Source: OJ L, 2025/300, 31.3.2025Current language: EN
Article 4 Information to be exchanged in relation to crypto-asset service providers
Summary What does Article 4 of the RTS on competent authority information exchange say?
This article mirrors the approach taken in earlier articles of the regulation but focuses specifically on crypto-asset service providers (CASPs).
It sets out the categories of information that competent authorities are required to exchange with one another for the purposes of investigation, supervision, and enforcement.
The scope is broad, covering everything from authorisation documentation and management body fitness assessments, to ownership structures, operational compliance, transaction records, and enforcement actions.
The article also includes a catch-all provision ensuring that any other information necessary for cross-border cooperation can be shared.
Important points:
- Competent authorities are required to exchange a comprehensive set of information on CASPs, spanning authorisation details, governance, shareholder identity, operational compliance, and any penalties or enforcement actions taken.
- The fitness and repute of both management body members and qualifying shareholders (those holding 10% or more) form a specific and notable part of the information-sharing obligation.
- Competent authorities are required to share information not only at the point of authorisation but on an ongoing basis throughout the supervisory lifecycle of a CASP, including where authorisation has been refused, withdrawn, or where non-compliance is suspected.
Springlex's summary of the article, a reading aid, not a substitute for the legal text.
Where necessary for the purpose of investigation, supervision and enforcement, competent authorities shall exchange the following information concerning crypto-asset service providers:
information and documents received in the context of the application for authorisation as a crypto-asset service provider pursuant to Commission Delegated Regulation (EU) 2025/305(11) or of the notification pursuant to Commission Delegated Regulation (EU) 2025/303(12), and where relevant supplemented thereafter in the framework of supervision, including:
the name of the crypto-asset service provider, its legal entity identifier as referred to in Article 17 of Commission Delegated Regulation establishing technical standards adopted pursuant to Article 68(10)(b) of Regulation (EU) 2023/1114, its website’s URL, its contact email address, telephone number, and physical address, and excerpts from national registers;
where applicable, the crypto-asset provider’s articles of association, as referred to in Article 62(2), point (c), of Regulation (EU) 2023/1114;
information about the management body of the crypto-asset service provider, including:
the names and where available, the personal identification numbers of its members;
information on the functions that each of its members hold within the crypto-asset service provider;
where relevant, information on any changes to the management body and the competent authority’s assessment thereof;
information about the members of the management body of the crypto-asset service provider necessary to assess their good repute and suitability, including where available:
information about their work experience, skills and time committed to their duties within the management body;
the information about their reputation referred to in Article 7, point (e) of Delegated Regulation (EU) 2025/305;
information about shareholders holding 10 % or more of the share capital or voting rights of the crypto-asset service provider, including their identity, the amount of their holdings, and the information about their reputation listed in Article 2, point (a), of Commission Delegated Regulation (EU) 2025/414(13), and where relevant, the competent authority’s assessment of any proposed acquisitions or disposals of a qualified holding in a crypto-asset service provider, in accordance with Article 83 of Regulation (EU) 2023/1114;
information about the organisational structure, operational conditions and compliance with the requirements set out in Title V of Regulation (EU) 2023/1114, including:
the programme of operations setting out the types of crypto-asset services provided, including where and how those services are marketed, pursuant to Article 62(2), point (d), of Regulation (EU) 2023/1114;
information about the governance arrangements and internal control mechanisms pursuant to Article 62(2), points (f) and (i) of Regulation (EU) 2023/1114;
information concerning compliance with Articles 67, 68 and 70 of Regulation (EU) 2023/1114, including risk-management and accounting procedures;
where available, the number of clients established or situated in a given Member State to which the crypto-asset service provider is providing services, the value of the crypto-assets managed or held for those clients, and the volumes of transactions executed for those clients;
information about any situations in which a crypto-asset service provider is suspected of not complying with the requirements set out in Title V of Regulation (EU) 2023/1114, together with an explanation of the consequent measures taken or planned by the competent authority;
information relating to the records kept by crypto-asset service providers in accordance with Articles 68(9) and 76(15) of Regulation (EU) 2023/1114;
information about the authorisation as a crypto-asset service provider, including where the authorisation was refused or the application for authorisation was retracted, and information on any withdrawal of the authorisation pursuant to Article 64 of Regulation (EU) 2023/1114;
information on any penalty issued pursuant to Regulation (EU) 2023/1114, including criminal penalties, administrative measures or enforcement actions in relation to a crypto-asset service provider;
any other information necessary for cooperation among competent authorities in investigation, supervision and enforcement activities pursuant to Article 95(1) of Regulation (EU) 2023/1114.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
placing of crypto-assets
Definition
official currency
Definition
distributed ledger
Definition
reception and transmission of orders for crypto-assets on behalf of clients
Definition
exchange of crypto-assets for funds
Definition
consensus mechanism
Definition
operation of a trading platform for crypto-assets
Definition
e-money token
Definition
crypto-asset service
- providing custody and administration of crypto-assets on behalf of clients;
- operation of a trading platform for crypto-assets;
- exchange of crypto-assets for funds;
- exchange of crypto-assets for other crypto-assets;
- execution of orders for crypto-assets on behalf of clients;
- placing of crypto-assets;
- reception and transmission of orders for crypto-assets on behalf of clients;
- providing advice on crypto-assets;
- providing portfolio management on crypto-assets;
- providing transfer services for crypto-assets on behalf of clients;
Definition
offer to the public
Definition
providing advice on crypto-assets
Definition
offeror
Definition
execution of orders for crypto-assets on behalf of clients
Definition
management body
Definition
crypto-asset service provider
Definition
crypto-asset
Definition
DLT network node
Definition
funds
Definition
client
Definition
asset-referenced token
Definition
issuer
Definition
exchange of crypto-assets for other crypto-assets
Definition
electronic money token
Definition
providing custody and administration of crypto-assets on behalf of clients
Definition
providing transfer services for crypto-assets on behalf of clients
Definition
distributed ledger technology
Definition
competent authority
- designated by each Member State in accordance with Article 93 concerning offerors, persons seeking admission to trading of crypto-assets other than asset-referenced tokens and e-money tokens, issuers of asset-referenced tokens, or crypto-asset service providers;
- designated by each Member State for the application of Directive 2009/110/EC concerning issuers of e-money tokens;
Footnote 11
Footnote 12
Footnote 13