Source: OJ L 150, 9.6.2023, pp. 40–205

Current language: EN

Article 73 Outsourcing


Summary What does Article 73 of the MiCA regulation say?

This article governs how crypto-asset service providers (CASPs) must manage the outsourcing of operational functions to third parties.

The core principle is that outsourcing does not relieve a CASP of any of its regulatory responsibilities — it remains fully accountable for its obligations under Title V regardless of what has been delegated externally.

The article sets out a series of conditions that must be maintained at all times when outsourcing, covering areas such as supervisory access, data protection, retention of internal expertise, and the preservation of client relationships.

It also requires CASPs to have a formal outsourcing policy, written agreements with termination rights, and to make information available to competent authorities on request.

Important points:

  • Maintain full responsibility for all regulatory obligations under Title V — outsourcing operational functions to third parties does not transfer or reduce that accountability.
  • Establish a written outsourcing policy covering contingency plans and exit strategies, and ensure all outsourcing arrangements are governed by written agreements that include the right to terminate.
  • Both CASPs and their third-party providers must make all relevant information available to competent authorities upon request to allow assessment of compliance.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Crypto-asset service providers that outsource services or activities to third parties for the performance of operational functions shall take all reasonable steps to avoid additional operational risk. They shall remain fully responsible for discharging all of their obligations pursuant to this Title and shall ensure at all times that the following conditions are met:

      1. outsourcing does not result in the delegation of the responsibility of the crypto-asset service providers;

      2. outsourcing does not alter the relationship between the crypto-asset service providers and their clients, nor the obligations of the crypto-asset service providers towards their clients;

      3. outsourcing does not alter the conditions for the authorisation of the crypto-asset service providers;

      4. third parties involved in the outsourcing cooperate with the competent authority of the crypto-asset service providershome Member State and the outsourcing does not prevent the exercise of the supervisory functions of competent authorities, including on-site access to acquire any relevant information needed to fulfil those functions;

      5. crypto-asset service providers retain the expertise and resources necessary for evaluating the quality of the services provided, for supervising the outsourced services effectively and for managing the risks associated with the outsourcing on an ongoing basis;

      6. crypto-asset service providers have direct access to the relevant information of the outsourced services;

      7. crypto-asset service providers ensure that third parties involved in the outsourcing meet the data protection standards of the Union.

    2. For the purposes of point (g) of the first subparagraph, crypto-asset service providers are responsible for ensuring that the data protection standards are set out in the written agreements referred to in paragraph 3.

    1. Crypto-asset service providers shall have a policy on their outsourcing, including on contingency plans and exit strategies, taking into account the scale, the nature and the range of crypto-asset services provided.

    1. Crypto-asset service providers shall define in a written agreement their rights and obligations and those of the third parties to which they are outsourcing services or activities. Outsourcing agreements shall give crypto-asset service providers the right to terminate those agreements.

    1. Crypto-asset service providers and third parties shall, upon request, make available to the competent authorities and other relevant authorities all information necessary to enable those authorities to assess compliance of the outsourced activities with the requirements of this Title.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod