Source: OJ L, 2025/305, 31.3.2025

Current language: EN

Article 12 Custody and administration policy


Summary What does Article 12 of the RTS on CASP authorisation say?

This article applies specifically to applicants intending to provide custody and administration of crypto-assets on behalf of clients, and sets out what information they must submit to the competent authority as part of their authorisation application.

It builds directly on Article 62(2)(m) of MiCA (Regulation (EU) 2023/1114).

The article covers the full scope of a custody operation: from the standard client agreement and custody policy, through to risk management, client asset identification, loss prevention, and the exercise of client rights.

Notably, it also addresses scenarios where custody functions are delegated to a third party, requiring disclosure of the delegate's identity, the scope of delegation, and oversight arrangements.

Important points:

  • Provide the competent authority with your full custody and administration policy, including how operational and ICT risks are identified and managed, even where custody is outsourced to a third party.
  • Submit documentation on how client crypto-assets and means of access are identified, segregated, and returned, along with arrangements to minimise the risk of loss.
  • Where custody functions are delegated, disclose the identity and regulatory status of all delegates and sub-delegates, the functions delegated, any conflicts of interest arising, and how you intend to supervise those delegations.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

For the purposes of Article 62(2), point (m), of Regulation (EU) 2023/1114, applicants that intend to provide custody and administration of crypto-assets on behalf of clients shall provide to the competent authority all of the following information:

  1. a description of the arrangements linked to the type of custody offered to clients, a copy of the applicant’s standard agreement for the custody and administration of crypto-assets on behalf of clients pursuant to Article 75(1) of Regulation (EU) 2023/1114and a copy of the summary of the custody policy made available to clients in accordance with Article 75(3) of Regulation (EU) 2023/1114;

  2. the applicant’s custody and administration policy, including a description of identified sources of operational and ICT risks for the safekeeping and control of the crypto-assets or the means of access to the crypto-assets of clients, together with a description of:

    1. the policies and procedures and a description of the arrangements to comply with Article 75(8) of Regulation (EU) 2023/1114;

    2. the policies and procedures, and a description of the systems and controls to manage operational and ICT risks, including where the custody and administration of crypto-assets on behalf of clients is outsourced to a third party;

    3. the policies and procedures relating to, and a description of, the systems ensuring the exercise of the rights attached to the crypto-assets by the clients;

    4. the procedures and a description of the systems ensuring the return of crypto-assets or the means of access to the clients;

  3. information on how the crypto-assets and the means of access to the crypto-assets of the clients are identified;

  4. information on arrangements to minimise the risk of loss of crypto-assets or of means of access to crypto-assets;

  5. where the crypto-asset service provider has delegated the provision of custody and administration of crypto-assets on behalf of clients to a third-party:

    1. information on the identity of any third-party providing the custody and administration of crypto-assets and its status in accordance with Article 59 or Article 60 of Regulation (EU) 2023/1114;

    2. a description of any functions relating to the custody and administration of crypto-assets delegated by the crypto-asset service provider, the list of any delegates and sub-delegates, as applicable, and any conflicts of interest that could arise from such a delegation;

    3. a description of how the applicant intends to supervise the delegations or sub-delegations.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod