Order No. 465: the official list of red flags that stop a transfer

Banks do not invent risk criteria, they are listed in Ministry of Finance Order No. 465, in force since 24 February 2023. It names both the classic P2P pattern and settlements in virtual assets.

The criteria banks use to stop a transfer were not invented by banks. They are listed in Ministry of Finance Order No. 465 of 28 December 2022, Criteria of Money Laundering Risk, registered with the Ministry of Justice on 9 February 2023 under No. 258/39314 and in force since 24 February 2023. That list expressly describes the classic pattern of P2P operations, and virtual assets are mentioned separately.

So the feeling that the bank is picking on you personally is almost always wrong. The bank is checking your behaviour against a list that is the same across the market, and it has no freedom to ignore it.

Below: what this document is, how a bank learns about your operation in the first place, which criteria catch P2P specifically, and what to do when your ordinary life happens to match a criterion. We are an exchange service, not lawyers: we summarise what the documents say and do not undertake to predict any particular bank's decision.

What this document is and since when it applies

Order No. 465 is the official list of criteria of the risk of laundering criminally obtained income. The Ministry of Finance approved it on 28 December 2022, the Ministry of Justice registered it on 9 February 2023, and it took effect on 24 February 2023. It replaced the earlier Order No. 584 of 2016.

The document is addressed not to clients but to primary financial monitoring entities: banks, payment institutions and other participants in the system. It sets a shared frame, a set of situations they are obliged to take into account when assessing a client's risk.

We quote nothing from the order directly: the verbatim text has not been checked against the primary source, so what follows is a summary of the content rather than the document's wording. The order itself is published in the legislation register under identifier z0258-23.

How a bank learns about your operation at all

Nobody reads your payments by hand. Operations pass through automated monitoring systems that check every transaction against a set of scenarios: amount, type, counterparty, frequency, balance, the account's usual behaviour.

A scenario firing does not mean suspicion. It means the operation has joined a review queue. A compliance officer then looks at it and decides whether it diverges from the client's profile and whether documents need to be requested.

Two practical points follow. First, the system's attention is drawn by a pattern over a period, not by a single payment. Second, an empty or odd payment description is no trifle: often it is the only explanation the bank sees at all.

Which criteria on the list catch P2P specifically

Four criteria in the order describe exactly the picture created by active crypto trading between individuals. The first is payments received from unrelated or unknown third parties. That is literally a description of a P2P deal, where the money is sent by a buyer you do not know.

The second is the use of an account as a pass-through: funds arrive and move straight on. The third is repeated operations whose character gives grounds to believe their purpose is to evade mandatory financial monitoring procedures. The fourth is the splitting of operations to circumvent thresholds.

It turns out that frequent, uniform incoming payments from different senders are not one bank's whim but a criterion from a Ministry of Finance order. The person may be breaking nothing: the criterion describes the shape of operations, not guilt.

What the list says about virtual assets

Cryptocurrency is mentioned in the criteria directly, which is rare for a regulatory document of this level. A situation is treated as risky when a client insists on settling exclusively or predominantly in virtual assets.

The second scenario is operations with virtual assets without evident legal, tax, commercial or other lawful reasons. The key phrase is without evident reasons: the criterion is triggered not by the fact of holding cryptocurrency but by the absence of a clear explanation.

For a reader this means one thing. Explanations and documents are not a formality or a gesture of goodwill, they are precisely what the criterion asks for in substance. We break down the documents behind crypto income in a separate article on source of funds.

Why the criteria are so broad

The criteria describe the shape of an operation, not the intent. You cannot tell a cryptocurrency sale from a front-man card scheme by the payment flow alone: from the outside they are identical incoming payments from different people onto one card.

So the list deliberately covers a wide range of situations. The state builds in redundancy on the assumption that checks and client explanations will clear the false positives. The price of that approach is that law-abiding people regularly land in the sample.

You cannot negotiate your way out of this, but you can work with it. A broad criterion filters by shape and distinguishes by explanation, and the explanation is the only part the client genuinely influences.

The criteria apply in combination, not one by one

A single match means almost nothing. Everyone gets a transfer from a third party: a friend repaying a debt, a relative sending money, a buyer paying for a classified ad. If every such payment were stopped, the banking system would seize up.

What matters is the combination. Incoming payments from various unrelated senders that move straight on, recur every week and do not match the declared income are no longer one criterion but four at once. It is the density of matches that moves an operation out of background noise and into the review queue.

So the question of whether you fall under a criterion is badly framed. The better question is how many criteria coincide in your case and whether each of them has a clear explanation.

What a client profile is and what it consists of

A profile is the bank's picture of how you normally use your account. It has two parts: what you declared when opening the account, and how the account has actually behaved during the relationship.

The declared part covers occupation, source of income, expected volume of operations and the purpose of opening the account. The factual part covers the amounts and frequency of incoming payments, the range of counterparties, payment descriptions, balances and the geography of operations.

Monitoring fires on discrepancies between those two parts. Someone stated a salary of forty thousand and three hundred arrives every month from twenty different senders: the question arises not because of the amount but because of the mismatch.

Hence the single most effective action available to a client: keep the declared part current. If your job changed or a new source of income appeared, update the questionnaire yourself rather than waiting for a request.

What the risk-based approach means in plain terms

The risk-based approach means that not everyone is checked equally, but in proportion to their assessed risk. The bank assigns the client a risk level, and that level determines how many questions and documents will be needed.

The level depends on the whole picture: declared income, occupation, the nature of operations, counterparties' countries, matches with the criteria in Order No. 465. The assessment is dynamic, it moves with the account's behaviour rather than being assigned once and for all.

Hence the answer to why it goes through for a friend but not for you. Because you have different profiles and different risk levels at different banks. This is not a public rating: you will not see your level in the app, the bank does not disclose it.

What to do if your ordinary life matches a criterion

The situation is a common one. A freelancer receives payments from different clients, a tutor from different students, a marketplace seller from different buyers. Formally these are payments from unrelated third parties, even though there is no scheme at all.

There is one workable strategy: make the picture explainable in advance. Meaningful payment descriptions, saved correspondence or contracts with clients, declared income, an up-to-date questionnaire at the bank. It is not a guarantee, it is what turns a request into a short exchange of letters instead of a long review.

The second element is consistency. A profile that has looked the same for three years raises fewer questions than an account whose character changed abruptly. If the nature of your income really has changed, it makes sense to update the questionnaire yourself rather than wait for a request.

The third is separating flows. Keeping work income and personal operations on different accounts is not legally required, but it noticeably simplifies the explanation when the bank asks you to show the source of a particular amount.

Why an honest person falls under a criterion

A risk criterion is not an accusation. It describes a situation in which a question should be asked, and says nothing about what the answer will be. Falling under a criterion means exactly one thing: your operation will be looked at more closely.

The reason is simple. Laundering schemes deliberately mimic ordinary behaviour, so any criterion capable of catching them inevitably catches lawful operations of the same shape.

In practice this changes the tone of the conversation with the bank. Answering a request from the position of being under suspicion is counterproductive: more often it means the system has seen a shape it has no explanation for yet. Explanations and documents close that gap.

What an operation that does not conflict with the criteria looks like

The simplest description is an operation where all three answers are visible at once: who the sender is, what the payment is for and where they got the money. When those three things are clear from the transaction and the account history, there is nothing for the criteria to catch on.

The signs of such an operation: a clear payment description instead of an empty field, a counterparty your activity explains, an amount proportionate to your declared income, and funds that do not leave the account the same minute.

The flip side is worth seeing too. Pass-through movement is the main amplifier of any criterion: money that lingers on an account reads differently from money that passes through in a few minutes.

This is no guarantee, and we will not promise one. But an operation where all three answers are visible in advance usually needs no separate explanation at all.

What this means for an ordinary cryptocurrency exchange

Someone who sells cryptocurrency via P2P a few times a month matches several criteria at once: incoming payments from unrelated third parties, fast onward movement of funds through the account, regularity of uniform operations. There is no breach in this, but there is more to explain.

Here we state our own interest plainly: we are an exchange service, and in our case the counterparty is a company, not a stranger from a classified ad. That does not make the operation invisible to monitoring and does not exempt you from the bank's questions, it simply means the source of funds is described by one counterparty rather than a dozen random senders.

We will not promise that a transfer through an exchange service is certain to go through. The decision in each case rests with the bank, and no exchange method changes that.

Why the advice to split the amount is harmful

Splitting operations is a risk criterion in its own right, from the very same Order No. 465. So it is not a way to avoid attention but a way to add one more reason for it: the question about the source of funds is joined by a question about the purpose of the splitting.

Right next to it on the list sits another criterion, repeated operations whose character gives grounds to believe their purpose is to evade mandatory financial monitoring procedures. It covers even cases where no single operation breaches anything.

Automated systems spot series better than isolated payments: the total over a period and the number of transactions are basic parameters of any scenario. We do not give advice on avoiding checks as a matter of principle, and this particular piece of advice also worsens the position of anyone who believes it.

The National Bank's draft resolution of July 2026

On 21 July 2026 the National Bank published a draft resolution with 16 indicators of suspicious payments and three risk levels: low passes automatically, medium requires confirmation, high stops the operation. The indicators include more than 10 top-ups within 60 minutes, minimal balances alongside large turnover, fast onward movement of funds, and one-to-many and many-to-one transfers.

Public consultation ran until 31 July 2026, and 90 days are allowed for adaptation after adoption. We have not verified whether the document had been adopted as of August 2026: the regulator's site is closed to automated requests. So these indicators cannot be called a rule in force, this is a draft.

And one point of precision that matters for our topic: the draft mentions neither P2P nor cryptocurrency. Texts that attribute such rules to it are adding something that is not there.

What the order does not contain: any ban

Order No. 465 contains no ban on P2P transfers or on cryptocurrency operations. It is a list of risk criteria, not a list of prohibited actions. Falling under a criterion means heightened attention, not a breach.

Nor is there any separate official warning from the National Bank or the State Financial Monitoring Service about P2P specifically. Banks' objections rest not on a rule saying P2P is prohibited, but on the general risk-based approach. The wording here should be careful: the absence of a ban is not a permission, only the absence of an explicit rule.

There is one practical conclusion from all of this. Knowing the list of criteria, you can predict which questions will arise and prepare the answers in advance. What to do next, once an operation has already been stopped, is covered in the article on financial monitoring.

Author: MW ExchangeUpdated
01

Read next