Source: OJ L, 2025/305, 31.3.2025

Current language: EN

Article 10 Segregation and safekeeping of clients’ crypto-assets and funds


Summary What does Article 10 of the RTS on CASP authorisation say?

This article addresses the segregation of client assets, requiring applicants that intend to hold clients' crypto-assets, means of access to those crypto-assets, or client funds to provide the competent authority with a detailed account of how they will keep those assets separate from their own.

It builds directly on Article 70 of Regulation (EU) 2023/1114, translating that provision's requirements into concrete disclosure obligations at the authorisation stage.

The article covers the full picture of segregation: wallet separation, cryptographic key management, handling of omnibus accounts, and the depositing of client funds with a central bank or credit institution.

It also requires applicants to explain how they will communicate their segregation arrangements to clients in plain language.

A specific carve-out applies to applicants that are already authorised as electronic money institutions or payment institutions, who need only provide information on the segregation of clients' crypto-assets, not their funds.

Important points:

  • Provide a detailed description of your procedures for segregating clients' crypto-assets and funds from your own, covering wallet separation, cryptographic key safeguarding, and the handling of omnibus accounts.
  • Clients' funds (other than e-money tokens) must be deposited with a central bank or credit institution by the end of the business day following receipt, and held in a separately identifiable account.
  • If you are an electronic money institution or payment institution, your disclosure obligation under this article is limited to the segregation of clients' crypto-assets only.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. For the purposes of Article 62(2), point (k), of Regulation (EU) 2023/1114, applicants that intend to hold crypto-assets belonging to clients or the means of access to such crypto-assets, or clientsfunds, other than e-money tokens, shall provide to the competent authority a detailed description of their procedures for the segregation of clients’ crypto assets and funds, including all of the following:

      1. how the applicant ensures that:

        1. clientsfunds are not used for its own account;

        2. crypto-assets belonging to the clients are not used for its own account;

        3. the wallets holding clientscrypto-assets are different from the applicant’s own wallets;

      2. a detailed description of the approval system for cryptographic keys and safeguarding of cryptographic keys, including multi-signature wallets;

      3. how the applicant segregates clientscrypto-assets, including from other clientscrypto-assets where wallets contain crypto-assets of more than one client (omnibus accounts);

      4. a description of the procedure ensuring that clientsfunds, other than e-money tokens, are deposited with a central bank or a credit institution by the end of the business day following the day on which those funds were received and held in an account separately identifiable from any accounts used to hold funds belonging to the applicant;

      5. where the applicant does not intend to deposit funds with the relevant central bank, which factors the applicant takes into account to select the credit institutions with which to deposit clientsfunds, including the applicant’s diversification policy, where available, and the frequency of review of the selection of credit institutions with which to deposit clientsfunds;

      6. how the applicant ensures that clients are informed in clear, concise and non-technical language about the key aspects of the applicant’s systems, policies and procedures to comply with Article 70(1), (2) and (3) of Regulation (EU) 2023/1114.

    1. In accordance with Article 70(5) of Regulation (EU) 2023/1114, crypto-asset service providers that are electronic money institutions or payment institutions shall only provide the information referred to in paragraph 1 of this Article in relation to the segregation of clientscrypto-assets.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod