Source: OJ L, 2025/305, 31.3.2025Current language: EN
- Markets in crypto-assets
Crypto-asset service provider
- RTS on CASP authorisation
Article 6 Detection and prevention of money laundering and terrorist financing
Summary What does Article 6 of the RTS on CASP authorisation say?
This article sits within the broader authorisation application framework established by Article 62 of Regulation (EU) 2023/1114, and specifically addresses the anti-money laundering and counter-terrorist financing (AML/CTF) obligations that applicants must demonstrate to the competent authority.
Rather than simply declaring an intention to comply, applicants must submit a comprehensive picture of their AML/CTF risk framework: from the initial risk assessment covering their customer base, services, and geographies, through to the concrete controls, staff training arrangements, and the named individual responsible for compliance.
The article also requires applicants to show that their controls are proportionate to the scale, nature, and complexity of their specific business model.
Important points:
- Applicants must provide a full AML/CTF risk assessment covering their customer base, services offered, distribution channels, and geographical areas of operation.
- Identify and name the person responsible for AML/CTF compliance, including evidence of that person's knowledge, skills, and experience.
- Submit copies of AML/CTF policies, procedures, and systems, along with details of how staff are trained on these matters and how frequently the adequacy of controls is assessed.
Springlex's summary of the article, a reading aid, not a substitute for the legal text.
For the purposes of Article 62(2), point (i), of Regulation (EU) 2023/1114, applicants shall provide the competent authority with information on their internal control mechanisms, policies and procedures to comply with the provisions of national law transposing Directive (EU) 2015/849 and the risk assessment framework to manage risks relating to money laundering and terrorist financing, including all of the following:
the applicant’s assessment of the inherent and residual risks of money laundering and terrorist financing associated with its business, including the risks relating to:
the applicant’s customer base;
services provided;
distribution channels used;
geographical areas of operation;
the measures that the applicant has or will put in place to prevent the identified risks and comply with applicable anti-money laundering and counter-terrorist financing requirements, including the applicant’s risk assessment process, the policies and procedures to comply with customer due diligence requirements, and the policies and procedures to detect and report suspicious transactions or activities;
detailed information on how those internal control mechanisms, policies and procedures are adequate and proportionate to the scale, nature, inherent risk of money laundering and terrorist financing, range of crypto-asset services provided, complexity of the business model and how those mechanisms, policies and procedures ensure compliance with Directive (EU) 2015/849 and Regulation (EU) 2023/1113;
the identity of the person in charge of ensuring compliance with anti-money laundering and counter-terrorist financing requirements, and evidence of that person’s knowledge, skills and experience;
arrangements, human and financial resources ensuring that the staff of the applicant is appropriately trained in anti-money laundering and counter-terrorist financing matters (annual indications) and on specific crypto-asset related risks;
a copy of the applicant’s anti-money laundering and counter-terrorism policies, procedures and systems;
the frequency of the assessment of the adequacy and effectiveness of those internal control mechanisms, policies and procedures, and the person or function responsible for such assessment.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
placing of crypto-assets
Definition
official currency
Definition
distributed ledger
Definition
reception and transmission of orders for crypto-assets on behalf of clients
Definition
exchange of crypto-assets for funds
Definition
consensus mechanism
Definition
operation of a trading platform for crypto-assets
Definition
e-money token
Definition
crypto-asset service
- providing custody and administration of crypto-assets on behalf of clients;
- operation of a trading platform for crypto-assets;
- exchange of crypto-assets for funds;
- exchange of crypto-assets for other crypto-assets;
- execution of orders for crypto-assets on behalf of clients;
- placing of crypto-assets;
- reception and transmission of orders for crypto-assets on behalf of clients;
- providing advice on crypto-assets;
- providing portfolio management on crypto-assets;
- providing transfer services for crypto-assets on behalf of clients;
Definition
offer to the public
Definition
providing advice on crypto-assets
Definition
offeror
Definition
execution of orders for crypto-assets on behalf of clients
Definition
crypto-asset service provider
Definition
crypto-asset
Definition
DLT network node
Definition
funds
Definition
client
Definition
asset-referenced token
Definition
issuer
Definition
exchange of crypto-assets for other crypto-assets
Definition
electronic money token
Definition
providing custody and administration of crypto-assets on behalf of clients
Definition
providing transfer services for crypto-assets on behalf of clients
Definition
distributed ledger technology
Definition
competent authority
- designated by each Member State in accordance with Article 93 concerning offerors, persons seeking admission to trading of crypto-assets other than asset-referenced tokens and e-money tokens, issuers of asset-referenced tokens, or crypto-asset service providers;
- designated by each Member State for the application of Directive 2009/110/EC concerning issuers of e-money tokens;