Source: OJ L, 2025/305, 31.3.2025Current language: EN
- Markets in crypto-assets
Crypto-asset service provider
- RTS on CASP authorisation
Article 12 Custody and administration policy
Summary What does Article 12 of the RTS on CASP authorisation say?
This article applies specifically to applicants intending to provide custody and administration of crypto-assets on behalf of clients, and sets out what information they must submit to the competent authority as part of their authorisation application.
It builds directly on Article 62(2)(m) of MiCA (Regulation (EU) 2023/1114).
The article covers the full scope of a custody operation: from the standard client agreement and custody policy, through to risk management, client asset identification, loss prevention, and the exercise of client rights.
Notably, it also addresses scenarios where custody functions are delegated to a third party, requiring disclosure of the delegate's identity, the scope of delegation, and oversight arrangements.
Important points:
- Provide the competent authority with your full custody and administration policy, including how operational and ICT risks are identified and managed, even where custody is outsourced to a third party.
- Submit documentation on how client crypto-assets and means of access are identified, segregated, and returned, along with arrangements to minimise the risk of loss.
- Where custody functions are delegated, disclose the identity and regulatory status of all delegates and sub-delegates, the functions delegated, any conflicts of interest arising, and how you intend to supervise those delegations.
Springlex's summary of the article, a reading aid, not a substitute for the legal text.
For the purposes of Article 62(2), point (m), of Regulation (EU) 2023/1114, applicants that intend to provide custody and administration of crypto-assets on behalf of clients shall provide to the competent authority all of the following information:
a description of the arrangements linked to the type of custody offered to clients, a copy of the applicant’s standard agreement for the custody and administration of crypto-assets on behalf of clients pursuant to Article 75(1) of Regulation (EU) 2023/1114and a copy of the summary of the custody policy made available to clients in accordance with Article 75(3) of Regulation (EU) 2023/1114;
the applicant’s custody and administration policy, including a description of identified sources of operational and ICT risks for the safekeeping and control of the crypto-assets or the means of access to the crypto-assets of clients, together with a description of:
the policies and procedures and a description of the arrangements to comply with Article 75(8) of Regulation (EU) 2023/1114;
the policies and procedures, and a description of the systems and controls to manage operational and ICT risks, including where the custody and administration of crypto-assets on behalf of clients is outsourced to a third party;
the policies and procedures relating to, and a description of, the systems ensuring the exercise of the rights attached to the crypto-assets by the clients;
the procedures and a description of the systems ensuring the return of crypto-assets or the means of access to the clients;
information on how the crypto-assets and the means of access to the crypto-assets of the clients are identified;
information on arrangements to minimise the risk of loss of crypto-assets or of means of access to crypto-assets;
where the crypto-asset service provider has delegated the provision of custody and administration of crypto-assets on behalf of clients to a third-party:
information on the identity of any third-party providing the custody and administration of crypto-assets and its status in accordance with Article 59 or Article 60 of Regulation (EU) 2023/1114;
a description of any functions relating to the custody and administration of crypto-assets delegated by the crypto-asset service provider, the list of any delegates and sub-delegates, as applicable, and any conflicts of interest that could arise from such a delegation;
a description of how the applicant intends to supervise the delegations or sub-delegations.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
placing of crypto-assets
Definition
official currency
Definition
distributed ledger
Definition
reception and transmission of orders for crypto-assets on behalf of clients
Definition
exchange of crypto-assets for funds
Definition
consensus mechanism
Definition
operation of a trading platform for crypto-assets
Definition
e-money token
Definition
crypto-asset service
- providing custody and administration of crypto-assets on behalf of clients;
- operation of a trading platform for crypto-assets;
- exchange of crypto-assets for funds;
- exchange of crypto-assets for other crypto-assets;
- execution of orders for crypto-assets on behalf of clients;
- placing of crypto-assets;
- reception and transmission of orders for crypto-assets on behalf of clients;
- providing advice on crypto-assets;
- providing portfolio management on crypto-assets;
- providing transfer services for crypto-assets on behalf of clients;
Definition
offer to the public
Definition
providing advice on crypto-assets
Definition
offeror
Definition
execution of orders for crypto-assets on behalf of clients
Definition
crypto-asset service provider
Definition
crypto-asset
Definition
DLT network node
Definition
funds
Definition
client
Definition
asset-referenced token
Definition
issuer
Definition
exchange of crypto-assets for other crypto-assets
Definition
electronic money token
Definition
providing custody and administration of crypto-assets on behalf of clients
Definition
providing transfer services for crypto-assets on behalf of clients
Definition
distributed ledger technology
Definition
competent authority
- designated by each Member State in accordance with Article 93 concerning offerors, persons seeking admission to trading of crypto-assets other than asset-referenced tokens and e-money tokens, issuers of asset-referenced tokens, or crypto-asset service providers;
- designated by each Member State for the application of Directive 2009/110/EC concerning issuers of e-money tokens;