, adopted 23 April 2026, added 46 further listings for a total of 632, delisted 11 vessels, introduced a mandatory no-Russia resale clause and a scrapping clause, and designated Murmansk, Tuapse and the Karimun Oil Terminal in Indonesia as circumvention-linked ports, with the Karimun listing having no direct equivalent in the OFAC or OFSI regimes.

A Netherlands-domiciled Trafigura subsidiary faces enforcement concentrated almost entirely offshore. Trafigura Group and its Netherlands subsidiary, Trafigura Beheer B.V., along with former chief operating officer Mike Wainwright, were convicted by the Swiss Federal Criminal Court for bribery of an Angolan official spanning 2009 to 2011. Trafigura Beheer B.V. separately pleaded guilty on 6 February 2025 in the United States District Court for the Southern District of Florida to conspiracy to violate the Foreign Corrupt Practices Act over Petrobras-related bribery in Brazil between 2003 and 2014, agreeing to pay over USD 126 million, with a further USD 75.8 million Brazilian civil settlement following on 31 March 2025.

Dutch supervisory and legislative pre-positioning continues ahead of EU harmonisation. The AFM published a dedicated Wwft guidance annex for crypto-asset service providers on 2 May 2025 covering due diligence, transaction monitoring, beneficial-ownership verification and suspicious-activity-report filing. Separately, a EUR 3,000 national cash-payment limit entered into force on 1 January 2025 and FIU-Nederland has added capacity, both framed as pre-positioning ahead of the 2027 AMLR application date.

AMLA continues its operational build-out. The Anti-Money Laundering Authority, established under Regulation (EU) 2024/1620, has been operational since mid-2025 under chair Bruna Szego, distinct from both the directly applicable AML Regulation and the sixth Anti-Money Laundering Directive, which each proceed on their own transposition and applicability timelines.

Cross-Monitor Connections

The Trafigura bribery pattern is directly relevant to WDM tracking of kleptocratic state capture, given the Angolan and Brazilian producer-state contexts implicated in the underlying conduct, and to ERM tracking of commodity-flow evasion and extractive-industry integrity, given that the corporate wrapper sits in Amsterdam while the operational corruption risk sits in the extractive and trade-finance sectors of third countries. The EU-only character of the first-ever crypto-provider sanctions and the novel Karimun, Indonesia port listing is relevant to GMM tracking of sanctions-regime divergence as a macro variable, since neither measure has a direct OFAC or OFSI counterpart on the same timeline, creating compliance friction for Dutch trading and shipping intermediaries operating across regimes. Across all three connections, the recurring analytical thread is that Dutch structural characteristics, whether corporate-domicile attractiveness or data-centre availability, function as enabling infrastructure for activity whose criminality, enforcement and geopolitical consequence sit substantially outside Dutch borders.

Outlook

The near-term trajectory is one of EU-level architecture tightening faster than the underlying Dutch structural gaps are being resolved domestically. The MiCA authorisation deadline that closed on 1 July 2026 and the 2027 AMLR application date will compress the window during which the beneficial-ownership definitional gap and the DNFBP supervisory-intensity deficiency can persist unaddressed by purely national instruments, while AMLA is expected to begin selecting a first cohort of high-risk cross-border obliged entities, potentially including major Dutch crypto-asset service providers, for direct supervision around 2028. Whether that selection process resolves the conduit-company and gatekeeper-supervision findings, or simply relocates the same structural gaps to a different supervisory layer, is an open assessment question for subsequent cycles, as is whether successor infrastructure has emerged in the Netherlands following the September 2024 disruption of the Cryptex and PM2BTC networks.

weekly_brief_draft · JID NL
Domain intelligence (D1–D6)

D1 Sanctions Architecture and Evasion

Sanctions Architecture and Evasion

Continue reading

The Netherlands occupies a dual position in the EU sanctions architecture against Russia: it is a frontline enforcement node for the measures the Council adopts, and it has repeatedly been the physical host for infrastructure those same measures are designed to disrupt. The EU 19th sanctions package, adopted 23 October 2025, introduced the first-ever EU sanctions on crypto providers, targeting the Russian state-linked A7A5 stablecoin ecosystem, alongside a phased LNG import ban, closed exemptions for Rosneft and Gazprom Neft, and 117 additional shadow-fleet vessel listings bringing the total to 557. The EU 20th sanctions package, adopted 23 April 2026, added 46 further vessel listings for a total of 632, delisted 11 vessels assessed as compliant, introduced a mandatory no-Russia resale clause and a scrapping clause for shadow-fleet exit, and listed Murmansk, Tuapse and the Karimun Oil Terminal in Indonesia as circumvention-linked ports. Both instruments are Council regulations, directly applicable in the Netherlands with no national transposition step, meaning the full designation set takes immediate domestic effect. Rotterdam, as the largest port in Europe, functions as a frontline node for the resulting port-access enforcement, giving the Netherlands an outsized operational role in implementing an architecture set at EU level.

The reverse side of this frontline role is enablement. Russian-linked no-KYC exchanges, Cryptex and PM2BTC, and a DPRK Lazarus-linked mixer successor, Sinbad.io, repeatedly located servers and hosting infrastructure physically in the Netherlands despite offshore beneficial ownership and predicate criminality disconnected from Dutch soil. Disruption of the Cryptex and PM2BTC infrastructure occurred through a coordinated action on 26 September 2024 involving OFAC designation, a FinCEN finding naming PM2BTC a primary money-laundering concern, and a joint seizure operation by the US Secret Service, Netherlands Police and FIOD. The pattern is reactive rather than proactive: Dutch enforcement acted once foreign partners, principally US authorities, had already identified the infrastructure and its criminal nexus. Whether successor hosting has since emerged in the Netherlands is not established this cycle, an explicit gap for forward monitoring.

A further architectural signal is the divergence exposed by the Karimun, Indonesia port listing, which has no direct OFAC or OFSI equivalent. Dutch trading houses and Rotterdam-based shipping and insurance intermediaries face compliance friction from operating across EU, US and UK sanctions lists that do not fully align on port-level and crypto-provider designations, a structural feature of the current sanctions landscape rather than a one-off gap, and one that creates an arbitrage surface for intermediaries structuring transactions to fall between regimes.

Outlook

The sanctions architecture affecting the Netherlands will continue to expand through further EU packages, each taking immediate direct effect domestically, while the crypto-hosting enablement pattern is structural and unlikely to resolve through designation activity alone. Whether Dutch authorities develop independent detection capability for illicit infrastructure hosted on national soil, rather than continuing to rely on foreign-partner referral, is the central forward-looking question for this domain, alongside whether the EU-US-UK divergence on port and crypto-provider listings will widen or narrow in subsequent packages.

Cumulative analysis

Sanctions Architecture and Evasion — Cumulative Analysis

Across the cycles for which the Netherlands has been assessed, the defining feature of its D1 posture has remained consistent: a jurisdiction that implements EU sanctions measures immediately and without transposition delay, functioning as a compliant frontline enforcement node, while simultaneously supplying, through data-centre availability rather than institutional design, the physical hosting infrastructure for sanctioned-adjacent illicit crypto flows. As an EU member state, the Netherlands gives direct effect to each successive Council sanctions package. The 19th package, adopted 23 October 2025, marked a qualitative escalation by introducing the first-ever EU sanctions on crypto providers, targeting the Russian state-linked A7A5 stablecoin ecosystem, alongside a phased LNG import ban and 117 additional shadow-fleet vessel listings for a running total of 557. The 20th package, adopted 23 April 2026, extended this trajectory with 46 further vessel listings, taking the total to 632, alongside a delisting of 11 compliant vessels, a mandatory no-Russia resale clause, a scrapping clause for exiting shadow-fleet vessels, and the designation of Murmansk, Tuapse and, notably, the Karimun Oil Terminal in Indonesia as circumvention-linked ports.

The Karimun listing has proven analytically significant beyond its immediate designation effect, because it has no direct equivalent in the OFAC or OFSI sanctions regimes, exposing a structural divergence in third-country port-designation practice between the EU and its principal partner jurisdictions. This divergence recurs as a standing feature of the Netherlands assessment: Rotterdam-based trading houses, shipping intermediaries and insurers operate across EU, US and UK sanctions lists that do not fully align on crypto-provider and port-level measures, generating a persistent compliance-friction and arbitrage surface rather than a single-cycle anomaly. Rotterdam, as the largest port in Europe, remains the operational locus through which this friction is transmitted into day-to-day trade-finance and shipping-insurance practice.

The enablement side of the Netherlands D1 profile is equally durable across cycles. Russian-linked no-KYC exchanges, Cryptex and PM2BTC, and a DPRK Lazarus-linked mixer successor, Sinbad.io, repeatedly located servers physically within Dutch borders notwithstanding offshore beneficial ownership and predicate criminality with no genuine Dutch nexus. The coordinated disruption of the Cryptex and PM2BTC infrastructure on 26 September 2024, involving OFAC designation, a FinCEN primary money-laundering-concern finding, and a joint seizure operation by the US Secret Service, Netherlands Police and FIOD, remains the clearest documented instance of this enabler dynamic being addressed, and it illustrates a recurring structural feature: Dutch enforcement action has depended on foreign-partner referral and identification rather than independent domestic detection of infrastructure hosted on national soil. Whether successor hosting infrastructure has emerged since that 2024 disruption has not been established across the cycles assessed to date and remains the single most consequential open item for this domain, since its resolution would materially affect whether the Netherlands enabler exposure is trending toward closure or toward simple relocation of the same physical-hosting dynamic to new infrastructure.

Taken together, the cumulative picture through this cycle is of an architecture-over-incident case study: no single enforcement action defines the Netherlands D1 posture, but the durable combination of immediate sanctions implementation, frontline port exposure at Rotterdam, EU-US-UK designation divergence, and reactive rather than proactive detection of hosted illicit crypto infrastructure defines a structurally mixed enabler-and-enforcer profile that is likely to persist as EU sanctions packages continue to expand in scope and granularity.

domain_sub_briefs · D1 · Cumulative analysis

D2 Beneficial Ownership and Corporate Transparency

Beneficial Ownership and Corporate Transparency

Continue reading

The standing structural backdrop against which any Netherlands beneficial-ownership signal must be read is the three-instrument EU AML Package. The AML Regulation, Regulation (EU) 2024/1624, is directly applicable and does not require national transposition, and is expected to become applicable from 2027, progressively superseding parts of the Dutch Wwft framework, including its customer due diligence, beneficial-ownership and enhanced due diligence provisions. The sixth Anti-Money Laundering Directive is a separate instrument requiring transposition by each member state into national law, and the Anti-Money Laundering Authority Regulation, Regulation (EU) 2024/1620, established the Anti-Money Laundering Authority itself, which has been operational since mid-2025 from its Frankfurt seat under chair Bruna Szego. AMLA is expected to progressively select a first cohort of high-risk cross-border obliged entities for direct supervision, shifting the supervisory perimeter from purely national authorities toward a hybrid EU-level regime in which national supervisors such as DNB and AFM continue to operate alongside a centralised authority. This three-instrument architecture is the durable frame within which this cycle should be read, and it is structurally improving, though the Netherlands transposition status, vehicle and deadline for the sixth directive specifically are not established this cycle and are flagged as an open item rather than assumed complete.

Against that backdrop, the Netherlands rating from the Financial Action Task Force stands at 10 Compliant, 29 Largely Compliant and 1 Partially Compliant following a September 2025 enhanced follow-up report that upgraded Recommendation 15 on virtual-asset service providers. That upgrade did not touch the Netherlands beneficial-ownership definition, which the 2022 mutual evaluation found does not capture persons exercising ultimate effective control, a gap that continues to enable the use of Dutch conduit and mailbox companies with no genuine operational presence to access favourable tax-treaty terms and layer ownership. The Netherlands is not, and has never been, listed by the Financial Action Task Force, the European Union or the United Kingdom as a high-risk jurisdiction, a status re-confirmed as of June 2026. Domestic pre-positioning ahead of AMLR harmonisation includes a EUR 3,000 national cash-payment limit that entered into force on 1 January 2025 and additional capacity added to FIU-Nederland, though the scale and timing detail on the latter is thin.

Outlook

The Netherlands beneficial-ownership posture through this cycle is one of a technically compliant framework carrying an unresolved definitional gap that predates and will likely outlast the current follow-up cycle absent a dedicated re-rating exercise. The 2027 AMLR application date and the prospective AMLA direct-supervision cohort around 2028 create the structural opportunity to close the conduit-company misuse pattern, but whether the shift from national to hybrid EU-level supervision resolves the underlying definitional gap, or merely relocates the same structural weakness to a different supervisory layer, remains an open assessment question, compounded by the unresolved 6AMLD transposition status for the Netherlands specifically.

Cumulative analysis

Beneficial Ownership and Corporate Transparency — Cumulative Analysis

The Netherlands D2 assessment through this cycle continues to rest on the same durable structural backdrop that has framed every prior reading of this domain: the EU AML Package is not a single instrument but three distinct ones, proceeding on separate timelines. The AML Regulation, Regulation (EU) 2024/1624, is directly applicable across the EU/EEA without national transposition and is expected to apply from 2027, progressively superseding national frameworks including the Dutch Wwft. The sixth Anti-Money Laundering Directive requires member-state transposition, and its specific vehicle and deadline for the Netherlands have not been established across any cycle assessed to date, a persistent open item rather than a resolved fact. The Anti-Money Laundering Authority Regulation, Regulation (EU) 2024/1620, established AMLA itself, which has been operational since mid-2025 from its Frankfurt seat under chair Bruna Szego and is expected to progressively select a first cohort of high-risk cross-border obliged entities for direct supervision, moving the supervisory perimeter from a purely national DNB/AFM model toward a hybrid EU-level regime.

Against that standing architecture, the substantive Netherlands-specific signal has been consistent across cycles: a technically strong compliance rating alongside two unresolved structural gaps. The Financial Action Task Force rates the Netherlands at 10 Compliant, 29 Largely Compliant and 1 Partially Compliant following the September 2025 enhanced follow-up report, which upgraded Recommendation 15 on virtual-asset service providers from Partially Compliant to Largely Compliant. That follow-up, addressing only the virtual-asset recommendation, left untouched the beneficial-ownership definitional finding from the 2022 mutual evaluation: the Dutch definition of beneficial ownership does not capture persons exercising ultimate effective control over legal arrangements, a gap that continues to enable Dutch BV conduit and mailbox companies with no genuine operational presence to be used for tax-treaty access and ownership layering. No beneficial-ownership-related recommendation has been re-rated since 2022, indicating the gap remains open through this cycle. The Netherlands has never appeared on the FATF grey or black lists, the EU high-risk third-country list, or the UK Money Laundering Regulations high-risk third-country advisory notice, a status re-confirmed as of June 2026, underscoring that the enabler exposure here is definitional and structural rather than a marker of overt non-compliance.

Domestic measures continue to accumulate as pre-positioning ahead of the 2027 AMLR harmonisation date: a EUR 3,000 national cash-payment limit entered into force on 1 January 2025, and FIU-Nederland has added capacity as part of the national AML strengthening programme, though the latter remains thinly evidenced on scale and timing across the cycles reviewed. A further standing evidentiary gap concerns the WODC National Risk Assessment 2023, whose full text has not been directly verified in any cycle to date, with an alternate accessible repository path identified but not yet re-pulled into the baseline.

The cumulative judgment through this cycle is that the Netherlands beneficial-ownership and corporate-transparency posture is improving at the level of the surrounding EU architecture, and stable to unresolved at the level of the specific Dutch definitional and evidentiary gaps that predate the current EU AML Package build-out. Whether the prospective AMLA direct-supervision cohort, expected around 2028, functions as the mechanism that finally closes the conduit-company misuse pattern, or simply relocates the same structural weakness from national to EU-level supervisory attention, is the central open question carried forward into subsequent cycles.

domain_sub_briefs · D2 · Cumulative analysis

D3 Enabler Jurisdictions and Professional Facilitators

Enabler Jurisdictions and Professional Facilitators

Continue reading

The Netherlands operates a twin-peaks AML/CFT supervisory architecture in which De Nederlandsche Bank handles prudential supervision and the Autoriteit Financiele Markten handles conduct supervision under the Wwft, with FIU-Nederland as the national financial intelligence unit. This structural description is foundational to assessing the Netherlands as an enabler jurisdiction under the Enabler Jurisdiction Filter, because the question is not whether a supervisory framework exists, but whether its capacity and intensity match the risk profile of the entities it oversees. On that question, the Financial Action Task Force continues to assess supervisory intensity for trust offices and corporate lawyers as insufficiently robust relative to identified risk, with unresolved legal ambiguity preventing effective implementation of preventive measures for corporate lawyers specifically. This finding predates and was not touched by the September 2025 follow-up report, which addressed only the virtual-asset recommendation.

The clearest illustration of the professional-facilitator and corporate-domicile dimension of Dutch enabler exposure is the Trafigura case. Trafigura Group, the Singapore-domiciled parent, and its Netherlands subsidiary, Trafigura Beheer B.V., together with former chief operating officer Mike Wainwright, were convicted by the Swiss Federal Criminal Court of bribery of an Angolan official spanning 2009 to 2011, with the conviction under appeal. The corporate structure sits in Amsterdam, yet criminal jeopardy, prosecution and enforcement resources were concentrated in Switzerland, Brazil and the United States, leaving Dutch authorities structurally peripheral to a bribery pattern channelled through a Dutch corporate wrapper. This is a capacity-versus-choice question in enabler-jurisdiction terms: the Netherlands functions as a low-friction domicile hub for global commodity-trading structures without itself directing or substantially detecting the underlying corruption, and enforcement action has occurred almost entirely through third-country referral rather than domestic-first investigation.

Outlook

The systemic significance of the Dutch enabler role in this domain lies less in any single case and more in the recurring pattern of corporate-domicile convenience combined with under-matched gatekeeper supervision. Whether the twin-peaks DNB/AFM model, as it is progressively absorbed into the AMLA supervisory perimeter, closes the DNFBP supervisory-intensity gap identified by the Financial Action Task Force, or whether legal ambiguity for corporate lawyers persists as a standing structural weakness independent of EU-level architecture change, is the key forward question for this domain.

Cumulative analysis

Enabler Jurisdictions and Professional Facilitators — Cumulative Analysis

The cumulative assessment of the Netherlands as an enabler jurisdiction rests on two durable and mutually reinforcing findings that have held consistent across the cycles reviewed. The first is structural: the Netherlands operates a twin-peaks AML/CFT supervisory architecture, with De Nederlandsche Bank responsible for prudential supervision and the Autoriteit Financiele Markten responsible for conduct supervision under the Wwft, supported by FIU-Nederland as the national financial intelligence unit. This is a well-resourced, institutionally mature architecture on its face, and it is precisely this combination of institutional maturity and residual under-supervision of specific gatekeeper categories that gives the Netherlands enabler profile its distinctive character. The Financial Action Task Force has consistently assessed the supervisory intensity applied to trust offices and corporate lawyers as insufficiently robust relative to identified risk, with legal ambiguity around preventive-measure obligations for corporate lawyers remaining unresolved since the 2022 mutual evaluation and untouched by the September 2025 follow-up report, which addressed only the virtual-asset recommendation. This is not a capacity failure in the DNB/AFM architecture generally; it is a targeted, persistent gap in a specific gatekeeper category, and it has proven resistant to a follow-up cycle that otherwise demonstrated the capacity of Dutch authorities to close identified deficiencies.

The second durable finding is the corporate-domicile dimension, most clearly illustrated by the Trafigura case, which has anchored this domain across cycles. Trafigura Group, the Singapore-domiciled parent, and its Netherlands subsidiary, Trafigura Beheer B.V., together with former chief operating officer Mike Wainwright, were convicted by the Swiss Federal Criminal Court of bribery of an Angolan official spanning 2009 to 2011, a conviction under appeal as of the most recent reporting. The pattern that recurs across cycles is not that the Netherlands directed or substantially concealed the underlying conduct, but that a Dutch corporate wrapper concentrated the legal and tax benefits of the domicile while the criminal jeopardy, investigation and enforcement resources were located almost entirely in Switzerland, Brazil and the United States. This is a capacity-versus-choice distinction central to enabler-jurisdiction analysis: the Netherlands does not appear to have chosen a permissive posture toward this conduct, but its corporate-domicile attractiveness for global commodity-trading structures creates a structural exposure that is disproportionate to the size of any domestic detection or enforcement effort.

Across the cycles assessed, the systemic significance of these two findings, gatekeeper under-supervision and corporate-domicile convenience, is that they are structural rather than episodic, and neither has moved materially since first identified. Whether AMLA absorption of Dutch supervisory oversight closes the DNFBP intensity gap, or whether corporate lawyers and trust offices continue to structure layered ownership arrangements under supervisory attention not matched to their risk profile, remains the central open question carried forward. Similarly, whether the Netherlands corporate-domicile role for global trading houses attracts a more proactive domestic detection posture following the Trafigura precedent, or continues to rely on third-country prosecutorial referral as the primary enforcement mechanism, is unresolved and will be a key marker to track in subsequent cycles.

domain_sub_briefs · D3 · Cumulative analysis

D4 Conflict Finance and Extractive-Industry Integrity

Conflict Finance and Extractive-Industry Integrity

Continue reading

The extractive-industry integrity signal for the Netherlands this cycle is channelled entirely through the Trafigura corporate structure, which is domiciled in Amsterdam as Trafigura Beheer B.V. while its underlying parent, Trafigura Group, sits in Singapore. The Swiss Federal Criminal Court convicted Trafigura Group, Trafigura Beheer B.V. and former chief operating officer Mike Wainwright of bribery of an Angolan official over conduct spanning 2009 to 2011, a conviction under appeal as of the most recent reporting available. In parallel, Trafigura Beheer B.V. pleaded guilty on 6 February 2025 in the United States District Court for the Southern District of Florida to conspiracy to violate the Foreign Corrupt Practices Act, arising from a decade of bribery, from 2003 to 2014, of officials at the Brazilian state oil company Petrobras, agreeing to pay over USD 126 million to the Department of Justice. A separate Brazilian civil settlement of USD 75.8 million was agreed on 31 March 2025 to resolve related civil claims, with partial credit applied against the US fine.

Read through the Conflict Finance Filter, tracing source, channel and deployment, the Angola and Brazil episodes together illustrate an extractive-sector corruption channel in which oil-sector contracts in producer states generated illicit proceeds that moved through a Dutch corporate wrapper without material Dutch-based detection or enforcement. This is a structural extractive-industry finding rather than an episodic one: three separate enforcement actions across three years, in three jurisdictions, arising from a single underlying decade-long pattern of conduct connected through one corporate structure domiciled in the Netherlands. The absence of a Dutch-led enforcement action in this sequence is itself an analytically significant data point regarding domestic detection capacity for extractive-sector corruption channelled through Dutch corporate vehicles.

Outlook

The Trafigura sequence closes out across Switzerland, Brazil and the United States with the appeal of the Swiss conviction as the only open procedural matter, but the broader question for this domain is whether the Netherlands develops any domestic-facing mechanism for detecting extractive-sector corruption laundered through Dutch corporate domiciles, given that none of the three 2025 enforcement actions originated from Dutch authorities.

Cumulative analysis

Conflict Finance and Extractive-Industry Integrity — Cumulative Analysis

The cumulative D4 record for the Netherlands is anchored entirely in the Trafigura corporate structure and the extractive-sector bribery pattern it channelled, a pattern that has now been assessed across every cycle to date without material change to the underlying facts, only to the procedural status of the enforcement actions themselves. Trafigura Beheer B.V., the Amsterdam-domiciled subsidiary of the Singapore-headquartered Trafigura Group, together with former chief operating officer Mike Wainwright, was convicted by the Swiss Federal Criminal Court of bribery of an Angolan official over conduct spanning 2009 to 2011, with that conviction under appeal as of the most recent reporting. Separately, and arising from an unrelated decade of conduct, Trafigura Beheer B.V. pleaded guilty on 6 February 2025 in the United States District Court for the Southern District of Florida to conspiracy to violate the Foreign Corrupt Practices Act in connection with bribery of officials at the Brazilian state oil company Petrobras between 2003 and 2014, agreeing to pay over USD 126 million, with a further USD 75.8 million Brazilian civil settlement following on 31 March 2025 and receiving partial credit against the US penalty.

What the cumulative record makes clear, more than any single cycle in isolation, is the consistency of the enforcement geography relative to the corporate-domicile geography. Across two distinct bribery patterns, in Angola and in Brazil, spanning a combined period of roughly two decades of underlying conduct, prosecution and financial penalty have been assessed and imposed exclusively by Swiss, Brazilian and US authorities. No enforcement action originating from Dutch authorities appears in the record for either pattern, despite the corporate vehicle through which both patterns were channelled being domiciled in Amsterdam. This is the structural extractive-industry integrity finding that the Netherlands case illustrates for FIM purposes: a producer-state corruption channel does not require the domicile jurisdiction to participate in detection or enforcement in order for that domicile to serve as the operative legal and financial wrapper for the underlying conduct.

The Trafigura sequence appears substantively concluded across the jurisdictions that did act, with the Swiss conviction appeal as the principal open procedural item carried forward. The persistent open question for the Netherlands specifically, unresolved across every cycle assessed to date, is whether any domestic mechanism exists or is being developed to detect extractive-sector corruption channelled through Dutch corporate vehicles independent of foreign prosecutorial initiative, a question the Trafigura case has not yet answered in the affirmative.

domain_sub_briefs · D4 · Cumulative analysis

D5 Crypto, Digital Assets, and Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

The Netherlands combines an active crypto-enforcement track record with a constructive supervisory posture toward the sector, and this cycle marks the closure of a significant transitional milestone. Under MiCA Article 143(3), Dutch crypto-asset service providers operating under national grandfathering had to be fully MiCA-authorised by 1 July 2026, ending the transitional legal basis under which many previously operated and shifting full AML/CFT supervisory responsibility onto AFM and DNB under the harmonised EU regime. Ahead of that deadline, the AFM published a dedicated Wwft guidance annex for crypto-asset service providers on 2 May 2025, formalising continuous customer due diligence, transaction monitoring, beneficial-ownership verification and suspicious-activity-report filing expectations for the sector, placing crypto-asset service providers on the same supervisory footing as the rest of the regulated financial sector.

This constructive regulatory posture is corroborated at the international level: the Financial Action Task Force upgraded the Netherlands Recommendation 15 rating, which specifically addresses virtual-asset service providers, from Partially Compliant to Largely Compliant in its September 2025 enhanced follow-up report, directly tied to supervisory improvements in this area. At the same time, the digital-asset channel remains a live enabler exposure. Russian-linked no-KYC exchanges, Cryptex and PM2BTC, and the DPRK Lazarus-linked mixer successor Sinbad.io repeatedly located hosting infrastructure physically in the Netherlands notwithstanding offshore beneficial ownership and predicate criminality with no genuine Dutch nexus, disrupted through a coordinated OFAC, FinCEN and FIOD action on 26 September 2024. Whether successor hosting infrastructure has since emerged is unconfirmed this cycle.

Outlook

The Netherlands crypto posture through this cycle is best read as regulatory improvement running ahead of infrastructural risk resolution: MiCA authorisation and AFM guidance close the supervisory gap for licensed entities operating openly in the Netherlands, while the physical-hosting enabler dynamic for offshore-controlled illicit infrastructure remains a distinct and unresolved exposure that operates largely outside the licensed-entity perimeter that MiCA and the Wwft guidance annex are designed to govern.

Cumulative analysis

Crypto, Digital Assets, and Financial Innovation — Cumulative Analysis

The cumulative Netherlands D5 profile through this cycle continues to combine two distinct threads that have each held consistent across prior assessment: a genuinely constructive and improving domestic regulatory posture toward licensed crypto-asset activity, and a persistent, structurally distinct exposure to offshore-controlled illicit infrastructure physically hosted on Dutch soil. On the regulatory side, the closure of the MiCA transitional window on 1 July 2026 under Article 143(3) ended the national-grandfathering legal basis under which many Dutch crypto-asset service providers previously operated, shifting full AML/CFT supervisory responsibility onto AFM and DNB under the harmonised EU regime. This closure was preceded by the AFM Wwft guidance annex for crypto-asset service providers, published 2 May 2025, which formalised continuous customer due diligence, transaction monitoring, beneficial-ownership verification and suspicious-activity-report-filing expectations ahead of the deadline, an early-mover supervisory posture relative to peer jurisdictions still working through MiCA implementation. This domestic trajectory is corroborated internationally: the Financial Action Task Force upgraded the Netherlands Recommendation 15 rating, covering virtual-asset service providers specifically, from Partially Compliant to Largely Compliant in the September 2025 enhanced follow-up report, the only recommendation re-rated in that exercise, and one directly tied to supervisory improvements in the digital-asset space.

The second thread, running in parallel rather than in tension with the first, is the recurring pattern of Dutch data-centre and hosting infrastructure being used by offshore-controlled illicit crypto operations disconnected from any genuine Dutch nexus. Russian-linked no-KYC exchanges, Cryptex and PM2BTC, and the DPRK Lazarus-linked mixer successor Sinbad.io, repeatedly located servers physically within the Netherlands notwithstanding beneficial ownership, customer base and predicate criminality situated entirely offshore. This infrastructure was disrupted through a coordinated action on 26 September 2024 involving OFAC designation, a FinCEN primary money-laundering-concern finding for PM2BTC, and a joint seizure operation by the US Secret Service, Netherlands Police and FIOD. Across the cycles assessed to date, this disruption has stood as the clearest documented instance of the pattern being addressed, but whether successor hosting infrastructure has since emerged in the Netherlands has not been established in any cycle reviewed, leaving the underlying enabler dynamic formally unresolved even where a specific instance of it has been shut down.

The cumulative judgment is that these two threads should be read as distinct rather than conflated: the Netherlands licensed crypto-asset sector is on an improving regulatory trajectory under MiCA and Wwft supervision, while the physical-hosting exposure to offshore-controlled illicit infrastructure operates largely outside that licensed perimeter and has not shown comparable improvement, since detection to date has depended on foreign-partner referral rather than Dutch-led identification. The central forward question, carried across cycles, remains whether Dutch authorities develop independent capacity to detect such infrastructure proactively, rather than relying on the same reactive pattern that resolved the 2024 Cryptex and PM2BTC case.

domain_sub_briefs · D5 · Cumulative analysis

D6 Compliance Technology and Active Defence

Compliance Technology and Active Defence

Continue reading

The clearest active-defence signal in the Netherlands this cycle is the AFM Wwft guidance annex for crypto-asset service providers, published 2 May 2025, which embeds continuous customer due diligence, transaction monitoring, beneficial-ownership verification and suspicious-activity-report filing expectations for the sector ahead of the 1 July 2026 MiCA transitional-window closure. This is a first-party supervisory action, distinguishing it from generic industry guidance, and it places crypto-asset service providers on a proactive, perpetual-KYC-oriented supervisory footing comparable to that already applied to the rest of the regulated financial sector under the twin-peaks DNB/AFM model. Alongside this, FIU-Nederland has added capacity as part of the broader national AML strengthening programme, and a EUR 3,000 national cash-payment limit entered into force on 1 January 2025, both framed as operational and control-technology pre-positioning ahead of the 2027 AMLR harmonisation date, though the specific scale and timing detail on the FIU capacity increase remains thinly evidenced.

Read against the Netherlands twin-peaks supervisory architecture, in which De Nederlandsche Bank handles prudential supervision and the AFM handles conduct supervision under the Wwft, the AFM guidance annex represents an example of a national supervisor moving proactively to extend an existing control-technology and monitoring framework onto a newly regulated sector ahead of a hard compliance deadline, rather than waiting for a deficiency to be identified through a mutual evaluation or enforcement action. This contrasts with the more reactive detection posture evident in the Netherlands D1 and D5 crypto-hosting enabler findings, where disruption has depended on foreign-partner referral.

Outlook

Whether the AFM Wwft guidance annex translates into measurable improvement in domestic detection of illicit crypto-hosting activity, closing the gap between proactive supervisory guidance for licensed entities and reactive detection of unlicensed or offshore-controlled infrastructure, is the key question to track for this domain in subsequent cycles, alongside how FIU-Nederland capacity gains are deployed operationally.

Cumulative analysis

Compliance Technology and Active Defence — Cumulative Analysis

The Netherlands D6 signal has, across the cycles assessed, centred consistently on the AFM Wwft guidance annex for crypto-asset service providers, published 2 May 2025, which remains the clearest documented instance of a Dutch supervisor proactively extending an existing control-technology and monitoring framework onto a newly regulated sector ahead of a hard compliance deadline rather than in response to an identified deficiency. The guidance annex embeds continuous customer due diligence, transaction monitoring, beneficial-ownership verification and suspicious-activity-report filing expectations for crypto-asset service providers, placing them on the same supervisory footing as the rest of the regulated financial sector operating under the twin-peaks model in which De Nederlandsche Bank handles prudential supervision and the AFM handles conduct supervision under the Wwft. This action preceded, and appears deliberately timed ahead of, the 1 July 2026 closure of the MiCA transitional authorisation window under Article 143(3), after which all Dutch crypto-asset service providers were required to be fully MiCA-authorised.

Alongside this centrepiece development, two supporting control-technology measures have been logged across cycles: a EUR 3,000 national cash-payment limit that entered into force on 1 January 2025, restricting a specific cash-based laundering vector ahead of EU-wide AMLR harmonisation, and additional capacity added to FIU-Nederland as part of the broader national AML strengthening programme, though the latter has remained thinly evidenced on scale and timing across every cycle reviewed to date, with no independent quantification available beyond the same aggregate narrative source.

The cumulative significance of this domain lies in the contrast it presents with the Netherlands D1 and D5 enabler findings. Where the physical-hosting exposure to offshore-controlled illicit crypto infrastructure has depended on foreign-partner referral for detection and disruption, the AFM guidance annex demonstrates that Dutch supervisory technology and active-defence posture can move proactively when the regulated population is clearly defined and the compliance deadline is fixed and known in advance, as with MiCA authorisation. This suggests the reactive detection pattern documented elsewhere in the Netherlands profile may be less a function of institutional capacity limits and more a function of the specific difficulty of detecting infrastructure operated by entities with no genuine Dutch beneficial-ownership or customer nexus, a harder detection problem than supervising a defined, licensed population.

The open question carried forward across cycles is whether the AFM guidance annex, once its expectations are operational for a full supervisory cycle, produces measurable improvement in domestic detection of illicit crypto-hosting activity of the kind documented in the Cryptex, PM2BTC and Sinbad.io cases, or whether the active-defence uplift remains confined to the licensed, MiCA-authorised population while the physical-hosting enabler dynamic for unlicensed or offshore-controlled infrastructure continues on its separate, largely foreign-referral-dependent detection track.

domain_sub_briefs · D6 · Cumulative analysis
Regulatory horizon
In Force1 Jul 2026 · ±quarter

MiCA transitional window closes for Dutch crypto-asset service providers

Dutch CASPs operating under national grandfathering must be fully MiCA-authorised; the transitional legal basis under Article 143(3) MiCA ends, shifting full AML/CFT supervisory responsibility to AFM/DNB under the harmonised EU regime.
In Force Pending2026-Q4 · ±half_year

AMLA Work Programme and supervisory methodology build-out

AMLA continues to build out its supervisory methodology and first work programme from its Frankfurt seat under chair Bruna Szego, following mid-2025 operational stand-up.
source not collected
Proposed2027 · ±multi_year

FATF Netherlands 5th round mutual evaluation onsite scheduling

Netherlands remains in FATF regular follow-up after the September 2025 report addressed only R.15; the remaining Partially Compliant recommendation awaits resolution, with 5th round onsite scheduling not yet published.
source not collected
Adopted1 Jan 2027 · ±year

AMLR direct applicability and 6AMLD transposition deadlines

The AML Regulation (AMLR) becomes directly applicable and 6AMLD transposition deadlines bite across EU/EEA Member States, superseding parts of national frameworks including the Dutch Wwft.
source not collected
Adopted2028 · ±multi_year

AMLA direct supervision of selected high-risk obliged entities

AMLA begins direct supervision of a first cohort of high-risk cross-border obliged entities, shifting supervisory perimeter from purely national authorities (DNB/AFM) to a hybrid EU-level regime.
source not collected
5 dated · 3 pending date · baseline fim-2026-07-08
Role action cards
MLROHigh

Netherlands beneficial-ownership definitional gap and DNFBP supervisory-intensity deficiency remain unresolved alongside a formalised CASP due-diligence and SAR-filing framework.

The persistent gap in the Dutch beneficial-owner definition and in supervisory intensity for trust offices and corporate lawyers sustains elevated red-flag salience for conduit-company and layered-ownership structures, while the AFM Wwft guidance annex formalises SAR-filing and beneficial-ownership-verification expectations specifically for crypto-asset service providers ahead of the MiCA deadline. The EUR 3,000 cash-payment limit and added FIU-Nederland capacity are relevant contextual control measures for domestic reporting thresholds.

6 evidence refs
ComplianceHigh

Netherlands FATF rating improves on VASP supervision while the AMLR and MiCA timelines compress the window for domestic framework alignment.

The FATF upgrade on Recommendation 15 and the AFM Wwft guidance annex signal an improving control-framework baseline for the crypto sector, while the MiCA transitional-window closure and the 2027 AMLR application date require obliged-entity policy frameworks in the Netherlands to be assessed for readiness against a directly applicable EU rulebook that will progressively supersede the Wwft.

5 evidence refs
LegalHigh

Trafigura enforcement across Switzerland, Brazil and the United States, and EU-only sanctions measures with no OFAC or OFSI equivalent, raise distinct liability and regime-divergence exposures.

The Trafigura conviction, FCPA guilty plea and Brazilian civil settlement demonstrate that liability exposure for a Dutch-domiciled corporate structure can crystallise entirely in third-country fora, while the EU-only crypto-provider sanctions and the Karimun port listing under the 20th sanctions package create a divergence from OFAC and OFSI designations that has direct sanctions-nexus and client-instruction implications for entities operating across regimes.

6 evidence refs
BoardHigh

A Netherlands-domiciled subsidiary of a major commodity trader was convicted and pleaded guilty across three jurisdictions, while EU-level supervisory architecture continues to expand toward direct oversight.

The Trafigura Angola conviction, the US FCPA guilty plea and the Brazilian civil settlement represent material reputational and financial-crime risk crystallising through a Dutch corporate domicile, a governance-relevant pattern given AMLA is now operational and the AML Regulation is expected to apply from 2027, both strategic-level regulatory developments with implications for group-wide compliance investment.

5 evidence refs
CTOHigh

The MiCA transitional window for Dutch crypto-asset service providers has closed and physical-hosting infrastructure risk for offshore-controlled crypto laundering remains an open technical exposure.

The FATF upgrade on the virtual-asset recommendation and the AFM Wwft guidance annex reflect an improving technical-supervisory environment for licensed platforms, but the recurring pattern of offshore-controlled exchanges and mixers physically hosting infrastructure in the Netherlands, disrupted mainly through foreign-partner referral, represents a distinct architecture-level technical evasion vector not addressed by MiCA authorisation of licensed entities alone.

4 evidence refs
RiskHigh

Conduit-company, DNFBP-supervision and offshore-hosting exposures concentrate the Netherlands residual risk profile, alongside a sanctions-regime divergence signal with cross-monitor relevance.

The unresolved beneficial-ownership definitional gap, the under-supervised trust-office and corporate-lawyer gatekeeper category, and the repeated physical hosting of offshore-controlled crypto-laundering infrastructure together concentrate the Netherlands exposure profile in a small number of structural risk vectors, while the EU-only sanctions divergence on crypto providers and third-country ports is a cross-monitor escalation signal relevant to sanctions-regime tracking.

4 evidence refs
OperationsHigh

New AFM CASP guidance, a national cash-payment limit and expanded EU sanctions listings introduce concrete screening and monitoring workflow implications.

The AFM Wwft guidance annex sets specific due-diligence, monitoring and SAR-filing expectations for crypto-asset service providers, the EUR 3,000 cash-payment limit and added FIU-Nederland capacity affect domestic reporting workflows, and the expanded shadow-fleet and crypto-provider listings under the 19th and 20th EU sanctions packages require screening-list updates directly applicable in the Netherlands with no transposition delay.

5 evidence refs
AuditHigh

Persistent FATF-identified gaps in beneficial-ownership definition and DNFBP supervision, alongside an unverified national risk assessment source, indicate documentation and control-testing scope items.

The Netherlands FATF rating of 10 Compliant, 29 Largely Compliant and 1 Partially Compliant, the unresolved beneficial-ownership and DNFBP-supervision findings, and the outstanding access gap on the WODC National Risk Assessment 2023 collectively indicate areas where control-testing scope and evidentiary documentation should be reviewed for currency, alongside confirmation that the Netherlands remains outside FATF, EU and UK high-risk listings.

5 evidence refs
Decision lens
MLRO

Netherlands beneficial-ownership definitional gap and DNFBP supervisory-intensity deficiency remain unresolved alongside a formalised CASP due-diligence and SAR-filing framework.

Compliance

Netherlands FATF rating improves on VASP supervision while the AMLR and MiCA timelines compress the window for domestic framework alignment.

Legal

Trafigura enforcement across Switzerland, Brazil and the United States, and EU-only sanctions measures with no OFAC or OFSI equivalent, raise distinct liability and regime-divergence exposures.

Board

A Netherlands-domiciled subsidiary of a major commodity trader was convicted and pleaded guilty across three jurisdictions, while EU-level supervisory architecture continues to expand toward direct oversight.

CTO

The MiCA transitional window for Dutch crypto-asset service providers has closed and physical-hosting infrastructure risk for offshore-controlled crypto laundering remains an open technical exposure.

Risk

Conduit-company, DNFBP-supervision and offshore-hosting exposures concentrate the Netherlands residual risk profile, alongside a sanctions-regime divergence signal with cross-monitor relevance.

Operations

New AFM CASP guidance, a national cash-payment limit and expanded EU sanctions listings introduce concrete screening and monitoring workflow implications.

Audit

Persistent FATF-identified gaps in beneficial-ownership definition and DNFBP supervision, alongside an unverified national risk assessment source, indicate documentation and control-testing scope items.

Shared evidence: 16 refs
Scenario sketches

AMLA direct-supervision transition and the cross-border obliged-entity perimeter

As the AML Regulation becomes directly applicable and AMLA progresses toward selecting a first cohort of high-risk cross-border obliged entities for direct supervision, one illustrative structural question is how the shift from a purely national DNB and AFM supervisory model to a hybrid EU-level regime could reshape both compliance posture and evasion strategy for entities that currently structure their EU footprint around national supervisory boundaries. An entity previously calibrating its cross-border presence to remain within a single national supervisory perimeter may, under a hybrid regime, find that structural characteristic itself becomes a selection criterion for direct AMLA oversight. This is offered as an illustrative structural orientation on the AMLA transition and its supervisory-perimeter implications, not as a description of any confirmed selection outcome.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Physical-hosting enablement surviving node disruption

The disruption of a specific instance of offshore-controlled crypto-laundering infrastructure hosted in a jurisdiction with strong data-centre availability illustrates a general structural pattern worth orienting toward: physical-hosting enablement of this kind is typically a property of infrastructure availability and cost rather than of any single operator, and disruption of one hosted instance does not by itself establish whether the underlying enabling condition, low-friction hosting disconnected from beneficial-ownership scrutiny, has been addressed. This is an illustrative structural orientation on how enabler exposure of this kind can persist across successive operator identities, not a claim about any specific successor infrastructure.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion ArchitectureescalatingEU 15 June 2026 designations (81 new listings) and first sectoral ban on Russian crypto-asset service providers.
T2 · EU AML Package / AMLAincrementalNL Wwft cash-limit and FIU-Nederland transaction-hold power (Art. 17a Wwft, from 1 July 2026) pre-empt the AMLR/Implementatiewet still pending national consultation.
T3 · FATF Grey Listmaterial_changeKuwait and Papua New Guinea newly added February 2026; Cambodia faces active re-listing risk.
T4 · Beneficial-Ownership Register StatusincrementalNL UBO register continues under Wwft/AMLD5-derived framework pending AMLD6-driven national register standards via the Implementatiewet.
T5 · Crypto & Digital-Asset Integritymaterial_changeEU-wide MiCA transitional period ended 1 July 2026; Huione Group successor entities targeted for further US financial-system severance.
T6 · Sanctions Regime DivergenceincrementalFive banks in China/Tajikistan and 11 vessels delisted from the EU's 20th package for behavioural change, not necessarily mirrored by US/UK autonomous lists.
Registers

Enforcement actions

  • Trafigura and its former chief operating officer were convicted on bribery charges relating to payments to an Angolan official between 2009-2011, the first conviction of a senior commodity-trading executive for corruption; the Amsterdam-domiciled parent entity itself was also convicted for inadequate internal controls. 31 Jan 2025
  • Trafigura agreed to a civil settlement resolving Brazilian bribery-related cases dating to at least 2020, following a 2024 guilty plea to a decade of bribery in Brazil entered in a Miami federal court. 31 Mar 2025
  • AFM published a dedicated annex to its Wwft guidelines specifically for CASPs, embedding EBA-aligned expectations on customer due diligence, transaction monitoring, beneficial-ownership verification and suspicious-activity reporting into the same supervisory footing as the rest of the regulated financial sector. 2 May 2025
  • FATF adopted the 1st Enhanced Follow-Up Report on the Netherlands, re-rating Recommendation 15 (new technologies/VASPs) from Partially Compliant to Largely Compliant following technical-compliance improvements since the 2022 mutual evaluation. 23 Sep 2025

Sanctions changes

  • EU 19th sanctions package against Russia introduced a phased LNG import ban, closed exemptions for Rosneft/Gazprom Neft transactions, added 117 shadow-fleet vessel listings (total 557) and imposed the EU's first-ever sanctions on crypto providers, targeting the Russian-state-linked A7A5 stablecoin ecosystem — all directly applicable in the Netherlands as an EU member state, including at Rotterdam port and via Dutch-domiciled trading/financial intermediaries. 23 Oct 2025
  • EU 20th sanctions package added 46 further shadow-fleet vessel listings (bringing the EU total to 632), delisted 11 vessels returning to compliance, introduced a mandatory 'no Russia' clause for EU sellers, a scrapping clause for shadow-fleet exit, and listed Murmansk, Tuapse and the Karimun Oil Terminal (Indonesia) as ports linked to shadow-fleet circumvention. 23 Apr 2026

Regulatory horizon (register)

  • AML Regulation (AMLR, Reg (EU) 2024/1624) becomes directly applicable
  • MiCA transitional window for Dutch CASPs closes
  • AMLA direct/indirect supervisory perimeter selection affecting Dutch entities

Active schemes

  • [HIGH] Netherlands as physical infrastructure host for Russian/DPRK-linked crypto laundering
  • Netherlands as domicile hub for global commodity-trading corporate structures
  • Dutch BV conduit/'mailbox' companies with no real presence
  • Trust offices and corporate lawyers as under-supervised gatekeepers
Sources
  1. FATF (multilateral first-party mutual evaluation of the Netherlands)
  2. FATF
  3. FATF
  4. Council of the European Union
  5. European Commission
  6. TRM Labs
  7. Chainalysis
  8. Bloomberg
  9. ICIJ Offshore Leaks Database
  10. OCCRP
Coverage gaps
FATF's 2022 mutual evaluation and 2025 follow-up continue to…
FATF's 2022 mutual evaluation and 2025 follow-up continue to flag that the Netherlands has not fully closed gaps around preventing misuse of legal persons and ensuring adequate, accurate and current beneficial-ownership information, including a beneficial-ownership definition that historically failed to capture persons with ultimate effective control over legal arrangements.
FATF assessors found the frequency, scope and intensity of A…
FATF assessors found the frequency, scope and intensity of AML/CFT supervision and monitoring for DNFBPs (including trust offices and corporate lawyers) insufficiently robust relative to identified risk, with legal ambiguities around preventive-measure obligations for corporate lawyers left unresolved.
The seed-designated authoritative NRA source (WODC — Dutch N…
The seed-designated authoritative NRA source (WODC — Dutch National Risk Assessment on Money Laundering 2023) returned a 403 response on automated fetch attempt during this baseline run, consistent with the seed's own bot-block hint, preventing verbatim citation of its content in this baseline.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.